Go to Main Contents

:: Industry developments

How does the WiFi certification system separate LDAP from the crowd?

The government agencies have a different system of WiFi certification than businesses and hotels.

Your position:Home > Content Centre > Industry News > > Text

The government services have a network of offices for internal staff, a network of service areas for the public, and a large number of networks that access their superiors."Easy."It's..."Controllable, manageable, retroactive"And it also determines the logic of the way government is accredited.

The NATSHELL_BRAD V7 Authentication & Billing system has a clear scope to cover the needs of government business certification, wireless access for government enterprises, and uniform administrative accreditation. On the certification mapping, the Government/Government landscape recommends double factor authentication, 802.1X certification and LDAP certification, alternative text messages and APs, similarly, do not recommend account passwords as the only authentication tool.

The government units are certified WiFi, usually in two lines.One line is the internal staff office network: the computer access network of employees is subject to a single identity certificate, and the unit ' s personnel system or Windows domain is combined with automatic opening of employee entry accounts and withdrawals from service, where LDAP certification works. V7 supports LDAP certification, combines it with Windows domain certification, and allows employees to access WiFi by using a domain account, without having to put an independent web account code. The other line is the public and visitor network: people can connect WiFi to the service hall, authenticating with SMS codes, which means that they can only visit the Extranet and cannot access the Web. The separation of the two lines from authentication sources, certification modalities and network privileges is a basic requirement for the political landscape.

The LDAP interface is the most effective link to government.If the unit has already built a single identity platform or AD domain, network authentication should be restored to this identification system instead of creating another account number. This means that all changes and additions to the employee's account numbers are done on the same identity platform, automatically synchronizing the web side, avoiding"People are leaving. The Internet account is still there.". The interface of the LDAP is conditional on opening up to the end interface and field mapping. The technical stacks of the unified identity platform, field specifications, interface openness vary from unit to unit, and V7 has LDAP docking capability, specifying whether it is successful, how the fields are mapped, if it is necessary to connect, and confirming by project that all units can be connected directly.

The political scene is more sensitive to security phase, and the security situation is not a problem.Access to core office areas could be considered 802.1XThe security phase is full with double-causing authentication for wireless access to highly sensitive areas, account password plus SMS. The logic of the panorama is that when project security level requirements are most advanced, double-factors and 802.1X are recommended, which is often hard in the internal government landscape.

The government projects also pay special attention to logs and audits. People’s online logbooks, employee logbooks of online behavior may be subject to regulatory checks and audit requirements."Fully meets all audit requirements", one by one.

There is also a detail specific to the political scene:Public Internet experience in the service lobbyThe WiFi page of the government administration and the marketing page of the business are two completely different design ideas, which need to be restrained, authoritative, and accessible, and which can be active and marketable. The program is designed in such a way as not to confuse these two lines.

Final recommendation: the government sector selects the WiFi certification system, which answers three questions first——The answer to three questions basically determines the method of authentication: a single identity source takes LDAP, a crowd takes a text message and a core area goes 802.1X plus two. This framework allows for much clearer discussion with the manufacturer, and does not lead to a multiplicity of unserviceable functions.

The government project also has a feature: it is common for a multi-sectoral network to be shared. There may be dozens of departments in an administrative centre, where the network is shared, but each department has accounts and boundaries of authority to be cleared.Departments are connected as independent regions or projects, account numbers, strategies and statements are segregated by department, departments run their own users and network management manages the entire organizationThis is in line with the multi-level authority logic of a chain of enterprises, but the sectoral boundaries are more serious in the political landscape and the consequences of cross-border access are even more severe.

Add a more detailed location: the policy of access to government units often changes with their superiors, such as temporary requirements to limit access to an area’s out-of-network for a certain period of time, and ad hoc actions to focus on keeping a certain type of log. The strategy of certification systems needs to be fast-adjusted, rather than always re-configurated. V7 strategies support rapid strategic landings by time, user, region, and ad hoc regulatory requirements. When the programme communicates, it is of real value to the day-to-day management of government projects.

Access Program I'll be right back. Telephone counselling