Home > Ask the Networking Experts > Wireless networking with Lisa Phifer Questions & Answers > Will 802.11n WAPs we purchase today be compatible with NAC?
Ask The Networking Expert: Questions & Answers
EMAIL THIS

Will 802.11n WAPs we purchase today be compatible with NAC?

Lisa Phifer EXPERT RESPONSE FROM: Lisa Phifer

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Network security news, advice and technical information
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 12 September 2007

How can we tell whether the new 802.11n WAPs that we purchase today will be compatible with NAC?


>
EXPERT RESPONSE

Today, there are several well-known Network Access Control (NAC) architectures, including Cisco NAC, Microsoft NAP, and Trusted Computing Group TNC. These architectures embed NAC capabilities into the network itself, using devices like Ethernet switches and Wireless APs to handle access requests and enforce access decisions. In addition, there are dozens of products that spin their own flavor of NAC, from proprietary network appliances to endpoint security agents.

This degree of diversity makes it hard to say whether or not any product is compatible with NAC -- a better question to ask is whether a given product is compatible with a specific NAC architecture or appliance. For example, Cisco NAC can protect networks composed of Cisco devices. Today, CNAC-compatible devices include Cisco routers, Catalyst switches, Aironet Access Points, and the Cisco VPN 3000 Concentrator. See Cisco's website for a list of CNAC-enabled products.

Nonetheless, some commonality does extend across all of these NAC architectures, and many proprietary NAC appliances. In particular, most can use 802.1X to handle Layer 2 access requests, relaying those requests over standard RADIUS to NAC policy server where decisions are made. 802.1X is designed to support an open-ended dialog between an 802.1X supplicant (the host requesting access) and an 802.1X authentication server (the system responsible for permitting or denying access). The messages exchanged during that dialog are represented using the Extensible Authentication Protocol (EAP). Today, NAC architectures use different EAP types and endpoint assessment messages carried within those EAP bindings. However, all of those EAPs ride on standard 802.1X.

The bottom line is this: If you plan to implement NAC, purchase Wireless APs (and Ethernet switches) that support standard 802.1X/RADIUS-based port access control. When examining Wi-Fi Alliance test certifications look for WPA-Enterprise and WPA2-Enterprise support. This is all your WAP will need to support basic go/no-go NAC decisions. If you plan to take NAC further, look for the following features:

  • 802.1Q VLAN support letting the WAP tag wireless traffic before it heads into your wired network.

  • RFC 3580 support letting the WAP understand and apply VLAN IDs returned by the NAC policy server in RADIUS Access Responses.

  • Virtual APs with the ability to simultaneously support multiple SSIDs, letting the same WAP support both open guest access and secure access.

  • Intra-WLAN security options that let the WLAN prevent unknown, potentially infected or malicious users from interacting with NAC-authorized users.

These features won't guarantee plug-and-play compatibility between your WAP and all NAC products, but it will give you a pretty good shot at integrating that WAP into many possible NAC deployments.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Wireless networking with Lisa Phifer
How can I implement VLANs across WLAN links?
Extending Wi-Fi range indoors or outside with 802.11n and WDS
How does WiMAX compare to other wireless broadband services?
How many more users will 802.11n wireless access points support?
Accessing printers on a LAN while connected to a WLAN.
How to maintain corporate VPN connection while printing to a private network.
How to connect wireless networks for printing capabilities
What is the Free Public WiFi network I keep seeing in public places?
Will different wireless card link speeds cause network latency?
Open source authenticator implementation for LANs: How is open1x an 802.1X supplicant?

Network Access Control (NAC)
Shifting defenses and dynamic perimeters challenge network security
Compliance in a virtualized world: Server virtualization and NAC security
Securing the new network architecture: Security for distributed, dynamic networks
What is data loss prevention? -- An introduction to DLP
How to set passwords on folders in Windows 2003 servers
Is my firewall setting preventing wireless network guest access?
NAC vendor Bradford Networks offers simplified product for guest and contractor access
What commands allow network traffic to pass through PIX firewalls?
Intelligent network switches on the rise as more is expected of the network
NAC solution authentication fix for your wireless network

Wireless LAN Equipment
HP ProCurve-Colubris deal signals WLAN market consolidation
Will different wireless card link speeds cause network latency?
802.11n vendor review finds partners matter most in Wi-Fi upgrades
Linksys WAP2000 Business Access Point: Review and configuration
7/11 chain cuts out controller to lower wireless networking costs
Distributed antenna system streamlines wireless management
Wireless LANs -- 'CCNA Official Exam Certification Library, Third Edition,' Chapter 11
Cisco smartens up the wireless network with Motion platform
Buying your own WAPs vs. Internet service provider's wireless routers
What is 802.11n Greenfield mode used for?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
network access control  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Expert networking advice and tips for IT professionals
Visit KnowledgeStorm's comprehensive and easy to use business white paper directory.
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts