WPA-Enterprise for Small Businesses (Part I)

By Eric Geier

July 18, 2008

An introduction to WPA-Enterprise security for small businesses and an overview of the best options for using it to secure an SMB WLAN.

It’s not a secret that the WEP (Wired Equivalent Privacy) encryption method for wireless networks can be easily cracked. Using WEP actually invites Wi-Fi eavesdroppers to take a stab at cracking your encryption key, so they can connect to your network in order to steal data and wreak havoc. This leaves you with using the more secure Wi-Fi Protected Access (WPA or WPA2) encryption method. However, you’ll find that the easy-to-setup WPA method (PSK or Pre-shared Key) is also vulnerable to cracking, which is explained in an earlier tutorial. Since each client or computer on the network has to be configured with the same passphrase, this method usually isn’t practical for small businesses that have employees using the network.

How WPA-Enterprise encryption works

If you require a highly secure wireless network, it’s best to use the WPA or WPA2 Enterprise encryption solution. After securely logging on to the network with a username and password, every client automatically receives a unique encryption key that’s long and regularly updated—making it impossible for a Wi-Fi snooper to intercept enough packets  (within hundreds of years) per key to decode a key. Even if a key was somehow decoded,  the extremely old hacker will find a new key would have already been put into place—the locks are already changed. Technically, WPA-PSK works by each client being assigned a unique encryption key, as well. However, the encryption keys for WPA-PSK are derived (between the client and access point/wireless router) in such a way that enables much easier decoding by eavesdroppers.

When using WPA-Enterprise, unlike WPA-PSK, employees won’t know the passphrase. This way they can’t share it with outsiders or use it when they are no longer employed with the company. WPA-Enterprise also can save you a great deal of time; the keys don’t have to manually changed on all of the clients. If you use WPA-PSK and you want to change the passphrase for your network (which is recommended on a regular basis to help prevent eavesdroppers from decoding it) you would have to go to each computer and input the new key.

Traditionally, the WPA-Enterprise implementation requires purchasing, installing, and configuring a RADIUS server and other technical components. This rather great investment of your money and time isn’t likely to be practical for your small business, especially if you lack a dedicated IT person or staff. This doesn’t have to be the case these days, however.

Your WPA-Enterprise options

In this series of tutorials you’ll discover some options to get enterprise-level wireless security to protect the sensitive information on your small business network. You don’t even have to drown yourself in the pool of network security acronyms. Here’s a sneak peak of some your options:

Buy an Access Point (AP) with a built-in RADIUS server: This is an easy way out; just purchase an AP with a built-in 802.1x RADIUS server that works with WPA/WPA2. You’ll find these APs, such as the USRobotics USR5453 or ZyAIR G-2000 Plus v2, online anywhere from $100 to $200 a piece. This solution typically is best if you only need a few APs for your entire wireless network and is more cost-effective if your APs already have this feature or you haven’t bought any yet.

To set up the server, all you have to do is select the wireless security type on the Web-based configuration screen and create accounts on the local databases of each of the APs. Then you can configure your client computers with the proper settings and you’re secured.

Use hosted third-party services: This is also another great way to ease the learning curve and simplify your wireless security journey. All you do is sign up for the service, configure your wireless router and/or APs, and set up your computers. The RADIUS server is hosted by the company. You’ll receive Web-based access to a portal where you can add/remove user accounts and APs.

WiTopia offers SecureMyWiFi, starting at $99 per year for one AP with up to 100 users, with +$99 one-time setup fee. Each additional AP costs $14.99 per year.

BoxedWireless offers this type of service for 1-10 users at $186 or 11-25 users at $257 per year (supports more users--see their Web site) with an unlimited number of APs.

Setup your own RADIUS server: If you want more control and flexibility of your encryption scheme, setting up a software-based server on your network that’s user-friendly and targeted towards small-businesses may be the way to go. That way you can have a bullet-proof Wi-Fi network up and running in a matter of an hour or two, rather than spending thousands of dollars on a traditional enterprise-level server that would take an average user days to wrap his or her head around.

You’ll need RADIUS/802.1x server software that supports protocols, such as Extensible Authentication Protocol (EAP). (We’ll discuss using Elektron in a later part.) The server handles the authentication of the clients trying to connect to your wireless network. It’s basically a database where you can list usernames and passwords for the people that you want to connect to your network. You input the address of the server into your wireless router and/or APs. Then, when someone tries to connect they’re prompted to login and the credentials are checked against those on the server. Additionally, the client computer must also have a certificate (a small file) installed and is checked against the certificates listed in the server.

Click here for Part 2.

Eric Geier is the Founder and President of Sky-Nets, Ltd., a Wi-Fi hotspot network. He is also the author of many networking and computing books, including Home Networking All-in-One Desk Reference For Dummies (Wiley 2008) and 100 Things You Need to Know about Microsoft® Windows Vista (Que 2007).



Comment and Contribute
(Maximum characters: 1200). You have
characters left.