AnthonyBowers wrote:Right now the Meraki Router/Firewall and Access Points are all controlled by church headquarters. However there is no documentation or instruction about configuring the devices for security purposes such as adding separate VLANs, DHCP guard, layer 2 filtering, etc.
I'm sure there's documentation, they just don't share it with the STS.
AnthonyBowers wrote:Right now I have big security concerns with all of my buildings simply due to lack of documentation and all of the computers and wireless access points on the same broadcast domain using dumb (non-managed) layer 2 switches to network everything together.
I share the concern - especially if for some reason the administrative share on the computer gets turned on. That's easy to do unintentionally trying to make some feature work. I have all mine disabled off.
AnthonyBowers wrote:With the new program replacing MLS and ward leaders wishing to print from their office (ex: temporary recommends), wireless printers are being requested and approved for purchase.
I'll refer you to the
Meetinghouse Technology Policy
5.1.3 Local Unit Provided Equipment: Local unit budgets should not be used to purchase any printers, copiers, and multifunction devices. The costs for repairing, upgrading, and replacing any equipment not provided as part of new building construction or by the FM group are the responsibility of the local unit.
I'd also reference Handbook 1: 14.7.2.2 which prohibits units from using funds to buy computers. (In the context, it raises question of it includes pritners as well)
AnthonyBowers wrote:scanning will be a thing that all ward and stake clerk's will need access. Since the church will not be purchasing scanners for wards that will need them for the new program, wards are going to be purchasing their own multifunction printers.
No doubt, some people are going to go "whole hog" on the electronic thing, but as someone who's day job is building document scanning systems, scanning is more work than filing. Given the points above, it might be best to wait and see what the church comes up with.
AnthonyBowers wrote:1) Is there ready documentation explaining all the rules in place on the firewall/routers? (Yes I know about the dumbed down version)
None that I've ever seen - at least made available to an STS.
AnthonyBowers wrote:2) Is there ready documentation explaining all the rules in place on the access points?
Sames as #1.
AnthonyBowers wrote:3) Is there a way to put individual LANs/broadcast domains on each router port (get the church to configure it)? That way I could put one broadcast domain on one port and another broadcast domain on another port and have everything run through the firewall, separating wireless and wired devices.
You might call support and ask if they can enable the Special Purpose (SP) zone for your buildings. Typically it's used for a FHC, but that's probably about as close as you're going to get for what you want. Everyone in the SP zone is assigned a unique church-wide 10.x.x.x IP separate from the 192.168.x.x of the "unwashed masses" (User zone). Port 2 will become the SP port. However, I don't think it's a good idea to put any APs on this zone.
AnthonyBowers wrote:4) Would it be possible to put all ward offices on their own VLAN?
See #3
AnthonyBowers wrote:5) Is there a reason why the church purchases routers and access points for each building but not managed switches?
Probably cost. I notice that TM seems to support "switches", so I assume managed switches are supplied for some situations. I'd guess it's to get multiple zones at a remote spot without having to run separate cabling for each zone.