<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ZoneDirector, Captive Portal, Grace Period, and users that leave the 
organization in Community and Online Support Services</title>
    <link>https://community.ruckuswireless.com/t5/Community-and-Online-Support/ZoneDirector-Captive-Portal-Grace-Period-and-users-that-leave/m-p/10266#M362</link>
    <description>Patrick, we don't recommend some of your suggested "workarounds", particularly with long authentication periods.&amp;nbsp; 802.1x does provide greater administrative control, and would allow&lt;BR /&gt;you to remove graduated students.&amp;nbsp; It might be best to discuss your security and accounting&lt;BR /&gt;needs with your local VAR or Ruckus SE, for a more complete solution.</description>
    <pubDate>Mon, 08 Jun 2015 18:03:36 GMT</pubDate>
    <dc:creator>michael_brado</dc:creator>
    <dc:date>2015-06-08T18:03:36Z</dc:date>
    <item>
      <title>ZoneDirector, Captive Portal, Grace Period, and users that leave the 
organization</title>
      <link>https://community.ruckuswireless.com/t5/Community-and-Online-Support/ZoneDirector-Captive-Portal-Grace-Period-and-users-that-leave/m-p/10264#M360</link>
      <description>I work for a School District that has 27 physical sites and over 7000+ users. &amp;nbsp;Currently to make our end user experience easy we have simply setup and PSK WPA2 SSID for BYOD users to connect to. &amp;nbsp;We have not been using the Ruckus captive portal to auth users. Our firewall (FortiGate) is currently doing it's own captive portal to allow users access.&lt;BR /&gt;&lt;BR /&gt;This has become a strain on our Firewall and we are looking to reduce the workload caused by the authentication requests and identity based policies on the firewall.&lt;BR /&gt;&lt;BR /&gt;We have discussed using the ruckus captive portal and a long grace period (7 days) to limit the amount of re authentication the end user must do and I can't quite find the info I am looking for in the docs. So here are my scenario&lt;BR /&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;UserA's Device Connects to BYOD SSID and authenticates via Ruckus Captive Portal to a RADIUS AAA server using AD User Credentials, RADIUS rule validates membership of AD Group "Has Wireless Access"&lt;/LI&gt;&lt;LI&gt;UserA's Device will be able to reconnect to the Wireless without requiring re authentication within 7 days.&lt;/LI&gt;&lt;LI&gt;UserA happens to live within Wireless distance of the School Site so UserA's device is basically able to remain connected 24x7.&lt;/LI&gt;&lt;LI&gt;UserA graduates from School, AD Account is removed and UserA would know longer be able to connect new devices using their defunct credentials.&lt;/LI&gt;&lt;/UL&gt;&lt;OL&gt;&lt;LI&gt;How do you deal with the existing connected device one UserA departs? &amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Can the UserA's device be disconnected by simply removing them from the "Has Wireless Access" group that RADIUS checks?&lt;/LI&gt;&lt;LI&gt;Does the Ruckus Controller recheck the RADIUS login validity?&lt;BR /&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;BR /&gt;One additional caveat is that at any time I need to know the IP of the device and associated user for up to 90 days after. &amp;nbsp;I believe RADIUS Accounting will allow me to record this info however I am unsure how reconnects using the Grace Period would be reported especially if the IP changes due to short DHCP Leases.&lt;BR /&gt;&lt;BR /&gt;I realize that many might say that I should be using a 802.1x User based SSID for this but management feels that this would be over complicated even though it is pretty much a one time setup.&lt;BR /&gt;&lt;BR /&gt;Also we do not feel that DPSK is an option as that requires a manual revoking the DPSK to disconnect the user.&lt;BR /&gt;&lt;BR /&gt;Does Ruckus provide any type of API access to the ZoneDirector? &amp;nbsp;If it was possible then I could easily integrate a call to the ZoneDirector from my User Provisioning system to deauth any devices.&lt;BR /&gt;&lt;BR /&gt;Thanks, I know this is long and may spur some conversation hopefully.&lt;BR /&gt;&lt;BR /&gt;Patrick</description>
      <pubDate>Tue, 02 Jun 2015 22:26:45 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Community-and-Online-Support/ZoneDirector-Captive-Portal-Grace-Period-and-users-that-leave/m-p/10264#M360</guid>
      <dc:creator>patrick_fitchie</dc:creator>
      <dc:date>2015-06-02T22:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: ZoneDirector, Captive Portal, Grace Period, and users that leave the 
organization</title>
      <link>https://community.ruckuswireless.com/t5/Community-and-Online-Support/ZoneDirector-Captive-Portal-Grace-Period-and-users-that-leave/m-p/10265#M361</link>
      <description>Anyone???</description>
      <pubDate>Mon, 08 Jun 2015 15:53:56 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Community-and-Online-Support/ZoneDirector-Captive-Portal-Grace-Period-and-users-that-leave/m-p/10265#M361</guid>
      <dc:creator>patrick_fitchie</dc:creator>
      <dc:date>2015-06-08T15:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: ZoneDirector, Captive Portal, Grace Period, and users that leave the 
organization</title>
      <link>https://community.ruckuswireless.com/t5/Community-and-Online-Support/ZoneDirector-Captive-Portal-Grace-Period-and-users-that-leave/m-p/10266#M362</link>
      <description>Patrick, we don't recommend some of your suggested "workarounds", particularly with long authentication periods.&amp;nbsp; 802.1x does provide greater administrative control, and would allow&lt;BR /&gt;you to remove graduated students.&amp;nbsp; It might be best to discuss your security and accounting&lt;BR /&gt;needs with your local VAR or Ruckus SE, for a more complete solution.</description>
      <pubDate>Mon, 08 Jun 2015 18:03:36 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Community-and-Online-Support/ZoneDirector-Captive-Portal-Grace-Period-and-users-that-leave/m-p/10266#M362</guid>
      <dc:creator>michael_brado</dc:creator>
      <dc:date>2015-06-08T18:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: ZoneDirector, Captive Portal, Grace Period, and users that leave the 
organization</title>
      <link>https://community.ruckuswireless.com/t5/Community-and-Online-Support/ZoneDirector-Captive-Portal-Grace-Period-and-users-that-leave/m-p/10267#M363</link>
      <description>So what would you recommend as a max for the Grace period?</description>
      <pubDate>Thu, 11 Jun 2015 17:13:41 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Community-and-Online-Support/ZoneDirector-Captive-Portal-Grace-Period-and-users-that-leave/m-p/10267#M363</guid>
      <dc:creator>patrick_fitchie</dc:creator>
      <dc:date>2015-06-11T17:13:41Z</dc:date>
    </item>
  </channel>
</rss>

