soapyfish Posted September 27, 2022 Posted September 27, 2022 To the collective hive mind....opinions and advice please Our network is broken into several VLANs one of which is the core network and another is the BYOD network where student's devices and staff phones reside. as a result we have mix of windows, apple and android devices. All students and staff are encouraged to have firewalls and anti virus etc on their devices before connecting them to the BYOD network. However I am thinking about malware and virus's that may be present on the BYOD VLAN and potentially what can be done to reduce the risk to one use from another on that VLAN. What measures do others take to dealing with this situation?
mrbios Posted September 27, 2022 Posted September 27, 2022 Enable "Client Device Isolation" Most if not all enterprise WiFi solutions should have something like that. So long as you don't have any devices on there that need to talk to each other, that should do the trick as far as I'm aware. 4
soapyfish Posted September 27, 2022 Author Posted September 27, 2022 (edited) Do you know how robust this is, I know our setup does allow this. https://docs.ruckuswireless.com/unleashed/200.1.9.12/t-ConfigClientIsolationWhitelist.html It looks like it will be a good start Edited September 27, 2022 by soapyfish
3s-gtech Posted September 27, 2022 Posted September 27, 2022 Enable "Client Device Isolation" Most if not all enterprise WiFi solutions should have something like that. So long as you don't have any devices on there that need to talk to each other, that should do the trick as far as I'm aware. “Can they print?” “We need them to connect to the AppleTVs!” Those are the downsides (and upsides!) Client device isolation should do what you want if it’s not on already. 1
soapyfish Posted September 27, 2022 Author Posted September 27, 2022 They only need access to internet based services so it sounds like client isolation is the way forward.
Davit2005 Posted September 28, 2022 Posted September 28, 2022 In that case create an ACL or if the BYOD is separated at the firewall use firewall rules to only specific services where necessary. At cost there are methods to use posture checking, etc. if you want to allow BYOD devices to access internal services and limit risk but I'd still separate by ACLs or firewall rules. 1
Chuckster Posted September 28, 2022 Posted September 28, 2022 My school's network is also broken up in to several VLANS. Most notably is our BYOD LAN which is different to the rest of the other VLANS. The firewall issues any DHCP and DNS requests to the BYOD LAND, thereby preventing any devices from ever touching the internal network. The school's wi-fi is approx. 8 years old and as a consequence we aren't able to do 'client isolation'. Other than that, it's all good. 2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now