Walled Garden for the Social Login

(Difference between revisions)
Jump to: navigation, search
(Undo revision 2318 by Renato.neves (talk))
Line 67: Line 67:
 
This list of IPs was generated based on the IP Address Blocks from public AS Numbers (ASN) of the following services. These ranges are very wide which can lead to security breaches or enabling unwanted services. In some cases you can restrict ranges to the ones used in your country.
 
This list of IPs was generated based on the IP Address Blocks from public AS Numbers (ASN) of the following services. These ranges are very wide which can lead to security breaches or enabling unwanted services. In some cases you can restrict ranges to the ones used in your country.
  
=== Social-ID NOW Platform ===
+
=== Social-ID Platform ===
  
Production - South America:
+
The Social-ID Platform can be used from different regions.
  
 +
Consider one of the following lists according to your Captive Portal region deployment:
 +
 +
==== Production: South America (sa-east) ====
 +
 +
18.231.0.0/16
 
  52.67.0.0/16
 
  52.67.0.0/16
 
  52.95.240.0/24
 
  52.95.240.0/24
Line 79: Line 84:
 
  177.71.128.0/17
 
  177.71.128.0/17
  
Staging - US:
+
==== Production: Europe Central (eu-central) ====
 +
 
 +
18.194.0.0/15
 +
18.196.0.0/15
 +
35.156.0.0/14
 +
52.28.0.0/15
 +
52.57.0.0/16
 +
52.58.0.0/15
 +
52.95.248.0/24
 +
52.95.255.128/28
 +
54.93.0.0/16
 +
 
 +
==== Staging: United States (us-east) ====
  
 
  198.211.103.48
 
  198.211.103.48

Revision as of 13:58, 2 June 2017

In order to enable social and traditional logins you need to configure a list of URLs that the users need to have access without being authenticated in the Wi-Fi network.

This list of URLs, called Walled Garden, can be configured based on domain names or IPs. The most effective configuration is based on domain names, once most of current social networks and applications use dynamic IPs and CDNs to deliver their services, which is very difficult to track all IPs ranges being used.

Contents

Walled Garden by domain names

Check if your vendor has full support to Walled Garden by DNS names. Some vendors accept domain names but resolve them to IP just once, which do not work for current applications using dynamic IP ranges.

The following list of domains includes the subdomains required to be whitelisted using the *. wildcard. Depending of your vendor, it may not be necessary to include the *. wildcard, adding just the domain already includes all its subdomains. Check your vendor specifications.

Social-ID NOW Platform

*.socialidnow.com

Facebook Login

*.akamaihd.net
*.facebook.com
*.facebook.net
*.fbcdn.net
facebook.com

Google+ Login

*.gstatic.com
*.googleusercontent.com
*.google.com
*.googleapis.com

Twitter Login

*.twimg.com
*.twitter.com

LinkedIn Login

*.licdn.com
*.linkedin.com

Google Analytics

*.google-analytics.com

Bypass Apple CNA

Sometimes you want to bypass the Apple CNA (Captive Network Assistant) portal. Add the following urls to disable it:

apple.com
captive.apple.com
appleiphonecell.com
ibook.info
itools.info
thinkdifferent.us

Bypass Android Captive Portal Login

Sometimes you want to bypass the Android Captive Portal Login browser. Add the following domains to disable it:

connectivitycheck.gstatic.com
connectivitycheck.android.com
clients3.google.com

Walled Garden by IP ranges

Important: the following list of IPs can change over time. You need to regularly check if new ranges were added or removed in order to keep all services working as expected. You can also inform us if any new IP range was added to a service by sending an email to support@socialidnow.com.

This list of IPs was generated based on the IP Address Blocks from public AS Numbers (ASN) of the following services. These ranges are very wide which can lead to security breaches or enabling unwanted services. In some cases you can restrict ranges to the ones used in your country.

Social-ID Platform

The Social-ID Platform can be used from different regions.

Consider one of the following lists according to your Captive Portal region deployment:

Production: South America (sa-east)

18.231.0.0/16
52.67.0.0/16
52.95.240.0/24
52.95.255.0/28
54.94.0.0/16
54.207.0.0/16
54.232.0.0/15
177.71.128.0/17

Production: Europe Central (eu-central)

18.194.0.0/15
18.196.0.0/15
35.156.0.0/14
52.28.0.0/15
52.57.0.0/16
52.58.0.0/15
52.95.248.0/24
52.95.255.128/28
54.93.0.0/16

Staging: United States (us-east)

198.211.103.48
107.170.154.155

Facebook Login

31.13.24.0/21
31.13.64.0/18
45.64.40.0/22
66.220.144.0/20
69.63.176.0/20
69.171.224.0/19
74.119.76.0/22
103.4.96.0/22
129.134.0.0/16
157.240.0.0/16
173.252.64.0/18
179.60.192.0/22
185.60.216.0/22
204.15.20.0/22

Twitter Login

8.25.194.0/23
8.25.196.0/23
69.12.56.0/21
103.252.112.0/22
104.244.40.0/21
185.45.4.0/22
188.64.224.0/21
192.44.68.0/23
192.48.236.0/23
192.133.76.0/22
199.16.156.0/22
199.59.148.0/22
199.69.58.0/23
199.96.56.0/21
202.160.128.0/22

LinkedIn Login

8.8.31.0/24
8.18.31.0/24
8.22.120.0/24
64.74.98.0/24
64.156.4.0/22
69.28.147.0/24
108.174.0.0/24
199.101.160.0/24
199.101.162.0/23
208.111.169.0/24
216.52.242.0/24
Personal tools
Namespaces
Variants
Actions
Navigation
Toolbox