Recently one of our clients has installed a SonicWall unit and wants to enable DPI. All the domain users machines are managed so we can push out the DPI-SSL certificate easily to them. I need to figure out how to deploy the certificate across the guest network when visitors arrive on site. It can't be expected to manually install certificates on every guest users device.
My initial idea was just to purchase an SSL cert, import that into the SonicWall unit and the Ruckus ZD. However from reading a knowledge base I found the following:
"You cannot request a DPI-SSL CA certificate from a commercial certificate authority
Commercial certificate authorities will not issue certificates with Certificate Signing or Certificate Re-signing authority."
Plan B was to use OpenSSL to generate my own cert but how will I get the ZD to then trust that.
Any help on the matter would be greatly appreciated.
You could probably do this using the zero-it on-boarding but it means users need to download and run an APP which is far from ideal for a guest network. Maybe as a policy for employee devices it might fly. For guests its just too cumbersome.
You can import your own self signed CA in ZD. You need to add the root CA (public key) to the import but it's quite straightforward.
From reading up about Ruckus Cloudpath it gives you the option to deploy your own self signed certificate so that will work with SonicWall. For the time being I've created an exclusion for the guest WLAN so they won't be hit by DPI.