What's considered the most secure enterprise wireless?

cpals

Diamond Member
Mar 5, 2001
4,494
0
76
We are in the process of implementing a new wireless vendor and are open to suggestions to change our current security, if it isn't the best. Unfortunately, he's more here to implement what we tell him and not giving much direction.

We currently are doing WPA w/TKIP and radius/certificate authentication. I'm not much of a wireless person and inherited this design.

We are also trying to implement a sort of byod wireless and also a guest network that has a portal so an employee can 'approve' the guest on our network first.

So is our current setup good or is there a more secure way of doing it?

Thanks!
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
Holy mackeral this topic could go a million ways. WPA2-AES enterprise is more than secure enough.

The trend today is having a single SSID that also does self provisioning of BYOD devices through a registration portal, pushing down VLAN memberships and access control lists. That's kinda advanced and it's easier to just have a corporate secure SSID and a guest/provisioning SSID that is wide open but only allowed to communicat with provisioning and guest control systems.

Ditch TKIP as modern radios need AES for throughput in hardware.
 

RadiclDreamer

Diamond Member
Aug 8, 2004
8,622
40
91
The more secure the more of a pain it becomes. I would say WPA2-AES ENT with cert and mac filtering would be pretty darned secure, but not really worth it IMO since WPA2-AES ENT is good enough for most.
 

Ayah

Platinum Member
Jan 1, 2006
2,512
1
81
The more secure the more of a pain it becomes. I would say WPA2-AES ENT with cert and mac filtering would be pretty darned secure, but not really worth it IMO since WPA2-AES ENT is good enough for most.

agreed. the question becomes, exactly how secure do you need it to be? it becomes exponentially more of a PITA the more secure you make it.
 

Emulex

Diamond Member
Jan 28, 2001
9,759
1
71
you need to use radius and 2-factor authentication.

but really that's all pointless if the client is not 1000% secure aka byod.
 

dawks

Diamond Member
Oct 9, 1999
5,071
2
81
Ditch TKIP as modern radios need AES for throughput in hardware.

TKIP also has a few small vulnerabilities, nothing major (not completely broken), but just another reason to move to AES.

As far as I know, if the hardware is setup to use RADIUS with something liek Server 2008 R2, as long as its implemented properly with the correct settings, the hardware doesn't matter much. Our larger affiliate organization requires we use cisco exclusively for wireless if we want to communicate with their network which is frustrating because we could implement a much better network (for our purposes) for 1/10th the cost with commodity hardware, and the same Server 2008 R2 RADIUS backend.


agreed. the question becomes, exactly how secure do you need it to be? it becomes exponentially more of a PITA the more secure you make it.

There's always a trade-off between security and convenience
The question is, how far do you want to push it.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |