Jump to content

Recommended Posts

Posted

Hi all. Can any of you comment on what works for your schools to provide quick and easy wifi user connections for visitors such as speakers, parents, clubs and adhoc connections to schools. We are driven by security and governance that stipulates separation from all staff and all students. Amongst other things.

 

Any suggestions or comments appreciated. Jersey, Channel Islands Education.

Posted

Separate VLAN that has the gateway as our Smoothwall so they have no route to internal systems, dumps them straight to the Internet through our filtering.

 

Getting them signed in and connected is a whole different matter. We've looked at the Ruckus Cloudpath, and it looks really good, but for the few visitors we have it isn't cost effective, in my mind.

  • Thanks 1
Posted

Similar to the above.

 

However we generate guest passes and they sit on reception. Each has a unique code that can be used once. That why if does does get compromised it’s only good for a day.

  • Thanks 1
Posted

Yes our Visitor Vlan is entirely seperate from our Staff/student BYOD Vlan

 

We have

 

Main SSID - Domain joined devices only with no restrictions once on

Staff/student BYOD SSID - Smoothwall 802.11x SSID that allows Internet access with school username & Password - VLAN is locked off from main IT equipment & Intra device traffic blocked

Visitor SSID - Bog standard WPA2 protected SSID that allows visitors Internet access - VLAN is seperate from the BYOD network but still locked off/Intra device traffic blocked.

 

We did used to just put visitors on the BYOD network, but as smoothwall requires users to accept a certificate onto their devices that became a bit of a faf with other orgs bringing restricted devices into school.

  • Thanks 1
Posted

Separate your VLAN, put them on a separate SSID and have some way of authenticating who they are against what they're doing on your network.

 

Don't let schools just add visitors to your existing network. Security nightmare waiting to happen, and dangerous inevitable when presented with potential costs of good quality security systems.

  • Thanks 1
Posted

Ha Ha this is exactly our challenge.

"We used to just put visitors on the BYOD network, but as smoothwall[our thing isn't smoothwall but the same issue] requires users to accept a certificate onto their devices that became a bit of a faf with other orgs bringing restricted devices into school.

Posted

Thanks all. We have created generic user accounts that become tied to a visitor. Students use 'this' separate SSID/VLAN so it is subject to filtering/proxy/cert'. However the cert' installation is an issue for 50 people at reception!

So I guess you are all saying another ssid/vlan, (groan) with no cert'. Let's hope students and staff don't get access?

 

Anyone feel they can add....please don't hesitate. This is all really helpful.

Thanks

Jeremy

Posted

Yep, entirely separate VLAN, with web access only. Onboarding is always going to be a bit of a pain, especially if a certificate is involved for filtering. We have a page on our website that makes the cert available for download to devices, with instructions for adding it to Windows, Mac, iOS, Android and ChromeOS. I'm not sure I'd want guests to have unfiltered Internet access. I can't remember what the legal obligations are on that front.

 

Browsers are becoming more and more hostile/secure, though. Even just downloading the certificate in Chrome now needs a right-click save as, then a securty warning to dismiss and confirmation to keep the downloaded file. I get why, but it does mean that guests rarely do the certificate onboarding themselves.

  • Thanks 1
Posted

We have three;

 

Main - School domain joined devices only

BYOD - Student/Staff personal devices - 802.1x RADIUS Auth that gives access to internet. Staff personal devices don't get HTTPS inspection (no cert required), student devices do. We have very limited student devices on the WiFi so not really an issue there.

Guest - Ruckus Guest Pass system (Individual passes for each guest, or group of guests), internet access only. No HTTPS inspection.

  • Thanks 1
Posted
This is why I use single use guest pass codes.

 

Yup I recommend this too. We used to use a generic password for our guest access but it would always find its way into student hands, either something like a member of staff telling a guest in earshot of a student, emailing it etc.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...