> Roles should be more generic like: general user (students, faculty,
> staff), visitors (perhaps rate limit, perhaps no access to mail server,
> etc.), users who are required to encrypt (people accessing student
> records and such), devices authenticated based on MAC only (we have some
> robots on campus), etc. You can put bandwidth abusers in a group and rate
> limit them, nachi infected users cannot ping, etc. One should not get too
> excited about this functionality though! It is a management nightmare!
> Keeping things relatively simple made our wireless network very
> successfull.

Hear, hear! We have been blocking & cleaning infected and unpatched (!) machines here on both wired and wireless over the past few weeks and let me tell you, it's a major time sink. And that's just something that really *has* to be done, I cannot imagine micro-managing user behavior for 15,000 people. Not with current staffing levels anyway, even if they dropped StimPacks in here like Skittles.

Speaking of simplicity, is anyone else going to the WNCG Symposium in Austin? I'm presenting a paper there on the a/b rollout we did for our MBA school and it is all about trimming away the B.S. If any of you are going to be attending maybe we can do a flash mob & warchalk the state capitol building or something.

John

John J. Brassil | Network Engineer, Vanderbilt Data/Video Engineering
voice 615.322.2496 | ICQ 9660375

Reply via email to