Jump to content

Recommended Posts

Posted

Simple question really, we have setup all our systems ready for BYOD "bring your own device".

 

- Guest wireless network

- 100mbit Internet line

- Transparent Proxy filtering (coming soon)

- VLAN

 

I'm happy enough with the technical side of things now.

 

But how do schools do it in real life? Does anyone actually allow this in school?

 

How do you manage and monitor it?

 

Its such a huge change I'm struggling to get my head around the implications.

Posted
We had a look at virtual desktop for this as it would be perfect, own device, but managed system. But unfortunately the licencing is a nightmare, requiring each device, which isn't yours, to have a VDA licence purchased for it even if you have EES or equivalent. Has been parked for now!
Posted
But how do schools do it in real life? Does anyone actually allow this in school?

 

How do you manage and monitor it?

 

We do this, though we run a netbook scheme which they can be purchased though the school. Access to their user area, VLE is done through the school website. To monitor this when they open IE etc they have to sign in to the proxy using their AD creds, this means that what they can browse is filtered as would be on any PC in the school.

Posted

I'm still trying to get my head around this at the moment.

 

Do I run 3 wireless SSID's

 

Main School Wireless - School owned and controlled devices only, full access to domain etc....

BYOD - Staff/Student owned devices, Smoothwall SSL login page to get customised filtering level, possible access to school resources file servers etc...

Guest - Unknown "dirty" guest devices, Internet access only, draconian web filtering

 

Or do I run the school one and the guest one to make it simpler?

 

To support the guest wireless on the current infrastructure but seperate it using vlans is this what I need to do:

 

Core switch HP 4108GL - At the moment the test WAP plugs into this but to support the guest wireless around the site all the switches would need to be setup to support the guest vlan.

 

Wireless Access Point - Main wireless SSID for school devices, Guest SSID, vlan set to 3 (guest), switch port that WAP is connected to tagged with vlan 3

 

DHCP Server for guest devices - Virtual machine running a dhcp server to give ip addresses etc... to guest devices, virtual nic tagged with vlan 3, switch port that virtual host connects to tagged with vlan 3.

 

Smoothwall SWG-1200 - different nic port from main school network configured with vlan 3, switch port tagged with vlan 3, transparent proxy running.

 

Ben

Posted
I

BYOD - Staff/Student owned devices, Smoothwall SSL login page to get customised filtering level, possible access to school resources file servers etc...

Guest - Unknown "dirty" guest devices, Internet access only, draconian web filtering

 

Or do I run the school one and the guest one to make it simpler?

 

Yep we've gone down the route of only offering 1 guest network that anyone can access. My problem is how do I manage it?

 

As soon as I give out the user and password for the web guest page, it will spread like wildfire around the school.

Posted

As plexer says best way is probably something like Smoothwall SWG-1200 with transparent proxy for the guest Vlan - you can have open access but force them to login with active directory username and password via smoothwall settings.

Will be setting it up here soon.

Posted

Am I to take it from the responses that no one here is doing BYOD in their school yet?

 

I've noticed in Australia and New Zealand this is quite common, any ideas what it hasn't become popular over here?

Posted
Yeah we wanted to do the same, we don't have any access for students to their files on the network at the moment, virtual desktop was our stab at it but MS and their licencing soon stopped that one!!
Posted
We're kinda sorta looking at it, but only in the context of allowing 6th Form students to use their laptops in the Common Room.

 

This is exactly our plan as well.

 

Problem is stopping all the other students connecting their mobile devices!!

Posted
This is exactly our plan as well.

 

Problem is stopping all the other students connecting their mobile devices!!

 

Yeah our IAS server was getting loads of weird requests from peoples mobile phones! We stopped using PEAP-MS-Chap a while back as we moved to certificate auth. Since then we now get loads of denied access requests which made me think that some policies had failed somewhere along the line! Turns out some crafty students had worked out you could connect with their username and passwords :D

Posted (edited)
We are also in the first steps of looking at this but are wondering were schools will stand with regards to PAT Testing. Edited by Kenny_G
Posted
Am I to take it from the responses that no one here is doing BYOD in their school yet?

 

We have a BYOD program. 500+ user owned devices. It is mandatory for 6th formers to bring in their own device.

Posted
We have a BYOD program. 500+ user owned devices. It is mandatory for 6th formers to bring in their own device.

 

Fantastic, finally found someone whos done it :) Tell me more please:

 

How well does it work?

How do you monitor the devices?

Does it cause any strain on your normal network

What do you do about legal requests, file sharing ect

How does the filter work?

Posted

Surely the licensing issue would depend entirely on how the user is connecting? If I were going to offer BYOD i think i would be tempted to actually really offer RDS Session based, which would make the licensing less complicated.

 

If the BYOD are connecting fully, they the CALs are different again. If the BYOD are using VDI pools then you need different licensing again, but this is a strangely grey area again and you will probably get different answers from different specialists.

Posted (edited)
Fantastic, finally found someone whos done it :) Tell me more please:

 

How well does it work?

 

Pretty good. We put in a lot of effort and had been directing things this way for the last 3-4 yrs.

It needs a lot of support from SLT and there (as always) are people against it. You really need to work on the infrastructure before contemplating BYOD,.

Biggest issue is out of date drivers on student machines

How do you monitor the devices?

They aren't our devices - so we are not entitled to monitor what people do on them. We do monitor authentication requests against the proxy of course, and with WiFi system (Meru) has a very good diagnostic capability.

 

Does it cause any strain on your normal network

Inevitably there is some additional network usage - we planned for this and upgraded our broadband, internal servers, wireless and network to cope with additional demand.

 

What do you do about legal requests, file sharing ect

Don't really understand the question. The whole network is blocked from bittorrent and the like. Kids can exchange files between their laptops if they want.

 

How does the filter work?

THey authenticate to it using username and password - its specified wpad.dat

Edited by CyberNerd
Posted
We're about to launch it in our 6 Form - but in a restricted form at the moment. No access to network, so Internet only. I suspect they'll bounce between ours and their own 3G or whatever simply because through ours they are filtered, so no Facebook, etc. However, it's currently seen as an addition to our facilities rather than the baseline, which is ideal. We were initially asked to provide a cluster of i-Pads, so once the infrastructure went in there was no good reason not to also try BYOD. My only concern at the moment is the impact on our broadband bandwidth, as we're already hitting our existing cap several times a day, but with us moving from 60mbps to 100 in December, we see BYOD as a bit of an experiment.
Posted
They aren't our devices - so we are not entitled to monitor what people do on them. We do monitor authentication requests against the proxy of course, and with WiFi system (Meru) has a very good diagnostic capability.

 

How do you complete your statutory Duty of Care to ensure that devices are not used, whilst in school, for bullying, sharing illegal materials, sexting, or other activities which may cause harm to children?

Posted
How do you complete your statutory Duty of Care to ensure that devices are not used, whilst in school, for bullying, sharing illegal materials, sexting, or other activities which may cause harm to children?

 

They only connect to the internet, Through a filtered proxy. We advise students about using a firewall, AV and password security. Everything else is done by the teachers following non-ict policies.

Posted
They only connect to the internet, Through a filtered proxy. We advise students about using a firewall, AV and password security. Everything else is done by the teachers following non-ict policies.

 

You mentioned that they can share files directly with one another though (but not via bittorrent, etc) ... how are the students protected from malicious or offensive actions of others?

Posted
You mentioned that they can share files directly with one another though (but not via bittorrent, etc) ... how are the students protected from malicious or offensive actions of others?

 

education.

  • Thanks 1
Posted
Surely the licensing issue would depend entirely on how the user is connecting? If I were going to offer BYOD i think i would be tempted to actually really offer RDS Session based, which would make the licensing less complicated.

 

If the BYOD are connecting fully, they the CALs are different again. If the BYOD are using VDI pools then you need different licensing again, but this is a strangely grey area again and you will probably get different answers from different specialists.

 

What do yuo mean RDS session based?

 

Microsofts licencing when it comes to terminal clients is strange. For instance VDi.

 

If you have 500 users in your 6th form, and you want them to be able to connect to VDi using your school owned laptops. Its legal to use your Software Assurance to 'upgrade' to VDA licences for your physical laptops so that they can connect to the virtual clients.

 

If your users are using their OWN laptops to connect to your VDi, it is no longer legal. As the OS on thelaptops is not owned by the school, our software assurance no longer covers the 'upgrade' to VDA licencing which means that you have to individually purchase VDA licences per DEVICE for each 6th former. As usual licences cannot be transferred between devices for 3 months (standard MS stuff)

Posted

We are on the verge of launching a second attempt at BYOD. Our first attempt with our sixth form failed mainly because many users found the LEA proxy server a struggle to deal with. Entering details, constantly authenticating, blocked services slowing down devices etc.

 

Our second (yet to be launched) system will utilise a non-authenticating transparent proxy. Users connect to a SSID for their year group, which is in it's own VLAN. Our captive portal authenticates them onto the network and logs the device MAC and user details. Each device is given it's own unique pre-shared key. These subnets are filtered at the standard LEA filtering level for their age. Devices are isolated using access lists, and can only communicate with our DHCP, DNS and Moodle servers, and of cause the gateway.

 

I will be happy for users to use phones, tablets, laptops or anything else. If it's got a browser in it, it's all right with me. If they are using devices in the wrong place or time; It is a behaviour issue, rather than a technology issue. If the technology is causing an otherwise compliant student to become disruptive, we could obviously revoke keys and disable further access.

 

@GrumbleDook Students are already bringing these devices into schools. Banning them, just puts them under the desk rather than on top of it. Devices still in use but the educational potential lost. Bullying, sexting and all the other online activities which do harm children could already be happening within the school fence. Education is key to stopping these activities, however monitoring internet use will also identify when students go off the rails. Schools can not monitor 3G connections. So to my mind, allowing BYOD should help reduce these risks rather than increase them.

 

Before launch I hope to get various members of the school community together to write a suitable user policy. It is my belief that if we involve students in the decision making, they will more likely stick to its outcomes.

  • Thanks 2
Posted
We are on the verge of launching a second attempt at BYOD. Our first attempt with our sixth form failed mainly because many users found the LEA proxy server a struggle to deal with. Entering details, constantly authenticating, blocked services slowing down devices etc.

 

Our second (yet to be launched) system will utilise a non-authenticating transparent proxy. Users connect to a SSID for their year group, which is in it's own VLAN. Our captive portal authenticates them onto the network and logs the device MAC and user details. Each device is given it's own unique pre-shared key. These subnets are filtered at the standard LEA filtering level for their age. Devices are isolated using access lists, and can only communicate with our DHCP, DNS and Moodle servers, and of cause the gateway.

 

I will be happy for users to use phones, tablets, laptops or anything else. If it's got a browser in it, it's all right with me. If they are using devices in the wrong place or time; It is a behaviour issue, rather than a technology issue. If the technology is causing an otherwise compliant student to become disruptive, we could obviously revoke keys and disable further access.

 

@GrumbleDook Students are already bringing these devices into schools. Banning them, just puts them under the desk rather than on top of it. Devices still in use but the educational potential lost. Bullying, sexting and all the other online activities which do harm children could already be happening within the school fence. Education is key to stopping these activities, however monitoring internet use will also identify when students go off the rails. Schools can not monitor 3G connections. So to my mind, allowing BYOD should help reduce these risks rather than increase them.

 

Before launch I hope to get various members of the school community together to write a suitable user policy. It is my belief that if we involve students in the decision making, they will more likely stick to its outcomes.

 

We have a similar setup, with transparent proxy, so once the user connects to the signal they enter their usual username and password to then gain access to the wireless network itself.

 

Regards the Duty of Care issue, we took the view that, whilst we acknowledge they will use their own devices on their own connections, if we provide the facility we are obliged to provide the care.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...