Jump to content

Do you allow students to bring there own devices on the network.  

61 members have voted

  1. 1. Do you allow students to bring there own devices on the network.

    • Yes
      13
    • No but may do in the future
      30
    • No and can't see we will ever allow it
      18


Recommended Posts

Posted
6th form are currently allowed wireless internet access after MAC addresses are collected and their laptop has been pat tested. They aren't allowed on to the main network, just a special vlan with access to the filtered proxy.
Posted

I'm looking into providing 6th form access via a suitably secured section of my BlueSocket infrastructure.

 

I think I will provide ridiculously heavy filtering for Internet access and a connection through to my Citrix farm.

Posted

Yes - we're a private school, and despite what some people might think we don't have very much money at all to spend on ICT (all our money is raised from fees, we don't just get money handed to us). Our pupils do, however, tend to be from the more affluent section of society, and many have their own laptop, phone, etc (some very nice Macbooks turning up after Christmas). Not allowing them to use it at school seems like a waste of an opportunity. Web access is transparently filtered, of course, but other than that we can't really stop them doing much - we don't have enough money to buy anything but the most basic of networking equipment anyway.

 

--

David Hicks

Posted (edited)

we allow student owned mac laptops(we had a laptop scheme 4/5 years ago) on to the wifi with small amount of network access, odd printer avilable for them to print and internet access.

 

ipod touches, iphones (yes students have these already! we have a fairly middle class cohort) wifi enabled phones such as Nokia N95s. Next years plans are netbooks for year 7 and more access for student owned windows laptops/netbooks in other years.

Edited by gaz350
Posted (edited)
6th form are currently allowed wireless internet access after MAC addresses are collected and their laptop has been pat tested. They aren't allowed on to the main network, just a special vlan with access to the filtered proxy.

 

Exactly how we do it, too. Uptake has been slower than anticipated, though...

 

Is PAT really necessary though? Some of them will have been bringing them in for years anyway without getting you test them, plus they no doubt have plenty of other non-PAT'ed electrical equipment (phones, CD players, etc), so why is the laptop different?

Edited by enjay
Posted
6th form are currently allowed wireless internet access after MAC addresses are collected and their laptop has been pat tested. They aren't allowed on to the main network, just a special vlan with access to the filtered proxy.

 

Looking at doing the same thing here, just another thing on the list.

Posted

We do allow other devices onto the wireless (although don't massively publicise the fact). It is all nicely locked down to require the student username/password for access & we log all activity too.

 

Seeing a gradual increase in the number of things connected, probably far more iPods and things than laptops at the moment.

 

Tim

Posted
We allow student's laptops to connect. Anything that connects has to authenticate via PEAP with the student's network login credentials, so we can trace back all internet access and kick anyone off by disabling their AD account.
Posted

little bit different, but we have a common room for our 6th form... and in there they have a 46" TV :) and they are going to be able to bring in there xbox360's etc but our ite manager has said they must be pat tested first! either that or the school have to buy a game console for them!

 

We have people coming in to school, we dont check to see if there laptop's are tested. just no need for it really

Posted
Those of you who are allowing students' devices straight onto your network - what are you doing to prevent use of packet sniffers and other suck HaCkInG tools, or to prevent Nimda-esque viruses grinding the network by polling for vulnerable computers?
Posted
Those of you who are allowing students' devices straight onto your network - what are you doing to prevent use of packet sniffers and other suck HaCkInG tools, or to prevent Nimda-esque viruses grinding the network by polling for vulnerable computers?

 

I am also interested in what you do, i would use a v-lan myself. It only takes one of them to have DHCP on a laptop to bring everything down.

Posted
Those of you who are allowing students' devices straight onto your network - what are you doing to prevent use of packet sniffers and other suck HaCkInG tools, or to prevent Nimda-esque viruses grinding the network by polling for vulnerable computers?

 

The use of VLANs to separate these devices off is one measuer that can be used. Theer are also methods of allowing access to specific destinations only - thus making packet sniffers a little redundent. Wireless traffic, of course, should always be denied access between clients.

Posted
6th form are currently allowed wireless internet access after MAC addresses are collected and their laptop has been pat tested. They aren't allowed on to the main network, just a special vlan with access to the filtered proxy.

 

That will be our approach, when we finally get round to it :)

Posted
What about those systems from like cisco which make sure the computer (in this case laptop) has filly updated antivirus and updates installed before allowing access to the restricted network (eg: would touch home network connection) i haven't seen/read much these but would it be worth-wile if you could get the funding for it?
Posted
What about those systems from like cisco which make sure the computer (in this case laptop) has filly updated antivirus and updates installed before allowing access to the restricted network (eg: would touch home network connection) i haven't seen/read much these but would it be worth-wile if you could get the funding for it?

 

There is NAP (Network Access Protection) built in to Windows Server 2008 and various security products, the seporate VLANS and subnets just give you an extra possibly more robust level of protection.

Posted

We use a seperate VLAN for student laptops, iphones etc. All students are welcome to bring their devices in, although parents are aware of the insurance implications - damage, theft etc.We use one of the ports on our smoothwall box for filtering and DHCP.

 

We have printed laminate business cards with a map of the school on one side with the various WAP's identified and the wireless security key on the other, that we distribute to students on request.

Posted
Is PAT really necessary though? Some of them will have been bringing them in for years anyway without getting you test them, plus they no doubt have plenty of other non-PAT'ed electrical equipment (phones, CD players, etc), so why is the laptop different?

 

Probably, in an arse-covering sense, if you're now formalising them - i.e. permitting them to bring them in and knowingly adding them to the network - you'd need to do it to cover yourself. Previously the school could just have said "we didn't know" or "they're not supposed to use equipment without PAT".

 

(This said we are very behind on our PAT because nothing is done about our lack of time/staffing, sigh).

 

As a rule we don't let personal devices on, I don't know what may happen in the future - it's outwith my control - I think I heard some mumbling about letting 6th formers on the wireless in their common room, but that's another (case of) tins of worms...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...