Answer the question
In order to leave comments, you need to log in
Tricky question?
Hello!
The school began to collect phones, so to make it more convenient for everyone, we decided to use the possibilities of the latest innovations of it. But there are a few nuances that need to be addressed.
1. Access levels - when connected via Ethernet or WiFi, require authorization (as in public hot spots):
1. Student - has access to the Internet on a schedule and with 18+ ads and unwanted content blocking, access (on the local network) to devices level Apprentice.
2. Parent - has access (on the local network) to devices of the Student and Parent level and full
access to the Internet according to the schedule.
3. Teacher - has access (on the local network) to devices of the Student and Teacher level and constant access to the Internet with the above restrictions.
4. Administration and technical staff - has access to the local network, school servers and permanent full access to the Internet.
At the same time, everyone has an em marin 125 kHz card and registration in the hot spot should be on them, and the data should be taken from the SKDP database (external access control system).
2. Queue, priorities and traffic capacity - 1 Administration and technical staff, 2 Teacher, 3 Parent, 4 Student.
3. Telephony and intercom - you need to compare the phone numbers of parents and the schedule of lessons of children-students in the database, so that when there is a lesson, the call from the parent goes to the right office, if there is a change or there are no lessons, then the call is forwarded to the shift, if computer science, then redirect call to the student's phone (internal). When dialing the office number on the intercom, the call goes to the phone in the office and using the key in the tone mode, open the turnstile in the right direction.
4. Integration of Active Directory and phones - when a Computer Science student logs into the computer using AD data, the nearby phone receives the student's internal number.
5. Access to the school servers from computers of computer science students only through services and protocols: AD, FTP, FTPs, HTTPs.
6. Offline e-journal - when there is no Internet connection, save all data on the school's servers, and when the Internet appears - send all data to the e-journal server.
What hardware, software, OS is needed to implement everything, where to dig, what protocols to watch.
Help me please!!!
Thanks in advance for your replies!!!!!!!!!!!
Answer the question
In order to leave comments, you need to log in
I think you want what you don't need.
1. There is no point in the role of the Apprentice. If you want to restrict access - raise wifi without a password, with access only to wikipedia and the school website.
2. There is no point in the role of Parent. The child's parent already has access to the child's devices, physically, with his hands.
3. There is no point in the role of Teacher. If you need unlimited access to the Internet - hang the password on a separate "teacher's network" and change it once a month, the password will still leak to the students.
4. In order to fully restrict the student from these Internets of yours - you will need at least a Faraday cage for the entire building in order to block all cellular operators. Well, you will block everything via wifi, which prevents you from surfing through EDGE / 3G / 4G .. or whatever you have.
5.
Telephony and intercom
Active Directory and phone integration
Access to the school servers from computers of computer science students
Offline e-zine - when there is no internet...
I support, reduce your Wishlist. There is no ready-made solution for your problem. I have experience in setting up infrastructure in American schools, and God forbid they have equipment (poppies, chromebooks, ipad), they allocate 11k greens per student per year, and even they do not put forward such strict requirements. Much of what you describe is more like a custom solution. Custom = expensive to buy, expensive to maintain.
As for authorization on ethernet and WiFI, nothing is impossible here. Radius server, enterprice level wifi (aruba or ruckus), switches supporting 802.1x. It is better to do authorization using a login password from AD, a certificate, or enter machines into a domain. Chromebooks have their own stripped-down analog of a domain for centralized management.
With telephony - I have not seen such solutions.
As my experience shows - it is not necessary to invent a bicycle. Think over the concept, see how similar tasks are implemented in other schools, and start small.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question