| NOTE: This guide is for v7.3 and above. For earlier versions, see this guide. |
Configuration
Log in to your SonicWall firewall and click Network at the top. Under IPSEC VPN > Rules and Settings > Settings ensure the Unique Firewall Identifier is the original serial number of the device.
Next, go to Device > Users > Settings and on the Authentication tab configure with:
| User authentication method | RADIUS + Local Users |
Click the Configure RADIUS button. Under the Settings header > RADIUS Servers sub-header click ADD... and configure on the Settings tab with:
| Host Name or IP Address | *insert radius_server here* |
| Port | 1812 |
| Shared Secret | *insert radius_secret here* |
| Confirm Shared Secret | as above |
On the Advanced tab:
| User Name Format | Name@Domain |
Click Save. Click ADD... again and configure exactly as above with the following change:
| Host Name or IP Address | *insert radius_server2 here* |
Click Save again. On the RADIUS Users header:
| Default user group to which all RADIUS users belong | Guest Services |
Finally, click Save. Next, under RADIUS Accounting Configuration, under the Servers tab click ADD... and configure on the Settings tab with:
| Host Name or IP Address | *insert radius_server here* |
| Port | 1813 |
| Shared Secret | *insert radius_secret here* |
| Confirm Shared Secret | as above |
On the Advanced tab:
| User Name Format | Name@Domain |
Click Save. Click ADD... again and configure exactly as above with the following change:
| Host Name or IP Address | *insert radius_server2 here* |
Click Save again. On the User Accounting tab configure:
| Guest users | Enabled |
| Include | Domain and local users |
| Send interim updates | Every 2 minutes |
Click Save.
Next, go to Object > Match Objects > Address Objects and click Add at the top. Here, you will need to add multiple rules to allow pre-authentication traffic to be permitted. For each of the domains you need to add a rule as follows, changing the Name and FQDN Hostname each time. Please refer to this list.
| Name | *domain here* |
| Zone Assignment | WAN |
| Type | FQDN |
| FQDN Hostname | *domain here* |
Once all the required entries are added click on the Address Groups tab and Add at the top. Enter a name of guestwifi and then for each of the entries you created above click the -> arrow to move them to the right hand box. Click OK to save.
Next, go to Object > Match Object > Zones and edit the zone you are using for your guest users (typically the WLAN zone). Under the Guest Services tab configure with:
| Enable Guest Service | Enabled |
| Enable Captive Portal Authentication | Enabled |
| External Captive Portal Vendor URL | *insert access_url here* |
| Captive Portal Welcome URL Source | Custom |
| Custom Captive Portal Welcome URL Source | *insert redirect_url here* |
| Session Timeout Source | From Radius |
| Idle Timeout Source | From Radius |
| Radius Authentication Method | PAP Encrypted |
Click Save.
| IMPORTANT: You must follow these instructions after upgrading to v7.3 or higher in order for the guest captive portal to continue to function. |
Next, go to Device > Administration and configure with:
| SonicOS API | Enabled |
| RFC-2617 HTTP Basic Access authentication | Enabled |
Click Accept.
Next, we need to upload a public SSL certificate to the firewall to ensure the required captive portal API calls are successful.
Go to Device > Certificates. If you already have a public certificate you wish to upload, click Import and follow the instructions. If you do not have a public certificate, click New Signing Request and complete the form. Be sure that the Common Name is the real hostname of which you wish to set up the firewall to host on, i.e. sonicwall.company.com. Once you click Generate, you'll need to provide the CSR to your chosen SSL certificate provider (such as Enom, GoDaddy etc). Once your certificate has been issued, return to the Certificates page and click Import and follow the instructions.
You'll need to ensure you create a public (or internal, if your Guest WiFi users are pointing at your own DNS server) DNS record that points your chosen Common Name (i.e. sonicwall.domain.com) to the Guest interface gateway IP in order for the captive portal API call to succeed.
Finally, if you are using SonicWall Access Points be sure to create an open SSID to enable guest users to connect.
Configuration Complete
The configuration is now complete.
| IMPORTANT NOTE: You need to add the Unique Firewall ID (LAN MAC address) as well as the WAN MAC address of the SonicWall to the portal under the Venue > Hardware tab. This is to ensure we are able to accept traffic from the device. Additionally, you'll need to set the firewall hostname (the one matching your SSL certificate as above) under the Venue > Options tab > SonicWall guest user gateway hostname heading. Without this the login will fail. |