Jump to content

Recommended Posts

Posted
And what product would you recommend to ensure they're not launching DoS attacks and such like from their laptops?

 

Here's a thought, albeit an unlikely one - where would the school stand if students hacked MI5 or wherever from a personally-owned PC over the school-provided Internet connection?

 

As an aside, I trust all those of you who are allowing this are PAT testing the laptops first...

 

Key here is don't need to pat test as long as they do not plug the device into a school mains socket. :)

 

 

Russ

Posted
We have one kid, who has serverly got special needs, who has permission to bring in his laptop. We make him sign a slightly edited AUP with an extra cause about not connecting it to the network. He has tried to connect it once again, and, then, it was taken out of our hands and delt with by our LMT.
Posted

Th way we have approached is to use setup a vlan and use radius server to authenticate users using their normal network logon. This cuts out the hassle of them remember yet another login.

 

In the vlan we have setup a simple (desktop PC) DNS and DHCP server which is allowed to talk to the internal DNS server only. This hands out DNS and DHCP info to the sixthform student's devices.

 

For security the DG is setup to point to out ISA server (a NIC dedicated to the wifi network) so we can create and lock down the vlan traffic. In additon i also created some ACLs on the switch for this particular vlan so it only allows HTTP, HTTPS, DNS to the outside world. The fact that the traffic is going through our proxy server which has our web filtering software installed is that we can create web filtering rules so they can only get to certain sites.

 

The radius server setup we use is the MS IAS 2003 with PEAP authentication. We used our own CA to issue the certificate to the radius server. Students come in with their laptop to be configured on the wifi network, they are not allowed to do this themselves. During the setup we copy the CA's Root certificiate to the student's laptops so our CA is trusted during PEAP process.

 

The students have to sign the form which has their name, serial number of their laptop/device and a signature of the technician who setup the wireless network. It also records the wireless mac address of the device as well.

 

The above works well and it didn't really cost that much as the DHCP/DNS server is a old desktop station that was taken out of classroom due to low spec.

 

Let me know if you want more information.

 

Ash.

Posted

Like a number of people have said this is the way forward. The issue is not a yes or no but how we ensure it happens in a safe and secure way which is easy for the user.

 

Start to think about the future and look at the big picture, technology changes and it will change how we do things. Don't look at it as doing old things in new ways but as new things in new ways. Ask yourself how mackie "D" does it? How it allows people on to its wifi but also uses the system for its business.

 

There are people pushing the idea, do schools need a network as such, do they need servers on site?

 

Why not use cloud computing and SAAS. Why buy computers give everyone a voucher ?

Posted

I have got an unpublished article that I wrote while back may tidy it up and publish it. Gist of it is that pupil computer schemes be that Computer for pupils or the usa one-to-one agenda are just not viable in the long term heck the laptop for teacher programme in uk proved that buy everybody a computer what do you you do 3/4 years down line where does replacement come from.

 

So next thing we have to do it looking at secure and safe way of doing it. But then another arugment to all this is we can never do it complete secure way and inexpensive way. So we then have to look at the bigger picture of digital literacy.

 

Russ

Posted
Why not use cloud computing and SAAS.

 

Sure, but not using computers somewhere at the other end of an Internet connection, not yet, anyway. Internet connections still aren't reliable/fast enough, it will be a few years until an Internet connection can cope with 30/60/90/etc pupils video editing at the same time. Also, your data winds up on someone else's random system somewhere, or (more likly) several someones' several systems somewhere, you don't have full control over it and you can't (yet) make all those separate system work together nicely.

 

--

David Hicks

Posted
Ask yourself how mackie "D" does it? How it allows people on to its wifi but also uses the system for its business.

Those systems probably aren't on the same network, though, possibly not even the same physical wiring.

 

Another question which needs addressing is how you ensure that staff aren't teaching lessons using illegal software on their personal computers - could put the school in a nasty position.

 

I know I'm coming across very negatively on this, which I don't entirely mean to. While we do have a "no" policy, this is because we haven't found acceptable (i.e. both technically and financially possible) methods of delivering such a service, and therefore say no, and will continue to do so until we can find a such a solution.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...