joanie_wexler
Writer

Cisco unifies security across wireless, wired LANs

Opinion
Feb 19, 20073 mins

* Company says Wi-Fi controllers now talk to wired security products

If you are a Cisco wired network shop and also use Cisco’s thin-AP, controller-based wireless LANs, you can now apply wired Cisco security functions to your Wi-Fi traffic.

Cisco last week said that many of its wired security products and technologies now interoperate with its WLAN controllers. In a nutshell, this means that Cisco security foundation products, such as its Network Access Control (NAC) appliance, intrusion prevention system (IPS), ASA 5500 Series Firewall, and other products, will talk to Cisco WLAN controllers.

As a result, you can put WLAN traffic through the same security paces as your wired traffic in one fell swoop, rather than a wireless client having to log in separately to the wireless and wired networks.

When wireless clients log in to a Cisco WLAN controller, the RF-specific security functions embedded in the 802.11 suite of protocols, such as WPA2, take place. In addition, the controller now automatically communicates with the various security appliances and functions on the wired network so that all security checks, scans, and remediation take place on wireless traffic, too.

Note that when I say “automatically,” I mean “automatically once you configure your wireless and wired networks to work together this way” using design guidelines that Cisco has developed. It doesn’t just happen without some twiddling on your part – either on your own or with assistance from Cisco or an integrator.

Also note that you can’t do away with wireless IPS capabilities just because wired IPS capabilities are now automatically engaged. Wireless IPS systems scan and filter the RF airwaves at Layer 1 for rogue devices and interference activity, while traditional wired IPSs comb through Layer 4-7 packet flows to detect malicious code that could infect operating systems and application software. With the integration, the RF and Layer 4-7 systems work together; if the wired IPS detects malicious code, it communicates with the WLAN controller to block that wireless client from accessing the network, explains Chris Kozup, Cisco manager of mobility services.

“Before, [the wired IPS] could detect the malicious code [on the wireless network], but couldn’t do anything about it,” Kozup says. He adds that Cisco Security Agent host and desktop threat-protection software can now detect a client that is physically connected to a wired network and disable its wireless card so that an ad-hoc connection from an undesirable third source couldn’t bridge into the network.

Integrated wired/wireless client provisioning and management weren’t part of this announcement, but Kozup advises to “stay tuned.”

joanie_wexler
Writer

Joanie Wexler is an independent writer and editor who has spent 20+ years writing about computer networking technologies, their business potential, and implementation considerations. She serves clients at technology companies and industry publications writing educational materials on all aspects of IT.

More from this author