ITB0SS
Members-
Posts
18 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ITB0SS
-
All is well in the world ChatGPT advised me
-
Ok thank you so I guess my question is how do I do that on NPS? I'm guessing I'd need to setup security groups whereby only certain computer names can access on prem managed infrastructure, and then if it does not match then just goes to Smoothwall.
-
Ok so how can I go about isolating my network? They need initial access to authorise there AD creds, but then yes after that all they need is access out through Smoothwall to internet.
-
Ok, so yes I think I'm getting a bit confused with BYOD. All I'm trying to accomplish is Staff users bringing in a device mainly a phone and then authenticating them the easiest way without using a PSK or temporary guest passes. Which is why I've started playing around with the Smoothwall for accounting and then AD for radius Authentication
-
No, no device is just allowed to join the network, this is just so that Staff can access the WiFi using there AD credentials
-
Yes exactly that, I know it works as I've tested with my test account, but no one else is in the security group, is this even a good way? How's everyone else doing NYPD, Radius makes sense but ofc they need to access the DC so that they can authorise there AD creds
-
But they need to be so that they can authorise against NPS and AD, it's a flat network at the moment aside from Guest VLAN on Smoothwall and PSK from Unifi
-
I want them to be able to connect any device with there AD username & password, but as that's an unmanaged device it could have a virus on or anything dodgy and then it's on the schools main network.
-
Yes this is my goal and currently works "For Wifi you will be hard to beat 802.1x with a self-signed cert for domain/managed devices" Just my concern is that if I enable this currently any unmanaged device would be on the main schools network authenticated with the Staff users AD credentials.
-
Hi I require Staff to be able to connect any device to the schools WiFi. The simplest way I can think to achieve this is where by Staff use there existing AD credentials to connect, rather than a pre shared key that ends up being obtained the Students all the time. We have a Guest VLAN setup on the Smoothwall and then Unifi acts as a Guest Hotspot with portal page and WiFi vouchers, just a bit to much over head for me having to manage Staff codes all the time. It's fine for the occasional guest, but then also it's fully transparent on the filtering too and unauthenticated. I have so far achieved this with Smoothwall and NPS using the Smoothwall for RADIUS accounting and the schools DC/NPS server for the RADIUS authorization server, I have a test security group with a test user in and can join the network with AD username and password, great. However this opens up our network for any member of Staff to bring in a laptop that's not managed onto the schools network, how have others got around this? I understand how VLANS work, however I find the Smoothwalls GUI interface confusing, the schools network is Unifi and I'm looking at getting a Unifi Gateway as currently we only have CloudKey that is limited and does not act as the gateway, the Smoothwall is the gateway, I'd look at setting the Unifi Gateway as they gateway and doing VLANS on that and then just using the Smoothie for filtering, unless any other simpler ideas? This is Smoothwalls response Hi James, Typically, BYO devices aren't mixed in with school managed devices - it's one of the basic principles for network security, really. How a given school goes about achieving this very much depends on their network design and what options they have. In many 'flat' networks the design may make use of an entirely separate interface on the Smoothwall, for example, to provide a dedicated Wi-Fi network with sane firewall rules permitting only the strictest required access across zones to allow for authentication or other critical services. In cases where VLANs are employed, it's normal t have the Wi-Fi system allocate the client device to a specific VLAN based on what SSID is joined or other factors. How you go about it really depends on what you have to accomplish the goal with.
-
Sorry did best practice get decided? in regards to primary and secondary DNS settings on domain controllers.
-
Hi did you ever get resolved? I have similar problems
-
student to teacher private folder within a MS Team
ITB0SS replied to chrisjako's topic in Office Software
Ok, I have tried this under Assignments created an assignment but still have no folders, nothing is being provisioned no Student work library? -
student to teacher private folder within a MS Team
ITB0SS replied to chrisjako's topic in Office Software
Hi sorry I cannot see where this is "student work" document library. Ours is setup with Class Teams they all have a class notebook which lists all children and only children have access to there part and the teacher can see all children in the class notebook, however we would like folders too. I cannot see where to set this, using the assignments app? -
Smoothwall Radius with unifi APs and Server 2016
ITB0SS replied to bodminman's topic in Wireless Networks
Hi could I get the guide too please? -
Hey my first post here How's everyone rolling with this? I had previously locked the laptops down and had been using WordPad but as a few have mentioned I'm also being forced to be using MS Office Word. Decided to download Word 2016.iso ONLY from VLSC (don't know if this is the best version to use, using this as most policies seem to refer back to Office 2016) I've just put everything above in place, testing now!
