Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

We have several student that bring in their own personal laptops. They are granted access to the wireless access points across the school. However, this is affectively like plugging directly into our main network (which is flat). They can browse UNC paths n all that :(

 

Files, printers etc are locked down with NTFS permissions but that doesnt mean they can't see or even steal a staff password to try get access.

 

Once they have just 1 password with more access rights then standard students then they may screw stuff up.

 

I have also tested and can confirm, a student can browse a share and use previous versions tab to restore an entire drive back months.

 

So... I've discussed the security issues regarding students bringing in unrestricted laptops and that i'm not supportive of the idea. The general feeling is - they are mature students that will lose the right to bring in a laptop should they abuse it.

 

Soo... we have dual channel radio points that I can enable to students could access a Students SID. However, how would I go about blocking everything other then port 80 etc.

 

We also use 1 local admin password for all workstations. If one student got hold of this information, they could affectively browse every staff laptop's system and data drive! Well you all know that's at risk.

 

I want to put something in place asap and as cheaply as possible.

Posted
If your APs will support it, you could have a student SSID which connects to a separate vlan and use routing acls to only allow access to 'student' resources.
Posted

I have also tested and can confirm, a student can browse a share and use previous versions tab to restore an entire drive back months.

 

If that's the case then I'm afraid you have a bigger problem.. students should only be able to restore their own files from shadow copies, otherwise - as you say - they can take the whole drive back as far as they want.

 

So... I've discussed the security issues regarding students bringing in unrestricted laptops and that i'm not supportive of the idea. The general feeling is - they are mature students that will lose the right to bring in a laptop should they abuse it.

 

Even if they lose the right to use them after the event, that doesn't undo the damage they've already done. First security principle: nobody is trustworthy beyond what you can verify about them independently.

 

Soo... we have dual channel radio points that I can enable to students could access a Students SID. However, how would I go about blocking everything other then port 80 etc.

 

That's the way to do it - but you also need to set up VLANs on your infrastructure, assign the students' SID to that VLAN (so their traffic is kept separate) and then firewall them off so they can only do what you want them to do - get to the web through your filter, for example. This all depends on your network hardware.

Posted
Files, printers etc are locked down with NTFS permissions but that doesnt mean they can't see or even steal a staff password to try get access.

 

Once they have just 1 password with more access rights then standard students then they may screw stuff up.

 

If your staff have passwords which are that easy to guess or steal, people bringing in unauthorised laptops is the least of your worries.

 

I have also tested and can confirm, a student can browse a share and use previous versions tab to restore an entire drive back months.

 

These users aren't members of your domain. Why are they able to access shares? Is there a particular reason that they can access these?

 

If so, do they just need read access? Take away any and all priviliges that they do not absolutely need.

 

Soo... we have dual channel radio points that I can enable to students could access a Students SID. However, how would I go about blocking everything other then port 80 etc.

 

As many have said, this'd be your best option. What access do these people actually need to your network?

 

We also use 1 local admin password for all workstations. If one student got hold of this information, they could affectively browse every staff laptop's system and data drive! Well you all know that's at risk.

 

Do you use the local admin account regularly? If not I'd say disable it using the GPO setting at Computer Policy | Windows Settings | Security Settings | Local policies | Security Options | Accounts | Administrator account status. Renaming it couldn't hurt either.

Posted

These users aren't members of your domain. Why are they able to access shares? Is there a particular reason that they can access these?

 

Because on browsing to the share, they will be prompted for credentials. Students with an account on the domain will just be able to use their normal login details here, and use the share in whatever way it is set up - normal NTFS permissions etc will still apply.

 

Do you use the local admin account regularly? If not I'd say disable it using the GPO setting at Computer Policy | Windows Settings | Security Settings | Local policies | Security Options | Accounts | Administrator account status. Renaming it couldn't hurt either.

 

I wouldn't, the point of the local administrator account is that it doesn't depend on network connectivity, functioning machine account, etc. If you break your domain membership, this is the only way to fix it.

 

I would set a strong password on it though, as you should be for any other sensitive account.

Posted

Our Sixth Formers connect to an AP in their Common Room (with MAC controls to prevent unauthorised access) on a separate VLAN; the router also has all the unnecessary ports locked down. We have given them instructions on how to configure the proxy server and how to add their networked printer; they then use the RAS (EasyLink in our case) to get at any files.

 

I wouldn't in a million years allow uncontrolled laptops to connect to the main network and get standard IP numbers. The risk of hacking programs, viruses, packet sniffers, etc is too great.

  • Thanks 1
Posted
As mentioned by others ... separate VLAN for students, use a WLAN controller to control what they can access (port 80 to a specific set of servers) and then run TS on these servers. The TS boxes are locked down, they can access what resources they need and have filtered internet access.
Posted

Ah thanks guys, really good advice.

 

@ powdarrmonkey - yup they use their own credentials to access shares.

 

Yes I agree with you guys, I want to restrict everything and section them off from the rest of the school.

 

They could use the VLE to access their work files should they need to.

 

Thanks again

 

:)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...