Jump to content

Recommended Posts

Posted

Probably not the most secure but on our XG i have the student BYOD VLAN set to

 

Destination Zone : WAN

Destination Network : Any

Services/Ports : Any

Web filter policy : Student

 

Captive portal login required

  • Thanks 1
Posted

TCP:80, TCP:443 and UDP:53 for DNS unless they can use an internal DNS will give you plain internet access.

 

I would look at UDP:123 for time, any email ports such as TCP587, 465, 993, 995 for any email client. VPN ports if any VPN's are needed such as UDP500 and UDP4500, UDP1701.

 

Any voice ports such as 5060 if any voice clients are needed and then Teams such as 3478 and the various ports that it uses with the specific destination noted, all found on Microsoft's website.

 

Depends on the use of that network but you need to consider what is been used like Google Drive, OneDrive, Teams, Zoom if it uses bespoke ports.

  • Thanks 1
Posted
I wouldn't open UDP:53 as blocking it can stop a lot of malware and ransomware phoning home. This may have been superseded by DoT & DoH but belt and braces.
  • Thanks 2
Posted
Interesting, why would you force users to set a manual DNS? Surely, you'd set your own DNS to look at the Google DNS and then push your own DNS to users via DHCP. Yes, you need to allow your own DNS servers to access external DNS, but that is beyond the scope of the question, it is asking about BYOD firewall.
  • Thanks 1
Posted
Hi all,

 

Just wondering what others allow protocol/ports wise who have BYOD networks for students. Going from a block all out perspective.

 

Thanks

Simon

block all out is the way, its too easy to spin up a tunnel on anything you leave open, its there to provide internet access nothing more from my point of view and thats done via proxy

  • Thanks 1
Posted
Probably not the most secure but on our XG i have the student BYOD VLAN set to

 

Destination Zone : WAN

Destination Network : Any

Services/Ports : Any

Web filter policy : Student

 

Captive portal login required

Isn't that just open, so farewell to any security. I'd be turning up with a VPN everyday. Or connecting to one of the millions of open proxies, or just setting my DNS to somewhere else.

 

Web filters are using 80/443 only. I'd be locking that down personally as that's open to abuse.

  • Thanks 1
Posted
If you force your clients to say have DNS of Google then you would need to allow that out, depends on your setup.

We use an internal DNS server, but for those who are setting an external DNS provider like Google in their DHCP settings, it'd probably be better to use 1.1.1.3/1.0.0.3 (https://one.one.one.one/family/) rather than Google as this blocks Malware and Adult Content via DNS (on top of your own filters).

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...