Networking Forums

Networking Forums > Wireless Networking > Wireless Internet > VPN needed if using WPA?

Reply
Thread Tools Display Modes

VPN needed if using WPA?

 
 
Dave S.
Guest
Posts: n/a

 
      01-13-2005, 06:11 PM
Hello All,

I'm in the process of designing a wireless solution using WPA and
RADIUS (actually the MS implementation, IAS) and I've been told that I
should consider VPN as an additional safeguard.

Since WPA protects both the authentication handshake and the
subsequent data transfer, there is no PSK configured on the clients,
and to date (at least to my knowledge) WPA has not been cracked, I
feel that a requirement to have users tunnel through VPN is extraneous
and only adds administrative overhead both in the management of the
VPN concentrator device and the configuration and management of the
client software necessary on the enduser computers.

Am I reasonably on-track with my assessment, or are there WPA
vulnerabilities that I am failing to consider which may warrant the
additional security afforded by a VPN?

Any advice is appreciated!
-Dave

 
Reply With Quote
 
 
 
 
Airhead
Guest
Posts: n/a

 
      01-13-2005, 08:46 PM

"Dave S." <please-(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Hello All,
>
> I'm in the process of designing a wireless solution using WPA and
> RADIUS (actually the MS implementation, IAS) and I've been told that

I
> should consider VPN as an additional safeguard.
>
> Since WPA protects both the authentication handshake and the
> subsequent data transfer, there is no PSK configured on the clients,
> and to date (at least to my knowledge) WPA has not been cracked, I
> feel that a requirement to have users tunnel through VPN is

extraneous
> and only adds administrative overhead both in the management of the
> VPN concentrator device and the configuration and management of the
> client software necessary on the enduser computers.
>
> Am I reasonably on-track with my assessment, or are there WPA
> vulnerabilities that I am failing to consider which may warrant the
> additional security afforded by a VPN?
>
> Any advice is appreciated!
> -Dave


I think the key is using a strong authentication method. Using 802.1x
with
EAP and a STRONG authentication protocol such as EAP-PEAP or EAP-TLS
or Funks EAP-TTLS. The user credentials are tunneled making it near
impossible
to collect user information. This combined with Dynamic Key Rotation
and AES
make for a very good security solution. I think VPNs have their place,
but not
necessarily in wireless. There are those that will disagree, but they
have probably
not yet become familiar enough with 802.11.i to feel comfortable. You
have to
realize, that wireless is greek to most network administrators,
therefore
sticking with wired ways gives them a warmer fuzzy feeling.

 
Reply With Quote
 
Airhead
Guest
Posts: n/a

 
      01-16-2005, 08:14 PM


--
> Hello All,
>
> I'm in the process of designing a wireless solution using WPA and
> RADIUS (actually the MS implementation, IAS) and I've been told that

I
> should consider VPN as an additional safeguard.
>
> Since WPA protects both the authentication handshake and the
> subsequent data transfer, there is no PSK configured on the clients,
> and to date (at least to my knowledge) WPA has not been cracked, I
> feel that a requirement to have users tunnel through VPN is

extraneous
> and only adds administrative overhead both in the management of the
> VPN concentrator device and the configuration and management of the
> client software necessary on the enduser computers.
>
> Am I reasonably on-track with my assessment, or are there WPA
> vulnerabilities that I am failing to consider which may warrant the
> additional security afforded by a VPN?
>
> Any advice is appreciated!
> -Dave


An article about using a VPN with PPTP vulnerability.
http://blogs.zdnet.com/Ou/index.php?p=21

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Simple mail "server" program needed - advice needed please Andrew Sayers Home Networking 12 08-24-2006 04:03 PM
ISP needed Tony Broadband 6 05-04-2004 09:53 AM
a little help needed beef & onion crisps Home Networking 0 12-12-2003 12:34 PM
HELP NEEDED!! Do I have a router that needs taken back. Please. Any information is much needed. newbie Windows Networking 0 09-28-2003 04:53 PM
Help needed Richard Baker Broadband 1 08-05-2003 11:45 AM



1 2 3 4 5 6 7 8 9 10 11