3 ms·
Couldn't it just fall back to the password version like it does every time now? Like optionally use the keys if present if not renegotiate
by nighthawk454 3y ago
Couldn't it just fall back to the password version like it does every time now? Like optionally use the keys if present if not renegotiate
- bongodongobob 3y agoI'm guessing that's going to be an issue for handoffs between APs. Think walking around a multi-story office on a Wi-Fi call. Now picture 30 APs and 100 people on wifi calls/VoIP etc. with DHCP recycling addresses, randomized MACs and so forth.
- klyrs 3y agoIs there any obstacle to having a centralized server these APs talk to, which manages authentication? I'm not seeing a hard obstacle, just another piece of network kit and it's cheaper to keep a clunky UX
- blibble 3y agoyou just described RADIUS
- bongodongobob 3y agoIn theory I suppose. But you have to take into account that these APs can potentially be on different subnets, physical networks, talking across ipsec tunnels, dealing with multiple VLANs etc. There's just more overhead. It's easier to push out the info to the APs than to pull from who knows where. Edit: For example: Say you have two buildings connected via an ipsec tunnel/static route. You have 4 wifi networks on 4 separate VLANs, 2 per building, guest and internal. Generally you'll have an internal wifi controller on an infra VLAN as well. The wifi VLANs are not allowed to route to the infra VLAN, but infra can route to wifi. Rather than punching holes back allowing the the APs to talk to infra, you push out from infra to the APs.
- deleted 3y ago[deleted]
- DougN7 3y agoIs that any stronger than using a password if an attacker could force a connection to fall back to the password?