Wireless LAN Access Control: managing users and their devices

Source: Internet
Author: User

In the first part of the wireless LAN certification series, we introduced how to ensure the security of the guest's wireless network. In the second part, we discuss Wireless LAN access control methods, including creating policies, device identification, and integrating other network access control solutions.

Enterprises have made great breakthroughs in network security and wireless LAN/WLAN Access Control. It can be traced to the WEP key that can be cracked statically, followed by a third-party Wi-Fi client and OS patch required to deploy strong authentication and encryption. Now some Wi-Fi devices and existing operating systems can support WPA2-Enterprise, and even small identifiable devices like phones can support.

Even with such advances, with 802.1X authentication and AES encryption) WPA2-Enterprise is still not dominant. 802.1X needs to integrate many components, which come from multiple vendors and are usually managed by different parts. To succeed, you must plan and coordinate, including user account management, device allocation, and network integration. Fortunately, there has been a better tool to solve Wireless LAN access control problems.

WLAN Access Control starting from Group Policy

Although enterprises using 802.1X often have good control over their laptops, this is not the same language for other wireless devices, especially those devices that cannot be purchased by the IT department.

IT often adds them to Active Directory before publishing a laptop. This is achieved by using the Group Policy Objects to automatically configure the 802.1X parameter to reflect the Group membership of each user. Both Windows 7, Vista, and XP support 802.1X group policies, including wired and wireless clients. This is described in the Microsoft Windows Server 2008 R2 guide:

Access Group Policy Extensions for 802.1X Wired and Wireless

Configure 802.1X Wired Access Clients by using Group Policy Management

Configure 802.1X Wireless Access Clients by using Group Policy Management

However, most staff usually use wireless devices that are not running on Windows, or even purchased by the IT department. Some IT departments treat a large number of smartphones and tablets purchased by employees as guest devices. For example, when CFO logs on to a wireless LAN from their laptop, they may be asked to connect to the company's SSID, and provide 802.1X login information based on their identity and role to obtain access permissions. However, when CFO uses their personal iPad to log on to a wireless LAN, it may connect to the guest SSID that only provides Internet access. This is a "right strategy" for companies that have not yet processed their own device purchases, but it is not an ideal long-term strategy.

Implement WLAN access control policies through device identification

To solve this problem, many network and security products currently use device identification technology. By observing MAC addresses, protocols, requests, and responses, people can guess that there is confidence in a device's manufacturer, model, and OS. The "fingerprint" can then map devices to a group based on access control, device allocation, and policy objectives.

Currently, the Amigopod Visitor Management Appliance (VMA) of Aruba Networks is a device recognition tool. The device can monitor the device using DHCP and HTTP sent by the company network. For example, by checking the traffic, VMA cloud can differentiate CFO's company laptop from his personal iPad, and map each identified device to the correct access policy. CFO laptops may have looser access permissions due to their trusted status, while iPad is limited to enterprise emails and access to internal websites. However, all the data sent by these two devices will be protected by the WPA2-Enterprise, where 802.1X is used to control access to the company SSID.

This example also misses the question: How can I configure the CFO iPad to access the company's SSID? Manual configuration is possible, but it is clear that automatic allocation is better.

Automated Wi-Fi client allocation and configuration files

In this example, our CFO may first connect his iPad to the visitor's SSID and access the automatic login page that provides VMA. VMA will generate a configuration file for our CFO iPad and send it via email or SMS. By clicking the included URL, CFO can install 802.1X parameters and certificates to enable the iPad to access the company's SSID.

In fact, many products now provide this type of automated Wi-Fi client allocation function. For iPad and other iOS devices, Apple's iPhone Configuration Utility can generate customizable and encrypted Wi-Fi Configuration files that can be sent to users and published on websites, you can also install the SDK by using the mobile device manager that supports IOS 4 Native MDM.

The latter applies to AirWatch, BoxTone, MobileIron, Sybase, and other types of devices. It can be integrated with the enterprise's Active Directory registration and generate certificates for each approved iPad. If one iPad is lost, all installed MDM files, including Wi-Fi settings, will be deleted. However, MDM is not limited to Apple devices-many of which can be used to register and allocate Androids, BlackBerrys, and laptops and netbooks owned by employees.

Integrate 802.1X authentication and network access control

With an effective new wireless device identification method, using WPA2-Enterprise for registration without IT assistance and applying appropriate access policies to each employee is not difficult. However, if WPA2 and NAC are integrated, the implementation of the policy is better.

Access AP) and the controller can forward requests to the 802.1X Authentication Server after simple configuration-many of them are even built into the authentication server that uses the local account database. To simplify the interoperability of Multiple Vendor devices, Wi-Fi Alliance now performs Extensible Authentication Protocol (EAP) type testing on all WPA2-Enterprise-certified products, includes EAP-TLS, EAP-TTLS/MSCHAPv2, PEAPv0/EAP-MSCHAPv2, PEAPv1/EAP-GTC, EAP-SIM, EAP-AKA and EAP-FAST.

However, if NAC is not used, 802.1X can be used as a simple exchange: if an error occurs, you will not be able to connect to the wireless LAN; if it succeeds, you can obtain the access permissions of your users/groups through the RFC 3580 VLAN tag ). However, when used together with NAC, 802.1X can execute policy decisions based on the user/group identity and device security status. Although NAC can be executed without 802.1X, these two technologies can achieve more powerful enterprise wireless LAN access control.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.