cancel
Showing results for 
Search instead for 
Did you mean: 

The WLAN device can access the zone director ftp service in the pre-authentication phase under the web / captive portal

fung_kwong
New Contributor

We have a problem about the The WLAN device can access the zone director ftp service in the pre-authentication phase under the web / captive portal. Even I disable ftp anonymous but it is a concern about the port is still open and it seem no any alert or event log trigger if anyone access the ftp service.

I submit a case to the Ruckus support and the reply as the following:

The guest device are able to reach the controller before entering the guest pass / web / captive portal . Once the user gets an IP after the DHCP DORA process, the user will be able to ping the controller or FTP into the controller provided he knows the credentials before the authentication. The ACLs are applied post-authentication. Controller can create the policy, but it cannot apply the policy pre-authentication of the user.

Would you have any idea about this case? Because it is a security issue in my view.

5 REPLIES 5

fung_kwong
New Contributor

For more information. In the post-auth phase of the guest-pass, I try to access the zone director from the guest device through ssh and the management web GUI but the result is blocked. Only ftp service is allow to connect.