Follow Us

How to secure unmanaged WiFi clients

Make sure they stick to your policy!

Industry endpoint security initiatives such as Cisco Network Admission Control and Microsoft Network Access Protection are helping enterprises keep the client devices that they provision and manage free of infection before they access the corporate network.

But what about mobile endpoints that are unmanaged? By "unmanaged," I mean devices that might need temporary access to your network, such as those that belong to a contractor, consultant or supplier, and are not provisioned and managed by your IT organisation.

One approach
Aruba Wireless Networks recently announced its approach to balancing the security and access issues surrounding foreign clients. Other Wi-Fi systems vendors, too, are at least thinking about endpoint security. After all, a wireless access point or wireless LAN switch might be the very first point of corporate network contact for a mobile device that has been exposed to Internet infections before attempting to reconnect.

In November 2004, Aruba said it was teaming with security companies Sygate and Fortinet to integrate the stateful firewall in Aruba's WLAN switch/controller with the other companies' client software and firewall technologies, respectively. In June, the fruit of the Sygate partnership emerged in the form of Client Integrity Module software for Aruba appliances.

With it, Aruba appliances can determine if the client attempting to connect is an unmanaged device. If it is, it will download to the client a Java applet that performs a host integrity check for up-to-date anti-virus software, personal firewalls, software patches and updates - whatever your security policy dictates. Similarly, policy will determine whether the state of the device means it is kept off the network, allowed on, quarantined, remediated for limited access, or redirected and brought into compliance.

While a WiFi device is not in compliance, it is also blocked from communicating with other Wi-Fi clients in peer-to-peer fashion, notes Jon Green, Aruba product manager.

Perhaps most interesting is the virtual desktop feature. Since most people don't really care for IT departments in other companies fooling with the software on their own PCs, the virtual desktop leaves everything already on the PC alone and creates a policy-compliant, encrypted virtual session for temporary use that users can erase after the fact or retain for future use when they return, Green explains.

What are other WiFi vendors doing?
Competitor Trapeze Networks deals separately with managed devices and guest devices. For managed devices, an 802.1X-based feature called Bonded Auth, which works in Windows, authenticates both the user and the machine, so a trusted user cannot attach to the network using an untrusted device. For temporary users, Trapeze offers a feature called GuestPass, a guest provisioning application that places guest traffic on a separate VLAN and gives them Internet access only.

Symbol Technologies says that WiFi endpoint security "is on its roadmap," and Meru Networks says it is pursuing a "best of breed partnership approach" to meet customer WLAN edge security requirements. In March 2004, Meru announced a partnership with iPolicy, a maker of intrusion prevention firewalls, to integrate iPolicy security capabilities into its controllers, but we haven't heard any further developments on that relationship (or on the Aruba-Fortinet relationship, for that matter).






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Desktop modernisation

On the one hand, there is the need to keep the existing desktop environment efficient, secure...

Download Whitepaper

Top 10 myths about virtualising business-critical applications

Even though virtualization has brought positive change to enterprise IT over the last decade,...

Download Whitepaper

Aligning CFO and CIO priorities

Forward-thinking organisations are viewing cloud computing as an investment in business...

Download Whitepaper

The new corporate network

Businesses can’t afford to have employee productivity suffer because they cannot use their...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards 2012
Coming Soon

Opening for submissions May 2012

 

Find out more

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...
LogMeIn Rescue

Accelerate Your IT Efficiency

View the latest capacity management resources including whitepapers, videos and news.

Find out more...

Site Map

* *