klssandman76 Posted May 22, 2024 Posted May 22, 2024 Hi all, Just wondering what others allow protocol/ports wise who have BYOD networks for students. Going from a block all out perspective. Thanks Simon
synaesthesia Posted May 22, 2024 Posted May 22, 2024 Allow 80 and 443 only. ICMP maybe for troubleshooting purposes. May need something else depending on printing solution but the likes of papercut webprint etc is 443 anyway.
Olliedawg Posted May 22, 2024 Posted May 22, 2024 Probably not the most secure but on our XG i have the student BYOD VLAN set to Destination Zone : WAN Destination Network : Any Services/Ports : Any Web filter policy : Student Captive portal login required 1
MatthewL Posted May 22, 2024 Posted May 22, 2024 TCP:80, TCP:443 and UDP:53 for DNS unless they can use an internal DNS will give you plain internet access. I would look at UDP:123 for time, any email ports such as TCP587, 465, 993, 995 for any email client. VPN ports if any VPN's are needed such as UDP500 and UDP4500, UDP1701. Any voice ports such as 5060 if any voice clients are needed and then Teams such as 3478 and the various ports that it uses with the specific destination noted, all found on Microsoft's website. Depends on the use of that network but you need to consider what is been used like Google Drive, OneDrive, Teams, Zoom if it uses bespoke ports. 1
TechMonkey Posted May 22, 2024 Posted May 22, 2024 I wouldn't open UDP:53 as blocking it can stop a lot of malware and ransomware phoning home. This may have been superseded by DoT & DoH but belt and braces. 2
MatthewL Posted May 22, 2024 Posted May 22, 2024 Depends on your setup, if you force your clients to say have DNS of Google then you would need to allow that out, depends on your setup.
TechMonkey Posted May 23, 2024 Posted May 23, 2024 Interesting, why would you force users to set a manual DNS? Surely, you'd set your own DNS to look at the Google DNS and then push your own DNS to users via DHCP. Yes, you need to allow your own DNS servers to access external DNS, but that is beyond the scope of the question, it is asking about BYOD firewall. 1
DGardiner Posted May 23, 2024 Posted May 23, 2024 Hi all, Just wondering what others allow protocol/ports wise who have BYOD networks for students. Going from a block all out perspective. Thanks Simon block all out is the way, its too easy to spin up a tunnel on anything you leave open, its there to provide internet access nothing more from my point of view and thats done via proxy 1
PaddyNewman Posted May 24, 2024 Posted May 24, 2024 Probably not the most secure but on our XG i have the student BYOD VLAN set to Destination Zone : WAN Destination Network : Any Services/Ports : Any Web filter policy : Student Captive portal login required Isn't that just open, so farewell to any security. I'd be turning up with a VPN everyday. Or connecting to one of the millions of open proxies, or just setting my DNS to somewhere else. Web filters are using 80/443 only. I'd be locking that down personally as that's open to abuse. 1
georgeescott Posted May 24, 2024 Posted May 24, 2024 If you force your clients to say have DNS of Google then you would need to allow that out, depends on your setup. We use an internal DNS server, but for those who are setting an external DNS provider like Google in their DHCP settings, it'd probably be better to use 1.1.1.3/1.0.0.3 (https://one.one.one.one/family/) rather than Google as this blocks Malware and Adult Content via DNS (on top of your own filters). 1
tom_newton Posted May 24, 2024 Posted May 24, 2024 Concur with 80 and 443 and wait for someone to complain about anything else. 99% of software can fall back to -over-https-connect style anyway
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now