4 ms·
Why not (and i realise that this is a dirty horrible hack) isolate those devices to their own dedicated virtual ap and isolated network. that way you get to res
by tacticus 11y ago
Why not (and i realise that this is a dirty horrible hack) isolate those devices to their own dedicated virtual ap and isolated network. that way you get to restrict what they can talk to, what can talk to them and the keys that everyone else uses.
this also allows you to finally get around to rolling out eap so the scourge of shared wifi keys can die out :)
- simoncion 11y ago> this also allows you to finally get around to rolling out eap * WPA2-Enterprise is not universally supported. (Ferinstance, no Chromecast can connect via WPA2-Enterpise. :( ) * Which EAP? EAP-TLS? EAP-MD5? [0] EAP-MSCHAPv2? Or perhaps EAP-GTC? [1][2] > this also allows you to finally get around to rolling out eap so the scourge of shared wifi keys can die out Unrelated to the issue at hand... I really wish OS X and Windows supported EAP-WFA-UNAUTH-TLS (and that EAP-UNAUTH-TLS would become an "actual" EAP method, rather than languishing as a vendor specific extension. Securely encrypted zero-configuration public WiFi can't come fast enough! :) [0] God no! ;) [1] It probably sounds like I'm trying to imply that WPA2-Enterprise is too complicated. Frankly (speaking as a guy who's implementing his own RADIUS server as a hobby project), it's really not. There are just many, many options available to you... and not all of them are supported by all RADIUS servers. [2] Anyway... given what very little I know about EAP-GTC, I would suggest that -if we're going for a near-zero-configuration deployment- it would be the most suitable for the situation that we're talking about... The trick would be hooking the verification logic for the security token in the device into the RADIUS server. :)
- darkr 11y ago> * Which EAP? EAP-TLS? EAP-MD5? [0] EAP-MSCHAPv2? Or perhaps EAP-GTC? EAP-TLS ideally. You need a CA infrastructure, a radius server, and a way of doing automated enrolment, revocation and install of client certificates. A lot of work if you haven't already got those parts (though many places already do), but it's fairly hassle free and secure once up and running. For bonus points you can extend 802.11x goodness to your wired desktop ports as well. You probably need at least one other network/BSSID with standard wpa2 for non-managed devices as you say.
- simoncion 11y agoSo, I'm fairly new to this... how would you do automated installation of client certs on: * OS X machines * Android devices * A Nest Thermostat > For bonus points you can extend 802.11x goodness to your wired desktop ports as well. Though, that only works if you have either a Smart or a Managed switch that understands that it needs to tag frames from that port with RADIUS-dictated VLAN tags, right?
- darkr 11y agoOS X - puppet/chef or equivalent Android - MDM (I think the stock google apps MDM can do client Certs and 802.11x network config) Nest - would not bother; stick on a dedicated standard WPA2 network, segregate from rest of network then leave well alone. Wired network - yes, you'd need a managed L2 switch (but then you'd need that anyway to trunk multiple tagged vlans to your APs).