Jump to content

Recommended Posts

Posted
I have been asked (told) we roll out BYOD for students across all year levels. It needs to be setup so that students should be able to bring their own device to school and connect to the school wireless network without IT even touching their device. My concern is, the risks it will pose on the rest of the network. They are going to bring their machines full of malware and will be able to freely connect any number of devices to download their personal stuff.To give you some idea of our network, it comprises of HP Procurve switches which are VLANed and subnetted but there are no ACLs as such to restrict access. We are running Windows Server 2012 R2 on VMware for most of the services. We are in the process of upgrading our wireless to cope with the increase in the number of devices and throughput.I know it is definitely possible but have no idea how it will work in reality as I have always worked in a tightly controlled environment where no such thing would ever happen. Moreover, I don't have advanced networking skills and don't have time to learn within the required timeframe as we are a very small team with a lot of pressure. Also, I would like not to use the production network as a guinea pig even if I gain the skills somehow.I would like to know if anyone else has done it and what is required to make it happen. Also, what are the challenges I should be prepared for and the implications it may have on the network and the school as a whole?
Posted
Challenges are the network and broadband they use a lot of the time you have to improve backbone and broadband before you do this especially if people using iPads which are network hungry
Posted (edited)

"I have been asked (told) we roll out BYOD for students across all year levels" ....

 

I'd be interested to know if this itself is the "objective" ...or exactly what the educational objective is. I'm not suggesting that BYOD might not be the solution to the educational objective - but how you implement BYOD may make the educational objective a success or a disaster. Focus on the Educational objective NOT the BYOD means of delivering it. There is a very real danger of having a brilliant BYOD system - but one which no one befits from. Its going to need to include training for staff....and students....with time allocated to this...and boots on the ground to support staff/students. Not just training to make it work - but training as to how to make good use of it in the classroom. Don't assume that because a teacher or student can use facebook or snapchat that they could actually create a spreadsheet in Google apps. And just using an APP (such as for vocal testing) is definitely not delivering ICT skills.

 

If students (and staff) bring their own devices - then yes - they could contain all sorts of malware that you would want to protect your network against...and other BYOD users. Most wireless systems allow you to isolate wireless devices from each other - even if they have common access to a gateway. This wireless network needs to be on a VLAN. No question about that. So you need smart switches that support Vlans and wireless access points configured to use it. And you need something like smoothwall with multiple "networks" , filtering, monitoring, firewall, rules etc. to act as a gateway. It needn't be smoothwall - but it probably needs to be a hardware device (maybe virtualised).

 

"connect to the school wireless network without IT even touching their device". Well IT might not need to "touch" the device - but users will have a learning curve. Its NOT going to be as simple as typing in an WPA code as you might at home and away to go.

 

To start with you are going to need meet the "Prevent Strategy". Its compulsory...or an obligation. Or whatever words you would like to use.

 

This requires you to "monitor" what users (staff and students) do. You cannot ignore this requirement. This is either going to require you to use "Enterprise" logons using Radius (or direct AD) with your access points - or ... you might consider some kind of captive logon screen using a browser. On second thought - you don't want a captive portal - because users will want to use "apps" and they will find it a real hassle if they have to open a browser and logon before using an app.

 

And you will require your web filter/monitor to "talk" to your radius server so that it can identify the user logon and allocate age appropriate filtering rules (because that is another requirement).

 

And if you are monitoring (and you will be) - they will need to have a certificate installed on their device. There is no way around this. Its is essential for https traffic to be monitored. No you don't need it at home for your home WiFi - but you will need this in a school. You can tell them they need to download it from a location on your school web page or whatever - but they are going to need to install it.....and you will probably end up doing it for at least some staff as well as many students because its a step too far for many....and users are confused because they think its working after the initial wireless connection because they can get to some web pages. And installing the certificate on Android is not always straight forward either - depending on the version of Android in use. Often you need to download it as a first step then find it and install it as a second step. Most Android users have no idea where to find the certificate after they download it - even when you give them step by step guides (they can't be bothered reading them).

 

...and making an Enterprise connection with Android can be a nightmare too - sometimes requiring you to make changes such as making it NOT require a certificate to make the connection to your access point....and choosing the correct PEAP/MSCHAP options...

 

Still - in theory - if you give them picture book guides some will manage to make this connection without "IT touching their device".

 

Finally - you will soon find that using your BYOD with the likes of filter devices like smoothwall is a nightmare. You tick boxes to allow them to use Google Apps, Office 365 or for staff to use social media - boxers that work fine for desktop PCs....but as you will soon discover are not going to allow things to work for mobile devices. Chromebooks are going to need even more work. Certificate pinning are going to stop YouTube working, and things like Spotify and Snapchat are going to require you to make changes to your firewall settings too - because they don't use http(s) ports for all their activities. (You might imagine that the likes of smoothwall would have added all these things and provide ready made configurations for mobile devices - but you'd be wrong.) Yes these things can be made to work - but only by a lot of configurations and trial and error....and a lot of irritated users.

 

And of course you need to consider the impact on your external internet bandwidth. And while you might allocate a quota - that won't be very helpful if when a student requires to use BYOD in the first lesson after lunch they can't because its all used up.

 

I'm an advocate for BYOD really - but its not an end in itself. Delivering ICT skills needs to be the objective...and too often school management (and IT departments) somehow get side tracked into making the infrastructure the objective without nearly enough thought as to how to deliver those ICT skills (possibly because the teachers don't have those skills and are not capable of delivering them)

 

And if you do not have Office 365 and Google Docs set up - with sync tools (free - except for the time to implement them) you will probably want to set these up.

 

And you will probably want to think about printing and how to use Airserver/Chromecast so that BYOD devices can show their screens on a classroom projector. Its really very difficult to explain to students what to do if you can't actually show them. I like using QR codes with manufacturer's APPs for printing - as it saves 50 printers appearing in a dropdown list using Air print. Google's Cloud print is worth setting up too.

 

Give yourself about a year to se this up. Its not a week of fortnight task - especially if you are still doing the day job of running a school computer system

Edited by AlanD
  • Thanks 2
Posted
Create a blank for byod WiFi and get the WiFi controller to send it direct to router out onto internet
As far as I know schools are required to authenticate all the students and staff so that won't work well.

 

- - - Updated - - -

 

What system are you going to use for your new wireless network?
We are currently looking at Cisco, Ruckus and couple of others. Will be decided next week.
Posted
Challenges are the network and broadband they use a lot of the time you have to improve backbone and broadband before you do this especially if people using iPads which are network hungry
We already have a solid backbone and will be upgrading our broadband in near future so covered well there.
Posted
"I have been asked (told) we roll out BYOD for students across all year levels" ....I'd be interested to know if this itself is the "objective" ...or exactly what the educational objective is. I'm not suggesting that BYOD might not be the solution to the educational objective - but how you implement BYOD may make the educational objective a success or a disaster. Focus on the Educational objective NOT the BYOD means of delivering it. There is a very real danger of having a brilliant BYOD system - but one which no one befits from. Its going to need to include training for staff....and students....with time allocated to this...and boots on the ground to support staff/students. Not just training to make it work - but training as to how to make good use of it in the classroom. Don't assume that because a teacher or student can use facebook or snapchat that they could actually create a spreadsheet in Google apps. And just using an APP (such as for vocal testing) is definitely not delivering ICT skills.
The objective is to have each student in the school with a device they can use in the classroom. As we can't afford to do it, it has been decided that we let them bring their own to cut costs.
If students (and staff) bring their own devices - then yes - they could contain all sorts of malware that you would want to protect your network against...and other BYOD users. Most wireless systems allow you to isolate wireless devices from each other - even if they have common access to a gateway. This wireless network needs to be on a VLAN. No question about that. So you need smart switches that support Vlans and wireless access points configured to use it. And you need something like smoothwall with multiple "networks" , filtering, monitoring, firewall, rules etc. to act as a gateway. It needn't be smoothwall - but it probably needs to be a hardware device (maybe virtualised). "connect to the school wireless network without IT even touching their device". Well IT might not need to "touch" the device - but users will have a learning curve. Its NOT going to be as simple as typing in an WPA code as you might at home and away to go.
Actually, I should have mentioned that 'IT not touching their devices' means us not installing anything on their devices because *students don't like it*. So I would like to know how this would work?To start with you are going to need meet the "Prevent Strategy". Its compulsory...or an obligation. Or whatever words you would like to use.
This requires you to "monitor" what users (staff and students) do. You cannot ignore this requirement. This is either going to require you to use "Enterprise" logons using Radius (or direct AD) with your access points - or ... you might consider some kind of captive logon screen using a browser. On second thought - you don't want a captive portal - because users will want to use "apps" and they will find it a real hassle if they have to open a browser and logon before using an app.And you will require your web filter/monitor to "talk" to your radius server so that it can identify the user logon and allocate age appropriate filtering rules (because that is another requirement).And if you are monitoring (and you will be) - they will need to have a certificate installed on their device. There is no way around this. Its is essential for https traffic to be monitored. No you don't need it at home for your home WiFi - but you will need this in a school. You can tell them they need to download it from a location on your school web page or whatever - but they are going to need to install it.....and you will probably end up doing it for at least some staff as well as many students because its a step too far for many....and users are confused because they think its working after the initial wireless connection because they can get to some web pages. And installing the certificate on Android is not always straight forward either - depending on the version of Android in use. Often you need to download it as a first step then find it and install it as a second step. Most Android users have no idea where to find the certificate after they download it - even when you give them step by step guides (they can't be bothered reading them)....and making an Enterprise connection with Android can be a nightmare too - sometimes requiring you to make changes such as making it NOT require a certificate to make the connection to your access point....and choosing the correct PEAP/MSCHAP options...Still - in theory - if you give them picture book guides some will manage to make this connection without "IT touching their device".Finally - you will soon find that using your BYOD with the likes of filter devices like smoothwall is a nightmare. You tick boxes to allow them to use Google Apps, Office 365 or for staff to use social media - boxers that work fine for desktop PCs....but as you will soon discover are not going to allow things to work for mobile devices. Chromebooks are going to need even more work. Certificate pinning are going to stop YouTube working, and things like Spotify and Snapchat are going to require you to make changes to your firewall settings too - because they don't use http(s) ports for all their activities. (You might imagine that the likes of smoothwall would have added all these things and provide ready made configurations for mobile devices - but you'd be wrong.) Yes these things can be made to work - but only by a lot of configurations and trial and error....and a lot of irritated users.And of course you need to consider the impact on your external internet bandwidth. And while you might allocate a quota - that won't be very helpful if when a student requires to use BYOD in the first lesson after lunch they can't because its all used up.I'm an advocate for BYOD really - but its not an end in itself. Delivering ICT skills needs to be the objective...and too often school management (and IT departments) somehow get side tracked into making the infrastructure the objective without nearly enough thought as to how to deliver those ICT skills (possibly because the teachers don't have those skills and are not capable of delivering them)And if you do not have Office 365 and Google Docs set up - with sync tools (free - except for the time to implement them) you will probably want to set these up.And you will probably want to think about printing and how to use Airserver/Chromecast so that BYOD devices can show their screens on a classroom projector. Its really very difficult to explain to students what to do if you can't actually show them. I like using QR codes with manufacturer's APPs for printing - as it saves 50 printers appearing in a dropdown list using Air print. Google's Cloud print is worth setting up too.Give yourself about a year to se this up. Its not a week of fortnight task - especially if you are still doing the day job of running a school computer system
Thanks for a very helpful post. I knew it is not going to be something simple and you have confirmed that.
Posted

We accomplished this by:

Setting up wifi that simply accessed the internet (filtered of course),

Setup a Citrix environment with a Netscaler,

Give users a URL to the Netscaler and instruction on installing the Citrix receiver,

Users then access a school desktop and print to their local printer.

 

Problem with this setup is the Citrix cost.

Posted
Because they search with Google which Is https and they can tunnel with https hide what they are doing

Which is why you need certificates on their BYOD devices - and block traffic that his "hidden". Then you can see (block and filter) all google searches - smoothwall for example will tell you exactly what they typed in when using https - and provide "prevent" information back to safeguarding leader based on this.

Posted
We accomplished this by:Problem with this setup is the Citrix cost.
This is going to be a deal breaker for us. We want to achieve this without spending any money on it. :-)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...