Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
FBI warns of holiday cyber scams
U.S. Open used Web filtering to prevent online gambling
Google Earth used by terrorists in India attacks
Mumbai terrorist attacks don't deter technology companies
Google layoffs: 10,000 jobs being cut, report claims
Experts to Feds: Sign the DNS root ASAP
Cisco shutting down between holidays
Sprint completes Clearwire WiMAX deal
Mobile sales to beat economic gloom, forecasts Ovum
Start-ups starting to feel economic pain
Spam levels fluctuate as crooks try to revive botnets
Mozilla eyes extra beta for Firefox 3.1
Grim forecast for holiday e-commerce sales
Talking Web, memory assistants and solar-powered cell phones headed mainstream, IBM says
Massive botnet returns from the dead, starts spamming


Wireless/Mobile /
Send to a friend Feedback

Strategy: Wireless security with 802.1X

Related linksToday's breaking news
Send to a friendFeedback


Network professionals in search of technology that melds authentication, encryption and wireless LANs will find the IEEE 802.1X specification is up to the job.

As a Layer 2 authentication protocol, 802.1X doesn't let anyone on the network until they've been properly authenticated. With built-in hooks for setting wireless encryption keys, 802.1X also solves the worst problems of wired equivalent privacy (WEP): avoiding well-known, widely distributed keys. The only problem with 802.1X is that it is an emerging technology that requires upgrades to authentication servers, client software on all PCs, and appropriate configuration in the wireless access points.

New products supporting 802.1X have popped up rapidly, and iLabs comprises the largest-ever public demonstration of 802.1X. Since the last round of iLabs testing in May, the team has added a new authentication server (Aegis, from Meetinghouse Data Communications), a Mac OS X 802.1X client (also from Meetinghouse), and prototype Protected Extensible Authentication Protocol (PEAP) support in Windows XP client and Cisco's ACS authentication server, to its secure wireless deployment.

Advertisement:

PEAP and Tunneled Transport Layer Security (TTLS) are two proposals that add support for legacy authentication mechanisms like username/password and token cards to the 802.1X spec. However, neither has reached standards status. The Internet Engineering Task Force (IETF) requires that any standardized protocol be proven to work, and having multiple interoperable implementations is a critical step along that path. TTLS offers support for a wider range of legacy authentication methods and was implemented first, so it should win favor among network managers. However, RSA Security, Microsoft and Cisco proposed PEAP. While company affiliation isn't supposed to be important within the IETF process, proposals brought in by these networking powerhouses are generally taken very seriously.

We tested different authentication methods to see how well we could mix and match products in the iLabs network. MD5, the simplest authentication method in the 802.1X world, worked pretty well. Some wireless access points, such as those produced by Symbol, don't support MD5. This is actually a good thing - MD5 is not appropriate for wireless 802.1X authentication, because it does not set up WEP keys.

When we moved onto TLS using digital certificates, the only authentication server that had trouble supporting this method was Microsoft.

We tried to use TLS authentication with a beta version of .Net Server. We found it easy to set up the .Net 802.1X authentication server, but for MD5 authentication only. When we tried to move to TLS authentication, using digital certificates, the .Net Server would not recognize our Netscape certificate authority. Microsoft assumes a total Microsoft implementation, using multiple servers, Active Directory and the Microsoft certificate authority, which wasn't the interoperability demonstration we sought.

Despite the .Net Server setback, we concentrated our testing on the 802.1X servers, adding two new products (from Cisco and Meetinghouse) to the list and retesting servers from Funk Software, Hewlett-Packard, Microsoft and Secure Computing.

The results are encouraging. Although we are dealing with new products and beta code, we've worked with the vendor development teams to get things to work. For example, Wind River, the OEM behind many popular access points, debugged and modified its software to pass PEAP properly after discovering an incompatibility during PEAP testing.

More N+I Atlanta 2002 iLabs coverage

Related Links

802.1X provides user authentication
Most end users connect to enterprise networks via a Category 5 wire to an Ethernet switch, but access via 802.11 wireless access points seems poised for rapid growth. Network World, 03/25/02.

802.11 insecurity
Security is still the main problem holding back deployment of all 802.11 products. Network World, 05/20/02.

Down and dirty with Wireless LAN security
The iLabs team puts 802.1X standard to the interoperability test. Network World, 05/06/02.

\

Apply for your free subscription to Network World. Click here. Or get Network World delivered in PDF each week.

Get Copyright Clearance
Request a reprint or permission to use this article.


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.