Top Banner
Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture
21

Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

Dec 28, 2015

Download

Documents

Charles Bradley
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

Certified Wireless Network Administrator (CWNA)PW0-105

Chapter 13802.11 Network Security Architecture

Page 2: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

Chapter 13 Overview

• 802.11 Security Basics• Legacy 802.11 Security• Robust Security• Traffic Segmentation• Infrastructure Security• VPN Wireless Security

2Certified Wireless Network Administrator: CWNA – PW0-105

Page 3: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

802.11 Security Basics

• Data privacy• AAA

Segmentation• Monitoring• Policy

3Certified Wireless Network Administrator: CWNA – PW0-105

Page 4: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

Data Privacy

• About the protection of data and the prevention of unauthorized access to it

• Uses encryption– RC4– AES

• Exercise 13.1

4Certified Wireless Network Administrator: CWNA – PW0-105

Page 5: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

AAA

• Authentication– Who are you?– What are you?

• Authorization– What can you do?

• Accounting– What did you do?

5Certified Wireless Network Administrator: CWNA – PW0-105

Page 6: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

Segmentation

• LANs• WANs• VLANs

6Certified Wireless Network Administrator: CWNA – PW0-105

Page 7: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

Policy

• Defines how computer systems must be implemented– Specific WiFi policies must be created– Traditional wired policies are not sufficient

7Certified Wireless Network Administrator: CWNA – PW0-105

Page 8: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

Legacy 802.11 Security

• Legacy authentication– Open System– Shared Key

• Static WEP encryption• MAC filters• SSID cloaking or hiding

8Certified Wireless Network Administrator: CWNA – PW0-105

Page 9: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

WEP Key and IV

9Certified Wireless Network Administrator: CWNA – PW0-105

Page 10: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

Robust Security vs. Legacy Security

10Certified Wireless Network Administrator: CWNA – PW0-105

Page 11: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

Robust Security Network (RSN)

11Certified Wireless Network Administrator: CWNA – PW0-105

• 802.11-2007, originally 802.11i, define an RSN– STAs must use the 4-way handshake– STAs must use CCMP or TKIP

• Pre-Shared Key (PSK)

• Proprietary PSK– Dynamic PSK and Private PSK are examples

• 802.1X/EAP

Page 12: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

802.1X Comparison

12Certified Wireless Network Administrator: CWNA – PW0-105

Page 13: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

WLAN Bridging and 802.1X

13Certified Wireless Network Administrator: CWNA – PW0-105

Page 14: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

802.1X/EAP Architecture and Process

14Certified Wireless Network Administrator: CWNA – PW0-105

Page 15: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

EAP Types

15Certified Wireless Network Administrator: CWNA – PW0-105

Page 16: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

Traffic Segmentation

16Certified Wireless Network Administrator: CWNA – PW0-105

• VLANs– Guest– Voice– Data

• RBAC

Page 17: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

Wireless VLANs

17Certified Wireless Network Administrator: CWNA – PW0-105

Page 18: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

Infrastructure Security

18Certified Wireless Network Administrator: CWNA – PW0-105

Page 19: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

VPN Wireless Security (Hotspot)

19Certified Wireless Network Administrator: CWNA – PW0-105

Page 20: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

VPN Wireless Security (Site-to-Site)

20Certified Wireless Network Administrator: CWNA – PW0-105

Page 21: Certified Wireless Network Administrator (CWNA) PW0-105 Chapter 13 802.11 Network Security Architecture.

Chapter 13 Summary

• 802.11 Security Basics• Legacy 802.11 Security• Robust Security• Traffic Segmentation• Infrastructure Security• VPN Wireless Security

21Certified Wireless Network Administrator: CWNA – PW0-105