?
Solved

wireless network security

Posted on 2003-12-04
10
Medium Priority
?
320 Views
Last Modified: 2013-12-04
hi, i am given a project on wireless network security, can i have more information about how RADIUS, VPN and IPsec works in the wireless environment? Does the three of them needs to be implemented together?
 thanks
0
Comment
Question by:phinie
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
10 Comments
 
LVL 57

Expert Comment

by:Pete Long
ID: 9873445
Hi phinie,
Is this a homework question?

PeteL
0
 
LVL 10

Expert Comment

by:BloodRed
ID: 9879280
Strange question.  The wireless network is just the meduim over which the other protocols communicate.  VPN is how the system connects to the remote network, IPSec is how the systems authenticate to each other(AH) and how they encrypt data if that feature is enabled(ESP), and RADIUS authenticates the user and checks to ensure they're permitted by policy to establish a connection.  If this is a project on wireless security I'd think they'd be more interested in how WEP, 802.1x, and other vendor specifc security protocols can be implemented.

The three don't have to be implemented together, or at all.  
0
 
LVL 10

Expert Comment

by:KingHollis
ID: 9892522
I'm not sure that this is as strange a question as it looks on the surface.

Which type of networking technology can authenticate users coming from an untrusted space and encrypt their communication so that someone listening can't intercept it? The answer is a VPN.

A VPN solves wireless networking's current deficiencies [WEP]. Granted, getting connected becomes a bit more difficult for your users. But if you've already invested time in building a VPN infrastructure for your mobile users to access your organization's network, installing a VPN to authenticate wireless users is a relatively simple process.

First, picture this:

Wireless User-->AP-->VPN Server-->RADIUS Server, DHCP, DC, and rest of protected network.

1. Wireless users associate with the access point but are given a non-secure address [either from the AP or DHCP on the VPN server] for example 172.27.0.10 - 172.27.0.50. They will at this point be able to communicate with only the VPN server and other non authenticated wireless clients in the 172.27.0.0/24 subnet.

2. If the VPN server has an address of 172.27.0.1 then wireless clients could attempt a VPN connection to 172.27.0.1.
3. The VPN server could then authenticate the user against the DC or, if there are multiple access points and VPN servers, it could use the RADIUS server for centralized authentication.
4. Once authenticated, the internal network 10.10.100.0/24 could issue the wireless client a trusted address via DHCP or the VPN server could issue one from it's static pool. And voila the wireless user is authenticated and communicating securely through the VPN.
5. You could use IPSEC on the VPN server to filter out all requests other than VPN attempts.

To strengthen this security, you could use EAP-TLS which would allow you to authenticate the machine and the user, but would require using certificates.

So, to answer your question, no they don't all have to be implemented together. But to get the strongest and best solution, yes!

For other useful security measures, you can explore the topics mentioned by BloodRed.
0
Threat Trends for MSPs to Watch

See the findings.
Despite its humble beginnings, phishing has come a long way since those first crudely constructed emails. Today, phishing sites can appear and disappear in the length of a coffee break, and it takes more than a little know-how to keep your clients secure.

 
LVL 10

Accepted Solution

by:
KingHollis earned 400 total points
ID: 10339528
phinie,

Did you get sorted out here? Do you still require assistance?
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 11150707
Hello this question has been open a while please take the time to come back and clean it up.

Closing Questions
http://www.experts-exchange.com/help.jsp#hs5


Best Wishes

Pete
www.petenetlive.com
0
 
LVL 10

Expert Comment

by:KingHollis
ID: 11177117
Pete,

I gotta feel like I nailed this one.

Regards,

~KingHollis~
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 11181806
NO arguments from me M8 :)
0
 
LVL 10

Expert Comment

by:KingHollis
ID: 11236665
Cheers!
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
SHARE your personal details only on a NEED to basis. Take CHARGE and SECURE your IDENTITY. How do I then PROTECT myself and stay in charge of my own Personal details (and) - MY own WAY...
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
This tutorial will teach you the special effect of super speed similar to the fictional character Wally West aka "The Flash" After Shake : http://www.videocopilot.net/presets/after_shake/ All lightning effects with instructions : http://www.mediaf…
Suggested Courses

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question