GRitchie Posted April 28, 2016 Posted April 28, 2016 We purchased some Linx 8 tablets in Summer last year (as I took over as NM) and they've been sat in their boxes ever since. The old NM had a way of imaging them, but he's been back in and we can't get them going. The headteacher has asked to have them set up as standalone devices, solely used for web browsing. Obviously internet filter tracking is going to be my biggest problem. I've created a VB application that opens on login, requests the users name to continue and then records it to a txt file on the C: with the date and time. But I can't help but feel like I'm still opening a whole can of worms letting these on the network without being connected to the domain. I've already told the HT that his idea would work, in theory, and he's keen to get them out ASAP. Thoughts??
LeMarchand Posted April 28, 2016 Posted April 28, 2016 Have you got a USB to Cat5 adapter? IIRC you should be able to image them that way.
ITGURU Posted April 28, 2016 Posted April 28, 2016 We purchased some Linx 8 tablets in Summer last year (as I took over as NM) and they've been sat in their boxes ever since. The old NM had a way of imaging them, but he's been back in and we can't get them going. The headteacher has asked to have them set up as standalone devices, solely used for web browsing. Obviously internet filter tracking is going to be my biggest problem. I've created a VB application that opens on login, requests the users name to continue and then records it to a txt file on the C: with the date and time. But I can't help but feel like I'm still opening a whole can of worms letting these on the network without being connected to the domain. I've already told the HT that his idea would work, in theory, and he's keen to get them out ASAP. Thoughts?? How many do you have and what will be done on them that would require imaging rather than setting up individually? AS for the internet, can you not add them to a device group (rather than user) and then assign the filtering policy to that group? It's what I do with our iPads.
GRitchie Posted April 28, 2016 Author Posted April 28, 2016 @LeMarchand - a thread online tells me you cannot do that with these tablets @ITGURU - We have about 30, going to be split 15 in two departments. We would have them using word etc. in lessons too. But primarily web browsers if I'm honest. I use Smoothwall, so I imagine I'd need to set them static IP's and then add them to a group? If so is there a way of asking for the students AD credentials every so often for logging filter concerns? That way, I can remove my naff VB application!
ITGURU Posted April 28, 2016 Posted April 28, 2016 @LeMarchand - a thread online tells me you cannot do that with these tablets @ITGURU - We have about 30, going to be split 15 in two departments. We would have them using word etc. in lessons too. But primarily web browsers if I'm honest. I use Smoothwall, so I imagine I'd need to set them static IP's and then add them to a group? If so is there a way of asking for the students AD credentials every so often for logging filter concerns? That way, I can remove my naff VB application! I don't have any experience with smoothwall. However, I add the MAC addresses into an 'Staff/Student' iPad (computer) policy group, so it doesn't matter what IP they have, then the relevant group gets assigned the student/staff policy. When I run a report, I just run it by the device name, you cannot see which user it was, but the filter report date/time should be enough to find who was using it in what class at the time if anything shows in the reports of concern.
pcstru Posted April 28, 2016 Posted April 28, 2016 If you are using smoothwall, why not have the students authenticate when the browse the web (smoothwall can prompt for creds when someone tries to access the web)? That way your filtering records will be able to identify individual accounts. Otherwise, in smoothwall we allow some VLAN/subnets to bypass authentication but have the default student filtering applied.
sted Posted April 28, 2016 Posted April 28, 2016 could you domain them but apply almost 0 policies to them just enough to allow logon to the domain and force local profiles etc?
GRitchie Posted April 28, 2016 Author Posted April 28, 2016 @pcstru - I think that's what I'm going to try. So in theory I can: Create a group on Smoothwall with only the tablets in (either via the IP or the mac address) then set a policy ONLY to those devices to ask for authentication credentials every (say) 20 minutes? That way we know who's doing what? I'm also going to put Impero on them, but again it won't tell me who's on them anyway...
Achandler Posted April 28, 2016 Posted April 28, 2016 Assuming you use Kerberos or NTLM on Smoothwall already, simple turn Proxy Authenication on but on a different port. Set the proxy setting on the tablets to point to the port and you will be asked to login each time. The downside is that people will tick remember my credentials and then end up authenicating as each other!
LeMarchand Posted April 28, 2016 Posted April 28, 2016 @LeMarchand - a thread online tells me you cannot do that with these tablets Will they boot from USB? If so, you could use Clonezilla or similar.
GRitchie Posted April 28, 2016 Author Posted April 28, 2016 @Achandler - will look into this, hoping there might be away to stop that from happening :/ @LeMarchand - nope, Clonezilla was the way the old NM had them imaging. No longer working for us - plus I've spent long enough on getting them to image, so we've just written it off as a possibility now...(!)
pcstru Posted April 28, 2016 Posted April 28, 2016 @pcstru - I think that's what I'm going to try. So in theory I can: Create a group on Smoothwall with only the tablets in (either via the IP or the mac address) then set a policy ONLY to those devices to ask for authentication credentials every (say) 20 minutes? That way we know who's doing what? Yes - we do it here for BYOD and chromebooks (a bit clunky as they have already logged in but single sign on seems to be broken), so it is possible to mix up authentication in that way (some devices pass creds, some are prompted, some are just let through but a policy is applied). 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now