Jump to content

Recommended Posts

Posted

To those schools who use shared iPads, how are you managing them now the KCSiE requires user reporting rather than device reporting?

 

We are struggling to understand / come up with a solution so that when UserA puts ipad back into the trolley, UserB is able to authenticate themself against the Smoothwall.

 

Setting the User Session for the proxy in Smoothwall to 5 mins will cause a heap of problems and it's a shame that cannot be configured per network / VLAN.

Posted

Funnily enough was looking at options for this the other day and found this page on Smoothwall - https://kb.smoothwall.com/hc/en-us/articles/360003319039-Minimizing-the-Need-for-Users-to-Log-in-When-Using-Shared-iPad-Devices

 

Basically sounds like you are setting whitelists just for the iPads that are allowed on without Authenticaton and only if they browse outside of that will it require authentication

 

So for example if you’re expecting them to be used for accelerated reader only (just an example) it wouldn’t need logging in, but if they browse to “insert random site” it’d then fall back to requiring login to meet kcsie

 

Haven’t had a chance to test it and I guess it depends on the age range you’re talking as to whether that’s likely to work but might be worth a look!

 

Steve

Posted

I'm trying to build a system for our primaires that have shared ipads.

 

Anything that is in proxy exceptions / auth bypass should be fine for us however the sticking point is web searches as we need to see what users are searching for.

 

The SSL login page will work however if we want to use the SSL login page for other things for web browsing, like getting users to sign with the Google login button or apply different SSL sign out times per network, it's not possible to do. For example, we have heard someone setting the user session to 5 mins and use NTLM auth, from my understandings that means if the device has not been used for more than 5 mins the user will need to re-login via SSL page to access the internet - this method is not going to work for us as we want to apply this method to a range of networks.

 

There needs to be some kind of log out button / app to kill the connection to Smoothwall once the user has finished using ipad just before they put it away.

 

I do feel that in smoothwall we may need to create categories for each app we use and then put yhose categorys into the proxy exceptions l

 

Really shared ipads should be banned and should only be use in a 1:1 setting but we can moan like that forevver and that doesn't get us finding a solution.

Posted
There needs to be some kind of log out button / app to kill the connection to Smoothwall once the user has finished using ipad just before they put it away.

 

On the login page once you're logged in it does appear as logout, that's mentioned in my link above "The shortcut to the login page on the main screen can then be used to manually log out once they are done."

 

Yes it still relies on them clicking it, but then that's user error rather than you not following guidance :p

 

Steve

Posted
On the login page once you're logged in it does appear as logout, that's mentioned in my link above "The shortcut to the login page on the main screen can then be used to manually log out once they are done."

 

Yes it still relies on them clicking it, but then that's user error rather than you not following guidance [emoji14]

 

Steve

I've seen that logout button too which will work if the user keeps the tab open in the background though we are dealing with primary school kids who struggle to remember their own name let alone remembering to do back to a tab or keep a browser tab open.

 

Maybe i'm trying to find a silver bullet it's no5 happening and o feel that Smoothwall (and others) are behind the curve with this at the moment with focus on "monitoring" rather than foundation and shared devices.

Posted

Honestly I think it's more an Apple issue regarding how the logins work rather than Smoothwall as haven't seen any other companies have a better solution. (same with any monitoring tools for ipads requiring a custom browser etc)

 

The only other way I could see of doing it is if you use the shared-mode where they have their own logins via ASM, as I assume each instance of Safari wouldn't remember cookies etc from the last one (or are these just standalone ipads as such) so wouldn't have the authentication cookies etc if switched to another user (that is an assumption without checking though)

 

Steve

  • Thanks 1
Posted (edited)
Honestly I think it's more an Apple issue regarding how the logins work rather than Smoothwall as haven't seen any other companies have a better solution. (same with any monitoring tools for ipads requiring a custom browser etc)

 

The only other way I could see of doing it is if you use the shared-mode where they have their own logins via ASM, as I assume each instance of Safari wouldn't remember cookies etc from the last one (or are these just standalone ipads as such) so wouldn't have the authentication cookies etc if switched to another user (that is an assumption without checking though)

 

Steve

Cheers @Steve21.

 

I guess i'm pointing the finger to web filtering products because we can't expect Apple to bring in processes that keep students safe :scarcasm:.

 

Will speak to our Primary Tech to see how the iPads are setup as logins via ASM might be an option.

Edited by timbo343
Posted
shared ipad mode is the work of satan just in case you are considering reprofiling your ipads in shared mode. But one thing it will do is lock the profile to a username for filtering.
  • Thanks 1
  • 3 weeks later...
Posted

We've not tested anything yet and wanting to look at the Shared Ipad mode but we are also thinking about putting the iPads on their own VLAN and setting the Smoothwall to have the SSL/Non-SSL login page on that network.

 

I'm looking to have a bookmark on each home screen of the iPad that goes to the log out page for students to log out of the session when they have finished using the ipad.

 

I'm aware this won't sign them out of any apps they are signed into though but i want to see if the SSL/Non-SSL login page is feasible first.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...