Re: Concern about wireless security
- From: "James McIllece [MS]" <jamesmci@xxxxxxxxxxxxxxxxxxxx>
- Date: Thu, 22 Dec 2005 11:57:45 -0800
"Newbie" <newbie@xxxxxxxxxxx> wrote in
news:eQFJn8vBGHA.228@xxxxxxxxxxxxxxxxxxxx:
> Hi,
>
> I currently have SBS 2003 Premium with ISA2004 running. I'm new to a
> lot of these stuff so please forgive me, if I'm asking some dummy
> questions!
>
> Anyway, what I'd like to do is for my wireless devices, I'd like to
> enable some sort of authentication mechanism such as prompting for
> username/password before it gets an IP address through the access
> point? Is this what the RADIUS/IAS server is for? Unfortunately, I
> have a few devices that won't support WPA, only WEP.
>
> I appreciate your responses, thanks.
>
>
>
WEP-only is OK, but as Eric mentions in his post, the access point must be
compatible with the RADIUS protocol. In addition, the APs must be
compatible with 802.1X authentication.
In this scenario, ISA is irrelevant, other than that you need to make sure
to allow RADIUS traffic through the firewall. Your basic setup would be:
Wireless client --->>> Wireless access point --->>> SBS 2003 Premium server
with Internet Authentication Service (IAS) installed and configured.
Here is a whitepaper that shows how to set it all up once you have your
hardware:
"Step-by-Step Guide for Secure Wireless Deployment for Small Office/Home
Office or Small Organization Networks" at
http://www.microsoft.com/downloads/details.aspx?familyid=269902e8-fc41-
4eb1-9374-44612e64f0fb&displaylang=en
--
James McIllece, Microsoft
Please do not send email directly to this alias. This is my online account
name for newsgroup participation only.
This posting is provided "AS IS" with no warranties, and confers no rights.
.
- References:
- Concern about wireless security
- From: Newbie
- Concern about wireless security
- Prev by Date: Re: W2K PEAP MSCHAPV2 and IAS Certifcates
- Next by Date: Dynamic VLAN-Assignment per MAC-Database ?!
- Previous by thread: Re: Concern about wireless security
- Next by thread: Dynamic VLAN-Assignment per MAC-Database ?!
- Index(es):
Relevant Pages
|
Loading