Jump to content

Recommended Posts

Posted

We are looking into whether to open up our wireless network to allow students to connect with their own devices via their standard AD credentials; this would be on an isolated wlan, on a separate vlan via our ruckus managed system. We already do this for staff though we haven't really needed to concern ourselves with the filtering on that as they get the same level of internet access as they do on a standard networked computer/laptop which isn't a problem.

 

In terms of the student devices, we're discussing how we would be filtering the internet and whether it should be an identical level of filtering they get on networked machines or a much stricter policy, perhaps even a whitelist only.

The idea, if it works out, would be to use a smoothwall box just for the student wifi wlan only which we can then have a greater degree of control over (and they would authenticate to each internet session), but it's a question of whether to retain the current network setup of having a blacklist of denied sites or saying the internet is blocked except for a list of approved sites.

 

We are wondering how other schools have done this given you lose that level of checking what is being browsed in real-time (as we can on networked machines via netsupport/rm tutor etc).

Posted
We use the SWGfL transparent proxy for our BYoD user provision (both student and staff) so they get the same filtering level on their phones/tablets as they do if they are on a network PC.
Posted
We have a BYOD portal for students and staff and they get the same filtering policies applied as they would if they were on a desktop PC. This is all done via our Ruckus/Smoothwall set up using their AD credentials. We've had it running for a couple of years now and its been fine. Not really sure why you would want to make the BYOD filtering stricter than their PC one - I think it adds an admin overhead and more complexity!
Posted (edited)

Filtering via Web Appliance same as normal network access.

 

Captive Portal for BOYD/Guest WiFi, currently being provided by Filtering appliance but soon will probably be on Firewall itself. Captive portal give us reporting via user if requested.

Edited by Davit2005
Posted

We use AD authentication on Wifi to determine which group a student is in. The Active directory group then determines which VLAN to put the student in.

The wifi controller then forwards an identification packet to the smoothwall that then puts them into the correct group for filtering. The proxy is transparent (but identified by AD) via WCCP.

 

I think this is what you want to do ?

Posted

SW here and same filtering as they get on a desktop PC.

 

If you're filtering (or whitelisting) student-owned devices more heavily, they won't bother because they'll have to swap to a school device for functional Internet access.

Posted

We use a separate wireless network on a completely separate Vlan and IP range from the main network. We then use Transparent proxying in Smoothwall and SSL login. Users login using their Active Directory credentials

and get filtered by the same policies that they would using an in house computer. Complete access and filter logs available on smoothwall.

Posted

Not Smoothwall, but our clients mostly use the same filtering settings for students whether they are on wifi or on a wired workstation (by having the device authenticate as the student's normal account - that way they still get audit logs for each user), although restricting some categories and relaxing others for some time periods is quite common (e.g. allowing social networking and tightening up porn filters outside of lesson times).

 

I think you will have real problems trying to use BYOD devices through a whitelist - Modern tablets/phones unfortunately expect to be on a fairly unrestricted connection and access a wide variety of online resources in the background during normal operation. Restricting those resources tends to cause the devices to misbehave in unexpected ways and you'll probably have to spend a great deal of time maintaining the whitelists in order to keep everyone's devices working reliably.

 

I'll also say that support for proxy servers is pretty poor on the current tablets/phones, so transparent filtering is de rigueur.

 

Guest wifi for non-student visitors (parents, contractors, etc) is often set up with some extremely light filtering (e.g. no authentication or HTTPS interception) to keep the filtering as transparent as possible so that the devices need no extra configuration.

Posted
We use a SSID provided by our Meru Controller which uses a capture page and Radius server (NPS) which transparently authenticates them against our Lightspeed proxy.
Posted
We filter them through smoothwall with transparent access identical to what they would get as students logged into a computer. Staff get the option of putting in their credentials to get a slightly less restrictive filter but most don't bother. Our filters are not very different for staff and students - basically social media

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...