Jump to content

Recommended Posts

Posted

I've been asked to investigate the possibility of allowing student owned laptops access to the network for internet and possibly file access.

 

I'm aware of the security, PAT and insurance issues, but not sure on the best technical method

 

As a background we already have in place Ruckus wireless and smoothwall NG. Email is the only service currently available externally. This would be for sixth form students to start with.

 

I can see two possibilities to this:

 

Divide the network with VLANs and create a guest area that has internet access. - Proxy settings would be a problem, as would file access.

 

Setup a Remote desktop server - allow student devices access to this server only using ruckus restrictions. - cost prohibitive? Is citrix a better solution?

 

I think RDS has more advantages because the enviroment is controllable and there would be less compatibility issues, but I've never had to set one up before - how does the licensing work? what spec server is needed? etc

 

Has anyone already set up a student laptop access system? or is it more hastle than it's worth?

Posted (edited)

I was looking at this product.

 

BWireless, Wi-Fi hotspot solution, managing a system of hotspots, ideal for schools, colleges and universities, wireless internet access

 

Which will authenticate against Active directory via a web form, simelar to the way BT-Openzone works. This means you won't need to give out encrypton keys etc, but can still keep your wireless system safe from outside users using it. From here, you can allow them access to whatever you see fit as the whole system works within its own V-Lan. My idea was to have them having internet access only - I've been told you can route the whole lot through a proxy so no need for individual proxy settings, and then serve students remote desktops via a web based interface - no direct connections to server to stop the virus risk. As I understand it devices connected via this system cannot see each other either, they can only get out to whatever service you specify. Seems the ideal solution to me. :)

 

Unfortunitely budget contraints have stoped the purchase of this in the school I work in, but I did a fair bit of research into how it worked.

 

Mike.

Edited by maniac
Posted

Manic: The ruckus wireless system we already have in place can do this - wireless isolation, guest pass, access control. but there are issues with proxy settings, and multi login (one for ruckus then for smoothwall etc.)

If we went down the remote desktop route I would rather they used the internet through the session so we control the browser, and can use AD authentication.

Posted (edited)
Manic: The ruckus wireless system we already have in place can do this - wireless isolation, guest pass, access control. but there are issues with proxy settings, and multi login (one for ruckus then for smoothwall etc.)

If we went down the remote desktop route I would rather they used the internet through the session so we control the browser, and can use AD authentication.

 

I'm not familiar with Ruckus, apologies - didn't realise it had this functionality built in - our current wireless system is some what more antiquated. I've been told that that B-wireless system will pass authentication details up the line to a proxy, and it can be set to route all the traffic through the proxy so no settings to program in on the end user devices, but I've not actually seen it in action, only spoken to a technical advisor about it and read a bit.

 

Edit: As I understand it, the device works as a gateway and DHCP server in its own V-LAN, so traffic is automatically routed to it once they connect. Once they authenticate to it, it acts as a proxy in its own right routing the traffic wherever you want, so you can point it at your filter and from there out to the internet as usual, or you could point it at an internal server for them to establish a remote desktop session through.

Edited by maniac
Posted
We're planning this in our new campus, we're having a 'guest' VLAN for students and staff who wish to bring in their own laptops. Web access only, and connection to the LAN via terminal server only.
Posted
Divide the network with VLANs and create a guest area that has internet access. - Proxy settings would be a problem, as would file access.

 

Why? Can't you get Smoothwall to act as a transparent proxy and simply have DHCP dish out the gateway address? Could you have a router pass traffic for your file servers on?

 

--

David Hicks

Posted
VLAN for security and to split all the DNS and DHCP records so as not to pollute the main system. I tried transparent on smoothwall a while ago. I seem to remember AD auth didn't work with it and I don't want normal users to have to login, not tried since the new auth update.
Posted
I tried transparent on smoothwall a while ago. I seem to remember AD auth didn't work with it and I don't want normal users to have to login, not tried since the new auth update.

 

By "AD auth" do you mean NTLM authentication, or could you not get Smoothwall set up to ask users for their AD username and password when they first accessed the web? Assuming your pupil-owned laptops aren't joined to your domain, their users are going to have to log in to something at some point to prove who they are. I had some issues getting Smoothwall to talk to Active Directory, but Smoothwall support got the problem sorted pretty quickly.

 

--

David Hicks

Posted
By "AD auth" do you mean NTLM authentication, or could you not get Smoothwall set up to ask users for their AD username and password when they first accessed the web?

 

yep NTLM. - I don't like the idea of having normal users, on school network machines having to logon again to use the internet - I have yet to experiment with smoothwall's multi auth. Can I combine NTLM for domain computers with web login if not on the domain?

Posted
Can I combine NTLM for domain computers with web login if not on the domain?

 

Yes, I think you can - I've not tried myself as our filtering policy is to require someone to log in if they want to see a page limited to only certain users, otherwise we have open access for all.

 

--

David Hicks

Posted

Atm we are looking at this appliance: Quarantainenet

It provides secure guest network access, it can put devices which are not secure (virus, outdated virusscanner, outdated windows updates etc.) in quarantaine and a lot more.

Posted
Also consider PacketFence

 

How difficult/time consuming was this to implement? As with the OP this is something on my 'to investigate' list, and looking at the Packetfence site this looks like a good (free!) solution.

 

Cheers

Posted
How difficult/time consuming was this to implement? As with the OP this is something on my 'to investigate' list, and looking at the Packetfence site this looks like a good (free!) solution.

 

Cheers

 

If you download the 'ZEN' version, you'll get a preinstalled and preconfigured VMWare image to play with straight away.

  • Thanks 1
Posted

As an idea, what we do is this:

1. License sixth form pupils on a per user basis for Windows CALs and Microsoft Office (this is a special addition to our schools agreement and has the advantage that our sixth form pupils get to have a copy of Office)

2. BlueSocket wireless captures them when they use the wifi and sends them to a login page to authenticate

3. If authentication is successful, they are automagically redirected to our Citrix Secure Gateway server

4. Student then authenticates on the Secure Gateway server where they can access a remote desktop via XenApp

 

The way it's licensed also allows remote access from home via Secure Gateway. Those that use it seem to like it.

Posted
I will be introducing a 'guest' network at some point this year for this purpose. It will be on a segregated VLAN, which will be the default vlan should someone connect their laptop via cable, or will be the vlan of the guest wireless network. The vlan will not have access to any internal resources, instead giving access via the web instead. So, file transfer will be available via our VLE, and a web based printing interface will be exposed to allow them to print things without actually connecting to our printers.
Posted

Id like to see a good easy / cheap solution to this too, seems to be getting worse on our network.

I'm currently monitoring smoothwall when internet traffic slows down and seeing if there's any IPs using too much b/w

if there is i usually just manually block their IP (drop all packets) - if it continues i block their MAC in DHCP. I expect a knock on the door

but they never do!

Seems to be more of a problem with torrents - is there an easy way in smoothwall just to stop them authenticated or not ?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...