{"id":2452,"date":"2014-11-22T22:59:48","date_gmt":"2014-11-22T22:59:48","guid":{"rendered":"https:\/\/thebeagle.itgroove.net\/?p=1905"},"modified":"2023-02-24T21:39:50","modified_gmt":"2023-02-24T21:39:50","slug":"uncle-robs-primers-wifi-and-a-secure-network","status":"publish","type":"post","link":"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/","title":{"rendered":"Uncle Rob&#8217;s Primers &#8212; WiFi and a Secure Network"},"content":{"rendered":"<p>This is another one of those oh-so-obvious things that you think are \u201cself-evident\u201d but which seem to get lost is the overall scheme of things.\u00a0 So what is it that I am talking about?\u00a0 Well, I&#8217;ll tell you, it&#8217;s about practicing \u201csafe wireless\u201d within your organization!<\/p>\n<p>OK, so what am I referring to with the term \u201csafe wireless\u201d?\u00a0 Well, this one is pretty simple \u2014 it&#8217;s about doing all the things that should be done to separate and segregate CORPORATE or ORGANIZATIONAL data traffic from GUEST or FOREIGN data traffic.\u00a0 It&#8217;s a simple concept, really, but one that I find more and more companies are messing up\u00a0in the mad rush to provide connectivity to the flood of devices that are showing up in offices on a daily basis.<\/p>\n<p>Example:\u00a0 I have been working with a client that has multiple physical locations and a less than \u201csolid\u201d network security policy.\u00a0 They asked us\u00a0 to \u201clock down\u201d the networks at a number of locations after a recent Cryptowall attack.\u00a0 We provided Sonicwall UTM firewalls so that there would be at one \u201ccontrolled\u201d point of ingress\/egress on their networks which would also do all the standard UTM scanning on traffic to\/from their networks.\u00a0 These units were to replace a mishmash of consumer-grade firewalls.\u00a0 All well and good and proper, specially so for corporate networks.\u00a0 Problem is the plan was blown out of the water when I discovered that each location was providing \u201cpublic\u201d WiFi access using open consumer-grade WiFi access points on the CORPORATE LAN without any sort of traffic segregation abilities.\u00a0 Talk about leaving the door wide open!<\/p>\n<p>There is little point in trying to control access to\/from your network with commercial-grade firewalls if you allow unfettered \u201cforeign\u201d access to your networks through the indiscriminate use of open WiFi access points and routers.<\/p>\n<p>So, how do you go about providing WiFi for all those devices?\u00a0 That&#8217;s a good question and I&#8217;ll try to give some good answers. There is nothing wrong with wanting to provide WiFi access, you just have to plan for the required security.<\/p>\n<p>First off, you should do everything you can to separate and segregate CORPORATE traffic from everything else.\u00a0 Wherever possible, WiFi access should be on a completely separate network from your corporate network.\u00a0 The separate network could be completely separate physical cable runs for access points with the runs terminated at a firewall that can handle multiple networks with firewall rules between the networks.\u00a0 Or, alternatively, you could have a similar scenario with VLAN&#8217;s substituting for the physical networks.\u00a0 In either case, you are putting a \u201cwall\u201d between your precious corporate traffic and that which is NOT corporate traffic.<\/p>\n<p>Scenarios like the above can be accomplished with many commercial grade firewalls and commercial WiFi gear.\u00a0 Some vendors, such as Sonicwall, have firewall\/WiFi gear combinations that allow you to build a single vendor solution.\u00a0 The point is, the equipment is available to build solutions like this.<\/p>\n<p>Another option is to use WiFi gear that can provide \u201cvirtual access points\u201d so that traffic connected to a \u201cguest\u201d access point cannot \u201csee\u201d or access resources on the internal network; traffic through the access point is allowed to only go out to the Internet.\u00a0 There are lots of consumer-grade firewalls and access points that incorporate this type of ability but I would not recommend them in a corporate environment due to the large number of security issues that seem to plague consumer-level gear.\u00a0 However, there are some excellent commercial-grade vendors that provide gear that can perform this function, an example is enGenius.\u00a0 For lack of a better way of describing how they work, the access points essentially \u201ctunnel\u201d guest traffic over your network and out through your gateway to the Internet and block access to the LAN.\u00a0 I still prefer and recommend\u00a0separate networks or VLAN&#8217;s but, if they are not an option then this is the next best way to go providing you are using commercial-grade gear.<\/p>\n<p>Another thing you need to keep in mind is the bandwidth that can be consumed by all of the connected WiFi devices.\u00a0 I see this all the time, customers complaining their network is \u201cslow\u201d when, in fact, it is saturated due to the large number of WiFi devices that are connected and consuming resources.\u00a0 Going down the route of physically separating your networks and even physically separating the Internet feeds for the corporate network from the WiFI network can make a very big difference in how things work.\u00a0 If you are on small Internet \u201cpipes\u201d you really want to make sure that corporate resources get the bandwidth they require.\u00a0 Having a guest network overlaid on top of your corporate network, even if properly secured, can be a great way to deny needed resources from your corporate users.\u00a0 If you can provide separate Internet feeds for corporate and guest then so much the better.\u00a0 If you can&#8217;t then you do want to be able to throttle how much overall bandwith is given to the guest access.\u00a0 This is accomplished with tools in the access points or tools in the firewall, all of which, again, should be commercial-grade.<\/p>\n<p>Keeping all of this in mind when you build\/expand your network can help close a lot of security holes before they happen.\u00a0 Of course, there is a whole other discussion to be had regarding granting employee&#8217;s devices WiFi access to your corporate assets but that is a topic for another post.\u00a0 Do the best you can to follow the segregate\/separate mantra and you will go a long way towards making your network as secure as you can.<\/p>\n<div class=\"bjtags\">Tags: <a href=\"http:\/\/technorati.com\/tag\/wifi,+security\" rel=\"tag\">wifi,+security<\/a><\/div>\n","protected":false},"excerpt":{"rendered":"<p>This is another one of those oh-so-obvious things that you think are \u201cself-evident\u201d but which seem to get lost is the overall scheme of things.\u00a0 So what is it that I am talking about?\u00a0 Well, I&#8217;ll tell you, it&#8217;s about practicing \u201csafe wireless\u201d within your organization! OK, so what am I referring to with the &hellip; <a href=\"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/\"><\/a><\/p>\n","protected":false},"author":10,"featured_media":2109,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[49,275],"tags":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Uncle Rob&#039;s Primers - WiFi and a Secure Network - Archive<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Uncle Rob&#039;s Primers - WiFi and a Secure Network - Archive\" \/>\n<meta property=\"og:description\" content=\"This is another one of those oh-so-obvious things that you think are \u201cself-evident\u201d but which seem to get lost is the overall scheme of things.\u00a0 So what is it that I am talking about?\u00a0 Well, I&#8217;ll tell you, it&#8217;s about practicing \u201csafe wireless\u201d within your organization! OK, so what am I referring to with the &hellip;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/\" \/>\n<meta property=\"og:site_name\" content=\"Archive\" \/>\n<meta property=\"article:published_time\" content=\"2014-11-22T22:59:48+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-02-24T21:39:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2014\/11\/halt-clipart-halt-man-md-e1442701865399.png\" \/>\n\t<meta property=\"og:image:width\" content=\"200\" \/>\n\t<meta property=\"og:image:height\" content=\"184\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Sean Wallbridge\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sean Wallbridge\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/\",\"url\":\"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/\",\"name\":\"Uncle Rob's Primers - WiFi and a Secure Network - Archive\",\"isPartOf\":{\"@id\":\"https:\/\/regroove.ca\/archive\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2014\/11\/halt-clipart-halt-man-md-e1442701865399.png\",\"datePublished\":\"2014-11-22T22:59:48+00:00\",\"dateModified\":\"2023-02-24T21:39:50+00:00\",\"author\":{\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77\"},\"breadcrumb\":{\"@id\":\"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/#primaryimage\",\"url\":\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2014\/11\/halt-clipart-halt-man-md-e1442701865399.png\",\"contentUrl\":\"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2014\/11\/halt-clipart-halt-man-md-e1442701865399.png\",\"width\":200,\"height\":184},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog Archive\",\"item\":\"https:\/\/regroove.ca\/archive\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Uncle Rob&#8217;s Primers &#8212; WiFi and a Secure Network\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/regroove.ca\/archive\/#website\",\"url\":\"https:\/\/regroove.ca\/archive\/\",\"name\":\"Archive\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/regroove.ca\/archive\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77\",\"name\":\"Sean Wallbridge\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g\",\"caption\":\"Sean Wallbridge\"},\"url\":\"https:\/\/regroove.ca\/archive\/author\/swallbridge\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Uncle Rob's Primers - WiFi and a Secure Network - Archive","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/","og_locale":"en_US","og_type":"article","og_title":"Uncle Rob's Primers - WiFi and a Secure Network - Archive","og_description":"This is another one of those oh-so-obvious things that you think are \u201cself-evident\u201d but which seem to get lost is the overall scheme of things.\u00a0 So what is it that I am talking about?\u00a0 Well, I&#8217;ll tell you, it&#8217;s about practicing \u201csafe wireless\u201d within your organization! OK, so what am I referring to with the &hellip;","og_url":"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/","og_site_name":"Archive","article_published_time":"2014-11-22T22:59:48+00:00","article_modified_time":"2023-02-24T21:39:50+00:00","og_image":[{"width":200,"height":184,"url":"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2014\/11\/halt-clipart-halt-man-md-e1442701865399.png","type":"image\/png"}],"author":"Sean Wallbridge","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sean Wallbridge","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/","url":"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/","name":"Uncle Rob's Primers - WiFi and a Secure Network - Archive","isPartOf":{"@id":"https:\/\/regroove.ca\/archive\/#website"},"primaryImageOfPage":{"@id":"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/#primaryimage"},"image":{"@id":"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/#primaryimage"},"thumbnailUrl":"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2014\/11\/halt-clipart-halt-man-md-e1442701865399.png","datePublished":"2014-11-22T22:59:48+00:00","dateModified":"2023-02-24T21:39:50+00:00","author":{"@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77"},"breadcrumb":{"@id":"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/#primaryimage","url":"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2014\/11\/halt-clipart-halt-man-md-e1442701865399.png","contentUrl":"https:\/\/regroove.ca\/archive\/wp-content\/uploads\/sites\/6\/2014\/11\/halt-clipart-halt-man-md-e1442701865399.png","width":200,"height":184},{"@type":"BreadcrumbList","@id":"https:\/\/regroove.ca\/archive\/2014\/11\/22\/uncle-robs-primers-wifi-and-a-secure-network\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog Archive","item":"https:\/\/regroove.ca\/archive\/"},{"@type":"ListItem","position":2,"name":"Uncle Rob&#8217;s Primers &#8212; WiFi and a Secure Network"}]},{"@type":"WebSite","@id":"https:\/\/regroove.ca\/archive\/#website","url":"https:\/\/regroove.ca\/archive\/","name":"Archive","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/regroove.ca\/archive\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77","name":"Sean Wallbridge","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g","caption":"Sean Wallbridge"},"url":"https:\/\/regroove.ca\/archive\/author\/swallbridge\/"}]}},"_links":{"self":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/2452"}],"collection":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/comments?post=2452"}],"version-history":[{"count":1,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/2452\/revisions"}],"predecessor-version":[{"id":2845,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/2452\/revisions\/2845"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/media\/2109"}],"wp:attachment":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/media?parent=2452"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/categories?post=2452"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/tags?post=2452"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}