Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

just over 2 years ago I managed to persuade SLT to drop student wifi (BYOD) access for the following reasons.

 

  • Cyber Security issues/concerns
  • Web Filtering - either blocked due not installing SSL Cert or the use of VPN to bypass it.

 

Now, there could be rumblings of the 6th Form team asking for it to be reinstated.

 

How many other schools with 6th Form allow Student BYOD

 

What Firewall/Filtering to you have and what APs?

 

Did have Smoothwall and Unfi NanoHD Aps and now have a Fortigate with Unifi U7 APs.

 

Any info welcome.

 

Cheers

 

  • Like 1
Posted

We have it, it's actually necessary due to the way we issue them laptops that aren't on our domain. Uses RADIUS with their normal logon, but it does not pop out on our range and it's on a separate VLAN I think. Filtering managed further up the chain by the firewall (LEA managed). Cisco APs (AX).

  • Like 1
Posted

Think carefully about how you are going to effectively filter and monitor devices using your connection which are not managed by you - in my previous role we removed BYOD entirely because of this.

  • Like 1
Posted

We have FortiGate firewall, Smoothwall filtering, Cisco Meraki Access points, radius authentication with AD credentials.

 

Student authenticate with their school account to the SSID, Meraki places the traffic on a specific 6th Form BYOD vlan. Vlan is location in the smoothwall to fine tune filtering if required, intervlan routing is handled by the firewalls which block everything between internal vlans and allow only specific ports to connect to the wan from the 6th form byod vlan. We do need to assist students wishing to join the network as they require the SSL CA cert installing, but this is manageable with the number of students and techs we currently have; 6th form students have a suite of domain joined computers they can use for study sessions/outside of lessons which lifts some of the pressure for byod.

  • Like 2
Posted (edited)

Currently you might have to lock it down so it's only certain devices, which some might deem unfair. You can't offer BYOD to anyone using iPhones or iPads with mobile connectivity and remain KCSIE compliant. For this purpose we're looking at removing it entirely from 6th form.

Edited by synaesthesia
  • Like 1
Posted

Before I removed it, they were in a isolated VLAN but due to not really know what was connected, I played the Cyber Security and Safeguarding cards which worked - as I was backe by the DSL and I'm hoping he is still on my side!

Posted
17 hours ago, synaesthesia said:

Currently you might have to lock it down so it's only certain devices, which some might deem unfair. You can't offer BYOD to anyone using iPhones or iPads with mobile connectivity and remain KCSIE compliant. For this purpose we're looking at removing it entirely from 6th form.

 

Can you expand on this so I can review and start discussions here please?

Posted
1 hour ago, ThomL said:

 

Can you expand on this so I can review and start discussions here please?

Sure - see 

 

In a nutshell, where mobile data is available should a device not be able to reach a website (in our case due to filtering) it will use other methods to get to that site, effectively loading it via mobile data even though wifi is available.

How this is reported on filtering systems is yet to be seen - the current assumption would appear to be it shows as blocked, but in reality the user is browsing those sites apparently still connected via WiFi.

My understanding may be flawed however and there's been precious little information other than this and a couple of news articles. It may be that we just "suck it up" but in my black and white mind I can't see how this could be usable.

Posted (edited)

This is obviously knocking on a bit since I was in education, but we implemented Eduroam with all the implications around RADIUS + Cert Auth for device and user identification. This allowed us to provide appropriate filtering on our connection as our WiFi and Firewall/Filtering system shared the same RADIUS identity. Users only had use of the wifi to get access to whatever services we offered externally (which even then, were considerable due to stuff being in the cloud).

 

This made visits by 6th formers to unis, and visits to us by uni people quite painless to support which was a nice bonus. Now we were a 6th form college which made it easier to do this of course, but it should be possible to set up Eduroam wifi, and only make it available to staff/6th formers.

 

Now I've said all that, the points about KCSIE and mobile devices fetching sites however they can are very well made. I might be tempted to steer well clear of anything that might create ambiguity about whether your school allowed browsing of anything questionable, these days. The easiest way to win an argument remains avoiding having it in the first place.

Edited by Roberto
Posted

Another vote for eduroam here. We've had very good uptake on it and the benefits to staff and students are very clear.

Personally I find that not providing any form of BYOD pushes students towards using their mobile data which may not be filtered appropriately. For cyber security concerns, would you be able to have the BYOD network's gateway on a firewall in an untrusted zone?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...