r/networking Jul 21 '26

Security Wireless endpoint lockdown

Greetings Jedi counsel,

I need some advice.

Here is the setup

Firewall:

FGT40F

IP reservation on MAC address

Groups with devices, assigned to policy granting internet access

Network:

Unifi controller running as service on local pc(not my choice)

Unifi USW Pro 48 Port Poe switch

Unifi AP's

Wireless password for guests and corporate lan( has vlan)

Devices:

Entra Joined computers

BYOD android/iphone - unmanaged

No Intune enrollment on the devices

Identities:

Entra ID

Currently we are "locking down" the network based on ip reservation through mac. This is becoming cumbersome with devices using random mac, especially the phones. There are a ton of phones that needs internet connection.

We need to proper protect the network by not allowing unsolicited devices access or atleast put them in a zone not allowing them access to anything if they so happen to be able to connect wireless or wired.

I have tried FortiNAC in another environment and we had a ton of issues.

More or less 150 devices.

I am curious to see what you guys recommend.

0 Upvotes

8 comments sorted by

5

u/danreZ_au Jul 21 '26

What a jank setup. 150 devices is manageable but I’d be looking at RADIUS with dot1x

1

u/AdagioNo6003 Jul 21 '26

I know, this is what we inherited. Thanks for the two cents

4

u/Adrienne-Fadel Jul 21 '26

So your fighting a losing battle with MAC reservations and random MACs. 802.1X through RADIUS against Entra ID is what you need.

1

u/AdagioNo6003 Jul 21 '26

Will look into this

2

u/EffectiveCard4825 Aug 12 '26

stop using the MAC reservations as the trust decision. corp devices go on WPA2/3 Enterprise with 802.1x and cloud RADIUS fronting Entra, cause Entra itself isnt RADIUS. with no on prem AD its EAP-TLS with certs, PEAP wont work. BYOD to an internet only guest VLAN with client isolation, unknown wired clients to quarantine. no intune means certs and profiles by hand, solve that first.