Jump to content

Recommended Posts

Posted

Hi all,

 

Just wondering what other boarding school do to allow students to contact parents. We had locked down our BYOD network which has had the intended action of blocking VPN software. I don't really want to start opening up additional ports for WhatsApp or Facetime as we might as well just open it back up again.

 

Thanks

Simon

Posted
Depends on what you are using for filtering. Our Fortigate allows us to control things at the application layer which allows us to be more flexible. Under the boarding standards there is a clause that defines the internet for "social purposes" so we relax our filtering slightly in the evening for boarders only. We then allow certain social network sites subject to age and currently allow Whatsapp (including calls) etc.
  • Thanks 1
Posted
We have set it up so that the boarding house pupils go on their own VLAN. This means we can relax the filtering on that VPN only with out them being able to mess around while in lessons. This does only work as teh boarding house is far enough from the school buildings so there is no bleeding of signal. This allows boarders not to be restricted if they have a free period, if they are ill and want to phone home or if they have a down day.
  • Thanks 1
Posted

Hi Andy, thank you for your reply.

 

So do you allow everything out effectively from the network layer (assuming for that vlan), but restrict at the application level? So blocking VPN applications, social networking apps etc, allowing you to allow the social networking apps on a time based schedule?

 

Thanks

Simon

Posted

Thanks for the reply TechMonkey. I like this, but its a shame that our boarding houses are close that they would be visible. I suppose I could always just broadcast on specific AP's, food for thought!

 

Thanks

Simon

Posted
We have filters for both web and application. These are both scheduled in the same policy which is matched against a group of users. Although we are moving to Lightspeed in the summer so will have to see what I can then achieve. Either way under the boarding standards it’s important to give them more access.
  • Thanks 1
Posted

Ah I see how it works then. Will be interesting to see how Lightspeed compares to the Fortigate. I used Lightspeed many years ago (probably getting on for 10!), I think it was called a bottle rocket then. Which model of Fortigate do you have? What made you change? We are due to replace ours Easter 2025 so will start the process around Dec this year.

 

Thanks

Simon

Posted
We have a managed virtual firewall set on independent hardware. We operate complete VLAN segmentation so it's not going anywhere as it governs traffic across the entire network and not just at the edge. When you look at the requirements from the DFE around offsite filtering (which is achievable with Fortigate) but mainly with DSL's having access to look at logs, monitoring etc I feel it doesn't meet them. Lightspeed will solve all of this for me especially as we are a BYOD school. To me their solution gives me the best support to protect boarders etc whilst allowing easy access and monitoring to DSL's. If we move to a 1:1 rollout they also allow parental access to device logs which could fit really into a boarding environment. From a technical perspective I love the Fortigate just feel they are trying to play catchup within Education. Having spoken to them directly they are also relying on a member of staff working in their own time for a set of reports to import into Fortianalyzer. This revelation was a little scary to discover!
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...