Home > Ask the Networking Experts > Wireless networking with Lisa Phifer Questions & Answers > Creating a WPA2 compliant network
Ask The Networking Expert: Questions & Answers
EMAIL THIS

Creating a WPA2 compliant network

Lisa Phifer EXPERT RESPONSE FROM: Lisa Phifer

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Wireless networks news, advice and technical information
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 12 October 2006

I have a large project where the customer wishes to use NetgearWAG102 access points with wireless Windows Mobile winCE.net devices. The customer has about 400 stores with about four to five mobile devices per store. Could you please explain the basic principles of creating a WPA2 compliant network in this environment?


>
EXPERT RESPONSE

WPA2 is available in two forms: WPA2-Personal for home and small office use, and WPA2-Enterprise for business use. Given your target application, you should use WPA2-Enterprise for strong, individual device authentication. You will require support WPA2-Enterprise support on your winCE.net devices and Netgear APs, and at least one RADIUS authentication server for 802.1X/EAP authentication.

Start with your mobile devices. Determine whether their Wi-Fi interfaces support WPA2-Enterprise; this may require installing driver upgrades. If WPA2 is not supported, use WPA instead. The Windows Mobile operating system supports 802.1X and several EAP types, but you'll need to choose an EAP type that meets your security needs and is supported by your devices as well. For example, Protected EAP (PEAP) would require configuring each mobile device with a username and password, while EAP-TLS would require installing a digital certificate on each device. If your mobile devices simply cannot support 802.1X, you may need to resort to WPA2-Personal in conjunction with MAC ACLs and a long, random PreShared Key.

Next, install, and configure a RADIUS authentication server to match the EAP type used by your mobile devices. You will need to create an account for each mobile device, either on the RADIUS server itself, or in a user database (e.g., Windows AD, LDAP database) that interfaces with your RADIUS server. The RADIUS server will be consulted each time a mobile device connects to the network, so give some consideration to where the RADIUS server should be placed, and if you really need more than one server for redundancy or performance. Depending on the EAP type, you will probably need to configure each authentication server with its own digital certificate.

The easiest component to configure will be your Netgear APs. In a WPA2-Enterprise network, APs serve as the middle man, relaying access requests from wireless clients to a RADIUS authentication server. WAG102 APs support WPA2-Enterprise, so just configure them with your authentication server's IP address and RADIUS shared secret. Beware that RADIUS protocol can expose sensitive information, so communication between APs and your authentication server(s) should be protected -- for example, using a site to site VPN to connect stores to a centrally-located server.

To learn more, read our Wireless LAN Security Lunchtime Learning Series tip about WPA2.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Wireless networking with Lisa Phifer
Buying your own WAPs vs. Internet service provider's wireless routers
What is 802.11n Greenfield mode used for?
Is my firewall setting preventing wireless network guest access?
Can you create a persistent wireless connection to a wired LAN?
Wireless troubleshooting: AP not reestablishing association after loss of connectivity
What can we expect in an 802.11n Wireless LAN standard implementation?
Can 802.11 protocols be used with GPRS connectivity?
Next generation wireless local area networks'(WLANs) important features
My wireless laptop connectivity disconnected once I downgraded my OS
How to debug poor WLAN performance

Wireless Network Management
7/11 chain cuts out controller to lower wireless networking costs
Cisco smartens up the wireless network with Motion platform
Book of Wireless author on wireless advantages and issues
Upgrading to 802.11n: Key considerations
Prevent IP address conflicts on your wireless network by managing DHCP scopes
How do we add wireless printer servers to our network?
WLAN troubleshooting with spectrum analyzers
Cisco to acquire Cognio
Wireless network troubleshooting: Connectivity
Wireless network deployment and management
Wireless Network Management Research

Wireless Network Implementation
Wireless deployment tips: How Amtrak deployed Wi-Fi on its trains
Linksys WAP2000 Business Access Point: Review and configuration
7/11 chain cuts out controller to lower wireless networking costs
Distributed antenna system streamlines wireless management
Wireless LANs -- 'CCNA Official Exam Certification Library, Third Edition,' Chapter 11
Book of Wireless author on wireless advantages and issues
What is 802.11n Greenfield mode used for?
Vendors at Interop in a scrum over WLAN architecture
Strategies for enterprise wireless deployment discussed at Interop
Upgrading to 802.11n: Key considerations

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
802.11a  (SearchNetworking.com)
home agent  (SearchNetworking.com)
iDEN  (SearchNetworking.com)
radio frequency  (SearchNetworking.com)
repeater  (SearchNetworking.com)
spectrum analyzer  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts