Jump to content

Recommended Posts

Posted

Help and Advice needed please,

 

I have just started a new technician job at a school that shall remain nameless for now, but I have inherited 2 problems that I hope someone can offer advice.

 

Problem one:

The schools wireless has been setup without any security at all, it is currently open to anyone who wants to connect. As soon as I had found this out I noticed that there are quite a few students bringing in their own devices and using them on the network. With no one checking for any virus or spyware etc. Fortunately to get out on the internet they have to supply their school username and password, so I'm hoping this is secure enough to prevent anyone from outside school actually sending illegal content or downloading inappropriate content, am I right in thinking this way. Also the schools antivirus seems to be preventing anything from attacking the schools computers but for how long.

 

Problem 2:

Some of the computers, laptops and even the switches are so old that they're not fit for purpose. The problem being though that the school bursar has had full control of the ICT equipment for such a long time that he is reluctant to let me take it over and he certainly doesn't like to spend any money on new equipment. It is painful watching the pupils and teachers struggling to use the equipment, so has anyone got any advice on how you would tackle this situation.

 

 

Any advice on either or both of the problems would be much appreciated.

 

Thanks in advance

Posted
No not new, have worked in IT for just over 10 years now. The role that I have was advertised as a technician but they know that what they are asking me to do is Network Manager. I am happy to start as technician but will be going back to them once I have a couple of things sorted, so i have evidence that I can do the job.
Posted (edited)

Hmmm...

 

1. Secure the wireless network. Find out what the school BYOD policy is (I'm guessing they don't have one), in which case bring one into play. Set-up a guest network. Find out what filtering is in place. Find out who is the ISP.

 

2. Audit the network, list when the hardware was purchased (all of it), including what warranties are in place.

 

3. Get writing a business proposal.

 

4. Keep your fingers crossed.

Edited by Mr_Jiminy
  • Thanks 1
Posted
There is no BYOD policy involved, I am currently sorting out out getting enterprise wireless installed in the next few weeks and then BYOD. My concern is can the school devices get a virus from any machine connecting to the wireless or because they aren't part of the domain are they safe. could someone connect and browse the domain, because as far as I'm aware shouldn't school data be secure and encrypted.
Posted

Sounds like you have a captive portal on your wireless network. This has its weaknesses, but is not wholly awful or unusual. Perhaps switching it to a Radius system where authentication to the wireless network itself requires the user credentials would be better suited, but different strokes.

 

For point 2, you'll need to make a case for the new equipment. Write documentation, justify and explain - don't berate. Money is tight in many schools - don't expect miracles. It's surprising the gains that can be made with a bit of thought, some second-hand hardware and careful forward planning.

  • Thanks 1
Posted

"The role that I have was advertised as a technician but they know that what they are asking me to do is Network Manager. I am happy to start as technician but will be going back to them once I have a couple of things sorted, so i have evidence that I can do the job."

 

Read some posts by abillybob to see how that usually works out :p

Posted (edited)
Sounds like you have a captive portal on your wireless network.

 

It could also be imposed using filtering by the local authority ;)

 

Doesn't sound like the in-house setup is wonderful, so I'm inclined to go with LA filtering... LightSpeed perhaps?

Edited by Mr_Jiminy
Posted

Thanks for the input everyone but, the enterprise wireless has been ordered previous to me accepting the role so it's going ahead no matter what.

 

What I really want to know is with students bringing in their own devices and connecting to the current unsecure wireless what are the chances of picking up a virus and is there any chnce a skilled user could access data on the servers.

 

Just worried that for the next few weeks we are vunerable to spyware or virus etc.

 

thank you

Posted (edited)

A virus wouldn't be high on my concern radar ;)

 

You need to give more info... What AV? What AV management? What kind of school?

 

You wouldn't need much skill to traverse across an unsecured network... Car park, laptop, ip scanner, open network shares = whole world of pain ;)

Edited by Mr_Jiminy
Posted

A device connected to your wireless network and allocated an ip address regardless of if they can then get out to the internet is an attack vector as it is connected to your internal network.

 

A virus could quite easily spread this way.

 

Ben

  • Thanks 1
Posted

I do not think the Bursar knows best than you in terms of IT, otherwise the school would not have employed you. I think, the reason he is in charge of the IT budget is due to he knows how to manage money and at that time the school did not have confidence to let the previous IT Tech to get to know much about IT budget and how much should be allocated to improve the IT network infrastructure.

 

It seems like the school did not have enough IT knowledge and decision making on IT improvement priorities otherwise they would have upgraded all network switches prior purchasing the wireless system.

 

But now you are in the job, you should convince the senior management (not the bursar) that you are capable of taking the role (because you have more than 10 years of experience).

 

Mr Jiminy advice is quite collect that you should produce some documentations to demonstrate urgent requirements on improving the school network security and network performance to meet the demand from the new wireless system that is going to be installed soon.

  • Thanks 1
Posted

I wouldn't get too hung up on the wireless network, although if that's the only real concern you have then the new one should be a positive step forward.

 

Regarding the IT budget, Bursars are strange animals and can be very reluctant to release the reigns of control when it comes to budgets. What you need to do is show her/him that you can be trusted with the money, maybe by asking to look after part of it at first.

 

Put together business cases for the areas that you think need attention, doing the most urgent ones first of course. They don't have to be complicated and there are people on here that can help if needed. Get two or three quotes together for each case that you do and take them to the SLT.

 

It's probably going to take time to get want you want, and you may not always be successful but slowly slowly catchy monkey etc 😀

  • Thanks 1
Posted

I'm not suggesting it isn't important, but he does seems to indicate that it requires a username and password to log on and there is AV in place. If the new wireless system is coming soon then it would seem pointless spending huge amounts of time on it if there are other concerns that need looking at.

 

Of course if it's completely insecure then I think I'd just turn it off until the new one turned up!

Posted (edited)

Of course if it's completely insecure then I think I'd just turn it off until the new one turned up!

 

Or secure the existing system!?

 

I'm not suggesting it isn't important, but he does seems to indicate that it requires a username and password to log on

 

Actually, the person inidcates an authentication request prompts users prior to accessing the internet, not when connecting to the network.

Edited by Mr_Jiminy

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...