Jump to content

Gruff

Members
  • Posts

    2
  • Joined

  • Last visited

Reputation

0 Neutral

About Gruff

  1. Thanks for the replies. I've been using DHCP to distribute wpad settings on the main network for a while now. This works great as we have full control over what OS and browers people are using. As the new WLAN is designed to facilitate BYOD, the aim was to have a system that could support various OS & browers, and have little or no client configuration required. What Grant's mentioned regarding HTTPS decryption and a 'safe man-in-the-middle attack' seems to be the only the to achieve this. I've read that the latest build of Squid proxy (3.2.x) now have features capable of doing this, but the configuration and compiling of the software seems a lot more involved than just the normal install/setup (especially nor a *nix novice like myself). The self-certified certificate is then the only issue for clients I guess. I'll have to look into the system further and see what I can do. I'll post back here if I get any further. Meanwhile, if anyone knows of any better solutions, I'd glad accept advice!
  2. Hi all, I've been searching the forums and have seen various threads relating to this topic but have yet to come across any real solutions. We've setup a guest wireless network to allow students to bring in laptops/tablets etc from home and access the Internet. To avoid having to configure any settings on the student devices, we've configured a transparent Squid proxy which passes all HTTP traffic from the guest wireless network through to the school network and out to the Internet. The problems occur when a student tries to access an HTTPS page on the guest wireless network, and they getting a response of unable to establish a secure connection. If the proxy details for the Squid server are manually entered, the HTTPS session works and secure connections are allowed, so it's obviously just the transparent aspect that's causing the issue. I've read a few articles saying the Squid can be compiled with the --enable-SSL feature to allow transparent HTTPS connections but I'm not really sure what I'm doing regarding this. There's also been mention of SmoothWall and Dansguardian, but again, I'm not familar with these and whether they could provide a better solution or not? Any help would be greatly appreciated!!
×
×
  • Create New...