Jump to content

Recommended Posts

Posted

OK first off let me say that I work for a boarding shcool and I am well aware that the answer the sensible answer to my question is "don't even think about" however pressing on...:D

 

Does anyone allow students to connect their laptops to their network? Either Wirelessly or cabled? If so what have you done to secure it and prevent them from spending most of their time looking for adult material on the internet, spreading virus and generally being pains in the backside?

Posted
Use a seporate routed, filtered and restricted VLAN to isolate them and only give them access to filtered net and those services that you can provide securely, it is almost like setting the network up for external access. You lock them off the primary network with something like packetfence or MAC based dynamic VLANs if your switches support this and you are away.
Posted

Personally I wouldnt allow the kids to connect there laptops, full stop!

 

If it was a member of staff I would check it over first for virus, spyware etc etc

 

Ian:)

Posted

When john used to work at a boarding school one of the little blights plugged in a wireless router. This gave everyone different IP address.

 

se a seporate routed, filtered and restricted VLAN to isolate them and only give them access to filtered net and those services that you can provide securely, it is almost like setting the network up for external access. You lock them off the primary network with something like packetfence or MAC based dynamic VLANs if your switches support this and you are away.

 

I would do all that put also in the DHCP give all laptops reserved IP's so you can trace back to a user more easier.

Posted
When john used to work at a boarding school one of the little blights plugged in a wireless router. This gave everyone different IP address.

 

Thats where a combo of packetfence and dynamic VLANS come in, it is trivial to clone the MAC of an existing pc to get past this but it is an extra layer of protection that would probably have stopped this form of bypass.

 

Implementing the NAP protection avalible in Server 2008 would also have rendered this pointless as they would not have been able to make contact with anything useful anyway.

Posted
Does anyone allow students to connect their laptops to their network?

 

Yes, anyone can wander in and use our network. I guess decent switches that can block unknown bits of hardware would be nice, but we can't afford those. I vaguely intend to get around to splitting the wireless network off onto its own separate VLAN at some point (although that wouldn't stop people simply plugging stuff into a wired port). We have a transparently filtered Internet connection, of course, and we secure our servers (er, I hope).

 

--

David Hicks

Posted

We're similar to David here except our router will only allow access to the internet via the proxy so we're covered on that angle.

 

A seperate vlan for wireless would be nice, and maybe for Christmas Santa'll give me it.

Posted
Use a seporate routed, filtered and restricted VLAN to isolate them and only give them access to filtered net and those services that you can provide securely, it is almost like setting the network up for external access. You lock them off the primary network with something like packetfence or MAC based dynamic VLANs if your switches support this and you are away.

 

We do pretty much that here. We freely give the WEP key out to all who want it and I think this way the plugging laptops directly into the network will be avoided.

Posted

I'm currently working on this for our school.

 

We've just updated our cisco wireless system. We can now have multiple SSIDs on any of our APs. Each SSID can have a different authentication method and will assign you to a pre defined VLAN.

 

We have an SSID with no security, that puts the users onto a separate VLAN where our smoothwall box sits.

 

When users attempt to access the internet it can be set to ask for a username / password or just an email address.

 

It was an expensive upgrade but it now gives us a great deal of flexibility. We intend to provide SSIDs for our conference centre, fitness centre and for pupils / trainee teachers.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...