Security issues with Students iOS devices

gramsm
New Contributor

I am having security issues with students. We had a student scan our network with an android device and basically hacked the password for our Staff network it only took three days using this program. We currently have a hundred students on our staff network in the matter of days. I am inquiring if there is a way to make it so our student iPads cannot connect to our staff network. Are there some sort of certificates I can send out? Any ideas greatly appreciated!

4 REPLIES 4

ultimatesetup
New Contributor

Your should have completely separate networks for public versus internal. This will shield you from attempts such as this. Higher end routers and access points can allow access to separate networks at the same time and for additional security you can add certificate based authentication for internal networks. If you want to be completely protected, don't allow any wifi for internal networks and have MAC address filtering for all ethernet ports. Hope this helps!

davidacland
Honored Contributor II
Honored Contributor II

A quick solution will be MAC address filtering. Assuming you have all the staff iPads in the JSS it will be easy to export a list.

The longer term solution may be WPA2 enterprise authentication which can use certificate based authentication.

adamcodega
Valued Contributor

You need to find out why they were able to get the staff network password. Are you using WEP, which is easy to crack?

I don't believe there's a way to stop an iPad from trying to connect to a particular network if the user wants to.

MAC address filtering won't protect you. You can't change an iPad's MAC address but if they are bringing in outside devices then they could change it on that device, a laptop or Android device.

Unless you find out how they got your password, or an educated guess to how, you're not going to protect yourself.

jarednichols
Honored Contributor

Use a different authentication scheme for the staff network than the student/public network. e.g. 802.1x for Staff, WPA2-PSK for students/public.