Jump to content

ITB0SS

Members
  • Posts

    18
  • Joined

  • Last visited

Reputation

0 Neutral

About ITB0SS

Personal Information

  • Occupation
    Network Manager

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. All is well in the world ChatGPT advised me
  2. Ok thank you so I guess my question is how do I do that on NPS? I'm guessing I'd need to setup security groups whereby only certain computer names can access on prem managed infrastructure, and then if it does not match then just goes to Smoothwall.
  3. Ok so how can I go about isolating my network? They need initial access to authorise there AD creds, but then yes after that all they need is access out through Smoothwall to internet.
  4. Ok, so yes I think I'm getting a bit confused with BYOD. All I'm trying to accomplish is Staff users bringing in a device mainly a phone and then authenticating them the easiest way without using a PSK or temporary guest passes. Which is why I've started playing around with the Smoothwall for accounting and then AD for radius Authentication
  5. No, no device is just allowed to join the network, this is just so that Staff can access the WiFi using there AD credentials
  6. Yes exactly that, I know it works as I've tested with my test account, but no one else is in the security group, is this even a good way? How's everyone else doing NYPD, Radius makes sense but ofc they need to access the DC so that they can authorise there AD creds
  7. But they need to be so that they can authorise against NPS and AD, it's a flat network at the moment aside from Guest VLAN on Smoothwall and PSK from Unifi
  8. I want them to be able to connect any device with there AD username & password, but as that's an unmanaged device it could have a virus on or anything dodgy and then it's on the schools main network.
  9. Yes this is my goal and currently works "For Wifi you will be hard to beat 802.1x with a self-signed cert for domain/managed devices" Just my concern is that if I enable this currently any unmanaged device would be on the main schools network authenticated with the Staff users AD credentials.
  10. Hi I require Staff to be able to connect any device to the schools WiFi. The simplest way I can think to achieve this is where by Staff use there existing AD credentials to connect, rather than a pre shared key that ends up being obtained the Students all the time. We have a Guest VLAN setup on the Smoothwall and then Unifi acts as a Guest Hotspot with portal page and WiFi vouchers, just a bit to much over head for me having to manage Staff codes all the time. It's fine for the occasional guest, but then also it's fully transparent on the filtering too and unauthenticated. I have so far achieved this with Smoothwall and NPS using the Smoothwall for RADIUS accounting and the schools DC/NPS server for the RADIUS authorization server, I have a test security group with a test user in and can join the network with AD username and password, great. However this opens up our network for any member of Staff to bring in a laptop that's not managed onto the schools network, how have others got around this? I understand how VLANS work, however I find the Smoothwalls GUI interface confusing, the schools network is Unifi and I'm looking at getting a Unifi Gateway as currently we only have CloudKey that is limited and does not act as the gateway, the Smoothwall is the gateway, I'd look at setting the Unifi Gateway as they gateway and doing VLANS on that and then just using the Smoothie for filtering, unless any other simpler ideas? This is Smoothwalls response Hi James, Typically, BYO devices aren't mixed in with school managed devices - it's one of the basic principles for network security, really. How a given school goes about achieving this very much depends on their network design and what options they have. In many 'flat' networks the design may make use of an entirely separate interface on the Smoothwall, for example, to provide a dedicated Wi-Fi network with sane firewall rules permitting only the strictest required access across zones to allow for authentication or other critical services. In cases where VLANs are employed, it's normal t have the Wi-Fi system allocate the client device to a specific VLAN based on what SSID is joined or other factors. How you go about it really depends on what you have to accomplish the goal with.
  11. Sorry did best practice get decided? in regards to primary and secondary DNS settings on domain controllers.
  12. Ok thanks Tom, for now I have deployed Ublock origin.
  13. Hi, is this broken again, ads in our school are no longer being blocked, I believe was all working fine before Egde had an update, anyone else got YouTube ads appearing? I've triple checked all the content modification stuff.
  14. Hi did you ever get resolved? I have similar problems
  15. Ok, I have tried this under Assignments created an assignment but still have no folders, nothing is being provisioned no Student work library?
×
×
  • Create New...