kennysarmy Posted January 23, 2012 Posted January 23, 2012 I've been asked to investigate the possibility of allowing students to use their own portable devices in school... The idea has been pitched as the teacher says 'right kids get your browser out'.....they connect to the schools wireless network ( which we don't yet have) and access the Internet on whatever they take out of their bag or pocket...school laptops being available to those who don't have anything.... I can't see how we would be able to log which sites they have visited.....as they won't be 'logging' in via AD.... The school Internet feed is obviously filtered so they should nt be able to get to anything that nasty...and it could be argued that the teachers should be keeping the kids on task, so that it would nt be necessary to log everything.... Wondered how other schools tackle this issue?
CyberNerd Posted January 23, 2012 Posted January 23, 2012 I can't see how we would be able to log which sites they have visited.....as they won't be 'logging' in via AD.... Get them to log in to AD via the proxy is how we do it. Smoothwall is probably what you need here. 1
saundersmatt Posted January 23, 2012 Posted January 23, 2012 Get them to log in to AD via the proxy is how we do it. Smoothwall is probably what you need here. This is exactly what I'm proposing as the solution to the same problem where I work. Matt
kennysarmy Posted January 23, 2012 Author Posted January 23, 2012 Get them to log in to AD via the proxy is how we do it. Smoothwall is probably what you need here. We are thinking of moving from our RM smartcache to the smoothwall product.... So with this we can direct the wireless traffic to the Internet via a logon screen linked to AD? Would it matter which wireless solution we end up going for? Are there any better ones which would work for the above scenario?
Ashm Posted January 23, 2012 Posted January 23, 2012 Yep, we're using Smoothwall with the SSL Login page authentication option for our student guest network. They login using their AD credentials and then they get their normal filter level depending if they're 6th form or yr7-11 etc as they would when they log onto one of the school computers. And of course all the usual logging is done in case we need to check up on anything later.
CyberNerd Posted January 23, 2012 Posted January 23, 2012 So with this we can direct the wireless traffic to the Internet via a logon screen linked to AD? yes. Would it matter which wireless solution we end up going for? Are there any better ones which would work for the above scenario? It should work with any wireless solution, essentially your just redirecting traffic to a proxy server. I would advise paying attention to whether your wired network and broadband can cope with the projected number of machines (as well as whether the wireless solution is scalable). 2
tom_newton Posted January 23, 2012 Posted January 23, 2012 Thanks guys, all the Smoothwall information presented here is correct as far as I see it We are working to integrate even more closely with various wireless providers, and to offer more options for login - but certainly right now the login page can be presented to wireless users so their accesses are logged against AD username.
AMLinington Posted January 24, 2012 Posted January 24, 2012 It is worth mentioning though, that by 'browsers' we assume you mean 'personal laptops' as Android devices and IPads are a whole different kettle of fish. IPad browsers currently do support SSL Login, so SSL Login would be ideal for laptops and ipads, but android devices do not support the keep-alive connection within multiple browser windows that is needed for the SSL login page to work and iPad apps will only work if they are proxy-aware. There are other ways to get around this, but Android devices in particular are a bit of a spanner in the works at the moment - at least until Ice Cream Sandwich (and honeycomb for tablets). It is also worth making you aware that if you set up a transparent SSL Login authentication method, the client machines will need to be using the Smoothwall as their default gateway and they must leave the login page open once they have logged in and browse via different tabs or a new browser window so some minor user training will be needed. As Tom mentioned, there are lots of exciting things going on in the Smoothwall development office surrounding authentication methods, Android devices and iPads etc so watch this space, so to speak.
10101010 Posted January 24, 2012 Posted January 24, 2012 I would be interested to know if Smoothwall can prevent access to the network if a student unplugs a school device(wired) and plugs their own device in?
DT2 Posted January 24, 2012 Posted January 24, 2012 Switch port access set to MAC of the school machine attached and set to shut down on violation would take care of that. Since only outbound traffic hits the smoothwall, if they're trying to attack your servers, then the smoothwall is helpless, and that's where the switch security comes in. If they're unplugging school systems to plug in their own and browse, then yes, transparent proxying will catch the little blighters out DT 1
CyberNerd Posted January 24, 2012 Posted January 24, 2012 I would be interested to know if Smoothwall can prevent access to the network if a student unplugs a school device(wired) and plugs their own device in? Other than securing your switches, you could also look at Network Access Control. Packetfence is free and designed for this sort of thing PacketFence: Open Source NAC (Network Access Control) 1
Sylv3r Posted January 24, 2012 Posted January 24, 2012 Another here for the SSL login via Smoothwall. Been using it here for a while and works well - not that we have any time to actively check the logs, but the option is there if we ever need to.
kernewek-sam Posted January 24, 2012 Posted January 24, 2012 Get them to log in to AD via the proxy is how we do it. Smoothwall is probably what you need here. They log in to AD via proxy, but the LA provides filtering which includes logging.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now