Wireless networks improve user productivity by enabling them to work anywhere in the office, but wireless networks also introduce security vulnerabilities. The hacker community is constantly working to develop new tools to connect to your wireless networks, intercept wireless communications or to simply disrupt your wireless communications. To protect the privacy of your data and keep your wireless network running, you need to regularly re-evaluate leading-edge wireless security technologies.
The good news is that makers of wireless networking equipment continue to enhance the security features of their products, and many of those designed for business use can be kept in sync through regular firmware or software updates. The key component of a wireless network, known as a wireless access points (APs), sport a robust spectrum of user authentication and data encryption features that can passively and actively protect you against a wide variety of attacks. These features include:
The following table shows a representative sample of APs and how they compare on security features.
| Feature |
Cisco Aironet [5]
|
||||
| Price |
$850 and up, plus Nortel WLAN Access Points [9]
|
$420 and up
|
$2,000 and up
|
$400 and up, includes firewall and router capabilities
|
$475 and up, includes firewall and router capabilities
|
| Dynamic WEP |
X
|
X
|
-
|
-
|
-
|
| WPA |
X
|
X
|
X
|
X
|
Pre-shared key only
|
| WPA2/ 802.11i |
X
|
X
|
-
|
X
|
-
|
| VPN |
-
|
-
|
X
|
X
|
-
|
| VLAN assignments |
X
|
X
|
X
|
X
|
X
|
| Wireless guest services |
X
|
-
|
-
|
X
|
X
|
| Centralized management |
X
|
X
|
X
|
X
|
X
|
| Intrusion prevention |
X
|
X
|
X
|
X
|
-
|
| Rogue AP detection |
X
|
X
|
-
|
X
|
-
|
| Antivirus |
-
|
-
|
-
|
X
|
X
|
| Anti-spyware |
-
|
-
|
-
|
X
|
-
|
This table doesn’t compare non-security features, so don’t base your buying decision on these factors alone. Additionally, many APs provide enhanced capabilities when matched with network hardware from the same vendor. Therefore, consider using the same vendor for your wired network infrastructure and wireless APs. The SonicWALL and Watchguard offerings are intended for smaller businesses, while the Nortel, Cisco and Fortress offerings are aimed at enterprises.
To aggressively protect yourself from rogue APs and clients, check out AirMagnet’s [10] laptop [11] and handheld [12] analyzers. With either product, you can detect and physically track down intruders attempting to connect to your internal network or preventing legitimate users from connecting with a denial-of-service attack. AirMagnet’s analyzers can also ensure connected devices conform to predetermined security policies and standards.
Unlike servers, APs often have to be placed in non-secured locations to enable the best reception. To help prevent an attacker from physically tampering with the hardware, consider a security cabinet designed for wireless access points [13]. Standard security cabinets may interfere with wireless signals.
Wireless network security has improved greatly in the last year, and you may need to upgrade your APs even if they are less than two years old. Fortunately, the cost of upgrading your APs is probably less than the cost of a successful exploit. For more information on wireless security, read 802.11 Security [14] from O’Reilly.
Links:
[1] http://support.microsoft.com/?id=893357
[2] http://www.cdw.com/shop/search/results.aspx?key=windows+server+2003&platform=pc&x=0&y=0
[3] http://www.microsoft.com/windowsserver2003/techinfo/overview/quarantine.mspx
[4] http://www.cdw.com/shop/search/results.aspx?key=nortel+wlan+security+switch&platform=all&x=0&y=0
[5] http://www.cdw.com/shop/search/results.aspx?key=cisco+aironet&platform=all&x=0&y=0
[6] http://www.cdw.com/shop/search/results.aspx?key=fortress+wireless&platform=all&x=0&y=0
[7] http://www.cdw.com/shop/search/results.aspx?key=sonicwal+TZ+wireless&platform=all&x=0&y=0
[8] http://www.cdw.com/shop/search/results.aspx?key=X5W+or+X15W+or+X50W&platform=all&x=0&y=0
[9] http://www.cdw.com/shop/search/results.aspx?key=nortel+wlan+access+point&platform=all&x=0&y=0
[10] http://www.cdw.com/shop/search/results.aspx?key=airmagnet&platform=all&x=0&y=0
[11] http://www.cdw.com/shop/products/default.aspx?EDC=816702
[12] http://www.cdw.com/shop/products/default.aspx?EDC=840981
[13] http://www.cdw.com/shop/search/results.aspx?key=wireless+cabinet&platform=all&x=0&y=0
[14] http://www.cdw.com/shop/products/default.aspx?EDC=675598