randle Posted October 5, 2007 Posted October 5, 2007 I'm getting asked increasingly whether a student can attach their laptop to our network for internet access only. I don't like this idea at all really due to not knowing what's on their laptops but i know at some point in the future this will be a request from the headteacher. A previous company i worked at had a seperate "Dirty line" (I'm sure it was called that) that was used by customers for internet access only without giving them any access to the network. Can this be configured? Over wireless?
SteveD Posted October 5, 2007 Posted October 5, 2007 We have a dedicated wireless Vlan & filter through SchoolGuardian. We also enforce MAC authentication so the students have to bring their laptops to us before they can get on the network. We also stipulate that they must have our AV software installed which reports back to us any problems (F-Secure, not brill but free via our LEA!). As the student laptops are 'unauthenticated' they drop into the default group on Guardian which is heavily filtered. This makes the monitoring easy. There are duty of care issues which need the logging so be careful if you just tip them out through another connection. Steve
SteveD Posted October 5, 2007 Posted October 5, 2007 forgot to mention... don't rely on the wireless key for security - there are plenty of ways to lift it from one laptop and move to wherever!
spc-rocket Posted October 5, 2007 Posted October 5, 2007 Hi, We are looking at this kind of setup as well where the 6th Form students buy their own laptop and when they are in school they will be able to access the internet, their my document and our VLE. We are proposing to use a completely seperate VLAN for this and use 802.1x authentication against a RADIUS server (IAS connected to the CC3) that will then allow them to use their normal network logon to login to the wireless network. What i mean by logging on to connect to the wireless network not logging on the OS as these will be configured by them we don't want that hassle. The unmanaged wireless vlan will be connected to our firewall and web filter and will filter out web access appropriately. For us its pretty easy or easier to setup because we are already utilising the vlans in our school. HTH, Ash.
GrumbleDook Posted October 5, 2007 Posted October 5, 2007 We do not want to give them unfiltered access. We are going to be setting up a separate WLAN that only allows traffic on :443 to a single box ... the students use that to access Secure Global Desktop and then onto a TS box where they log on with their school account. It keeps everyone happy. Our system is setup by The Cutter Project and they will be explaining more at the conference
BKGarry Posted October 5, 2007 Posted October 5, 2007 In Kent we use the KCN so if they do connect with no proxy settings it goes through the Primary School Filter. Makes things a lot easier, but Students are not allowed their own laptops in due to the Electrical Testing Hazard.
plexer Posted October 5, 2007 Posted October 5, 2007 but Students are not allowed their own laptops in due to the Electrical Testing Hazard. What's that then? Ben
BKGarry Posted October 5, 2007 Posted October 5, 2007 Well Every item that is plugged into the School Electrical System should be electrically tested atleast once Per Annum for damaged and H&S risks. If a student it using their own one, any damage to power is not likely to be reported at all. Therefor a frayed cable that isn't reported is a fire risk etc etc
localzuk Posted October 5, 2007 Posted October 5, 2007 All personal equipment (which is only allowed in for things like school fair's) has to be PAT tested by our site manager before it can be used. Otherwise it is a liability.
plexer Posted October 5, 2007 Posted October 5, 2007 hmm yes I know what PAT is but the timescales as talked about in another thread seem to be personal preference. Using packetfence you'd only allow them to connect once it had been tested and presumably expire it after the year so it has to be retested? Ben
Geoff Posted October 5, 2007 Posted October 5, 2007 Using packetfence you'd only allow them to connect once it had been tested and presumably expire it after the year so it has to be retested? I suggest you skim read the FAQ http://www.packetfence.org/dokuwiki/doku.php?id=faq
Geoff Posted October 5, 2007 Posted October 5, 2007 Because the answer to your question is 'it depends'.
TechMonkey Posted October 8, 2007 Posted October 8, 2007 We have a no to staff and teachers hooking up random laptops. We have supplied 'dirty' lines to a few places, including one to our office so we can clean dodgy pcs and laptops. Rather a botch job in that we have taken the patch points straight into a mini hub which hooks into a smoothwall box that has two cards, with the second card hooking into the network with the Soothwall box pointed directly to the gateway. Ropey but works, mini network is on completely different ip range. Eventually we are going to look into rigging it into a VPN so we can choose any point around the school to be 'dirty' (ohhh, dirty line sir? Suits you) without jerry rigging spaghetti between cabs. But until then in it works.
Psymon Posted October 25, 2007 Posted October 25, 2007 We have a VLAN called guest, and an ACL (Access Control List) applied to that VLAN that ONLY ALLOWS DNS, DHCP, HTTP and HTTPS traffic. It then blocks all traffic to internal adresses apart from the firewall, and allows any other adress, so providing a website doesnt start with 10.0, they can access it, and not have any access at all to internal printers, servers etc... Works very well.
randle Posted October 25, 2007 Author Posted October 25, 2007 Thanks for the feedback guys. Unfortunately i have other projects that take priority but this has given me food for thought
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now