Jersey_EDU Posted October 21, 2021 Posted October 21, 2021 Hi all. Can any of you comment on what works for your schools to provide quick and easy wifi user connections for visitors such as speakers, parents, clubs and adhoc connections to schools. We are driven by security and governance that stipulates separation from all staff and all students. Amongst other things. Any suggestions or comments appreciated. Jersey, Channel Islands Education.
TechMonkey Posted October 21, 2021 Posted October 21, 2021 Separate VLAN that has the gateway as our Smoothwall so they have no route to internal systems, dumps them straight to the Internet through our filtering. Getting them signed in and connected is a whole different matter. We've looked at the Ruckus Cloudpath, and it looks really good, but for the few visitors we have it isn't cost effective, in my mind. 1
FN-GM Posted October 21, 2021 Posted October 21, 2021 Similar to the above. However we generate guest passes and they sit on reception. Each has a unique code that can be used once. That why if does does get compromised it’s only good for a day. 1
DrCheese Posted October 21, 2021 Posted October 21, 2021 Yes our Visitor Vlan is entirely seperate from our Staff/student BYOD Vlan We have Main SSID - Domain joined devices only with no restrictions once on Staff/student BYOD SSID - Smoothwall 802.11x SSID that allows Internet access with school username & Password - VLAN is locked off from main IT equipment & Intra device traffic blocked Visitor SSID - Bog standard WPA2 protected SSID that allows visitors Internet access - VLAN is seperate from the BYOD network but still locked off/Intra device traffic blocked. We did used to just put visitors on the BYOD network, but as smoothwall requires users to accept a certificate onto their devices that became a bit of a faf with other orgs bringing restricted devices into school. 1
paulkerton Posted October 21, 2021 Posted October 21, 2021 Separate your VLAN, put them on a separate SSID and have some way of authenticating who they are against what they're doing on your network. Don't let schools just add visitors to your existing network. Security nightmare waiting to happen, and dangerous inevitable when presented with potential costs of good quality security systems. 1
Jersey_EDU Posted October 21, 2021 Author Posted October 21, 2021 Ha Ha this is exactly our challenge. "We used to just put visitors on the BYOD network, but as smoothwall[our thing isn't smoothwall but the same issue] requires users to accept a certificate onto their devices that became a bit of a faf with other orgs bringing restricted devices into school.
Jersey_EDU Posted October 21, 2021 Author Posted October 21, 2021 Thanks all. We have created generic user accounts that become tied to a visitor. Students use 'this' separate SSID/VLAN so it is subject to filtering/proxy/cert'. However the cert' installation is an issue for 50 people at reception! So I guess you are all saying another ssid/vlan, (groan) with no cert'. Let's hope students and staff don't get access? Anyone feel they can add....please don't hesitate. This is all really helpful. Thanks Jeremy
DrCheese Posted October 21, 2021 Posted October 21, 2021 Let's hope students and staff don't get access? Just cycle the key on a regular basis & keep an eye on the amount of devices on that SSID.
jthompson Posted October 21, 2021 Posted October 21, 2021 Yep, entirely separate VLAN, with web access only. Onboarding is always going to be a bit of a pain, especially if a certificate is involved for filtering. We have a page on our website that makes the cert available for download to devices, with instructions for adding it to Windows, Mac, iOS, Android and ChromeOS. I'm not sure I'd want guests to have unfiltered Internet access. I can't remember what the legal obligations are on that front. Browsers are becoming more and more hostile/secure, though. Even just downloading the certificate in Chrome now needs a right-click save as, then a securty warning to dismiss and confirmation to keep the downloaded file. I get why, but it does mean that guests rarely do the certificate onboarding themselves. 1
Chaniel Posted October 21, 2021 Posted October 21, 2021 We have three; Main - School domain joined devices only BYOD - Student/Staff personal devices - 802.1x RADIUS Auth that gives access to internet. Staff personal devices don't get HTTPS inspection (no cert required), student devices do. We have very limited student devices on the WiFi so not really an issue there. Guest - Ruckus Guest Pass system (Individual passes for each guest, or group of guests), internet access only. No HTTPS inspection. 1
FN-GM Posted October 21, 2021 Posted October 21, 2021 Let's hope students and staff don't get access? This is why I use single use guest pass codes.
Chaniel Posted October 21, 2021 Posted October 21, 2021 This is why I use single use guest pass codes. Yup I recommend this too. We used to use a generic password for our guest access but it would always find its way into student hands, either something like a member of staff telling a guest in earshot of a student, emailing it etc.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now