g-mi wrote:hey guys.
i set up a wireless network with around 60 users, i'v been using WPA2 for authentication but the users keep sambazaring the passphrase to their pals. i now need a AAA to authenticate the clients should use Radius since i'm using a linksys router. i need help selecting a cheap or even free software for the AAA service.
You cannot use a WPA2 key to control users if your intentions is to have user management and accounting, such as an ISP, and for that reason, you are doing the right thing by seeking RADIUS.
Heard of MikroTik.com?
They produce highly customizable hardware & software for wireless and wired networks that can have full AAA with or without RADIUS. ISP's use them all over the world.
For your case, the magic will happen with their "RouterOS" software. This software runs on top of their hardware, known as "RouterBoards". You will have to choose one or multiple RouterBoard(s) for your Access Point(s), depending on they type of network that you want to deploy. You will also have to choose an enclosure for the AP (weather proof), hence the AP will be powered by their "RouterBoards". The RouterOS software can also be run from a PC.
You will get more familiar with RouterOS & RouterBoards if you go through the brouchures.
http://download.mikrotik...what_is_routerboard.pdf (21mb)
http://download.mikrotik.com/what_is_routeros.pdf (1mb)
Quoting page 32 of what_is_routerboard.pdf
"MikroTik RouterOS is the operating system of MikroTik
RouterBOARD hardware.
It has all the necessary features for an ISP - routing, firewall,
bandwidth management, wireless access point, backhaul
link, hotspot gateway, VPN server and more.
RouterOS is a stand-alone operating system based on
the Linux v2.6 kernel, and our goal here at MikroTik is
to provide all these features with a quick and simple
installation and an easy to use interface."
Quoting page 11 what_is_routeros.pdf
"The MikroTik HotSpot Gateway enables providing of public
network access for clients using wireless or wired network
connections. The user will be presented a login screen when
first opening his web browser. Once a login and password is
provided, the user will be allowed internet access."
"This is ideal for hotel, school, airport, internet cafe or any other
public place where administration doesn’t have control over the
user computer. No software installation or network configuration
is needed, hotspot will direct any connection request to the login
form."
"Extensive user management is possible by making different user
profiles, each of which can allow certain uptime, upload and
download speed limitation, transfer amount limitation and more."
"Hotspot also supports authentication against standard RADIUS
servers and MikroTik’s own User Manager which will give you a
centralized management of all users in your networks."
The setup will be able to authenticate and authorize users, control the amount of bandwidth and bandwidth speeds on a per user level. Should you want to proceed to use radius, then feel free, it can be integrated.
It was pretty sleek when I used it. Users will select the access point, it will immediately connected them to the network without the need of entering any key, but it will not allow them to browse. When a user opens the web browser, they will see a branded login screen (which you brand. See samples in page 11 of what_is_routeros.pdf). The user will need to have received the login details from the admin. If the users paid for a particular amount of time e.i. for a month @ x speed or for a particular amount of bandwidth e.i.1Gb @ x speed, the system will handle all automatically. Users will be able to login and logout as much as they need, so long as they have not depleted the resources that they purchased for their account. - Full AAA without the need of radius.
Another neat thing that can be done is to automatically give users a free demo or trial that will expire. You can setup the system to give them something like a free 20min browsing or a free 50mb when they first connect to the network. The login screen will have your details, and they will contact you when ready.
The hardware is affordable:
http://routerboard.com/
Once you have the hardware, you will need to purchase the RouterOS software license, which is also affordable:
http://wiki.mikrotik.com...:License#License_Levels
They tried to bury us, they didn't know we were seeds.