3 ms·
Since Covid we have moved to a Zero Trust approach regarding all the things regarding the network. We have more and more access control on the LAN to avoid whoe
by simonm21 2y ago
Since Covid we have moved to a Zero Trust approach regarding all the things regarding the network. We have more and more access control on the LAN to avoid whoever to connect and now it's time for the Wi-Fi to change its implementation. Currently, most of companies have implemented an "Open SSID" to provide access to visitors, BYOD or partners. Because no other solution existed. Based on the Open SSID, we can configure multiple layers of security to avoid to have this network impacting the corporate network. But now, some mechanisms exist such like OWE to secure the association of device to the network. You may say that I need to have an OWE device to connect to an OWE network and you right, not all devices support this security mechanism. Based on a vendor solution, you can implement an "Open SSID" with a redirection mechanism allowing OWE device to connect to the SSID with OWE and other device which doesn't understand OWE will still connect to the Open SSID. So you keep one SSID with both functionalities and this is huge
- Simranjeet2709 2y agoWhen it comes to securing access through open SSIDs, the best way is to have the captive portal in place. Its the perfect way to to build a zero trust network, where in you don't trust anyone who connects to the SSID and is forced to authenticate through the captive portal. Put captive portal in place and force the users to validate through their phone numbers, social media accounts or emails. You can even integrate your existing IdP to the captive portal and even ask your employees to connect through the captive portal.