The most difficult thing to make a manager when the campus network certification system is online is visitors and material networking. To be easy for visitors, the access to the network is stable, but they cannot follow the same strict route as their students and teachers. These two types of access are processed, and the system can function on one step; it is poorly handled, either the visitor's voice channel or smart equipment is turned around for three days.
Visitors' accreditation."Time-limited speed limit range"
The biggest difference between visitors and students is that"Temporary"and"Low Trust"So the core of the visitors' portal is designed to be three limits: time-bound, speed-limited, restricted areas. Time-bound is a period of maturity such as one day or week, which automatically expires without manual recovery; speed is a limit on allowing visitors to eat their bandwidth and affect normal teaching; only public area networks are limited to accommodations and office interiors. These three doves are easy for visitors and they are comfortable with schools. We see that visitors are given long-term unlimited speed accounts, and they are exported as usual and then back to tight borders, so we have to set boundaries from the outset.
Visitors' documents are given in a light manner.
The most important is the number of paper copies registered at front desk, and the least lightly the clearance self-service application. The compromise option is to give reception services a retransmitable temporary voucher that allows guests to fill in a cell number. The key is not to allow visitors to run three trips to the administration building for the last network. When actually deployed, it is recommended that the visitor's application be cleared up to the point where backstage screening is possible and credible visits are made directly.
Don't log in manually on the device.
The object network terminal and the visitors are the opposite."I'm gonna have to get out of here once, year after year."The facility is not supported by web login, monitoring, a cartoon, and environmental sensors. If you have to send them through the teacher-student authentication channel, the device will be out of contact once the password strategy has been updated or the session has expired. The right approach is to create a fixed access policy for the network based on equipment marking: the equipment is connected, distributed over the network and permissions according to the type of equipment, without being involved in recertification it."Things"Not."People"The system is stable.
The network has to be isolated.
Material networking equipment is often less secure, and well-known people like cameras, printers, etc. are vulnerable to attack. If they are in the same network as teachers and students, there is a high risk of lateral movement once an item is charged. So it's not just access to the Internet."Let it be connected."More."Disconnect it."The authentication system, in conjunction with the switchboard, is segmented to allow the item to be connected to a separate address section, which can only access the back end of the visit and cannot easily search the network. This isolation is planned at the structural stage and will be much more costly to unbundling after being online. Safety and convenience are given priority for such equipment because they cannot hold it.
Leave management view for each of the two types of equipment
There's a common demand for visitors and things networking: the manager has to see it. Visitors now have how many online, when they expire, what devices are offline, how long they're offline, all of which require a dedicated management view instead of being mixed up in the students-to-teacher account. We suggest that we put them on the certification system."Visitors""Material networking"As a separate management category, each has a list, a status and an alert. For example, the physical network is offline to remind visitors that they will mark when they reach the threshold."All equipment is a single account."Started.
Don't let the private router be a gray channel.
Finally, a realistic question is that if the formal visitor and object access is not working, teachers and students will buy their own routers to get the whole floor turned around for certification. Once this gray access has winded, all security designs are zero. So, you should have visitors and things connected."A good formal access."And then we're gonna have to get rid of the private connection. It's going well. We don't need to take risks. The private connection is just needed."Experience is safe."The example is worth a little more thought in schools.
The object network is best identified with device features.
The size of the devices is such that it is unrealistic to use manual registration numbers and addresses. It is more stable to identify them with their own features, such as card tags and fingerprints from the factory, automatic system categorisation, automatic set-up strategies, and managers review anomalies only. This will allow a new batch of cameras or sensors to be added without using manual registration.
We need to get a quick white list on the emergency.
The formal access is smooth, and there are always special circumstances: temporary meetings have to put a collection of guest equipment in place and emergency guarantees are to be made directly accessible to a given region. So the system has to keep an opening mouth that allows quick white lists to be opened, which are set up on a regional basis and released on time, and then automatically recovers them. Don't let the process get stuck or people turn back to private routers.