Networking Forums

Networking Forums > Computer Networking > Windows Networking > Choosing which way to secure WLANs (IAS, WPA and certs or passwd)

Reply
Thread Tools Display Modes

Choosing which way to secure WLANs (IAS, WPA and certs or passwd)

 
 
Heath
Guest
Posts: n/a

 
      07-11-2007, 04:24 PM
I have been looking into setting up a wireless LAN and I am debating between
using certificates or not. I read the documents on Securing Wireless using
certs and Securing using PEAP and passwords. The one using PEAP and passwords
seems to be less complicated but I wondering how much less secure it is.

Lets say I set up the following: RADIUS server (IAS), Microsoft root CA
(Windows 2003), Wireless Access Points (Proxim), Windows XP clients, WPA
encryption, settings using group policy. Also, in IAS, I create a group with
the users and computers that can use wireless.

How will the computer authentication work? What does it check for exactly?
At what point does it get an IP address? What is the risk of being hacked
compared to installing certificates on the client PC's?
 
Reply With Quote
 
 
 
 
Pieman
Guest
Posts: n/a

 
      07-12-2007, 01:16 PM
Health

certificates are a lot more secure than password strings. The use of
certificates demands a PKI infrastructure whether this be an internal MS
windows CA or a third party CA (i.e. Thwart, Veri-Sign, etc).

The idea behind certificates is that client A trusts client B certificate
and vice versa, so in your case computer certificates would be deployed
across the LAN for the clients and servers, when the client boots and
attempts to connect to the WLAN the request for the computer account to be
authenticated to the LAN is passed via IAS, as long as the computer account
is a member of the allowed group and the computer certificate is valid then
the computer would be allowed to authenticated and logon to the wireless
LAN, after this the client would then receive the Ctrl + Alt + Del screen
allowing the "user" to enter logon credentials to login to the PC and access
resources that they have been granted permissions to.

"Heath" <(E-Mail Removed)> wrote in message
news:ECB91673-D85F-42BB-A7A9-(E-Mail Removed)...
>I have been looking into setting up a wireless LAN and I am debating
>between
> using certificates or not. I read the documents on Securing Wireless using
> certs and Securing using PEAP and passwords. The one using PEAP and
> passwords
> seems to be less complicated but I wondering how much less secure it is.
>
> Lets say I set up the following: RADIUS server (IAS), Microsoft root CA
> (Windows 2003), Wireless Access Points (Proxim), Windows XP clients, WPA
> encryption, settings using group policy. Also, in IAS, I create a group
> with
> the users and computers that can use wireless.
>
> How will the computer authentication work? What does it check for exactly?
> At what point does it get an IP address? What is the risk of being hacked
> compared to installing certificates on the client PC's?



 
Reply With Quote
 
Robert L [MVP - Networking]
Guest
Posts: n/a

 
      07-12-2007, 04:52 PM
Agree. That is what we are using.

Bob Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
"Pieman" <bullens_at_no_spam_nifcoeu.com> wrote in message news:(E-Mail Removed)...
Health

certificates are a lot more secure than password strings. The use of
certificates demands a PKI infrastructure whether this be an internal MS
windows CA or a third party CA (i.e. Thwart, Veri-Sign, etc).

The idea behind certificates is that client A trusts client B certificate
and vice versa, so in your case computer certificates would be deployed
across the LAN for the clients and servers, when the client boots and
attempts to connect to the WLAN the request for the computer account to be
authenticated to the LAN is passed via IAS, as long as the computer account
is a member of the allowed group and the computer certificate is valid then
the computer would be allowed to authenticated and logon to the wireless
LAN, after this the client would then receive the Ctrl + Alt + Del screen
allowing the "user" to enter logon credentials to login to the PC and access
resources that they have been granted permissions to.

"Heath" <(E-Mail Removed)> wrote in message
news:ECB91673-D85F-42BB-A7A9-(E-Mail Removed)...
>I have been looking into setting up a wireless LAN and I am debating
>between
> using certificates or not. I read the documents on Securing Wireless using
> certs and Securing using PEAP and passwords. The one using PEAP and
> passwords
> seems to be less complicated but I wondering how much less secure it is.
>
> Lets say I set up the following: RADIUS server (IAS), Microsoft root CA
> (Windows 2003), Wireless Access Points (Proxim), Windows XP clients, WPA
> encryption, settings using group policy. Also, in IAS, I create a group
> with
> the users and computers that can use wireless.
>
> How will the computer authentication work? What does it check for exactly?
> At what point does it get an IP address? What is the risk of being hacked
> compared to installing certificates on the client PC's?



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
VPN and WLANs wlaoye Wireless Internet 1 05-01-2007 03:09 AM
IAS fails with certs from Stand Alone CA Harrison Midkiff Wireless Networks 2 07-22-2004 09:45 PM
detect wlans Christian Christmann Linux Networking 1 07-08-2004 09:29 AM
2 WLANs, VPN routing? Is it possible? Martin Schaffoener Linux Networking 5 04-23-2004 09:50 AM
Illegal WLANs Rob Wireless Internet 18 10-31-2003 10:09 AM



1 2 3 4 5 6 7 8 9 10 11