Many organizations have put off the deployment of IEEE 802.1X authentication for years while waiting for networking and computing vendors to make it easier. Earlier this year, the IT team at Brigham Young University–Hawaii set out to deploy a secure 802.1X Cisco and Xirrus wireless network to serve the university’s 3,000 users. The team shares its best practices to ensure a smooth 802.1X implementation in any organization.
Everyone knows that most things worth doing are never easy. IEEE 802.1X authentication is clearly worth doing, but many organizations have put it off for years while waiting for networking and computing vendors to make it easier. While networking vendors started offering 802.1X in their products, one big challenge remained that continued to cause delays: How do you add new and stronger security controls to each and every computer while causing the least amount of disruption for your users and staff?
Even though 802.1X has been one of the most talked about authentication methods over the past few years, changes in the way users access the network and compliance requirements are now finally driving its acceptance. Organizations are now expected to support network access for guests, contractors, employee-owned laptops and smartphones, to name a few scenarios. Who wouldn’t want an access solution that includes encrypted authentication and the ability to differentiate access privileges, and offers the ability to deny access to unknown users and untrusted devices?
Despite all these benefits, networking and security teams have struggled when rolling out 802.1X because it meant manually touching each device being allowed onto the network. Interoperability challenges between network infrastructure components and user devices (a supplicant and configuration changes are required), scalability issues and management complexities have also hampered 802.1X deployments.
Things are changing and organizations of all types are addressing these hurdles head on. As an example, the IT team at Brigham Young University–Hawaii set out to deploy a secure 802.1X Cisco and Xirrus wireless network to serve its 3,000 users. In addition to locking down the university’s wide-open wireless network, their challenge was to find a solution that best eased their deployment, limited disruption of service to users, and supported their diverse mix of user devices and multi-vendor network equipment. After careful evaluation of three vendors’ products, BYU–Hawaii selected Avenda’s eTIPS identity-based AAA and NAC platform and Avenda’s Quick1X endpoint configuration wizard.
Mark Aughenbaugh, infrastructure director at BYU–Hawaii says, “Regarding policy enforcement using 802.1X, Avenda is the farthest down the road in this capability. They have a very mature product.”
BYU–Hawaii also chose to use Avenda’s Quick1X endpoint configuration product to help streamline their process. Aughenbaugh says that with Quick1X, they easily installed and configured 802.1X on everyone’s devices without a major burden. The end result was a Web-based portal that lets users run a wizard with a predefined configuration template that streamlines the process and removes the help desk from having to configure each laptop.
“The Avenda solution has allowed us to easily resolve our previous wireless issues and because it worked so well, we’ve started looking at when to deploy 802.1X security to our wired and VPN networks, as well,” Aughenbaugh says. “Our main security goals have been achieved, and as a result we now have network access visibility that we didn’t have before. We’re seeing per user connection and usage details that have even helped us fine tune our wireless network, which has improved our users’ experience.”
The team at BYU–Hawaii used the following best practices to ensure that their 802.1X deployment went smoothly. They added that these best practices can be applied in any organization and enterprise:
1. Deploy a solution that supports all existing infrastructure, and works in multi-vendor environments. This is important in BYU–Hawaii’s case, since its network is made up of 240 access points from Cisco and Xirrus, and Active Directory and other components play an active role.
2. Find a solution that includes RADIUS or works easily with your existing RADIUS infrastructure.
3. For user configuration support, use a solution that supports multiple operating systems, such as Windows 7, Windows Vista, Mac OS X, Mac iOS and Linux.
4. Make sure the user configuration tool can create multiple preconfigured packages so you can distribute different configuration options for students, employees, part-time employees, guests and so on.
5. Ensure that the users are given an easy-to-use tool or wizard that simplifies the configuration process to just a few mouse clicks.
6. Make sure that the IT department can easily configure and distribute new packages when a configuration or policy change requires.




