Jump to content

Recommended Posts

Posted

Good afternoon,

 

We had some reports of slow BYOD wifi in our Post 16 college and after looking into it the problem, I discovered that it was actually the content that wasn't loading for social media apps that students have on their phone.The apps opened but then the web filter kicked in and did its job but as an end user the app just tries to connect and doesn't provide any kind of blocked page. As a result the students then reported slow wifi, turned off their wifi on their phone and used mobile data to access the social media. It's worth notice that controls are in place in the classroom and this is only in the social areas.

 

It brought up the discussion in the office about what content should be allowed for students at post 16 age and should we even provide a BYOD wifi at all if the students are just going to use mobile data. I personally was of the opinion that Whatsapp is probably the only type of social media that I would like to allow but at present we block it for students. I thought it would be good to discuss it on here and get peoples thoughts and opinions on how they approach things.

 

Is it better to allow access and monitor as much as we can for safeguarding purposes?

What social media do you allow if any?

Do we need to provide access to wifi for students who might be disadvantaged and not be able to afford mobile data?

How do you filter your BYOD wifi?

 

Any thoughts, opinions or even links to similiar posts are welcomed!

 

Cheers,

 

Jonny

Posted

Following this post - from the sounds of things we are in a very similar position to you! We block most social media and with the expansion of BYOD are getting wi-fi complaints... haven't yet come up with good solutions but SLT want me to figure something out.

 

We've also struggled with the MITM stuff as we get sporadic issues with students either failing to authenticate or their phones not liking our certification authority. Are you doing SSL decryption on your BYOD network?

  • Thanks 1
Posted

We've replaced the wifi now as we had literally hundreds of students passing through areas at certain times and overloading the access points, which caused them to grind to a halt but it's looking like 90% of their time on the wifi is actually just checking social media which doesn't surprise me. The other 10% is using a new app that we've recently launched which allows them to order their lunch.

 

We have lots of hard wired clients on site so for work they tend to use those.

 

With regards to MITM we don't have that in place, i've supported it before in a previous job and it caused headaches trying to get it working reliably. We're currently trialing DNS filtering on this vlan, restricting it to our cloud web filters DNS server but I know it's not the ideal solution.

 

I need to read KCSIE again just to see if there's specific wording about what level of monitoring is required.

  • Thanks 1
Posted

We're a sixth form with BYOD for all students who choose to bring something in(phone/tablet/laptop). Social media is blocked for students for safeguarding reasons, doesn't stop them trying to use VPN applications to bypass filtering. So it's a little like playing wack a mole blocking these things.

 

Our web filtering is done on our Firewall(Palo Alto + their URl filtering). Don't yet do SSL Decryption on BYOD as it's a headache I don't think I'm ready for.

  • Thanks 1
Posted

You are treading on difficult ground with BYOD for students.

 

I have had nothing but problems with SSL decryption on BYOD, I have not found a good solution for certificate install and it was the first item on our recent wireless upgrade requirements document. The guidance is fairly vague about what to filter but about 75% of the internet is now HTTPS so you are going to have to have a good reason why you are not doing inspection.

 

Personal devices are also more likely to be infected or used to compromise the network. I question the requirement for anyone staff or student to have their phone on the school network. What is the business case for allowing access?

 

Social media on the other hand is a decision the DSL should be able to make.

  • Thanks 2
Posted

When I was in secondary, we did the following:

 

Laptops & Tablets: brought to IT helpdesk, mac registered so it could be allowed on the wifi - not by radius, just by mac filtering - and given a meaningful name in DNS, MITM Certificate installed, basic health checks carried out on the device, confirmed the presence of some sort of anti malware. Same filtering level as any other student device.

 

Phones: not allowed on the wifi.

  • Thanks 1
Posted

Previous employments we deployed decryption and filtering on Palo's. We also ran all application based policies.

 

We jus put a link to the cert on a web page people could get to as they joined the network for the cert, managed devices we deployed the cert via GPO or JAMF for MAC devices.

  • 2 weeks later...
Posted
Previous employments we deployed decryption and filtering on Palo's. We also ran all application based policies.

 

We jus put a link to the cert on a web page people could get to as they joined the network for the cert, managed devices we deployed the cert via GPO or JAMF for MAC devices.

 

I have tried the self service route but it seem too complex for 75% of users especially users who are not using PCs, I gave up in the end and ran drop in sessions. For school devices I deployed via GPO or MDM and it worked like a charm.

Posted
Diladele offers elements of reporting. Most solutions are overkill, expensive and unnecessary..what level of reporting do you require, to what detail, by who, and for what reasons/purpose. That's the question I would be asking. The KCSIE does not ask for overkill reporting.
Posted (edited)
Diladele offers elements of reporting. Most solutions are overkill, expensive and unnecessary..what level of reporting do you require, to what detail, by who, and for what reasons/purpose. That's the question I would be asking. The KCSIE does not ask for overkill reporting.

 

The minimum level of reporting I'd want is the ability to see which sites a particular user had been on with some alerting for concerning browsing such as suicide related content.

 

It's also worth considering your statutory duty relating to Prevent when thinking about monitoring and reporting.

 

Can both of the 2 solutions you suggested link to directory services such as AD so as to monitor and report on what individual users are doing? From what I can see CloudFlare cannot, does Diladele have all the appropriate lists such as the IWF ones? Does it include the list provided by the Home Office?

 

KCSIE requires both filtering and monitoring: "Whilst it is essential that governing bodies and proprietors ensure that appropriate filtering and monitoring systems are in place"

 

I would suggest that if your filter cannot tell you who did what and when then it's not up to the job - you cannot take risks with safeguarding, lives can literally be on the line and the consequences of getting it wrong can be horrific.

 

I have direct experience of an instant alert relating to suicide where it's highly likely the alert prevented very serious harm and potentially the loss of a young person's life.

 

KCSIE references the Safer Internet Centre - https://saferinternet.org.uk/guide-and-resource/teachers-and-school-staff/appropriate-filtering-and-monitoring - you don't have to follow the guidance here but the general principle is that you need a good and documented reason to deviate from guidance from authorities such as this.

Edited by Primus
Posted

I'm confused why the SSL BYOD device needs to be enforced on devices, we don't & the normal URL blocking still applies as expected & I can see what sites the users have been on.

 

As long as you can track what the user has been on & enforce a blocklist, I don't see what the problem is?

  • 5 months later...
Posted

I'm going through this exact dilemma here. BYOD became compulsory for older students.

We require certificates for students and of course many of them either get a new laptop, borrow one from a sibling/parent/friend, or a particular device or antivirus may not like the certificate or some sort parental control feature makes it difficult to install or a parent is the device’s admin and child does not know the password.

 

I would say this sort of issue accounts for 90% of students not being able to navigate to the internet.

On top of that, sometimes we have genuine slowness due to all the filtering rules and ssl inspection.

User perception (students) is of course that the school internet is slow and the WiFi does not work. And this is the perfect excuse for students to claim that they “need to use their hotspot to do their classwork”.

 

I am therefore seriously considering removing the need for certificates, at least for the older ones, 16+.

 

Students authenticate using their AD credentials. If there is no certificate, they can’ go out to the internet, only navigate the Intranet page.

 

The SSID they use is separate from the one used with school-owned devices so they cannot access file server for instance.

 

Our Fortigate will continue to have all the category filtering which blocks social media, games and the no-go sites.

 

Given we will still have web filtering, how risky would it be to remove the need for certificates?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...