Please note this service is only available to schools with an LGfL connection in place.
To administer the remote access configuration for your users click or hover over the Service Desk tab and select Freedom2Roam.
Enabling Remote Access
To enable the service, the Head Teacher or Head Teacher Proxy needs to log in to the support site and navigate to the Freedom2Roam page (Service Desk >> Freedom2Roam). They will then be able to tick the box to enable the service. Once this has been enabled, Nominated Contacts for the school will have access to all the configuration options. |
Configuration basics
If you are an existing user of RAv3, the configuration page of Freedom2Roam will be familiar to you as there are only a few differences between the two.
The interface can be used to determine what different users can access on your internal network. Users can be granted access to anything from a single location to an entire network.
To configure remote access options for other users, you must:
•Create different groups of users
•Define their authentication requirements (whether second-factor authentication is required)
•Specify what each group of users can access - this is done either by setting up bookmarked locations or making the VPN client available and configuring its settings
Best practices
File transfer
When connecting to Freedom2Roam via the website, by default, access to transfer files between the device in your school and the device you are using to connect from is disabled. Although features such as these can be helpful, they could also potentially lead to breaches of data, the spreading of malicious software (Malware) and local policy.
It is possible to enable file transfer, so that you can move files between devices. Guidance on doing this is available here. If enabled, this will mean that your establishment’s data will be able to be transferred directly from the computer within your establishment, which is managed by your local policies, to an unmanaged device, that is not, by both intentional (user copying the data) and unintentional means (user error). As a result, this could mean that your establishment’s data could reside on unmanaged devices that may or may not be encrypted and not owned by staff members at your establishment i.e. they have connected to Freedom2Roam using a shared computer, for example, a computer in an Internet Cafe. If the computer used to connect to Freedom2Roam has Malware, this could mean that the Malware could potentially spread across your network, infecting computers within your establishment.
We therefore recommend giving the above good consideration before enabling this feature.
Recommendations
Our recommendations for the configuration of Freedom2Roam are:
•Remote access is only provided to those users that require access and for as long as access is required for.
•Restricting remote access to only devices access is needed to.
•The remote access settings for your establishment should be reviewed regularly.
•The use of second factor authentication. Soft OTP tags are provided to school's free of charge and are supported by both the website and VPN.
•Consider not enabling file transfer functionality. Files can be stored securely in the cloud on a number of platforms including myDrive, Google Drive & OneDrive which all support collaboration and have online editors that do not require files to be downloaded.
•Limiting VPN access to those that require it and only installing the client on school managed devices.
•If VPN access is required, only provide access to the IP ranges that access is required for - rather than adding the whole range into the VPN configuration
We also recommend:
•Ensuring that up to date antivirus is installed on machines you are connecting from and to. Sophos is provided free of charge to LGfL schools.
•Operating system updates are regularly carried out.
•Access logs are reviewed regularly.
•Generic accounts are not used.
Using Remote Access after it has been configured
All users who have been set up to use this system should read the Freedom2Roam User Guide before they attempt to log in to the system for the first time. This guide contains essential configuration information for the end user. URLs for logging in are also contained in this section.
See next: