- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
BYOD and RADIUS
We're a K-12 boarding school with a ton of BYOD devices on our network. Currently, we have three SSIDs: Open (Mac auth), 802.1x MS-CHAP v2, and WPA2-Personal for guest access.
We need to keep the open network around for devices that can't do 802.1x auth like gaming consoles. My question is, how do you handle BYOD device authentication? Is 802.1x still the only game in town? We need it to be fast and simple. I'd like to avoid EAP-TLS for these types of devices as it can make the onboarding more difficult. This is why we're still using EAP-PEAP.
Any suggestions?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The simplest way is to use MAC filtering/authentication through RADIUS and host registration, authentication through the Portal. There is an example shown in this article for guests.
If the users already have an account in LDAP or in a remote RADIUS server, a Standard login through the portal is also possible. There is a dedicated portal section for Game device registration.
If the network need to be secure than EAP-PEAP is still good to go, FNAC supports a local RADIUS server and Winbind.
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Nothing has really changed with wifi in the recent years. It's still either open, PSK, or EAP (802.1x/"Enterprise"), nothing else.
(captive portal, or anything else, being optional on top of either of the primary three methods)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How does everyone handle EAP-TLS through a portal registration?
Created on ‎01-09-2025 04:40 AM Edited on ‎01-09-2025 04:43 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FNAC has the EasyConnect tool but it currently supports only EAP-PEAP and not TLS:
Supplicant Policies are applied to the host using an agent, except in the case of iOS devices where the user is prompted to download the configuration from the Captive Portal. The Dissolvable Agent or the Persistent Agent is used for Windows and macOS hosts and the Mobile Agent is used for Android devices.
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks but we're already doing PEAP without the need for an agent and Supplicant Connect. I'm guessing there's no way to do TLS unless the cert is already pushed to the end user device beforehand?
Created on ‎01-09-2025 05:36 AM Edited on ‎01-09-2025 05:40 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Technically you can personalize the portal page or also redirect to external pages that instruct the end user on how to provision their devices, but currently FNAC doesn't have a built in CA/PKI infrastructure or a tool that facilitate certificate distribution to end hosts.
You may also check FortiAuthenticator.
If you have found a solution, please like and accept it to make it easily accessible for others.
