Jump to content

Recommended Posts

Posted
I'm getting asked increasingly whether a student can attach their laptop to our network for internet access only. I don't like this idea at all really due to not knowing what's on their laptops but i know at some point in the future this will be a request from the headteacher. A previous company i worked at had a seperate "Dirty line" (I'm sure it was called that) that was used by customers for internet access only without giving them any access to the network. Can this be configured? Over wireless?
Posted

We have a dedicated wireless Vlan & filter through SchoolGuardian. We also enforce MAC authentication so the students have to bring their laptops to us before they can get on the network. We also stipulate that they must have our AV software installed which reports back to us any problems (F-Secure, not brill but free via our LEA!). As the student laptops are 'unauthenticated' they drop into the default group on Guardian which is heavily filtered. This makes the monitoring easy. There are duty of care issues which need the logging so be careful if you just tip them out through another connection.

 

Steve

Posted

forgot to mention...

 

don't rely on the wireless key for security - there are plenty of ways to lift it from one laptop and move to wherever!

Posted

Hi,

 

We are looking at this kind of setup as well where the 6th Form students buy their own laptop and when they are in school they will be able to access the internet, their my document and our VLE.

 

We are proposing to use a completely seperate VLAN for this and use 802.1x authentication against a RADIUS server (IAS connected to the CC3) that will then allow them to use their normal network logon to login to the wireless network. What i mean by logging on to connect to the wireless network not logging on the OS as these will be configured by them we don't want that hassle.

 

The unmanaged wireless vlan will be connected to our firewall and web filter and will filter out web access appropriately.

 

For us its pretty easy or easier to setup because we are already utilising the vlans in our school.

 

HTH,

 

Ash.

Posted

We do not want to give them unfiltered access. We are going to be setting up a separate WLAN that only allows traffic on :443 to a single box ... the students use that to access Secure Global Desktop and then onto a TS box where they log on with their school account.

 

It keeps everyone happy.

 

Our system is setup by The Cutter Project and they will be explaining more at the conference

Posted

In Kent we use the KCN so if they do connect with no proxy settings it goes through the Primary School Filter.

 

Makes things a lot easier, but Students are not allowed their own laptops in due to the Electrical Testing Hazard.

Posted
Well Every item that is plugged into the School Electrical System should be electrically tested atleast once Per Annum for damaged and H&S risks. If a student it using their own one, any damage to power is not likely to be reported at all. Therefor a frayed cable that isn't reported is a fire risk etc etc
Posted
All personal equipment (which is only allowed in for things like school fair's) has to be PAT tested by our site manager before it can be used. Otherwise it is a liability.
Posted

hmm yes I know what PAT is but the timescales as talked about in another thread seem to be personal preference.

 

Using packetfence you'd only allow them to connect once it had been tested and presumably expire it after the year so it has to be retested?

 

Ben

Posted

We have a no to staff and teachers hooking up random laptops. We have supplied 'dirty' lines to a few places, including one to our office so we can clean dodgy pcs and laptops. Rather a botch job in that we have taken the patch points straight into a mini hub which hooks into a smoothwall box that has two cards, with the second card hooking into the network with the Soothwall box pointed directly to the gateway. Ropey but works, mini network is on completely different ip range.

 

Eventually we are going to look into rigging it into a VPN so we can choose any point around the school to be 'dirty' (ohhh, dirty line sir? Suits you) without jerry rigging spaghetti between cabs. But until then in it works.

  • 3 weeks later...
Posted

We have a VLAN called guest, and an ACL (Access Control List) applied to that VLAN that ONLY ALLOWS DNS, DHCP, HTTP and HTTPS traffic. It then blocks all traffic to internal adresses apart from the firewall, and allows any other adress, so providing a website doesnt start with 10.0, they can access it, and not have any access at all to internal printers, servers etc...

 

Works very well.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...