Jump to content

Recommended Posts

Posted

All our staff ipads authenticate to the wireless using radius with their network username and password. This means on smoothwall they are identified as themselves (via Radius Accounting).

 

At the moment all pupil ipads are on a WPA3 network with a proxy set to connect to smoothwall with our infant filter list applied. This works fine, but logs it against the ip address of the ipad, which takes a fair while to track it back to the device.

 

I want to change the pupil ipads to the same wifi network as staff (it's a flat network at the moment anyway, so just a different way of connecting to it)in 2 ways:

 

1:1 devices will connect using their own username and password.

Shared devices - I will create a user account for each ipad, e.g IpadA01, IpadA02 and sign it in with this. Each child will always use the same ipad number and teachers will record when their class has the ipads.

 

Am I missing anything obvious here? Long term when we vlan the network (it's grown a lot over the last few years) I should be able to use this to dynamically assign vlans based on their user groups.

Posted

Hi Steve,

 

Looks like a good idea. I'm always a fan of keeping SSIDs down if possible e.g. if you have a network already accepting RADIUS authentication for Staff then there are little to no benefits of creating one for students as you should be able to set the VLAN, speed, default filtering etc by an AD group rather than the SSID which most people do? Looks like you've already thought of this when you move from being a flat network.

 

 

It may also be worth (provided that students have unique AD logins) setting up a generic 'iPads' network with WPA2 then setting the smoothwall to use a captive portal which asks for the student credentials once per hour (or 30 mins depending on their use etc). This means that filter logs are attributed to a user's name rather than the iPad they were using on that day which may cut down on some work?

Posted
It may also be worth (provided that students have unique AD logins) setting up a generic 'iPads' network with WPA2 then setting the smoothwall to use a captive portal which asks for the student credentials once per hour (or 30 mins depending on their use etc). This means that filter logs are attributed to a user's name rather than the iPad they were using on that day which may cut down on some work?

I'm guessing to do that you'd have to have the traffic on the WPA2 SSID on a seperate VLAN?

Posted
I believe so, yes - personally I would move away from a flat network ASAP - even if you build a basic servers/printers/students/staff/guest setup this would make life easier in the long run.
Posted
Hi Steve,

 

 

It may also be worth (provided that students have unique AD logins) setting up a generic 'iPads' network with WPA2 then setting the smoothwall to use a captive portal which asks for the student credentials once per hour (or 30 mins depending on their use etc). This means that filter logs are attributed to a user's name rather than the iPad they were using on that day which may cut down on some work?

 

We're mostly using the iPads lower down in a primary setting, so trying to avoid too much signing in etc, while still complying with KCSIE guidance. Hopefully being able to identify the exact iPad, and then a record of who had it at the time will get us most of the way there.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...