This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Wireless Strategy / Best Practices

Dear Sophos Com,

 

We recently switched from an older UTM220 to an SG135w. Regarding Wireless, I would like to redo our current setup and cannot find much information on strategies in the Knowledge Base. Basically, we have the SGw internal Wifi and an older AP10 that we would like to use as a range extender.

 

Currently, my desired scenario would be like:

- Guest network, isolated from internal. May be ticket based (Hotspot).

- Internal WiFi, bridged to LAN. This would be for mobile workstations etc. that need to access the LAN like any cable-connected device. Authentication against Active Directory preferred.

- Internal WiFi, BYOD. Isolated from internal, but preferred with authentication against AD. So only current Employees would be able to use it.

 

Is that a valid design? Are there any documenst/whitepapers that cover something like this? I actually don't really know where to start. As we are no longer utilizing our previous Sophos Partner, I'd prefer to work thru this myself. I am experienced with the Sophos UI and would like to learn about Wireless.



This thread was automatically locked due to age.
Parents
  • You can authenticate WPA2 against a RADIUS server, and the Windows RADIUS service does use AD.  Start with a Google on:

    site:community.sophos.com/kb utm wireless

    You might find Configuring HTTP/S proxy access with AD SSO helpful.  Although the article is aimed at Standard mode, 98% of it applies to Transparent mode, too.  Finally, you might be interested in a document I maintain that I make available to members of the UTM Community, "Configure HTTP Proxy for a Network of Guests."  If you would like me to send you this document, PM me your email address. I also maintain a version auf Deutsch initially translated by fellow member hallowach when he and I did a major revision in 2013.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • You can authenticate WPA2 against a RADIUS server, and the Windows RADIUS service does use AD.  Start with a Google on:

    site:community.sophos.com/kb utm wireless

    You might find Configuring HTTP/S proxy access with AD SSO helpful.  Although the article is aimed at Standard mode, 98% of it applies to Transparent mode, too.  Finally, you might be interested in a document I maintain that I make available to members of the UTM Community, "Configure HTTP Proxy for a Network of Guests."  If you would like me to send you this document, PM me your email address. I also maintain a version auf Deutsch initially translated by fellow member hallowach when he and I did a major revision in 2013.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data