Jump to content

Recommended Posts

Posted

I have some kindles to set up here they are an older model but not the one with the full keyboard. I have been experimenting with the best way to connect them to the WIFI. Our setup is Ruckus and NPS. I already have a BYOD using domain credentials and school owned devices using certificates pushed through GPO. I know that the Kindles' capabilities are fairly basic when it comes to this so I have been experimenting with the different ways of using MAC authentication. My choices seem to be:

 

NPS - MAC authentication, account in AD and CHAP authentication, but I have to use reversible encryption on the password. This seems to be a long winded way when I could just use a list of MAC addresses on a Ruckus ACL, plus the reversible encryption is not desirable (but anyone who knows how this method works would know the password anyway!)

 

Just use a MAC based ACL on the Ruckus equipment and use a VLAN ACL on my networking equipment so they can only access the internet so any MAC spoofing will only gain access to that VLAN.

 

Anyone else using any different methods and possibly more secure methods?

Posted

Not really an answer to your question, but also note that they don't support proxies.

 

I just made a SSID for kindles that had a transparent proxy as the gateway, and ACL to only let them use that. Not that there's really any way to use them for abuse. Parental controls let me turn off the browser, store etc.

 

What's the attack scenario with reversible encryption?

  • Thanks 1
Posted
Passwords are basically plain text with enough user privileges. Our LEA uses LightSpeed so I don't have to worry about proxy addresses.
Posted
Handy about the proxy. You'd have to hack a kindle via usb to get enough privileges to see the encoded password though, so not too much of an issue.
Posted
No I meant on the windows server side of things, using this method a device will send its MAC address as its user name and password so you would have to make sure those accounts were well locked down or deny them logon to your PCs etc.
Posted
Ah, I see, I treat kindles as anonymous as I only use the wifi to send books via the website, so I just created that ssid without any account auth
Posted

Okay I have reached a solution for now, I have:

 

Used MAC filtering and full client isolation on the Ruckus system.

Created an ACL on our VLAN router to do the following:

 

Allow only access to DNS and DHCP on the relevant servers

Deny access to all other VLANS/Internal IP ranges

Allowed only HTTP and HTTPS traffic

 

So pretty much the same kind of security as you apply to your BYOD (apart from 802.1x).

 

Improvements to implement later:

 

Use DHCP and DNS on gateway router, rather than internal DNS and DHCP.

Use more Ruckus restrictions such as restricted subnets etc.

It would have been nice to use the OS restriction on the Ruckus as well but you only get a choice of the major OS to choose from.

 

Hope my final solution helps someone as there's nothing worse than searching for these things and finding the question and not the answer!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...