Home > Networking Tips > Wide Area Networks > Do you really need a VPN for secure wireless LAN communications?
Networking Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WIDE AREA NETWORKS

Do you really need a VPN for secure wireless LAN communications?


Kevin Beaver
09.22.2004
Rating: -3.20- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


There's a lot of talk – especially from the VPN vendors – about using a VPN to secure wireless LAN (WLAN) communications. But do you really need to put forth the time, money, and effort required to do this? I've got two good arguments for it and two against it. Sure, there are probably dozes of other pros and cons, but this is what I'm seeing in the field from a practical perspective. Of course, you'll have to decide what matters to you, but here's my take on it.

Reason #1 for WLAN VPNs – VPNs are right up your alley
VPNs certainly aren't the easiest components of a network security infrastructure to setup or manage. If you can walk the VPN walk and you won't have a steep learning curve, installing and maintaining a VPN to secure your airwaves makes good sense – especially since it'll be second nature to you. Barring any major technical innovations that complicate things in the future, if it's easy for you now, it's hard to argue that it won't be easy long-term.

Reason #2 for WLAN VPNs – A VPN fits into your existing network architecture
If you're already relying on VPNs for external, and even untrusted internal network communications, why not configure your VPN to support the WLAN. You can use the same authentication, integrity, and encryption features present in your wired LAN VPN setup for your WLAN. You probably won't even have to purchase any additional hardware (software licenses are a different issue) to make this happen if your existing VPN system supports multiple network segments. Certain WLAN access points are VPN-aware so look for that as well.

Reason #1 against WLAN VPNs – It's just extra overhead you don't need
Adding a VPN to your WLAN comes with a cost – and I'm not just referring to the purchase price of hardware and licenses. A VPN requires ongoing maintenance and support. VPN systems must be hardened, patched, and sometimes tweaked even though many vendors claim a "setup and forget" solution. Also, don't forget extra failover systems you may need to put in place for business continuity as well as ongoing support contract costs. If you do the right things to secure your WLAN, do you really need to add another system (the VPN) into the mix? It can certainly be just another point of potential failure and frustration.

Reason #2 against WLAN VPNs – WLANs can be secured by other means (really)
Hardening a small WLAN is not difficult at all. Larger WLAN deployments can take more time – but it's certainly doable. WLAN hardening techniques are well-documented. There's WEP, SSID tweaks, and other access point, wireless client, and 802.11 protocol settings that can really tighten down a WLAN. On top of that, you can deploy WPA or the new WPA2 and 802.11i security settings in your WLAN making it rock solid. A VPN is certainly not the only answer.

I'm prejudiced towards the more practical side of IT and security. The thing is, in this situation, there are practical aspects to both sides of the argument. A VPN can offer maximum security, but a properly hardened WLAN can offer maximum practicality at the lowest cost. So, do I believe a VPN is the ultimate solution to WLAN security? Probably not, but, like all things IT, it depends. The final call on whether to secure your WLAN using existing best practices and standards or to just setup a VPN is ultimately up to you. It really boils down to what you're trying to protect and what lengths you're willing to go to to protect it. As long as you take the necessary steps, your airwaves should be plenty secure.


Kevin Beaver is the founder and principal consultant of Atlanta, GA-based information security services firm Principle Logic, LLC. He has over 16 years of experience in IT and specializes in information security assessments and incident response. Kevin is the author of Hacking For Dummies by Wiley Publishing and the free ebook The Definitive Guide to Email Management and Security by Realtimepublishers.com and co-author of the book The Practical Guide to HIPAA Privacy and Security Compliance by Auerbach Publications. He can be reached at kbeaver@principlelogic.com.


Rate this Tip
To rate tips, you must be a member of SearchNetworking.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Wide Area Networks
How WAN optimization and application acceleration improve branch office network performance
Remote Desktop troubleshooting
How the NetFlow protocol monitors your WAN
Network design: Five ways to lower your costs
Remote office backup, archiving and disaster recovery for networking pros
Troubleshooting WAN performance issues
Cisco CCIP MPLS certification: Introduction
Distribution of labels -- Cisco CCIP MPLS certification: Lesson 3
Configuring MPLS -- Cisco CCIP MPLS certification: Lesson 5
Configuring MPLS and VRF -- Cisco CCIP MPLS certification: Lesson 6

Virtual Private Networks
VPN clients for handheld devices
Networking Products of the Year 2004
MPLS and CE redundancy
Letting telecommuters in -- your VPN alternatives
Configuring MPLS experimental bits
The best of 2004
MPLS QoS models
Layer 2 VPN scalability
MPLS case study: Kodak
MPLS - Interoperability of customer QoS with provider QoS

VPN Design
Creating Remote Access and Site-to-Site VPNs with ISA Firewalls: from 'The Best Damn Firewall Book Period, Second Edition'
A basic virtualized enterprise -- from 'Network Virtualization'
How can I get our VPN to work on Windows Vista?
To set up a VPN server, do you need two NIC cards?
MPLS technology overview
How do I connect my VLANs to the Internet using NAT and the appropriately configured ACL?
What equipment do I use to connect two LANs in different cities? What are the steps?
Are there any architectures of IPsec VPN apart from lookaside and flow-through?
How can I access each device from my network while keeping the companies' networks secure?
VPN operating system interoperability -- Configure VPNs with Linux
VPN Design Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
extranet  (SearchNetworking.com)
Layer Two Tunneling Protocol  (SearchNetworking.com)
virtual private LAN service  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsWebcastsWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts