An open network doesn’t provide any of the requirements for what is needed so we can ignore this. Like wise only implementing a captive portal doesn’t provide encryption which is one of the requirement for this network.
Schools may not expand in size but we can expect there to be a large fluctuation in the number of students attending the school at any given year, also as technology advances it is likely that move devices will be added on to the network because of this we want to choose a scalable security solution. A virtual private network will not provide the flexibility needed for a school network to cope with fluctuations in traffic. It sis likely that if a large school choose this solution they would need to either purchase hardware for a VPN which is significantly larger than what the school currently needs, which will likely increase the costs for the school or the school would need to limit the number of devices a student can have which could be difficult as VPNs only provide user end validation.
WPA2-PSK + AES is not suitable in my option because even though it provides a lot of what we need for the schools security it has limitations. The scalibility may not be enought for a large school which is likely using BYOD, it’s Authorisation is vendor dependent which could lead to issues if the vendor lies or there is an oversight in what the admonistration chooses to purchase. Because of this I think it would be best to avoid this possible solution.
Out of the remain three options WPA2-EAP with 802.1x, WPA2 with Captive Portal and WPA2+AES+ 802.1x + Per User PSK, WPA2 with Captive Portal is more complicated to connect to. As the demographic for this project is high school students it is likely we want to have the connection process to be as easy as possible because teenagers are likely not going to want to deal with a hard to use complicated system.
In my opion the two remaining options of WPA2-EAP with 802.1x and WPA2+AES+ 802.1x + Per User PSK are comparable to each other. WPA2-EAP with 802.1x is slightly easier to administrate that WPA2+AES+ 802.1x + Per User PSK but is slightly less secure. WPA2+AES+ 802.1x + Per User PSK provides device and user authentication and Authorization. Personal I would use WPA2+AES+ 802.1x + Per User PSK as it is more security and we want to have the network be as secure as feasibly possible. Also from my personal experience teenagers have a habit of tinkering with any part of a network which they have access to. By providing device authentication we can prevent outlier security risks such as students connecting insecure devices to the network.
Some common security issues include that which could come from users in this case students. These include issues such as out of date devices which can be mitigate by only allowing devices with WPA2, bad user log in which can be mitigate by setting stricter password rules and the extension of the networks wireless network outside of the set area or this can be the result of a user adding an additional access point using one of there own devices as a hot spot, though proper group policy and rules these issue can be prevented.
Outside entities might try and gain access to the network as they can see it. Problems such as this can be mitigate by restringing the area the network covers, restricting the times the network is available and having strong sercurity in place to keep unauterised users out.
Other things which need to be considered include BYOD devices needing there own network as they are less controlable that school devices. Special guests needing a larger range of priverlages than a normal guest would need. Students need protecting from certain forms of content so some restrictions need to be put in place.