neilmac Posted September 25, 2013 Posted September 25, 2013 The last few commenters - you are absolutely right about 802.1X. We are referring to user WepHack who has old equipment with varying levels of compatibility and low user skills. His immediate problem is a crackable WEP implementation. His immediate course of action should be to replace WEP with WPA2, with additional support for WPA for those devices that only support WPA. Now, in the longer term, WPA2 Enterprise (802.1X) is absolutely the right solution. It's the only way to authenticate the user or device accessing the network, and to provide a Robust Secure Network (RSN). When WepHack gets round to upgrading his network he should definitely implement a managed solution with enterprise security. Now, those of you who have commented and who are using WPA2 enterprise, I am sure you will agree with me that implementing it is not something you can do easily and quickly. It requires planning, testing and finally time to implement, and it's absolutely worth it in the end. So to correct my statement, it's not that 802.1X is a terrible idea, it's that I wouldn't advise WepHack to use it now to fix his current problem. When he upgrades though he absolutely should. There are alternatives too - Ruckus have dynamic Pre-Shared Key system that gives each user their own key that can be time limited and revoked. As for security compliance, there are many policies that organisations are required to adhere to, from PCI mentioned by m25man to HIPAA, ISO27000, SARBOX and many more. Tools such as AirMagnet WiFi Analyzer and AirMagnet Enterprise will scan a network and immediately highlight where a network fails any of these policies. It can also scan against a custom policy. (Enterprise Network Security - AirMagnet Enterprise | Fluke Networks) AME is in use in financial institutions and healthcare, it's probably overkill for a school, however you should definitely look into new offerings from AirTight, where security checking is built into the access points - AirTight Wireless Intrusion Prevention System The point here is that when you are dealing with environments like education, there is an expectation of privacy and security of data. If there isn't a mandated security policy then the school and IT department need to develop one. Check out CWNP's Certified wireless Security Professional CWNP | Certifications) for training on understanding threats and developing policy. Overall, your responsibility as an admin is to make the network as secure as you can.
WEPHack Posted September 25, 2013 Author Posted September 25, 2013 Could length of WPA key cause compatibility/connection issues with some devices? I'm trying to troubleshoot why some of our mishmash of devices won't connect to WPA.
neilmac Posted September 25, 2013 Posted September 25, 2013 Yes. What are you using right now and what are the options available ? (on the access point) 1
WEPHack Posted September 25, 2013 Author Posted September 25, 2013 I was trying with a 504 bit key. The suggestion is that light is 64 bit, and medium is 160 bit. From what has happened a reasonably long key would be wise in case someone tries to write it down (albeit we'll try and prevent access to the key as best possible). The APs are certainly accepting the 504 bit key, but our Android tablets here don't seem to like it. So many variables though it's hard to know whether it's this, the level of encryption, or AP compatibility.
WEPHack Posted September 25, 2013 Author Posted September 25, 2013 Education is certainly a difficult environment. You have extremely sensitive data combined with low budgets for hardware, and are then expected to work miracles. A lot of staff, including senior staff, just don't realise the pressure. To boot I've been trying to sort out a mess of an IT department for a couple of years now, replacing hardware that desperately needs sorting, along with all the documentation required to properly support. This is with minimal human resources as well.
neilmac Posted September 25, 2013 Posted September 25, 2013 You don't need a 504 bit key, that's probably the problem. Do you have an option for an ASCII key or is it HEX only ? By the way, WPA/WPA2 are WiFi alliance designations, so it you check the devices WiFi alliance certificates and it's listed then they should be compatible and interoperable. Your WG302 is certified for WPA and WPA2. Keep is simple, a short ASCII key will be fine if it's complex enough, 10 characters is good. As for the environment, I come across this all of the time. I don't know why schools/IT departments are so resistant to a) getting trained on wifi basics and b) calling for professional help. WiFi is not easy to deploy correctly, it's a difficult and complex technology and needs careful planning and design, yet the expectation on the IT staff seems to be that you should just nail up access points in any old place and expect to get enterprise class performance. Bizarre ! Anyhow, focus on the problem in had for now, get a stable tested connection. What errors are you getting when you try to connect ? How have you set up the SSID ? NM
WEPHack Posted September 25, 2013 Author Posted September 25, 2013 You don't need a 504 bit key, that's probably the problem. Do you have an option for an ASCII key or is it HEX only ? It doesn't seem to differentiate and just has a single field for entry of the key. I'm using a website based generator to create the key. By the way, WPA/WPA2 are WiFi alliance designations, so it you check the devices WiFi alliance certificates and it's listed then they should be compatible and interoperable. Your WG302 is certified for WPA and WPA2. That's good news at least! Although I'm wary of these WAPs as they just seem to behave strangely. Even more so our newer Netgear WAPs, the WNDAP350. As for the environment, I come across this all of the time. I don't know why schools/IT departments are so resistant to a) getting trained on wifi basics and b) calling for professional help. WiFi is not easy to deploy correctly, it's a difficult and complex technology and needs careful planning and design, yet the expectation on the IT staff seems to be that you should just nail up access points in any old place and expect to get enterprise class performance. Bizarre ! Certainly where we are it's just pressure at every level i.e. not enough budget to easily change what's an expensive item (both consulting and hardware) when done properly, and getting training is not easy when you're required most of the time. It's not impossible though, and a wireless replacement was already pencilled in for next FY, although it's still likely to be £10-20k+, even more with a possible change also required to our wired infrastructure (new higher bandwidth switches, VLAN setup etc.). What errors are you getting when you try to connect ? How have you set up the SSID ? With the tablets I've not had much chance to troubleshoot. It sees the SSID on a scan, but just doesn't connect. SSID is just an alphanumeric string with the name of the school and a "2" at the end. No spaces or symbols.
neilmac Posted September 25, 2013 Posted September 25, 2013 You could also lease the solution rather than face a large up front expenditure. I know of fully managed systems (aruba access points + cloud management) for around 30 GBP per access point per month, including hardware upgrades every 3 years. It's fully managed and supported so you don't have to learn anything. Airtight offer similar. Back to the problem. Set up one ssid on an access point, with WPA encryption. Get a leptop and remove all of the predefined wlan profiles, then try to connect to the access point as if it were a new connection. View the AP logs to see if it gives you any diagnostics. NM 1
apeman Posted September 25, 2013 Posted September 25, 2013 Please note i said a test setup in an hour. You would only need the RADIUS server (very easy to setup) as most people running 802.1x use PEAP and not EAP-TLS, PEAP only requires a server side certificate which can be created with self ssl or one of the many free certificate websites. I agree the problem is that the encryption key has been compromised but what is to stop this happening again?? just changing the key to WPA is not a fix as this key can still be compromised. I have not done this for a while so please correct me if i am wrong but the only way to deploy WEP/WPA keys is via a profile with a login script which is a bit of a pain and you run into the same problem if the profile gets compromised. WPA/WPA2 Enterprise is much more secure and allows settings to be pushed out very easily via group policy, it will only let devices or users you specify to connect to the network. 1
neilmac Posted September 26, 2013 Posted September 26, 2013 @apeman - You are right, anyone responsible for WLAN security should be setting up and testing security methods. If they don't know how or don't have time then they should be getting help. Someone with no experience is going to struggle to work out how to set up enterprise encryption. A lot of people do have problems trying to deploy it, which is why they end up with PSK. There are lots of forum posts of users asking for advice. For anyone who has to deploy 802.1X, this is a great book: http://www.amazon.co.uk/Implementing-Security-Solutions-Wireless-Networks/dp/0470168609 Ruckus invented Dynamic Pre-Shared Key as an alternative to 802.1X, giving an equivalent level of security with a simplified setup method - Ruckus Wireless Awarded Wi-Fi Security Patent for Dynamic Authentication and Encryption | Ruckus Wireless - I see from the poll in another post there are a lot of Ruckus users, it would be good to hear if any of them use Dynamic PSK. Also read: Ruckus Introduces Secure Hotspot - (Note - I am not commercially linked with Ruckus). Aruba and AirTight have alternatives to 802.1X also (though I am not as familiar). If anyone knows of other vendors with similar solutions then do say. If Radius is your bag, then here are some tips: The 9 Best Low-Cost RADIUS Servers -- ServerWatch It would be interesting to ask everyone how they implement security, maybe people could comment back or open a new thread, I am genuinely interested in hearing about it. NM 1
WEPHack Posted September 26, 2013 Author Posted September 26, 2013 Back to the problem. Set up one ssid on an access point, with WPA encryption. Get a leptop and remove all of the predefined wlan profiles, then try to connect to the access point as if it were a new connection. View the AP logs to see if it gives you any diagnostics. Having done a lot more troubleshooting, and tested many combinations of laptop and WAP, the problem only seems to be with the Lenovo/Intel Centrino chipset and the WG302 running any form of WPA encryption. The Lenovo connects without issue to the WNDAP350 and WPA, and the WG302 and WEP. The built-in WG302 log is pretty useless so I will have to get SYSLOG up and running, which I haven't done for a while. We're changing the key tomorrow, so I'll have to leave a second SSID for WEP enabled until I can figure out what's wrong. Could it be that these (very old) WG302 APs just aren't going to be compatible with this Intel wireless chipset?...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now