Jump to content

Recommended Posts

Posted

Staff - 802.1x secured SSID presented by Ruckus and authenticated against SmoothWall RADIUS

Students - Ruckus captive portal for authentication against AD, with RADIUS accounting packets passed to our SmoothWall for seamless filtering

Visitors - receptionist creates a guest pass via the Ruckus web portal - she can set the amount of devices, length of time - this is printed including instructions for connecting. Visitors connect to our visitors SSID and are then prompted for their guest pass

Posted
With BYOD using MSCHAPv2, how are you ensuring you staff are securing their devices against evil twin attacks?

 

The topic is about Guest WIFI and not BYOD.

Posted
With BYOD using MSCHAPv2, how are you ensuring you staff are securing their devices against evil twin attacks?
We do not allow students/staff onto our wireless that have twins. Problem solved
Posted

Hi Ian, here's a quote from the Cloudpath datasheet which answers your question about social media onboarding. Hope this helps.

 

Nick

SELF-SERVICE ONBOARDING AND DEVICE ENABLEMENT

 

Easy self-service onboarding ensures that users gain network access quickly and securely—without help desk involvement.

 

Optional pre-boarding lets users set their devices up for secure access before arriving at a given location

Device provisioning capability can prompt users to install specific software during onboarding

Customizable onboarding portal for guest access—including optional social login with Google, Facebook, LinkedIn and other popular identity providers

Guest credentials via email, SMS,or printed voucher

  • 4 weeks later...
Posted
Just running a guest SSID with a password with no authentication or tokens. Interested to hear what the benefits are of doing that, whether it's accountability/safeguarding etc or something else but likely for another topic.
If the password gets out, how do you stop the students connecting there laptops to this WiFi, skipping any monitoring? Stopping GPO's etc.
Posted

Heh, forcing people to be tracked by facebook, surely against human rights.

 

Guest Wifi here has a password that changes whenever anyone asks for it (it's rarely used and I forget what it is), ACLs to stop access to anything that's not dns or the internet, https inspection turned off, so just simple Exa filtering via transparent proxy

Posted (edited)

We use Meraki. I just create an SSID using Meraki NAT. We have a management VLAN that the Meraki access points are part of, and that IP range is then filtered through their own WebScreen policy.

 

At another school, Atomwide have just given me a completely separate range that I have configured on the MS250 layer 3 switch.

Edited by Zoom7000
Posted
Heh, forcing people to be tracked by facebook, surely against human rights.

 

Guest Wifi here has a password that changes whenever anyone asks for it (it's rarely used and I forget what it is), ACLs to stop access to anything that's not dns or the internet, https inspection turned off, so just simple Exa filtering via transparent proxy

 

How did you go about setting up your transparent proxy? This is something I'm looking into myself with a hotspot setup

Posted
How did you go about setting up your transparent proxy? This is something I'm looking into myself with a hotspot setup

 

Exa do it by default, but you can do it with most systems. Used IPCop before, also Fortigate does it, I assume everything does. Sophos have that free UTM for a few users.

  • Thanks 1
  • 1 month later...
Posted
We use Meraki's guest network settings with no password or even popup. Our head just wanted it as open and easy to use as possible and its still filtered safely via our lightspeed anyway. It helps because someone somewhere always has a device which dosnt like the popup screen (im looking at you kindle fire hd and Windows S with edge!).
Posted
We use Meraki's guest network settings with no password or even popup. Our head just wanted it as open and easy to use as possible and its still filtered safely via our lightspeed anyway. It helps because someone somewhere always has a device which dosnt like the popup screen (im looking at you kindle fire hd and Windows S with edge!).

 

This sounds very easy and straightforward for people connecting but how do you then look at a specific users Internet browsing habits in the event of a safeguarding concern?

Posted
well we don't as such. Our default web filtering is set to year 7 content and we are confident its safe along side restricted DNS for Youtube. Being a year 7 policy, all social media and email other than ours is blocked so don't expect any issue with safeguarding. Seems to work well.
Posted

I'd be quite concerned by that, if I'm honest. Even the best filtering systems in the world will let some things through, some of the time. Students may also access content that is allowed on your filtering system, that may be useful to build up a picture when investigating a safeguarding concern, e.g. searching for information and help about abuse in the home, Samaritans etc. Without these logs, you'd have to tell your safeguarding officer, an outside agency or the police you are unable to provide any information about a students browsing habits whilst connected to your Wi-Fi which may make it more difficult for those people to spot a concern or pattern; making it hard for them to support the child concerned. With authentication and logging in place, it may be that any logs you hand over just confirm that nothing sinister has taken place in school - but that's a really good thing and much better than saying "they shouldn't be able to access anything inappropriate as our Wi-Fi is filtered; but I can't confirm this for sure as we don't log their activity whilst connected to our Wi-Fi".

 

IMHO all Internet activity on school premises by any individual should be fully logged in order to meet your safeguarding obligations. If I were you I'd be asking your head to reconsider or to provide in writing instruction that he is happy to operate the system in this way.

Posted
IMHO all Internet activity on school premises by any individual should be fully logged in order to meet your safeguarding obligations. If I were you I'd be asking your head to reconsider or to provide in writing instruction that he is happy to operate the system in this way.

 

I agree with you on this. All of our internet browsing is authenticated to AD, even on BYOD, and our 1 day guest passes are to a named visitor in case of any misuse.

Posted
well we don't as such. Our default web filtering is set to year 7 content and we are confident its safe along side restricted DNS for Youtube. Being a year 7 policy, all social media and email other than ours is blocked so don't expect any issue with safeguarding. Seems to work well.

I'm not sure that complies with the rules for schools - we are supposed to engage in "monitoring" of internet activity as well as filtering. No logs means no monitoring?

Posted
Yes...the requirement is not (just) to block unsuitable material. The requirement is to monitor and to provide evidence of this...ie who did what and when...regardless of whether the material is appropriate. So, for example you might have reports of words used in searches...the fact that sites are subsequently blocked is not so important. And yes...you will need certificates on user devices to make this work. While headmasters wishes should be listened to, they are not above the law and demands of the governments prevent strategy, which you may need to educate him/her about.
Posted

The DfE has this covered in Keeping Children Safe in Education

 

Page 93 (my bold)

Governing bodies and proprietors should be doing all that they reasonably can to limit children’s exposure to the above risks from the school’s or college’s IT system. As part of this process, governing bodies and proprietors should ensure their school or college has appropriate filters and monitoring systems in place.

 

Whilst considering their responsibility to safeguard and promote the welfare of children, and provide them with a safe environment in which to learn, governing bodies and proprietors should consider the age range of their pupils, the number of pupils, how often they access the IT system and the proportionality of costs vs risks.

 

The appropriateness of any filters and monitoring systems are a matter for individual schools and colleges and will be informed in part, by the risk assessment required by

the Prevent Duty.

 

It directs schools to the UK Safer Internet Centre for guidance on what is appropriate filtering and monitoring

Appropriate Filtering and Monitoring - UKSIC

 

There are a number of Monitoring Strategies ... Not monitoring is not an option.

Posted

Now the question is who was using the ipad that went on the bad site?

 

Is everyone sharing John Smith's password?

 

I have a guest wifi that's not using https inspection, but it's not for use by children, only visitors to the school, and people who want voice to text in google docs to work (I assume it's blocking something, but as Chrome removed net-internals I don't know what)

  • 2 weeks later...
Posted

We have three BYOD networks, Students, Staff & Guest. All require a AD account to authenticate which means our Smoothwall can filter and log based on this. We create a AD account for each guest and all three BYOD networks have HTTPS inspection (So users must install the certificate). Guides are shown on the portal page when connecting.

 

Its time consuming creating the accounts but covers what DFE require and means all your filtering and logging is done by one system in one manor. If something does go wrong you want to find the information quickly.

Posted
Is it a requirement to log adult guest users?

 

My understand is all school traffic should be monitored. So any school guess is included in that.

 

For example, why shouldn't a guest working with a student be monitored? They could be alone with that student just like a member of staff.

 

The other thing is, how do you know that its a guest using the guest account and not a student? For me the decision was easy, monitor everything (Bar lettings which fall outside our school hours and thus are not school traffic) and make sure guests agree by connecting. Its both on the BYOD sign in page and the paper copy of their login I hand out to visitors.

Posted (edited)
Is it a requirement to log adult guest users?

 

We don't. One of ours schools won the 360 eSafety award and also outstanding in all areas with Ofsted. Both asked about guest access and didn't have any issues with the arrangement. Grant access via single use access cards and there is no audit log that we can track back to guest users. Prevent wouldn't cover guests.

Edited by FN-GM

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...