* When are rogues a threat?
endif; ?>A number of you replied in earnest to my recent newsletter, “Do we really need rogue AP detection?”
Some of you asserted, for example, that if you’ve done a good job getting all your other network security ducks in a row, you shouldn’t have to chase after rogue access points (AP). I agree. But I also think that’s a big “if,” at least in these early days of wireless.
Others felt that even when properly implemented, 802.1X authentication wouldn’t keep rogues from admitting intruders onto the corporate network. There I tend to disagree. But note the synergies between these two arguments.
Let’s start with No. 1: An otherwise well-secured network shouldn’t be susceptible to rogues.
True. But how many of you are completely up to speed with 802.11i deployments, wireless best practices and wired-network best practices, all working in harmony? 802.11i (a.k.a. WPA2) product certifications are very new, for example, and thus only a few are on the market.
In addition, very few of the enterprises I interview tell me they are using even the older WPA to secure their wireless LANs. Most use dynamic WEP or MAC filtering (usually with SSID suppression) as their primary security method. Until wireless security deployment and practices catch up to the technology, it’s not a bad idea to suppress rogues as a backup.
Argument No. 2: 802.1X wouldn’t disarm rogues.
With no authentication measures implemented in the network, a rogue would allow any client to associate to the WLAN and possibly penetrate the wired corporate network. But with properly configured 802.1X framework in place, the supplicant (client) needs authentication credentials that can be verified by the back-end authentication server. If those don’t exist, accompanied by network-access permissions, the user should not be able to tap any resources on the wired network.
That leaves the user able to communicate, potentially, with other wireless devices.
However, you could implement a two-way, mutual authentication algorithm within the 802.1X framework (using a two-way Extensible Authentication Protocol such as EAP-TTLS, PEAP or Cisco LEAP). This algorithm will authenticate not only the supplicant but also the AP. If it’s a rogue, clients can’t use it to get anywhere, on either the wireless or wired network.
The degree to which you need to scan for rogues does depend on the strength of the rest of your security system. Until the latest wireless security products and best practices are installed and humming, though, having an automated system to identify rogues connected to your network and to potentially close them down is probably wise.




