Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Primus

Members
  • Posts

    2,232
  • Joined

Everything posted by Primus

  1. So it spoofs a MAC address - the very thing you said couldn't be done? MAC address spoofing is trivially easy, do not rely on it as it's not secure at all.
  2. That would be for the MITM SSL interception certificate and at that point they're on the network so if they can't join the network they cannot get to that page. You could host the RADIUS certificate on your website and then people could download it over their 4G, trust it and then Android devices would allow connection as far as I'm aware.
  3. It is trivially easy for an iPad to spoof a MAC address - that's literally what private WiFi addresses does. Advising people to move from RADIUS authentication to MAC authentication is an interesting one.
  4. But MAC addresses are trivially easy to spoof?
  5. I'm assuming you have Plus licences? I'm testing this at present and had to use the button the Classroom page to generate the link - then everything worked for my test parent account
  6. It depends - with resilient networks and dynamic routing it's not always possible. I can predict where traffic from a given vLAN will emerge 99% of the time but if we have a failover of the node that traffic flows to then it will route to another node which is up - at which point it'll be knocking on the wrong Smoothwall. I find it strange that IDex replicates information within the nodes but the secret knocks don't.
  7. Having a Mac Mini act as a caching server for OS updates, Apps etc can still be beneficial if you have large numbers of iPads.
  8. So the secret knock tells the Smoothwall to ignore the requests coming from the device for the defined period so that it's not dual filtered (by the appliance and the extension) and it prevents double notifications from the on prem and the cloud safeguarding notifications. All Smoothwall would need to do is store the secret knock IPs in a database that could replicate - they already do this with IDex.
  9. @tom_newton - I've flagged this to support before and it could easily be fixed by synchronising secret knocks in the same was IDex synchronises.
  10. So because they don't share the secret knock they're not knocking on the correct Smoothwall to be able to have their temporary filtering exeption because they've got the cloud filter client/extension working is what I mean.
  11. Is this because they don't share secret knocks like they do with IDex etc?
  12. I mean you can listen or you can end up back in the same position again at some future, random and unpredictable point.
  13. I'd urge you not to start using them - if this wasn't a lesson in what happens when you use EoL kit that relies on the cloud I don't know what is.
  14. Yes I think you could help everyone by explicitly prompting them to involve their IT team!
  15. We've ended up giving them access to settings - we restrict virtually everything anyways. Obviously test this before you do - but ours can't change much other than add and remove bluetooth devices. Our 1:1s can obviously add and remove personal WiFi SSIDs but they can't remove the pushed ones.
  16. There are various ways of getting the certificate to people but you cannot push it out to a unmanaged device. What we do is we host an internal webpage with the certificate on it and as part of the instructions for using the WiFi it tells you to visit the page - the page then has instructions on how to download and install the certifcate on a range of different devices.
  17. Fingers crossed - let me know how you get on.
  18. Did this help at all?
  19. Sorry I'm not sure what you mean about the first bit but if they've not got email turned on I think Classroom will show them invited classes on the Classroom homepage and they can click accept that way. Last one - that's up to your teachers/you. We archive all classes at the end of an academic year, our sync then runs against our timetables and creates new classes. If it were me I'd want a new class at the start of each year.
  20. Either they join themselves using a teacher supplied code, the teacher manually invites them and they accept the invitation or you have some kind of sync software do it such as Salamander.
  21. Have you tried backing the power off? We run: 2.4Ghz 20Mhz channels Low transmit power Minimum RSSI -75 5Ghz 40Mhz channels Medium transmit power Minimum RSSI -75 We've left all ours on auto channels - we're using hundreds of Unifi APs across 5 sites with no issues.
  22. The OUs in Google Workspace have nothing to do with Classroom whatsoever.
  23. Yup! We had one of our schools on hosted SIMS and did exactly this about 3 years ago!
  24. RIP removal wasn’t ever documented and is vital for our WAN configuration. They got rid of the client as it’s meant to be a more compliant OpenVPN file Maiden produces/uses. You can turn the VPN service back on in the web GUI.
  25. Yes I had two issues - one the service had been disabled (easy fix) and the second was routing issues due to RIP being removed from Maiden but not being documented - I had to rollback to Leeds.
×
×
  • Create New...