Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Primus

Members
  • Posts

    2,232
  • Joined

Everything posted by Primus

  1. The legislation is Keeping children safe in education. It references the UK Safer Internet Centre's guidance. It also references the "Prevent Duty" - aka Protecting children from radicalisation: the prevent duty. It does leave some questions down to individual schools and their risk assessments and it does discuss "over blocking". But the requirement is clear, you are expected to filter and monitor your school Internet connection.
  2. Filtering and monitoring go hand in hand, you have to do both for any adult on site.
  3. Any adult on the premises is requires filtering, you cannot provide a school Internet connection to a guest and not filter it appropriately.
  4. I’m glad we claimed all of ours as soon as we could!
  5. To effectively filter and report in 2020 you need to both filter and SSL intercept, the majority of the web is now HTTPS. Not following best practice because it's a "hassle" is why IT gets such a bad reputation.
  6. From Securly's own website: "On-Site and Off-Site Solution: A PAC file that is created by your Sales Engineer is a hard requirement for any off-site iPads. Please reach out to your Sales Engineer by submitting an email to [email protected] to have this created for you."
  7. Yes it needs to be on a separate vLAN so that you can keep your trusted network safe and secure. Best practice is to filter and SSL decrypt all guest traffic and log it against particular users in case of any issues.
  8. You're getting into very detailed discussions here. What do you mean log in to use the network? They use their AD creds to join the network. You can use RADIUS on a user or computer basis. For a guest network it'll be using user creds.
  9. We have AD accounts for guests, when they've been used we record who used them.
  10. Our RADIUS uses AD accounts.
  11. No because access is granted using RADIUS so the correct user gets the correct filtering.
  12. I wouldn't give guests greater access than staff - staff access is the least restrictive I would grant anyone. That said I wouldn't block webmail etc for staff - a degree of personal use is permitted. You're providing a service, this service has a clear benefit, why make it harder than it needs to be? Governors are volunteers, expecting them to use their own data in a meeting etc would be wrong IMO. Security by obscurity is no security at all. Do not use a preshared key, setup RADIUS! Why would you want to stop people using your guest network?
  13. Broadcast the SSID - don't make it harder than it has to be. Assume all network users are capable of doing something suspicious.
  14. To effectively filter to the degree necessary in a school you need to do more than that. There is plenty of content out there that won't be filtered by just the FQDN. Are you suggesting your guests are less filtered than your staff?
  15. Filtering should be applied with SSL interception as without it's pointless.
  16. Not everywhere has good 4G - we have a school slap bang in the city centre where coverage is spotty. Providing guest WiFi is something I'd expect a school to do, but I would expect them to filter it and keep track of who is using each account. That means a little bit of work creating a guide etc so that people can onboard themselves by joining using RADIUS creds and then trust the MITM cert.
  17. You can prevent this happening by correctly configuring your switches. Suggesting that vLANs are as insecure as MAC Address filtering for access control of WiFi isn't true. To suggest it is well known that vLANs shouldn't be used for security is also not true.
  18. Whilst I broadly agree with your points, can you identify the legislation that requires this please as this is contrary to our MAT financial compliance?
  19. My most recent purchase of Adobe licences was from Insight for £20.10 per licence per device per year - it's the standard Adobe Edu plan with a minimum purchase of 25 I think.
  20. True instant alerts are missing right now. I'm also a little suspicious about how well behaved the kids are being haha
  21. Our Chrome solution involves the reporting being done on prem - the data is pushed back to our S14 once per hour - is this different to what you have?
  22. I know what you're saying and how it probably wasn't your decision to do it this way but you might want to flag to the powers that be that fully scoping out a project before commiting to such a huge spend would be better - you'd also know exactly how much you're spending rather than potentially now having to spend more than intended adding additional products etc.
  23. I've never used Intune but you can set a global proxy using MDM on iPads. Not to be awkward but before the decision was made to purchase a particular device surely this was all investigated - 500 devices incoming?
  24. If you are tendering again it is because circumstances have changed, what was right before may not be right now with the new circumstances.
  25. The tender is part of the process of that though, for you to select the best product you have to use a methodology and the tender is part of that.
×
×
  • Create New...