joanie_wexler
Writer

F100 firm seeks tighter mobile access control

Opinion
May 6, 20113 mins

Aims to ID device types and associate them each with policy, SSID

A principal network analyst at a worldwide Fortune 100 company worries that people presume mobile devices are inherently more secure than they really are.

Aunudrei Oliver, who holds four wireless technology certifications from CWNP Inc. and CompTIA, asserts that “there’s a bit of misconception in the wireless world that once a device is authenticated that it’s secure. It’s really not.”

For iPads, iPhones and Androids, “the process of getting onto the network is now easy and available, where it used to be hard and controlled,” says Oliver, whose employer supports about 12,000 mobile devices and asked that the company not be named. Also, where each employee used to consume one IP address, now they may consume many more, because they might be associated with any number of fixed and wireless devices.

REPORT: Ready or not, iPad, other tablets are in the enterprise

“Yet companies have no visibility beyond a username and password,” Oliver points out. “Without being able to distinguish among devices, it’s difficult to put a policy in place.”

Oliver, who runs Cisco wireless and wired LANs, had been using Great Bay Software’s Endpoint Profiler product, “but at the end of the day, it was expensive and difficult to cost-justify,” he explains.

He’s since been testing Aruba’s recently announced Mobile Device Access Control (MDAC) for Cisco, an alternative to Cisco’s just-announced TrustSec suite of access control components that can identify device types and register devices with an 802.1x certificate.

Oliver’s company runs a public key infrastructure (PKI), which works well for workstations that are part of a network domain. “But mobile devices aren’t part of a domain; how do you get certificates to those devices?” he explains.

You do it at the place where the devices enter the network: at the WLAN controller, Oliver professes. The Aruba WLAN controller sits as a “bump in the road” between the company’s Cisco WLAN controller and authentication server. In other words, the company uses Cisco WLCs to manage and control Cisco APs, but an Aruba controller to identify and classify the devices that attempt to access the network.

“If you’re a desktop or laptop, it’s authentication/business as usual. If you’re a mobile handheld or tablet, you’re redirected to the [Aruba] Amigopod server. Amigopod prompts for a username/password and then issues a certificate to install on the device and a WLAN SSID, based on device type.”

Oliver says he’s “still open to solutions” and says that Cisco’s recently announced Identity Services Engine (ISE) also “should address some of our concerns.”

joanie_wexler
Writer

Joanie Wexler is an independent writer and editor who has spent 20+ years writing about computer networking technologies, their business potential, and implementation considerations. She serves clients at technology companies and industry publications writing educational materials on all aspects of IT.

More from this author