Jump to content

Recommended Posts

Posted

I'm trying to get my head around using our Ruckus for allowing certain students to access the internet from their own devices in school. I would like them to effectively only have access to the web proxy (smoothwall) and authenticate using their AD credentials. We don't have our APs on a seperate VLAN (due to the nature and variety of network switches) so I'm hoping that Ruckus's own isolation will help with that, but I am struggling to get my head around how Ruckus do this.

 

I've tried to enable guest pass authentication, using our RADIUS server, but when redirected to the authentication page no valid credentials work so I get the feeling I'm missing a stage out at some point.

 

Has anyone managed to do this, and have they got an idiot guide handy!

Posted

Cheers for the offer - I might take you up on that when I get some time set aside.

 

I've got a simple guest network running, which works with RADIUS and allows valid AD accounts to connect. However my wpad.dat file isn't recognised by any device. I've got the wpad.dat on the Zoendirector and configured in DHCP but everything that connects seems to ignore it!

Posted

I was trying to do you same with wpad.dat to get proxy setup on guest laptop! don't get it to work and gave up in the end after being off work for a week.

 

Would like to get this to work some how?

 

Any one had any luck with setup Ruckus with wpad.dat?

Posted
I think theres something fundamentally wrong with my ruckus. I've got the RADIUS servers setup, and configured Roles for each group (admins/staff/students etc) but the AAA query always shows success but the group assignment will be 'default'!
Posted (edited)

I've never used VLANs before - is there an idiots guide somewhere?

 

I've got Ruckus to authenticate with AD, no worries, and without the VLAN settings it's getting IP addresses from a DHCP server and, when the proxy settings are put in manually, all is well.

 

I'm thinking one way to proceed now is:

1. set a spare port on a managed switch to be a new VLAN

2. connect a smoothwall transparent proxy with DHCP, which I've used before to add a proxy setting where the client device didn't support it, to it

3. set that VLAN to the BYOD Network in Ruckus

 

How does that sound? will that then give a client device an IP from Smoothwall and allow it to access the web? or have I fundamentally missed a point or two along the way?

 

edit: I've just read through the thread again and it looks as if I've hijacked it - mods if you want to move this to a new thread that's fine by me!

Edited by BatchFile
Posted
I've never used VLANs before - is there an idiots guide somewhere?

 

 

You need to get your head round that first, took me a while as well and I believe a number of posts on here will point you in the right direction.

 

But, in a nutshell ;) - You'll need switches that are managed, you'll need to setup the VLANs on all your switches (obviously, only those that will have traffic flowing for each VLAN), 'tag' the trunks/uplinks to each Edge switch with the associate VLANS, setup DHCP helper on your Core Switch for the VLANs to point at your DHCP server, Setup a DHCP scope for the BYOD with the gateway set to the IP address of your Core Switch, 'tag' the port that has the AP plugged into for your guest VLAN (you'll need to tag it with the other VLANs as well if you have other SSIDs for on it and management so that ZoneDirector can still access it), setup the SSID on the ZoneDirector to be associated with a particular VLAN and, errr, that is about it. I think, working from memory. May have missed out a step but hopefully it'll help.

 

Pete

  • Thanks 2
Posted
I think theres something fundamentally wrong with my ruckus. I've got the RADIUS servers setup, and configured Roles for each group (admins/staff/students etc) but the AAA query always shows success but the group assignment will be 'default'!

 

You need to add some additional attributes to get the radius groups working

 

Windows NPS Radius + ZoneDirector, A How to guide. - Ruckus Wireless Forums

 

I have got it working to assign available ssids via group membership

  • 2 weeks later...
Posted

Hmm I feel I am so near to getting this working, yet so far!

 

I've got AD authentication working, and using the youtube example above I've managed to get a hotspot service set up and zero-it provisioning working, with a WLAN for staff and another for students.

 

This seems to work, a user select the 'open' wlan and then when any web page is requested the authentication page appears. After successful authentication the zero-it installer comes in and adds the correct WLAN on the test pc (in this case an iMac).

 

But thats where it stops, the mac stays connected to the hotspot wlan and ignores the specific wlan that is assigned to the user's group. The zero it part seems to configure this correctly and thats where it falls apart as you can't go any further!

Posted

It's the one failing, that myself and others have noticed - it doesn't switch the user to the SSID automatically that has been setup with the Auto Provisioning. The user has to switch to that Wireless SSID themself to start using your internet connection. Also, the problem on Android devices is that by default they don't allow .apk files to be installed from unknown sources; this has to be setup on the phone by the user, but of course, trying to explain that to some users is tricky.

 

Looks like your there really, try it out on a few guinea pigs and see how it goes.

 

Pete

Posted (edited)

I noticed the issue with apk files on android phones as well, but thats something thats easy to work around I suppose.

 

I gave up with the mac, and got it working on and android device but that ignores the proxy settings I uploaded to the zonedirector (wpad.dat) so even when I get a connection its useless!

 

I'm so close I can almost taste it!

 

EDIT, spoke too soon! Android devices just sit in a loop of Authenticating... and Obtaining ip address.

 

The macs connect and fail to connect to the correctly assigned wlan, and even when manually connected they ignore the wpad.dat settings. Oddly my test mac now refuses to open the zero-it file (prov-mobileconfig) and attempts to open it with Apple Logic Pro!

Edited by Sheridan
Posted

I think I'll have to ditch the byod aspect of ruckus - it doesn't seem to work very well. For starters the zero-it part doesn't work on Macs and then the correct WLAN isn't selected. Plus it simply ignores the wpad.dat file that is uploaded to the zonedirector so it means manual proxy details have to be entered - that defeats the purpose a bit.

 

Its inconsistent on android devices as well, so I have no faith in rolling this out to staff/students who might be on ipod/ipads/macs/phones etc!

 

Has anyone implemented a robust byod system with anything like Aruba or a similar competitor?

Posted

All I would say in conclusion is - don't waste too much time with byod on ruckus. It looks like a bit of a mess and I've given up trying to sort it out.

 

I've decided to ditch the ruckus and use some Dlink WAP's (just using wpa) and stick them on a seperate vlan in key areas of the school. This Vlan will have its own non-authenticating smoothwall web filter and thats all they will have access to. They will still need to put the proxy settings manually in but that would have been the case with ruckus anyway. Frustrated and disappointed with ruckus - but I've wasted too much time on this.

  • Thanks 1
  • 11 months later...
Posted (edited)

well i'm pretty much there with it.

 

the video a few posts up really helped.

 

I have 5 WLAN's. a bog standard WPA2 with MAC filtering for all school devices. schools ios devices are configured via apple configurator with WLAN, proxy and the mcafee firewall certificate which the county insist we use.

 

then we have a portal/provisioning WLAN for the site. which handles the zero-it shenanigans and pushes the users to either the staff or students WLANS depending on their AD group membership. windows clients have autodetect settings for wpad and ios users have to manually enter the FDQN to a local IIS serving a .pac

 

Finally and this is the stumbling block. the guest wlan. I'm trying to set it up and it it works ish. all the problems lie with ios and the inability to add cetificates and proxy settings to the zero-it mobile.config file. however the wpad deployed doesnt seem too clever on windows either. with ios i can add the .pac path to the WLAN before connecting. when connecting it will sometimes call the captive portal directly, sometimes i'll have to open safari and either type a random url or have to type the fdqn of the ZD activate page. today i felt all smug that it was working. we had to prep 8 netbooks for some training. the first one went in a treat and then it fell apart. they just wouldnt take the wpad. the worst part is these proxy files might be cached somewhere leaving me running around in circles trying to fix it.

 

I think i might just create AD users for guests and just assign them login credentials via a laminated card. Just to get the job signed off for half term.

 

A side note. we use owncloud to shovel files from ios to windows. works like a bought one

 

s1n

Edited by s1ndr0me
Posted
I think I'll have to ditch the byod aspect of ruckus - it doesn't seem to work very well. For starters the zero-it part doesn't work on Macs and then the correct WLAN isn't selected. Plus it simply ignores the wpad.dat file that is uploaded to the zonedirector so it means manual proxy details have to be entered - that defeats the purpose a bit.

 

Its inconsistent on android devices as well, so I have no faith in rolling this out to staff/students who might be on ipod/ipads/macs/phones etc!

 

Has anyone implemented a robust byod system with anything like Aruba or a similar competitor?

 

What version of the Ruckus firmware are you currently using and what model of ZD and APs do you have? The ZeroIT works excellently on both iPads and Macs. Ruckus has one of the more robust BYOD setups I've used.

 

Everything is likely going to be inconsistent on Android devices if you are using a wide mix of hardware and OS versions...that's what we've found.

Posted

A bit off topic, but I have to ask.

 

Why are so many of you still using an explicit proxy setup rather than a transparent proxy? Using an explicit proxy is an enormous headache, some systems don't play well with it or at all, and as many of you are finding PAC deployment is not very simple or reliable in a BYOD or heterogenous device environment. On the other hand, a transparent proxy eliminates all of those headaches and still ensures that all traffic flows through the correct path (the filter). If you are using an explicit proxy as a form of network security to prevent unauthorised clients form joining, there are better ways to do it including MAC filtering, NPS, Packetfence, or other NAC systems.

 

Anyway, off-topic post finished.

  • Thanks 2
Posted

Thanks for the reply seawolf,

 

I've heard a bit about transparent proxies whilst trawling the boards for ruckus info. we just run a couple of explicit squids that authenticate with the counties ISA server, they take care of firewall/filtering duties. We are tied in with them for years and they are inflexible to say the least. Are you saying that NPS or packetfence act as transparent proxies?

 

If you have the time could you explain a bit further?

 

many thanks

Posted
Thanks for the reply seawolf,

 

I've heard a bit about transparent proxies whilst trawling the boards for ruckus info. we just run a couple of explicit squids that authenticate with the counties ISA server, they take care of firewall/filtering duties. We are tied in with them for years and they are inflexible to say the least. Are you saying that NPS or packetfence act as transparent proxies?

 

If you have the time could you explain a bit further?

 

many thanks

 

We use a Transparent Inline Bridge configuration for our web filter, which means that it sits in between the core network switch/router (LAN) and the firewall. So, all traffic HAS to flow through the filter to get from the LAN to the WAN and vice versa. This is a bit different than what some have called a transparent proxy in the past, which was really more of an automatic proxy mode rather than being an inline proxy, because traffic is intercepted and redirected (causing problems with SSL) with that method.

 

NAC systems don't act as proxies, they control access onto your network. My comment was more regarding the issue I sometimes see where network managers see explicit proxies as a way to restrict access to the network (or WAN access at least) and that is why they won't look at the transparent inline bridge/proxy option. However, that's not what a proxy is for and using proper NAC such as NPS or packetfence are the proper ways to achieve access control to your network.

Posted
My comment was more regarding the issue I sometimes see where network managers see explicit proxies as a way to restrict access to the network (or WAN access at least) and that is why they won't look at the transparent inline bridge/proxy option.

 

School network managers in much of the UK will be using explicit proxies because that is the *only* form of internet access they have from their ridiculously overpriced RBC connection. Transparent with a forced upsteam doesn't get you very far these days with so much needing ssl, which you are still forced to proxy upstream...

 

Leaving the only way of getting anything sensible working, is having clients set a proxy on their mobile device.

  • Thanks 1
Posted

Thanks guys, your help is appreciated. I think I fall into DMcCoy's bracket of users.

 

TBH after this morning I've had a guts full. Got in and now cant get the captive portal page up unless all the windows lan settings are unticked including auto detect. once provisioned I then need to go back in and check the auto detect settings again. pain in the ...... probably something to do with the walled garden.

Posted
School network managers in much of the UK will be using explicit proxies because that is the *only* form of internet access they have from their ridiculously overpriced RBC connection. Transparent with a forced upsteam doesn't get you very far these days with so much needing ssl, which you are still forced to proxy upstream...

 

Leaving the only way of getting anything sensible working, is having clients set a proxy on their mobile device.

 

Can't comment on the overpriced RBC connections in the UK.

 

However, SSL works just fine with a properly configured transparent inline bridge/proxy (no certificate errors). Forced upstream isn't really a "transparent" proxy, it's just an automatic proxy, thus the problems with SSL.

Posted
Can't comment on the overpriced RBC connections in the UK.

 

However, SSL works just fine with a properly configured transparent inline bridge/proxy

 

By doing ssl domain lookup from the cert, like one of the smoothwall options (and other filters), and allowing a *direct* ssl connection avoiding a mitm issue. Can't do that when you *don't* have direct https access to sites...

Posted
By doing ssl domain lookup from the cert, like one of the smoothwall options (and other filters), and allowing a *direct* ssl connection avoiding a mitm issue. Can't do that when you *don't* have direct https access to sites...

 

Sounds like the internet services available for UK schools leave a lot to be desired...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...