Information Systems:Managing staff and guest devices on the wireless network

From uniWIKI
Jump to navigation Jump to search

Overview

uwd_staff and uwd_guest are the wireless networks for staff and guest use, respectively. This article will discuss the management of devices connected to these networks.

A few configuration notes to provide context:

  • Both networks use captive portal authentication. There is a separate captive portal instance for each network, but both use the same backend (RADIUS) to authenticate.
  • uwd_guest uses captive portal only.
  • uwd_staff has MAC authentication and captive portal authentication. MAC authentication takes precedence. Captive portal is used as a fallback.
  • Both networks are on VLAN 2. DHCP is currently provided by the Telus-provisioned, Actiontec router in the Narc cage.
  • Both are unencrypted (e.g. they do not use WPA/WPA2).

Despite MAC authentication being the primary authentication method for uwd_staff, the premise is that when a staff member joins a new device to the network, the MAC address will not yet exist in the database and thus authentication will 'fall back' to captive portal. For more information on the authentication scheme used in these networks, read here.

Procedure for adding a staff device

The RADIUS user pool Staff_LocalAuth already contains credentials (matching their Windows credentials) for all staff, as of December 2017. These instructions are specifically for adding a MAC address to bypass captive portal authentication for a staff member. However, instructions for adding a new staff member (username/password) can be extrapolated here.

  • You will receive an email - similar to the one below - when a staff member successfully authenticates a device using captive portal.
Date		 		 :2017-11-01 14:00:43
Device		 		 :ap-controller-office-2nd-floor
Description		 :Captive-portal authentication success for client 40-D3-AE-45-2E-04(192.168.1.106) user 'Darrenf'
  • Log in to WiNG (username/password found here).
  • Under the Configuration tab, navigate to RADIUS -> User Pools. Double-click the Staff_LocalAuth user pool to enter it.
  • As is shown, both the MAC addresses used for MAC authentication and username/passwords used for CP authentication are defined here.
  • Click 'Add'.
  • Using the email, set MAC address as the username and password. Important: Use lowercase and hyphens.
  • Add the MAC address and username to the table below. This, along with the email, are currently the only ways we can keep track of user-device relationships. It is unfortunate that a field doesn't exist in the WiNG implementation of RADIUS that we could use to specify this user-device relationship. Maybe in the future.
  • For Group List, check uniPHARM_Staff. (There isn't much to groups right now.)
  • Save the addition, and perform a Commit and Save. At this point, the changes are live.
  • At this point, the staff member should no longer see the captive portal when connecting to the network.

Procedure for connecting to the guest network

There is nothing that needs to be done for a guest to be able to connect to uwd_guest, other than perhaps providing the staff member hosting the guest with the username/password. In due time, this will become common knowledge anyway. Currently, it is 'unipharm/guest'. All guests connect to the network under the same user.

Caveats, issues, and other notes

  • Guest network consists of a single user (although I guess we could always define more, but they'll still be generic).
  • Currently users in the staff user pool can log in to uwd_guest, despite being in a group that technically forbids this.
  • Self-registration using OTPs (one-time passwords) to be explored in the future. Requires at least a VX controller.

List of registered staff devices

Company policy equates a successful login to an acceptance of the Terms of Conditions, as specified on the login page. Devices listed here should not prompt re-authentication via captive portal e.g. association to uwd_staff is via MAC authentication. A list of Registered Staff Devices can be found here.[file:\\superserver\tech\common\Staff_Wifi\Staff_MAC_Addresses.xlsx]