SlideShare a Scribd company logo
1 of 7
Security Policy
Security Policy
       Authentication and Encryption
    ◦    IEEE 802.11i
    ◦    WPA2-Enterprise 802.1x RADIUS authentication
         with EAP-TLS.
    ◦    AES 128-bit encryption.
    ◦    Broadcast SSIDs, up to eight per radio, each with
         unique security controls (guest VLAN, 802.1Q,
         802.11e, employee network).

       Access Point and RF Management
    ◦ Plenum-rated AP’s, ceiling-mounted.
    ◦ Limit RF power levels to coverage area.
Guest VLAN
                                                      Database




          802.1Q                 L3 Switch
          tagging                                     RADIUS




                                    PoE
  Guest
                    Guest SSID               802.1x
Traffic Prioritizing
                High
                Priority


                                      802.1p



                                                     L3 Switch   AP Controller
  Voice/Video                                                           Supports
                   802.11e                                              802.11e



                                                       PoE

                                           802.1Q
FTP/Applications                           tagging
                           Low                                      Database
                           Priority
VPN Access


                              RADIUS
               ISP
                     802.1x

 VPN Tunnel



                               SSL VPN
                                         Corporate
       Mobile                            Network
       Broadband
Network Management

                                            Admin
                          802.1x               1000BASE-T
            RADIUS
                                               Port-based VLAN



       AP Controller               L3 Switch
                  Management
                  VLAN
HTTPS Web GUI                                         HTTPS Web GUI
management, SSH                                       management, SSH
telnet, SNMP.                                         telnet, SNMP.

                                      PoE
References
How to configure VLANs with 802.1X for WLAN authorization. (2009, June). TechTarget.
Retrieved from http://searchsecurity.techtarget.com/feature/How-to-configure-VLANs-with-8021X-for-WLAN-
authorization

Javvin Company. (n.d.). IEEE 802.1p: LAN Layer 2 QoS/CoS Protocol for Traffic Prioritization. Retrieved
from http://www.javvin.com/protocol8021P.html

Netgear. (2009). WNDAP350 User Manual. Retrieved from http://support.netgear
.com/app/products/model/a_id/12823

Netgear. (2010). ProSafe Quad WAN Gigabit SSL VPN Firewall SRX5308. Retrieved from
http://ftp://downloads.netgear.com/files/SRX5308_DS_12Mar10.pdf

Netgear. (2012). ProSafe 24-Port 10/100/1000 Smart PoE Switch GS724TP. Retrieved from http://www.
netgear.com/business/products/switches/smart-switches/gs724tp.aspx

Netgear. (2012). ProSafe 48-Port Gigabit L3 Managed Stackable Switch GSM7352S-200. Retrieved from
http://www.netgear.com/service-provider/products/switches/fully-managed-
switches/gsm7352s-200.aspx#two

Netgear. (2012). ProSafe 20-AP Wireless Controller WC7520. Retrieved from
http://www.netgear.com/business/products/access-points-wireless-controllers/wireless-
management/WC7520.aspx#two

More Related Content

What's hot

Aerohive-HiveAP300
Aerohive-HiveAP300Aerohive-HiveAP300
Aerohive-HiveAP300ppuichaud
 
Deploying the Cisco Mobility Services Engine for Advanced Wireless Services
Deploying the Cisco Mobility Services Engine for Advanced Wireless ServicesDeploying the Cisco Mobility Services Engine for Advanced Wireless Services
Deploying the Cisco Mobility Services Engine for Advanced Wireless ServicesCisco Mobility
 
New cisco aironet 1850 series access points focus on wave 2 wifi
New cisco aironet 1850 series access points focus on wave 2 wifiNew cisco aironet 1850 series access points focus on wave 2 wifi
New cisco aironet 1850 series access points focus on wave 2 wifiIT Tech
 
[Cisco Connect 2018 - Vietnam] Shamil fernando hcmc next-gen cisco sd-wan (vi...
[Cisco Connect 2018 - Vietnam] Shamil fernando hcmc next-gen cisco sd-wan (vi...[Cisco Connect 2018 - Vietnam] Shamil fernando hcmc next-gen cisco sd-wan (vi...
[Cisco Connect 2018 - Vietnam] Shamil fernando hcmc next-gen cisco sd-wan (vi...Nur Shiqim Chok
 
Anuta Networks at Networking Field Day 14
Anuta  Networks at Networking Field Day 14Anuta  Networks at Networking Field Day 14
Anuta Networks at Networking Field Day 14Kiran Sirupa
 
ALOHA Load Balancer - Rackable Appliance
ALOHA Load Balancer - Rackable ApplianceALOHA Load Balancer - Rackable Appliance
ALOHA Load Balancer - Rackable ApplianceEXCELIANCE
 
Secure collab on prem hikmat
Secure collab on prem   hikmatSecure collab on prem   hikmat
Secure collab on prem hikmatCisco Canada
 
Innovations in Mobility
Innovations in MobilityInnovations in Mobility
Innovations in MobilityCisco Canada
 
Overview on cisco catalyst 3750 switches,features, technology, intelligent sw...
Overview on cisco catalyst 3750 switches,features, technology, intelligent sw...Overview on cisco catalyst 3750 switches,features, technology, intelligent sw...
Overview on cisco catalyst 3750 switches,features, technology, intelligent sw...IT Tech
 
Cisco catalyst 2960 series switches overview
Cisco catalyst 2960 series switches overviewCisco catalyst 2960 series switches overview
Cisco catalyst 2960 series switches overview3Anetwork com
 
Intel Network Builders Summit: Key Lessons from an advanced multi-vendor NFV ...
Intel Network Builders Summit: Key Lessons from an advanced multi-vendor NFV ...Intel Network Builders Summit: Key Lessons from an advanced multi-vendor NFV ...
Intel Network Builders Summit: Key Lessons from an advanced multi-vendor NFV ...Kiran Sirupa
 
E zcall ge telligence sql interface sales doc
E zcall ge telligence sql interface sales docE zcall ge telligence sql interface sales doc
E zcall ge telligence sql interface sales docQBsoft Solutions
 

What's hot (20)

Aerohive-HiveAP300
Aerohive-HiveAP300Aerohive-HiveAP300
Aerohive-HiveAP300
 
ICC icXchange Solution Brochure
ICC icXchange Solution BrochureICC icXchange Solution Brochure
ICC icXchange Solution Brochure
 
Deploying the Cisco Mobility Services Engine for Advanced Wireless Services
Deploying the Cisco Mobility Services Engine for Advanced Wireless ServicesDeploying the Cisco Mobility Services Engine for Advanced Wireless Services
Deploying the Cisco Mobility Services Engine for Advanced Wireless Services
 
New cisco aironet 1850 series access points focus on wave 2 wifi
New cisco aironet 1850 series access points focus on wave 2 wifiNew cisco aironet 1850 series access points focus on wave 2 wifi
New cisco aironet 1850 series access points focus on wave 2 wifi
 
Wi Max Updated
Wi Max UpdatedWi Max Updated
Wi Max Updated
 
[Cisco Connect 2018 - Vietnam] Shamil fernando hcmc next-gen cisco sd-wan (vi...
[Cisco Connect 2018 - Vietnam] Shamil fernando hcmc next-gen cisco sd-wan (vi...[Cisco Connect 2018 - Vietnam] Shamil fernando hcmc next-gen cisco sd-wan (vi...
[Cisco Connect 2018 - Vietnam] Shamil fernando hcmc next-gen cisco sd-wan (vi...
 
Anuta Networks at Networking Field Day 14
Anuta  Networks at Networking Field Day 14Anuta  Networks at Networking Field Day 14
Anuta Networks at Networking Field Day 14
 
ALOHA Load Balancer - Rackable Appliance
ALOHA Load Balancer - Rackable ApplianceALOHA Load Balancer - Rackable Appliance
ALOHA Load Balancer - Rackable Appliance
 
Aerohive SR2024 Switch
Aerohive SR2024 SwitchAerohive SR2024 Switch
Aerohive SR2024 Switch
 
Aerohive AP 170
Aerohive AP 170Aerohive AP 170
Aerohive AP 170
 
Secure collab on prem hikmat
Secure collab on prem   hikmatSecure collab on prem   hikmat
Secure collab on prem hikmat
 
Innovations in Mobility
Innovations in MobilityInnovations in Mobility
Innovations in Mobility
 
Overview on cisco catalyst 3750 switches,features, technology, intelligent sw...
Overview on cisco catalyst 3750 switches,features, technology, intelligent sw...Overview on cisco catalyst 3750 switches,features, technology, intelligent sw...
Overview on cisco catalyst 3750 switches,features, technology, intelligent sw...
 
Aerohive SR2024P Switch
Aerohive SR2024P SwitchAerohive SR2024P Switch
Aerohive SR2024P Switch
 
Cisco catalyst 2960 series switches overview
Cisco catalyst 2960 series switches overviewCisco catalyst 2960 series switches overview
Cisco catalyst 2960 series switches overview
 
Intel Network Builders Summit: Key Lessons from an advanced multi-vendor NFV ...
Intel Network Builders Summit: Key Lessons from an advanced multi-vendor NFV ...Intel Network Builders Summit: Key Lessons from an advanced multi-vendor NFV ...
Intel Network Builders Summit: Key Lessons from an advanced multi-vendor NFV ...
 
E zcall ge telligence sql interface sales doc
E zcall ge telligence sql interface sales docE zcall ge telligence sql interface sales doc
E zcall ge telligence sql interface sales doc
 
TeraVM_overview
TeraVM_overviewTeraVM_overview
TeraVM_overview
 
Aw aerohive ap 330
Aw aerohive ap 330Aw aerohive ap 330
Aw aerohive ap 330
 
Secure Your Network for Scale & the Cloud
Secure Your Network for Scale & the CloudSecure Your Network for Scale & the Cloud
Secure Your Network for Scale & the Cloud
 

Similar to Wireless Security Policy

tplink manual best
tplink manual best tplink manual best
tplink manual best bhandaridaka
 
Indian railways presentation
Indian railways presentationIndian railways presentation
Indian railways presentationgps2012
 
Cisco aironet 1140 access point overview
Cisco aironet 1140 access point overviewCisco aironet 1140 access point overview
Cisco aironet 1140 access point overviewIT Tech
 
Handlink ISS-7000 Datasheet
Handlink ISS-7000 Datasheet Handlink ISS-7000 Datasheet
Handlink ISS-7000 Datasheet ITWare
 
Aerohive AP330 802.11n Wireless Access Point
Aerohive AP330 802.11n Wireless Access PointAerohive AP330 802.11n Wireless Access Point
Aerohive AP330 802.11n Wireless Access PointAerohive Networks
 
Radiojungle AAA RADIUS introduction
Radiojungle AAA RADIUS introductionRadiojungle AAA RADIUS introduction
Radiojungle AAA RADIUS introductionsmoscato
 
Cisco Small Business Wireless Portfolio
Cisco Small Business Wireless PortfolioCisco Small Business Wireless Portfolio
Cisco Small Business Wireless PortfolioWaker Jiang
 
Cisco Small Business Wireless Portfolio
Cisco Small Business Wireless PortfolioCisco Small Business Wireless Portfolio
Cisco Small Business Wireless Portfoliosz0755520
 
Aerohive AP350 802.11n Wireless Access Point
Aerohive AP350 802.11n Wireless Access PointAerohive AP350 802.11n Wireless Access Point
Aerohive AP350 802.11n Wireless Access PointAerohive Networks
 
EnGenius Europe Sales presentation EAP600
EnGenius Europe Sales presentation EAP600EnGenius Europe Sales presentation EAP600
EnGenius Europe Sales presentation EAP600EnGenius Europe
 
Aerohive AP110 802.11n Wireless Access Point
Aerohive AP110 802.11n Wireless Access PointAerohive AP110 802.11n Wireless Access Point
Aerohive AP110 802.11n Wireless Access PointAerohive Networks
 
Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)
Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)
Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)Ari Zoldan
 
Cisco rv110 w wireless n vpn firewall
Cisco rv110 w wireless n vpn firewallCisco rv110 w wireless n vpn firewall
Cisco rv110 w wireless n vpn firewallIT Tech
 
Nexaira Nexconnect Router Product Brochure (quantum-wireless.com)
Nexaira Nexconnect Router Product Brochure (quantum-wireless.com)Nexaira Nexconnect Router Product Brochure (quantum-wireless.com)
Nexaira Nexconnect Router Product Brochure (quantum-wireless.com)Ari Zoldan
 
14.) wireless (hyper dense wi fi)
14.) wireless (hyper dense wi fi)14.) wireless (hyper dense wi fi)
14.) wireless (hyper dense wi fi)Jeff Green
 

Similar to Wireless Security Policy (20)

tplink manual best
tplink manual best tplink manual best
tplink manual best
 
Indian railways presentation
Indian railways presentationIndian railways presentation
Indian railways presentation
 
Cisco aironet 1140 access point overview
Cisco aironet 1140 access point overviewCisco aironet 1140 access point overview
Cisco aironet 1140 access point overview
 
Handlink ISS-7000 Datasheet
Handlink ISS-7000 Datasheet Handlink ISS-7000 Datasheet
Handlink ISS-7000 Datasheet
 
Aerohive AP330 802.11n Wireless Access Point
Aerohive AP330 802.11n Wireless Access PointAerohive AP330 802.11n Wireless Access Point
Aerohive AP330 802.11n Wireless Access Point
 
Radiojungle AAA RADIUS introduction
Radiojungle AAA RADIUS introductionRadiojungle AAA RADIUS introduction
Radiojungle AAA RADIUS introduction
 
Cisco Small Business Wireless Portfolio
Cisco Small Business Wireless PortfolioCisco Small Business Wireless Portfolio
Cisco Small Business Wireless Portfolio
 
Cisco Small Business Wireless Portfolio
Cisco Small Business Wireless PortfolioCisco Small Business Wireless Portfolio
Cisco Small Business Wireless Portfolio
 
Aerohive AP350 802.11n Wireless Access Point
Aerohive AP350 802.11n Wireless Access PointAerohive AP350 802.11n Wireless Access Point
Aerohive AP350 802.11n Wireless Access Point
 
EnGenius Europe Sales presentation EAP600
EnGenius Europe Sales presentation EAP600EnGenius Europe Sales presentation EAP600
EnGenius Europe Sales presentation EAP600
 
Aerohive AP110 802.11n Wireless Access Point
Aerohive AP110 802.11n Wireless Access PointAerohive AP110 802.11n Wireless Access Point
Aerohive AP110 802.11n Wireless Access Point
 
Aerohive AP 330
Aerohive AP 330Aerohive AP 330
Aerohive AP 330
 
Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)
Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)
Top Global 3G Phoebus Wireless Router (MB6000) (Quantum-Wireless.com)
 
Cisco rv110 w wireless n vpn firewall
Cisco rv110 w wireless n vpn firewallCisco rv110 w wireless n vpn firewall
Cisco rv110 w wireless n vpn firewall
 
Ap300 spec sheet
Ap300 spec sheetAp300 spec sheet
Ap300 spec sheet
 
Ap300 spec sheet
Ap300 spec sheetAp300 spec sheet
Ap300 spec sheet
 
802 standerd
802 standerd802 standerd
802 standerd
 
Aerohive AP 350
Aerohive AP 350Aerohive AP 350
Aerohive AP 350
 
Nexaira Nexconnect Router Product Brochure (quantum-wireless.com)
Nexaira Nexconnect Router Product Brochure (quantum-wireless.com)Nexaira Nexconnect Router Product Brochure (quantum-wireless.com)
Nexaira Nexconnect Router Product Brochure (quantum-wireless.com)
 
14.) wireless (hyper dense wi fi)
14.) wireless (hyper dense wi fi)14.) wireless (hyper dense wi fi)
14.) wireless (hyper dense wi fi)
 

Wireless Security Policy

  • 2. Security Policy  Authentication and Encryption ◦ IEEE 802.11i ◦ WPA2-Enterprise 802.1x RADIUS authentication with EAP-TLS. ◦ AES 128-bit encryption. ◦ Broadcast SSIDs, up to eight per radio, each with unique security controls (guest VLAN, 802.1Q, 802.11e, employee network).  Access Point and RF Management ◦ Plenum-rated AP’s, ceiling-mounted. ◦ Limit RF power levels to coverage area.
  • 3. Guest VLAN Database 802.1Q L3 Switch tagging RADIUS PoE Guest Guest SSID 802.1x
  • 4. Traffic Prioritizing High Priority 802.1p L3 Switch AP Controller Voice/Video Supports 802.11e 802.11e PoE 802.1Q FTP/Applications tagging Low Database Priority
  • 5. VPN Access RADIUS ISP 802.1x VPN Tunnel SSL VPN Corporate Mobile Network Broadband
  • 6. Network Management Admin 802.1x 1000BASE-T RADIUS Port-based VLAN AP Controller L3 Switch Management VLAN HTTPS Web GUI HTTPS Web GUI management, SSH management, SSH telnet, SNMP. telnet, SNMP. PoE
  • 7. References How to configure VLANs with 802.1X for WLAN authorization. (2009, June). TechTarget. Retrieved from http://searchsecurity.techtarget.com/feature/How-to-configure-VLANs-with-8021X-for-WLAN- authorization Javvin Company. (n.d.). IEEE 802.1p: LAN Layer 2 QoS/CoS Protocol for Traffic Prioritization. Retrieved from http://www.javvin.com/protocol8021P.html Netgear. (2009). WNDAP350 User Manual. Retrieved from http://support.netgear .com/app/products/model/a_id/12823 Netgear. (2010). ProSafe Quad WAN Gigabit SSL VPN Firewall SRX5308. Retrieved from http://ftp://downloads.netgear.com/files/SRX5308_DS_12Mar10.pdf Netgear. (2012). ProSafe 24-Port 10/100/1000 Smart PoE Switch GS724TP. Retrieved from http://www. netgear.com/business/products/switches/smart-switches/gs724tp.aspx Netgear. (2012). ProSafe 48-Port Gigabit L3 Managed Stackable Switch GSM7352S-200. Retrieved from http://www.netgear.com/service-provider/products/switches/fully-managed- switches/gsm7352s-200.aspx#two Netgear. (2012). ProSafe 20-AP Wireless Controller WC7520. Retrieved from http://www.netgear.com/business/products/access-points-wireless-controllers/wireless- management/WC7520.aspx#two

Editor's Notes

  1. The access points can broadcast up to eight SSIDs per radio and each SSID can be configured with different security controls, according to Netgear, (2009). When a guest associates with an access point guest SSID, the access point applies 802.1Q tagging to guest packets. As mentioned in “How to configure VLANs with 802.1x for WLAN authorization,” 2009) access points can tag wireless traffic in order to segregate it as it moves through the wired LAN. All LAN equipment supports 802.1Q tagging and funnels guest traffic to the internet. By tagging the guest packets, 802.1Q segregates guest traffic from the internal network traffic. 802.1x authentication prevents users from accessing network resources.
  2. The access points support 802.11e QoS giving high priority to voice and video traffic over data transfers such as FTP, applications. Low priority data such as FTP receives a best effort or background priority while high priority such as voice data sees minimal latency. Each access point applies an 802.1Q tag to packets in order to indicate priority level. The switches, controller, and firewall are connected over 1000BASE-T Ethernet cable and support 802.1p Class of Service (CoS). 802.1p allows switches to prioritize traffic, according to Javvin Company (n.d.).
  3. Remote clients can access the corporate network over SSL VPN anywhere there is access to the internet. The firewall supports simultaneous SSL VPN tunnels. Firewall supports user authentication through RADIUS server. VPN users are first authenticated by the RADIUS server before accessing the corporate network. VPN user traffic is protected over-the-air by SSL AES 128-bit encryption.
  4. Admin PC is connected to the network over 1000BASE-T Ethernet using a port-based static VLAN. The PC has personal firewall and virus protection software installed. The admin PC must first be authenticated as the administrator through the RADIUS server over 802.1x. This helps prevent unauthorized users from gaining administrator privileges. The Layer 3 switch is managed by web GUI with SSL HTTPS encryption, SSH telnet, command line interface (CLI) with SSH, or SNMP (Netgear, 2012). The access controller can be managed by VLAN connection through the HTTPS web GUI, telnet with SSH, and SNMP (Netgear, 2012). The PoE switch can be maintained through SSL web GUI, or SNMP. The PoE switch also offers port-based security through MAC filtering (Netgear, 2012). The access point can be configured though HTTPS web GUI, SSH telnet, CLI with SSH, and SNMP (Netgear, 2009). The firewall can be managed through HTTPS web GUI, SSH telnet, or SNMP (Netgear, 2010).