Follow Us

Keep your users secure on public-access Wi-Fi

Do VPNs and look for hotspots with multiple SSIDs.

Q: What is the best approach to securing public access Wi-Fi? And what is needed to accomplish this? - D.J., Chicago

The Wizards (top staff from wireless network vendors) have pondered your question and reply:

T.K. "Ranga" Rengarajan, Pronto Networks
Use HTTPS/SSL for initial communication at a hot spot (eg, for authentication, entering credit card information, etc). Practically all hot spot solutions have this capability built-in. After that, use a VPN between the client and the secured site, such as a corporate LAN. Microsoft Windows 2000 and XP come with a built-in VPN client, thus a user has all he/she needs for secure connectivity to e-mail and other sensitive information on a corporate LAN. Granted, regular HTTP traffic is not encrypted but most users are less concerned about others sniffing this type of traffic as this information is generally not confidential.

Dan Simone, Trapeze Networks
If your employees will be using Wi-Fi in public access locations, make sure the client devices are configured to support personal firewalls and that users are trained to launch a VPN to access corporate resources. Also, make sure your employees’ laptops are configured with automatically updated virus protection software.

To provide your own guest access securely, make sure the WLAN you select supports your own employees on their typical private groups but enables support for a new “guest” group, on an encrypted SSID, that gains access to the network that is outside your corporate firewall.

Marcel Wiget, Chantry Networks
Today, most public access Wi-Fi hot spots are using secure captive portals to authenticate users. There are multiple potential problems with this solution: no wireless encryption is used and hence unencrypted user traffic can be captured and analysed by anyone close by. Even worse, a potential hacker can learn the MAC and IP address from a validated wireless user and take over his session by modifying his own client card with the stolen information and get a “free ride.”

The obvious solution is to use wireless per session encryption as provided by WPA (802.1x with TKIP). Unfortunately, this requires up-to-date drivers and software on the client side, which most likely customers won't necessarily have immediately. The good news is that more wireless solutions offer multi-SSID support, allowing the advanced user to select the security access that best suits their requirement and hardware capabilities.

So for legacy clients, the standard captive portal secured access without encryption is provided on one SSID and 802.1x with PEAP and TTLS support on another SSID (allowing username and password authentication). 802.1x with either dynamic WEP or TKIP will guarantee privacy by session and packet based dynamic encryption.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Desktop modernisation

On the one hand, there is the need to keep the existing desktop environment efficient, secure...

Download Whitepaper

Top 10 myths about virtualising business-critical applications

Even though virtualization has brought positive change to enterprise IT over the last decade,...

Download Whitepaper

Aligning CFO and CIO priorities

Forward-thinking organisations are viewing cloud computing as an investment in business...

Download Whitepaper

The new corporate network

Businesses can’t afford to have employee productivity suffer because they cannot use their...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards 2012
Coming Soon

Opening for submissions 30th April 2012

 

Find out more

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...
LogMeIn Rescue

Accelerate Your IT Efficiency

View the latest capacity management resources including whitepapers, videos and news.

Find out more...

Site Map

* *