ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Enterprise wireless access control system

    Scheduled Pinned Locked Moved IT Discussion
    30 Posts 9 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      Francesco Provino
      last edited by Francesco Provino

      Hi everybody, I have to deploy a wireless network that will span over 300 users for a house rental.
      The customer want to implement an access control system that will provide any user unique credentials and that will log not only the access but also the traffic for legal reason (https proxy in here).

      I'm searching for an all-in-one solution, easy to learn and deploy. Any advice is welcome!

      1 Reply Last reply Reply Quote 1
      • F
        Francesco Provino
        last edited by

        Addendum: can ubiquiti provides a captive portal and detailed log of any http request?

        What about Aerohive?

        jt1001001J 1 Reply Last reply Reply Quote 0
        • gjacobseG
          gjacobse
          last edited by

          I would go with Ubiquity -

          It is easy to deploy, centrally managed and can do Captive Portal.

          F 1 Reply Last reply Reply Quote 0
          • F
            Francesco Provino @gjacobse
            last edited by

            @gjacobse can it do also Radius? I see that a Radius server is needed for guest wifi.
            Can it also log any internet site visited by the users?

            1 Reply Last reply Reply Quote 0
            • gjacobseG
              gjacobse
              last edited by

              Yup sure can -

              https://help.ubnt.com/hc/en-us/articles/115004589707-UniFi-How-to-Implement-RADIUS-Authentication

              F 1 Reply Last reply Reply Quote 0
              • F
                Francesco Provino @gjacobse
                last edited by

                @gjacobse "beta program" is not what I could use in production…

                DashrenderD 1 Reply Last reply Reply Quote 0
                • jt1001001J
                  jt1001001 @Francesco Provino
                  last edited by

                  @francesco-provino we use Aerohive, you need the Identity Manager in order to provide a unique 1 time login per user. For the cost I would not recommend and we are looking at Ubiquity for our next hardware refresh

                  1 Reply Last reply Reply Quote 0
                  • DashrenderD
                    Dashrender @Francesco Provino
                    last edited by

                    @francesco-provino said in Enterprise wireless access control system:

                    @gjacobse "beta program" is not what I could use in production…

                    Then you need a full proxy solution

                    F 1 Reply Last reply Reply Quote 0
                    • F
                      Francesco Provino @Dashrender
                      last edited by

                      @dashrender what if I just need a log of the visited websites? No content filter is needed, just logging. What can the USG do?

                      coliverC 1 Reply Last reply Reply Quote 0
                      • coliverC
                        coliver @Francesco Provino
                        last edited by

                        @francesco-provino said in Enterprise wireless access control system:

                        @dashrender what if I just need a log of the visited websites? No content filter is needed, just logging. What can the USG do?

                        You could easily do something like a squid proxy for this.

                        F 1 Reply Last reply Reply Quote 0
                        • F
                          Francesco Provino @coliver
                          last edited by

                          @coliver said in Enterprise wireless access control system:

                          @francesco-provino said in Enterprise wireless access control system:

                          @dashrender what if I just need a log of the visited websites? No content filter is needed, just logging. What can the USG do?

                          You could easily do something like a squid proxy for this.

                          I want something fully supported, it's a production environment.

                          coliverC scottalanmillerS 2 Replies Last reply Reply Quote 0
                          • coliverC
                            coliver @Francesco Provino
                            last edited by

                            @francesco-provino said in Enterprise wireless access control system:

                            @coliver said in Enterprise wireless access control system:

                            @francesco-provino said in Enterprise wireless access control system:

                            @dashrender what if I just need a log of the visited websites? No content filter is needed, just logging. What can the USG do?

                            You could easily do something like a squid proxy for this.

                            I want something fully supported, it's a production environment.

                            I... what? What part of Squid isn't supported? Squid is fully production ready and is used in dozens of other appliances to do web filtering.

                            http://www.squid-cache.org/

                            It's a mature project that has been around for twelve years.

                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller @Francesco Provino
                              last edited by

                              @francesco-provino said in Enterprise wireless access control system:

                              @coliver said in Enterprise wireless access control system:

                              @francesco-provino said in Enterprise wireless access control system:

                              @dashrender what if I just need a log of the visited websites? No content filter is needed, just logging. What can the USG do?

                              You could easily do something like a squid proxy for this.

                              I want something fully supported, it's a production environment.

                              Squid is the industry standard and is as enterprise as it gets. You can get any level of support that you want for it. Literally, nothing gets more support for enterprise deployments.

                              1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @coliver
                                last edited by

                                @coliver said in Enterprise wireless access control system:

                                @francesco-provino said in Enterprise wireless access control system:

                                @coliver said in Enterprise wireless access control system:

                                @francesco-provino said in Enterprise wireless access control system:

                                @dashrender what if I just need a log of the visited websites? No content filter is needed, just logging. What can the USG do?

                                You could easily do something like a squid proxy for this.

                                I want something fully supported, it's a production environment.

                                I... what? What part of Squid isn't supported? Squid is fully production ready and is used in dozens of other appliances to do web filtering.

                                http://www.squid-cache.org/

                                It's a mature project that has been around for twelve years.

                                Has to be a lot more than 12 years. It was mature when I deployed it in production 12 years ago.

                                coliverC 1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller
                                  last edited by

                                  Squid is 21 years old.

                                  1 Reply Last reply Reply Quote 0
                                  • coliverC
                                    coliver @scottalanmiller
                                    last edited by

                                    @scottalanmiller said in Enterprise wireless access control system:

                                    @coliver said in Enterprise wireless access control system:

                                    @francesco-provino said in Enterprise wireless access control system:

                                    @coliver said in Enterprise wireless access control system:

                                    @francesco-provino said in Enterprise wireless access control system:

                                    @dashrender what if I just need a log of the visited websites? No content filter is needed, just logging. What can the USG do?

                                    You could easily do something like a squid proxy for this.

                                    I want something fully supported, it's a production environment.

                                    I... what? What part of Squid isn't supported? Squid is fully production ready and is used in dozens of other appliances to do web filtering.

                                    http://www.squid-cache.org/

                                    It's a mature project that has been around for twelve years.

                                    Has to be a lot more than 12 years. It was mature when I deployed it in production 12 years ago.

                                    July 1996 was the first stable release. It has probably been around significantly longer then that.

                                    1 Reply Last reply Reply Quote 0
                                    • scottalanmillerS
                                      scottalanmiller
                                      last edited by

                                      Companies providing Squid enterprise support include Red Hat, Suse and Canonical. Many others do as well, those are just quick examples of "no product on Windows has this level of support, including Windows itself." I think IBM supports it, too.

                                      1 Reply Last reply Reply Quote 0
                                      • F
                                        Francesco Provino
                                        last edited by

                                        Thanks everybody for the hints!

                                        So, your suggestion is using ubiquiti hw for access point and for the gateway (USG for example) and squid for the proxy part.

                                        I think I could put squid in a vm aside the ubiquiti controller, a small 1U server should be more than enough.

                                        scottalanmillerS 1 Reply Last reply Reply Quote 0
                                        • PenguinWranglerP
                                          PenguinWrangler
                                          last edited by

                                          I would go with the edge Routers over the USG.

                                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                                          • scottalanmillerS
                                            scottalanmiller @Francesco Provino
                                            last edited by

                                            @francesco-provino said in Enterprise wireless access control system:

                                            Thanks everybody for the hints!

                                            So, your suggestion is using ubiquiti hw for access point and for the gateway (USG for example) and squid for the proxy part.

                                            I think I could put squid in a vm aside the ubiquiti controller, a small 1U server should be more than enough.

                                            Yes, and @JaredBusch and I would "always" recommend a proxy inside of a VM and not in the firewall itself. That's not a function that you want located on your firewall box. By having it in a VM you have more power, more flexibility and better options for support.

                                            1 Reply Last reply Reply Quote 2
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post