dgsmith Posted May 15, 2015 Posted May 15, 2015 We are looking into whether to open up our wireless network to allow students to connect with their own devices via their standard AD credentials; this would be on an isolated wlan, on a separate vlan via our ruckus managed system. We already do this for staff though we haven't really needed to concern ourselves with the filtering on that as they get the same level of internet access as they do on a standard networked computer/laptop which isn't a problem. In terms of the student devices, we're discussing how we would be filtering the internet and whether it should be an identical level of filtering they get on networked machines or a much stricter policy, perhaps even a whitelist only. The idea, if it works out, would be to use a smoothwall box just for the student wifi wlan only which we can then have a greater degree of control over (and they would authenticate to each internet session), but it's a question of whether to retain the current network setup of having a blacklist of denied sites or saying the internet is blocked except for a list of approved sites. We are wondering how other schools have done this given you lose that level of checking what is being browsed in real-time (as we can on networked machines via netsupport/rm tutor etc).
chazzy2501 Posted May 15, 2015 Posted May 15, 2015 you could use opendns they have a parental filter service (family shield) you'd just have to issue new dns settings via dhcp.
Boredguy Posted May 15, 2015 Posted May 15, 2015 We use the SWGfL transparent proxy for our BYoD user provision (both student and staff) so they get the same filtering level on their phones/tablets as they do if they are on a network PC.
truebluesteve Posted May 15, 2015 Posted May 15, 2015 We have a BYOD portal for students and staff and they get the same filtering policies applied as they would if they were on a desktop PC. This is all done via our Ruckus/Smoothwall set up using their AD credentials. We've had it running for a couple of years now and its been fine. Not really sure why you would want to make the BYOD filtering stricter than their PC one - I think it adds an admin overhead and more complexity!
Davit2005 Posted May 15, 2015 Posted May 15, 2015 (edited) Filtering via Web Appliance same as normal network access. Captive Portal for BOYD/Guest WiFi, currently being provided by Filtering appliance but soon will probably be on Firewall itself. Captive portal give us reporting via user if requested. Edited May 15, 2015 by Davit2005
mjk Posted May 15, 2015 Posted May 15, 2015 We use AD authentication on Wifi to determine which group a student is in. The Active directory group then determines which VLAN to put the student in. The wifi controller then forwards an identification packet to the smoothwall that then puts them into the correct group for filtering. The proxy is transparent (but identified by AD) via WCCP. I think this is what you want to do ?
pete Posted May 15, 2015 Posted May 15, 2015 SW here and same filtering as they get on a desktop PC. If you're filtering (or whitelisting) student-owned devices more heavily, they won't bother because they'll have to swap to a school device for functional Internet access.
alfatec Posted May 15, 2015 Posted May 15, 2015 We use a separate wireless network on a completely separate Vlan and IP range from the main network. We then use Transparent proxying in Smoothwall and SSL login. Users login using their Active Directory credentials and get filtered by the same policies that they would using an in house computer. Complete access and filter logs available on smoothwall.
Opendium_Steve Posted May 19, 2015 Posted May 19, 2015 Not Smoothwall, but our clients mostly use the same filtering settings for students whether they are on wifi or on a wired workstation (by having the device authenticate as the student's normal account - that way they still get audit logs for each user), although restricting some categories and relaxing others for some time periods is quite common (e.g. allowing social networking and tightening up porn filters outside of lesson times). I think you will have real problems trying to use BYOD devices through a whitelist - Modern tablets/phones unfortunately expect to be on a fairly unrestricted connection and access a wide variety of online resources in the background during normal operation. Restricting those resources tends to cause the devices to misbehave in unexpected ways and you'll probably have to spend a great deal of time maintaining the whitelists in order to keep everyone's devices working reliably. I'll also say that support for proxy servers is pretty poor on the current tablets/phones, so transparent filtering is de rigueur. Guest wifi for non-student visitors (parents, contractors, etc) is often set up with some extremely light filtering (e.g. no authentication or HTTPS interception) to keep the filtering as transparent as possible so that the devices need no extra configuration.
tekins Posted May 19, 2015 Posted May 19, 2015 We have 2 SSID's one open for all on student level filtering, one secured that is on Staff level filtering, works well.
RobD Posted May 19, 2015 Posted May 19, 2015 We use a SSID provided by our Meru Controller which uses a capture page and Radius server (NPS) which transparently authenticates them against our Lightspeed proxy.
Sagima Posted May 19, 2015 Posted May 19, 2015 We filter them through smoothwall with transparent access identical to what they would get as students logged into a computer. Staff get the option of putting in their credentials to get a slightly less restrictive filter but most don't bother. Our filters are not very different for staff and students - basically social media
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now