caffrey Posted February 12, 2013 Posted February 12, 2013 Not sure with forum to stick this in as it has a bit of everything, not even sure how I'll write it up but here goes. Current situation is this :- Wifi is split into two vlans, one domain and one guest. The guest is transparent with no authentication, the domain has authentication via two smoothwalls. Everything works great except I've now got two problems, well three if you count I've got no budget ;p We have 45 staff Ipads, which connect to the guest wifi without a problem, they are managed via a mac mini server with profile manager. So far so good. Except I've been asked if I can get them on the same IP Range as the domain so they can start using applications like airserver / displaynote etc. Okay I can do this, I can set up IDs / passwords for each Ipad and join them to the domain via a profile manager payload (PITA but doable). Now this is the kicker, SLT have authorised students to bring their own I devices to lessons to participate in group application activities, however they will of course be on the wrong IP range. How can I fix this without any cost or routing (I'd like to keep the vlans separate - they are vlans for a reason!)? can I send a payload to a guest device without end user interaction?
tmcd35 Posted February 12, 2013 Posted February 12, 2013 This suggestion depends a lot on how your vlans are set up and what version of Windows (I sure Windows 7 can do this) you are running, and there may be other security implications (local firewall on the Windows PC's), but here's one possible solution: On the PC's running AirServer/Displaynote set up a virtual NIC, give it an IP or dhcp on your guest VLAN. Now the iDevices should see those AirServers as being on the same network without having to join your domain VLAN. 1
caffrey Posted February 12, 2013 Author Posted February 12, 2013 That would mean tagging every port, its a possibility, plus forgot to mention all the machines are still on XP... (so airserver is moot afaik) I am going to recommend all the machines are upgraded to 7 during the summer.
Danp Posted February 12, 2013 Posted February 12, 2013 How many student devices are you expecting to have? We manually set proxy on all of our student devices, works out about 250'odd a year between the two of us.
caffrey Posted February 12, 2013 Author Posted February 12, 2013 On BYOD ? I've no idea of numbers yet - won't be a whole heap - seems a lot of work doing it that way, though I suppose once they are done they are done (although entering the network key would be interesting (how do you do that?)). The other issue with this would be lack of authentication on their devices - not a huge problem they would just have to be told to enter their domain username and password. Just trying to make this as transparent as possible!
tmcd35 Posted February 12, 2013 Posted February 12, 2013 What about suggesting SLT buy some AppleTV's for the guest lan rather than allowing unsecure devices on to the domain lan?
caffrey Posted February 12, 2013 Author Posted February 12, 2013 We have some appletvs on the guest network at present, but if they were on domain they'd be a bit more flexible with displaynote / airserver (cheaper too) and similar apps, plus I'm not a huge fan of them (dropouts, picture size etc.)
tmcd35 Posted February 12, 2013 Posted February 12, 2013 Damn you! I'm going to come with a creative solution that'll work even if it's the last thing I ever do... How about... Putting the PC's running airserver/displaynote on the guest network then setting up VPN's to your domain vlan for access to the secure stuff?
SYNACK Posted February 12, 2013 Posted February 12, 2013 Damn you! I'm going to come with a creative solution that'll work even if it's the last thing I ever do... How about... Putting the PC's running airserver/displaynote on the guest network then setting up VPN's to your domain vlan for access to the secure stuff? Domain trusted computers on an untrusted networks, ummmmmm, eeep.
tmcd35 Posted February 12, 2013 Posted February 12, 2013 Domain trusted computers on an untrusted networks, ummmmmm, eeep. Surely the devil is in the detail (aka, I can't come up with any better - can you?). I'm sure you can say the same about just about any VPN connection. The questions would be who as physical access/uses the machine(s) with the VPN connection(s), how does the VPN initiate and what does it have access to once it's connected. The other answer so far is to put BYOD devices on the domain...
plexer Posted February 12, 2013 Posted February 12, 2013 Surely the answer is.......Rasberry Pi???? No? Ok then. Ben
caffrey Posted February 12, 2013 Author Posted February 12, 2013 You can see the conundrum I'm having, I don't think there is a single answer to it. It has to be one thing or another, can't think of one easy free solution I'm thinking raspberry pi, but rather not have a full distro of xbmc on there (plus I think it only mirrors video and audio correct me if I'm wrong) I looked around to see if some bright spark came up with just an airplay mirroring distro - not sure if one's been done yet. Got the raspberry pi working on lan via vlan no problem, but this still isn't going to help with PC apps (which is moot until they decide I can upgrade everything to windows 7) Hating apple one day at a time.....
caffrey Posted February 12, 2013 Author Posted February 12, 2013 And now I've just had a brand new (cr)appletv taken fresh out of the box that will not connect to the wifi, no signal strength, nothing GRRRRRRRRRRRRRRRRRR
SHimmer45 Posted February 12, 2013 Posted February 12, 2013 with apple TV's found it easier to activate them at home.......... (i didnt thank god)
Geoff Posted February 12, 2013 Posted February 12, 2013 Staff IPads on the Domain IP range. Fine they are under your control so you can trust them. BYOD, no way even with NAC, accidents or maliciousness could turn your network to Swiss cheese before you knew what was going on.
Tsonga Posted February 12, 2013 Posted February 12, 2013 What is your wireless solution? If its anything like Ruckus, make the Apple TV's be tagged from the ruckus box for the guest/staff iPad VLAN, then plug it into the network via its ethernet for the rest of the access you might want. Also, not thinking of making a third VLAN for BYOD? Get DHCP to dish out appropriate proxy settings so they go through at a certain level of filtering (no auth, wouldn't be able to look at a suer level but at least they would be filtered) or rely on smoothies SSL bypass.
caffrey Posted February 12, 2013 Author Posted February 12, 2013 Its ad-hoc home made solution using off the shelf netgear wnap200s, network consists of netgear smart switches, it's far from ideal but its done the job. If I can get them to stump up some cash I'll got with ubiquiti soon at the moment its an unmanaged wifi network that I can't do a lot with without a lot of work (logging into each AP etc, tagging on switches etc) powers that be don't realise this, busy enough as it is since they got rid of the NM a few weeks ago!
Tsonga Posted February 12, 2013 Posted February 12, 2013 Its ad-hoc home made solution using off the shelf netgear wnap200s, network consists of netgear smart switches, it's far from ideal but its done the job. If I can get them to stump up some cash I'll got with ubiquiti soon at the moment its an unmanaged wifi network that I can't do a lot with without a lot of work (logging into each AP etc, tagging on switches etc) powers that be don't realise this, busy enough as it is since they got rid of the NM a few weeks ago! Woah, bit of a raw deal.
SYNACK Posted February 12, 2013 Posted February 12, 2013 (edited) Surely the devil is in the detail (aka, I can't come up with any better - can you?). I'm sure you can say the same about just about any VPN connection. The questions would be who as physical access/uses the machine(s) with the VPN connection(s), how does the VPN initiate and what does it have access to once it's connected. The other answer so far is to put BYOD devices on the domain... I'd say an internal dmz for simple shared devices like the appletv but I don't think thats possible as it still uses the non-routable bonjour like they toy it is. With a decent IP6 implementation this may be possible, I don't know if Apple have fixed their ip6 stack yet. The closest to a remotely secure way would be to have the ipads vpn internally to a dmz where the resources are, putting them on the same subnet and using the vpn system to screen out all but the required traffic. Edited February 12, 2013 by SYNACK
IrritableTech Posted February 12, 2013 Posted February 12, 2013 Funding must be aligned with ambition. I like what your school is trying to achieve however I'd have to ask the question "how many byod devices, in reality, are going to be sharing with the projector in a room?" If the answer is loads, you need some investment to realise the learning potential. If the answer is one or two every now and then... I'd suggest pupil owned devices sharing to whiteboards will get limited use, and any BYOD scheme should be device agnostic. Before you can successfully access the learning potential of BYOD, you need to get your infrastructure sorted. It's Bring Your Own Device, not Bring Your Own Apple. I actually prefer Prof Stephen Heppell's term "Bring a Browser". Students could collaborate on Google Docs using their own devices (not just apples), and easily show their work from the windows pc at the front of class. Dropbox, wallwisher, evernote, sketch, prezi etc.... all browser tools. That's where a BYOD scheme really starts to take off. I'd separate the two schemes. iPads for teachers is a very different scheme to pupils bringing in devices. For more thoughts on BYOD in schools, take a look at my blog. This is a good starting point... BYOD: Wifi, Network, Internet, Proxies | IrritableTech
caffrey Posted February 12, 2013 Author Posted February 12, 2013 I totally agree, however it's SLT decision not mine - personally I'd get the infrastructure sorted first - but no one is listening. SLT are very apple centric, and very quick to jump in regardless of infrastructure, I've just read the half term letter about byod and it only mentions apple, we recently advertised a job for an Ipad technician... Don't get me wrong I'm not against this idea at all just under pressure to deliver what I can't do with no budget! Projectors aren't totally important to this, even though they do need replacing badly, apps like Socrates are generating a lot of interest here. Anyway that's veered ever so slightly off topic ;p So basically without chew it can't really be done - I'll recommend against any domain joining (which is what I told them in the first place!)
caffrey Posted February 13, 2013 Author Posted February 13, 2013 Thrashed out a possible working idea, Move all teaching machines to the guest vlan, it's a tonne of work and a there's few kinks to work out but might just be a possibility.
Tsonga Posted February 13, 2013 Posted February 13, 2013 You need to have a good sit down with the SLT. If you start messing about too much you might start to compromise sensitive data just to get an iPad working. Should direct them this way, see what all of us have said about what you're trying to do
caffrey Posted February 13, 2013 Author Posted February 13, 2013 Indeed but I don't get much choice in the matter, i'm employed to come up with solutions cheaper the better!, but plan is to move all teacher / classroom pc's off the main domain (the MIS is cloud based anyway). Plan :- Have domain only for resources and support / admin. mail / teacher resources / home drives will eventually be all on gapps soon hopefully. So classroom pc's will have no logon to domain options - just a standalone pc that can connect to the internet. I've got a lot of work ahead of me it seems ! But this seems the only way, especially seeing SLT want rid of desktops from the classroom eventually. Maybe this is the future? Just weighing up pros and cons now.
DMcCoy Posted February 13, 2013 Posted February 13, 2013 Remember to keep an eye on licensing with BYOD. such things aren't covered by the standard EES (but there *is* a student option). Not that this should be a problem with all Apple stuff! As long as you aren't using dhcp, dns or AD credentials, windows file servers etc.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now