I´m new with this stuff, so I would like to know what can I do to get the connections between the two buildings as secure as possible. I´ve found something about RADIUS server but in conjuction with access points and not with bridges. What is possible with the bridges only and what with further hardware/software ? Thank you for your support !
Re: AIR350 Bridge security connecting two buildings
Without a radius server you can define static WEP keys on each of the bridges and use Ciscos WEP enhancements to mitigate the attacks on WEP. Ciscos WEP enhancements are;
Message Integrity Check (MIC)
MIC prevents attacks on encrypted packets called bit-flip attacks. During a bit-flip attack, an intruder intercepts an encrypted message, alters it slightly, and retransmits it, and the receiver accepts the retransmitted message as legitimate. The MIC, implemented on both the bridge and all associated client devices, adds a few bytes to each packet to make the packets tamper-proof.
Temporal Key Integrity Protocol (TKIP)
Temporal Key Integrity Protocol (TKIP), also known as WEP key hashing, defends against an attack on WEP in which the intruder uses an unencrypted segment called the initialization vector (IV) in encrypted packets to calculate the WEP key. TKIP removes the predictability that an intruder relies on to determine the WEP key by exploiting IVs. TKIP protects both unicast and broadcast WEP keys.
If you do have a RADIUS server (that understands EAP-Cisco, AKA LEAP), you can have all the above features in addition to dynamic unicast/broadcast WEP keys, and periodic key timeout and renewal.
Further information on Cisco Bridge security features is available here;
Transferring Crash file from standby:
Login to the Active WLC in HA.
(Cisco Controller) >transfer upload datatype crash
(Cisco Controller) >transfer upload filename <Desired filename>
(Cisco Controller) >transfer up...
This is the start of a display filter cross reference between Wireshark and OmniPeek.
The 1st installment is a table of advanced filters. More filters will be added as time allows.
It is a living doc, so check back for changes every so often
Please feel ...
I have created a Powershell script to automatically add a Wireless Guest User on Cisco WLCs. (tested on 2500 Series)
The script should be completely self explanatory.
Powershell SNMP Module (Install-Module -Name SNMP)
SNMP Write Access to...