Jump to content

Recommended Posts

Posted

There are several threads on this topic but I wonder if I could ask 2 questions to tie these together?

 

1. Why should teachers and students NOT use their personal laptops at school?

( I wouid like as many reasons as possible please)

 

2. If they should be allowed, how should the network be configured? (here I need some ideas of cost and suppliers/installers of hardware, software, VLANs, managed wifi, switches, etc.)

 

Many thanks.

Posted

They can have them in school, BUT they must PAT tested in line with our H&S policy.

 

They may not be connected to the network as we have no control over viruses etc on the machines.

Posted

Seriously Security is a really big reason not to, as you don't have them set on the same security policy so they aren't locked down and virus protection may be weak.

 

You can solve all this as long as your support team has enough time, but if like us, you're pretty much flat out 99.9% of the time, then it becomes rather unmanagable.

 

Chris

Posted
The problem with using a NAC box is that all the teachers and students laptops will need a CAL to access the network which is often forgotten. I'd be tempted to say NO as you can't rely on student PC's to be upto date on AV and patches and judging by most i've come accross will almost certainly be infested with spyware. You could VLAN them to give them internet access only but that's as far as i would go.
Posted

Nope, they only get Internet here if they connect and the NAC doesn't hate them. You only need CALs if you let them connect to the domain.

 

Our NAC box will OS fingerprint them when they connect, audit their machine with Nessus when they authenticate and then passively monitor them with snort. If they should incur it's wrath at any point during this process, they get arp poisoned and their mac address is blacklisted in the NAC database.

Posted

Aside from virus, don't forget whatever lovely hacking or packet capturing programs they little darlings might have installed, too.

 

We are considering ways in which Sixth Formers could hook up to a wireless VLAN allowing them Starbucks-style Internet access, but that is as close to our network as a private computer is ever going to get. We have full SLT-backing for our policy of saying no to any non-school equipment going on our network; no ifs, no buts, no exception. We have had a few high profile sacrificial lambs to drive this point home, too!

Posted
Aside from virus, don't forget whatever lovely hacking or packet capturing programs they little darlings might have installed, too.

 

Again this will piss off snort here. Thus leaving them lacking a network connection.

Posted
Nope, they only get Internet here if they connect and the NAC doesn't hate them. You only need CALs if you let them connect to the domain.

 

Our NAC box will OS fingerprint them when they connect, audit their machine with Nessus when they authenticate and then passively monitor them with snort. If they should incur it's wrath at any point during this process, they get arp poisoned and their mac address is blacklisted in the NAC database.

 

 

what software are you using for your NAC box?

Posted (edited)

There's also no way to audit what software is installed on a computer and whether the licence covers you to use that software for teaching. For example what happens if a teacher brings in laptop loaded with software that it loaded with programs that are only licences for 'home/non-public' use and then runs them for pupils to use/see?

Then there's the issue of what happens if a teacher brings in a laptop full of personal/illegal material and copies it onto a network share. Also what happens if another user(staff or pupil) browse's onto their laptop or hacks it when they're on your network and steals that users personal files/data?

Tech support could also be a massive drain on resourses. How can you be expected to troubleshoot problems and make things work when you have hundreds of computers with different OS's, software and hardware configurations all of which you have no control over whatsoever?

 

It's one thing if it's a locked down laptop provided to the staff by the school specifically for school-use but as far as Im concerned there are far too many issues to allow even staff to bring in their own computers into school and onto the network. And don't even think about the possibility of letting pupils bring in their own PCs!

Edited by flyinghaggis
Posted

We have a 'no non-school owned equipment in school' policy here. This is due to the following:

 

1. Insurance - if the item is damaged, stolen etc... whilst on the premises, it is not covered by our insurance and we don't want the hassle.

2. Security - by allowing computers into school they could be using them to attempt to connect to the network, which is not allowed due to them not having a fully audited machine.

3. Security - allowing them access to the network introduces an aspect of risk. Regardless of security features in place, you could still end up with an infected network.

Posted
Well being a boarding school we have 3 boarding house's full of students laptops and also have a 6th form center kitted out with points at every desk. Always looking at ways to improve our network bandwidth as they often max things out.
Posted

Hmm, the PAT testing thing. How do you know the charger is rated for the battery etc?

 

. Also locked down with ACLs even after you get in. Windows 2008 NAP will be online and testing soon. Also got a procurve managed wireless mod on the way for my zl :)

Posted

Well there's been a lot of good points mentioned already. There are issues regarding PAT testing (but if the laptop isn't been plugged into the mains then there's the way around that). Antivirus issues. There's no way for you to ensure that "foreign equipment" (as in not your school's kit) is up to date on the current definitions. Security policies. Kids'll install all sorts of crap and play around when they're meant to be doing work etc.

 

I'd like to implement a secure method of access for students and staff for their own machines to gain network access. This would probably centre around a VMPS, a captive portal, a liability waver (Ts&Cs), some cisco APs etc etc. For access to network shares the remote access system for home access would probably be used.

 

Posted
Nope, they only get Internet here if they connect and the NAC doesn't hate them. You only need CALs if you let them connect to the domain.

 

Our NAC box will OS fingerprint them when they connect, audit their machine with Nessus when they authenticate and then passively monitor them with snort. If they should incur it's wrath at any point during this process, they get arp poisoned and their mac address is blacklisted in the NAC database.

 

That sounds tres cool... And being open source you can custom it to do all kinda cool stuff I bet like custom messages and upside down Internet tricks :D

Posted

We have at least one teacher who refuses to use school laptops because they're "not very good", yet she is one of the people with regular problems. Unfortunately she's the head of English and gets pretty much what she wants.

I've only been here three years, so there's till time to train them :cool:

 

 

We are considering ways in which Sixth Formers could hook up to a wireless VLAN allowing them Starbucks-style Internet access, but that is as close to our network as a private computer is ever going to get.

 

@Nick: I was considering the same sort of idea but in my local neighbourhood instead of in the school (it's a bit out in the sticks), and I came across this.

 

http://www.howtoforge.com/wireless_hotspot_howto

Posted

Geoff, I keep on meaning to look at packetfence, how easy is it to install/maintain?

 

Don't suppose you could spare some time to write a luser guide?

Posted

It's easy if you start with the right distro (ie, the same one as the developers, Fedora). I did not. Thus it was entertainingly difficult to make go.

 

I'll see what I can do about a guide. Although the documentation on the site is quite thorough.

Posted

when we get asked if students/teachers can use their laptops in school, we reply "Yes sure, but we have to have administritive access over the machine so we can access the machine at any time, and you'll have to be a limited user"

 

This normally gets a reply of "ah, ok...now worries...are there any spare laptops that I can use?"

 

problem solved ;)

Posted

Packetfence was originally developed at Havard University. It's used at many other Universites in the USA and abroad.

 

If you don't fancy DIYing it, use the VMWare version.

Posted
Nope, they only get Internet here if they connect and the NAC doesn't hate them. You only need CALs if you let them connect to the domain.

 

Our NAC box will OS fingerprint them when they connect, audit their machine with Nessus when they authenticate and then passively monitor them with snort. If they should incur it's wrath at any point during this process, they get arp poisoned and their mac address is blacklisted in the NAC database.

 

This all sounds very cool.

 

What is Nessus able to audit?

 

Once blacklisted does the luser have to come grovelling or do you permanently ban that machine/user from accessing the network?

 

Do you monitor for p2p usage?

Posted
Our HM and Bursar are currently in a push to provide network/power points at ever desk in all refurbed classrooms. Personally i think it could work if we were providing the laptops but they are looking at it being personal ones. So currently looking at NAC and new switches around the entire college to give me more control over this.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...