https://www.ironwifi.com/
IRONWifi was designed around the support for a cloud based Wifi authentication systems . It works great and is used by numerous guest and hotels based WIFI solutions & that needs to authentication users.
Here I will demo a straight configuration using a IronWIFI radius-server for a fortigate user.
On IronWIFI you will need a portal account in order to select a radius server region and create the RADIUS_users. The offer demo access and pricing solutions that will meet most ORGs needs.
They will provide a specific RADIUS-server port for the auth/acct function which are not the well known radius services udp1812/1813 . The pricing model of IronWiFi makes it economical if you need to support array of APs and numerous users. We are going to use it for a fortigate-firewall & for a local defined system admin user in this case kfelix.
Here's the cfg on the fortigate, it's identical to any other radius user cfg, btw.
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQxM1-r68N3jWluWrDNrVRb_9XpkVush91_misoNT7Mm5X8p4TEGcdSIdJLQUgIPatK4IzGB5meUE5SRhDgnM0qpf4PGhtYXp8qAMs2dJ-TIzbONoTx8l37cg8qr-e4OycU3K9yElSyGs/s400/Screen+Shot+2017-04-06+at+11.05.09+AM.png)
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEikh4aAZgdoPUjp7_SWwnPww6J60P_Vb8zCIEgwXw-J4nqwYZ19fzwyysjU5-zLrtEWWA5C95L7BXS5eyZEAX7ZQZbFt7qhY1qcwdq3x8gpJKsxiXiF5UR2fqK4jm_zUQWtLacMbQRPZl8/s640/cfg.png)
Once you have an account setup, the cfg is simple for the IronWIFI items.
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhkeXgQbbdS1n41daPcNvX1ouRZo0Ork0IRIvk-OKibGIy_Mt-g0VNEAm6FTmLXfG7RAcUrH9twHVBMS2FA4mCUhXtrSKRAa-Jua8UVIe7h9MEPZiPy4NgvxSsjVRsVhZEq_OsdVVg51Lk/s640/rad_aaa.png)
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjrunrQfTZLDq1q28CMq54bbs8xyvQ_TTDCOZyc890FCLHcX9fXTMkYoAD1alGPYlzWdwdovSXwgTSIVJYSPI6n_hLwQFF9h4uGtPtZyo38vZzJP7mXHs8gPB3DnOkVSVOeV7TwYP-PXRY/s400/Screen+Shot+2017-04-06+at+11.05.09+AM.png)
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhMmiKb-A0Ru2kcUFl13Pt_icSKYtWaw019CjcQ_mlYY2LkLrorlO87Id0zQPY24XqUE3EP114_Ydgy2HymfQoEpOMYsQF62Gx0sXgZZenKQUQvdlkvU2RsrnbcVkjEr6tHEvOvK49kgE/s1600/display_the_secret.png)
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj2dhJ3ZG6KnB18wst1iSff38MRj_oVnTW0ldU_I5tMnJj0-siLG2DdFDlABrsYLbXd8-gQRAYeQhvXjbUa8auxPHYI2XGec2rLz9X9JXslNqyPQgjDCR-aR31ouwuYKTzTNeDd4WhwwTY/s640/RAD_DETS.png)
RadiusClient
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjitbtOD9FakMjclBKt7mhgqa1zrUiPKqglk3YtjcgKqYTUlnp-8KzXxONbvmDXegiQ1-IqilgAA66ZN3AfB2sQAR0korqUjgv0XOO4qXdEyXQGhLsxXzyFT23i39iPnyKKQ3TbvFSeBwg/s640/SOCPUP.png)
Users accounts creations
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoFEEXIC3PPvrnBmSABduh4gE-g8Xk329QSMae1Ds0O7RGUs6BqE7NmUHytq8QR50s0Th5ntPtxL6Q3y5XlAipA6azBIJo9L3jqrpMO7M1zDXyqu_IOtM7RaBKkyhRYXRCaFOxQmvwv5A/s640/user-creation.png)
You have a simple dashboard , and its provides very good details for the avg administrator and on what's happen ( when/what/who/etc....)
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjbmVARKPzgnUlNuw4KFCKAoS0YgDBGBqZrvDcDQZs3BAwgfVc0I3g9oUL7aj-mvHidKZlpRAd8YfabvLmb14qdEbTCCYxdqxPwA1BMfyo2QL3Gg9wHEk1Z58KP9qWrG5Zb7umJwpcBZ6s/s640/dashboard.png)
You have a host of pre-defined reports that can be executed to displau access-accept or rejects. These logs can be downloaded as a text-format which will meet most audit-trails.
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEis-kxF8zd9Rof5QeSkbTAQ2SzInCYu5YNojHlPZvFzs3HKnnDEbxvGMTR95j_UJNafw5OIkWWi0m6pmRturkhg8u4tXuEsSIsVwbHgYViXJGFNFJ5XkYD4hgH82EBI9Yj0jU6JVNhX3vE/s640/defined_reports.png)
The meer fact that you can download logs is a big plus imho and these logs are simple to follow.
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiuJGoMjrQDaBhGvbovs8GbYVfc6lCsqlfrXMt-xOp3oTUS-XEbQAv_cVJcxmfDaRGRsuBnI_orxbgoVoi67tbiKY3iQrvbb-99SBICW0dJNHM1BI84IHdWKaWCUR52Ug1BK-EvvBgXWe4/s640/acces-reject.png)
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXAS3bpIjV4dhy1Aj42WHA08FjTgAxdY95ZIFZIwL9wvkT2mInI0gDqTCp9uZa4kGJpcKOmpnk2SwMExQkgNSEjFTEnF3JMH7FAdT3jmxuzVaqgS3vfX-mwblgG8WXsem-yLPs3Rh9DP4/s640/sucess_login.png)
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhaZi_zCnQ6YgFQb-DsC7SEkcoO_PoiD5CyypTEc71dOppef9gn4KWtf715kVy5yoGWJK29p66AqbmDFEBDL0lzHxRPHj4GS6XpUA1DSAe-ipp2fRJ4STEkgUiA09OPkhVH4d0drIgaUpg/s640/failed_logins.png)
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgBS3ZtY0A-pL0Id-nXjxVvid44roQW7RIsuhZgbl953wC1Qi6ORR3AukwtDNy9BRodMZ0UhKQ-2lyULsw01OzMKjUKb-U1eu9oGjvx7EmimvKVC8Zv_a3WtQ7wwWqWJoRWcGUdJU-hPyA/s640/denied_reports.png)
The advantage of IronWiFi over jumpcloud RADIUS-aaS are listed here & along with a typical deployment design.
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEih75U23ElmAZ6gvp4Rn7HmX_f6qOlg-rfiVSrfV8tOIqDcr8JLV6O1STJ88pgd9v8-nc4PjQ-pY6yeTaNY19OQzcknCe8jnVlowI1WzpgTCosHAWjo_wunM8buRnC3STZXCLTeQjw85No/s1600/Screen+Shot+2017-04-06+at+10.52.04+AM.png)
Both are gear as RADIUS-aaS services but they are different in many way. IronWIFI an JumpCloud are reliable and good solutions.
AFAIK,
IronWIFI does not have a LDAP-aaS other contender in this market are foxpass.
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEinrZxaRupttH13NZdsH56OdJoki3ySmf7l9PM3bJ-kd1EEnaDpJeKGUbCZf6IcUmVS5MIW5tSmEVeoYC1v2noAvss1Wu_yVr78x0w6vJzpl9zVw1Oz7L_JETmfsKj3yzU2EziosNB-yCY/s400/Screen+Shot+2017-04-06+at+11.05.09+AM.png)
Ken Felix
Ken Felix
NSE ( network security expert) and Route/Switching Engineer
kfelix -----a----t---- socpuppets ---dot---com
^ ^
=( @ @ )=
o
/ \
No comments:
Post a Comment