Home > Ask the Networking Experts > Wireless networking with Lisa Phifer Questions & Answers > Creating a WPA2 compliant network
Ask The Networking Expert: Questions & Answers
EMAIL THIS

Creating a WPA2 compliant network

Lisa Phifer EXPERT RESPONSE FROM: Lisa Phifer

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Wireless networks news, advice and technical information
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 12 October 2006

I have a large project where the customer wishes to use NetgearWAG102 access points with wireless Windows Mobile winCE.net devices. The customer has about 400 stores with about four to five mobile devices per store. Could you please explain the basic principles of creating a WPA2 compliant network in this environment?


>
EXPERT RESPONSE

WPA2 is available in two forms: WPA2-Personal for home and small office use, and WPA2-Enterprise for business use. Given your target application, you should use WPA2-Enterprise for strong, individual device authentication. You will require support WPA2-Enterprise support on your winCE.net devices and Netgear APs, and at least one RADIUS authentication server for 802.1X/EAP authentication.

Start with your mobile devices. Determine whether their Wi-Fi interfaces support WPA2-Enterprise; this may require installing driver upgrades. If WPA2 is not supported, use WPA instead. The Windows Mobile operating system supports 802.1X and several EAP types, but you'll need to choose an EAP type that meets your security needs and is supported by your devices as well. For example, Protected EAP (PEAP) would require configuring each mobile device with a username and password, while EAP-TLS would require installing a digital certificate on each device. If your mobile devices simply cannot support 802.1X, you may need to resort to WPA2-Personal in conjunction with MAC ACLs and a long, random PreShared Key.

Next, install, and configure a RADIUS authentication server to match the EAP type used by your mobile devices. You will need to create an account for each mobile device, either on the RADIUS server itself, or in a user database (e.g., Windows AD, LDAP database) that interfaces with your RADIUS server. The RADIUS server will be consulted each time a mobile device connects to the network, so give some consideration to where the RADIUS server should be placed, and if you really need more than one server for redundancy or performance. Depending on the EAP type, you will probably need to configure each authentication server with its own digital certificate.

The easiest component to configure will be your Netgear APs. In a WPA2-Enterprise network, APs serve as the middle man, relaying access requests from wireless clients to a RADIUS authentication server. WAG102 APs support WPA2-Enterprise, so just configure them with your authentication server's IP address and RADIUS shared secret. Beware that RADIUS protocol can expose sensitive information, so communication between APs and your authentication server(s) should be protected -- for example, using a site to site VPN to connect stores to a centrally-located server.

To learn more, read our Wireless LAN Security Lunchtime Learning Series tip about WPA2.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Wireless networking with Lisa Phifer
Problem connecting to virtual private network (VPN) through Linksys router
Why wireless network cards show activity when no one uses the computer
Wireless networking problems 802.11g and 802.11n access points cause
How to implement VLAN switches across wireless LAN (WLAN) links
Are there 802.11n wireless network range extenders to boost my signal?
How does WiMAX compare to other wireless broadband services?
How many more users will 802.11n wireless access points support?
Accessing printers on a LAN while connected to a WLAN
How to maintain corporate VPN connection while printing to a private network
How to connect wireless networks for printing capabilities

Wireless Network Management
Voice over wireless LAN is on the rise: Prepare your networks
Measure wireless network performance using testing tool iPerf
Wireless network reporting tool: Graph performance behavior with Pilot
HP ProCurve-Colubris deal signals WLAN market consolidation
How to prioritize wireless traffic
7/11 chain cuts out controller to lower wireless networking costs
Cisco smartens up the wireless network with Motion platform
Book of Wireless author on wireless advantages and issues
Upgrading to 802.11n: Key considerations
Prevent IP address conflicts on your wireless network by managing DHCP scopes
Wireless Network Management Research

Wireless Network Implementation
Voice over wireless LAN is on the rise: Prepare your networks
Wireless networking problems 802.11g and 802.11n access points cause
Wireless LAN tips from Iraq: Networking Joint Base Balad
Wireless LAN vulnerabilities
Are there 802.11n wireless network range extenders to boost my signal?
Accessing printers on a LAN while connected to a WLAN
Will different wireless card link speeds cause network latency?
Open source authenticator implementation for LANs: How is open1x an 802.1X supplicant?
How do I increase network signal strength over a large distance?
Wireless deployment tips: How Amtrak deployed Wi-Fi on its trains

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
802.11a  (SearchNetworking.com)
home agent  (SearchNetworking.com)
iDEN  (SearchNetworking.com)
radio frequency  (SearchNetworking.com)
repeater  (SearchNetworking.com)
spectrum analyzer  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Expert networking advice and tips for IT professionals
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts