Jump to content

IrritableTech

Members
  • Posts

    1,738
  • Joined

Everything posted by IrritableTech

  1. If there is a route around your filter, you'll fall foul of the safeguarding section of an ofsted inspection - assuming an inspector finds out about it, and understands what that means. Under recent changes, HMI's must put eSafety based questions to the pupils. If you can't prevent BYOD users circumventing your filter, it's a serious safeguarding issue. You need to look at your current technology or if there is a better way to implement it - work with your provider, or get a new one!
  2. 1. The iPad doesn't belong to the child so we can't trace it on that. Staff could document which student is using which device today/this lesson? This might be a bit hit or miss, but you're putting a procedure in place and highlighting the safeguarding element to teaching staff. 2. No idea what the IP was nor time it was logged on. We archive our DHCP leases here. Active directory archives one weeks worth, we copy these off, and I now have over six months at any one time. 3. The SSID is open (but filtered) due to BYOD and class sets (WPA Enterprise causes issues) Where possible an SSID should have an encryption key, it will protect your users from outside MITM attacks. However better still is radius or individual WPA2 passphrases. This will help protect your users from each other, as well as outsiders. If this becomes a wider issue, your schools needs to identify the need for new systems. 4. No logs on the device. Bar a bit of browser history, the device is useless unfortunately. 5. The simple fact that another child can easily pick up another child's device and do what will (I would expect people at workstations to log out / lock them) Yes I'm aware of pin codes but again class sets / BYOD. For BYOD you should probably have a policy which explains the need for security, and unauthorised use of devices is a no-no. This helps cover the school, but let's be honest doesn't stop it happening. In a BYOD scheme, the onus is on the owner to ensure their devices is used responsibly. For school owned devices the best option is a filter which requires authentication for internet access - with a fairly short time out. 6. No Smoothwall logs as the WIFI is open and IP cannot be traced easily (I can use unifi to get the IP but this changes so is unreliable) Your DHCP logs will help here - each device will have a unique name (right?) and if you were able to cross reference this with the teacher list in point 1 you're quickly narrowing down your search. 7. Children bypassing filtering using apps, also filtering level is the same across the whole SSID I guess apps aren't using your proxy - or can be changed so they aren't? You've got a couple of options - find another filter which doesn't use a proxy to filter traffic, or create an access list, or firewall so the ipads can only talk to your proxy and can't use direct internet access. None of these are magic bullets, but each step helps reduce risk and increase your monitoring of individuals. With regards to Google Docs, I believe you can take ownership of the documents and see the full history of changes including time and dates things were changed by the 'user'. Obviously the user will be incorrect in this case, but teachers and senior leaders are used to picking these issues apart. It's very similar as a student drawing an offensive image or offensive language on a bit of paper and passing it across the classroom to their victim. I hope that helps @caffrey
  3. @Micron Hello Dan. You're very welcome. Have a good look around... and if you have any questions, just shout.
  4. Have you got an edge firewall? Create a rule that requests for port 80/443 etc. only come from your proxy server.
  5. It's worth checking with a higher authority - a quick email is best so you can keep a copy of the reply. Not only aren't they an employee yet, it's likely they aren't CRB cleared yet either.
  6. I largely agree, but found the average end user didn't follow our mind set. I do believe however that we need to put in place as many solutions as possible to make a project a success for the learners - whilst ensuring regulations, legislation and laws are still respected.
  7. Captive portals do cause issues on smartphones and tablets. Users hate having to open up their browser to authenticate before an app can be used. If you want to invite the devices onto the network, you have to make them usable - over complicating matters unfortunately puts barriers in the way of the original brief. Finding the happy medium is tough.
  8. A interesting product - I read the blog too. So devices don't see a man in the middle attack when loading https pages then?
  9. We've come up with a reasonably happy medium here using the ruckus Dynamic Pre Shared Key system. Each user has to authenticate every couple of weeks and they receive their own 64 character wifi password, after that it works like it does at home until it expires. From our point of view each device is authenticated to a user and we can filter appropriately, from their point of view, they don't have to authenticate every hour or day. If I didn't use Ruckus or have another solution with a similar feature, I'd have to insist on WPA2-Enterprise/Radius here. Otherwise all your users traffic encryption key is the same and therefore useless.
  10. Hi @kerryturner. You're asking all the right questions. Some can be answered using technology, other risks mitigated through policy. Some risks will remain but might be outweighed by advantages. If you are going to put BYOD devices on your network you are best off separating these devices from your normal network. Your smoothwall can definitely help here, but you'll need to consider the capabilities of your switches and your wireless network here too. Generally I'd advise putting these devices in another VLAN. Adding a suitable access list to the vlan will help keep these devices from accessing your server too. If you're worried about your server security though, this is something you need to look into anyway... If a teacher brought in their laptop now and unplugged their classroom PC, they'd potentially have the same network access and administrator rights on their machine. In places where this happens regularly, a well managed BYOD scheme can help improve security! Some schools have gone down the VDI route - I think it depends on what you want your users to access and where the curriculum is heading. Much of our curriculum is heading towards web technology. We're trying to be device agnostic in our BYOD scheme, so everything can be served through the browser. It's cheaper generally too! School email on phones/tablets should really be covered under policies. I think it would be obstructive to disallow it, but you should be putting safeguards in place - devices must be pin protected, loss must be reported etc. You could put a restriction on how much mail can be cached, to reduce the data loss risk. A further note I'd add is around your core infrastructure and your internet connection. Is it up to the job of another 30-50-100-1000 devices jumping on it? I've blogged a bit about BYOD on my site. Feel free to have a look.
  11. On my home setup I made the jump (and then last night I moved to 3.2.2b). No issues upgrading, but then my setup is of three APs with a basic config. Good Luck!
  12. Seventy students, or seven hundred? Two students to one staff sounds like bliss! Do you know what your FTTC sync's at? Or do SWGfL not let you see this?
  13. As suggested, take sims out of the equation first. Test wifi speed generally. Perhaps copy one single large file, then a directory of small files because they can act quite differently. How does this compare with your wired network? Then try again grabbing these files from your sims server. How does that compare? If the problem is only sims - then I'd be looking at your new setup. Is the laptop in another vlan, have you got an access list / firewall on it etc?
  14. @speckytecky - Tell us your numbers - it's pointless people suggesting a gigabit leased line if you've only 20 staff and 30 devices. Concurrent users, devices, current sync speed etc.
  15. What kind of information does the LEA/Head send and receive from these addresses? Have the LEA considered that emails sent between themselves and schools could be intercepted as they traverse the public internet if they continue along this line? Do they have other solutions in place?
  16. Welcome @raimon. Enjoy your stay.
  17. What does your FTTC sync at? How many users have you got, how many devices? Could it be a router issue, rather than a bandwidth one? It could be that your FTTC circuit isn't up to the job, or the SWGfL infrastructure isn't. The cost of full fibre from FTTC is quite a leap if you're looking down that route - but isn't to say another provider wouldn't be cheaper than your RBC.
  18. You can trunk more than one port together, either using J4858C modules or copper ports.
  19. I'd like to help if I can. You may have found an issue I'm not aware of - my users could be doing the same. I'll dm you my number. We might be able to help each other?
  20. This doesn't sound right. Lightspeed should look at the certificate for a HTTPS site and decide based on who it was issued for whether the site should be allowed or blocked. We have facebook blocked for some users, but they can still get to other https sites and I haven't seen any suggestion that they are circumventing the block - yet. Happy to help a fellow school if I can...
  21. Do these switches have the correct gateway info?
  22. I've searched around (perhaps badly) but I was wondering if there was going to be a copy of the conference stream put up for those who were unable to watch/attend on the day? Thanks in advance. cc. @Dos_Box ?
  23. That seems high - without doubt well above average. At my school, we average less than a terabyte a week I think. You're pushing a quarter of that over standard ADSL? Glad I'm not on your exchange! :-) At home we have quite a few more devices, but don't do as much streaming as you. I'm interested to more closely monitor my usage now.
  24. I've recently run through an exercise like this for three schools. One with 6 handsets, one with 12 and one with 65. In every case an on site solution was the most cost effective. There are some really good little VoIP & hybrid systems available and you can reduce your ongoing costs too. DM me if you want some more specific info, or if you want some general tips I've picked up recently.
  25. Indeed that would add an additional safeguard, however my worry was more with the way sims works, and how data can be easily extracted in one fell swoop once past the fortinet. Being able to run a report, from home (airport, starbucks...) which can extract all personal and sensitive data about students and staff past and present into a handy csv file worries me. The connection may be safe, but the device once that data has passed over the connection, may not be. A user training issue rather than a technical one generally.
×
×
  • Create New...