Jump to content

Do you allow students personal devices on your Wifi?  

54 members have voted

  1. 1. Do you allow students personal devices on your Wifi?

    • Yes, with conditions/AUP
      12
    • Yes, with no AUP
      2
    • Nope!
      23
    • Yes, Guest SSID, with VLAN
      17


Recommended Posts

Posted

So, if a student brings their tablet/laptop to school do you allow them onto your WiFi to access the net?

 

Here all unauthenticated (IE non AD) users get forced to our proxy and asked for an AD logon, hence students get the same level of filtering regardless of device because they have to login to the proxy with their AD account.

 

But what concerns me is what happens if they do something like download a virus to their device while using our Wifi, who gets the blame? And as an extension of that, am I to blame because I put the WiFi key in? I have a policy of not touching personal devices because I have no insurance should something happen like I drop it...

 

Also, poll!

Posted

Yes.

 

We have a guest network which students are allowed to connect their devices to. It's bandwidth restricted and it only lets traffic from ports 80 and 443 through.

Posted (edited)
Yes, we do allow students on the WiFi. We have four different SSIDs and four different VLANS (Staff, Year 7, BYOD, Student). The "Student" wifi is for college owned devices used by students. Each VLAN has filtering settings appropriate for the group and has bandwidth shaping as well, so we don't require authentication, but we can track the users anyway because devices must be enrolled so we know the IP address a device has and the user of that device. We don't worry about viruses as most of our WiFi devices are iPads or Macbooks and we have four layers of malware protection (ClamX AV for Macs or Avast! for PCs, iBoss web filter (malware and phishing sites), OpenDNS (only for botnet and malware protection), and firewall gateway AV). Edited by seawolf
Posted

Yes, we have an open Wi-Fi that they still have to logon to the internet for filtering.

 

This wireless is completely off our main subnet so they can't even attempt to access certain systems.

Posted

Interesting, cheers for modifying the poll, one of the things we want to do when we get our new wireless in is to setup a guest SSID and route the traffic straight out.

 

For those of you who use some sort of control/AUP what to do you use/do?

 

Do you get the students to agree to a policy which means you aren't to blame and that they take responsibility etc? Or is it purely technical in the sense of security/vlans etc?

Posted
Interesting, cheers for modifying the poll, one of the things we want to do when we get our new wireless in is to setup a guest SSID and route the traffic straight out.

 

For those of you who use some sort of control/AUP what to do you use/do?

 

Do you get the students to agree to a policy which means you aren't to blame and that they take responsibility etc? Or is it purely technical in the sense of security/vlans etc?

 

Our AUP includes sections specifically related to the college having no responsibility or liability for damage caused by malware or loss of data whether or not it is the fault of the college (e.g. we delete a students work from the server accidentally or server crashes and backups are no good).

 

In other words, you use our network with your device - you swim at your own risk. If we deleted your data and you don't have a backup - learn to make backups. Users are about 100x more likely to get malware at home than on our network, and we have never had devices get infected on our network except by students bringing malware from home on USBs, which was sorted within a couple of days with restrictions on students opening or saving any executable files of any type on a USB or any network drives, even zip files (that they were using to run games from within the zip file to get around our restrictions). That little trick has saved sum a LOT of headaches let me tell you.

Posted

Information has to be secure, networks must be protected and users have to be monitored. However none of these are issues that can't be overcome with a bit of planning, money and time.

 

We allow sixth form students and staff to BYOD. We use firewalls, encryption and secure passwords to keep information secure, VLANs, ACLs and device segregation to protect the network, and AUPs, filtering and monitoring to keep the users safe.

 

All of which should already be set up even if you don't allow BYOD really. I think the arguments for not allowing people to use the devices they all ready own are becoming weaker by the day.

Posted (edited)

To follow on from @Norphy's answer, we require staff, not just students, to use our guest portal for BYOD devices.

 

I wouldn't entertain letting untrusted devices connect directly to the LAN via an unfiltered, unprotected wireless connection, and while I agree with irritable tech's comment about the arguments against letting people use their own devices becoming weaker, I would still stand firmly behind the idea that it's better not to do "BYOD" at all than to do it badly.

Edited by Roberto
Posted
Our AUP includes sections specifically related to the college having no responsibility or liability for damage caused by malware or loss of data whether or not it is the fault of the college (e.g. we delete a students work from the server accidentally or server crashes and backups are no good).

 

In other words, you use our network with your device - you swim at your own risk. If we deleted your data and you don't have a backup - learn to make backups. Users are about 100x more likely to get malware at home than on our network, and we have never had devices get infected on our network except by students bringing malware from home on USBs, which was sorted within a couple of days with restrictions on students opening or saving any executable files of any type on a USB or any network drives, even zip files (that they were using to run games from within the zip file to get around our restrictions). That little trick has saved sum a LOT of headaches let me tell you.

 

So I take it your AUP is one which students (and staff) are required to sign before they are given the college owned device?

 

I definitely agree with IrritableTech that BYOD stuff should be segregated and treated by default as though it is virus ridden and dodgy and kept well away from critical areas! As for staff BYOD they too would be subject to traffic VLANs and what not, the technical aspects are fairly straight forward, what I can't get my head around is how we protect ourselves/the school, from accusations of "He deleted all my photos/infected my ipad/their internet destroyed my kindle" etc...

Posted

I voted "Yes" before the "guest SSID/VLAN" option was available.

I don;t think a VLAN in itself is good enough for BYOD, it has to be firewalled from the other networks.

Posted

We don't, but that's more a pastoral decision rather than a "we can't do it" or "we have technical/security objections to it".

 

We'd push them through the same proxy that av filters everyone else and give access to a few printers, authenticated based on their AD credentials + known device and auto-kick any devices causing shenanigans.

 

Our setup would be "your device must meet $standards to connect to school Wifi, here's the (tested against a range of kids/staff) guide to connect" and we'd probably refresh the AUP (which already has "for the avoidance of doubt, any device connected to $school_network is considered part of $school_network when assessing breaches of the AUP") to be explicit about BYOD.

Posted
So I take it your AUP is one which students (and staff) are required to sign before they are given the college owned device?

/QUOTE]

 

Nope, they are presented with a "Use of the college network constitutes acceptance of our Acceptable User Policy (link) and all responsibility lies with YOU for protecting your own device and data. If these terms are not acceptable to you, please leave your device at home or turn it off while at the college" type of message when they access the network. Students know that loss of their assignments due to a technical problem will not be accepted as an excuse - welcome to the real world! Better they learn it now rather than later when mistakes have bigger consequences than in school (like being fired from a job for being irresponsible or incompetent).

Posted
So I take it your AUP is one which students (and staff) are required to sign before they are given the college owned device?

/QUOTE]

 

Nope, they are presented with a "Use of the college network constitutes acceptance of our Acceptable User Policy (link) and all responsibility lies with YOU for protecting your own device and data. If these terms are not acceptable to you, please leave your device at home or turn it off while at the college" type of message when they access the network. Students know that loss of their assignments due to a technical problem will not be accepted as an excuse - welcome to the real world! Better they learn it now rather than later when mistakes have bigger consequences than in school (like being fired from a job for being irresponsible or incompetent).

 

Gotcha, we will have to look into making a splash page for unauth'd users!

Posted
I voted "Yes" before the "guest SSID/VLAN" option was available.

I don;t think a VLAN in itself is good enough for BYOD, it has to be firewalled from the other networks.

 

And how would you achieve that without having an isolated network, which would preclude access to any network resources (servers, printers, etc.)? That would be good for a guest network or WiFi hotspot use case where only access to the Internet is required, but I can't see how that could be very useful in a school environment? Access to other VLANs can be controlled through the router if there are servers or VLANS that users should not be able to access.

Posted
And how would you achieve that without having an isolated network, which would preclude access to any network resources (servers, printers, etc.)? That would be good for a guest network or WiFi hotspot use case where only access to the Internet is required, but I can't see how that could be very useful in a school environment? Access to other VLANs can be controlled through the router if there are servers or VLANS that users should not be able to access.

 

So the way we did it was to treat the wireless network as if it is part of the internet. There is no access to internal network resources whatsoever. However, all of our learning resources are published on webservers inside the DMZ (web printing too), the students home drive and applications are spread over Google apps and Citrix terminal servers (via a web server). Students have the SAME access to their resources whether they are in school, at home, on their own device in school or in an internet cafe the other side of the planet.

Posted
Yes we allow all students to access the WiFi. We are changing the way this works this Summer. In September they will be able to access school WiFi via a transparent proxy [on a separate IP range from our network] but will still be required to authenticate via AD.
Posted
So the way we did it was to treat the wireless network as if it is part of the internet. There is no access to internal network resources whatsoever. However, all of our learning resources are published on webservers inside the DMZ (web printing too), the students home drive and applications are spread over Google apps and Citrix terminal servers (via a web server). Students have the SAME access to their resources whether they are in school, at home, on their own device in school or in an internet cafe the other side of the planet.

 

I see. You have migrated student network resources to "the cloud" a bit more than most schools, and this approach could work in that case. Two resources I see missing though is access to printing and authentication servers (AD or LDAP). How do you achieve that? Are you using Google Cloud Print and LDAP over SSL?

Posted
Students have access to just the Citrix gateway, their wifi is on its own ip range as many others here. Then running a vdi as if external the vdi will work as an internal computer :) simples.
Posted
I see. You have migrated student network resources to "the cloud" a bit more than most schools, and this approach could work in that case. Two resources I see missing though is access to printing and authentication servers (AD or LDAP). How do you achieve that? Are you using Google Cloud Print and LDAP over SSL?

 

Google apps Single Sign on. Papercut web printing (I'm hoping they'll integrate cloud print at some point). Citrix secure gateway.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...