Username101 Posted April 18, 2024 Posted April 18, 2024 (edited) Firstly, I apologise for my lack of expertise in this field. This isnt something I have had to implement before. Here is my scenario: So like most schools we have the following devices that require wireless access: Domain joined PC's Domain joined Laptops iPads Interactive screens Around 20 non domain joined PC's (acts as a kiosk for youtube access only) Guest devices Staff personal devices I am aware that many SSID's cause a world of pain, but with my limited knowledge this is the best way I can describe what our desired outcome would be. What we need: A main SSID for domain joined devices only, with access to multiple vlans for resources etc. An SSID servicing pupil iPads and interactive screens An SSID servicing staff iPads An SSID for the non domain joined PC's where it can be secured off our main network through a VLAN A Guest SSID where staff and guests can get 'unrestricted' (to a certain degree) access. The idea of the mutiple SSID's is so that a certain IP scope can be defined and then filtered at the firewall, and/or can be secured through VLANs. I have setup 802.1x as a 'main' SSID and connected all domain joined devices through gpo. This works perfectly, as no user input is required, and is filtered based on what user is logged in. Also stops unwanted devices joining the network. But I am now stuck on how to manage our other devices. We do have a captive portal which could be implemented somewhere, but it is not the best. We are also an SEN school, so many of the students will be unable to log into a captive portal easily, at least not without staff help. Something else to note is, we currently have Aruba and Ruckus servicing the same SSID's across two schools on the same site. We are upgrading the ruckus to Aruba later in the year so it'll all be the same. TLDR;I need to seperate wireless devices so they can be filtered seperately without causing a busy airspace with multiple SSIDs. Also needs to be easy for students as its in an SEN school. If you were in my shoes, what would you implement? Open to all suggestions. Thank you for reading! Edited April 18, 2024 by Username101
Rob_D Posted April 18, 2024 Posted April 18, 2024 (edited) What we need: A main SSID for domain joined devices only, with access to multiple vlans for resources etc. An SSID servicing pupil iPads and interactive screens An SSID servicing staff iPads An SSID for the non domain joined PC's where it can be secured off our main network through a VLAN A Guest SSID where staff and guests can get 'unrestricted' (to a certain degree) access. Or. Single SSID, NPS all the things and get the NPS server to put them in the right VLANS (or you can probably get the NPS server to forward the authentication token for user accounts to the webfilter so it just filters by username as normal). Domain joined devices auth via computer account/cert like they presumably do now. Staff and Students authenticate using their normal network logins. non-domain joined devices auth using a (wifi access only) domain account, or a cert, or maybe by IP or something (lots of options here). Visitor accounts are just AD accounts without any file/system access. EDIT: With NPS you could probably MAC authenticate the student devices and then hive them off into an IP range for location based filtering, so the kids don't need to log in to the wifi at all. Or if you're worried about giving visitors AD accounts, then Visitor SSID with captive portal, and main SSID for everything else as above. (this is pretty much what we do) Edited April 18, 2024 by Rob_D 1
dmj Posted April 18, 2024 Posted April 18, 2024 Agree with @Rob_D that any RADIUS server should be able to assign VLAN's based on whatever criteria you choose. The SSID's aren't relevant here, and adding more just complicates things. 1
Aprice Posted April 18, 2024 Posted April 18, 2024 VLAN assignment via Radius would be our preferred. We do strongly advise against staff WiFi for personal devices, we've been aware of a number of alerts that originated from personal devices most of the time with a completely innocent explanation. Its just a problem nobody needs, and risks a lot of embarrassment. Genuine Guest SSIDs do have their place.
Rob_D Posted April 18, 2024 Posted April 18, 2024 VLAN assignment via Radius would be our preferred. We do strongly advise against staff WiFi for personal devices, we've been aware of a number of alerts that originated from personal devices most of the time with a completely innocent explanation. Its just a problem nobody needs, and risks a lot of embarrassment. Genuine Guest SSIDs do have their place. What kind of alerts were you getting from staff devices?
Aprice Posted April 19, 2024 Posted April 19, 2024 What kind of alerts were you getting from staff devices? Smoothwall alerts from some 'websites' 1
Username101 Posted April 19, 2024 Author Posted April 19, 2024 Or. Single SSID, NPS all the things and get the NPS server to put them in the right VLANS (or you can probably get the NPS server to forward the authentication token for user accounts to the webfilter so it just filters by username as normal). Domain joined devices auth via computer account/cert like they presumably do now. Staff and Students authenticate using their normal network logins. non-domain joined devices auth using a (wifi access only) domain account, or a cert, or maybe by IP or something (lots of options here). Visitor accounts are just AD accounts without any file/system access. EDIT: With NPS you could probably MAC authenticate the student devices and then hive them off into an IP range for location based filtering, so the kids don't need to log in to the wifi at all. Or if you're worried about giving visitors AD accounts, then Visitor SSID with captive portal, and main SSID for everything else as above. (this is pretty much what we do) Love the sound of this! Thank you @Rob_D
Roberto Posted April 19, 2024 Posted April 19, 2024 (edited) TLDR;[/b]I need to seperate wireless devices so they can be filtered seperately without causing a busy airspace with multiple SSIDs. Also needs to be easy for students as its in an SEN school. If you were in my shoes, what would you implement? Fewer SSIDs. More than three is too many imo and I'm struggling to get above two for your use case. You can assign profiles for devices based on a number of factors and this below is roughly what my employer does with two SSIDs for about 8000 devices in our main building. Org-owned devices go on one SSID, everything else on the second SSID. Looking at your requirements, I'd go: SSID 1 / "Corporate" A main SSID for domain joined devices only, with access to multiple vlans for resources etc. SSID 1 / "Corporate" A SSID servicing staff iPads. SSID 1 / "Corporate" A SSID servicing pupil iPads and interactive screens (I'm not sure why you think these are different from Staff iPads, assuming in both cases you're referring to devices issued by the school...) SSID 2/ "Guests" A SSID for the non domain joined PC's where it can be secured off our main network through a VLAN SSID 2/"Guests" A Guest SSID where staff and guests can get 'unrestricted' (to a certain degree) access. Edited April 19, 2024 by Roberto
PotNoodleTech Posted April 19, 2024 Posted April 19, 2024 Here is my scenario: So like most schools we have the following devices that require wireless access: Domain joined PC's Domain joined Laptops iPads Interactive screens Around 20 non domain joined PC's (acts as a kiosk for youtube access only) Guest devices Staff personal devices I am aware that many SSID's cause a world of pain, but with my limited knowledge this is the best way I can describe what our desired outcome would be. Just some comments on your main scenario before you implement the wifi as per the several great replies on this thread already: 1 - Domain Joined PCs should all be wired - they don't move so cable them in, this makes them faster more reliable and unburdens your wifi points to serve actual WIFI only devices that may need the bandwidth. 2 - Non domain joined but still internet connected PCs - is a big no no nowadays as they're a rife target for viruses and malware - wipe them join them in to the domain so you can ensure basic security and more advanced cybersecurity compliance and make sure they are hard wired in for reliability etc as above. 3 - Staff personal devices should be treated as guest devices. Basically anything that is school owned is not a guest, anything that is a personal owned device is on the guest network. 4 - Keep the number of customer facing Vlans to a minimum as the more vlans you have the more everything (particularly WIFI) slows down.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now