Jump to content

Recommended Posts

Posted

Apologies if this has been covered in another thread.

 

What are your school’s approaches to filtering on your guest/byod networks? Do you allow students to connect and identify them/inspect their search terms?

 

We are trying to get a seamless experience for people joining our guest wifi but also want to be able to identify users and block suspicious search terms to meet the new KCSIE guidance/technology standards, which states:

 

Your filtering systems should allow you to identify: 

• device name or ID, IP address, and where possible, the individual

• the time and date of attempted access

• the search term or content being blocked

 

This means installing a certificate on the device which can get messy for end users particularly with android devices (in our experience). We currently have Meraki WiFi and use LightSpeed with a few different SSIDs using radius with and without accounting as well as PSKs and would like to simplify this. I would be grateful of any advice or ideas!

Posted
we use fortigate as a transparent proxy that will allow the device to be filtered and we use the NX filter free to filter the BYOD network where guest and staff members have access we are in the process of using radius with the wifi controller that we us ruckus so that staff use there credentials to login and this will log against who been searching for what.
Posted (edited)

Our Ruckus system has unfiltered guest access and is only for guests, never for Staff or Student use.

 

BYOD is currently for Sixth Formers and Staff and follows Smoothwall filtering by year group.

 

The Smoothwall block messages give the details required.

Edited by MartinT
Posted
Thanks. Do you inspect search terms on your guest/byod networks and therefore receive reports of suspicious search terms for users on these?
Posted
Do you inspect search terms on your guest/byod networks and therefore receive reports of suspicious search terms for users on these?

 

Indirectly, inappropriate search terms appear in the daily safeguarding report which is sent to our DSL. She then speaks to students who have crossed the line.

Posted

I would separate my BOYD and Guest networks.

 

The guest network should not have HTTPS inspection and only a basic filtering set unless you like spending an hour with each visitor setting up the certificate and explaining why they can get on to a specific page.

 

Your BYOD network on the other hand should have HTTPS filtering which is a pain on unmanaged devices and the correct comprehensive filtering for the user.

 

The best options for this are some sort of radius gateway or PPSKs because this gives you more control and transparency than a normal PSK.

Posted
Definitely agree wrt splitting the networks. Guest, BYO and regular LAN might be a good 3-way split - as BYO can often auth with RADIUS as our friend above recommends, whilst guests often don't. Wether you try and MiTM on those networks is not something I - or anyone else on here can say yay or nay to. It's a conversation between you and your DSLs, and needs to start with "who is using these networks"
  • Thanks 4
Posted (edited)
we're moving to individual guest codes on Ruckus SmartZone that reception will give out, makes it a lot easier in testing as they can print them out or email them and then they expire and don't worry about the lack of filtering in case students manage to get on it. Edited by ittech2342323

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...