Educause Security Discussion mailing list archives

Re: Wireless Guest Access


From: Geoff Nathan <geoffnathan () WAYNE EDU>
Date: Fri, 29 Sep 2006 06:27:05 -0400

Matt Arthur wrote:
Thanks for the good discussion.  To answer Joe's particular comment
below, we would set up this ESSID to ONLY have access to http, port 80
traffic so their access to our university would be the same as if they
were coming in from off-campus.

It sounds like most of you are doing some kind of 'sponsored' guest
access (which is what we do for our current system), but how do parents
and prospective students find someone to 'sponsor' them?

And, do you think (assuming the technical security problems are taken
care of) there is large political (or legal) risk in simply allowing
folks to come in and use a non-login guest account?

Thanks,
Matt


We restrict traffic in the same way as Matt describes--our guests can
only get to places they could get from elsewhere in the
world--everything else requires an additional log-in (our e-mail,
Pipeline--our Portal, etc.).
While it is probably totally unenforceable, we ask sponsors (who are any
Wayne State employee) to ask their guests to read and agree to our AUP,
(you must click to request the guest ID's) and the sponsors are also
asked to keep a log (just paper) of those to whom they distribute the
ID's.  Again, probably worth the paper it's printed on, but given the
limited access we're not too worried about it.  Since the service is
also about a month old, we're also watching how it goes.
Since we purchase our internet access from Merit we're also assuming we
don't have to worry about CALEA, for now, but, of course, we're watching
those events closely.

Geoff

--
Geoffrey S. Nathan
Department of English/Computing and Information Technology
Wayne State University
Detroit, MI, 48202
<geoffnathan () wayne edu>
Phones:  C&IT (313) 577-1259/English (313) 577-8621

Current thread: