Re: [fw-wiz] Discretionary WiFi Access

From: Brenno Hiemstra (brenno.hiemstra_at_gmail.com)
Date: 07/08/05

  • Next message: StefanDorn_at_bankcib.com: "RE: [fw-wiz] Discretionary WiFi Access"
    To: firewall-wizards@honor.icsalabs.com
    Date: Fri, 8 Jul 2005 17:42:25 +0200
    
    

    Read this overview:

    http://www.netcraftsmen.net/welcher/papers/wlandesign02.html

    I think this describes some technologies that could be applicable for your case.

    Brenno.

    > -----Original Message-----
    > From: firewall-wizards-admin@honor.icsalabs.com
    > [mailto:firewall-wizards-admin@honor.icsalabs.com] On Behalf Of Dave Null
    > Sent: Friday, July 08, 2005 2:17 AM
    > To: firewall-wizards@honor.icsalabs.com
    > Subject: [fw-wiz] Discretionary WiFi Access
    >
    > Its not firewall related, but there's some smart minds on this list.
    > My company has started looking into campus-wide WiFi. I'll keep my personal
    > feeling on this to myself though. One thing that keeps comming up is that
    > one of the largest user communities that would take advantage of this would
    > be non-employees. Vendors, Salesmen, people meeting with GMs/VPs/Execs are
    > probably going to be the main users of this. My question is, if you
    > currently have a similar situation in your work environment, how do you
    > handle granting these people temp/guest WiFi access.
    >
    > Access controls for employees can be fairly stringent (i.e. only connect
    > from company owned assets who's MAC is inventoried, use of 2 factor
    > authentication, etc), but a lot of this isnt applicable for temporary
    > visitors. I know one company that would give you a WiFi card when you signed
    > in that was in their database of 'allowed' MAC addresses (I know, dont get
    > me started on MAC spoofing), however I would bet cash money that those cards
    > walked away regularly. Similar thing with issuing a temporary token fob
    > (SecureID or the like).
    >
    > I know the easy answer here is 'Dont give them WiFi access', but I don't
    > think that is going to be an option. Thoughts, comments, flames?
    >
    > -noid
    > _______________________________________________
    > firewall-wizards mailing list
    > firewall-wizards@honor.icsalabs.com
    > http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    >
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: StefanDorn_at_bankcib.com: "RE: [fw-wiz] Discretionary WiFi Access"

    Relevant Pages

    • Re: [fw-wiz] Discretionary WiFi Access
      ... I know one company that would give you a WiFi card ... > when you signed in that was in their database of 'allowed' MAC ... > addresses (I know, dont get me started on MAC spoofing), however I ... > I know the easy answer here is 'Dont give them WiFi access', ...
      (Firewall-Wizards)
    • Re: [fw-wiz] Discretionary WiFi Access
      ... I know one company that would give you a WiFi card ... > when you signed in that was in their database of 'allowed' MAC ... > addresses (I know, dont get me started on MAC spoofing), however I ... > I know the easy answer here is 'Dont give them WiFi access', ...
      (Firewall-Wizards)
    • Re: wireless and XP sp2
      ... > see wifi access point but not connect. ... it's uising wep 64 bit. ... See if there are updated drivers for that wifi card from DLink. ...
      (microsoft.public.windowsxp.general)