Essentially there are three primary components in a typical 802.x Wireless Access POP topology:
typical 802.x Wireless Access POP topology:

The Client /User (CU) such as Computers, PALMS, other
802 capable devices, the Authenticator or wireless
Access Point (AP), and the Authentication Server

***However, I believe that one should consider a
Bastion/FW/NAT as a fourth and essential component.
This also reduces the threat of disclosure integrity or
accessibility from a Man-In-The-Middle Attack, which is
one of the vulnerabilities of Key-based cryptography.
Mirowave (MASER) jamming (you can build one for
about $99) is another significant DDOS threat, but I will
save that for another time.***

The Client/User (CU) communicates via 900Mhz – 2 GHz
 RF to wireless Access Point (AP). The AP is typically
(or should be in IMO) installed behind a Bastion Host
FW / NAT Box, this way the Bastion/NAT can control
the distribution of Internet IP, or specific IEFT 1918
address space for controlled access to a VPN/Intranet,
i.e. access the “Network”.

Typically, the CU communicates authentication
information with the AP, which forwards the information
to a RADIUS server to authenticate and authorize access
to the Network by the CU. The authentication information
between the CU AP and RADIUS is exchanged using the
EAP/TLS method. EAP/TLS is a Certificate Based
authentication method, which uses dynamic rotating 128
bit WEP keys for data encryption.

The CU must be able to do EAP/TLS, which Micro$oft
WinXP is able to do. Beware of the flaw in softee’s
implementation of x509. I think this was patched, but not

The AP more or less is a forwarder of the authentication
information and its primary existence is to act as a
wireless converter and router/gateway.

The RADIUS server typically interfaces with a Certificate
 Server / Key Encryption application such as OpenSSL
manage the cryptography and certs.

The Bastion Host keeps, for the most part, the good fenced
 in and bad fenced out. A honeypot or two is a good
addition as well. It gives a place for the kids to play.

That’s a quick view IMHO…




