Jump to content

Recommended Posts

Posted

Having disabled the Student BYOD when we had Fortigate installed, I had been managing to keep it off for almost a year.....until now! SLT want it back on to allow students to access online polls etc as some students don't have enough data.

 

Having sorted out a way to give them easy access to install the SSL Cert, I wanted to double check some firewall rules before going live with a test group.

 

Student-Wifi.png

 

Student Wifi -> LAN - Do i really need this rule?

Year 7 and Year 12 Filtering - thinking, should I change the Services from All to http, https only?

 

Also, on my student test user, on an iphone, I am having issues when accessing any google, such as accessing the url google.co.uk and web searches due to blocking QUIC - is this normal?

 

Would you suggest any other changes?

 

Cheers

Posted

Student Wifi -> LAN - Do i really need this rule?

Does your student wifi dhcp hand out your LAN DNS servers addresses? that's what it looks like that rule is for. If you don't need to use the LAN DNS servers, you could swap to an internet DNS (like 8.8.8.8) or you can set up a DNS on the fortigate itself. I have done this for my Guest WiFi

 

Year 7 and Year 12 Filtering - thinking, should I change the Services from All to http, https only?

You can always try and see what breaks :) Since it is BYOD there maybe email apps etc that need other ports open.

 

We don't have BYOD and we don't use apple, so I can't help you if that's normal or not behaviour but we do block QUIC on our Windows desktops/Chromebooks without issue. Do the devices specifically it is a QUIC error?

  • Thanks 1
Posted

What filtering do you have on there.

 

Filter DNS query type 65, your fortigate can do it by itself, otherwise filtering can be bypassed.

 

Wouldnt be pointing any BYOD to lan, except for DHCP relaying if you do that. Firewall should handle that in some ways though.

 

Quic should be blocked on your Lan either way, student needs to turn off private relay, you also need to block those URLs on your firewall or run your own DNS and blackhole the requests to the iCloud relay...again, bypasses filter, anyone allowing iCloud.com is going to suffer with that.

  • Thanks 1
Posted
What DNS do you give them? I'd be very careful with how you manage the DNS provision and ideally you block the DoH/DoT options as it can be an easy bypass. I'd hope you/your ISP are doing some form of DNS scrubbing, but I believe your fortigate can, can't log in to one currently to check though.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...