Jump to content

Recommended Posts

Posted

We're in the process of writing a tender for a new wireless network to be put in. I'm curious to see how other schools handle guest wifi and how they provision users on it.

 

This isn't a question about technology stacks. I don't care if you use Meraki, Ubiquiti, Aruba, Meru, Ruckus, Huawei, TPLink, Netgear or Crazy Joe's House of Wifi, that's irrelevant so let's head that one off at the pass now. I'm more interested in how you're managing guest users, how you're provisioning them, how they're being registered for the guest network and what the approval process is, if there is one.

 

Thanks :)

Posted

Our guest network is an open network. When a user connects the web interface opens and they are asked for a code.

We generate codes in bulk. Using Photoshop mail merge we then create access cards with a unique code on each. The card also has basic instructions. Receptionists then issue the cards to guests.

  • Thanks 1
Posted
We have a BYOD network that students/staff log into using their AD accounts through Radius. External guests are registered manually by us on a portal for a one-day, three-day or five-day login, which automatically expires after that period of time.
  • Thanks 1
Posted
Just running a guest SSID with a password with no authentication or tokens. Interested to hear what the benefits are of doing that, whether it's accountability/safeguarding etc or something else but likely for another topic.
Posted
Our guest network is an open network. When a user connects the web interface opens and they are asked for a code.

We generate codes in bulk. Using Photoshop mail merge we then create access cards with a unique code on each. The card also has basic instructions. Receptionists then issue the cards to guests.

 

This.

 

We use Sophos XG to do this also. not HTTPS scanning also

Posted
Just running a guest SSID with a password with no authentication or tokens. Interested to hear what the benefits are of doing that, whether it's accountability/safeguarding etc or something else but likely for another topic.

 

The problem with that is the possibility of the password leaking, then students who aren't supposed to have access to the WLAN getting onto it.

 

Can people go into a bit more detail? Are you using something like Clearpass to generate the unique codes?

  • Thanks 1
Posted
Are you using something like Clearpass to generate the unique codes?

 

It is all built into our Ruckus system. No need for a third party. The codes we generate expire 24 hours after they are used as well. It minimises the risks of students using the guest WIFI.

  • Thanks 1
Posted

We create SSIDs for large groups with one password for them to use.

 

As soon as the group leaves we delete it or change the password if we would need to use it again.

 

Any long term users get added to the school guest SSID via us putting in thee password for them.

Posted

Our Sophos xg allows us to generate "cards" that we issue to guest users.

 

The cards only works for a time/data based period and then the user will need another one. The wifi is "open" and anybody can connect to it...... but they all get redirected to the "enter voucher" to continue. You can also limit the number devices each card can be assigned to.

Posted

WE have to logon to our Meraki portal and create a guest user; we enter their name and email address and it generates a random password.

 

A password sheet can be printed off and handed to the guest.

 

 

I'd like our reception team to do this, but apparently it should not fall under their remit as it's and IT issue....!!!

Posted
Just running a guest SSID with a password with no authentication or tokens. Interested to hear what the benefits are of doing that, whether it's accountability/safeguarding etc or something else but likely for another topic.

 

It's definitely around safeguarding and accountability for us. If the access is misused in some way, how do you prove who has done what?

  • Thanks 1
Posted

For the people who use the vouchers, are you tracking who the vouchers get issued to in any way or is it just a case of "There you go, fill your boots"?

 

This is all very useful, thankyou to everyone who has posted so far.

Posted (edited)

we are using facebook connect. So anyone with a facebook account can use our guest wifi. it's only available in some areas and the radio power is limited. it also makes users check in to our facebook page.

 

EDIT: as most users are already logged into facebook on their personal device, they just press a button to join. Also people get a sense that they are monitored.

Edited by chazzy2501
Posted
For the people who use the vouchers, are you tracking who the vouchers get issued to in any way or is it just a case of "There you go, fill your boots"?

 

This is all very useful, thankyou to everyone who has posted so far.

 

Its the latter for us. It was determined there is no need to monitor the access of external parties as they are not covered by prevent. The connection is filtered anyway so they can't access stuff like adult sites etc.

  • Thanks 1
Posted
The hotspot manager shows which device used a token, shows b/w etc. Other than that it is just a case of "free internets" we don't even set b/w limits (maybe I should...)
  • Thanks 1
Posted
For the people who use the vouchers, are you tracking who the vouchers get issued to in any way or is it just a case of "There you go, fill your boots"?

 

This is all very useful, thankyou to everyone who has posted so far.

 

It's a fill your boots scenario here.

 

Staff and students are forbidden access to the guest network and its in our AUP/policies.

 

This is also on the terms of the voucher page that the user sees and "acknowledges" and on the polices sheets they get provided with their voucher.

 

It has all the usual stuff blocked, adult content, gambling etc etc but allows guests to use protocols normally blocked on our internal network. So they can connect to their remote desktop session at there place of work for example.

 

It's primarily provided as a means to get emails and casual web browsing. It has a bandwidth limit also that stops people streaming all day.

 

We also use it if we have a conference on where we might have 80+ external users that absolutely "need" a non 4G internet connection. However we then change the mode of operation from "voucher" to "password of the day" so we don't need to print of 80+ vouchers!

  • Thanks 1
Posted
we are using facebook connect. So anyone with a facebook account can use our guest wifi. it's only available in some areas and the radio power is limited. it also makes users check in to our facebook page.

 

EDIT: as most users are already logged into facebook on their personal device, they just press a button to join. Also people get a sense that they are monitored.

 

That's actually an interesting idea. Can you use other ID providers other than Facebook? I mean, if you could use (say) Twitter, Azure/O365, standard MS and Google along with Facebook that would cover most bases. One question though, can you (or do you) stop students from using guest wifi? What's to stop them from using their FB accounts to access your wifi?

Posted
Unifi Hotspot manager generates the tokens for us, you can set time, limits etc. It's all built into their software

 

This is what we do. Admin office has a stack of tokens which are single use and good for one day only. Connecting to the guest network and then opening a browser brings up a page with conditions and basic instructions on setting the proxy and asks for a voucher code.

 

Have only once been called to sort out problems with this, and I suspect that the problems were not reading the page followed by most of the then required URLS being in someone else's walled garden and hence being unavailable. (Though I suspect that many think, "I don't understand this proxy stuff. Think I'll just use my phone.")

  • Thanks 1
Posted

Ruckus Guest passes Generated by either us in IT or Reception, on a separate VLAN and no HTTPS inspection and very lightly filtered network.

BYOD is more a pain in the but with mobile devices because we have to do https inspection but that's another thread

Posted
I think you may need to expand your remit from just wireless...to how guest accounts are handled across the network. Its not just that might require access to the internet (in fact they can probably do that with 4G with less hassle) You may require them to have access to ...say ...airserver so that they can show their screen on a projector if they are giving a talk, or being able to print something...and those things might tie into rules to tranverse VLANs. Or there might be data on your network you need to give them (read only) access to. So I would make them use the wireless the same way as students and staff - with AD logins albeit temporary ones, which assign them to suitable (visitor)groups which have appropriate permissions depending on their guest status. Weird and wonderful guest vouchers and login portals are fine if its just internet access you want to give them...but my experience is their reason to connect to your network will be potentially more than that.
Posted

Nothing remotely as interesting as the above here, we're a primary.... we just have a guest SSID + password. The password is changed termly.

 

The guest SSID has the same level of Internet access as the regular wifi, but without local LAN access, so it's not really to the children's benefit to join it. I did look into giving more access (visitors are always trying and failing to check their email on it), but that would involve VLAN routing that we don't have the capability for currently.

Posted
I think you may need to expand your remit from just wireless...to how guest accounts are handled across the network. Its not just that might require access to the internet (in fact they can probably do that with 4G with less hassle) You may require them to have access to ...say ...airserver so that they can show their screen on a projector if they are giving a talk, or being able to print something...and those things might tie into rules to tranverse VLANs. Or there might be data on your network you need to give them (read only) access to. So I would make them use the wireless the same way as students and staff - with AD logins albeit temporary ones, which assign them to suitable (visitor)groups which have appropriate permissions depending on their guest status. Weird and wonderful guest vouchers and login portals are fine if its just internet access you want to give them...but my experience is their reason to connect to your network will be potentially more than that.

 

Yeah, no thanks.

 

People who aren't a member of the organisation are not going to have access to any part of our production network. If a guest needs to print something off, they can email the work to a member of staff. Being able to allow guests to cast to an AppleTV is actually relatively trivial to achieve. The sole reason for people to connect to our guest wifi is to get onto the internet, not to the internal network and that's not about to change.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...