Jump to content

Recommended Posts

Posted

Hey guys,

 

SLT are asking about monitoring of BYOD devices. Not just filtering but actually seeing what students and staff are viewing on their personal devices.

 

They want to know web searches and websites students have viewed.

 

Is this even possible? We have NetSupport DNA but this only monitoring domain PCs and Laptops, unless I'm wrong.

 

Thanks

  • Thanks 1
Posted

Websites and web searches is different to viewing their devices and what they're doing. That's all possible from any standard web filter as obviously any requests are logged against a device/username.

 

Which is it you mean?

 

Steve

Posted
Hey guys,

 

SLT are asking about monitoring of BYOD devices. Not just filtering but actually seeing what students and staff are viewing on their personal devices.

 

They want to know web searches and websites students have viewed.

 

Is this even possible? We have NetSupport DNA but this only monitoring domain PCs and Laptops, unless I'm wrong.

 

Thanks

 

You can do this if your firewall/filter solution supports it. It would be a man in the middle attack as google encrypts searches ( i know Fortigate support this, i'm sure Smoothwall do too), so you would have need to install a certificate on the end users devices to intercept the traffic.

Posted

We have NPS set up to allow only staff and 6th Form to connect to the BYOD SSID, then our Smoothwall kicks in and asks for their credentials again, and this page also has a link to download our SSL inspection certificate. Once logged in to both the SSID and the Smoothwall, they have exactly the same level of filtering as they would on the school machines.

 

I'm pretty sure there is a way to bypass the Smoothwall authentication step by getting it to look at the NPS server or something like that so they only have to authenticate once, but I've not figured that out yet (if anyone has instructions please PM me :) ).

Posted
Personal (BYOD) devices here all use the same policy as if they were using a PC, so if they can access on a PC they can access on their own device.
Posted
Hey guys,

 

SLT are asking about monitoring of BYOD devices. Not just filtering but actually seeing what students and staff are viewing on their personal devices.

 

They want to know web searches and websites students have viewed.

 

Is this even possible? We have NetSupport DNA but this only monitoring domain PCs and Laptops, unless I'm wrong.

 

Thanks

 

We have just started using DNA and you are right in that it monitors domain PCs and laptops. As far as I know it doesnt cover BYOD, Chromebooks or IOS devices.

Posted

SLT are asking about monitoring of BYOD devices. Not just filtering but actually seeing what students and staff are viewing on their personal devices.

 

They want to know web searches and websites students have viewed.

 

Is this even possible?

 

Your web filter should be able to produce those kinds of reports. e.g. something like:

images_report.pngwordcloud.png

Posted
I'm pretty sure there is a way to bypass the Smoothwall authentication step by getting it to look at the NPS server or something like that so they only have to authenticate once, but I've not figured that out yet (if anyone has instructions please PM me :) ).

 

I imagine you'd set your Wifi controller to send RADIUS accounting updates to the SW box.

Posted
We want to monitor BYOD activity, I.e Google searches, visited sites etc.

 

All of this is possible - how easy and how transparent it is to the end-users is a bit dependent on how your network is already set up and the capabilities of the equipment. It wouldn't surprise me if you can do what you want without significant investment.

 

You're going to want to figure out what you need to log or filter for each group of users, because there are pros and cons that have the be weighed. If you're going to log individual web searches, what specific youtube videos have been watched, etc. then you will need your web filter to do HTTPS interception. That allows it to decrypt the HTTPS traffic, examine it, filter it and log it, but it has the down side that you have to install a certificate on each user's device.

 

If you can't install a certificate on each device, the best you can do is passive HTTPS inspection (different filtering systems use different names for this, such as "HTTPS snooping", etc.). If your filtering system can do this, you can log the host names of the web sites being visited, but nothing especially invasive. e.g. you'll be able to see that the user visited youtube, but you won't know what videos they watched, and you'll be able to see that a user visited google but not what they searched for, etc.

 

Depending on your filtering system, you may be able to choose how invasive its being based on the user name or which network the user is on - i.e. you probably want to go to the trouble of installing certificates on students' devices, but not visitors' devices; so you'd want to have HTTPS interception turned on for the students and only passive HTTPS inspection for the visitors.

 

There's information how HTTPS interception works here: http://www.opendium.com/sites/www.opendium.com/files/https_interception/https_interception.pdf

(MODERATORS: if you think it is not appropriate to link this here, please consider just removing this link rather than the whole post :)

 

Secondly, you need to decide how to identify the users - the nicest way is to use 802.1x authentication and have your wifi controller send RADIUS accounting data to your web filter. If you can't do that, you can probably set your web filter to produce a captive portal page that the user would have to log in to before gaining access to the internet. Again, this is something you may want to set differently for different networks - you might not want to bother identifying guest users.

  • Thanks 1
  • 2 weeks later...
Posted
We have NPS set up to allow only staff and 6th Form to connect to the BYOD SSID, then our Smoothwall kicks in and asks for their credentials again, and this page also has a link to download our SSL inspection certificate. Once logged in to both the SSID and the Smoothwall, they have exactly the same level of filtering as they would on the school machines.

 

I'm pretty sure there is a way to bypass the Smoothwall authentication step by getting it to look at the NPS server or something like that so they only have to authenticate once, but I've not figured that out yet (if anyone has instructions please PM me :) ).

@sllorep take a look at RADIUS accounting to do this. Your wireless clients will pass along their username and it should then be seamless

  • Thanks 1
Posted
@sllorep take a look at RADIUS accounting to do this. Your wireless clients will pass along their username and it should then be seamless
@markwilfan indeed it does but you then get a different problem in how to deploy the MITM certificate page as there doesn't seem to be a way to redirect a RADIUS client to a splash page :(
  • Thanks 1
Posted
I'll take a look at this when I get a free moment, but good point, I guess I'd have to put posters in the Common Room and Staff Room how to get to the download and instructions page.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...