Home > Security Security Schools > Integration of Networking and Security School > Wireless security threat and attack defense > VLANs -- Controlling wired and wireless traffic
Security Schools: Integration of Networking and Security School:
EMAIL THIS
 START   ENDPOINT 101   SIMS   NAC   NETWORK   UNIFIED COMM   APP SECURITY   SNYDER   REMOTE   FABRIC   WIRELESS   
Wireless security threat and attack defense

<< PREVIOUS | NEXT >>
 TIPS & NEWSLETTERS TOPICS 

WIRELESS NETWORKS

VLANs -- Controlling wired and wireless traffic


Lisa Phifer
03.15.2007
Rating: -4.13- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Today, most business networks rely on virtual LANs (VLANs) to partition Ethernets and control the destinations reached by each worker. As users begin to shift between Ethernet and Wi-Fi throughout the work day, it makes sense to apply VLANs to both wired and wireless network access. This tip describes common methods for mapping Wi-Fi stations onto corporate VLANs and suggests when you might want to do so.


Wired VLANs
VLANs break a physical LAN into several logical broadcast domains. Each LAN station hears traffic sent by its own VLAN but receives nothing from stations in other VLANs -- not even from those physically connected to the same Ethernet switch.

VLANs also group stations together, independent of network topology. When stations in a VLAN are cabled to different Ethernet switches, traffic is relayed over inter-switch trunks in order to reach all stations participating in that VLAN.

VLAN membership can be statically configured into Ethernet hosts and switches, based on MAC address or port number, or membership can be determined dynamically by inspecting each Ethernet frame's VLAN Identifier (VID). These IEEE 802.1Q "tags" let upstream network devices apply different policies to each VLAN, from IP address assignment and quality of service to broadcast forwarding and network access control.

For example, Figure 1 illustrates a network composed of four distributed Ethernet edge switches and two logical VLANs: Engineering (VID #3) or Sales (VID #6). Each VLAN has its own IP subnet and can reach associated workgroup servers. Although they share infrastructure and work from different locations, each VLAN operates as though its members were connected to their own independent LAN.


Figure 1. Wired VLAN

Wireless VLANs
Now, suppose that one office decides to upgrade to Wi-Fi. How can we extend these existing VLANs to incorporate wireless stations, giving those workers exactly the same network access rights and limitations previously experienced over Ethernet?

In a small network, we might configure each wireless Access Point (AP) with Extended Service Set Identifiers (SSIDs) that map to each VLAN. Using business APs capable of supporting multiple SSIDs, we would configure two SSIDs, binding each to one existing Ethernet VID, as shown in Figure 2. Now, when Jack associates with the "EngNet" SSID, the AP tags all of his frames with VID #3. Others participating in the Engineering VLAN can now talk to Jack, and he will be able to reach the Engineering servers.


Figure 2. Mapping SSIDs to VLANs

Mapping a few SSIDs can be easy, but this method doesn't scale well. As the number of APs and VLANs grows, so does the administrative chore of maintaining static mappings. The likelihood that a user will end up on the wrong VLANs grows -- and not just as a result of administrator error. Rather, we have done nothing here to prevent Jack from associating to the "SalesNet" SSID, thereby placing himself into the Sales VLAN, where he will have access to the Sales servers.

We can defeat this "VLAN hopping" problem by using 802.1X Port Access Control to control SSID usage. An office concerned about wireless security should be using WPA (or WPA2) Enterprise to encrypt over-the-air traffic. Using WPA-Enterprise, whenever Jack tries to associate with the "SalesNet" SSID, the AP sends a RADIUS Access-Request to an 802.1X Authentication Server. That Server verifies Jack's identity and credentials before deciding whether to permit LAN access. To prevent Jack from hopping onto the Sales VLAN, we could configure the Server to return his authorized SSID ("EngNet") as a RADIUS attribute (see Figure 3). If the requested and permitted SSIDs do not match, the AP will disassociate Jack, denying access to unauthorized VLANs.


Figure 3. Using 802.1X to control SSID usage

So far so good; but what if we had tens or hundreds of VLANs? It would be terribly inefficient -- perhaps even impossible -- to map each VID onto its own unique SSID. In a large network, we need an altogether different approach. Instead of static SSID/VLAN mappings, we could use 802.1X RADIUS attributes to supply dynamic VLAN bindings whenever wireless users authenticate. Now, when Jack associates with the "CorpNet" SSID, the Server returns his authorized VID (#3), which the AP uses to tag all of his traffic. When Jill associates with that same "CorpNet" SSID, the Server returns her authorized VID (#6), which the AP uses to tag her traffic. With this method, authenticated users are mapped onto VLANs, independent of access medium.


Figure 4. Using 802.1X to supply VLAN tags

The bottom line
Using 802.1X to supply VLAN tags is flexible, scalable and secure. Because the wireless network does not need to be segmented to match VLAN topology, SSIDs can be used for other purposes, such as separating wireless voice and data traffic, isolating wireless guests or quarantined hosts, or migrating from legacy devices to next-generation Wi-Fi. Those other SSIDs can be mapped to their own VIDs to keep traffic segregated as it moves through the network -- for stations that don't speak 802.1X, for example.

In fact, the same 802.1X Authentication Server can be used to dynamically supply VLAN tags to wired Ethernet stations, if all Ethernet switches and hosts are 802.1X-capable. Administrators would no longer need to configure every AP and edge Ethernet switch with VLAN mappings. Instead, VLAN tags would be configured into individual or group authorization policies, stored in just one place: the user database consulted by the 802.1X Authentication Server.

To learn more about wireless VLAN configuration and best practices, see these tips:

About the Contributor: Lisa A. Phifer is vice president of Core Competence Inc. She has been involved in the design, implementation, and evaluation of data communications, internetworking, security, and network management products for over 20 years and has advised companies large and small regarding security needs, product assessment, and the use of emerging technologies and best practices.


NETWORK SECURITY SCHOOL MENU

  Network Security School: Home
  Lesson: Home
  Lesson webcast
  Lesson podcast


Rate this Tip
To rate tips, you must be a member of SearchNetworking.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


<< PREVIOUS | NEXT >>
VIEW ALL IN THIS CATEGORY


RELATED CONTENT
Wireless Networks
How to plan for 802.11n wireless LAN upgrades
Deploying 802.11n access points: Best practices
Rogue access points: Preventing, detecting and handling best practices
Persistent, secure connections for roaming WiMAX, 3G and 802.11x
Securing embedded 802.11n devices
802.11n's impact on WLAN security
Set up secure wireless networks with 802.11x, access points and bridges
How to use Netsh WLAN to configure Windows Server 2008 and Windows Vista wireless connections from the CLI
How to avoid the WPA wireless security standard attack
IEEE 802.11w protects wireless LAN management frames

Wireless LAN Implementation
University tackles large-scale 802.11n wireless network management
Why is my network adapter not working after a Vista Business upgrade?
How many wireless base stations can connect to 802.11g access points?
802.11n wireless APs bring IP video to sprawling Illinois high school
No data cable? Wireless mesh networking the answer for Wi-Fi backhaul
Integrated wireless and wired LAN: Brocade-Motorola deal ups the ante
802.11n WLAN architecture strategies: The 2.4 vs. 5 GHz band debate
802.11n upgrade: College ditches legacy network for new vendor
802.11n ratification will drive down wireless LAN prices
How does Wi-Fi ad-hoc mode react when 802.11n and legacy peers are present?

LANs (Local Area Networks)
How to test LAN switch energy efficiency
Testing LAN switch power consumption: A best practices guide
3Com acquisition confirms HP-Cisco battle for China
Integrated wireless and wired LAN: Brocade-Motorola deal ups the ante
Enterprise passive optical networks: a spanning-tree LAN alternative
10 Gigabit Ethernet tutorial: Connecting data centers, storage, LAN and beyond
Intelligent edge switches: Complexity is driving a smarter LAN
Q&A: Jim Metzler previews the networking track at Interop
Extreme's port extender can replace consumer devices at network edge
VLANs versus IP subnets: Why use a VLAN over IP subnetting?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
802.11a  (SearchNetworking.com)
Asynchronous Pulsed Radiated Incident Light  (SearchNetworking.com)
beamforming  (SearchNetworking.com)
cognitive radio  (SearchNetworking.com)
direct sequence spread spectrum  (SearchNetworking.com)
frequency-hopping spread spectrum  (SearchNetworking.com)
patch antenna  (SearchNetworking.com)
phase-locked loop  (SearchNetworking.com)
radio frequency  (SearchNetworking.com)
wireless mesh network  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Networking Solutions for Business

Alcatel-Lucent Network Business Communications Solutions

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts