Jump to content

Recommended Posts

Posted

@Primus just for clarification - are you decrypting guest device traffic with MITM for your VPN mitigation/filtering strategy? If so, how do you handle onboarding regarding installation and trusting of required certificates?

 

This thread has me thinking of our strategy and if we are in our best stance moving forwards - we have complications that letting of the school room/pitches/etc. to the public/third-parties is handled by a separate business, the use of internet has been included with these lettings. At this point I'm not sure if the DfE holds relevance for this situation - it is not the school itself granting the internet access, however it is piggy backing the schools connectivity. Thoughts anyone?

Posted

Consider these lines in the DfE guidance:

"No filtering system can be 100% effective, you need to understand:

Your filtering systems coverage

Any limitations"

 

Being able to HTTPS MiTM Guest and BYOD devices presents a limitation, right? If that limitation is identified, noted and key stakeholders are aware, does that not automatically make you compliant with their guidance? Afterall, you're still filtering what you can within your technical and financial limitations. Hopefully you also have your users accepting an AUP as well.

 

I'd also highlight this:

"An effective filtering solution needs to block internet access to harmful sites and inappropriate content. It should not:

unreasonable impact teaching and learning or school or college administration

restrict students from learning how to assess and manage risk themselves"

 

At what point does blocking everything on your Guest WiFi for example cause administration an issue in terms of external agencies coming in that support the school? We have someone that comes in every week from county council, they connect to our guest wifi and they have to connect to some citrix server. If i block that so that no one can connect to such things, is that not an unreasonable impact to administration?

 

Important to note I'm not saying we shouldn't find solutions to those limitations, we constantly battle vs privacy to ensure our filtering is as effective as it can be, but there will always be some way to get around filtering .... short of blocking everything and only whitelisting, which is unworkable.

Posted (edited)
@Primus just for clarification - are you decrypting guest device traffic with MITM for your VPN mitigation/filtering strategy? If so, how do you handle onboarding regarding installation and trusting of required certificates?

 

This thread has me thinking of our strategy and if we are in our best stance moving forwards - we have complications that letting of the school room/pitches/etc. to the public/third-parties is handled by a separate business, the use of internet has been included with these lettings. At this point I'm not sure if the DfE holds relevance for this situation - it is not the school itself granting the internet access, however it is piggy backing the schools connectivity. Thoughts anyone?

 

Yes we apply HTTPS decryption to all devices using our connection. If a device cannot accept our certificate (usually because a user doesn't have admin priviliges) then it cannot use our WiFi.

We handle onboarding by referring people to the internal Smoothwall page that has the certificate and instructions for each OS - we use a DNS redirect so that they just have to enter sw.co/getmitm and it takes them to the page they need.

We will sometimes do the onboarding for people if they have issues following the instructions or they are VIPs such as Ofsted inspectors - we have found they often have a device from their school and so cannot use our WiFi because they cannot add the certificate but Ofsted supplies them with a 4G hotspot - truth be told Ofsted should really be supplying them with a device, they shouldn't be using their school device for Ofsted inspections IMHO.

 

I think we're clutching at straws with the piggy backing comments.

 

- - - Updated - - -

 

Consider these lines in the DfE guidance:

"No filtering system can be 100% effective, you need to understand:

Your filtering systems coverage

Any limitations"

 

Being able to HTTPS MiTM Guest and BYOD devices presents a limitation, right? If that limitation is identified, noted and key stakeholders are aware, does that not automatically make you compliant with their guidance? Afterall, you're still filtering what you can within your technical and financial limitations. Hopefully you also have your users accepting an AUP as well.

 

I'd also highlight this:

"An effective filtering solution needs to block internet access to harmful sites and inappropriate content. It should not:

unreasonable impact teaching and learning or school or college administration

restrict students from learning how to assess and manage risk themselves"

 

At what point does blocking everything on your Guest WiFi for example cause administration an issue in terms of external agencies coming in that support the school? We have someone that comes in every week from county council, they connect to our guest wifi and they have to connect to some citrix server. If i block that so that no one can connect to such things, is that not an unreasonable impact to administration?

 

Important to note I'm not saying we shouldn't find solutions to those limitations, we constantly battle vs privacy to ensure our filtering is as effective as it can be, but there will always be some way to get around filtering .... short of blocking everything and only whitelisting, which is unworkable.

 

If you allow and acccept VPN usage you have no idea what sites they're accessing and you have no control over it.

Edited by Primus
Posted
I think we're clutching at straws with the piggy backing comments.

 

The issue comes that it is an entity/organisation/charity/business/...whatever of it own right that sits outside of the school, has it's own books/finance etc. Ideally this should mean it has it's own internet that is managed as part of that business, but as it's a businesses started by the school (I believe) there would never be the investment in this. The school has internet connectivity, so just as it's the schools rooms/facilities that are let by this other organisation (that I believe to be owned by the school), the internet would fall into the schools resources they wish to make available.

 

To be clear - I'm not looking to evade anything/ get around DfE stuffs. More seeking advice and trying to produce a strategy that will work here with their setup. As an example, there is a letting that will have multiple different vendors with the site basically used as a convention centre in a few weeks. Vendors require internet access to complete card transactions as well as just general access, it's part of the stipulation for the letting - card machines aren't going to work with radius auth, at least not in the easy way needed for the vendors or with MITM in place - they are expecting a network they can just join. If this is a separate organisation that has made the letting agreement with these vendors (even if owned by the school) surely the DfE stuffs don't hold relevance, it now becomes about legal obligations and duties similar to a convention/business centre or even a pub that offers WiFi would have to honour?

 

The lines feel blurred for this situation, these visitors aren't guests of the school - or have any relevance to the school, they have hired a venue from an organisation that isn't the school...

 

I'm not being combative, or trying to play the system. Just trying to give more info and seeking thoughts and advice if anyone wants to share any thoughts.

 

 

The school's actual WiFi strategy is still a bit of a problem - it was/is felt that MITM is too hard to implement on guest devices - we are going to shift to radius auth for guests so at least traffic is tied to a user account.

Posted
The issue comes that it is an entity/organisation/charity/business/...whatever of it own right that sits outside of the school, has it's own books/finance etc. Ideally this should mean it has it's own internet that is managed as part of that business, but as it's a businesses started by the school (I believe) there would never be the investment in this. The school has internet connectivity, so just as it's the schools rooms/facilities that are let by this other organisation (that I believe to be owned by the school), the internet would fall into the schools resources they wish to make available.

 

To be clear - I'm not looking to evade anything/ get around DfE stuffs. More seeking advice and trying to produce a strategy that will work here with their setup. As an example, there is a letting that will have multiple different vendors with the site basically used as a convention centre in a few weeks. Vendors require internet access to complete card transactions as well as just general access, it's part of the stipulation for the letting - card machines aren't going to work with radius auth, at least not in the easy way needed for the vendors or with MITM in place - they are expecting a network they can just join. If this is a separate organisation that has made the letting agreement with these vendors (even if owned by the school) surely the DfE stuffs don't hold relevance, it now becomes about legal obligations and duties similar to a convention/business centre or even a pub that offers WiFi would have to honour?

 

The lines feel blurred for this situation, these visitors aren't guests of the school - or have any relevance to the school, they have hired a venue from an organisation that isn't the school...

 

I'm not being combative, or trying to play the system. Just trying to give more info and seeking thoughts and advice if anyone wants to share any thoughts.

 

 

The school's actual WiFi strategy is still a bit of a problem - it was/is felt that MITM is too hard to implement on guest devices - we are going to shift to radius auth for guests so at least traffic is tied to a user account.

 

We have taken the view - and had this supported by some consultancy we pay for in Safeguarding etc that if you are using our Internet connection you will go through our filter and we will not allow VPNs.

 

For WiFi you need something like RADIUS or a captive portal as you must know who did what. In 2024 if you're not using MITM then you're blind to so much traffic.

 

If you are a third party on our site and you are in an area of the building that does not have access to students and your company provide a dedicated connection for you use - eg. 4G hotspot then this is acceptable but running them through a VPN on our WiFi or even hard-wired is not since they would be using the school Internet connection and this requires filtering and monitoring.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...