Wireless signals are inherently exposed to interception, making strong encryption and proper authentication protocols essential for any secure network deployment. This content covers wireless security fundamentals, from outdated and broken protocols like WEP to modern WPA3 configurations and enterprise-grade 802.1x authentication.
Wireless Security
When we're communicating wirelessly, the traffic is just flowing through the air, and anything, anybody, any device that has wireless can pick that up, read those signals and interpret them. So those signals must be secured. They must be encrypted.
Wireless signals get broadcasted out, and we don't have a whole lot of control about how it gets broadcasted out. There are certain antennas which will focus that. There are power settings which will allow us to adjust the radius. But even with those settings, we probably want to get good coverage, so we're probably going to extend beyond the walls of our building. Even if it is within our building, we still want to make sure that it is secure. So we need to implement good security with our wireless.
There are certain protocols that we can use to secure the traffic, and some of them are better than others.
First of all, we could just have it open, where all the traffic is open and you don't need any credentials or anything to connect to it. This is obviously problematic, because anybody can read the traffic going across it.
We have wired equivalent privacy. WEP was designed to be something that would be the equivalent to a wired network — that is, it's so secure that no one else can see the traffic going across it. And it was a big lie, in that it was broken right away. You don't want to use WEP at all. It was crazy how long people were using WEP even knowing that it is a broken protocol and we shouldn't be using it.
Then we had several variations of this wireless protection access, or WPA. We have WPA1, 2 and 3. Obviously it gets better with each iteration, so we want to use as high as we can. There is also a compatibility issue that we've got to be concerned about, so we have to choose the right one that works best for our scenario. But the higher the WPA that we can go, the better it's going to be.
With those different versions like WPA3, we have some options on how we connect.
We can have a pre-shared key. That is, we can create a key ahead of time and we can share it with other people. The problem with this, though, is that once that gets out, anybody can use that key in order to be able to access the wireless. And wireless passwords like that get shared all the time, and it really just opens up your network for some problems.
There is a portal, in which what would happen is once you connect it opens up a browser window and you can log in. That would be another option to secure your network for authentication.
But there is also 802.1X. 802.1X allows the computer to communicate through the wireless access point into the server and make a connection for authentication, and it can do that using certificates or usernames and passwords, or there's various methods. So that is one way that we can make this a really secure network, using something like 802.1X.
There are other things that we should do when we roll out wireless. They come with probably some sort of SSID already preset up, and then the default credentials on that device. We do want to harden this device and secure it. So we change that SSID, we change the default credentials, we change it to better match our system, and implement a level of security within our wireless network.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →