cwuk100 Posted February 19, 2025 Posted February 19, 2025 Hi, we have a iOS devices currently and we can only identify the device in the filtering logs and not the user and when we have 1:many devices this is not really suitable. We started looking at third party options such as solutions by Albion and Securly. However I contacted LGfL to see if we could "potentially" drop the SchoolProtect filtering part of the broadband provision as we do not want multiple filters and we were told "It is not possible to turn off SchoolProtect while still using the LGfL firewall. 3rd party filtering may be possible but will create interference ". I am fairly new to LGfL and SchoolProtect so any information or guidance would be great. Thanks in advance. Chris
psydii Posted February 19, 2025 Posted February 19, 2025 (edited) 0) If you have a product that does all the filtering you need on the ipads in the way you want, this should be possible. 1) move the ipads on to their own vlan so the are double NAT'd, the ipads have a 192.168.x.x address, and this egresses into LGFL via a gateway/router/fw that has an LGfL 10.x.x.x address as its WAN interface. 2) depending on the solution chosen step 0, this gateway might be the 3rd part firewall, or your own (school managed) router/firewall (with the ipad filteirng being an app/vpn based solution). 3) In SchoolProtect, set things up so traffic from the WAN interface of this gateway DOES NOT HAVE SSL/TLS inspection enabled - leave that to you 3rd party filter. 4) apply a default set of policies to the WAN interface of your gateway, and from then on ONLY use the 3rd party filter to controll what users on the iPads can see. Just be aware that sometimes you may encounter a situation where your default SchoolProtect policy is more restrictive than your 3rd party filter, and you will need to relax the SchoolProtect policy to allow the traffic, but generally we find we don't have to make adjustments to the filtering. You just need to remember to check both locations when something odd happens. Edited February 19, 2025 by psydii
PaddyNewman Posted February 20, 2025 Posted February 20, 2025 I've reached out and if we can do a teams call that would be awesome. If it was 1:1 its so much easier but 1:many means you can't truly know pupilA is using it, devices get passed around. I'm not sure you can identify users clearly with a 1:many... I have a mild dislike to apple for these things as there's very little in the way of school based authentication at the start of the session and it's rather hard to filter them when they are just IPs. However let me tag in @DavidYoung also... 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now