maxrebo Posted February 12, 2020 Posted February 12, 2020 Just wondering what peoples procedures for allowing trainees and guest devices on to your network? We had a trainee teacher this morning asking to join our WiFi, her laptop AV was out of date and it got me thinking if i should allow it on? Whats everyone's view on this?. Bare in mind in my last school it was determined that it was a trainee teacher that brought in the Conficker virus and infected our entire network! We currently dont have our Wifi VLAN`d so its a flat network.
FragglePete Posted February 12, 2020 Posted February 12, 2020 We have an account we use for things like Open Evenings - it's where a visitor could use a computer so we also use this for visiting speakers, etc - it's based on a Student Credentials with limited access to network drives. Password is changed on a regular basis (usually after it's been used for an event, visitor, etc). Wireless devices are on a Guest Network WiFi SSID which we issue time limited passes for. Pete 1
foofighterjim Posted February 12, 2020 Posted February 12, 2020 We currently dont have our Wifi VLAN`d so its a flat network. Without addressing this issue then I would not permit any unmanaged device at all. 1
Davit2005 Posted February 12, 2020 Posted February 12, 2020 (edited) Terminating the Guest WiFi at the firewall should be straight enough to do. In basic form just create a layer 2 vlan for the SSID back to the firewall and ether set as side an interface or use the vlan. I used a separate interface when I done this about 10 years ago with SonicWall firewall and Ruckus WiFi. Then just make sure that vlan/interface is in its own zone or interface depending on how the firewall works to get the isolation. Then create the rules to permit the traffic needed/required. Edited February 12, 2020 by Davit2005
robyholmes Posted February 12, 2020 Posted February 12, 2020 VLAN for guest network (And isolated between clients). If they need access to school devices then we create a Visitor AD account which is locked down with no network drive access. Each visitor has an account made for them so our Smoothwall logs have their name in them. If you have multiple visitors on site and only use one account then you can't say who did what. 1
FishCustard Posted February 12, 2020 Posted February 12, 2020 Separate VLAN for guest WiFi, so no issue with unmanaged devices. For visitors logging on to school PCs we have a visitor AD account as above - no network drive access, machine and Internet access only. 1
ICT-Joe Posted February 12, 2020 Posted February 12, 2020 For guests, we have created a separate SSID which is on its own VLAN. Guests connect to it and then they're prompted to create a guest account, which one of us can then authorise (for a limited time too, if required). Filtering is done by Smoothwall. When guests sign in, they're prompted to agree to our AUP, which states that they must have up-to-date AV before we'll allow them on the network.
mavhc Posted February 12, 2020 Posted February 12, 2020 SSID for guests with ACL to only allow DNS and HTTP to WPAD server and external IPs. Question is why do they want access (internet? printing? more?), and why can't they use another computer?
free780 Posted February 12, 2020 Posted February 12, 2020 At a former. Job we actually had seperate DNS servers. ACLs protecting the subnets. Different subnets for student, staff, guests. These days I'm thinking you need a provision ssid where devices can Windows Update etc before they are allowed on.
mavhc Posted February 12, 2020 Posted February 12, 2020 As soon as they have write access to a shared drive you have ransomware problems though, be Mulder, trust no one 3
3s-gtech Posted February 12, 2020 Posted February 12, 2020 Our guest wifi is on a separate range which isn’t routed across to our main network, with client isolation too. It doesn’t break out on our network at all. I’ve been happy to allow free access for devices on there as a result, but we do encourage keeping them up to date. As we use NPS server, I wonder whether we can use filters to deny connections for unsupported OSs...
mavhc Posted February 12, 2020 Posted February 12, 2020 Problem with NPS is it relies on the computer itself to report if it's up to date, totally no way to lie about that
3s-gtech Posted February 12, 2020 Posted February 12, 2020 It’s certainly not foolproof, but wouldn’t it be easier to update than go to the trouble of faking having done so? For some odd reason, Windows 7 hasn’t been able to connect to our guest wifi for years. It’s now a ‘security measure’, yay!
FN-GM Posted February 12, 2020 Posted February 12, 2020 In 2020 I don’t think it’s an unreasonable request. I would look at setting up a Guest or BYOD network.
pete Posted February 13, 2020 Posted February 13, 2020 "Use the segregated guest network". Student teachers are issued a work laptop from the teaching school for the duration of their stay, so there's not much call for it.
chazzy2501 Posted February 13, 2020 Posted February 13, 2020 Just a reminder that VLANs are not a security tool, it is trivial to double wrap a packet to hop VLANs. I have a pair of very expensive Meraki APs for the 6th form, this works well as the AP NATs all of their traffic before it hits the VLAN. Meraki also have a feature that will VPN guest traffic from the AP to the firewall if you're especially security focused. I issue laptops to student teachers.
Kelechi93 Posted March 4, 2020 Posted March 4, 2020 It’s certainly not foolproof, but wouldn’t it be easier to update than go to the trouble of faking having done so? For some odd reason, Windows 7 hasn’t been able to connect to our guest wifi for years. It’s now a ‘security measure’, yay! I think the keyword here is "Windows 7"
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now