Enterprise WiFi Hardening
Enterprise wireless networks are prime targets for attackers due to their exposure to both internal and external threats. Securing these networks requires a layered approach combining strong authentication, centralized management, and continuous monitoring. Below are best practices for hardening enterprise Wi-Fi infrastructure, with technical examples to guide implementation.
Authentication Protocols: WPA3-Enterprise as the Baseline¶
WPA3-Enterprise replaces WPA2 and provides stronger encryption, resistance to brute-force attacks, and improved key management. It mandates the use of EAP (Extensible Authentication Protocol) methods such as PEAP, EAP-TLS, or EAP-FAST.
Example: Configure WPA3-Enterprise on a Linux-based access point using hostapd:
# /etc/hostapd/hostapd.conf
interface=wlan0
driver=nl80211
ssid=Secure_Ess
hw_mode=a
channel=36
wpa=3
wpa_key_mgmt=WPA-EAP
wpa_pairwise=CCMP
rsn_pairwise=CCMP
eap_server=1
eap_user_file=/etc/hostapd/eap_users
Command to verify WPA3 support on a client:
Centralized Authentication: RADIUS Integration¶
Integrate access points with a RADIUS server (e.g., FreeRADIUS, Microsoft NPS) to enforce centralized user authentication and policy enforcement. This reduces reliance on static credentials and enables dynamic access control.
Example: Configure FreeRADIUS to validate user credentials:
# /etc/freeradius/radiusd.conf
clients {
client 127.0.0.1 {
secret = testing123
short_name = localhost
}
}
Command to test RADIUS authentication:
Network Segmentation and VLANs¶
Segment guest and internal networks using VLANs to limit lateral movement. Ensure that IoT devices and users are isolated from sensitive systems.
Example: Configure VLANs on a switch:
# Cisco IOS example
interface Vlan10
ip address 192.168.10.1 255.255.255.0
!
interface FastEthernet0/1
switchport mode access
switchport access vlan 10
Monitoring & Auditing: Detect Anomalies Early¶
Deploy tools like Wireshark, tcpdump, or SIEM systems to monitor traffic for rogue devices, credential leaks, or abnormal behavior.
Example: Use tcpdump to capture and analyze traffic:
sudo tcpdump -i wlan0 -n -s 0 'tcp port 443' -w capture.pcap
# Analyze with Wireshark: wireshark capture.pcap
Command to audit WPA3 handshakes:
aireplay-ng --deauth 0 -a [BSSID] -c [Client_MAC] wlan0
# Monitor for handshake captures using airodump-ng
Physical Security and Firmware Updates¶
Disable unused ports, use directional antennas to limit signal range, and enforce firmware updates for APs and controllers.
Example: Check for firmware updates on a Cisco AP:
Key takeaways¶
- Migrate to WPA3-Enterprise with EAP methods to secure client authentication.
- Centralize authentication via RADIUS to enforce policies and audit user access.
- Segment networks using VLANs to isolate sensitive systems and reduce attack surfaces.
- Monitor traffic continuously with tools like tcpdump or SIEMs to detect anomalies.
- Maintain physical and software security by updating firmware and restricting hardware access.