Jump to content

Recommended Posts

Posted

We use radius here and offer WiFi to the sixth form and year 11 - In return for their MAC address they are given the key to log on.

 

Their MAC is entered into a local database within the managed wireless and then their AD account is added to a guest wireless group. Then when they access the SSID and go on the internet they are prompted to logon using AD account.

 

We dont support the devices directly but will help where we can - also have an active thread on our VLE where students share there issues and solutions etc if there are any blips.

 

They can access the internet and things like home access plus for their documents etc - in future we plan to offer Xenapp.

Posted

Not heard back from last night's meeting yet, but really hoping they let me wait the year.

 

Increasingly starting to suspect the best/easiest way to do this will be with a managed wireless system - I suspect we would need it anyway as at the moment, we just have a handful of dumb 802.11n APs dotted around as there's less than two dozen mobile devices on the network anyway - just a handful of laptops for the times when they're needed, a spattering of netbooks. If we start allowing personal student devices there's not much chance that infrastructure will hold up.

 

Might be worth looking getting HAP+ running to prevent the SPOF nature of local storage as well. And so the snowball rolls on...

Posted

Hi,

 

We too are looking at options for open wireless for students. We have a managed wireless system in place (Xirrus) and can set up a new SSID on a separate VLAN to keep the traffic seperate. We'd probably then look at a new server to handle DHCP (to registered MACs only) with a transparent proxy. Our LEA use NetSweeper, hopefully we can utilise that somehow also. RADIUS and AD authentication would be good, so we can place all registered users in a group - and firewalling to allow only port 80 as someone suggested earlier is a great idea!

 

My question - is there any product / appliance 'out of the box' that can do this at the moment (linking in to an existing wireless system)? I realise we can do all of this anyhow with various software and hardware but wondered if there was anything available?

 

Thanks!

Posted

We have started a BYOD scheme with our Sixth Form students this term, and its been a good success. As you would expect from my many posts on the topic over the last 4 to 5 years, I have used Ruckus wireless for my managed wireless, Smoothwall for the filtering, DNS and DHCP on this Sixth Form BYOD LAN and using Juniper Switching for the nice VLANs.

 

In terms of success, no complaints from students or the few staff using it, students logon to Ruckus into the Sixth Form wireless SSID, this is AD Security Group based, thus i have to add your account into an AD group before you can pass that point, once you have passed the Ruckus you can then get to the Smoothwall SSL Auth page and it then authenticates you against the main AD on our main systems, that be the last point you play with the main systems as you are put into the Sixth Form wifi VLAN and all you get is the internet and from that you get to the internet, webmail, vle and files and it works great :)

  • Thanks 2
Posted
May I ask: What is meant by "KS5 filtered internet" and "KS3 filtered internet"

 

Key Stage 3 (KS3) are filtered more strongly than Key Stage 5 (KS5 i.e. 6th form) here. As KS5 are voluntary students, it's up to them if they waste their time on Hotmail, as far as I'm concerned.

  • Thanks 1
Posted (edited)

@sonofsanta thanks!

 

I work at an independent boarding school so internet filtering here is quite complex. We keep all pupils away from web based email sites during their school day. Out of hours we allow those over 13 years old to access web based email sites and social networking sits.

 

Trying to recreate something like this on a guest wireless network proving difficult for us due to how personal devices vary in how they can work with proxy servers.

 

Not sure if a guest wireless network using a transparent proxy with no auth giving all connected users KS3 filtering would actually be used, they would probably just turn on their 3G connections :getmecoat:

Edited by drewp
Posted
Not sure if a guest wireless network using a transparent proxy with no auth giving all connected users KS3 filtering would actually be used, they would probably just turn on their G3 connections :getmecoat:

 

That's where "100 year old building out in the sticks" actually works out for me for once - to get 3G signal here I have to go and stand on the playing field over the road, so given the choice between unfiltered-GPRS-web and filtered-fibre-optic-web I reckon that unfiltered 3G connections isn't a worry ;)

 

(Plus, they can connect to the web that way whether you offer a wireless provision or not. If anything, offering something should reduce the numbers using mobile tethering etc.)

Posted (edited)
The problem with not telling them the password is Win 7 now allows you to view a key. Therefore removing the point in it being secret as they can just share with each other. I tend to look through logs and block ipods etc via mac address.

 

Apologise for being off subject.

 

Can they do this without knowing administrator credentials? I have tried on a student login, both trying to show the key and copying the wireless profile to memory stick require admin credentials.

 

Of course the allowing of student wireless devices opens a whole bunch of filtering, distraction, technical issues and access to unwanted sites and think there must be an SMT decision on this with all these points raised with any cost to infrastructure support.

Edited by Davit2005
Posted
Apologise for being off subject.

 

Can they do this without knowing administrator credentials? I have tried on a student login, both trying to show the key and copying the wireless profile to memory stick require admin credentials..

if they are bringing their own devices they are going to be admins of their own machines.

Posted

Some Wireless solutions can produce a shared key per user per device, once the key has been put into a device that key can't be used again.

 

Ruckus calls a it a Dynamic Pre-Shared key, AeroHive calls it a Private Pre-Shared key - I dont know of any other Wi-Fi solutions that offer this feature!

Posted
the student wireless is seperated and locked down to port 80 only

 

I accept that https traffic would have to be blocked if using a transparent proxy as it can’t be filtered, but how usable is the internet without it?

Posted

the reason we let them use their laptops at school is as a learning device.

 

so they can google, they can read wikipedia, they can access learning resources etc.

 

I have whitelisted a couple of SSL sites namely our MIS and Live@edu which is achieved by IP based ACL

  • Thanks 1
Posted
You need a better firewall \ filter for BYOD really, so much stuff can tunnel through 80 \ 443 now an application-aware firewall is a must imo...
Posted
I accept that https traffic would have to be blocked if using a transparent proxy as it can’t be filtered, but how usable is the internet without it?

 

It is possible to transparently filter https with the right filter. Sadly this relies on client side extensions not present in winXP, early IOS or pre-gingerbread android.

  • Thanks 1
Posted
@tom_newton I'm sure that I have the right filter in that case :D It's a shame it depends on the device being used though.

 

SNI is the trick we use - basically the browser gives away where it is going, so you can domain filter (and MITM if you feel that way out), sadly its a fairly new extension, but support is there in all major tablets and laptops afaik

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...