Home > Networking Tips > Wireless Networks > WLAN security tools: Buyers' guide for SMBs
Networking Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WIRELESS NETWORKS

WLAN security tools: Buyers' guide for SMBs


Elisabeth Horwitt, Contributor
03.28.2006
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Definition: Wireless LAN security systems thwart unauthorized access attempts and denial-of-service attacks on wireless LANs. Most products fit into one of two categories:

Benefits

WLAN security has become increasingly critical for small and midsized businesses (SMBs) as much as large enterprises, according to John Pescatore, a vice president at Stamford, Conn.-based Gartner Inc. "If someone finds out you've got an unprotected WAP, they'll use it," he warns. Casual passersby may simply want a free connection to the Internet; but an unguarded WLAN can also be used for more malicious purposes, such as sending spam, launching a denial-of-service attack or downloading sensitive files.

Wireless LANs are especially vulnerable to break-ins because, unlike wired LANs, they are not contained within a physical structure. Radio waves carry traffic beyond corporate walls, enabling intruders to gain access to the network without entering a corporate building. Furthermore, WLAN traffic does not flow through a central node that can be used to monitor and control who gets access to what.

Lastly, SMBs may need to implement WLAN security in order to comply with government regulations such as the Health Insurance Portability and Accountability Act.

Industry trends

Until recently, the primary WLAN security mechanism was Wired Equivalent Privacy (WEP). WEP is an encryption protocol designed to protect data in transit. However, the standard provides minimal protection -- researchers found that transmissions can be intercepted and modified to give intruders access to a "secured" WLAN. "A teenager can break in," Pescatore said.

While most wireless LANs still support WEP, newer and more effective security standards have entered the market in recent years:

Costs

A growing number of vendors offer 802.1X authentication platforms and IPSs that target SMBs:

Infob


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Wireless Networks
Rogue access points: Preventing, detecting and handling best practices
Persistent, secure connections for roaming WiMAX, 3G and 802.11x
Securing embedded 802.11n devices
802.11n's impact on WLAN security
Set up secure wireless networks with 802.11x, access points and bridges
How to use Netsh WLAN to configure Windows Server 2008 and Windows Vista wireless connections from the CLI
How to avoid the WPA wireless security standard attack
IEEE 802.11w protects wireless LAN management frames
Measure wireless network performance using testing tool iPerf
How to prioritize wireless traffic

WLAN Security
Wireless LAN security: SonicWall joins crowded WLAN market
Stolen laptop recovery using remote access and wireless network SSIDs
Enterprise wireless LAN security: 802.11 and seamless wireless roaming
Monitoring your network to detect rogue access points (APs)
Persistent, secure connections for roaming WiMAX, 3G and 802.11x
802.11n's impact on WLAN security
Set up secure wireless networks with 802.11x, access points and bridges
How wireless network encryption affects signal strength, connectivity
New PCI compliance rules ban WEP, tighten wireless LAN security
How to avoid the WPA wireless security standard attack

Troubleshooting Wireless Networks
How radio frequency (RF) of microwaves alter wireless signal strength
Distributed antenna systems and WLAN: A network management burden
Wireless LAN management platforms key differentiator for WLAN vendors
How is wireless access point (AP) coverage affected by frequency?
From Cisco to Meru to Aruba, school finally finds right WLAN
How to find an SSID and identify neighboring WLANs
How to stop channel interference on 802.11x wireless access points
Troubleshooting networks: Can vendor software self-install firewalls?
How to use Netsh WLAN to configure Windows Server 2008 and Windows Vista wireless connections from the CLI
Free consumer Wi-Fi hot spots: Retail fad or enterprise business tool?
Troubleshooting Wireless Networks Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
802.11a  (SearchNetworking.com)
home agent  (SearchNetworking.com)
iDEN  (SearchNetworking.com)
radio frequency  (SearchNetworking.com)
repeater  (SearchNetworking.com)
spectrum analyzer  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


lox Inc.
's Infoblox 1000 appliance, configured with the RadiusOne server module, is priced at $9,995. It comes with a Web graphical user interface and wizards to ease installation and configuration.

Corriente Networks LLC's Elektron 1.1 provides 802.1X security to WPA-enabled access points. Priced at $299.99, it automatically performs common administrative tasks, such as backing up databases and adding user accounts.

Funk Software Inc., which is now part of Juniper Networks Inc., offers its Steel Belted Radius (SBR) Enterprise server software for about $5,000. It provides Radius-based authentication for virtual private networks (VPNs) and 802.1X wireless and wired networks.

Aruba Networks' low-end 200 Mobility Controller provides Radius authentication for up to six Aruba WAPs and 100 simultaneous users. It starts at $1,750.

McAfee Inc. and BoxedWireless provide hosted wireless LAN encryption and authentication services. McAfee's Wireless Security for Small Business hosted service costs $49.99 per year per user for one to four users and $44.99 per user per year for five users and up. BoxedWireless' service starts at $15.50 per month for up to 10 users.

Tips and gotchas

Not all rogue WAPs are operated by rogues. Businesses sharing a building may inadvertently intrude on each others' WLANs. An IPS should be able to tell the difference and disable the neighboring AP's access to your WLAN, but not theirs.

When deploying 802.1X authentication, make sure all laptops and other wireless client devices are equipped with 802.1X "supplicant" software.

SMBs may find it easier to cost justify a Radius server if it isn't just for WLANs. Aruba's Mobility Controller and Funk Software's SBR provide authentication for both wired and wireless LANs and VPN connections as well.

Make sure your WLAN security system supports your wireless cards.

Product sampler

BoxedWireless.com
Corriente Networks
Juniper Networks
Aruba Networks
McAfee
Network Chemistry (IPS)
Infoblox

Expert viewpoint: John Pescatore, vice president, Gartner

"We tell our clients, 'If your policy is no wireless LANs, then definitely get intrusion prevention, because if you don't give a WLAN to your employees, they'll sneak it in. Every laptop comes with a wireless card now, and people can pick up a wireless access point at CompUSA for $40.

"If an SMB is already using a virtual LAN, it's smart to segregate WLAN access points on different VLAN segments, for security purposes. A medium-sized business should look at Aruba Networks or Cisco subsidiary Airespace, which implement VLANs on a wireless network through a central switch. WLAN systems with no central switch can set up primitive VLAN segmentation, like everybody can access everything except financial systems.

"Watch out for what we call 'accidental association,' when your employees tap into a nearby company's wireless network. You could be liable. Or someone in the other company could use the link to download something to your PCs, like a virus."

Elisabeth Horwitt is a contributing writer based in Waban, Mass.

This tip originally appeared on SearchSMB.com. View their previous buying guides.

Rate this Tip
To rate tips, you must be a member of SearchNetworking.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Networking Solutions for Business

Alcatel-Lucent Network Business Communications Solutions

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts