Jump to content

Recommended Posts

Posted

We purchased some Linx 8 tablets in Summer last year (as I took over as NM) and they've been sat in their boxes ever since.

The old NM had a way of imaging them, but he's been back in and we can't get them going.

 

The headteacher has asked to have them set up as standalone devices, solely used for web browsing.

Obviously internet filter tracking is going to be my biggest problem. I've created a VB application that opens on login, requests the users name to continue and then records it to a txt file on the C: with the date and time.

 

But I can't help but feel like I'm still opening a whole can of worms letting these on the network without being connected to the domain.

 

I've already told the HT that his idea would work, in theory, and he's keen to get them out ASAP.

 

Thoughts??

Posted
We purchased some Linx 8 tablets in Summer last year (as I took over as NM) and they've been sat in their boxes ever since.

The old NM had a way of imaging them, but he's been back in and we can't get them going.

 

The headteacher has asked to have them set up as standalone devices, solely used for web browsing.

Obviously internet filter tracking is going to be my biggest problem. I've created a VB application that opens on login, requests the users name to continue and then records it to a txt file on the C: with the date and time.

 

But I can't help but feel like I'm still opening a whole can of worms letting these on the network without being connected to the domain.

 

I've already told the HT that his idea would work, in theory, and he's keen to get them out ASAP.

 

Thoughts??

 

How many do you have and what will be done on them that would require imaging rather than setting up individually?

AS for the internet, can you not add them to a device group (rather than user) and then assign the filtering policy to that group? It's what I do with our iPads.

Posted

@LeMarchand - a thread online tells me you cannot do that with these tablets :(

@ITGURU - We have about 30, going to be split 15 in two departments. We would have them using word etc. in lessons too. But primarily web browsers if I'm honest.

I use Smoothwall, so I imagine I'd need to set them static IP's and then add them to a group? If so is there a way of asking for the students AD credentials every so often for logging filter concerns?

That way, I can remove my naff VB application!

Posted
@LeMarchand - a thread online tells me you cannot do that with these tablets :(

@ITGURU - We have about 30, going to be split 15 in two departments. We would have them using word etc. in lessons too. But primarily web browsers if I'm honest.

I use Smoothwall, so I imagine I'd need to set them static IP's and then add them to a group? If so is there a way of asking for the students AD credentials every so often for logging filter concerns?

That way, I can remove my naff VB application!

 

I don't have any experience with smoothwall. However, I add the MAC addresses into an 'Staff/Student' iPad (computer) policy group, so it doesn't matter what IP they have, then the relevant group gets assigned the student/staff policy.

 

When I run a report, I just run it by the device name, you cannot see which user it was, but the filter report date/time should be enough to find who was using it in what class at the time if anything shows in the reports of concern.

Posted

If you are using smoothwall, why not have the students authenticate when the browse the web (smoothwall can prompt for creds when someone tries to access the web)? That way your filtering records will be able to identify individual accounts.

 

Otherwise, in smoothwall we allow some VLAN/subnets to bypass authentication but have the default student filtering applied.

Posted
could you domain them but apply almost 0 policies to them just enough to allow logon to the domain and force local profiles etc?
Posted

@pcstru - I think that's what I'm going to try.

So in theory I can:

Create a group on Smoothwall with only the tablets in (either via the IP or the mac address)

then set a policy ONLY to those devices to ask for authentication credentials every (say) 20 minutes?

 

That way we know who's doing what?

 

 

I'm also going to put Impero on them, but again it won't tell me who's on them anyway...

Posted
Assuming you use Kerberos or NTLM on Smoothwall already, simple turn Proxy Authenication on but on a different port. Set the proxy setting on the tablets to point to the port and you will be asked to login each time. The downside is that people will tick remember my credentials and then end up authenicating as each other!
Posted

@Achandler - will look into this, hoping there might be away to stop that from happening :/

@LeMarchand - nope, Clonezilla was the way the old NM had them imaging. No longer working for us :( - plus I've spent long enough on getting them to image, so we've just written it off as a possibility now...(!)

Posted
@pcstru - I think that's what I'm going to try.

So in theory I can:

Create a group on Smoothwall with only the tablets in (either via the IP or the mac address)

then set a policy ONLY to those devices to ask for authentication credentials every (say) 20 minutes?

 

That way we know who's doing what?

Yes - we do it here for BYOD and chromebooks (a bit clunky as they have already logged in but single sign on seems to be broken), so it is possible to mix up authentication in that way (some devices pass creds, some are prompted, some are just let through but a policy is applied).

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...