Lost Password? No account yet? Sign up! Why bother?
  • Narrow screen resolution
  • Wide screen resolution
  • Auto width resolution
  • Increase font size
  • Decrease font size
  • Default font size

SmallNetBuilder - Small Network Help

  
Home arrow Wireless arrow Wireless How To arrow How To: Setting up FreeRADIUS for WPA & WPA2 Enterprise - Part 1
How To: Setting up FreeRADIUS for WPA & WPA2 Enterprise - Part 1 Print E-mail
Brandon Teska   
November 02, 2007

The Different Flavors of WPA

That's enough background. Let's start talking about WPA. WPA stands for Wi-Fi Protected Access. The original version—WPA—was created by a group organized by the Wi-Fi Alliance. WPA was a stop-gap measure, intended to restore confidence in 802.11 wireless technology that was lost when it was shown that its original security technology—WEP—could be easily compromised.

WPA is based on a subset of IEEE 802.11i, which was slowly crawling toward completion.

WPA2 is an enhanced version of WPA, based on the final, ratified version of IEEE 802.11i. The key difference between WPA and WPA2 is that WPA uses TKIP encryption while WPA2 uses the stronger AES.

Both WPA and WPA2 come in two versions: "Personal" and "Enterprise". The Personal versions are typically referred to as WPA-PSK and WPA2-PSK, with "PSK" meaning "Pre-Shared Key", which is a fancy term for password. The Enterprise versions are commonly referred to as WPA-RADIUS and WPA2-RADIUS because they require a RADIUS server employing one of five different EAP standards. If you want the long story behind why five EAP standards, George Ou's article is suggested reading.

Version Encryption Authentication Pros Cons
WPA-Personal TKIP PSK - Easy to set up
- Wide h/w support
- Weaker encryption
- Weak passwords are susceptible to dictionary-type attacks
WPA-Enterprise TKIP RADIUS+EAP - Robust authentication - Weaker encryption
- Requires RADIUS server
- Difficult to set up
WPA2-Personal AES PSK - Easy to set up
- Strong encryption
- Weak passwords are susceptible to dictionary-type attacks
- Might not be supported on older h/w
WPA2-Enterprise AES RADIUS+EAP - Robust authentication
- Strong encryption
- Might not be supported on older h/w
- Requires RADIUS server
- Difficult to set up
Table 1: Summary of WPA / WPA2 Key Features

Table 1 summarizes the key features and attributes of the four versions. The short story is that you should be using WPA2 if your hardware supports it and WPA2 Enterprise for the most security.

Tip: Our testing of Draft 802.11n products show significant throughput reduction when using WEP or WPA wireless security. You'll need to use WPA2 (either Personal or Enterprise) in order to minimize throughput loss—which can still run up to around 20% with some products.

The good news is that, with a few exceptions, all current-generation "Wi-Fi" products support at least WPA2 Personal. The bad news is that there are many wireless LAN products out there that can't be upgraded to support WPA2. Sometimes this is because their vendors have not produced the required driver and firmware updates. But there are also older products such as Wi-Fi VoIP phones and media players whose chipsets can't handle the higher number-crunching requirements of AES.

If you find yourself in this situation, your only options are to contact the problem product's vendor and ask if there is a WPA2 update available. If there isn't, see if there is a WPA upgrade. Newer Wi-Fi access points and routers will allow you to run a mix of WPA and WPA2 clients. (They won't allow you to mix WEP and either WPA or WPA2.) If neither WPA or WPA2 is available, you'll need to replace the product with one that supports WPA2.

Conclusion

I have set up the basic concepts behind why your wireless network needs strong encryption and authentication and provided some background on how the authentication and encryption process works. In Part 2, I'll show you how to tie all of this together and set up FreeRADIUS (which really is Free, except for the computer you need to run it on) to implement WPA2-Enterprise and add industrial-strength security to your wireless network.



Tags: FreeRADIUS, How To, RADIUS, WiFi, WPA, WPA2,

Related Articles:

Cisco jumps on the draft 11n bandwagon
WPA - Wireless Security for the rest of us
Smart Switch How to - Part 2: Security
PGP Universal - Part 1
SMC intros dual-band outdoor AP/bridges
 

Most Read

 
 

Slideshows

Western Digital My Book World Edition II (white bar) Buffalo TeraStation III Linksys WET610N Wireless-N Ethernet Bridge with Dual-Band NETGEAR ReadyNAS Vault Buffalo Linkstation Pro XHL LaCie Network Space More

Over At The Forums

Are STBC mandatory for 802.11n?
STBC for those who don't know are "Space Time Block Code" the feature of 802.11n that is supposed to extend the range to infinity and...

Definitely clueless..Please help!
Hey there. First let me tell you that I am really NOT technically savvy. I mean I can follow instructions (I was able to connect...

good laptop card to use w/WZR-HP-G300NH?
Going to order a Buffalo WZR-HP-G300NH wireless router. Was looking for advice on a laptop card (32 bit cardbus card) for my gf's laptop (Inspiron...

Best way to sync NASs directly (not through computers)
I just finished reading Kevin's "How To Back Up Offsite for Free with rsync" article and it was pretty useful *but* it dealt with doing...

Wirless NIC and Vista64.
I've lately noticed frequent packet loss and connection drop from my desktop in my usual doings (gaming & web browsing). I thought this connection was...

Go Shopping with PriceGrabber

Get Email Updates

Enter your email address:

Delivered by FeedBurner once a day

 
 

Ldr:0.00158786773682, Rct:0.00567388534546, Sky:0.00698280334473, Tlink:0.237418889999, TopPG:0.23749089241, GQV:0.237628936768 seconds to load.