WhizInTraining Posted August 27, 2015 Posted August 27, 2015 Hi, At my company, I have been set a task of possibly allowing our staff to bring their own devices. We have wireless already which they can connect to, but my real questions are... Do you guys allow staff to bring their own devices? And also, Do you use any special programs or features for this? I'd appreciate any response given. Thanks!
rrrrr Posted August 27, 2015 Posted August 27, 2015 We use the byod functionality in the ruckus wireless system to isolate any byod traffic using acls from the rest of network so its purely for internet and for rate limiting. If its a computer we also supply sophos av to the staff member so they are protected. This is included in our agreement 1
WhizInTraining Posted August 27, 2015 Author Posted August 27, 2015 Hi rrrrr, Do you use the Ruckus wireless system solely for the BYOD traffic? So do you have that, alongside another Wireless setup? Do you use virtualised desktops? Or just the standard PC setup?
rrrrr Posted August 27, 2015 Posted August 27, 2015 All staff are given a staff device (surface pro 3) which are on their own ssid. These are fully encrypted with vpn access. We then have a byod ssid for staff and a seperate one for students. The staff one is generally used just for mobile phone internet access and is setup as mentioned before. The student one is also restricted with acls, rate limiting and web filtering. This is used by students with their own laptops. I have also implemented port security on our switches to stop students plugging in their laptops to ethernet ports. I have setup workfolders in server 2012r2 for students to access their work on byod. We dont do vdi
s_miller Posted August 28, 2015 Posted August 28, 2015 There are always security concerns with WiFi. Consider using a basic web filtering tool to protect and secure your users. We prefer to have all our devices connected to a wired network because it is that much easier to manage. No need to having to deal with scans and wireless intrusions, etc. For all non-company property, we give our user's access to a guest WiFi network.
rrrrr Posted August 28, 2015 Posted August 28, 2015 There are always security concerns with WiFi. Consider using a basic web filtering tool to protect and secure your users. We prefer to have all our devices connected to a wired network because it is that much easier to manage. No need to having to deal with scans and wireless intrusions, etc. For all non-company property, we give our user's access to a guest WiFi network. Wlreless scans and intrusions can be mitigated by client isolation and ACL's. All our BYOD users can connect to is the DNS/DHCP servers on ports 67 & 53 and our UTM/Webfilter for internet traffic. Also, through device registration, their device is linked to their username for accountability. We also do rate limiting to stop bandwidth hogging. If you run your wireless without any ACL's / Isolation it would behave the same as if they were to plug their personal laptop into the Ethernet socket in a room. They could perform the same scans and attacks and the only accountability you would have is a time/place and ip address which wont help you pin it on a user unless their are witnesses/CCTV. This is why we use port security in any unsupervised areas, limiting each port to 1 mac address
Gibson335 Posted August 28, 2015 Posted August 28, 2015 Don't overlook the legal side - insurance, misuse, loss, theft, damage, etc. Also, if using in a way where data may be collected, or using mail, then also include the issue of remote data wipe.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now