Jump to content

Recommended Posts

Posted

Just wondering what peoples procedures for allowing trainees and guest devices on to your network?

We had a trainee teacher this morning asking to join our WiFi, her laptop AV was out of date and it got me thinking if i should allow it on?

 

Whats everyone's view on this?.

 

Bare in mind in my last school it was determined that it was a trainee teacher that brought in the Conficker virus and infected our entire network!

 

We currently dont have our Wifi VLAN`d so its a flat network.

Posted

We have an account we use for things like Open Evenings - it's where a visitor could use a computer so we also use this for visiting speakers, etc - it's based on a Student Credentials with limited access to network drives. Password is changed on a regular basis (usually after it's been used for an event, visitor, etc).

 

Wireless devices are on a Guest Network WiFi SSID which we issue time limited passes for.

 

Pete

  • Thanks 1
Posted (edited)
Terminating the Guest WiFi at the firewall should be straight enough to do. In basic form just create a layer 2 vlan for the SSID back to the firewall and ether set as side an interface or use the vlan. I used a separate interface when I done this about 10 years ago with SonicWall firewall and Ruckus WiFi. Then just make sure that vlan/interface is in its own zone or interface depending on how the firewall works to get the isolation. Then create the rules to permit the traffic needed/required. Edited by Davit2005
Posted
VLAN for guest network (And isolated between clients). If they need access to school devices then we create a Visitor AD account which is locked down with no network drive access. Each visitor has an account made for them so our Smoothwall logs have their name in them. If you have multiple visitors on site and only use one account then you can't say who did what.
  • Thanks 1
Posted

Separate VLAN for guest WiFi, so no issue with unmanaged devices.

 

For visitors logging on to school PCs we have a visitor AD account as above - no network drive access, machine and Internet access only.

  • Thanks 1
Posted
For guests, we have created a separate SSID which is on its own VLAN. Guests connect to it and then they're prompted to create a guest account, which one of us can then authorise (for a limited time too, if required). Filtering is done by Smoothwall. When guests sign in, they're prompted to agree to our AUP, which states that they must have up-to-date AV before we'll allow them on the network.
Posted

SSID for guests with ACL to only allow DNS and HTTP to WPAD server and external IPs.

 

Question is why do they want access (internet? printing? more?), and why can't they use another computer?

Posted
At a former. Job we actually had seperate DNS servers. ACLs protecting the subnets. Different subnets for student, staff, guests. These days I'm thinking you need a provision ssid where devices can Windows Update etc before they are allowed on.
Posted
Our guest wifi is on a separate range which isn’t routed across to our main network, with client isolation too. It doesn’t break out on our network at all. I’ve been happy to allow free access for devices on there as a result, but we do encourage keeping them up to date. As we use NPS server, I wonder whether we can use filters to deny connections for unsupported OSs...
Posted

It’s certainly not foolproof, but wouldn’t it be easier to update than go to the trouble of faking having done so?

 

For some odd reason, Windows 7 hasn’t been able to connect to our guest wifi for years. It’s now a ‘security measure’, yay!

Posted

"Use the segregated guest network".

 

Student teachers are issued a work laptop from the teaching school for the duration of their stay, so there's not much call for it.

Posted

Just a reminder that VLANs are not a security tool, it is trivial to double wrap a packet to hop VLANs.

 

I have a pair of very expensive Meraki APs for the 6th form, this works well as the AP NATs all of their traffic before it hits the VLAN. Meraki also have a feature that will VPN guest traffic from the AP to the firewall if you're especially security focused.

 

I issue laptops to student teachers.

  • 3 weeks later...
Posted
It’s certainly not foolproof, but wouldn’t it be easier to update than go to the trouble of faking having done so?

 

For some odd reason, Windows 7 hasn’t been able to connect to our guest wifi for years. It’s now a ‘security measure’, yay!

 

I think the keyword here is "Windows 7" :doh:

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...