Jump to content

Recommended Posts

Posted

Hi,

 

At my company, I have been set a task of possibly allowing our staff to bring their own devices. We have wireless already which they can connect to, but my real questions are... Do you guys allow staff to bring their own devices? And also, Do you use any special programs or features for this?

 

 

I'd appreciate any response given.

 

Thanks!

Posted
We use the byod functionality in the ruckus wireless system to isolate any byod traffic using acls from the rest of network so its purely for internet and for rate limiting. If its a computer we also supply sophos av to the staff member so they are protected. This is included in our agreement
  • Thanks 1
Posted

Hi rrrrr,

 

Do you use the Ruckus wireless system solely for the BYOD traffic? So do you have that, alongside another Wireless setup?

 

Do you use virtualised desktops? Or just the standard PC setup?

Posted

All staff are given a staff device (surface pro 3) which are on their own ssid. These are fully encrypted with vpn access. We then have a byod ssid for staff and a seperate one for students. The staff one is generally used just for mobile phone internet access and is setup as mentioned before. The student one is also restricted with acls, rate limiting and web filtering. This is used by students with their own laptops.

I have also implemented port security on our switches to stop students plugging in their laptops to ethernet ports.

I have setup workfolders in server 2012r2 for students to access their work on byod.

We dont do vdi

Posted
There are always security concerns with WiFi. Consider using a basic web filtering tool to protect and secure your users. We prefer to have all our devices connected to a wired network because it is that much easier to manage. No need to having to deal with scans and wireless intrusions, etc. For all non-company property, we give our user's access to a guest WiFi network.
Posted
There are always security concerns with WiFi. Consider using a basic web filtering tool to protect and secure your users. We prefer to have all our devices connected to a wired network because it is that much easier to manage. No need to having to deal with scans and wireless intrusions, etc. For all non-company property, we give our user's access to a guest WiFi network.

Wlreless scans and intrusions can be mitigated by client isolation and ACL's. All our BYOD users can connect to is the DNS/DHCP servers on ports 67 & 53 and our UTM/Webfilter for internet traffic.

Also, through device registration, their device is linked to their username for accountability. We also do rate limiting to stop bandwidth hogging.

 

If you run your wireless without any ACL's / Isolation it would behave the same as if they were to plug their personal laptop into the Ethernet socket in a room. They could perform the same scans and attacks and the only accountability you would have is a time/place and ip address which wont help you pin it on a user unless their are witnesses/CCTV.

 

This is why we use port security in any unsupervised areas, limiting each port to 1 mac address

Posted
Don't overlook the legal side - insurance, misuse, loss, theft, damage, etc. Also, if using in a way where data may be collected, or using mail, then also include the issue of remote data wipe.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...