Jump to content

Recommended Posts

Posted

Sorry, this might turn into a bit of a long post!

 

Looking at the best way to filter our Chromebooks. They are all being used on-site with no immediate plans to let them go off-site. (Primary School)

 

I looked at getting the chromebooks to authenticate automatically to an 802.1x wifi, which I successfully did with my test account, this sent the account info to the smoothwall and filtering worked as expected. The few issues with this are:

 

  • Wifi for when not logged on needs to be less filtered (ssl certificate not available at this point?) to allow the authentication part to take place (google and we redirect to 365/azure). I can achieve this by pushing out a wifi network with a proxy with less filtering, but how can I guarantee it doesn't connect to this wifi network still when someone is logged in?
  • I can only push the Wifi settings out to an organisational unit? Is there a simple way to move users in a group (group synced from Azure ad) into an organisation unit automatically?

 

 

 

Am I better off using connect for chromebooks? Have had a quick go at installing this and it didn't work too well, although I've just noticed the guide I downloaded from their site is dated 2016 so maybe things have changed a little? Will this work without requiring the user to authenticate again once they have logged into the Chromebook?

 

If it's relevant our smoothwall appliance is setup in bridged mode with a transparent proxy.

Posted

 

  • Wifi for when not logged on needs to be less filtered (ssl certificate not available at this point?) to allow the authentication part to take place (google and we redirect to 365/azure). I can achieve this by pushing out a wifi network with a proxy with less filtering, but how can I guarantee it doesn't connect to this wifi network still when someone is logged in?

 

deploy the cert as a device policy on the devices OU, this preloads the cert, you will still have to exempt a few urls to get enrolment working, but you can sit with the live filter and see what urls its talking to to get it going.

you then dont need to deploy the cert to users

then restrict your chromebooks to logging in with accounts on your domain.

  • Thanks 1
Posted
The best bet is to use the cloud filter, does all the filtering in a chrome extension, and solves all auth/mitm issues

 

Does this not require the certificate to be deployed to the Chromebook then? How do I get around the issues of filtering/ ssl issues affecting the login process?

 

Do I create a proxy just for the Chromebooks which has much more relaxed filtering, with the cloud filter then kicking in to provide the filtering once logged in, or is there a better way of doing this?

Posted
Does this not require the certificate to be deployed to the Chromebook then? How do I get around the issues of filtering/ ssl issues affecting the login process?

 

Do I create a proxy just for the Chromebooks which has much more relaxed filtering, with the cloud filter then kicking in to provide the filtering once logged in, or is there a better way of doing this?

 

setup a proxy with no ssl interception and point the chromebooks through it.

 

once the cloud filters installed you dont need to intercept cause all the filtering is done in the browser itself

  • Thanks 1
Posted
setup a proxy with no ssl interception and point the chromebooks through it.

 

once the cloud filters installed you dont need to intercept cause all the filtering is done in the browser itself

 

Thanks, that makes sense. Are there ever any issues with the cloud filter not installing? Just worried that the default is more relaxed filtering until the cloud filter is installed.

Posted
Thanks, that makes sense. Are there ever any issues with the cloud filter not installing? Just worried that the default is more relaxed filtering until the cloud filter is installed.

 

not that ive noticed, just make sure you do all the other stuff like disable dev console etc so they cant guest session around it and that

Posted
not that ive noticed, just make sure you do all the other stuff like disable dev console etc so they cant guest session around it and that

 

Thanks, will do. We're a primary school so children aren't quite as determined to bypass things, but will still tighten them down. Don't suppose there is a list of recommended settings for Chromebooks in schools somewhere is there?

Posted
Thanks, will do. We're a primary school so children aren't quite as determined to bypass things, but will still tighten them down. Don't suppose there is a list of recommended settings for Chromebooks in schools somewhere is there?

 

not that ive seen, i just sat and read through them and turned off what i didnt like, if youre refering to the extension etc i think smoothwall have a list of stuff to disable that can be used to get around it with the installation instructions

Posted
not that ive seen, i just sat and read through them and turned off what i didnt like, if youre refering to the extension etc i think smoothwall have a list of stuff to disable that can be used to get around it with the installation instructions

 

Ok thanks, think I've seen the smoothwall one before and will just work through all the other settings.

 

With them going in to school so much it would be useful if Google offered a couple of default lock down options, like primary and secondary that schools could then just tweak!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...