Jump to content

Recommended Posts

Posted

So, I'm all for asking questions today that I should probably know the answer to... but here goes!

 

The Head just waltzed into my room and casually asked why we don't have a guest wi-fi (because ALL the other schools have one and people from other schools are always asking for the wi-fi details when they come here)...

 

Well, short answer is - I've never actually been asked to get one set-up (in over 11 years).

 

Longer answer is I believe it may cost a bit (which is why I'm asking here), all our internal network is run on managed switches (supported by a third-party) and I'm pretty sure they will say adding a guest wi-fi SSID and securing it away from the rest of the network is going to be chargeable, everything is in VLANs at the moment, so I'm thinking it might have to be secured away on its own VLAN or something (as I wouldn't want it running through either of our staff or student SSIDs)?

 

There are also massive concerns (mine) over how well known this 'guest' wi-fi is going to become (with all the staff/govenors/visitors/parents) and as it is essentially on our network, what someone could do whilst on it.

 

I can see that is it probably going to be another massive thing to manage, but now I've been 'officially' asked to look into it, I can't hope it will quietly go away (even if the cost is going to be high) because ALL THE OTHER SCHOOLS HAVE IT...

Posted
We have it on it's own VLAN and use Radius via our Smoothwall for authentication. We have a Unifi AP wireless system. I create AD accounts for guests so they can login. However from a filtering point of view it's the same as the main network. Smoothwall still knows who you are and filters as need be.
Posted

When we had Ruckus we used Guest tokens to access the WIFI, worked really well as I could give reception access so they could create access tokens for visitors... separate VLAN as recommended above too.

 

Now we have UNIFI I have AD accounts which i give out.. again.. on a seperate VLAN Wifi.

 

We stick a disclaimer on the sign in page.. if you do anything naughty we are watching and just lock it down to only the ports they need.. doesn't take much to manage

Posted

We have unifi with a separate VLAN, but we use the Guest Voucher System built in too.

 

We print out a stock of the vouchers for reception and they give them out when visitors come and request WiFi access

Posted
What Wi-Fi solution do you have?

 

It's a very old Cisco system, I don't know a great deal about it unfortunately as it is all managed, I have never really had much to do with it apart from plugging in the odd cable...

 

There are currently two SSIDs being pushed out from the wireless controller all dealt with on the switch side of things (which also deals with DNS).

 

Do I really need to have any kind of certificates/vouchers/Radius/authentication/AD accounts...?

 

I am being naive in thinking they just get given a wi-fi password and off they go?

 

I will also have to look at the filtering side of things (with LGfL) as these are currently filtered on the IP address scope of the VLANs.

Posted
It's a very old Cisco system, I don't know a great deal about it unfortunately as it is all managed, I have never really had much to do with it apart from plugging in the odd cable...

 

There are currently two SSIDs being pushed out from the wireless controller all dealt with on the switch side of things (which also deals with DNS).

 

Do I really need to have any kind of certificates/vouchers/Radius/authentication/AD accounts...?

 

I am being naive in thinking they just get given a wi-fi password and off they go?

 

I will also have to look at the filtering side of things (with LGfL) as these are currently filtered on the IP address scope of the VLANs.

 

On my Cisco WLC I created an ACL so devices on the guest ssid could only access the router, and dns server. Set the WLC to give out DHCP IPs in a different range, and the router to output their traffic on a different IP, so the Exa Surfprotect could be set to not MITM the SSL.

 

Then I change the password every so often to annoy people.

  • Thanks 1
Posted
We have a Unifi system but don't have the guest login section enabled, but do use the guest mode, which keeps the traffic sperate, this means we can just give out the WiFi password and off they go. We also have Smoothwall set to default all none proxied traffic the same as the students traffic, so the guest doesn't need to worry about proxy stuff either.
Posted
We have a Unifi system but don't have the guest login section enabled, but do use the guest mode, which keeps the traffic sperate, this means we can just give out the WiFi password and off they go. We also have Smoothwall set to default all none proxied traffic the same as the students traffic, so the guest doesn't need to worry about proxy stuff either.
Could you elaborate on your smoothwall setup? I presume smoothwall is the default route for all external traffic, have you setup an additional transparent proxy ? All unauthenticated requests just get the same filtering as students?
Posted (edited)
So, I'm all for asking questions today that I should probably know the answer to... but here goes!

 

The Head just waltzed into my room and casually asked why we don't have a guest wi-fi (because ALL the other schools have one and people from other schools are always asking for the wi-fi details when they come here)...

 

Well, short answer is - I've never actually been asked to get one set-up (in over 11 years).

 

Longer answer is I believe it may cost a bit (which is why I'm asking here), all our internal network is run on managed switches (supported by a third-party) and I'm pretty sure they will say adding a guest wi-fi SSID and securing it away from the rest of the network is going to be chargeable, everything is in VLANs at the moment, so I'm thinking it might have to be secured away on its own VLAN or something (as I wouldn't want it running through either of our staff or student SSIDs)?

 

There are also massive concerns (mine) over how well known this 'guest' wi-fi is going to become (with all the staff/govenors/visitors/parents) and as it is essentially on our network, what someone could do whilst on it.

 

I can see that is it probably going to be another massive thing to manage, but now I've been 'officially' asked to look into it, I can't hope it will quietly go away (even if the cost is going to be high) because ALL THE OTHER SCHOOLS HAVE IT...

 

Depends what you have setup, we have aruba wireless and clearpass and can do roles on the controllers then tie down the roles via ACLs. The WiFi is all on a different firewall zone so is very easy to manage access.

 

But a different vlan terminated on the firewall would be a start then only allow specific traffic to your internal network where required.

 

Switching wise at the most would include setting up the vlan on the ports then let the firewall do the routing.

 

I have used a Ruckus system before which had it's own captive portal which worked well.

 

Bear in mind with Unifi that if the controller is down there is no Unifi captive portal unless they have changed that.

Edited by Davit2005
Posted

We have a cambium system, and have vouchers printed and left at reception. You can specify an expiry date, how long the voucher is active once used, how many devices it can be used on, and whether its locked only to those devices.

 

All quite swish and easy to use. We've done 3 types of vouchers - 1 day, 5 day and let-ins.

 

Underneath, its on its own vlan, and users get the default student filtering, so if a student gets a card they can't do that much. We only allow some students wifi access on personal devices.

Posted
We have a Unifi system but don't have the guest login section enabled, but do use the guest mode, which keeps the traffic sperate, this means we can just give out the WiFi password and off they go. We also have Smoothwall set to default all none proxied traffic the same as the students traffic, so the guest doesn't need to worry about proxy stuff either.

 

very sorry but all our internet traffic is routed through our LA who manage the Smoothwall system, I don't have any access to it.

 

I'm getting on to our LA after 1/2 term to see if we can get that. Would make Guest access so much easier!

 

There have been a few (still ongoing) problems with our Smoothwall, so I'll give the LA team a week of peace first.

Posted

Just a reminder that VLANs offer NO security they're for managing traffic, it is trivial to "hop" vlans.

 

The Meraki APs are the best I've seen as it can not only NAT the traffic at the access point (what I use) but if you're really paranoid it can setup a VPN between the AP and the Meraki Firewall.

 

I only have pair of Meraki APs (as they cost loads of money) this is for open facebook wifi for the 6th form study areas.

 

I also have staff guest (with a key) using unifi and this is on a vlan to a domestic vdsl but it is only issued to staff and agency workers.

Posted

So, this could work in the most simple terms (because I haven't finished my coffee yet) on a managed system with old Cisco Switches and WLCs (already with VLANs), by asking them to set up what exactly?

 

Divide up an already existing VLAN on the switches (say VoIP as we don't use that), get the WLC to broadcast the guest SSID, have DHCP on the switches give out a set of IPs (possibly utilise an ACL) and pass data to directly to the router (making sure it can't speak to the rest of the network)?

 

the trouble I'm going to have is that the switches are managed (but really only on a break-fix support contract) and everything else is chargeable. So no way to mess about if I need to change the ACL or the SSID password every month...

Posted
Just a reminder that VLANs offer NO security they're for managing traffic, it is trivial to "hop" vlans.

 

Can you expand on this please? On a network setup properly you cannot just hop between a guest and main production VLAN.

  • Thanks 1
Posted

This was something I had wondered...

 

Obviously I shouldn't need to tell the support company, but I would need to make sure that everything stays secure.

 

We have the whole network split into VLANs (for wi-fi [student and admin] for the physical network connections [student and admin] for the servers and printers, and for VoIP - which isn't utilised here).

 

All these networked devices can obviously 'speak' to each other across the VLANs (through some networking magic) as obviously we can access the server, print and I can RD onto any PC or laptop...

 

So the VLAN used for the guest wi-fi would have to be secured against any of that.

Posted

to hop vlans you double wrap a packet. The switches just dumbly remove the vlan wrapper on the packet, if a packet smith double wraps a packet the switch will double unwrap it. (with no security checks) then the packet essentially hops to another vlan. Good for ARP poisoning etc.

 

I heard it in a security now episode years ago some my terminology may not be correct. but the idea that VLANs like mac address filtering should never be used for security is well known.

Posted (edited)

 

So the VLAN used for the guest wi-fi would have to be secured against any of that.

 

By default Cisco (and I think every other vendor) allows unrestricted communication between Layer 3 VLANS. 9 / 10 times this is what people desire.

 

To stop this you can do 2 things

 

1. Place an Access Control List on the VLAN to prevent access to anything that has a private IPv4 address. You can add exceptions for things like DHCP & DNS. I use public DNS on guest networks so you don’t reveal IP addresses of internal devices. This assumes that you’re not using public IP addresses on internal devices.

 

2. Use a layer 2 VLAN and terminate this straight onto your firewall. The traffic isn’t routed at all on the switch.

 

You can also do some access restrictions on some WIFI systems. This is a little hit and miss.

Edited by FN-GM
  • Thanks 3
Posted
to hop vlans you double wrap a packet. The switches just dumbly remove the vlan wrapper on the packet, if a packet smith double wraps a packet the switch will double unwrap it. (with no security checks) then the packet essentially hops to another vlan. Good for ARP poisoning etc.

 

I heard it in a security now episode years ago some my terminology may not be correct. but the idea that VLANs like mac address filtering should never be used for security is well known.

 

You can prevent this happening by correctly configuring your switches.

 

Suggesting that vLANs are as insecure as MAC Address filtering for access control of WiFi isn't true.

 

To suggest it is well known that vLANs shouldn't be used for security is also not true.

  • Thanks 1
Posted (edited)
to hop vlans you double wrap a packet. The switches just dumbly remove the vlan wrapper on the packet, if a packet smith double wraps a packet the switch will double unwrap it. (with no security checks) then the packet essentially hops to another vlan. Good for ARP poisoning etc.

 

If you configure switches correctly this won’t happen. This is the prime reason you should never use the native VLAN ( default VLAN 1). It’s surprising how many people do this. I have seen accidentally VLAN hopping when someone placed a DHCP server in the native VLAN. It dished out IP addresses to all other VLANS. That was fun!

 

Dynamic ARP Inspection is quite good for ARP attacks. If there is anything other that the IP and MAC the device should have it will shutdown the port. You should be careful with this as some software (such as LanSchool) spoof the MAC address of devices.

Edited by FN-GM
Posted (edited)
to hop vlans you double wrap a packet. The switches just dumbly remove the vlan wrapper on the packet, if a packet smith double wraps a packet the switch will double unwrap it. (with no security checks) then the packet essentially hops to another vlan. Good for ARP poisoning etc.

 

I heard it in a security now episode years ago some my terminology may not be correct. but the idea that VLANs like mac address filtering should never be used for security is well known.

 

There are a number of mitigation options depending on the switches you use and the features they provide.

 

DHCP snooping is another easily deploy-able option and can save a lot of headaches.

Edited by Davit2005
Posted

At my last school I implemented guest WiFi after a similar conversation, ie everyone has it, why don't we?

 

The specific example was for people coming from NHS and LA who were on working visits.

 

Obviously I did it, but all the while grumbling to myself "what kind of organisation sends people out to work at remote sites without providing an independent way of accessing the internet?"

 

And for governors "out of people who want to bring their own mobile device to meetings, who doesn't have a phone which can run a hotspot?"

 

Eight years ago it would have seemed reasonable, but with the current price of data packages and with full strength 4G signal, it seems unnecessary to me.

 

Rant over [emoji57]

  • Like 1
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...