Jump to content

Recommended Posts

Posted (edited)

Firstly, I apologise for my lack of expertise in this field. This isnt something I have had to implement before.

 

Here is my scenario:

  • So like most schools we have the following devices that require wireless access:
  • Domain joined PC's
  • Domain joined Laptops
  • iPads
  • Interactive screens
  • Around 20 non domain joined PC's (acts as a kiosk for youtube access only)
  • Guest devices
  • Staff personal devices

I am aware that many SSID's cause a world of pain, but with my limited knowledge this is the best way I can describe what our desired outcome would be.

 

What we need:

  • A main SSID for domain joined devices only, with access to multiple vlans for resources etc.
  • An SSID servicing pupil iPads and interactive screens
  • An SSID servicing staff iPads
  • An SSID for the non domain joined PC's where it can be secured off our main network through a VLAN
  • A Guest SSID where staff and guests can get 'unrestricted' (to a certain degree) access.

The idea of the mutiple SSID's is so that a certain IP scope can be defined and then filtered at the firewall, and/or can be secured through VLANs.

 

I have setup 802.1x as a 'main' SSID and connected all domain joined devices through gpo. This works perfectly, as no user input is required, and is filtered based on what user is logged in. Also stops unwanted devices joining the network. But I am now stuck on how to manage our other devices.

 

We do have a captive portal which could be implemented somewhere, but it is not the best. We are also an SEN school, so many of the students will be unable to log into a captive portal easily, at least not without staff help.

 

Something else to note is, we currently have Aruba and Ruckus servicing the same SSID's across two schools on the same site. We are upgrading the ruckus to Aruba later in the year so it'll all be the same.

TLDR;I need to seperate wireless devices so they can be filtered seperately without causing a busy airspace with multiple SSIDs. Also needs to be easy for students as its in an SEN school.

 

If you were in my shoes, what would you implement? Open to all suggestions.

 

Thank you for reading! :)

Edited by Username101
Posted (edited)
What we need:

  • A main SSID for domain joined devices only, with access to multiple vlans for resources etc.
  • An SSID servicing pupil iPads and interactive screens
  • An SSID servicing staff iPads
  • An SSID for the non domain joined PC's where it can be secured off our main network through a VLAN
  • A Guest SSID where staff and guests can get 'unrestricted' (to a certain degree) access.

 

Or.

Single SSID, NPS all the things and get the NPS server to put them in the right VLANS (or you can probably get the NPS server to forward the authentication token for user accounts to the webfilter so it just filters by username as normal).

Domain joined devices auth via computer account/cert like they presumably do now.

Staff and Students authenticate using their normal network logins.

non-domain joined devices auth using a (wifi access only) domain account, or a cert, or maybe by IP or something (lots of options here).

Visitor accounts are just AD accounts without any file/system access.

 

EDIT: With NPS you could probably MAC authenticate the student devices and then hive them off into an IP range for location based filtering, so the kids don't need to log in to the wifi at all.

 

Or if you're worried about giving visitors AD accounts, then Visitor SSID with captive portal, and main SSID for everything else as above. (this is pretty much what we do)

Edited by Rob_D
  • Thanks 1
Posted
Agree with @Rob_D that any RADIUS server should be able to assign VLAN's based on whatever criteria you choose. The SSID's aren't relevant here, and adding more just complicates things.
  • Thanks 1
Posted

VLAN assignment via Radius would be our preferred.

 

We do strongly advise against staff WiFi for personal devices, we've been aware of a number of alerts that originated from personal devices most of the time with a completely innocent explanation. Its just a problem nobody needs, and risks a lot of embarrassment.

 

Genuine Guest SSIDs do have their place.

Posted
VLAN assignment via Radius would be our preferred.

We do strongly advise against staff WiFi for personal devices, we've been aware of a number of alerts that originated from personal devices most of the time with a completely innocent explanation. Its just a problem nobody needs, and risks a lot of embarrassment.

Genuine Guest SSIDs do have their place.

 

What kind of alerts were you getting from staff devices?

Posted
Or.

Single SSID, NPS all the things and get the NPS server to put them in the right VLANS (or you can probably get the NPS server to forward the authentication token for user accounts to the webfilter so it just filters by username as normal).

Domain joined devices auth via computer account/cert like they presumably do now.

Staff and Students authenticate using their normal network logins.

non-domain joined devices auth using a (wifi access only) domain account, or a cert, or maybe by IP or something (lots of options here).

Visitor accounts are just AD accounts without any file/system access.

 

EDIT: With NPS you could probably MAC authenticate the student devices and then hive them off into an IP range for location based filtering, so the kids don't need to log in to the wifi at all.

Or if you're worried about giving visitors AD accounts, then Visitor SSID with captive portal, and main SSID for everything else as above. (this is pretty much what we do)

 

Love the sound of this! Thank you @Rob_D

Posted (edited)

TLDR;[/b]I need to seperate wireless devices so they can be filtered seperately without causing a busy airspace with multiple SSIDs. Also needs to be easy for students as its in an SEN school.

 

If you were in my shoes, what would you implement?

 

Fewer SSIDs. More than three is too many imo and I'm struggling to get above two for your use case. You can assign profiles for devices based on a number of factors and this below is roughly what my employer does with two SSIDs for about 8000 devices in our main building.

 

Org-owned devices go on one SSID, everything else on the second SSID.

 

Looking at your requirements, I'd go:

SSID 1 / "Corporate" A main SSID for domain joined devices only, with access to multiple vlans for resources etc.

SSID 1 / "Corporate" A SSID servicing staff iPads.

SSID 1 / "Corporate" A SSID servicing pupil iPads and interactive screens (I'm not sure why you think these are different from Staff iPads, assuming in both cases you're referring to devices issued by the school...)

 

SSID 2/ "Guests" A SSID for the non domain joined PC's where it can be secured off our main network through a VLAN

SSID 2/"Guests" A Guest SSID where staff and guests can get 'unrestricted' (to a certain degree) access.

Edited by Roberto
Posted

 

Here is my scenario:

  • So like most schools we have the following devices that require wireless access:
  • Domain joined PC's
  • Domain joined Laptops
  • iPads
  • Interactive screens
  • Around 20 non domain joined PC's (acts as a kiosk for youtube access only)
  • Guest devices
  • Staff personal devices

I am aware that many SSID's cause a world of pain, but with my limited knowledge this is the best way I can describe what our desired outcome would be.

 

Just some comments on your main scenario before you implement the wifi as per the several great replies on this thread already:

 

1 - Domain Joined PCs should all be wired - they don't move so cable them in, this makes them faster more reliable and unburdens your wifi points to serve actual WIFI only devices that may need the bandwidth.

 

2 - Non domain joined but still internet connected PCs - is a big no no nowadays as they're a rife target for viruses and malware - wipe them join them in to the domain so you can ensure basic security and more advanced cybersecurity compliance and make sure they are hard wired in for reliability etc as above.

 

3 - Staff personal devices should be treated as guest devices. Basically anything that is school owned is not a guest, anything that is a personal owned device is on the guest network.

 

4 - Keep the number of customer facing Vlans to a minimum as the more vlans you have the more everything (particularly WIFI) slows down.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...