Pages

Thursday, October 28, 2010

How to manage AP Folder in AirWave

What is folder management ? Folder in layman term means something that we can represent as location or building or LAN Room where we can group our AP. In my case, I named it based on geographical location and buildings. Currently, I'm managing a nation wide wireless infrastructure. It is important to group all the APs in order to simplify all our works. It helps us to manage the reporting and also identifying which AP is currently down. 

Firstly you need to log on to your Airwave server. After you successfully login to the Airwave Management Platform server, you will see the user interface as below:


Wednesday, July 14, 2010

How to set the start-time of future user on Aruba Controller ?

Many wireless administrator looking for a solution on how to set the start-time or specifying the detail such as duration/expiry time for our future user on Aruba Controller. I never come across the solution on Airheads before. Normally, by using GUI based of Aruba controller powered with ArubaOS 3.3.1.22, we can add the user inside the internal database are as follows:
Go to Configuration tab, select Authentication under security section, and click Servers tab. Then click Internal DB.
Configuration > Authentication > Servers > Internal DB
After that, there will appear configuration windows as follows:

Monday, May 18, 2009

How to configure Ubuntu 8.10 / 9.04 for 802.1x WPA TKIP environment

IIUM wireless environment implement WPA authentication and TKIP encryption. The overall using 802.1x authentication method which deploy protected EAP (PEAP) using EAP token. User database stored in a Radius server by using FreeRadius running on FreeBSD platform. 


One of my user said, before upgrading his Ubuntu 8.10, he was using Ubuntu Hardy Heron 8.04. The previous Ubuntu is running well. Once he upgrade it to Ubuntu 8.10, he cannot get connected to our secure wireless environment anymore. 

Hmmmmm... while other user with other stardard OS e.g Windows XP, Mac OS and Windows Vista doesn't have any problem, so I suspect, the WPA configuration in Ubuntu 8.10 something need to change drastically. It seems like doesn't works well in a secured wireless environment. 

We have tried and yes, it does not work with IIUM wireless campus. I tried to switch to fedora 10, but the result is still the same. Then we tried to migrate to knoppix, my best linux distro ever, but still not working and become more worst when knoppix cannot detect Intel PRO/Wireless 3945ABG device. We dont want to use ndiswrapper since it finally could corrupt my entire OS. FYI, Suse linux will work smoothly with IIUM wireless.


Thursday, February 19, 2009

Why we need to deploy network access control (NAC) ?

The deployment plan of Network Access Control (NAC) technology in IIUM aims to protect IIUM heterogeneous wireless networks from the public back door (possibly done through 3G, bluetooth, firewire, UTP, USB etc), and often dangerous, Internet. It also provides protection from viruses and other types of malware that may be resident on the mobile gadgets that staff, students and visitors connected into IIUM wireless networks. NAC places a virtual shield around a network by guarding its endpoints, the places where heterogeneous wireless networks mesh with the outside world.
While NAC vendors take various approaches to NAC, the technology basically works by treating all endpoints with suspicion. Access to the wireless network is granted only after Aruba Wireless Controller, LDAP and NAC authenticates the user’s identity (username, password and MAC address), verifies the security state of the user’s endpoint and ensures that the user meets policies that define who should be allowed to use which resources and under what conditions (using role base idenfication offered by Aruba Controller).
A survey conducted earlier this year by Infonetics, a technology research firm located in San Jose, Calif., found that enterprises acquire NAC technology for various reasons, including blocking viruses (86 percent), intercepting external attacks (80 percent), stopping spyware/malware (73 percent) and blocking e-mail attacks (70 percent). Other motivations cited by the respondents included regulatory compliance (54 percent), adding LAN security (45 percent), blocking internal attacks (38 percent) and meeting customer and business partner demands (36 percent).
Much of NAC’s overall appeal comes from its simplicity, as well as its ability to provide enhanced security and more sanitized networks with little or no negative impact on the community productivity especially in IIUM. In fact, many instituition that have adopted NAC technology report improved productivity. By deploying this IIUM Community are now free to use devices that were formerly banned from any other enterprises networks due to security concerns. By deploying NAC, ITD is trying to secure the wireless connection even browsing via smartphone or PDA since this devices is not really have a good antivirus software.
NAC often arrives on customer premises in the form of a network appliance. This approach is appealing to many enterprises, and the solution that ITD is looking for: the appliance must simply be plugged into the wireless network, providing fast, painless, out-of-the-box security and avoid changes to the existing configuration. Many NAC appliances are multifunction security devices, offering capabilities such as network-based virus scanning and intrusion prevention systems (IPSs) along with NAC capabilities. The appliance must be capable to integrate with the existing equipments.
Non-appliance-based approaches to NAC are more complex and tend to require a bit more hands-on work. The available alternate choices are to enforce NAC with functionality that’s built into network devices, such as switches, or to enforce NAC using SSL VPN gateways.
No network is airtight—malware continues to get in, whether via mobile gadget (PDA, smartphone) of staff, student or guest laptops, or end users downloading dodgy content. Antivirus software at the gateway or on the desktop helps with computers under your control, but guests and unmanaged servers remain problematic. And let’s face it: Sometimes attackers are just smarter than we are. Even the companies following best practices get hit.
Deploying NAC don’t just mean a security best practices, either. Protecting the network from malicious hosts is, ultimately, a desktop management function. NAC is what puts teeth in our policies, providing an enforcement mechanism that helps ensure computers are properly configured. By weighing such factors as whether a user is logged in; their computer’s patch level; and if anti-malware or desktop firewall software is installed, running and current, ITD can decide whether to limit access to network resources based on condition or not. A host that doesn’t comply with your defined policy could be directed to remediation servers, or isolate it in a quarantine VLAN.
Remember Slammer? If a company could have determined that a host was running an unpatched version of MSDE 2000 and denied access until it was patched, Slammer would have had a much less dramatic effect.
After reviewing other reading materials,
NAC’s soaring popularity which has attracted numerous vendors to the market. NAC technology suppliers include such heavyweights as Bardford, Microsoft, Infoexpress, Juniper, Consentry, Cisco, Fortinet and Aruba Networks. Altogether, there are close to 50 +/- NAC vendors, large and small, meaning that enterprises have plenty of products and approaches to choose from.
With all the available choices, settling on the right NAC technology from the right vendor requires a significant amount of research. The final selection usually boils down to finding the product that most closely matches the IIUM’s NAC goals and the network’s size, complexity, budget and configuration.

Monday, December 1, 2008

IIUM Wireless : No. 1 Benchmark for Secure Wireless Depoyment in Malaysia ?

Unofficially, IIUM Wireless has become a reference model by other IPTA in Malaysia for campus wide wireless deployment. This rumours has been talked among the system integrators and vendors in Malaysia. FYI, UM has visited us for discussion and sharing experience which are related to wifi deployment. I have mentioned it  in my previous post. Click here.
IIUM has deployed a secured wireless infrastructure which is based on role-based identity authentication. IIUM is the first organization deploying this kind of authentication method in Malaysian. Thanks to Dr. Unggul for his experties and concern on wireless security issues in the beginning of design stage of wireless implementation. The facts can be obtained from this link. Click here.

Tuesday, October 14, 2008

Installing Wireshark

During my Aruba SWDI Training in KL, my instructor Mr. Kevin Hamilton has teached us a little bit about network security analyst’s toolkit using Wireshark. Immediately after the training session, I try to find a way where to got this analyzer (freedownload if possible) and how to install it.
According to the security expert in the University of Notre Dame, Mike Chapple… he said, Installing Wireshark is a piece of cake. Binary versions can be downloaded for Windows or Macintosh OS X. Wireshark is also available through the standard software distribution systems for most flavors of Unix/Linux, and the source code is also available for installation on other operating systems.
The Wireshark development team built the Windows version on top of the WinPcap packet capture library. Those running Windows must install WinPcap if they haven’t already. One word of caution: If you’re running an outdated version of WinPcap, remove it manually through the “Add/Remove Programs” control panel before running the Wireshark installer.
The installation process uses a familiar wizard-based sequence that only asks two significant questions: whether you want to install WinPcap and whether you want to start the WinPcap Netgroup Packet Filter (NPF) service at startup. Selecting the latter option allows users without administrator privileges to capture packets. If you don’t start this service, only administrators will be able to run Wireshark.

Friday, September 19, 2008

Global Wireless Broadband will be the next mobile generation for IIUM Community

As we can see our mobile service today has equipped with the latest technology embodied. Application like MMS, email , mobile web browser (firefox), video call, Fixed mobile convergence (FMC), mobile extension, could deliver easily via 3G. Everybody could run all of these application as long as they are within 3G coverage. Limited coverage right?…. Well after the GPRS (40kbps) evolve to egde (300kps) , then to 3G (2MBps) , and then HSDPA (36Mbps), the next generation (4G) of mobile network would run at least 300Mbps. Using what ?…They call it as Worldwide Interoperability for Microwave Access (WiMax).
Since the first idea, WiMAX has the potential to replace a number of existing telecommunications infrastructures. In a fixed wireless configuration it can replace the telephone company’s copper wire networks, the cable TV’s coaxial cable infrastructure while offering Internet Service Provider (ISP) services. In its mobile variant, WiMAX has the potential to replace cellular networks. But in Telco, we would call it as mobile WiMax. Mobile WiMAX takes the fixed wireless application a step further and enables cell phone-like applications on a much larger scale. For example, mobile WiMAX enables streaming video to be broadcast from a speeding police or other emergency vehicle at over 70 MPH. It potentially replaces cell phones and mobile data offerings from cell phone operators such as EvDo, EvDv and HSDPA. In addition to being the final leg in a quadruple play, it offers superior building penetration and improved security measures over fixed WiMAX. Mobile WiMAX will be very valuable for emerging services such as mobile TV and gaming.
mimo2.JPG
The technologies used to build this huge trunk highway are Orthogonal Frequency-Division Multiplexing (OFDM) and multiple input & Mulitple output (MIMO). OFDM & MIMO have emerged as the technologies of choice to satisfy this growth, not only for WiMAX (802.16e & 802.16m), but also for 3GPP’s future LTE standard as well as Wi-Fi (802.11n). The combination of OFDM and MIMO is highly scalable and systems based upon it are best positioned to satisfy the headroom requirements for mobile broadband data over the next decade.
uia.jpg
Then, how will it give benefit to IIUM environment ? Well.. the fast growth of MIMO technology will enable IIUM to become fully wireless campus territory. With the existing aruba Network environemt , and additional deployment of out-door antennas, which decrease in quantity , but will increase about more than 50% coverage by using MIMO technology, this dream would become true. The existing coverage, which cover only for kulliyyah and admin building, would be expendable to Mahallah area, and also all other coverage with lesser amount of budget.
The other application like video conference, In-house video streaming, or in-house IIUM TV program , which require great bandwidth, will be easily adopted with the existence of great warrior of IIUM mobile WiMax. As for the mobile application, the mobile VoIP (SIP enabled mobile phone) could be used as to greatly lower down the call billing among the IIUM Community. Integration with call routing will also decrease the charge from local to adjacent call and other nation wide call billing. Is it really a great ROI? In fact, yes for long term benefit. The continuous educational program will last forever as the infrastructure has tremendously being develop in advanced for better future people development.