Jump to content

Recommended Posts

Posted

I'm sure we're not unique in that we use a good few mobile devices that have unauthenticated access to our smoothwall filter, which puts them into an group which is filtered the same as staff or students (depending on the devices) This is essential to get any of these devices to work properly.

 

However since we started monitoring safeguarding issues through smoothwall I'm now wondering how we (and how would you) deal with a potential safeguarding incident that was linked to one of these devices?

 

For example, if a student used a ipad and spent a concerning amount of time on self harm sites for example, this would be flagged up but you wouldn't be able to track it down to anything other than an IP address. Finding out who used that ipad would be tricky to say the least!

 

This hasn't actually happened yet but I'm curious if anyone has had to deal with this?

Posted (edited)

We've just updated a few of our systems to tackle the very same problem.

 

After exploring a few different options (such as Captive Portals), we opted to implement RADIUS 802.1x authentication.

Students and Staff are prompted for their School Username and Password with accessing the SSID. No more PSK/PPSK to worry about. It's all tied to Active Directory via Windows NPS/RADIUS.

 

Once a user has Authenticated, the RADIUS accounting information is sent to our Web Filter (CensorNet USS in our case, but Smoothwall does the same I believe).

From that point on the Web Filter has User to IP mapping so all traffic from that device is mapped to the User rather than just an unknown IP.

Edited by Arcolite
  • Thanks 2
Posted

It seems that adding authentication back in is the only option. One of the reasons the ipads were popular is that there is no 'login'

 

Also, how do you deal with one kid authenticating on an ipad, which is then used by another? - unless they close the wifi connection it would still be against their login.

Posted

We use Policy Central in the primary school across all the PCs, but the school does have some iPads. I've voiced my concern on this matter too, although Policy Central do offer an iPad monitoring software it is a bit rubbish.

 

It was an app that had to be installed and this is what had to used instead of Safari for web browsing, also if the user doesn't logout of the session when finishing the next user just comes along and carriers on with authentication still showing as if its the original user still using the device. There isn't even any built session expiring etc. The monitoring only exists 'inside' that particular app - so a user could simply fire up Safari and search what they like without any monitoring.

 

The authentication also didn't link into AD so they'd (students) of been required to know/remember another login step. This was a paid option too, wasn't impressed.

 

Long story short - i'd like to know what you do on this front and what you decide on doing.

Posted
We use Policy Central in the primary school across all the PCs, but the school does have some iPads. I've voiced my concern on this matter too, although Policy Central do offer an iPad monitoring software it is a bit rubbish.

 

It was an app that had to be installed and this is what had to used instead of Safari for web browsing, also if the user doesn't logout of the session when finishing the next user just comes along and carriers on with authentication still showing as if its the original user still using the device. There isn't even any built session expiring etc. The monitoring only exists 'inside' that particular app - so a user could simply fire up Safari and search what they like without any monitoring.

 

The authentication also didn't link into AD so they'd (students) of been required to know/remember another login step. This was a paid option too, wasn't impressed.

 

Long story short - i'd like to know what you do on this front and what you decide on doing.

 

I'm in two minds here - unauthenticated access is what makes the ipads usable and flexible. Taking that away will annoy the staff and students, but does open up a loophole for tracking safeguarding issues. It might be down to SLT to decided which way this has to go!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...