# Types of authentication in wireless networks

## 6.1 Authentication methods in wireless networks

### Server-based authentication (WPA2/WPA3-Enterprise).

Used in corporate networks and large organisations. The **802.1X** mechanism provides individual logins and passwords for users.

Authentication process
* **Supplicant (client)** - the device that requests access.
* **Authenticator** - the Wi-Fi access point (Access Point) that forwards the request to the server
* **Authentication Server** - the **RADIUS** server that checks the credentials

### Certificate-based authentication

* Used in **corporate** and **government** networks.
* Requires issuing **digital certificates** to devices or users.
* Provides **high security** through encryption and unique certificates

**Application:**
* Logging in with certificates, usernames and passwords.
* Possibility to use different authentication methods, e.g. **EAP-TLS**

### Portal Captive (Captive Portal Authentication)

Used in public areas such as **airports**, **hotels**. Once connected, the user is redirected to a login page.

**The authentication process may require:**.
* Registration on the site
* Entering a password provided by the administrator
* Access fee (e.g. at paid hotspots).

### MAC Address Filtering

* The Wi-Fi access point only allows devices with **registered MAC addresses to connect.
* A simple authorisation method, but easy to bypass by modifying the MAC address.

## 6.2 Discussion of WLAN configuration in NACVIEW

The configuration of the wireless network in NACVIEW is very simple, but at the same time important from the point of view of creating access policies. As a result of the previous points, we already have subnet addresses and VLANs assigned to them in the system. In order to be able to create a policy for a wirelessly broadcast network, it is necessary to add their SSID in NACVIEW. The next step is to add the network devices through which the wireless network will be broadcast.

## 6.3 Adding a WiFi AP/controller

1) In the main menu, go to **Network Devices** under **Networks**.
Click **Add a new item** and complete the form:
  	- select the device model (e.g. **Acces Point** or **WiFi Controller**
   Enter the number of physical ports on the device, name and IP address
   - click **Change/set password** to configure RADIUS passwords
   Enter the RADIUS key set on the device and repeat the password
3. if you have created a group for network devices, select it from the **Object Groups** list
4. click **Save**. On the next screen (Credentials settings) we have the possibility to select the login data for the device for the different connection protocols
5. then **Next** to proceed to the summary
6. in the **Monitoring** section, check the SNMP settings and save
7. if the device supports CoA:
   - click **Edit Disconnect**
   - fill in the port number (default **3799**)
   - enter the RADIUS password
   Select the device manufacturer name
8. click **Save** - the device has been added

## 6.4 Configuring the WLAN network in NACVIEW

1. in the **WiFi networks** menu, click **Add new item**.
2. name the network and enter its SSID (in the access policy section, add a new rule for the wireless network)
4. select the VLAN, devices and change the network type to wireless
5. click **Save** and **Install List**.

## 6.5 Access policy

From the main menu, select **Access Policies** under **Configuration**.
Click **Add a rule**.
3. name the policy
4. select the authentication method (e.g. MAC) and action **VLAN access**.
5. indicate the VLAN and:
   1. **Endpoint** - select MAC address or address group.
   2. **Network devices** - select a device or device group
In the **Network** section, change the network type to wireless and select a network from the list
7. click **Save** and then the yellow button **Install list**.

> **Note**: Remember to install the access policy list when you make changes or add a policy. Until a new list is installed, network access is governed by the previous installed list.

