Title: Managing a Wireless Rollout in an Educational Environment
1Managing a Wireless Rollout in an Educational
Environment
- Graham Robinson
- grahamr_at_simplywireless.com.au
2Agenda
- Session 1
- WLAN Requirements Analysis
- Understanding a Site Survey
- Hands-on Opportunity (Lab)
- Session 2
- WLAN Security
- Demonstration
3Who is Simply Wireless?
4WLAN Requirements Analysis
5WLAN Requirements
- Technology Choice
- RF Spectrum Management
- Access Point Communications
- Network Integration
6WLAN Requirements (Contd)
- Security
- Management Architecture
- Redundancy
- Future Proofing
7Technology Choice
802.11a
802.11b
802.11g
54 / 32 Mbps
11 / 7 Mbps
54 / 22 Mbps
Bandwidth
Frequency Band
5 GHz
2.4 GHz
2.4 GHz
Worldwide
US/AP
Worldwide
Availability
Future Usage
Yes
No
Maybe
8RF Spectrum Management
- Cell Sizes
- Power Output
- Managing User Density
- External Antennae
9Access Point Communication
- Layer 2 Roaming (Hand-off)
- No Roaming
- Enterprise Roaming
- Fast Roaming (802.11f)
- Load Balancing
- Variable Environments (Classrooms)
- High Density Areas
10Network Integration
- Layer 3 (Network) Roaming
- Virtual LAN / Network Design
- IGMP / Multicast
- Quality of Service (QoS)
11Security
access point (AP)
client
Encryption Key
Encryption Key
Open?
WEP?
VPN?
WPA?
EAP?
802.11i?
RADIUS Server
access point (AP)
client
12Management Architecture
- Firmware Upgrades
- Configuration Changes
- Usage Statistics and Logging
- Remote Administration
- Existing Management Platform
13Redundancy Support
- Component Failure
- Active Redundancy
- Hot-Swap
- Re-Integration Times
14Future Proof
- Software/Firmware Updates
- Hardware Updates
15Understanding a Site Survey
16Indoor Environment
17RF Design Documentation
- RF Coverage
- Signal Strengths
- Layer 2 Roaming
- Network Baseline
- Troubleshooting
18Channel Planning
- RF Interference
- Optimal Spectrum Usage
- Legacy System Cohesion
19Questions?
20Hands-on Lab
- Demonstration Access Points
- No WEP, DHCP On
- SSID tsunami
- Cisco AP1100 (10.0.0.1)
- Cisco AP1200 (10.0.0.2)
- Web Access Cisco / graham
- Telnet Cisco / Cisco ? graham (enabled)
21WLAN Security
22WLAN Security
Radio Link Security Network Security
23Evolution of Security
access point (AP)
client
Encryption Key
Encryption Key
Open?
WEP?
VPN?
WPA?
EAP?
802.11i?
RADIUS Server
access point (AP)
client
24First Generation Security
- 802.11 (FHSS)
- Security through Obscurity
- 802.11b (HS/DSSS)
- Shared Key Authentication
- Wired Equivalent Privacy 40bit
- Wired Equivalent Privacy 128bit
25First Generation Security Problems
- 802.11 (FHSS)
- Security through Obscurity FLAWED
- 802.11b (HS/DSSS)
- Shared Key Authentication FLAWED
- Wired Equivalent Privacy 40bit FLAWED
- Wired Equivalent Privacy 128bit FLAWED
26Security Objectives
User Authentication Data Encryption
27User Authentication
- 802.1X / Extensible Authentication Protocol (EAP)
RADIUS Server
Access Point (AP)
Client
RADIUS
802.1X
28Secure EAP Flavours
EAP-TTLS
PEAP
EAP-TLS
Funk Software
Cisco, MS, RSA
IEEE
Authored By
PKI Certificate
PKI Certificate
PKI Certificate
Server Security
Username Password
Username Password
PKI Certificate
Client Security
Yes
Yes
Yes
Multi-OS Support
Poor
Great
Great
Scalability
Highest
High
High
Security
29Security Objectives
User Authentication Data Encryption
30Encryption with WEP
31Encryption with WEP/TKIP
WEP Key Hashing
IV
BASE KEY
PLAINTEXT DATA
CIPHERTEXT DATA
XOR
HASH
IV
PACKET KEY
STREAM CIPHER
RC4
32Message Integrity Check (MIC)
33Virtual Private Network or EAP?
802.1X/EAP
VPN
No
Yes
Requires DMZ
No
Yes
VPN Concentrator
No
Yes
Double Login
20 - 30
2 - 7
Encryption Overhead
Fair
Excellent
Client Support
Scalability
Excellent / Costly
Excellent / Cheap
34WLAN Security
Radio Link Security Network Security
35Security Attempts
- User and Device Management
- MAC Address Filtering
- Static DHCP Reservations
- Manually Distributed WEP Keys
- Implications
- Overworked Technical Support Team
36Secure Network Designs
- Segregation Tactics
- Logical Separation
- Physical Separation
- DMZ / Wireless VLAN with ACLs
- Segregation Devices
- Firewall (eg. IPTables)
- Wireless Gateway
37Wireless Gateway Devices
- Network Management Device
- Some security features
- Firewall
- VPN Endpoint
- Examples
- Bluesocket
- Vernier Networks
- Reef-Edge
38Questions?Packet Analysis