How can we report on which users are connected to which APs in IdentiFi V10?

  • 0
  • 2
  • Question
  • Updated 2 years ago
  • Answered
  • (Edited)
We are a high school with a V2110 IdentiFi controller appliance and I have recently updated from V9 to V10 firmware.  We have two SSIDs - one for internal users with WPA2 security, another for BYOD users with RADIUS security.

We used to be able to report on "Clients by VNS".  This was very useful because we could find out where students were by checking which access point their device (almost all of them have one) was associated to on the BYOD SSID.  Now, the single "Clients" report doesn't allow us to filter by which VNS, and also doesn't seem to show the username (the column is always blank on that SSID).

Is there any way around this?
Photo of Patrick Timms

Patrick Timms

  • 130 Points 100 badge 2x thumb
  • frustrated

Posted 2 years ago

  • 0
  • 2
Photo of Ronald Dvorak

Ronald Dvorak, Embassador

  • 48,924 Points 20k badge 2x thumb
You'd use the filter field in the upper left corner to show only clients with that filter string.

Here a example if I search for "SecureAccess" which is the used SSID and also the role name for that client...



I'm not sure why the username field is clear for you - as you'd see in the example the 802.1X PEAP username is listed in my report.

Could you post a example and also the exact firmware that you use so we'd get clearer view of the issue.

-Ron
Photo of Patrick Timms

Patrick Timms

  • 130 Points 100 badge 2x thumb
Thanks for this.  Maybe we'll make a feature request for an auto-refresh (like the old reports had) too.

This is what I see:



So it seems that WPA2 devices show the hostname as a User (which I don't mind but doesn't seem right), and all BYOD devices show as completely unknown - no user, no IP, no type, nothing... :/

This firmware is 10.21.01.0065.
Photo of Ronald Dvorak

Ronald Dvorak, Embassador

  • 48,894 Points 20k badge 2x thumb
I also miss the auto-refresh function so I support this CR ;-)
Photo of Ronald Dvorak

Ronald Dvorak, Embassador

  • 48,924 Points 20k badge 2x thumb
Could you tell me about the BYOD setup I'd like to unterstand why it doens't show the user information.

You've mentioned RADIUS, is it PEAP with NAC or how does it work.
Photo of Patrick Timms

Patrick Timms

  • 130 Points 100 badge 2x thumb
I'm now getting reports that people can't associate to the BYOD SSID - and indeed, nor can I.  This is since the upgrade and no VNS/RADIUS settings have been changed.

This is our RADIUS setup:

Photo of Ronald Dvorak

Ronald Dvorak, Embassador

  • 48,924 Points 20k badge 2x thumb
Wild guess - replace the shared secret on the controller and RADIUS and don't use special characters.

I'd like to unterstand the process in case there is a new guest at the site.
Is someone creating the AD account for every new guest or how does the guest get's the username/password.
Photo of Patrick Timms

Patrick Timms

  • 130 Points 100 badge 2x thumb
Thanks - that seems to have helped, clients with usernames and IPs are beginning to filter in (guessing we need to wait for individual client devices to try again).

For info, these are students so they use their existing AD account to log in, which goes via our web filter - SmoothWall - which talks to AD itself.
Photo of Ronald Dvorak

Ronald Dvorak, Embassador

  • 48,924 Points 20k badge 2x thumb
Great, let's see whether everything is working after they clients get reconnected.