kerryturner Posted June 13, 2014 Posted June 13, 2014 My apologies if this has already been posted and answered elsewhere on here. I trawled the forums and struggled to find anything. Essentially, more and more staff are wanting to use their personal devices on the school network. It stands to reason that if tablets and phones can connect to a filtered wireless connection, so could laptops. This then leads to staff being able to type in a file path to their network documents, bringing about a potential risk. Should I be less worried about IOS devices and more concerned about Android/others? What do others do about foreign devices on their networks? Has anyone set up a Sophos UTM? Perhaps we should be looking at a VDI solution? (Sounds expensive.) Also, school email access on personal phones, iPads? Seems a bit of a data protection risk if the device can't be wiped if lost, stolen or sold on? Or am I over thinking this? Sorry if all of this seems really simple. I'd appreciate responses.
fairm010 Posted June 13, 2014 Posted June 13, 2014 We allow personal devices but they are fully audited for firewall / AV / etc before being allowed on the network. No one but IT know the encryption key. We also get staff to sign a disclaimer waiving any damage to the device and they are held accountable for any network breaches via their device. 1
hardtailstar Posted June 13, 2014 Posted June 13, 2014 I dont allow it. Purely because they get given a laptop for School work 2
kerryturner Posted June 13, 2014 Author Posted June 13, 2014 Much appreciated! This sounds like a simple solution. I found another thread about this - once I'd posted this and the AUP seems to be important too. It was the emails on phones thing which had me worried.
kerryturner Posted June 13, 2014 Author Posted June 13, 2014 Fair point! Thank you. I think its more the phones/iPads which I'm concerned about. We also have assistants who are often in on a short turn around and they aren't issued with laptops.
fairm010 Posted June 13, 2014 Posted June 13, 2014 We offer RDS / HAP+ so that even those without school hardware can work remotely. We allow school email on phones ONLY if they consent to having the Meraki app installed so that in the event of loss we can wipe. 1
kerryturner Posted June 13, 2014 Author Posted June 13, 2014 We offer RDS / HAP+ so that even those without school hardware can work remotely. We allow school email on phones ONLY if they consent to having the Meraki app installed so that in the event of loss we can wipe. Thanks again!
Dos_Box Posted June 13, 2014 Posted June 13, 2014 My apologies if this has already been posted and answered elsewhere on here. I trawled the forums and struggled to find anything. Essentially, more and more staff are wanting to use their personal devices on the school network. It stands to reason that if tablets and phones can connect to a filtered wireless connection, so could laptops. This then leads to staff being able to type in a file path to their network documents, bringing about a potential risk. Should I be less worried about IOS devices and more concerned about Android/others? What do others do about foreign devices on their networks? Has anyone set up a Sophos UTM? Perhaps we should be looking at a VDI solution? (Sounds expensive.) Also, school email access on personal phones, iPads? Seems a bit of a data protection risk if the device can't be wiped if lost, stolen or sold on? Or am I over thinking this? Sorry if all of this seems really simple. I'd appreciate responses. The technical term is Bring Your own Device or BYOD as it's more commonly known. If you search for that you will find a lot more topics on this especially in the Wireless and Netbooks, PDA and Phones forum.
kerryturner Posted June 13, 2014 Author Posted June 13, 2014 The technical term is Bring Your own Device or BYOD as it's more commonly known. If you search for that you will find a lot more topics on this especially in the Wireless and Netbooks, PDA and Phones forum. Thanks. Will look - had always thought BYOD referred to student devices not staff, but it makes sense to look there too.
HarryMonkey Posted June 13, 2014 Posted June 13, 2014 Staff are allowed to put their own devices on using the BYOD network. It gives filtered access to the Internet as well as any apps that they have installed. If they decide to pick up their email from the Exchange server then they are required to put a pin lock on their device. It's mainly tablets and phones, very few bring laptops in as all staff are issued with a school laptop.
RobD Posted June 13, 2014 Posted June 13, 2014 We allow personal devices on the wifi but apply a load of ACL's so they can only get to the internet on port 80 and 443. They also have to authenticate against our proxy!
IrritableTech Posted June 13, 2014 Posted June 13, 2014 Hi @kerryturner. You're asking all the right questions. Some can be answered using technology, other risks mitigated through policy. Some risks will remain but might be outweighed by advantages. If you are going to put BYOD devices on your network you are best off separating these devices from your normal network. Your smoothwall can definitely help here, but you'll need to consider the capabilities of your switches and your wireless network here too. Generally I'd advise putting these devices in another VLAN. Adding a suitable access list to the vlan will help keep these devices from accessing your server too. If you're worried about your server security though, this is something you need to look into anyway... If a teacher brought in their laptop now and unplugged their classroom PC, they'd potentially have the same network access and administrator rights on their machine. In places where this happens regularly, a well managed BYOD scheme can help improve security! Some schools have gone down the VDI route - I think it depends on what you want your users to access and where the curriculum is heading. Much of our curriculum is heading towards web technology. We're trying to be device agnostic in our BYOD scheme, so everything can be served through the browser. It's cheaper generally too! School email on phones/tablets should really be covered under policies. I think it would be obstructive to disallow it, but you should be putting safeguards in place - devices must be pin protected, loss must be reported etc. You could put a restriction on how much mail can be cached, to reduce the data loss risk. A further note I'd add is around your core infrastructure and your internet connection. Is it up to the job of another 30-50-100-1000 devices jumping on it? I've blogged a bit about BYOD on my site. Feel free to have a look.
kerryturner Posted June 13, 2014 Author Posted June 13, 2014 Hi @kerryturner. I've blogged a bit about BYOD on my site. Feel free to have a look. Thanks for all of these replies. IrritableTech - I follow you on twitter, so I'll take another look at your blog. (@4goggas)
Oaktech Posted June 13, 2014 Posted June 13, 2014 separate wireless network on VLan with no route to the main network, IP provided by firewall. Every device registered for MAC filtering, horrifically complex 26 digit hex key jealously guarded..
DrPerceptron Posted June 13, 2014 Posted June 13, 2014 (edited) If you're thinking about allowing staff laptops etc onto your network - have a think about: Network Policy and Access Services You can then look at making sure that stuff connected to your network has at least working anti-virus, firewalls and a minimum windows update level etc. Edited June 13, 2014 by DrPerceptron
Oaktech Posted June 13, 2014 Posted June 13, 2014 We say the following: this is on the top of the sheet that records username, mac address and signature I understand that by requesting and receiving access to, and using, the <> wireless network that I have agreed to not disclose the access key to any other person; student, teacher or visitor. I will direct all requests for this information to the IT Department. I further agree that I will not disclose any other information about the colleges network, such as server addresses, IP schemes or proxy details, that I may have access to as a result of receiving wireless access. By signing this document I also confirm that my device has appropriate and up to date firewall, antivirus and system updates. I undertake to ensure that this protection will continue for the duration of my use of this wireless network I am aware that wireless access is a privilege, that it is filtered for my safety and that it's use will be monitored, and that the privilege can be withdrawn at any time.
Quackers Posted June 13, 2014 Posted June 13, 2014 We just have a separate VLAN for the guest WiFi, on a separate SSID with a captive portal on Ruckus. Any staff member can connect their personal phones, tablets to it and login using their Active Directory login for our domain, or we can generate a guest pass. That way if there is something nasty it won't touch the main network, and we also have Fortigate checking all traffic on the separate VLAN for malware/viruses so we can see if something with an infection is on.
elsiegee40 Posted June 13, 2014 Posted June 13, 2014 School devices only on the curriculum network. Staff are only allowed to put their personal devices on the Guest network.
iom100 Posted June 13, 2014 Posted June 13, 2014 I'm curious about organisations who are using a single preshared key for wireless. Why do you do this when things like WPA 802.11x RADIUS authenticating against AD are available?
Oaktech Posted June 13, 2014 Posted June 13, 2014 I'm curious about organisations who are using a single preshared key for wireless. Why do you do this when things like WPA 802.11x RADIUS authenticating against AD are available? Level of complexity that our staff won't stomach. We tried it, along with a captive portal that gave them the correct level of filtering based on their AD credentials (which should have been a massive bonus) they decided we were deliberately trying to be difficult. The feedback was 'we want it to work like it does at home' so preshared key it was...
kerryturner Posted June 13, 2014 Author Posted June 13, 2014 We say the following: this is on the top of the sheet that records username, mac address and signature That's very useful = thanks.
kerryturner Posted June 13, 2014 Author Posted June 13, 2014 (edited) ...so preshared key it was... That's interesting , we're looking at Radius at the moment. Edited June 13, 2014 by kerryturner
Oaktech Posted June 13, 2014 Posted June 13, 2014 That's interesting , we're looking at Raduis at the moment. I wouldn't discount it untill you've tried it, we have some proper luddites!
Jasbo Posted June 13, 2014 Posted June 13, 2014 Similar to those above in separating byod access from the internal network except for pointing out to them they are not at home, they are working at a school dealing with confidential information about children and they should be looking for my replacement if they want a network like at home, I have visited some teachers homes (cough) usually to clean up the viruses from all 3 computers (cough) and would certainly not be plugging anything of mine into their home networks, so radius and ad based access it is...
Oaktech Posted June 13, 2014 Posted June 13, 2014 Similar to those above in separating byod access from the internal network except for pointing out to them they are not at home, they are working at a school dealing with confidential information about children and they should be looking for my replacement if they want a network like at home, I have visited some teachers homes (cough) usually to clean up the viruses from all 3 computers (cough) and would certainly not be plugging anything of mine into their home networks, so radius and ad based access it is... I totally understand and agree, but when you get the kind of backlash we've had, you do just go 'whatever' and go back to what you were doing before. If they were on the main network I'd be less inclined to roll over about it, but when it's a separate network and they are using essentially external tools (ePortal/HAP) to access things, to me it's not really any different from them using the tools at home.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now