Jump to content

Recommended Posts

Posted
Even with SSL inspection in place (for now), VPNs are still a huge issue on student BYOD networks, plus all the apps it breaks. And studnets can just switch to 4G (or tethering) and get access to whatever they want. So although it's great to put what measures we can in place, it still feels like a loosing battle.
  • Thanks 1
Posted
Even with SSL inspection in place (for now), VPNs are still a huge issue on student BYOD networks, plus all the apps it breaks. And studnets can just switch to 4G (or tethering) and get access to whatever they want. So although it's great to put what measures we can in place, it still feels like a loosing battle.

 

Which begs the question - are you safeguarding more by opening up your wifi and reducing barriers such as a MITM certificate, or are you safeguarding more by inspecting everything and encouraging users to circumvent your efforts?

Posted
There is a certainly a problem with 3G/4G devices...especially as contracts now regularly have multi gigabit allowances....and are often capable of delivering higher speeds to clients than through a shared WiFi connection. I've always argued that student phones should be subject to both parental and school monitoring, and government need to wake up to do something about this. Children need to be monitored for their safety and to educate - about bullying etc. Perhaps we should be allowed to use 3G/4G blockers in school...(and prisons...) . And yes there is a problem with VPNs (which firewall/web filters are poor at blocking...often a completely open door) ...and yes there is a problem with generic unmoderated content delivery servers which can contain the most useful educational material - and at the same time - contain the most vile content. And yes all these "holes" make us wonder why we are often paying thousands of pounds a year - when a "free" DNS filter would be almost as good. (or bad...depending on your point of view)
Posted
I'm currently having issues with Windscribe and TorGuard on our BYOD network. I'm feeling that having a safe browsing environment and a BYOD policy are mutually exclusive.
Posted
Can I ask how you prevent pupils signing on to the guest system to access things they are filtered from on the student network?
We only turn it on for specific guests and change the password each time.
Posted

We can do nothing about 3G/4G except educate the parents and insist on the teenage filter with contracts.

 

Tethering we prevent by using the Meraki Air Marshall and repeatedly killing hotspots.

Posted
Can I ask how you prevent pupils signing on to the guest system to access things they are filtered from on the student network?
We have one time pass codes. Reception hands it to the guest, they connect and that is it. After this it doesn't work so it doesn't matter if it gets left hanging around.

 

After 24 hours they will need a new code.

Posted
We have one time pass codes. Reception hands it to the guest, they connect and that is it. After this it doesn't work so it doesn't matter if it gets left hanging around.

 

After 24 hours they will need a new code.

Out of interest, do you leave the SSID open or does the user have to authenticate via WPA2 first?
Posted
Out of interest, do you leave the SSID open or does the user have to authenticate via WPA2 first?

 

It is open and there is a captive portal where you type the code.

  • Thanks 1
Posted
Out of interest, do you leave the SSID open or does the user have to authenticate via WPA2 first?

 

We’ve recently added a password to our byod network so the wireless traffic is encrypted. A guest still then needs to use the captive portal and a token. Hasn’t caused us any issues as yet.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...