Types of authentication in wireless networks🔗
6.1 Authentication methods in wireless networks🔗
Server-based authentication (WPA2/WPA3-Enterprise).🔗
Used in corporate networks and large organisations. The 802.1X mechanism provides individual logins and passwords for users.
Authentication process
Supplicant (client) - the device that requests access.
Authenticator - the Wi-Fi access point (Access Point) that forwards the request to the server
Authentication Server - the RADIUS server that checks the credentials
Certificate-based authentication🔗
Used in corporate and government networks.
Requires issuing digital certificates to devices or users.
Provides high security through encryption and unique certificates
Application:
Logging in with certificates, usernames and passwords.
Possibility to use different authentication methods, e.g. EAP-TLS
Portal Captive (Captive Portal Authentication)🔗
Used in public areas such as airports, hotels. Once connected, the user is redirected to a login page.
The authentication process may require:.
Registration on the site
Entering a password provided by the administrator
Access fee (e.g. at paid hotspots).
MAC Address Filtering🔗
The Wi-Fi access point only allows devices with **registered MAC addresses to connect.
A simple authorisation method, but easy to bypass by modifying the MAC address.
6.2 Discussion of WLAN configuration in NACVIEW🔗
The configuration of the wireless network in NACVIEW is very simple, but at the same time important from the point of view of creating access policies. As a result of the previous points, we already have subnet addresses and VLANs assigned to them in the system. In order to be able to create a policy for a wirelessly broadcast network, it is necessary to add their SSID in NACVIEW. The next step is to add the network devices through which the wireless network will be broadcast.
6.3 Adding a WiFi AP/controller🔗
In the main menu, go to Network Devices under Networks. Click Add a new item and complete the form:
select the device model (e.g. Acces Point or WiFi Controller Enter the number of physical ports on the device, name and IP address
click Change/set password to configure RADIUS passwords Enter the RADIUS key set on the device and repeat the password
if you have created a group for network devices, select it from the Object Groups list
click Save. On the next screen (Credentials settings) we have the possibility to select the login data for the device for the different connection protocols
then Next to proceed to the summary
in the Monitoring section, check the SNMP settings and save
if the device supports CoA:
click Edit Disconnect
fill in the port number (default 3799)
enter the RADIUS password Select the device manufacturer name
click Save - the device has been added
6.4 Configuring the WLAN network in NACVIEW🔗
in the WiFi networks menu, click Add new item.
name the network and enter its SSID (in the access policy section, add a new rule for the wireless network)
select the VLAN, devices and change the network type to wireless
click Save and Install List.
6.5 Access policy🔗
From the main menu, select Access Policies under Configuration. Click Add a rule. 3. name the policy 4. select the authentication method (e.g. MAC) and action VLAN access. 5. indicate the VLAN and:
Endpoint - select MAC address or address group.
Network devices - select a device or device group In the Network section, change the network type to wireless and select a network from the list
click Save and then the yellow button Install list.
Note: Remember to install the access policy list when you make changes or add a policy. Until a new list is installed, network access is governed by the previous installed list.