Go to Main Contents

:: Industry developments

How does the WiFi certification system use 802.1X to make wireless access a single-lined one?

Many units, when planning the WiFi certification system, consciously understand it as"Add a login page to the wireless network"But when we put the cable and the wireless together, it's complicated: Wireless...

Your position:Home > Content Centre > Industry News > > Text

Many units, when planning the WiFi certification system, consciously understand it as"Add a login page to the wireless network"But when we really put the cable and wireless networks together, the problem is complicated: Wireless can play Portal pages, what about the wired site? What about printers, cameras, and time-to-work machines that do not have browsers? What's the process of taking notebooks that are temporarily connected to the conference room? If the network is completely excluded from authentication, it would be like putting doors in the yard but leaving a secure way for the side door.

This is 802.1 X certification. NATSHEL_BRAND V7 Authentication & Billing authentication in the form of a system, 802.1 X is port-level authentication with an exchange or NAC connection: when terminal access is at the interface, the portal does not give traffic first, and only opens when the terminal has completed identification. If authentication fails, the port is closed. The difference between it and Portal is that Portal authenticates are"People play pages, lose accounts."This action, 802.1X certified"Is this terminal that's connected to the port a authorized device?"This thing itself.

Why does 802.1X have a bottom-line wireless access?Because wireless side can take 802.1X to the wireless terminal through AC, Cable side switches directly support 802.1X, so that the endway is a single identification check whether it is connected from the portal or WiFi. For IT, the direct benefit is to maintain an identity source rather than a wireless one, a cable one, and a visitor one by one, in the WiFi network in the conference room, and SSID below the floor.

Here, one boundary is highlighted: 802.1X's landing relies heavily on the ability of a switcher or NAC. V7 provides 802.1X authentication capability as an authentication server, but in each case it needs to be confirmed whether it supports the 802.1X agreement, which type of EAP (PEAP, EAP-TLS etc.), and whether port configuration can interface with certification systems. The rules in the knowledge base are clear: the feasibility of intersystem interfaces depends on whether interfaces are open, that fields are mapable, and that the connection conditions are not available because"Switches to 802.1X"Default"We'll be able to get on board with V7."。

The biggest pit in operation is"One cut."。Some units have been severely certified for all ports as soon as they hear that 802.1X security levels are high, and the next day printers are collectively disconnected, conference room equipment is completely delineated, visitors are totally out of reach. 802.1X should be separated from port to site: staff-level interfaces are strictly authenticated, visitor regional portals are released from Portal or Visitors Network, dumb terminal white lists are made or assigned directly to isolated VLAN. V7 is capable of supporting a differential strategy by port, user group, but which ports are tight and which vents are loose must be determined by unit according to actual scenario, which is a strategic design issue, not a product problem.

There is also a real problem:Compatibility of older devices. If the units are purchased a few years ago, some low end models may not support 802.1X or there is limited EAP types to support. Either this will be done with strict certification of capable floors or an alternative solution in old areas."You buy a certification system and you can handle all the Internet outlets."The coverage of 802.1X should be determined by mapping the existing switch model.

Also, the difference between 802.1X and Seamless Authentication. Some people think that 802.1X has a bad experience and always loses an account number. After coordinating with EAP-PEAP or certificate, the terminal remembers identity for the first time, and its access is almost non-existent."Trouble."Focus on the first configuration: Windows computers need to be equipped with trusted root certificates or 802.1X settings, and mobile phones need to install description files. So 802.1X is more appropriate for a public setting where businesses, government enterprises, banks are controlled, IT can be integrated into configurations, and hotels, malls, etc. are completely uncontrollable.

View 802.1X, Portal, and Visitors ' Networks together. Full access to one unit should be layered: the core office area is wired 802.1X, the general office area is used as Portal plus account code, visitors are left with independent SSID text messages or temporary authorization codes, and the dumb terminal is sent out on the MAC White List. Each level corresponds to different security levels and management costs, V7 NAMSHELL_AUTH_BILLING combines these authentication methods on the same platform by user, region, network. This is the complete form of wired wireless access, not just one place with a login.

Finally, it is important to do greyscale before the 802.1X is online. Run for two weeks on the pilot floor and confirm that there are no problems with the employee terminal configuration, printer dumb terminals, conference room equipment, and then gradually extend to all office areas.

There is another detail that is often asked: 802.1X and Seamless Authentication, which can be used together. The answer is yes, and many items are matched by this. Staff members walk 802.1X through the office terminal to record their identity on a switchboard or an AC after certification, in conjunction with unconscious mechanisms, follow-up AP switching or reconnecting every day without repeating the number of the account.802.1X settlement"Is this terminal legal?"I don't know what to do with it."Do you want to re-certification every time a legitimate device gets in?"The two mechanisms are concerned with different links. But note that unwitting release is bound to validity and end features, otherwise people can mix the features of this device and lower security levels.

The PEAP-type EAP method requires terminal verification of server certificates, the unit to have a certificate system ready and the end side to install or trust the corresponding root certificate.——Looks like it."WiFi's connected, but not online.". The certificate is then entered into the transport process before being online, and not waiting for user batch feedback to check it.

Access Program I'll be right back. Telephone counselling