Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Wi-Fi security: Leverage what you know

Remember the 'big picture' in Wi-Fi security
Wireless Alert By Joanie Wexler , Network World , 06/06/2005
Sign up for this newsletter now!

Joanie Wexler looks at how enterprises can take advantage of wireless LANs and WANs.

How do you know that you've covered all the bases when it comes to wireless LAN security? 

To finish up our short, basic series on getting started with securing enterprise Wi-Fi networks, Lisa Phifer, vice president at networking consultancy Core Competence, notes that it's easy to get focused on selected technologies and lose sight of the big picture.

"Certainly, 802.11 poses new challenges that require unique solutions such as link-layer encryption and rogue access point monitoring," says Phifer. "But many existing network security practices also apply to wireless," she says. She advises to leverage what you know about wired best practices for your wireless network, too. For example, she says:

* Wireless APs and switches must be hardened against attack and compromise, just as we harden WAN-facing devices like access routers and perimeter firewalls.  Subjecting your APs and switches to "regular" (wired) network and system vulnerability assessment scans can help you find (and subsequently fix) open ports, unpatched software, default accounts, weak passwords, lax access controls and out-of-policy configurations.

* Wireless stations of all types must also be protected. Most enterprises already have policy and procedures to secure Internet-connected laptops. These measures should be applied to wireless stations, not only at hot spots and homes, but even on-campus. In a WLAN, you can't assume that every other station is trusted. Desktop firewalls, integrity checkers, network-admission controls and centrally managed security policies can all be applied to wireless stations. 

Some configuration details may differ - for example, you might block file sharing over wireless in some cases but not others. And some platforms, such as wireless printers and phones, might prove challenging. But it makes good sense to leverage what you already have when moving from (or between) wired and wireless networks.

* Wireless intrusion detection and prevention (IDS/IPS) requires deep understanding of 802.11 (and often 802.1X) protocols, attack signatures, and expected/unexpected behavior, using wireless sensors (or APs) to monitor the air. However, that doesn't mean wireless IDS/IPS is an entirely new ballgame.  If you have an existing wired network IDS/IPS, use it to watch for attacks that make their way from wireless onto your wired network. Re-use existing network management systems and log servers to monitor events on APs, switches and your wireless IDS/IPS itself. When possible, implement automated responses involving device reconfiguration through your network manager so that you'll have fewer points of configuration control and audit.

Joanie Wexler is an independent networking technology writer/editor in Silicon Valley.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

Whitepapers

The Frontline LAN Troubleshooting Guide

This comprehensive, 115 page guide provides frontline network troubleshooters with practical advice...

File Integrity Monitoring: Secure Your Virtual and Physical IT Environments

Discover the capabilities your file integrity monitoring solution should have to effectively secure...

Realizing the Potential of User-Generated and Social Networking

Can communication service providers (CSPs) leverage Web 2.0 services and create new service...

Webcasts

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Intelligent Mobility: BlackBerry Technical Seminar 2008

The virtual BlackBerry Technical Seminar keeps growing in popularity every year, and we want to...

Harnessing the power of communications to increase workplace performance

Due to the convergence of IT and telecommunications technologies, the business workplace has been...

Special Reports

Ethernet Services: WAN options mature

WAN Ethernet services are reliable, cost-efficient offerings that are widely available and in a...

Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.