jonnykewell1 Posted October 10, 2022 Posted October 10, 2022 Good afternoon, We had some reports of slow BYOD wifi in our Post 16 college and after looking into it the problem, I discovered that it was actually the content that wasn't loading for social media apps that students have on their phone.The apps opened but then the web filter kicked in and did its job but as an end user the app just tries to connect and doesn't provide any kind of blocked page. As a result the students then reported slow wifi, turned off their wifi on their phone and used mobile data to access the social media. It's worth notice that controls are in place in the classroom and this is only in the social areas. It brought up the discussion in the office about what content should be allowed for students at post 16 age and should we even provide a BYOD wifi at all if the students are just going to use mobile data. I personally was of the opinion that Whatsapp is probably the only type of social media that I would like to allow but at present we block it for students. I thought it would be good to discuss it on here and get peoples thoughts and opinions on how they approach things. Is it better to allow access and monitor as much as we can for safeguarding purposes? What social media do you allow if any? Do we need to provide access to wifi for students who might be disadvantaged and not be able to afford mobile data? How do you filter your BYOD wifi? Any thoughts, opinions or even links to similiar posts are welcomed! Cheers, Jonny
amathieson Posted October 10, 2022 Posted October 10, 2022 Following this post - from the sounds of things we are in a very similar position to you! We block most social media and with the expansion of BYOD are getting wi-fi complaints... haven't yet come up with good solutions but SLT want me to figure something out. We've also struggled with the MITM stuff as we get sporadic issues with students either failing to authenticate or their phones not liking our certification authority. Are you doing SSL decryption on your BYOD network? 1
jonnykewell1 Posted October 11, 2022 Author Posted October 11, 2022 We've replaced the wifi now as we had literally hundreds of students passing through areas at certain times and overloading the access points, which caused them to grind to a halt but it's looking like 90% of their time on the wifi is actually just checking social media which doesn't surprise me. The other 10% is using a new app that we've recently launched which allows them to order their lunch. We have lots of hard wired clients on site so for work they tend to use those. With regards to MITM we don't have that in place, i've supported it before in a previous job and it caused headaches trying to get it working reliably. We're currently trialing DNS filtering on this vlan, restricting it to our cloud web filters DNS server but I know it's not the ideal solution. I need to read KCSIE again just to see if there's specific wording about what level of monitoring is required. 1
chris11256 Posted October 11, 2022 Posted October 11, 2022 We're a sixth form with BYOD for all students who choose to bring something in(phone/tablet/laptop). Social media is blocked for students for safeguarding reasons, doesn't stop them trying to use VPN applications to bypass filtering. So it's a little like playing wack a mole blocking these things. Our web filtering is done on our Firewall(Palo Alto + their URl filtering). Don't yet do SSL Decryption on BYOD as it's a headache I don't think I'm ready for. 1
msi_school Posted October 12, 2022 Posted October 12, 2022 You are treading on difficult ground with BYOD for students. I have had nothing but problems with SSL decryption on BYOD, I have not found a good solution for certificate install and it was the first item on our recent wireless upgrade requirements document. The guidance is fairly vague about what to filter but about 75% of the internet is now HTTPS so you are going to have to have a good reason why you are not doing inspection. Personal devices are also more likely to be infected or used to compromise the network. I question the requirement for anyone staff or student to have their phone on the school network. What is the business case for allowing access? Social media on the other hand is a decision the DSL should be able to make. 2
Oaktech Posted October 12, 2022 Posted October 12, 2022 When I was in secondary, we did the following: Laptops & Tablets: brought to IT helpdesk, mac registered so it could be allowed on the wifi - not by radius, just by mac filtering - and given a meaningful name in DNS, MITM Certificate installed, basic health checks carried out on the device, confirmed the presence of some sort of anti malware. Same filtering level as any other student device. Phones: not allowed on the wifi. 1
DJ_MonkeyBoy Posted October 19, 2022 Posted October 19, 2022 Save yourself a headache, create a separate vlan, restrict bandwidth, install dns filtering. Free: https://blog.cloudflare.com/introducing-1-1-1-1-for-families/ or https://dnssafety.diladele.com/
Davit2005 Posted October 19, 2022 Posted October 19, 2022 Previous employments we deployed decryption and filtering on Palo's. We also ran all application based policies. We jus put a link to the cert on a web page people could get to as they joined the network for the cert, managed devices we deployed the cert via GPO or JAMF for MAC devices.
msi_school Posted October 27, 2022 Posted October 27, 2022 Previous employments we deployed decryption and filtering on Palo's. We also ran all application based policies. We jus put a link to the cert on a web page people could get to as they joined the network for the cert, managed devices we deployed the cert via GPO or JAMF for MAC devices. I have tried the self service route but it seem too complex for 75% of users especially users who are not using PCs, I gave up in the end and ran drop in sessions. For school devices I deployed via GPO or MDM and it worked like a charm.
Primus Posted October 27, 2022 Posted October 27, 2022 Save yourself a headache, create a separate vlan, restrict bandwidth, install dns filtering. Free: https://blog.cloudflare.com/introducing-1-1-1-1-for-families/ or https://dnssafety.diladele.com/ How would you meet the requirement for reporting with this kind of setup?
DJ_MonkeyBoy Posted November 1, 2022 Posted November 1, 2022 Diladele offers elements of reporting. Most solutions are overkill, expensive and unnecessary..what level of reporting do you require, to what detail, by who, and for what reasons/purpose. That's the question I would be asking. The KCSIE does not ask for overkill reporting.
Primus Posted November 1, 2022 Posted November 1, 2022 (edited) Diladele offers elements of reporting. Most solutions are overkill, expensive and unnecessary..what level of reporting do you require, to what detail, by who, and for what reasons/purpose. That's the question I would be asking. The KCSIE does not ask for overkill reporting. The minimum level of reporting I'd want is the ability to see which sites a particular user had been on with some alerting for concerning browsing such as suicide related content. It's also worth considering your statutory duty relating to Prevent when thinking about monitoring and reporting. Can both of the 2 solutions you suggested link to directory services such as AD so as to monitor and report on what individual users are doing? From what I can see CloudFlare cannot, does Diladele have all the appropriate lists such as the IWF ones? Does it include the list provided by the Home Office? KCSIE requires both filtering and monitoring: "Whilst it is essential that governing bodies and proprietors ensure that appropriate filtering and monitoring systems are in place" I would suggest that if your filter cannot tell you who did what and when then it's not up to the job - you cannot take risks with safeguarding, lives can literally be on the line and the consequences of getting it wrong can be horrific. I have direct experience of an instant alert relating to suicide where it's highly likely the alert prevented very serious harm and potentially the loss of a young person's life. KCSIE references the Safer Internet Centre - https://saferinternet.org.uk/guide-and-resource/teachers-and-school-staff/appropriate-filtering-and-monitoring - you don't have to follow the guidance here but the general principle is that you need a good and documented reason to deviate from guidance from authorities such as this. Edited November 1, 2022 by Primus
DJ_MonkeyBoy Posted November 2, 2022 Posted November 2, 2022 Then you need full SSL MITM proxying, difficult to implement with BYOD (as per the original discussion) due to the user having to install the cert. However, diladele also does full AD integrated SSL decryption: https://www.diladele.com/ for managed devices. Fill your boots.
DrCheese Posted November 2, 2022 Posted November 2, 2022 I'm confused why the SSL BYOD device needs to be enforced on devices, we don't & the normal URL blocking still applies as expected & I can see what sites the users have been on. As long as you can track what the user has been on & enforce a blocklist, I don't see what the problem is?
DJ_MonkeyBoy Posted November 2, 2022 Posted November 2, 2022 It really depends on what degree of snooping you require, the ethics around this and how you interpret KCSIE. Which in itself is another discussion point.
_Rob_A_ Posted April 25, 2023 Posted April 25, 2023 I'm going through this exact dilemma here. BYOD became compulsory for older students. We require certificates for students and of course many of them either get a new laptop, borrow one from a sibling/parent/friend, or a particular device or antivirus may not like the certificate or some sort parental control feature makes it difficult to install or a parent is the device’s admin and child does not know the password. I would say this sort of issue accounts for 90% of students not being able to navigate to the internet. On top of that, sometimes we have genuine slowness due to all the filtering rules and ssl inspection. User perception (students) is of course that the school internet is slow and the WiFi does not work. And this is the perfect excuse for students to claim that they “need to use their hotspot to do their classwork”. I am therefore seriously considering removing the need for certificates, at least for the older ones, 16+. Students authenticate using their AD credentials. If there is no certificate, they can’ go out to the internet, only navigate the Intranet page. The SSID they use is separate from the one used with school-owned devices so they cannot access file server for instance. Our Fortigate will continue to have all the category filtering which blocks social media, games and the no-go sites. Given we will still have web filtering, how risky would it be to remove the need for certificates?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now