Jump to content

Recommended Posts

Posted

Not sure with forum to stick this in as it has a bit of everything, not even sure how I'll write it up but here goes.

 

Current situation is this :-

 

Wifi is split into two vlans, one domain and one guest. The guest is transparent with no authentication, the domain has authentication via two smoothwalls.

 

Everything works great except I've now got two problems, well three if you count I've got no budget ;p

 

We have 45 staff Ipads, which connect to the guest wifi without a problem, they are managed via a mac mini server with profile manager.

 

So far so good.

 

Except I've been asked if I can get them on the same IP Range as the domain so they can start using applications like airserver / displaynote etc.

 

Okay I can do this, I can set up IDs / passwords for each Ipad and join them to the domain via a profile manager payload (PITA but doable).

 

Now this is the kicker, SLT have authorised students to bring their own I devices to lessons to participate in group application activities, however they will of course be on the wrong IP range.

 

How can I fix this without any cost or routing (I'd like to keep the vlans separate - they are vlans for a reason!)? can I send a payload to a guest device without end user interaction?

Posted

This suggestion depends a lot on how your vlans are set up and what version of Windows (I sure Windows 7 can do this) you are running, and there may be other security implications (local firewall on the Windows PC's), but here's one possible solution:

 

On the PC's running AirServer/Displaynote set up a virtual NIC, give it an IP or dhcp on your guest VLAN.

 

Now the iDevices should see those AirServers as being on the same network without having to join your domain VLAN.

  • Thanks 1
Posted
That would mean tagging every port, its a possibility, plus forgot to mention all the machines are still on XP... (so airserver is moot afaik) I am going to recommend all the machines are upgraded to 7 during the summer.
Posted
How many student devices are you expecting to have? We manually set proxy on all of our student devices, works out about 250'odd a year between the two of us.
Posted
On BYOD ? I've no idea of numbers yet - won't be a whole heap - seems a lot of work doing it that way, though I suppose once they are done they are done (although entering the network key would be interesting (how do you do that?)). The other issue with this would be lack of authentication on their devices - not a huge problem they would just have to be told to enter their domain username and password. Just trying to make this as transparent as possible!
Posted
We have some appletvs on the guest network at present, but if they were on domain they'd be a bit more flexible with displaynote / airserver (cheaper too) and similar apps, plus I'm not a huge fan of them (dropouts, picture size etc.)
Posted

Damn you! I'm going to come with a creative solution that'll work even if it's the last thing I ever do... ;)

 

How about...

 

Putting the PC's running airserver/displaynote on the guest network then setting up VPN's to your domain vlan for access to the secure stuff?

Posted
Damn you! I'm going to come with a creative solution that'll work even if it's the last thing I ever do... ;)

 

How about...

 

Putting the PC's running airserver/displaynote on the guest network then setting up VPN's to your domain vlan for access to the secure stuff?

 

Domain trusted computers on an untrusted networks, ummmmmm, eeep.

Posted
Domain trusted computers on an untrusted networks, ummmmmm, eeep.

 

Surely the devil is in the detail (aka, I can't come up with any better - can you?). I'm sure you can say the same about just about any VPN connection. The questions would be who as physical access/uses the machine(s) with the VPN connection(s), how does the VPN initiate and what does it have access to once it's connected.

 

The other answer so far is to put BYOD devices on the domain...

Posted

You can see the conundrum I'm having, I don't think there is a single answer to it. It has to be one thing or another, can't think of one easy free solution :(

 

I'm thinking raspberry pi, but rather not have a full distro of xbmc on there (plus I think it only mirrors video and audio correct me if I'm wrong)

I looked around to see if some bright spark came up with just an airplay mirroring distro - not sure if one's been done yet.

 

Got the raspberry pi working on lan via vlan no problem, but this still isn't going to help with PC apps (which is moot until they decide I can upgrade everything to windows 7)

 

Hating apple one day at a time..... :)

Posted
And now I've just had a brand new (cr)appletv taken fresh out of the box that will not connect to the wifi, no signal strength, nothing GRRRRRRRRRRRRRRRRRR
Posted
Staff IPads on the Domain IP range. Fine they are under your control so you can trust them. BYOD, no way even with NAC, accidents or maliciousness could turn your network to Swiss cheese before you knew what was going on.
Posted

What is your wireless solution? If its anything like Ruckus, make the Apple TV's be tagged from the ruckus box for the guest/staff iPad VLAN, then plug it into the network via its ethernet for the rest of the access you might want.

 

Also, not thinking of making a third VLAN for BYOD? Get DHCP to dish out appropriate proxy settings so they go through at a certain level of filtering (no auth, wouldn't be able to look at a suer level but at least they would be filtered) or rely on smoothies SSL bypass.

Posted
Its ad-hoc home made solution using off the shelf netgear wnap200s, network consists of netgear smart switches, it's far from ideal but its done the job. If I can get them to stump up some cash I'll got with ubiquiti soon at the moment its an unmanaged wifi network that I can't do a lot with without a lot of work (logging into each AP etc, tagging on switches etc) powers that be don't realise this, busy enough as it is since they got rid of the NM a few weeks ago!
Posted
Its ad-hoc home made solution using off the shelf netgear wnap200s, network consists of netgear smart switches, it's far from ideal but its done the job. If I can get them to stump up some cash I'll got with ubiquiti soon at the moment its an unmanaged wifi network that I can't do a lot with without a lot of work (logging into each AP etc, tagging on switches etc) powers that be don't realise this, busy enough as it is since they got rid of the NM a few weeks ago!

 

Woah, bit of a raw deal.

Posted (edited)
Surely the devil is in the detail (aka, I can't come up with any better - can you?). I'm sure you can say the same about just about any VPN connection. The questions would be who as physical access/uses the machine(s) with the VPN connection(s), how does the VPN initiate and what does it have access to once it's connected.

 

The other answer so far is to put BYOD devices on the domain...

 

I'd say an internal dmz for simple shared devices like the appletv but I don't think thats possible as it still uses the non-routable bonjour like they toy it is.

 

With a decent IP6 implementation this may be possible, I don't know if Apple have fixed their ip6 stack yet.

 

The closest to a remotely secure way would be to have the ipads vpn internally to a dmz where the resources are, putting them on the same subnet and using the vpn system to screen out all but the required traffic.

Edited by SYNACK
Posted

Funding must be aligned with ambition.

 

I like what your school is trying to achieve however I'd have to ask the question "how many byod devices, in reality, are going to be sharing with the projector in a room?" If the answer is loads, you need some investment to realise the learning potential. If the answer is one or two every now and then...

 

I'd suggest pupil owned devices sharing to whiteboards will get limited use, and any BYOD scheme should be device agnostic. Before you can successfully access the learning potential of BYOD, you need to get your infrastructure sorted.

 

It's Bring Your Own Device, not Bring Your Own Apple. I actually prefer Prof Stephen Heppell's term "Bring a Browser". Students could collaborate on Google Docs using their own devices (not just apples), and easily show their work from the windows pc at the front of class. Dropbox, wallwisher, evernote, sketch, prezi etc.... all browser tools. That's where a BYOD scheme really starts to take off.

 

I'd separate the two schemes. iPads for teachers is a very different scheme to pupils bringing in devices.

 

For more thoughts on BYOD in schools, take a look at my blog. This is a good starting point... BYOD: Wifi, Network, Internet, Proxies | IrritableTech

Posted

I totally agree, however it's SLT decision not mine - personally I'd get the infrastructure sorted first - but no one is listening. SLT are very apple centric, and very quick to jump in regardless of infrastructure, I've just read the half term letter about byod and it only mentions apple, we recently advertised a job for an Ipad technician...

Don't get me wrong I'm not against this idea at all just under pressure to deliver what I can't do with no budget!

Projectors aren't totally important to this, even though they do need replacing badly, apps like Socrates are generating a lot of interest here.

 

Anyway that's veered ever so slightly off topic ;p

 

So basically without chew it can't really be done - I'll recommend against any domain joining (which is what I told them in the first place!)

Posted

Thrashed out a possible working idea,

Move all teaching machines to the guest vlan, it's a tonne of work and a there's few kinks to work out but might just be a possibility.

Posted

You need to have a good sit down with the SLT. If you start messing about too much you might start to compromise sensitive data just to get an iPad working.

 

Should direct them this way, see what all of us have said about what you're trying to do ;)

Posted

Indeed but I don't get much choice in the matter, i'm employed to come up with solutions :) cheaper the better!, but plan is to move all teacher / classroom pc's off the main domain (the MIS is cloud based anyway).

Plan :-

Have domain only for resources and support / admin.

mail / teacher resources / home drives will eventually be all on gapps soon hopefully.

So classroom pc's will have no logon to domain options - just a standalone pc that can connect to the internet.

I've got a lot of work ahead of me it seems ! But this seems the only way, especially seeing SLT want rid of desktops from the classroom eventually.

Maybe this is the future?

 

Just weighing up pros and cons now.

Posted
Remember to keep an eye on licensing with BYOD. such things aren't covered by the standard EES (but there *is* a student option). Not that this should be a problem with all Apple stuff! As long as you aren't using dhcp, dns or AD credentials, windows file servers etc.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...