IAS (Internet Authentication Service)
Let's finish up the infrastructure WPA, for which we will start implementing our RADIUS server. For an organization to have a RADIUS server is not only a secure solution for wireless connections is also an important element in the authentication of VPN connections, both between remote sites to customers or to the solutions we come up NAP (Network Access Protection) and will soon be implemented in all companies.
If the RADIUS server implementation is something few users or not you want to deploy a dedicated server, you can easily purchase routers and / or Wireless Access Points, including within its firmware, small system RADIUS servers with EAP-MD5 authentication in most cases. Obviously this is a bit scalable solution because, first, forces us to replicate the user database in the firmware and also in the case that we have 2 or more Access Point we have to duplicate these users at all the AP or link them to think.
We will implement the solution as a RADIUS server for Microsoft, Internet Authentication Service (IAS). This is that in Windows 2000 Server is provided as a separate download but is a service that comes "standard" in Windows Server 2003 and installed like any other, with the option Control Panel Add / Remove Programs. This is a network component so that IAS should be selected within them.
Figure 1: Installing IAS component
Once installed you have to register the RADIUS server in Active Directory of our organization, and for that three options, the easy, from the management console IAS MMC , highlight your IAS server and choose the option "Regristrar Active Directory" (Figure 2), the craft: At the end, doing so through the console only is adding the machine account to certain privileged groups, so that we can do it manually and add the machine account of our IAS server to the security group RAS and IAS in Active Directory, and commands: You can also use the same process using the netsh command from the command line.
Figure 2: Register IAS in Active Directory
Once registered we can proceed to configure your IAS server. Three simple steps. First configure the logging of connections, both the correct and the failed to get an idea of \u200b\u200bwhat is happening with our network. This is a simple operation to detect intrusion attempts or connections "unusual" customer.
Second set up a Remote Access Policy, ie, who will be able to connect remotely, or what is the same in our environment, who will be able to make a wireless connection. To complete the server configuration we are going to be establishing the connection options, ie we require mechanisms to authenticate users.
Remote Access Policy
With IAS we can create remote access policies for all types of connections, VPN Client, Wireless Client, and even for network clients, which is what NAP is based. In this case we will create a Remote Access Policy for our customers and we Wireless create it by following the wizard. Select the option for Remote Access Policy and began:
Figure 3: Creating a Remote Access Policy
After entering the name of the policy dialogue box we got to where we are required to type Remote Access Policy that we are creating, as you can see in the image we have policies for VPN connections, dial calls Dial-up telephone lines point to point for wireless connections and even for ethernet connections, which will be used NAP. Select the Wireless option, of course, and continue forward.
Figure 4: Select type of Remote Access Policy
As we wish to integrate the security of connections within the infrastructure of our company, we create ourselves in our Active Directory user group in this case called "Bad" (pardon the pun), which will let users authorize the Remote Access Policy. It is necessary that users have permission to dial, as for the VPN connection or Dial-Up, as is the permission that is used for remote connections. As this is a bit cumbersome, selecting all the users and give them that permission, you can use an option Once created the policy with the wizard, on the properties to ignore and that permission be granted from IAS directly dial permission if you are the Remote Access Policy.
Figure 5: Selection of clients authorized by this policy
The authorization can be both user and machine level so we could make a double authentication, ie, authorized users and machines authorized. Once elected
user group must choose the authentication system. The two options to choose from.
Option 1: PEAP (Protected EAP), which as we saw last month generated using a TLS channel with server certificate, in this case the IAS server, then choose an authentication method the client will either password, sent by the MS-CHAP v2 protocol, or be used directly to a digital certificate thereof which tend on the client machine or a smartcard.
Option 2: Do not have canal TLS EAP authentication before, so we use a smart card based authentication and digital certificate installed on the client machine.
Figure 6: Selection of client authentication method
These options have finished creating the Remote Access Policy for our example. Note that you can create remote access policies so as we wish. These policies are to be evaluated as firewalls fewer higher order and applied the first match. Thus, we have authenticated connections from machines, or valid connections from any machine for some users, or connections are authenticated with passwords for devices that do not support smartcard, etc ... a need for infrastructure.
Figure 7: Properties Connection Policy Once created
policy we, entering their properties, define some specific values \u200b\u200bof it, as if time slot for the connection, time limits, IP address allocation, etc ... to further refine policy options.
Connection Request Policy
Okay, we have created the policy for our wireless customers, which will be authenticated or not our RADIUS server, now we have to configure the structure of authentication requests within our RADIUS servers . To do this we create a Connection Request Policy, ie which is the order of validation of the connections in the case we have a complex infrastructure.
default policy is created determines that the RADIUS server authenticate connections that originate directly or through a VPN connection using the database in Active Directory. Authentication If the RADIUS server or give another if the requests come through an ISP or any other parameter you want to check the connection, such as phone numbers on a dial-up or wireless card manufacturer we can create new connection policies. For our example, the default policy is perfect. High
RADIUS Client
We have defined Remote Access Policy and the Connection Request Policy, we set the trail and have the IAS server registered in Active Directory, what's left? For only discharging Acess points and / or Wireless Routers that can make requests to our server to authenticate clients. To do this in the RADIUS Clients create a new one.
Figure 8: High
RADIUS Client
first thing we request is the name we are going to give the access point and what is the DNS name or IP address from which it is accessible to our IAS server. Second, we must choose the type of RADIUS client is because although there is a standard, many manufacturers have made small changes on it in the form of communication.
Figure 9: Choosing RADIUS client type
Finally, most importantly, the shared secret between our RADIUS server and client. Is the mutual authentication is used. We might think that is an unsafe, since the shared key is not the best of ways of authenticating connections, but it is assumed that the physical connection between the client and the RADIUS server is a private and secured.
Figure 10: Configuring Shared Secret for RADIUS Client
When we finish this wizard, and registered as a RADIUS client to our AP, but the communication will not operate until a symmetrical manner to give high point in our RADIUS server Access or Wireless Router.
Figure 11: Client List
IAS RADIUS
To register to the RADIUS server must enter the administration tool in our Wireless Access Point and set the RADIUS server's IP address, port , which by default is 1812 and the shared secret. And it would be.
Figure 12: RADIUS Server Configuration in the AP
Client Configuration
To end the connection in the infrastructure we create the connection from the client, so it went into the options and give your network card Register a new wireless network. We discharged the same SSID, select the option of WPA and TKIP encryption. We spent the second part of authentication where you can select "PEAP" or "Digital Certificate or Smartcard."
Figure 13: Configuring WPA
Customer must realize that if we can use to authenticate using PEAP MS Chap v2 password or digital certificate or smartcard, while if we use digital certificate or smartcard can not use password. In both cases we choose the certification that we are using to validate all digital certificates for server and client, so you can see in the properties of both configurations.
Figure 14: Settings Authentication Properties
On the left is that we have used Digital Certificate or Smartcard and how we choose which will be our certificate and who is the certification that validates them. To the right is seen as an entity used to validate the server certificate to create the TLS tunnel and like then we can choose the way to authenticate with EAP-MSCHAP v2 or EAP-TLS.
802.11i WPA2 (Wi-Fi Protected Access 2)
WPA was born without a standard to support it in its origins, but taking into account what would be the 802.11i standard that would improve the WEP-based solutions. For this purpose, drafts and the information was obtained for WPA evolve. When they had a clear idea of \u200b\u200bwhat appeared would be 802.11i WPA2. What are the differences between WPA and WPA2? The answer should be said is that few and many. Much as long as it is based on the 802.11i standard that if a little change and if we consider that WPA was already focused on that destination. The main novelty is the system that includes AES encryption.
AES (Advanced Encryption Standard) AES
born as an initiative of the American government to replace DES as the encryption system. AES algorithm had a name before and was looking through a "mega-competition" worldwide algorithm which should be used. Rijndael was selected at the end is so named because of the curious mixture of the names of the two creators. From a technical standpoint, AES is the option we should use encryption with WPA2, but the use of AES involves the use of various encryption algorithms below. Actually, the algorithm is called 802.11i RSN (Robust Security Network) is a system that negotiates the encryption algorithm and authentication between the options supported and configured on client and server. RSN use permits you to negotiate with backward compatibility in the case of being necessary to live with devices that do not support AES and TKIP or WEP used as phones, PDAs, or older operating systems. RSN supports WEP-104 WEP, TKIP, WRAP and CCMP implementations are AES block cipher and stream cipher. Is not it all very sencillito?
business infrastructure
To mount a solution of this kind can not lie in the assembly manual that we used in these examples, but we rely on the utilities offered by the Active Directory. First, for the implementation of this infrastructure we have assumed that we had made a display of user and machine certificates within our organization. That is, PKI is the underlying infrastructure. Second, we have made configurations of the connections of individual customers, but this can be automated with policies.
Figure 15: Creating a Wireless Policy in Active Directory
This policy created a new organizational unit of the machine you want configured to use wireless connections and within settings machine level we created a new Wireless Connection Policy. Once we set the properties to establish what are the options for the wireless connection we want to create in customers. Here we must configure the same options we have seen in creating a connection from the client: SSID, Authentication, Encryption, and after authentication options.
Figure 16: Options for the Common Authentication Wireless
Other options of securing a wireless network
Yes, there are other options for securing wireless networks and businesses have been using basically two approaches based on the same: Authenticating connections.
To authenticate connections can use a different entry point to the wireless device, ie, instead of authenticating to the Access Point, you can let it connect to but after the AP you want we will find the company network will not allow connections that do not come from an authenticated client. And how clients authenticate valid?
Option 1: With VPN connections. Clients connect to the AP and from that connection is authenticated to the VPN server. Once the VPN server has been established that a client is valid and may be imposed on the network.
Option 2: Using digital certificates and IPSec. If the organization's network is deployed with IPSec communications, you can only communicate over the network connecting the client who has a digital certificate. This option is less desirable because communications unencrypted if that can be captured by an intruder and can even get information that is not desirable.
Farewell and Close
three months have been talking about how to secure a wireless network and because you have to do it, so you have no excuse. Secures your network for three reasons.
1) There is technology to do so.
2) It is difficult and you know it.
3) Always thinking of someone boring like "fun."
Author: Chema Alonso. Microsoft MVP Windows Security
Let's finish up the infrastructure WPA, for which we will start implementing our RADIUS server. For an organization to have a RADIUS server is not only a secure solution for wireless connections is also an important element in the authentication of VPN connections, both between remote sites to customers or to the solutions we come up NAP (Network Access Protection) and will soon be implemented in all companies.
If the RADIUS server implementation is something few users or not you want to deploy a dedicated server, you can easily purchase routers and / or Wireless Access Points, including within its firmware, small system RADIUS servers with EAP-MD5 authentication in most cases. Obviously this is a bit scalable solution because, first, forces us to replicate the user database in the firmware and also in the case that we have 2 or more Access Point we have to duplicate these users at all the AP or link them to think.
We will implement the solution as a RADIUS server for Microsoft, Internet Authentication Service (IAS). This is that in Windows 2000 Server is provided as a separate download but is a service that comes "standard" in Windows Server 2003 and installed like any other, with the option Control Panel Add / Remove Programs. This is a network component so that IAS should be selected within them.
Once installed you have to register the RADIUS server in Active Directory of our organization, and for that three options, the easy, from the management console IAS MMC , highlight your IAS server and choose the option "Regristrar Active Directory" (Figure 2), the craft: At the end, doing so through the console only is adding the machine account to certain privileged groups, so that we can do it manually and add the machine account of our IAS server to the security group RAS and IAS in Active Directory, and commands: You can also use the same process using the netsh command from the command line.
Once registered we can proceed to configure your IAS server. Three simple steps. First configure the logging of connections, both the correct and the failed to get an idea of \u200b\u200bwhat is happening with our network. This is a simple operation to detect intrusion attempts or connections "unusual" customer.
Second set up a Remote Access Policy, ie, who will be able to connect remotely, or what is the same in our environment, who will be able to make a wireless connection. To complete the server configuration we are going to be establishing the connection options, ie we require mechanisms to authenticate users.
Remote Access Policy
With IAS we can create remote access policies for all types of connections, VPN Client, Wireless Client, and even for network clients, which is what NAP is based. In this case we will create a Remote Access Policy for our customers and we Wireless create it by following the wizard. Select the option for Remote Access Policy and began:
After entering the name of the policy dialogue box we got to where we are required to type Remote Access Policy that we are creating, as you can see in the image we have policies for VPN connections, dial calls Dial-up telephone lines point to point for wireless connections and even for ethernet connections, which will be used NAP. Select the Wireless option, of course, and continue forward.
As we wish to integrate the security of connections within the infrastructure of our company, we create ourselves in our Active Directory user group in this case called "Bad" (pardon the pun), which will let users authorize the Remote Access Policy. It is necessary that users have permission to dial, as for the VPN connection or Dial-Up, as is the permission that is used for remote connections. As this is a bit cumbersome, selecting all the users and give them that permission, you can use an option Once created the policy with the wizard, on the properties to ignore and that permission be granted from IAS directly dial permission if you are the Remote Access Policy.
The authorization can be both user and machine level so we could make a double authentication, ie, authorized users and machines authorized. Once elected
user group must choose the authentication system. The two options to choose from.
Option 1: PEAP (Protected EAP), which as we saw last month generated using a TLS channel with server certificate, in this case the IAS server, then choose an authentication method the client will either password, sent by the MS-CHAP v2 protocol, or be used directly to a digital certificate thereof which tend on the client machine or a smartcard.
Option 2: Do not have canal TLS EAP authentication before, so we use a smart card based authentication and digital certificate installed on the client machine.
These options have finished creating the Remote Access Policy for our example. Note that you can create remote access policies so as we wish. These policies are to be evaluated as firewalls fewer higher order and applied the first match. Thus, we have authenticated connections from machines, or valid connections from any machine for some users, or connections are authenticated with passwords for devices that do not support smartcard, etc ... a need for infrastructure.
policy we, entering their properties, define some specific values \u200b\u200bof it, as if time slot for the connection, time limits, IP address allocation, etc ... to further refine policy options.
Connection Request Policy
Okay, we have created the policy for our wireless customers, which will be authenticated or not our RADIUS server, now we have to configure the structure of authentication requests within our RADIUS servers . To do this we create a Connection Request Policy, ie which is the order of validation of the connections in the case we have a complex infrastructure.
default policy is created determines that the RADIUS server authenticate connections that originate directly or through a VPN connection using the database in Active Directory. Authentication If the RADIUS server or give another if the requests come through an ISP or any other parameter you want to check the connection, such as phone numbers on a dial-up or wireless card manufacturer we can create new connection policies. For our example, the default policy is perfect. High
RADIUS Client
We have defined Remote Access Policy and the Connection Request Policy, we set the trail and have the IAS server registered in Active Directory, what's left? For only discharging Acess points and / or Wireless Routers that can make requests to our server to authenticate clients. To do this in the RADIUS Clients create a new one.
RADIUS Client
first thing we request is the name we are going to give the access point and what is the DNS name or IP address from which it is accessible to our IAS server. Second, we must choose the type of RADIUS client is because although there is a standard, many manufacturers have made small changes on it in the form of communication.
Finally, most importantly, the shared secret between our RADIUS server and client. Is the mutual authentication is used. We might think that is an unsafe, since the shared key is not the best of ways of authenticating connections, but it is assumed that the physical connection between the client and the RADIUS server is a private and secured.
When we finish this wizard, and registered as a RADIUS client to our AP, but the communication will not operate until a symmetrical manner to give high point in our RADIUS server Access or Wireless Router.
IAS RADIUS
To register to the RADIUS server must enter the administration tool in our Wireless Access Point and set the RADIUS server's IP address, port , which by default is 1812 and the shared secret. And it would be.
Client Configuration
To end the connection in the infrastructure we create the connection from the client, so it went into the options and give your network card Register a new wireless network. We discharged the same SSID, select the option of WPA and TKIP encryption. We spent the second part of authentication where you can select "PEAP" or "Digital Certificate or Smartcard."
Customer must realize that if we can use to authenticate using PEAP MS Chap v2 password or digital certificate or smartcard, while if we use digital certificate or smartcard can not use password. In both cases we choose the certification that we are using to validate all digital certificates for server and client, so you can see in the properties of both configurations.
On the left is that we have used Digital Certificate or Smartcard and how we choose which will be our certificate and who is the certification that validates them. To the right is seen as an entity used to validate the server certificate to create the TLS tunnel and like then we can choose the way to authenticate with EAP-MSCHAP v2 or EAP-TLS.
802.11i WPA2 (Wi-Fi Protected Access 2)
WPA was born without a standard to support it in its origins, but taking into account what would be the 802.11i standard that would improve the WEP-based solutions. For this purpose, drafts and the information was obtained for WPA evolve. When they had a clear idea of \u200b\u200bwhat appeared would be 802.11i WPA2. What are the differences between WPA and WPA2? The answer should be said is that few and many. Much as long as it is based on the 802.11i standard that if a little change and if we consider that WPA was already focused on that destination. The main novelty is the system that includes AES encryption.
AES (Advanced Encryption Standard) AES
born as an initiative of the American government to replace DES as the encryption system. AES algorithm had a name before and was looking through a "mega-competition" worldwide algorithm which should be used. Rijndael was selected at the end is so named because of the curious mixture of the names of the two creators. From a technical standpoint, AES is the option we should use encryption with WPA2, but the use of AES involves the use of various encryption algorithms below. Actually, the algorithm is called 802.11i RSN (Robust Security Network) is a system that negotiates the encryption algorithm and authentication between the options supported and configured on client and server. RSN use permits you to negotiate with backward compatibility in the case of being necessary to live with devices that do not support AES and TKIP or WEP used as phones, PDAs, or older operating systems. RSN supports WEP-104 WEP, TKIP, WRAP and CCMP implementations are AES block cipher and stream cipher. Is not it all very sencillito?
business infrastructure
To mount a solution of this kind can not lie in the assembly manual that we used in these examples, but we rely on the utilities offered by the Active Directory. First, for the implementation of this infrastructure we have assumed that we had made a display of user and machine certificates within our organization. That is, PKI is the underlying infrastructure. Second, we have made configurations of the connections of individual customers, but this can be automated with policies.
This policy created a new organizational unit of the machine you want configured to use wireless connections and within settings machine level we created a new Wireless Connection Policy. Once we set the properties to establish what are the options for the wireless connection we want to create in customers. Here we must configure the same options we have seen in creating a connection from the client: SSID, Authentication, Encryption, and after authentication options.
Other options of securing a wireless network
Yes, there are other options for securing wireless networks and businesses have been using basically two approaches based on the same: Authenticating connections.
To authenticate connections can use a different entry point to the wireless device, ie, instead of authenticating to the Access Point, you can let it connect to but after the AP you want we will find the company network will not allow connections that do not come from an authenticated client. And how clients authenticate valid?
Option 1: With VPN connections. Clients connect to the AP and from that connection is authenticated to the VPN server. Once the VPN server has been established that a client is valid and may be imposed on the network.
Option 2: Using digital certificates and IPSec. If the organization's network is deployed with IPSec communications, you can only communicate over the network connecting the client who has a digital certificate. This option is less desirable because communications unencrypted if that can be captured by an intruder and can even get information that is not desirable.
Farewell and Close
three months have been talking about how to secure a wireless network and because you have to do it, so you have no excuse. Secures your network for three reasons.
1) There is technology to do so.
2) It is difficult and you know it.
3) Always thinking of someone boring like "fun."
Author: Chema Alonso. Microsoft MVP Windows Security
0 comments:
Post a Comment