Skip Links

Network World

  • Social Web 
  • Email 
  • Close

802.1X for a small network

Wireless Security By Andrew Lockhart , Network World , 01/29/2007
  • Share/Email
  • Comment
  • Print

What are some easy solutions for implementing 802.1X based authentication on a SOHO wireless network?

For those involved in deploying wireless networks in enterprise settings, using 802.1X for authentication is most likely old hat. However, smaller operations that have not made a significant investment in wireless infrastructure or taken the time to investigate the matter may not realize that they already possess all the needed tools to migrate to a WPA-Enterprise deployment.

An 802.1X wireless network consists of three components, the RADIUS server, Network Access Servers (your APs), and any client devices. Many consumer grade APs now support 802.1X and are easily configurable - just tell it which RADIUS server to connect to and the shared secret used to protect traffic between it and your AP. Additionally most operating systems in common use (Windows XP, Mac OS X, and Linux) easily support 802.1X for wireless authentication. So far these requirements should be easily satisfied.

The biggest piece of the puzzle is the RADIUS server. Here there are several options for fulfilling this role. For instance if you're utilizing a Windows domain you can deploy Certificate Services and Internet Authentication Service, which is Microsoft's RADIUS server. However, if you're not using a Windows domain, the choices are less clear. If you have extra hardware lying around or a system to run VMware on, you can setup a Linux system and use FreeRADIUS, an excellent OpenSource RADIUS server.

For most SOHO setups all of this may be more trouble than it's worth since the time spent in deploying the solution may not be worth the benefits of a more granular authentication system. With only a few users and client devices it may be simpler to use WPA-PSK (or WPA2-PSK), with a strong key, and change it whenever access for a particular user needs to be revoked.

If you're determined to go down the 802.1X path there are still some other options that require minimal to no investment in additional hardware. For instance if you have an AP that is compatible you can re-flash its firmware with OpenWRT (http://openwrt.org), a Linux distribution that supports many common APs. This will allow you to install FreeRADIUS on the AP itself, removing the need for a separate system. Still this can be a daunting task.

  • Share/Email
  • Comment
  • Print
Partner Content

Company Description

Emerson Network Power and its Liebert power and cooling technologies increase IT system flexibility and availability, while lowering the total cost of ownership.

Power and Cooling Guidelines

Learn how to optimize power and cooling in network access rooms to keep equipment operating at peak performance and proactively monitor changes.

Download this white paper

Business-Critical Continuity

Read about Sequent and how they implemented a new data center to meet current requirements while easily scaling to support projected growth.

Download this case study

Cutting Energy Costs

Reduce cooling system energy costs by 30 to 45 percent through five data center efficiency strategies.

Download this white paper

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

Whitepapers

Windows Vista: Necessity and Opportunity

The Vista era of Windows is here. Yet most organizations will retain Windows XP alongside new Vista...

Gartner Research: Hype Cycle for IT Operations Management, 2008.

If you are evaluating service management tools, managing emerging technologies such as...

Unified Threat Management from Check Point

Unified Threat Management platforms all consolidate and simplify an enterprise's approach to...

Webcasts

Migrating to Windows Vista: Necessity and Opportunity

The Vista era of Windows is here. Yet most organizations will retain Windows XP alongside new Vista...

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Special Reports

Unified Threat Management from CheckPoint

Discover why Unified Threat Management Firewalls are ready for the enterprise today. High...

Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.