Jump to content

Recommended Posts

Posted

Hi

 

Sorry if this questions has been asked a million times before.

 

We're trying to advertise a guest WIFI using Meraki wireless across a secondary school. Unfortunately our schools' internet and firewall is provided by a managed service provider where SSL inspection is turned on.

 

If we were to advertise a guest WIFI we'd have to install this certificate on all guest devices (Iphone, Android etc) so that the user does not receive certificate errors.

 

If i use a Radius server, will i be able to use this to install the certificate on the guest device or prompt them that they need to install it? I've had a look into it and just don't understand how to go about doing this!

 

Many thanks :D

Posted
I don't see why you can't put the certificate on a website that just uses http and make it the default page for those connecting to meraki. You cant force them to load the certificate and they will get warnings about potential privacy... But you can explain in text on that page why thay need to both load it and enable it in ios devices before https websites will workm
Posted
Previously I put a hyperlink to the certificate file on the captive portal, the certificate file was stored on a web server where they could get to from the portal page.
  • 1 month later...
Posted
I'd ask your MSP to open it for a specific subnet. Waste of resources tbh, inspecting guest traffic

 

I was under the impression that as a school, we had to appropriately filter and inspect all traffic on our network - be it a student, staff member or guest. Do you have information on the contrary, as i'd love to not have to deal with guests and security certs'.

Posted

Blocking isn't sufficient, you need to do user level reporting.

 

Our guest traffic is HTTPS inspected - don't like it then use your 4G.

  • 2 weeks later...
Posted

There is simply no excuse not to have certificates installed - because without them you won't be able to produce any reports of which students (and staff?)went where or when.

 

We are not (only) being asked to "BLOCK" sites...indeed it can often be more informative not to block some sites and analyse the results with a view to challenging and asking students (and possibly staff) why they thought it was acceptable or necessary to use these sites. No; clearly some classes of sites just need blocking. But others are a disciplinary offence.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...