Networking Forums

Networking Forums > Wireless Networking > Wireless Networks > Best Practices for Wireless/Wired LAN Implementation

Reply
Thread Tools Display Modes

Best Practices for Wireless/Wired LAN Implementation

 
 
Tane M. Baum
Guest
Posts: n/a

 
      10-19-2006, 04:58 AM
I thought I throw this question for an advice. We're just about to
implement our wireless solution. After reading numerous technical
documentation cover to cover, it came down to the below questions.

Scope:
Clients - Windows(XP/2000/2003)(Primarily WinXP),Linux, MacOS X
Wireless Router/Switches/Access Point: Cisco, Nortel

RADIUS Server:
Microsoft IAS, Juniper Steel-Belted RADIUS

Authentication Server(Authenticator):
Microsoft Active Directory, Linux Server, MacOS X Server

Authentication Method:
Juniper Steel-Belted: TTLS Pass-thru, PEAP Pass-thru, Web-AAA
Microsoft IAS: PEAP-Offload, PEAP Pass-thru, Web-AAA

What I'm trying to achieve is:
1 - Have the best overall security
2 - No additional wireless client required
3 - Widely supported

My question:
Which Authentication Method is the best? Why?
Which encryption to use?


Thanks





 
Reply With Quote
 
 
 
 
James McIllece [MS]
Guest
Posts: n/a

 
      10-23-2006, 08:39 PM
"Tane M. Baum" <(E-Mail Removed)> wrote in
news:(E-Mail Removed):

> I thought I throw this question for an advice. We're just about to
> implement our wireless solution. After reading numerous technical
> documentation cover to cover, it came down to the below questions.
>
> Scope:
> Clients - Windows(XP/2000/2003)(Primarily WinXP),Linux, MacOS X
> Wireless Router/Switches/Access Point: Cisco, Nortel
>
> RADIUS Server:
> Microsoft IAS, Juniper Steel-Belted RADIUS
>
> Authentication Server(Authenticator):
> Microsoft Active Directory, Linux Server, MacOS X Server
>
> Authentication Method:
> Juniper Steel-Belted: TTLS Pass-thru, PEAP Pass-thru, Web-AAA
> Microsoft IAS: PEAP-Offload, PEAP Pass-thru, Web-AAA
>
> What I'm trying to achieve is:
> 1 - Have the best overall security
> 2 - No additional wireless client required
> 3 - Widely supported
>
> My question:
> Which Authentication Method is the best? Why?
> Which encryption to use?
>
>
> Thanks
>
>
>
>
>
>


Hi Tane --

Certificate-based authentication methods are the most secure as they
protect against a large variety of possible attacks.

Because you plan on using Microsoft WS03 with IAS, the most secure method
provided with that OS is EAP-TLS. EAP-TLS provides mutual authentication
and requires certificates on IAS servers; it also requires either a
certificate in the client certificate store or the use of smartcards.

If the cost of deploying certificates is prohibitive, you can deploy
Protected EAP with MS-CHAP v2 (PEAP-MS-CHAP v2). PEAP-MS-CHAP v2 also
provides mutual authentication, where the IAS server has a server
certificate; however user authentication is performed with password-based
credentials (user name and password).

If you haven't previously seen this paper you will probably find it useful.

"The Advantages of Protected Extensible Authentication Protocol (PEAP): A
Standard Approach to User Authentication for IEEE 802.11 Wireless Network
Access" http://www.microsoft.com/downloads/d...lyid=05951071-
6b20-4cef-9939-47c397ffd3dd&displaylang=en

And these are the companion deployment papers, which also explain how to
deploy EAP-TLS:

"Enterprise Deployment of Secure 802.11 Networks Using Microsoft Windows"
at
http://www.microsoft.com/technet/pro...y/ed80211.mspx


"Deployment of IEEE 802.1X for Wired Networks Using Microsoft Windows" at
http://www.microsoft.com/downloads/d...05951071-6b20-
4cef-9939-47c397ffd3dd&DisplayLang=en

--
James McIllece, Microsoft

Please do not send email directly to this alias. This is my online account
name for newsgroup participation only.

This posting is provided "AS IS" with no warranties, and confers no rights.
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
wrt54gl (wired and wireless router) - wired not working Kerry Liles Network Routers 3 11-14-2009 02:43 AM
Best practices NAP / NPS placement with TS Gateway Koen Wijnstok Windows Networking 0 03-04-2009 01:18 PM
Best Practices for Subnetting Irwin Fletcher Windows Networking 10 04-20-2008 05:47 AM
Church Wireless network implementation. jeremyje@gmail.com Wireless Internet 6 02-17-2007 12:20 AM
WAP Best Practices stormrunner Wireless Internet 7 10-02-2005 06:02 PM



1 2 3 4 5 6 7 8 9 10 11