Your wireless network

Size: px
Start display at page:

Download "Your wireless network"

Transcription

1 Your wireless network How to ensure you are meeting Government security standards Cabinet Office best practice Wi-Fi guidelines Overview Cyber Security is a hot topic but where do you start? The Cabinet Office has provided some assistance for the Public Sector, to help them secure wireless networks, and produced a set of guidelines on Sharing Workplace Wireless Networks. These guidelines were produced by the Cabinet Office as a direct result of their in-depth technical evaluation of the leading Enterprise Wi-Fi solutions for their own Wi-Fi project. The winning solution had several innovative features including a cloud management platform and a more secure and flexible architecture with distributed controllers in each Access Point instead of a central controller. As a result the official Wi-Fi guidelines were updated to describe how these features could enhance security. This document builds on the Cabinet Office experience and provides a summary checklist of the features required in enterprise Wi-Fi when implementing a secure wireless solution compliant with government guidelines. Download the official guidelines here: 1

2 Onboarding users and devices to Wi-Fi There are two approved methods of providing authenticated access to a government Wi-Fi network depending on the type of device used. Access for guests or users with unknown, non-managed devices (generally referred to as BYOD) should follow method 1. If access is required for users with known, fully managed (corporate) devices, method 2 should be followed. Both methods should adhere to these basic rules: Only basic internet access should be provided through Wi-Fi Always use VPNs to provide access to privileged resources and servers Access method 1 - BYOD, Guest, or GovWifi service devices Sometimes referred to as user.wifi in the guidelines Use this method when: The device is owned by the user or third party organisation The device is owned by the organisation but uses internet cloud services only and manages the device using mobile device management You use a strict always-on VPN This method should always: Access method 2 - For managed devices Sometimes referred to as device.wifi in the guidelines Use this method when: The user has a managed device without an always-on VPN The user has a managed device with a selective always-on VPN policy which allows direct communication on trusted networks Choose an enterprise WLAN solution that provides Device and Client Certification through a Radius server using Active Directory Credentials and a Certification Authority (CA). This method uses Public Key Infrastructure (PKI) certificates installed on the managed devices to provide strong authentication of devices and users: Require user sign up Provide access to the internet only Prohibit users from accessing any internal systems Choose an enterprise WLAN solution that provides Client Certification through a Radius server using Active Directory Credentials. They can t be stolen by rogue networks They are almost impossible to extract from devices when the private key is stored in a trusted platform module or smart card Certificates should be checked for validity using an up to date certificate revocation list (CRL) or using Online Certificate Status Protocol (OCSP). Choose an enterprise WLAN solution that provides Private Pre Shared Keys for added security. 2

3 Roaming To allow secure roaming between participating buildings within an infrastructure, choose an enterprise WLAN solution that supports: Public Key Infrastructure certificates with per user Private Pre Shared Keys Easy onboarding of users look for examples of integrations using APIs that automate self-registration Standardising the process by which access is provided to a specific set of SSIDs Limiting the SSIDs broadcast to approved locations and documents exceptions For more information on setting up a secure wireless network for roaming read this government blog: To allow the use of external authentication systems such as Govroam, Eduroam or GovWifi choose an enterprise WLAN solution that supports: WPA2-Enterprise Advanced Encryption Standard (AES) Microsoft Challenge Handshake Authentication Protocol (MS-CHAPv2) Protected Extensible Authentication Protocol (PEAPv0) EAP method When configuring the network to allow external authentication for Government employees from trusted systems such as Govroam, Eduroam or GovWifi, do not: Implement unencrypted or open networks Implement captive portals - these interfere with always-on VPNs Allow the user to choose their password - they could reuse the passwords they use for other government services Allow access to internal or privileged networks - these should only be accessible using certificates or a VPN client Use public pre-shared keys (PSKs) as they provide little privacy between users use a solution providing per user Private Pre-Shared Keys Network separation Choose an enterprise WLAN solution that provides: Isolation by SSID and certificate authority (CA), identified by a device certificate Dual Ethernet APs to allow separation of networks within the APs Support for encrypted tunnels between APs and VPN concentrator A firewall to separate IP addressing, routing and access controls for each Wi-Fi network VLAN and SSID separation if using multi-tenant environments QoS by Application and SSID, with bandwidth limitation applied for each SSID as well as each user The capability to ensure that all clients pass through a gateway device before communicating with devices on the same network and ensuring that only approved services can be accessed 3

4 Coverage Choose an enterprise WLAN solution with these considerations: Automatic channel selection features Centrally managed AP hardware 5 GHz frequency band and ac support + ac wave 2 and MIMO support Ensure there s sufficient uplink bandwidth from APs to the building switch infrastructure Use at - type 2 capable switches to power the APs and futureproof the installation Disable low-bandwidth Wi-Fi protocols like a and g on the 5 GHz band and confine legacy clients to the 2.4 GHz band Ability to broadcast provide SSIDs only to required areas Ability to disable 2.4 GHz radios on APs in large open plan areas to reduce interference Ability to manage channel width and implement channel bonding with fall back to a non-overlapping channel Ability to enable dynamic frequency selection (DFS) or h for 5 GHz band Ability to enable band steering which works by regulating probe responses to clients and making 5 GHz channels appear more attractive to clients by delaying probe responses to clients on 2.4 GHz Ability to enable standards based (802.11r) support for smoother roaming for devices on the move Ability to enable Wi-Fi Voice Enterprise or equivalent if voice support is required Administration and monitoring Choose an enterprise WLAN solution with these considerations: Ability to configure an Acceptable Use Policy against an SSID Provides central management and reports of usage and trends with historical network activity and heat maps to provide a visual insight into coverage and use Allow API connection and provide analysis of location data to improve business operations, like real time people finder, crowd management and emergency response, queue length reporting, hot desk/meeting room usage and path planning Security and availability Choose an enterprise WLAN solution which: Enables central management to provide non-obtrusive software upgrades with minimal disruption Protects access to all network infrastructure management interfaces either directly or indirectly using two-factor authentication 4

5 Wired LAN requirements The security and performance of the WLAN is heavily dependent on the wired LAN. This should be configured as follows: Wireless network names and authentication Choose an enterprise WLAN solution that: Provides an easy onboarding process for users to sign up to BYOD, Guest, GovWifi (user.wifi) Provides access to the internet only Does not allow users to access any internal systems Provides per user Private Key Self-Registration against Active Directory Automatically and securely connects government managed devices to device.wifi Gives devices access to internal local area network (LAN) resources in home buildings or shared buildings following the shared WAN guidance Doesn t require any user set up - it just works Gives devices access to the internet for a VPN when roaming Can be deployed alongside a VPN client to switch seamlessly between a trusted home network and VPN using the same authentication infrastructure Authenticates devices securely using certificates Provide uplinks at least twice the bandwidth of the fastest user connection to avoid one person impacting the network Implement QoS where appropriate Shared LANs use 802.1x certificate-based authentication or restriction to an authorised MAC address on every accessible floor port Use the same authentication methods and servers for both Wi-Fi and wired LAN ports Block guest access on wired LAN ports Local RADIUS server returns vendor specific attributes (VSAs) to allow the client to access the locally allocated VLAN Use the local RADIUS server, if required, to filter and rewrite VSAs received from the central RADIUS proxy Do not span VLANs between shared and non-shared switches without agreement to share a spanning tree instance and mitigate the impact of a broadcast storm 5

6 Implement the design Choose an enterprise WLAN installation partner that: Has relevant experience of installing secure wireless networks that meet the criteria described in this document Provides Prince 2 qualified Project Management Recommends a Capacity Survey, Coverage Survey and Mounting Survey to identify all the risks prior to design and installation Includes both logical and physical constraints in the Rick Assessment and Method Statements Differentiates between general coverage and high capacity Identifies structured cabling requirements for APs with 2 Cat5e or Cat6 connections per AP Considers network architecture and Switch requirements especially with regard to PoE support for APs Includes an assessment of Cyber Security requirements Further reading For more information on the Cabinet Office case study that inspired the guidelines, visit the link below: To find out more about how to design and implement a compliant, secure Wi-Fi network, visit the link below: network-security/ Contact For more information on how to deploy intelligent Wi-Fi please get in touch. Call or visit our website 6

NHS WI-FI Technical and Security Policies and Guidelines

NHS WI-FI Technical and Security Policies and Guidelines Document filename: NHS WIFI Policies and Guidance Project / Programme NHS Wi-Fi Project NHS Wi-Fi Document Reference NWS_WIFI_POLGUID Project Manager Andy Smith Status Approved Owner David Corbett Version

More information

Wireless LAN Solutions

Wireless LAN Solutions Wireless LAN Solutions Juniper Networks delivers wireless solutions for enterprises of all sizes and types from small retail installations to the largest campuses Your JUNIPER NETWORKS dedicated Sales

More information

Exam Questions CWSP-205

Exam Questions CWSP-205 Exam Questions CWSP-205 Certified Wireless Security Professional https://www.2passeasy.com/dumps/cwsp-205/ 1.. What is one advantage of using EAP-TTLS instead of EAP-TLS as an authentication mechanism

More information

BYOD: BRING YOUR OWN DEVICE.

BYOD: BRING YOUR OWN DEVICE. white paper BYOD: BRING YOUR OWN DEVICE. On-BOaRDING and Securing DEVICES IN YOUR Corporate NetWORk PrepaRING YOUR NetWORk to MEEt DEVICE DEMaND The proliferation of smartphones and tablets brings increased

More information

HiveManager Local Cloud

HiveManager Local Cloud DATA SHEET HiveManager Local Cloud Enterprise Access Network Management Offering Intuitive Configuration Workflows, Real-Time & Historical Monitoring, and Simplified Troubleshooting DATASHEET HiveManager

More information

Prepare Your Network for BYOD. Meraki Webinar Series

Prepare Your Network for BYOD. Meraki Webinar Series Prepare Your Network for BYOD Meraki Webinar Series 1 Agenda Introduction to Meraki and Cloud Networking BYOD objectives Taming BYOD: capacity, security & management Design considerations Live demos Product

More information

Securing Cisco Wireless Enterprise Networks ( )

Securing Cisco Wireless Enterprise Networks ( ) Securing Cisco Wireless Enterprise Networks (300-375) Exam Description: The 300-375 Securing Wireless Enterprise Networks (WISECURE) exam is a 90minute, 60-70 question assessment that is associated with

More information

Configuring a VAP on the WAP351, WAP131, and WAP371

Configuring a VAP on the WAP351, WAP131, and WAP371 Article ID: 5072 Configuring a VAP on the WAP351, WAP131, and WAP371 Objective Virtual Access Points (VAPs) segment the wireless LAN into multiple broadcast domains that are the wireless equivalent of

More information

Ubiquiti UniFi AC Dual-Radio Access Point with 1300Mbps / 600ft range / 24V Passive PoE

Ubiquiti UniFi AC Dual-Radio Access Point with 1300Mbps / 600ft range / 24V Passive PoE Innovative Antenna Design Designed for Optimal RF Performance Scalable Enterprise Wi-Fi Management Overview UQ-UAP-AC-LR 1/5 Scalable Enterprise Wi-Fi Management UniFi is the revolutionary Wi-Fi system

More information

Ruckus ZoneDirector 3450 WLAN Controller (up to 500 ZoneFlex Access Points)

Ruckus ZoneDirector 3450 WLAN Controller (up to 500 ZoneFlex Access Points) Product Name: Manufacturer: - Model Number: 901-3450-UK00 Ruckus ZoneDirector 3450 supporting up to 500 ZoneFlex APs (901-3450-UK00) The Ruckus ZoneDirector 3450, The First Simple and Powerful Enterprise

More information

Ruckus ZoneDirector 1106 WLAN Controller (up to 6 ZoneFlex Access Points)

Ruckus ZoneDirector 1106 WLAN Controller (up to 6 ZoneFlex Access Points) Product Name: Manufacturer: - Model Number: 901-1106-UK00 Please Note: The Ruckus ZoneDirector 1106 has been discontinued. For an alternative, we recommend the Ruckus ZoneDirector 1205. Ruckus ZoneDirector

More information

A connected workforce is a more productive workforce

A connected workforce is a more productive workforce A connected workforce is a more productive workforce D-Link wireless networking solutions enable business networks of all sizes to create highly mobile, highly productive work environments at a low total

More information

NHS WIFI Technical and Security Policies and Guidelines

NHS WIFI Technical and Security Policies and Guidelines Document filename: NHS WIFI Policies and Guidance Project / Programme NHS WiFi Project NHS WiFi Document Reference NWS_WIFI_POLGUID Project Manager Donna Braisby Status Approved Owner David Corbett Version

More information

802.11ac 3x3 Dual Band High-Powered Wireless Access Point/Client Bridge

802.11ac 3x3 Dual Band High-Powered Wireless Access Point/Client Bridge Datasheet ECB1750 802.11ac 3x3 Dual Band High-Powered Wireless Access Point/Client Bridge The ECB1750 marks a new speed and performance breakthrough for users with 802.11ac laptops and other devices, who

More information

PROTECTED EXTENSIBLE AUTHENTICATION PROTOCOL

PROTECTED EXTENSIBLE AUTHENTICATION PROTOCOL Q&A PROTECTED EXTENSIBLE AUTHENTICATION PROTOCOL This document answers questions about Protected Extensible Authentication Protocol. OVERVIEW Q. What is Protected Extensible Authentication Protocol? A.

More information

SOLUTION OVERVIEW THE ARUBA MOBILE FIRST ARCHITECTURE

SOLUTION OVERVIEW THE ARUBA MOBILE FIRST ARCHITECTURE SOLUTION OVERVIEW THE ARUBA MOBILE FIRST ARCHITECTURE March 2018 Table of Contents Introduction...1 Design...2 Use Cases...2 Underlay...3 Overlay...3 Dynamic Segmentation...3 Non-Stop Networking...4 Summary...5

More information

OWL630 OUTDOOR ACCESS POINT

OWL630 OUTDOOR ACCESS POINT OWL630 OUTDOOR ACCESS POINT Wireless INTRODUCTION The OWL630 is an enterprise-grade, concurrent dual-band 802.11ac outdoor access point, designed specifically to withstand harsh weather conditions in outdoor

More information

The following chart provides the breakdown of exam as to the weight of each section of the exam.

The following chart provides the breakdown of exam as to the weight of each section of the exam. Introduction The CWSP-205 exam, covering the 2015 objectives, will certify that the successful candidate understands the security weaknesses inherent in WLANs, the solutions available to address those

More information

Datasheet. Enterprise WiFi System. Models: UAP, UAP-LR, UAP-Pro, UAP-Outdoor, UAP-Outdoor5. Unlimited Indoor/Outdoor AP Scalability in a

Datasheet. Enterprise WiFi System. Models: UAP, UAP-LR, UAP-Pro, UAP-Outdoor, UAP-Outdoor5. Unlimited Indoor/Outdoor AP Scalability in a Enterprise WiFi System Models: UAP, UAP-LR, UAP-Pro, UAP-Outdoor, UAP-Outdoor5 Unlimited Indoor/Outdoor AP Scalability in a 1 The UniFi Enterprise WiFi System is a scalable enterprise access point solution

More information

Release Notes for Avaya WLAN 9100 AOS-Lite Operating System WAP9112 Release WAP9114 Release 8.1.0

Release Notes for Avaya WLAN 9100 AOS-Lite Operating System WAP9112 Release WAP9114 Release 8.1.0 WLAN 9100 Release Notes Release Notes for Avaya WLAN 9100 AOS-Lite Operating System WAP9112 Release 8.1.0 WAP9114 Release 8.1.0 Avaya Inc - External Distribution 1. Introduction This document provides

More information

Wireless LAN, WLAN Security, and VPN

Wireless LAN, WLAN Security, and VPN Wireless LAN, WLAN Security, and VPN 麟瑞科技台南辦事處技術經理張晃崚 WLAN & VPN FAQ What is WLAN?802.11a?802.11b?802.11g? Which standard (product) should we use? How to deploy WLAN? How to block intruders? How to authenticate

More information

The Aruba S3500 Mobility Access Switch

The Aruba S3500 Mobility Access Switch Tech Brief Enterprise The Aruba S3500 Mobility Access Switch Tech Brief: The Aruba S3500 Mobility Access Switch Table of Contents Introducing the Aruba S3500 Mobility Access Switch... 2 Flexible deployment

More information

Standard For IIUM Wireless Networking

Standard For IIUM Wireless Networking INTERNATIONAL ISLAMIC UNIVERSITY MALAYSIA (IIUM) Document No : IIUM/ITD/ICTPOL/4.3 Effective Date : 13/11/2008 1.0 OBJECTIVE Standard For IIUM Wireless Networking Chapter : Network Status : APPROVED Version

More information

Wireless AC1750 Wave 2 Dual-Band PoE Access Point

Wireless AC1750 Wave 2 Dual-Band PoE Access Point Product Highlights Enjoy High-Performance Wireless Connectivity Harness the power of IEEE 802.11ac Wave 2 wireless and experience wireless speeds of up to 1750 Mbps 1, perfect for high-demand business

More information

Cisco Securing Cisco Wireless Enterprise Networks (WISECURE) Download Full Version :

Cisco Securing Cisco Wireless Enterprise Networks (WISECURE) Download Full Version : Cisco 300-375 Securing Cisco Wireless Enterprise Networks (WISECURE) Download Full Version : https://killexams.com/pass4sure/exam-detail/300-375 QUESTION: 42 Which two considerations must a network engineer

More information

Exam HP2-Z32 Implementing HP MSM Wireless Networks Version: 7.1 [ Total Questions: 115 ]

Exam HP2-Z32 Implementing HP MSM Wireless Networks Version: 7.1 [ Total Questions: 115 ] s@lm@n HP Exam HP2-Z32 Implementing HP MSM Wireless Networks Version: 7.1 [ Total Questions: 115 ] HP HP2-Z32 : Practice Test Question No : 1 What is a proper use for an ingress VLAN in an HP MSM VSC?

More information

Add a Wireless Network to an Existing Wired Network using a Wireless Access Point (WAP)

Add a Wireless Network to an Existing Wired Network using a Wireless Access Point (WAP) Add a Wireless Network to an Existing Wired Network using a Wireless Access Point (WAP) Objective A Wireless Access Point (WAP) is a networking device that allows wireless-capable devices to connect to

More information

Enterprise WiFi System. Datasheet. Tel: +44 (0) Fax: +44 (0)

Enterprise WiFi System. Datasheet.  Tel: +44 (0) Fax: +44 (0) Enterprise WiFi System Models: UAP, UAP-LR, UAP-PRO, UAP-AC, UAP-Outdoor+, UAP-Outdoor5, UAP-AC Outdoor Unlimited Indoor/Outdoor AP Scalability in a Unified Management System Breakthrough Speeds up to

More information

Cisco WAP371 Wireless-AC/N Dual Radio Access Point with Single Point Setup

Cisco WAP371 Wireless-AC/N Dual Radio Access Point with Single Point Setup Data Sheet Cisco WAP371 Wireless-AC/N Dual Radio Access Point with Single Point Setup High-Performance, Easy-to-Deploy, and Highly Secure Business-Class Wireless-AC Connectivity. Highlights Provides cost-effective

More information

Datasheet ac Wave 2 Enterprise Wi-Fi Access Point. Model: UAP-AC-HD. Simultaneous Dual-Band 4x4 Multi-User MIMO

Datasheet ac Wave 2 Enterprise Wi-Fi Access Point. Model: UAP-AC-HD. Simultaneous Dual-Band 4x4 Multi-User MIMO 802.11ac Wave 2 Enterprise Wi-Fi Access Point Model: UAP-AC-HD Simultaneous Dual-Band 4x4 Multi-User MIMO Four-Stream 802.11ac Wave 2 Technology 802.3at PoE+ Compatibility Scalable Enterprise Wi-Fi Management

More information

NXC Series. Handbook. NXC Controllers NXC 2500/ Default Login Details. Firmware Version 5.00 Edition 19, 5/

NXC Series. Handbook. NXC Controllers NXC 2500/ Default Login Details. Firmware Version 5.00 Edition 19, 5/ NXC Series NXC 2500/ 5500 NXC Controllers Firmware Version 5.00 Edition 19, 5/2017 Handbook Default Login Details LAN Port IP Address https://192.168.1.1 User Name admin Password 1234 Copyright 2017 ZyXEL

More information

Nuclias by D-Link is a complete cloud-managed networking solution for small to medium-sized organisations with one or more sites.

Nuclias by D-Link is a complete cloud-managed networking solution for small to medium-sized organisations with one or more sites. Nuclias by D-Link is a complete cloud-managed networking solution for small to medium-sized organisations with one or more sites. Simpler to install and easier to manage How it works Wi-Fi coverage and

More information

SUB-TITLE WLAN Management-as-a-Service

SUB-TITLE WLAN Management-as-a-Service TITLE RUCKUS GOES CLOUD HEREWI-FI SUB-TITLE GOES HERE CASE STUDY Ruckus Cloud Wi-Fi is. Wi-Fi coverage and capacity is provided by high-performance APs deployed on site; control and management are delivered

More information

802.3at ac 3x3 Dual Band Ceiling Mount Access Point/WDS. Datasheet. can be used with EAP1750H. Key Features. capable switches or injectors

802.3at ac 3x3 Dual Band Ceiling Mount Access Point/WDS. Datasheet. can be used with EAP1750H. Key Features. capable switches or injectors Datasheet EAP1750H 802.11ac 3x3 Dual Band Ceiling Mount Access Point/WDS The EAP1750H leverages the breakthrough speed and performance of 802.11ac for connecting to laptops and other devices that need

More information

802.3at ac 3x3 Dual Band Ceiling Mount Access Point/WDS. can be used with EAP1750H. Key Features

802.3at ac 3x3 Dual Band Ceiling Mount Access Point/WDS. can be used with EAP1750H. Key Features EAP1750H can be used with 802.3at capable switches or injectors 802.11ac 3x3 Dual Band Ceiling Mount Access Point/WDS The EAP1750H leverages the breakthrough speed and performance of 802.11ac for connecting

More information

RUCKUS CLOUD WI-FI Cloud Managed Wi-Fi

RUCKUS CLOUD WI-FI Cloud Managed Wi-Fi TITLE GOES HERE SUB-TITLE GOES HERE RUCKUS CLOUD WI-FI Cloud Managed Wi-Fi SIMPLIFIED MANAGEMENT OF MULTI-SITE WI-FI NETWORKS Ruckus Cloud Wi-Fi simplifies deployment, monitoring and management of your

More information

Enterprise WiFi System. Datasheet. Models: UAP, UAP-LR, UAP-PRO, UAP-AC, UAP-Outdoor+, UAP-Outdoor5, UAP-AC Outdoor

Enterprise WiFi System. Datasheet. Models: UAP, UAP-LR, UAP-PRO, UAP-AC, UAP-Outdoor+, UAP-Outdoor5, UAP-AC Outdoor Enterprise WiFi System Models: UAP, UAP-LR, UAP-PRO, UAP-AC, UAP-Outdoor+, UAP-Outdoor5, UAP-AC Outdoor Unlimited Indoor/Outdoor AP Scalability in a Unified Management System Breakthrough Speeds up to

More information

Wireless# Guide to Wireless Communications. Objectives

Wireless# Guide to Wireless Communications. Objectives Wireless# Guide to Wireless Communications Chapter 8 High-Speed WLANs and WLAN Security Objectives Describe how IEEE 802.11a networks function and how they differ from 802.11 networks Outline how 802.11g

More information

Enterprise WiFi System. Datasheet. Models: UAP, UAP-LR, UAP-PRO, UAP-AC, UAP-Outdoor+, UAP-Outdoor5, UAP-AC Outdoor

Enterprise WiFi System. Datasheet. Models: UAP, UAP-LR, UAP-PRO, UAP-AC, UAP-Outdoor+, UAP-Outdoor5, UAP-AC Outdoor Enterprise WiFi System Models: UAP, UAP-LR, UAP-PRO, UAP-AC,, UAP-Outdoor5, UAP-AC Outdoor Unlimited Indoor/Outdoor AP Scalability in a Unified Management System Breakthrough Speeds up to 1300 Mbps (802.11ac)

More information

Aerohive and IntelliGO End-to-End Security for devices on your network

Aerohive and IntelliGO End-to-End Security for devices on your network Aerohive and IntelliGO End-to-End Security for devices on your network Introduction Networks have long used a password to authenticate users and devices. Today, many cyber attacks can be used to capture

More information

COPYRIGHTED MATERIAL. Contents

COPYRIGHTED MATERIAL. Contents Contents Foreword Introduction xxv xxvii Assessment Test xxxviii Chapter 1 WLAN Security Overview 1 Standards Organizations 3 International Organization for Standardization (ISO) 3 Institute of Electrical

More information

For a full description of Wi-Fi Cloud features and functionality, see WatchGuard Wi-Fi Cloud Help.

For a full description of Wi-Fi Cloud features and functionality, see WatchGuard Wi-Fi Cloud Help. WatchGuard Wi-Fi Cloud Release Notes Latest Wi-Fi Cloud Update 31 May 2018 Release Notes Revision Date 31 May 2018 Current Wi-Fi Cloud Version 8.5.0-658 Introduction WatchGuard Wi-Fi Cloud is a powerful,

More information

Wireless technology Principles of Security

Wireless technology Principles of Security Wireless technology Principles of Security 1 Wireless technologies 2 Overview This module provides an introduction to the rapidly evolving technology of wireless LANs (WLANs). WLANs redefine the way the

More information

FortiNAC. Cisco Airespace Wireless Controller Integration. Version: 8.x. Date: 8/28/2018. Rev: B

FortiNAC. Cisco Airespace Wireless Controller Integration. Version: 8.x. Date: 8/28/2018. Rev: B FortiNAC Cisco Airespace Wireless Controller Integration Version: 8.x Date: 8/28/2018 Rev: B FORTINET DOCUMENT LIBRARY http://docs.fortinet.com FORTINET VIDEO GUIDE http://video.fortinet.com FORTINET KNOWLEDGE

More information

L2+ Unified Wired/Wireless Gigabit PoE Switches

L2+ Unified Wired/Wireless Gigabit PoE Switches Scalable Unified Wired/Wireless Network Architecture Manages up to 48 D-Link Unified Access Points 1 Up to 192 Unified Access Points can be managed by a cluster of four DWS-3160 switches Robust Wired/Wireless

More information

23 Must-Have WiFi Features

23 Must-Have WiFi Features 23 Must-Have WiFi Features Installing, updating or expanding a WiFi network can seem complicated because of the long list of features available and the always-evolving nature of technology. The point of

More information

Basic Wireless Settings on the CVR100W VPN Router

Basic Wireless Settings on the CVR100W VPN Router Basic Wireless Settings on the CVR100W VPN Router Objective A Wireless Local Area Network (WLAN) utilizes radio communication to connect wireless devices to a LAN. An example is a Wi-Fi hotspot at a cafe.

More information

Gigabit Layer 2+ Unified Switches

Gigabit Layer 2+ Unified Switches Product Highlights Unified Network Architecture Manages up to 48 D-Link Unified Access Points (192 Access Points in a cluster) Robust Wired/Wireless Security With Access Control Lists, Captive Portal,

More information

Aerohive Private PSK. solution brief

Aerohive Private PSK. solution brief Aerohive Private PSK solution brief Table of Contents Introduction... 3 Overview of Common Methods for Wi-Fi Access... 4 Wi-Fi Access using Aerohive Private PSK... 6 Private PSK Deployments Using HiveManager...

More information

Cisco Exam Implementing Advanced Cisco Unified Wireless Security v2.0 Version: 9.0 [ Total Questions: 206 ]

Cisco Exam Implementing Advanced Cisco Unified Wireless Security v2.0 Version: 9.0 [ Total Questions: 206 ] s@lm@n Cisco Exam 642-737 Implementing Advanced Cisco Unified Wireless Security v2.0 Version: 9.0 [ Total Questions: 206 ] Cisco 642-737 : Practice Test Question No : 1 RADIUS is set up with multiple servers

More information

AP AC 1200Mbps Wireless In-Wall Access Point.

AP AC 1200Mbps Wireless In-Wall Access Point. 11AC 1200Mbps Wireless In-Wall Access Point www.ip-com.com.cn/en 11AC 1200Mbps Wireless In-Wall Access Pointt Product Description is designed to provide wifi coverage for hotel rooms,villa,university dormitories,

More information

NAP ac Dual-Radio Smart Antenna 3x3 Nebula Cloud Managed Access Point

NAP ac Dual-Radio Smart Antenna 3x3 Nebula Cloud Managed Access Point NAP303 802.11ac Dual-Radio Smart Antenna 3x3 Nebula Cloud Managed Access Point The Zyxel Nebula NAP303 802.11ac Dual-Radio Smart Antenna 3x3 Nebula Cloud Managed Access Point is a high-performance 3x3

More information

Vendor: HP. Exam Code: HP2-Z32. Exam Name: Implementing HP MSM Wireless Networks. Version: Demo

Vendor: HP. Exam Code: HP2-Z32. Exam Name: Implementing HP MSM Wireless Networks. Version: Demo Vendor: HP Exam Code: HP2-Z32 Exam Name: Implementing HP MSM Wireless Networks Version: Demo QUESTION 1 A network administrator deploys several HP MSM APs and an HP MSM Controller. The APs discover the

More information

cnpilot Indoor e400 Gigabit Wi-Fi: ac dual band 2x2 Indoor access point

cnpilot Indoor e400 Gigabit Wi-Fi: ac dual band 2x2 Indoor access point cnpilot Indoor e400 Gigabit Wi-Fi: 802.11ac dual band 2x2 Indoor access point Affordable Enterprise grade High density capable 802.11ac Indoor access points for Schools, Indoor public spaces, Malls, Hotels

More information

Potential Mitigation Strategies for the Common Vulnerabilities of Control Systems Identified by the NERC Control Systems Security Working Group

Potential Mitigation Strategies for the Common Vulnerabilities of Control Systems Identified by the NERC Control Systems Security Working Group Potential Mitigation Strategies for the Common Vulnerabilities of Control Systems Identified by the NERC Control Systems Security Working Group Submitted on behalf of the U.S. Department of Energy National

More information

PASS4TEST. IT Certification Guaranteed, The Easy Way! We offer free update service for one year

PASS4TEST. IT Certification Guaranteed, The Easy Way!   We offer free update service for one year PASS4TEST \ http://www.pass4test.com We offer free update service for one year Exam : 642-737 Title : Implementing Advanced Cisco Unified Wireless Security (IAUWS) v2.0 Vendor : Cisco Version : DEMO Get

More information

WAP9112/9114 Quick Start Guide

WAP9112/9114 Quick Start Guide WAP9112/9114 Quick Start Guide Release 7.6 NN47252-308 Issue 02.01 March 2016 Contents Chapter 1: Introduction... 3 Chapter 2: Required Software Components... 4 Chapter 3: Installing or Upgrading Wireless

More information

Enterprise WiFi System. Datasheet. Models: UAP, UAP-LR, UAP-Pro, UAP-Outdoor, UAP-Outdoor5

Enterprise WiFi System. Datasheet. Models: UAP, UAP-LR, UAP-Pro, UAP-Outdoor, UAP-Outdoor5 Enterprise WiFi System Models: UAP, UAP-LR, UAP-Pro, UAP-Outdoor, UAP-Outdoor5 Unlimited Indoor/Outdoor AP Scalability in a Unified Management System Breakthrough Capacity up to 750 Mbps Intuitive UniFi

More information

Enterprise WiFi System. Datasheet. 4Gon Tel: +44 (0) Fax: +44 (0)

Enterprise WiFi System. Datasheet. 4Gon   Tel: +44 (0) Fax: +44 (0) Enterprise WiFi System Models: UAP, UAP-LR, UAP-Pro, UAP-Outdoor, UAP-Outdoor5 Unlimited Indoor/Outdoor AP Scalability in a Unified Management System Breakthrough Capacity up to 750 Mbps Intuitive UniFi

More information

802.1x Port Based Authentication

802.1x Port Based Authentication 802.1x Port Based Authentication Johan Loos Johan at accessdenied.be Who? Independent Information Security Consultant and Trainer Vulnerability Management and Assessment Wireless Security Next-Generation

More information

Auranet EAP Solution 2

Auranet EAP Solution 2 Auranet EAP Solution 2 EAP Indoor Wi-Fi Solution for Medium-Sized and Single-Subnet Networks Tom.Wu 2017-1-24 Contents Background... 2 Application Scenarios... 2 Why TP-Link?... 2 Solution... 2 A. Solution

More information

OmniAccess Instant AP Update

OmniAccess Instant AP Update OmniAccess Instant AP Update Pre-Sales Expert November COPYRIGHT 2011 ALCATEL-LUCENT ENTERPRISE. ALL RIGHTS RESERVED. AGENDA 1) OmniAccess Instant AP reminder 2) Instant AP versus Campus AP 3) Virtual

More information

Information Technology Policy Board Members. SUBJECT: Update to County WAN/LAN Wireless Standards

Information Technology Policy Board Members. SUBJECT: Update to County WAN/LAN Wireless Standards COUNTY OF SACRAMENTO Inter-Departmental Correspondence December 6, 2007 TO: FROM: Information Technology Policy Board Members Jeff Leveroni, Chair Technology Review Group SUBJECT: Update to County WAN/LAN

More information

EWS320AP New Product Setup for Distribution & Messaging Guide

EWS320AP New Product Setup for Distribution & Messaging Guide EWS320AP New Product Setup for Distribution & Messaging Guide Model (SKU): EWS320AP Product Name: Dual-Band Wireless N900 Managed Indoor Access Point UPC number: 6 55216 00712 3 MSRP: $499 Product Short

More information

TestsDumps. Latest Test Dumps for IT Exam Certification

TestsDumps.  Latest Test Dumps for IT Exam Certification TestsDumps http://www.testsdumps.com Latest Test Dumps for IT Exam Certification Exam : PW0-200 Title : Certified wireless security professional(cwsp) Vendors : CWNP Version : DEMO Get Latest & Valid PW0-200

More information

IP network that supports DHCP or manual assignment of IP address, gateway, and subnet mask

IP network that supports DHCP or manual assignment of IP address, gateway, and subnet mask Network Requirements, page 1 Wireless LAN, page 2 Wi-Fi Network Components, page 3 802.11 Standards for WLAN Communications, page 6 Security for Communications in WLANs, page 9 WLANs and Roaming, page

More information

Cisco WAP131 Wireless-N Dual Radio Access Point with PoE

Cisco WAP131 Wireless-N Dual Radio Access Point with PoE Data Sheet Cisco WAP131 Wireless-N Dual Radio Access Point with PoE Improved Coverage, Easy to Deploy, Secure Business-Class Wireless-N Connectivity Highlights Provides cost-effective 802.11n connectivity

More information

Cisco WAP121 Wireless-N Access Point with Single Point Setup

Cisco WAP121 Wireless-N Access Point with Single Point Setup Data Sheet Cisco WAP121 Wireless-N Access Point with Single Point Setup Secure, Easy-to-Deploy, Affordable Wireless-N Connectivity Highlights Provides affordable high-bandwidth 802.11n wireless connectivity

More information

Expected Outcomes Able to design the network security for the entire network Able to develop and suggest the security plan and policy

Expected Outcomes Able to design the network security for the entire network Able to develop and suggest the security plan and policy CHAPTER 9 DEVELOPING NETWORK SECURITY STRATEGIES Expected Outcomes Able to design the network security for the entire network Able to develop and suggest the security plan and policy Network Security Design

More information

New Windows build with WLAN access

New Windows build with WLAN access New Windows build with WLAN access SecRep 24 17-18 May 2016 Ahmed Benallegue/Hassan El Ghouizy/Priyan Ariyansinghe ECMWF network_services@ecmwf.int ECMWF May 19, 2016 Introduction Drivers for the new WLAN

More information

1.0 Basic RF Characteristics (15%) 1.1 Describe RF signal characteristics Frequency Amplitude Phase 1.1.

1.0 Basic RF Characteristics (15%) 1.1 Describe RF signal characteristics Frequency Amplitude Phase 1.1. CWT 100 Objectives The Certified Wireless Technician (CWT) is an individual who can install APs based on a design document, configure the AP for initial operations and ensure connectivity. The individual

More information

Grandstream Networks, Inc. GWN76xx Wi-Fi Access Points Master/Slave Architecture Guide

Grandstream Networks, Inc. GWN76xx Wi-Fi Access Points Master/Slave Architecture Guide Grandstream Networks, Inc. GWN76xx Wi-Fi Access Points Master/Slave Architecture Guide Table of Contents INTRODUCTION... 4 DISCOVER AND PAIR GWN76XX ACCESS POINTS... 5 Discover GWN76xx... 5 Method 1: Discover

More information

Auranet EAP Solution 1

Auranet EAP Solution 1 Auranet EAP Solution 1 EAP Indoor Wi-Fi Solutions for Small-Sized and Single-Subnet Networks Tom.Wu 2017-1-24 Contents Background... 2 Application Scenarios... 2 Why TP-Link?... 2 Solution... 2 A. Solution

More information

Cisco WAP321 Wireless-N Selectable-Band Access Point with Power over Ethernet

Cisco WAP321 Wireless-N Selectable-Band Access Point with Power over Ethernet Data Sheet Cisco WAP321 Wireless-N Selectable-Band Access Point with Power over Ethernet Secure Wireless-N Networking with Gigabit Ethernet Connectivity Highlights Provides selectable-band high-bandwidth

More information

EWS310AP New Product Setup for Distribution & Messaging Guide

EWS310AP New Product Setup for Distribution & Messaging Guide EWS310AP New Product Setup for Distribution & Messaging Guide Model (SKU): EWS310AP Product Name: Dual-Band Wireless N600 Managed Indoor Access Point UPC number: 6 55216 00711 6 MSRP: $349 Product Short

More information

Cisco WAP321 Wireless-N Selectable-Band Access Point with Power over Ethernet

Cisco WAP321 Wireless-N Selectable-Band Access Point with Power over Ethernet Data Sheet Cisco WAP321 Wireless-N Selectable-Band Access Point with Power over Ethernet Secure Wireless-N Networking with Gigabit Ethernet Connectivity Highlights Provides selectable-band high-bandwidth

More information

ACCESS POINTS. Configuration Specifications

ACCESS POINTS. Configuration Specifications With a powerful integrated controller, application level intelligence, zero-touch provisioning, and available cloud-based network management, Xirrus XR-500 and XR-600 series Access Points provide a powerful

More information

Creating Wireless Networks

Creating Wireless Networks WLANs, page 1 Creating Employee WLANs, page 2 Creating Guest WLANs, page 4 Internal Splash Page for Web Authentication, page 7 Managing WLAN Users, page 9 Adding MAC for Local MAC Filtering on WLANs, page

More information

ARUBA INSTANT Combining enterprise-class Wi-Fi with unmatched affordability and configuration simplicity

ARUBA INSTANT Combining enterprise-class Wi-Fi with unmatched affordability and configuration simplicity ARUBA INSTANT Combining enterprise-class Wi-Fi with unmatched affordability and configuration simplicity Table of Contents Introduction... 3 Aruba Instant Overview... 4 Aruba Instant APs... 4 Adaptive

More information

Secure Mobility Challenges. Fat APs, Decentralized Risk. Physical Access. Business Requirements

Secure Mobility Challenges. Fat APs, Decentralized Risk. Physical Access. Business Requirements Unified Wireless Switching Enabling a Truly Converged Network White Paper Abstract As businesses scale, traditional wireless network deployments become more complex, more costly and less secure. Users

More information

Add performance and security to your business' wireless network with the Intellinet High-Power Wireless AC1750 Dual-Band Gigabit PoE Access Point.

Add performance and security to your business' wireless network with the Intellinet High-Power Wireless AC1750 Dual-Band Gigabit PoE Access Point. High-Power Wireless AC1750 Dual-Band Gigabit PoE Access Point 450 Mbps Wireless N (2.4 GHz) + 1300 Mbps Wireless AC (5 GHz), WDS, Wireless client isolation, 27.5 dbm, wall-mount Part No.: 525787 Add performance

More information

MR30H. MR30H and Meraki Cloud Management: A Powerful Combination. Robust Feature Set for Multi-dwelling Wireless. Product Highlights

MR30H. MR30H and Meraki Cloud Management: A Powerful Combination. Robust Feature Set for Multi-dwelling Wireless. Product Highlights MR30H Dual-band, 802.11ac Wave 2 2x2:2 Wall Switch Access Point with dedicated security and RF management radio as well as an integrated Bluetooth Low Energy beacon and scanning radio Robust Feature Set

More information

Cisco Small Business 550/560 Wireless Access Points

Cisco Small Business 550/560 Wireless Access Points Data Sheet Cisco Small Business 550/560 Wireless Access Points High-Performance, Easy-to-Deploy, Secure Business-Class Wireless-N Connectivity Highlights Provides cost-effective selectable or concurrent

More information

Simple, full featured and budgetary deployment of single AP or distributed APs Hot-Spot for small scale projects.

Simple, full featured and budgetary deployment of single AP or distributed APs Hot-Spot for small scale projects. Colubris Wireless Hot-Spot solution for small and medium scale deployments 1. Definitions, goals, and objectives Simple, full featured and budgetary deployment of single AP or distributed APs Hot-Spot

More information

Cisco Exam Questions and Answers (PDF) Cisco Exam Questions BrainDumps

Cisco Exam Questions and Answers (PDF) Cisco Exam Questions BrainDumps Cisco 300-375 Dumps with Valid 300-375 Exam Questions PDF [2018] The Cisco 300-375 Securing Cisco Wireless Enterprise Networks (WISECURE) exam is an ultimate source for professionals to retain their credentials

More information

Submitted on behalf of the DOE National SCADA Test Bed. Jeff Dagle, PE Pacific Northwest National Laboratory (509)

Submitted on behalf of the DOE National SCADA Test Bed. Jeff Dagle, PE Pacific Northwest National Laboratory (509) Potential Mitigation Strategies for the Common Vulnerabilities of Control Systems Identified by the NERC Control Systems Security Working Group (CSSWG) Submitted on behalf of the DOE National SCADA Test

More information

300Mbps Wireless N Gigabit Ceilling Mount Access Point

300Mbps Wireless N Gigabit Ceilling Mount Access Point Datasheet 300Mbps Wireless N Gigabit Ceilling Mount Access Point 120 Highlights Wireless N speed up to 300Mbps The Controller Software enables administrators to manage hundreds of s easily from any PC

More information

MERU EDUCATION GRADE - MEG

MERU EDUCATION GRADE - MEG BYOD the driver to high density wireless and the advent of 802.11ac Henry Batten Meru Networks hbatten@merunetworks.com 07904 381 977 Evolution of Campus Wireless Hot Spot Mission Critical Utility Learning

More information

D. The bank s web server is using an X.509 certificate that is not signed by a root CA, causing the user ID and password to be sent unencrypted.

D. The bank s web server is using an X.509 certificate that is not signed by a root CA, causing the user ID and password to be sent unencrypted. Volume: 119 Questions Question No: 1 John Smith uses a coffee shop's Internet hot-spot (no authentication or encryption) to transfer funds between his checking and savings accounts at his bank's website.

More information

Cisco AP 541N Wireless Access Point Part of the Cisco Small Business Pro Series

Cisco AP 541N Wireless Access Point Part of the Cisco Small Business Pro Series Cisco AP 541N Wireless Access Point Part of the Cisco Small Business Pro Series The success of your business depends on the ability of your employees to stay connected to applications and customers, and

More information

Wireless AC1200 Concurrent Dual Band PoE Access Point

Wireless AC1200 Concurrent Dual Band PoE Access Point DAP-2660 Version 1.00 AirPremier Wireless AC1200 Concurrent Dual Band PoE Access Point Product Overview...5 Introduction... 5 Features... 6 Package Contents... 7 System Requirements... 7 Hardware Overview...8

More information

300Mbps Wireless Gigabit PoE Access Point

300Mbps Wireless Gigabit PoE Access Point WAP-6150 Version: 1 300Mbps Wireless Gigabit PoE Access Point The tough, high performance WAP-6150 is designed for fast wireless connectivity in enterprise or industrial environments of all dimensions.

More information

AC1200 Dual Band Wireless Controller Kit TEW-821DAP2KAC (v1.0r)

AC1200 Dual Band Wireless Controller Kit TEW-821DAP2KAC (v1.0r) AC1200 Dual Band Wireless Controller Kit TEW-821DAP2KAC (v1.0r) Centralized AP management Includes two dual band wireless AC1200 access points with PoE injectors Wireless controller with five gigabit ports

More information

Securing Wireless LANs with Certificate Services

Securing Wireless LANs with Certificate Services 1 Securing Wireless LANs with Certificate Services PHILIP HUYNH University of Colorado at Colorado Springs Abstract Wireless Local Access Network (WLAN) is used popularly in almost everywhere from the

More information

LCOS 8.82 RC1 Feature Notes.

LCOS 8.82 RC1 Feature Notes. Feature Notes www.lancom.de Introduction The LANCOM operating system LCOS and the corresponding management tools (LCMS) regularly provide free new functions for current LANCOM routers, access points, and

More information

Ubiquiti UniFi UAP-Pro Access Point

Ubiquiti UniFi UAP-Pro Access Point Product Name: Manufacturer: - Model Number: UAP-PRO Please Note: The UAP-PRO is no longer available. For an alternative, we recommend the UAP-AC-PRO. Ubiquiti UniFi Pro Access Point (UAP-Pro) The Ubiquiti

More information

P ART 3. Configuring the Infrastructure

P ART 3. Configuring the Infrastructure P ART 3 Configuring the Infrastructure CHAPTER 8 Summary of Configuring the Infrastructure Revised: August 7, 2013 This part of the CVD section discusses the different infrastructure components that are

More information

Cisco WAP351 Wireless-N Dual Radio Access Point with 5-Port Switch

Cisco WAP351 Wireless-N Dual Radio Access Point with 5-Port Switch Data Sheet Cisco WAP351 Wireless-N Dual Radio Access Point with 5-Port Switch Improved Coverage, Easy to Deploy, Secure Business-Class Wireless-N Connectivity Highlights Provides cost-effective 802.11n

More information

cnpilot e502s Outdoor Sector AP

cnpilot e502s Outdoor Sector AP cnpilot e502s Outdoor Sector AP IP67 802.11ac 30 Outdoor Narrow Sector Access Point Perfect for very high density applications such as Stadiums, High density event coverage, Public Wi-Fi in high noise

More information

Application Example (Standalone EAP)

Application Example (Standalone EAP) Application Example (Standalone EAP) CHAPTERS 1. Determine the Network Requirements 2. Build the Network Topology 3. Log In to the EAP 4. Configure the EAP 5. Test the Network This guide applies to: EAP225-Outdoor

More information