Jump to content

Recommended Posts

Posted
Can I ask what the difference in terms of access/use between the key and the Radius was? Was it like a two step authentication, or more lock down on filtering? What did they object to? Or did they just object because it wasn't what it used to be?
Posted
Level of complexity that our staff won't stomach. We tried it, along with a captive portal that gave them the correct level of filtering based on their AD credentials (which should have been a massive bonus) they decided we were deliberately trying to be difficult. The feedback was 'we want it to work like it does at home' so preshared key it was...

 

I had some whinging along those lines here, and told them it was tough luck - we found a need to be able to pinpoint what anyone was doing on any web connected device in the school, so individual logins are mandatory.

Posted
Level of complexity that our staff won't stomach. The feedback was 'we want it to work like it does at home' so preshared key it was...

 

Are you sure you don't work here and how come we've never met?

Posted

We've come up with a reasonably happy medium here using the ruckus Dynamic Pre Shared Key system.

 

Each user has to authenticate every couple of weeks and they receive their own 64 character wifi password, after that it works like it does at home until it expires. From our point of view each device is authenticated to a user and we can filter appropriately, from their point of view, they don't have to authenticate every hour or day.

 

If I didn't use Ruckus or have another solution with a similar feature, I'd have to insist on WPA2-Enterprise/Radius here. Otherwise all your users traffic encryption key is the same and therefore useless.

  • Thanks 1
Posted
Can I ask what the difference in terms of access/use between the key and the Radius was? Was it like a two step authentication, or more lock down on filtering? What did they object to? Or did they just object because it wasn't what it used to be?

 

They came to us, we recorded the mac address, entered into the mac filtering and installed a certificate, The device was then allowed onto the network and when a browser was opened a pretty page was shown asking for username and password, they entered it, the system backed off and let them do anything they were allowed to do by the filtering.

 

They didn't like the certificate process, they got jittery about us installing stuff they didn't understand (read:didn't want to understand) then they didn't like the captive portal as they felt it was intrusive as it overrode their homepage.

  • Thanks 1
Posted

Captive portals do cause issues on smartphones and tablets. Users hate having to open up their browser to authenticate before an app can be used.

 

If you want to invite the devices onto the network, you have to make them usable - over complicating matters unfortunately puts barriers in the way of the original brief. Finding the happy medium is tough.

Posted
Captive portals do cause issues on smartphones and tablets. Users hate having to open up their browser to authenticate before an app can be used.

 

If you want to invite the devices onto the network, you have to make them usable - over complicating matters unfortunately puts barriers in the way of the original brief. Finding the happy medium is tough.

 

Having to open a browser before using an app is not a dreadful hardship. Much like logging in to a desktop PC before using Word isn't.

Posted
Having to open a browser before using an app is not a dreadful hardship. Much like logging in to a desktop PC before using Word isn't.

 

I largely agree, but found the average end user didn't follow our mind set. I do believe however that we need to put in place as many solutions as possible to make a project a success for the learners - whilst ensuring regulations, legislation and laws are still respected.

Posted
Captive portals do cause issues on smartphones and tablets. Users hate having to open up their browser to authenticate before an app can be used.

 

If you want to invite the devices onto the network, you have to make them usable - over complicating matters unfortunately puts barriers in the way of the original brief. Finding the happy medium is tough.

 

We offered them a 'without captive portal' option in the consultation which would give them a general set of restriction at the firewall, they decided they didn't want the restrictions, then after half a term of grumbling about what they'd asked for, they decided they didn't want the means of working round the restrictions - so now they have the general restrictions, but otherwise it works like it does at home. Go Figure. The students adapted fine and were actually a bit miffed that we took the portal away.

Posted
I totally understand and agree, but when you get the kind of backlash we've had, you do just go 'whatever' and go back to what you were doing before.

 

If they were on the main network I'd be less inclined to roll over about it, but when it's a separate network and they are using essentially external tools (ePortal/HAP) to access things, to me it's not really any different from them using the tools at home.

 

No criticism intended btw - I know exactly where you are coming.

 

Radius for us is part of the same ruckus setup that does dpsk that irritable tech mentioned, its reasonably smooth and we have the promise of shiny apps and services staff we can entice them with when they play ball :)

Posted

For those using pre shared keys and saying only IT know the key, you do know there are lots of tools out there that can recover the key once its on a system??? usually the tools require admin rights which all users shouldn't have but with it being there personal device then they will probably have admin rights. so my question is how do you stop this??

 

To the original question we have a separate SSID with a captive web portal which uses AD for authentication, this puts the users on a separate vlan with ACL's and then our firewall also filters traffic and only allows some ports out.

For email we run exchange 2010, we only allow SSL connections to the server and if the user wants to connect there phone they are required to encrypt there device and setup a passcode.

Posted

On a note about personal mobile devices being used to access emails, etc ...

 

Within your AUP you must point out that these devices must be encrypted, secured with a complex passphrase (4 digit pass code or being able to follow a greasy, sliding trail on the screen is *not* good security) and, where possible, set to autowipe after x failed attempts to log in.

 

Staff should give permission for routine checks to see that this is in place on personal devices, and should it not be then that device will be blocked from accessing the service.

 

These are the *reasonable* technical and organisational measures that can be put in place to protect data (DPA principle 7).

 

If staff don't like the IT staff doing checks then you increase the technical measures (VDI, etc) but the school accepts that this increases the capital and operational costs of the service.

Posted
Within your AUP you must point out that these devices must be encrypted, secured with a complex passphrase (4 digit pass code or being able to follow a greasy, sliding trail on the screen is *not* good security) and, where possible, set to autowipe after x failed attempts to log in.

 

You don't even need it in the AUP.

 

You can set security rules in O365 if they're adding it to mobile devices. [iIRC]

Posted
You don't even need it in the AUP.

 

You can set security rules in O365 if they're adding it to mobile devices. [iIRC]

 

You *do* need it in the AUP as you are keeping staff informed, gaining their acceptance and understanding of how and why things are set up in a particular way. If you don't include things like this you are not helping yourself or the school.

 

It is not *all* about the technology, but also about the education of users ... oh, and PR too.

Posted
This is a very handy post, although working in primary schools with very basic filtering etc makes BYOD much harder to implement. I have noticed remote wipe / policy pushing to devices in the Google apps for Education admin panel but have never played with it, something I will now rectify.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...