Jump to content

Recommended Posts

Posted

We've currently considering whether BYOD is necessary and also probably about to add a Guest wireless for occasional visitors.

 

How do you set yours up? Do you apply any security (i.e PSK) on the connection before its passed to a secondary authentication such as Radius or a portal?

 

As we have Xirrus, the actual SSID can be Open or secured with Radius/PSK etc before you even get to the Guest portal (where we will use a token based system)

Posted

We have set up a BYOD SSID to only use Radius to sign in, so they must have a staff account to login or they just get rejected. Once on they are filtered as if they are at any other PC, based on the their logon.

 

Guests are setup as an open wifi point that is directed to a Ruckus Portal that gets them to sign in for a token. They put in an email and name but this isn't verified. We could have set it up so it would email a link but it would have confused most people I think. MAC Address is logged so if someone does something silly we just ban the MAC and all traffic is logged so we can see what they did, or tried to do. Token last 24 hours and filtering is our most restrictive so that pupils won't attempt to use it instead of the one with their account.

  • Thanks 1
Posted
We have set up a BYOD SSID to only use Radius to sign in, so they must have a staff account to login or they just get rejected. Once on they are filtered as if they are at any other PC, based on the their logon.

 

Guests are setup as an open wifi point that is directed to a Ruckus Portal that gets them to sign in for a token. They put in an email and name but this isn't verified. We could have set it up so it would email a link but it would have confused most people I think. MAC Address is logged so if someone does something silly we just ban the MAC and all traffic is logged so we can see what they did, or tried to do. Token last 24 hours and filtering is our most restrictive so that pupils won't attempt to use it instead of the one with their account.

 

What if guests need access to something restricted?

Do you open up Facebook etc as and when required?

Posted (edited)

Nope. Guest access is what it is. If someone needs something special, visiting speaker say, then we use a guest login on the BYOD with very specific permissions and staff level filtering that we can change the password after.

 

Our reasoning is, if the guest ssid has anything over and above student access kids will jump on it in a heartbeat. Parents wanting to update their Facebook status can jump on their 4G if it is that desperate, that is not why we provide it.

Edited by TechMonkey
Posted
Nope. Guest access is what it is. If someone needs something special, visiting speaker say, then we use a guest login with very specific permissions and staff level filtering that we can change the password after.

 

Our reasoning is, if the guest ssid has anything over and above student access kids will jump on it in a heartbeat. Parents wanting to update their Facebook status can jump on their 4G if it is that desperate, that is not why we provide it.

 

Thats my reasoning - guest access is not supposed to be way of saving your data allowance! We intend it for occasional visitors but even then we prefer to offer them a guest staff login. We've noticed that visitors who 'desperately' needed to get on the wifi suddenly weren't so bothered when we offered them the guest network login instead, which makes me suspect that a lot of the usage is nothing to do with the visit!

 

Same goes for BYOD, unless we as a school intend to allow students to use their own devices for working in classrooms then BYOD is still not a great priority.

 

I'd still like the options to offer both though, as it covers all the bases then.

Posted

I'd still like the options to offer both though, as it covers all the bases then.

 

That is our thoughts too, BYOD for staff is currently used on phones (to save data I bet) and guest is so that we have a basic service just in case. A supplier has commented they managed to get their emails and check some docs on it and were pleased, that is the use case. I guess if a supplier wanted to look at innocuous manufacturer site and it was blocked we would open that, but it would be something that can be opened to everyone, so more a filtering error rather than them wanting to access something anyone else can't.

Posted

Our guest network is filtered based on sixth form level - it includes some social networking. We get asked for a guest pass I'd say weekly. Mostly these are guests who are doing some kind of workshop or presentation to students. Most have brought a laptop to work with and some may even be doing presentations on social networks. Passes are created for a suitable length of time and generally only allow one device to be connected to our ruckus wifi network.

 

BYOD-wise we primarily use three SSIDs - one for provisioning which doesn't have a password. One for staff to use and one for sixth form. The staff and sixth form SSIDs are secured using unique passcodes for each device. Sixth form are limited to a couple of devices. We throttle the connection of these networks a bit but it has never really been an issue. Sixth form get exactly the same level of filtering on the wifi as they do on the PCs - as do staff.

 

We've taken the view that allowing social networking for sixth form allows us to intervene if they are making mistakes. Reducing the blocked list and increasing the monitoring. We've lost the opportunity to intervene if they use 3/4G.

Posted

I think we'll be using an open system for Guests (with generated token logins) and then open/Google portal for BYOD for staff and students when that is approved.

 

I was just curious if anyone secured the SSID before any radius authentication or portal logins, as this would mean giving them a key and a token to login? Well, for the guest wifi anyway.

Posted

I have a ruckus system as well.

Staff / Students are secured with 802.1x Radius back to an NPS box. This gives them the correct filter level.

Guests have an open ssid with just a ToS page that needs agreeing to. I've never really setup the whole guest pass thing. The guest network is also most restrictive and and bandwidth throttled.

I want to keep it for legit guests, not students.

 

Not to go to far off topic but how do you limit them to a certain number of devices?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...