Recommendations for wireless security...

We have a small campus and the following equipment:
1 - 4402 WLC
12 - APs
3 Networks (Guest, Student, Staff)
1 ACS server
What would you recommend in regards to a practical, yet effective, security setup. We currently use WEP/MAC filtering for the staff network, the student and guest side are wide open.
I am just looking for some ideas of how you would implement security.

Hi,
I think the below may help!!
GUEST = WEB AUTH internal page
STAFF = PEAP MSCHAP V2 server side certs
STUDENTS = MAC FILETERING with WEP.
Lemme know if this answered ur question!!
Regards
Surendra

Similar Messages

  • MAC filter for wireless security????

    I have hooked up my wireless router and had trouble with the security part.  I am now set up with the wireless security disabled but the MAC filter enabled and my wireless computers mac number entered and all is working.  will the MAC filter work as security for my wireless network.  thanks tdm

    MAC address filtering is considered a very low level of security.  It will keep honest people from accidentally logging into your network, but that is about it.  MAC addresses are transmitted wirelessly when you use your router.  Anyone can monitor your transmissions, so it is easy to learn a working MAC address.  They can then fake the MAC address and loggin to your network whenever you are not connected.
    Also, when your transmissions are not encrypted, anyone within range can monitor your wireless transmissions, even without logging into your network.  With a good antenna, your transmissions can probably be picked up for at least half a mile from your home.  So someone could monitor the web sites you visit, your email, etc., and in some cases, your passwords.
    You really should setup wireless security on your network.
    Here are my tips for setting up wireless security:
    To set up wireless security, you must use a computer that is wired to the router.
    Where to find the router settings: The router's login password is usually on one of the "Administration" pages. The other settings are all found in the "Wireless" section of the router's setup pages, located at 192.168.1.1
    First, give your router a unique SSID. Don't use "linksys".
    Make sure "SSID Broadcast" is set to "enabled".
    Next, leave the router at its default settings (except for the unique SSID), and then use your pc to connect wirelessly to the router. Test your wireless Internet connection and make sure it is working correctly. You must have a properly working wireless connection before setting up wireless security.
    To implement wireless security, you need to do one step at a time, then verify that you can still connect your wireless computer to the router.
    Next, encrypt your wireless system using the highest level of encryption that all of your wireless devices will support. Common encryption methods are:
    WEP - poor (see note below)
    WPA (sometimes called PSK, or WPA with TKIP) - good
    WPA2 (sometimes called PSK2, or WPA with AES) - best
    WPA and WPA2 sometimes come in versions of "personal" and "enterprise". Most home users should use "personal". Also, if you have a choice between AES and TKIP, and your wireless equipment is capable of both, choose AES. With any encryption method, you will need to supply a key (sometimes called a "password" ).
    The wireless devices (computers, printers, etc.) that you have will need to be set up with the SSID, encryption method, and key that matches what you entered in the router.
    Retest your system and verify that your wireless Internet connection is still working correctly.
    And don't forget to give your router a new login password.
    Picking Passwords (keys): You should never use a dictionary word as a password. If you use a dictionary word as a password, even WPA2 can be cracked in a few minutes. When you pick your login password and encryption key (or password or passphrase) you should use a random combination of capital letters, small letters, and numbers, but no spaces. A login password, should be 12 characters or more. WPA and WPA2 passwords should be at least 24 characters. Note: Your key, password, or passphrase must not have any spaces in it.
    Most home users should have their routers set so that "remote management" of the router is disabled. If you must have this option enabled, then your login password must be increased to a minumum of 24 random characters.
    One additional issue is that Windows XP requires a patch to run WPA2. Go to Microsoft Knowledge base, article ID=917021 and it will direct you to the patch.
    Sadly, the patch is not part of the automatic Windows XP updates, so lots of people are missing the patch.
    Note:
    WEP is no longer recommended. The FBI has demonstrated that WEP can be cracked in just a few minutes using software tools that are readily available over the Internet. Even a long random character password will not protect you with WEP. You should be using WPA or preferably WPA2 encryption.
    Message Edited by toomanydonuts on 01-16-2008 03:38 AM

  • Any recommendations for Firefox security add-ons?

    I noticed here on the site, that several people recommend using Firefox with the "No Script" add-on.
    Does anyone happen to have a good link for downloading a Mac version of this?
    Are there maybe any suggestions for other security add-ons worth installing for Firefox / Thunderbird?

    Well, then I can't understand why this is happening. Found this for an earlier version.
    It's important to understand that whitelisting is slightly limited by domain-obscuring page elements like iframes. When a call is made from an iframe, it's made from the domain in the iframe's source, so Ghostery can't tell that it's coming from the domain you've whitelisted. As a result, it may appear that Ghostery is blocking on a site you've whitelisted, even though it's doing its best to follow your instructions. Any script, ad, widget, or other element that calls directly from the whitelisted domain will go through without a second glance.
    BUT, it's supposed to have been "relaxed" in 2.5.2, the version I'm using; i.e. now it's supposed to allow anything from a domain regardless of where it's coming from.
    And, yours is showing brightcove as blocked. If so, you shouldn't be getting any video, since that's where it all comes from in the Times.
    You said video was loading on the video page, but I wonder are you able to load video on the homepage? It's in a large box "Video" near the middle of the page.
    I have an email in to their support.

  • Recommendations for wireless adapter to use with Tivo?

    I'm shopping for my first Tivo box, and was wondering if any of the Tivo-recommended wireless USB adapters work better with Airport/Mac than the others?
    Thanks!
    Erin

    I'm glad to see this topic addressed here. I have a TiVo (Humax w/DVD Burner) and I have home network using Airport for our 3 Macintosh computers. I have been avoiding trying to hook up my TiVo to the network...and thought I'd do some research before I take the plunge. Based on what I'm reading, I should purchase a D Link DWL 120B?? We also have ReplayTV as well, has anyone tried doing networking with RPTV and Airport?

  • Recommendations for Internet security package with lion?

    Any recommendations fro an Internet security package with lion?

    Seems to me you are getting limited replies about Mac OSX security and viruses. Internet security can also be about safe surfing and being warned the safety and suitability of web sites. Also you may be running applications, like Microsoft Office, on your iMac which may have similar weakness and vulnerabilities to the Windows office suite. Although many nastys you may get via macros and e-mail are aimed at messing up Windows, there are others which aim to steal personal information or can be used to infect others when you send files or mail onwards. While I believe Mac OS itself is probably better protected than Windows, I think it may still worth extra protection and warnings about web sites. etc. which you get from Internet Security Packages such as Norton or Mcafee (which is good for the mac).

  • Recommendations for Wireless Card?

    I am thinking of getting a new wireless card for my laptop because my wireless connection is very weak at home. We all use a router, however my sister in the room next to me has flawless connection on her Windows laptop. It was suggested to me to look into getting a networking card that matches my Linksys router for stronger wireless connection, but I was hoping for some more advice. I do not know where to look first or how to start searching.

    Some WiFi issues are known to be fixed simply by upgrading to 10.4.11. To upgrade to 10.4.11, follow my FAQ*:
    http://www.macmaps.com/upgradefaq.html
    Others may be fixed by following my FAQ*:
    http://www.macmaps.com/WIFI1048.html
    - * Links to my pages may give me compensation.

  • Best options for wireless security

    I have an Aironet 1040 access device, no controller. I have an LDAP server with radius in front to allow for username and password authentication(using MS CHAPv2) with mandatory WEP and PEAP.
    I was wondering what the strongest security option is that allows me to retain the username and password authentication. The current setup functions but leaves much to be desired.

    ill just add. Make sure you use somethin other then your ID for the outter ID becuase this is sent in the clear and can be sniffed. To prevent a man in the middle I would also vaidlate the certificate with PEAP.
    "Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
    ‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."

  • Recommendations for wireless speakers for airplay.

    I am looking to get some wireless speakers for our home so I can play my iTunes via AirPlay. It is a 1 level house so nothing elaborate. Any suggestions welcomed.

    some options here.

  • Recommendations for wireless bridge

    I have several 1262 LAP's connected to a virtual WLC controller. I need to build a wireless bridge to a warehouse for a few computers and voip phones. Any recomendations on the hardware and configeration? I've done this before with Proxim AP's, but am new to Cisco's wireless hardware. Duel radio's would help, so I can put one inside and one outside for the bridge.

    The WLC won't be able to control a 'bridge', unless you were using 1552. 
    But you could use the radios on the bridge as well, so long as you use 'infrastrucure-ssid optional' under the SSID.  that will allow you to 'bridge' on teh 5GHz and still use the 2.4GHz
    HTH,
    Steve
    Please remember to rate useful posts, and mark questions as answered

  • Need step by step instructions for wireless security setup on my westell modem

    I tried setting up security shortly after getting the modem, but I had trouble getting vista laptop to work with the security settings. I don't feel like figuring this all out. I would like step by step instructions for my modem. It is the Westell VersaLink 327W. If these instructions are on a web site somewhere that would be great.
    Thanks.

    I think I just answered my own question. I exported to my desktop and then added it to my iDisk.
    If anyone has any other tips, that would be great. Not sure how to set up the size of the frames.

  • Recommendations for wireless mono laser printer compatible with OS 10.6.7?

    I am looking for a wireless mono laser printer compatible with Snow Leopard OS10.6.7. This is to be shared by 4 Macs in a small office. We are connected to the internet via DSL modem (2 wired, 2 wireless), and communicate with the Bonjour network. We have a Time Capsule, but are not using that for a server at this time. Any suggestions would be much appreciated.

    How long is a piece of string?
    There's a myriad of compatible printers that meet your given criteria, but that's mostly because you haven't been very specific about your needs... 'compatible with 10.6.7' is just one of many considerations.
    For a start, what's your budget? That may narrow the field considerably.
    Then what's your expected print run? If you're printing tens of thousands of pages per month your needs are way different from someone printing one or two pages a day (or week!). There's a reason why printer manufacturers list a 'duty cycle' on their spec sheets - it tells you what they think it's capable of handling so that you don't under or over-spec your printer.
    And 'duty cycle' is way more than just the speed per page - it's how quickly the components wear out and need replacing. If you print 10,000 pages per month then the manufacturer has to build using higher-grade components that can run for hundreds of thousands of pages before servicing/replacing (and I'm talking here of things like fusers, belts, and the like, not consumables like ink and toner).
    On the other hand there's no point in the manufacturer using high-grade components that can handle 1,000,000 cycles in a printer that's printing 100 pages a month - the printer, your computer and probably even you would be obsolete way before those components wore out.
    Then you need to consider input capacity. If you're printing a lot you'd probably appreciate high-capacity input bins (so you don't have to walk over to the printer every hour to refill the tray).
    What about duplex? Do you want to be able to print double-sided (either now or in the future)?
    Since this is a small office, do you want other multi-function features such as fax/scan/copier?
    These questions (and probably more) will go a long way to identifying the 'right' printer for your needs. As it stands, though, there really isn't enough data to offer any advice.

  • I have a Westell 6100G modem.  I want to set up Airport Express for wireless.  Can someone tell me how to do it step by step.  I'm using an HP with Windows Vista.  I'm a tech idiot.

    Just got Airport Express to save on GBs of data.  I have already a Westell 6100G which is for use as Internet Broadband, via Verizon.  How do I set up the Airport Express with this Westell.  Do I even still need the Westell, or do I need to also buy a wireless router?  I'm a tech idiot and this is driving me nuts.

    The Westell 6100G is a combination modem and router or gateway device. The AirPort Express is a wireless router.
    Since the Express does not have a built-in modem, you will still need your Westell gateway in order to access the Internet.
    Which exact model of AirPort Express do you have. It will be written (in very hard to read type on a label on one of the AirPort's sides). It should look something like: A1392. It may also state a Order#. In that case it would look something like: MC414LL/A
    Regardless of which model you have, the basic network configuration would be that you would connect an Ethernet cable between the Westell's Ethernet port and the WAN (circle of dots) port on the Express. (Note: If you have an earlier model of the Express, you would connect the cable to the only Ethernet port on the Express.)
    The good news is that you will not have to make any configuration changes to the Westell. We should be able to use it as configured.
    What we are going to start with is getting a basic Wi-Fi network that should provide your computer with wireless access to the Internet. Once verified as working, we can fine-tune this network to include wireless security and any other goals that you may have.
    Ready to start?
    I would recommend that you do the following as a minimum:
    Power-down the Westell and computer(s).
    While all of the devices are powered-down, perform a "factory default" reset on the AirPort Express base station. This will get it back to its "out-of-the-box" configuration and make setting it up much easier, especially if you use the "Assist me" process within the AirPort Utility. (ref: Resetting an AirPort Base Station or Time Capsule)
    Once the reset has completed, remove the AirPort Express from power.
    Connect an Ethernet cable between the Westell and the AirPort Express.
    Power-up the Westell; wait at least 10-15 minutes to allow it adequate time to initialize.
    Power-up the AirPort base station; wait at least 5-10 minutes. Note: The AirPort's status light may continue to flash amber after it has intialized. That is because, there may be some additional configuration items necessary, like setting up wireless security, before the overall setup is completed to get a green status.
    Power-up your computer(s).
    In this basic configuration, the AirPort base station will broadcast an unsecured wireless network with a Network Name (SSID) of Apple Network NNNNNN. Network clients, connected to the base station either by wire or wireless, should now be able to access the Internet through the ISP's modem. Once Internet connectivity has been verified, you can use the AirPort Utility to configure the base station for wireless security and any other desired options. Please post back your results.

  • Help with setting up wireless security with mac

    We have just set up a Linksys WRT54G on a pc, and it connects to the internet fine. the problem is, anyone can connect.
    I do not understand how to set up a password for this so no one can leach off my internet connection.
    I tried to put in a code but it didnt work.
    is there a step by step way to do this?

    FAQs are on the linksys support pages. For wireless security there are a few. One is here:
    http://linksys.custhelp.com/cgi-bin/linksys.cfg/php/enduser/std_adp.php?p_faqid=759
    However, I would not configure WEP as described there but WPA or better WPA2. New iMacs support WPA2. WEP can be cracked within a few minutes.
    If it still does not work, please post the exact settings you are using in your router (Wireless tab and Wireless Security tab) and the settings you are trying on your mac.

  • Anti-Virus Recommendations for Windows 7 Bootcamp Partition

    Hello smart mac users
    I am running a Windows 7 64bit Bootcamp Partition on my 27" iMac (new to Mac).
    Can anyone recommend a reliable Anti-Virus software for my Windows 7 Partition?
    All the posts I've read about Norton or Mcaffee have been bad....I've not found one good recommendation
    I've found multiple recommendations for Microsoft Security Essentials but I'm always shy of free products (you get what you pay for) ...and I read a not so great but not bad review about it online. Comments? Can it really be as safe and reliable as a paid antivirus software?
    AVG free anti-virus is also recommened here..
    Everything I've read about paid Anti-Virus software on this forum is bad...seems to cause many more problems
    I haven't heard anything bad about Kapersky on Windows bootcamp..comments?
    Anyone out there using Kapersky / Norton / Mcafee / Sophos / Others with no problems?
    I will use Clam Xav for the Mac partition...
    I've read on this forum that the bootcamp windows partition is just like running windows on a normal PC...and we should install Anti-virus just like you would on a normal PC....but I've read nothing but bad reviews when installing Norton or Mcafee on the Windows bootcamp partion....please comment
    If people can reassure me Microsoft Security Essentials is safe (or another) ..I'll use it...just need convincing it can still provide the protection required..
    I will only be using my iMac for work ....I plan on using Paragon NTFS and Paragon HFS+ to simply copy/paste working files between windows and mac partitions
    Thanks in advance for any comments/recommendations!
    VietBrad

    Security Essentials
    AVG
    Avast
    are all good. Norton and McAffee are bloated, cause system slowdowns, and are not easy to uninstall, not to mention expensive, imho. The free programs I listed above, and others, offer as good protection as any of the paid for programs. I don't know how to "reassure" you but many thousands, if not millions of Windows users are using free anti-virus apps with success.

  • Security Router: Best and cheap recommendation for a home router (security bundled)

    Security Router: Best and cheap recommendation for a home router (security bundled), to practice commands and all CCSP configurations.
    Wireless needed, 802.11N preferred
    Looking for the all in an appliance solution, and maybe compatible with future Unified Communications acquisition like a UC500 maybe...
    Please, please, please...

    At the moment checking these two options:
    SR520W-FE-K9
    CISCO881W-GN-A-K9
    Fast Ethernet

Maybe you are looking for

  • How can i update my ipod touch to 4.3.3 it always come out with 3194 error

    i can't update my ipod touch ios from 4.1 to 4.3.3 i don't know why i already try every method i can like turn to DFU mode and then restore or rn the itune as administrator but it still can't it always show the 3194 error i have no idea now what to d

  • IDVD 7.1.2 in OSX 10.8.5 Cannot get to finish burning DVD

    I tried two different slideshow templates in iDVD thinking that I had chosen a newer template causing my problem. I know I burned a DVD slideshow successfully last year on my computer and with my current operating system and current iDVD version. But

  • How does "High Dynamic Range" Photos work?

    I see that I'm getting two photos from each shot. I suppose that's because I tabbed "on" the selection to keep the regular photo. What's going on with "High Dynamic Range" photos and how can I tell which photo is the regular photo and which is the HD

  • Motion 4: Motion tracking a moving mask

    I'm making a video for our church which is a knockoff of the E-Trade babies commercials. I have a segment of it done which you can see here using the password "jaymack": http://www.vimeo.com/26897268 As you can see, I'm dealing with both a moving bab

  • How to skip the '\n' char when reading with BufferedReader

    Hello to all the comunity that is at these forums, ;) I'm a venezuelan IT student, and as many arround here, I'm looking for some help with this homework... well the thing is that I need to read from the System.in untill I get the "" String. Well the