Skip to content

Enterprise WiFi Hardening

Enterprise wireless networks are prime targets for attackers due to their exposure to both internal and external threats. Securing these networks requires a layered approach combining strong authentication, centralized management, and continuous monitoring. Below are best practices for hardening enterprise Wi-Fi infrastructure, with technical examples to guide implementation.


Authentication Protocols: WPA3-Enterprise as the Baseline

WPA3-Enterprise replaces WPA2 and provides stronger encryption, resistance to brute-force attacks, and improved key management. It mandates the use of EAP (Extensible Authentication Protocol) methods such as PEAP, EAP-TLS, or EAP-FAST.

Example: Configure WPA3-Enterprise on a Linux-based access point using hostapd:

# /etc/hostapd/hostapd.conf
interface=wlan0
driver=nl80211
ssid=Secure_Ess
hw_mode=a
channel=36
wpa=3
wpa_key_mgmt=WPA-EAP
wpa_pairwise=CCMP
rsn_pairwise=CCMP
eap_server=1
eap_user_file=/etc/hostapd/eap_users

Command to verify WPA3 support on a client:

nmcli device wifi show | grep 'Security'
# Expected output: WPA3-Enterprise


Centralized Authentication: RADIUS Integration

Integrate access points with a RADIUS server (e.g., FreeRADIUS, Microsoft NPS) to enforce centralized user authentication and policy enforcement. This reduces reliance on static credentials and enables dynamic access control.

Example: Configure FreeRADIUS to validate user credentials:

# /etc/freeradius/radiusd.conf
clients {
    client 127.0.0.1 {
        secret = testing123
        short_name = localhost
    }
}

Command to test RADIUS authentication:

radtest user password 127.0.0.1 1812 testing123
# Success: Authentication accepted


Network Segmentation and VLANs

Segment guest and internal networks using VLANs to limit lateral movement. Ensure that IoT devices and users are isolated from sensitive systems.

Example: Configure VLANs on a switch:

# Cisco IOS example
interface Vlan10
 ip address 192.168.10.1 255.255.255.0
!
interface FastEthernet0/1
 switchport mode access
 switchport access vlan 10


Monitoring & Auditing: Detect Anomalies Early

Deploy tools like Wireshark, tcpdump, or SIEM systems to monitor traffic for rogue devices, credential leaks, or abnormal behavior.

Example: Use tcpdump to capture and analyze traffic:

sudo tcpdump -i wlan0 -n -s 0 'tcp port 443' -w capture.pcap
# Analyze with Wireshark: wireshark capture.pcap

Command to audit WPA3 handshakes:

aireplay-ng --deauth 0 -a [BSSID] -c [Client_MAC] wlan0
# Monitor for handshake captures using airodump-ng


Physical Security and Firmware Updates

Disable unused ports, use directional antennas to limit signal range, and enforce firmware updates for APs and controllers.

Example: Check for firmware updates on a Cisco AP:

show bootvar
# Verify firmware version and download updates from Cisco TAC


Key takeaways

  • Migrate to WPA3-Enterprise with EAP methods to secure client authentication.
  • Centralize authentication via RADIUS to enforce policies and audit user access.
  • Segment networks using VLANs to isolate sensitive systems and reduce attack surfaces.
  • Monitor traffic continuously with tools like tcpdump or SIEMs to detect anomalies.
  • Maintain physical and software security by updating firmware and restricting hardware access.