Home > Lesson 3: How to implement secure access
Security School:
EMAIL THIS

Lesson 3: How to implement secure access

26 Jun 2009 | SearchSecurity.com

Network Security Tactics
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Lesson 3: Wireless
Lunchtime Learning

  • VIDEO: SECURING WIRELESS ACCESS
  • TIP: CONTROL WLAN ACCESS ON A BUDGET
  • TIP: CHOOSING A VERSION OF 802.1X PORT ACCESS CONTROL
  • TIP: CONFIGURE VLANs WITH 802.1X FOR WLAN AUTHENTICATION
  • TIP: DEFEATING EVIL TWIN ATTACKS
  • LESSON 3 QUIZ
  • by Lisa Phifer

    In Lesson 3 of Wireless Security Lunchtime Learning, you'll learn the pros and cons of the various wireless access protocols so that you can choose the best method to control, authenticate and authorize access to your WLAN.

    Use the sidebar on your right to navigate to this lesson's video and three companion tips. Also, navigate to the quiz at the end to test what you've learned.

    Also be sure to check out the lower sidebar, which features links to the other lessons in our Wireless Security Lunchtime Learning series.




    Video: Who goes there? Securing wireless access
    Wireless encryption is essential, but addresses only part of the security problem. Security measures are also needed to permit or deny WLAN access, authenticate stations and users, and determine the destinations and applications that each is authorized to reach. This webcast describes readily-available alternatives, from MAC ACLs and captive portals to Preshared Secret Keys and 802.1X Port Access Control.

    Wireless Security
    Lunchtime Learning

  • ENTRANCE EXAM
  • LESSON 1: HOW TO COUNTER WIRELESS THREATS AND VULNERABILITIES
  • LESSON 2: HOW TO BUILD A SECURE WIRELESS INFRASTRUCTURE
  • LESSON 3: HOW TO IMPLEMENT SECURE ACCESS
  • LESSON 4: HOW TO USE WIRELESS IPS
  • FINAL EXAM
  • ABOUT LISA PHIFER
  • Tip: Security on a budget: How to control access to a WLAN
    802.1X/EAP can provide robust, granular WLAN access control and authentication, but can your organization afford the "WPA-Enterprise" approach? This tip recommends alternatives for companies that are concerned about securing WLAN access, yet faced with limited IT staff and budget. Whether the answer is outsource, open source or make the best of "WPA-Personal," this tip will help you understand associated costs and consequences.

    Tip: 802.1X Port Access Control: Which version is best for you?
    802.1X Port Access Control provides an extensible framework for authenticating and authorizing WLAN usage. But 802.1X is merely an envelope that carries some type of Extensible Authentication Protocol (EAP). More than 50 EAP Types have already been defined; how do you know which one(s) to use? This tabular tip provides a direct comparison of the most popular EAP Types used with 802.1X today, the authentication methods supported by each, known vulnerabilities associated with them and suitable usage environments.

    Tip: How to configure VLANs with 802.1X for WLAN authorization
    Many WLAN owners know that 802.1X/EAP makes it possible to authenticate individual wireless users. But did you know that 802.1X can also be used to funnel wireless traffic onto VLANs, enforcing user or group-based permissions? This tip explains how to use RADIUS attributes returned by 802.1X to supply VLAN tags, establishing that critical link between authentication and authorization.

    Tip: Defeating evil twin attacks
    Evil Twin attacks -- also known as AP phishing, honeypot APs or hotspotters -- pose a clear and present danger to wireless users in public and private WLANs. This tip describes several steps that your company can take to defend employees against this poorly-understood attack. Learn why SSL or SSH may not be enough to protect your users, and how 802.1X mutual authentication can help defeat these phony APs.

    Quiz
    Securing wireless acess is no easy business. Find out how much you retained from Lesson 3 of Wireless Lunchtime Learning.

    About Lisa Phifer
    Lisa Phifer
    Lisa Phifer owns Core Competence Inc., a consulting firm specializing in network security and management technology. Lisa has been involved in the design, implementation and evaluation of data communications, internetworking, security and network management products for over 25 years. At Core Competence, she has advised large and small companies regarding security needs, product assessment and the use of emerging technologies and best practices. Before joining Core Competence, Lisa was a Member of Technical Staff at Bell Communications Research where she won a president's award for her work on ATM Network Management.

    Lisa teaches about wireless LANs, mobile security and virtual private networking at many industry conferences and on-line webinars. Lisa's WLAN Advisor and Wireless-To-Go columns are published by SearchNetworking.com and SearchMobileComputing.com where she is a site expert on wireless LANs. She also has written extensively about network infrastructure and security technologies for numerous publications including Wi-Fi Planet, ISP-Planet, Business Communications Review, Information Security and SearchSecurity.com.



    BROWSE BY TAG
    Wireless Network Security: Setup and Tools,   Wireless Network Protocols and Standards,   Enterprise Network Security,   Enterprise Identity and Access Management,   Enterprise User Provisioning Tools,   Identity Management Technology and Strategy,   Wireless LAN Design and Setup,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Wireless Network Protocols and Standards
    Wireless network guidelines for PCI DSS compliance
    Best Wireless Security Products
    MMS messaging spoof hack could have global ramifications
    PCI group releases wireless security guide
    802.1X Port Access Control: Which version is best for you?
    Wireless Security Lunchtime Learning
    An introduction to wireless security
    Lesson 1: How to counter wireless threats and vulnerabilities
    Risky Business: Understanding WiFi threats
    Lesson 1 quiz: Risky business

    Enterprise User Provisioning Tools
    Identity lifecycle management for security and compliance
    Content-aware IAM: Uniting user access and data rights
    Is Identity Management as a Service (IDaaS) a good idea?
    Top tactics for endpoint security
    How to edit group policy objects to give a user local admin rights
    Privileged account management critical to data security
    Making the case for enterprise IAM centralized access control
    Best practices for a privileged access policy to secure user accounts
    Risk management must include physical-logical security convergence
    PCI compliance requirement 7: Restrict access

    Wireless LAN Design and Setup
    Wireless network guidelines for PCI DSS compliance
    Best Wireless Security Products
    How to prevent wireless DoS attacks
    Lesson 4 quiz: How to use wireless IPS
    Wireless intrusion prevention systems: Overlay vs. embedded sensors
    Rogue AP containment methods
    How to monitor WLAN performance with WIPS
    The role of VPN in an enterprise wireless network
    Wireless AP placement basics
    Lesson 3 quiz: Who goes there?
    Wireless LAN Design and Setup Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Wired Equivalent Privacy  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary




    Search Additional Security Research and Solutions
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts