Jump to content

Recommended Posts

Posted

Hi everyone

 

I would like to set up BYOD for our Sixth Form area. I am going to use a combination of AeroHive web management and Smoothwall to enable the solution. I would like Sixth Form students to be able to come into school with their own devices and only get an internet connection so that they can access Office365 and the VLE. I was wondering if there is a way that I could create security, segragation authorisation, identification without setting up VLANs on our switches.

 

I would appreciate any help/advice on this.

 

Many thanks

 

Eddie

Posted (edited)
We have similar requirements. What I have done is set up 8021x auth using Active Directory as the Auth Server. Then in Aerohive I have one SSID with two users profiles. The profiles are assigned based on AD group membership. The AD NPS server passes back the pvt-tunnel-Group-ID attribute back to Aerohive to facilitate user policy assignment. In the Aerohive student user profile there is an IP firewall policy that only allows traffic to and from port 80 and 443 and well as DNS and DHCP. Edited by uctutor1
Posted
With BYOD you might into the issue with those devices not authenticating through AD (like mine) I have two SSIDs set up one for school owned and one for guest and students so that each can be filtered separately because I do not have a RADIUS server set up yet. My suggestion though would be to have a RADIUS server and just use a captive portal tied into the RADIUS server and authenticate through the firewall with a whitelist for those student accounts.
  • 5 months later...
Posted
Smoothwall can act as both DHCP and Radius server. So its really easy for BYOD - and we use aerohive with smoothwall. Students use their AD details on their device for wireless authentication...and that's it. They don't get challenged again, and webfiltering automatically knows who they are. You can "isolate" wireless users from each other (although there are some apps which make use of peer to peer connections - although you might not want to encourage that). But without vLANs, BYOD devices would able to connect to see your domain servers and PCs with risk of spreading infections. I wouldn't be advising that at all. They could for example - bring down your network with a DDOS attack. My feeling is that its pretty important to keep all your BYOD traffic on a separate VLAN (and IP subnet) and add rules to permit any connection to a particular internal web server /port/printer.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...