Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Limiting wireless clients to secured access points

Wireless Security By Devin Akin , Network World , 06/12/2007

I am attempting to enable all my wireless users to ONLY connect to WEP or WAP enabled WLAN's. I do not even want them to be able to see unsecured ones if possible, but would like them only to connect to secured ones. Do you think this is even possible and if so how easy is it to implement?

Configuring and enforcing security policy on wireless stations was a significant problem until the release of "Endpoint Security Solutions" by vendors such as Network Chemistry and Senforce. These solutions consist of client agent software and a central policy server with a management console. Using the management console, network administrators can control connectivity on client devices by using security policies enforced by the agent software. It's important to note that every endpoint security solution is not created equal. Some solutions are focused solely on Layers 1-2 while others are focused on Layer 1-7. The L1-L2 solutions focus on controlling Wi-Fi connectivity using policies that, for example:

* Allow connectivity only to specific SSIDs

* Disable Wi-Fi adapters when a wired adapter is connected and bridged to the Wi-Fi adapter

* Require use of VPN protocols when connected to an authorized-but-unsecure Wi-Fi network

* Prevent hotspot evil twin and phishing attacks

* Provide alerts and reporting

* Set minimum authentication and encryption levels or enforce specific parameters

Layer 1-7 solutions provide many of the same functionality as the L1-2 solutions, but add additional higher-layer features such as:

* Network Access Control (NAC)

* Stateful firewall

* Application control

While a comprehensive solution of this magnitude is never a "no brainer" to implement, each vendor provides a "best practices" whitepaper and instruction manuals on how to get their products up and running fairly quickly. Before you decide that "more layers are better", consider the following:

* You may already have a managed client firewall solution

* You may already have a managed client VPN solution

* You may only need to control the wireless connectivity of client devices

The mindset behind endpoint security solutions is to take the security reins out of the hands of the end user and put it back into the hands of the security administrator - where it belongs. Using this new technology, the security administrator can assure that the organization's security policy is enforced on every mobile device running the endpoint agent software.

Comments (2)
Login
Forgot your account info?

AirDefense has had a laptopBy FD on July 5, 2007, 3:55 pmAirDefense has had a laptop wireless security client for 3 years now. You can download a free copy from: http://www.airdefense.net/products/adpersonal/index.php AirDefense...

Reply | Read entire comment

AirDefense can limit client access to access pointsBy Anonymous on June 25, 2007, 5:19 pmThe AirDefense Personal product can enforce corporate wireless policies on user laptops. Re: Limiting wireless clients to secured access points.

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.

Whitepapers

File Integrity Monitoring: Secure Your Virtual and Physical IT Environments

Discover the capabilities your file integrity monitoring solution should have to effectively secure...

Toward More Flexible, Next-Generation Collaboration Solutions

A recent study by CIO Magazine and IDG Research Services found that while collaboration tools are...

Boost Productivity While Cutting Costs with Next-generation Collaboration

IDG says that "providing employees with collaboration tools that enable them to work together...

Webcasts

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Intelligent Mobility: BlackBerry Technical Seminar 2008

The virtual BlackBerry Technical Seminar keeps growing in popularity every year, and we want to...

Harnessing the power of communications to increase workplace performance

Due to the convergence of IT and telecommunications technologies, the business workplace has been...

Special Reports

Ethernet Services: WAN options mature

WAN Ethernet services are reliable, cost-efficient offerings that are widely available and in a...