Difference between revisions of "Virginia Tech Wifi (OLD)"

From the Linux and Unix Users Group at Virginia Teck Wiki
Jump to: navigation, search
imported>Mutantmonkey
imported>Telnoratti
Line 1: Line 1:
Since the fall of 2008, there have been two wireless networks on campus. One network, called '''VT-Wireless''', encrypts all traffic and is secured with EAP-TLS or PEAP-MSCHAPv2. The other network, [[VT_WLAN]], is an unencrypted, captive portal wireless network. While connections to VT-Wireless are secure by default, and require no user authentication once set up, the EAP-TLS setup has a number of steps. In contrast, setup for VT_WLAN network is negligible, but you will be required to manually authenticate each time you connect (although this can be scripted), and your traffic will be readable to everyone.
+
Since the fall of 2008, there have been two wireless networks on campus. One network, called '''VT-Wireless''', encrypts all traffic and is secured with EAP-TLS or PEAP-MSCHAPv2. The other network, called [[VT_WLAN]]. In July, 2013 VT_WLAN was superseded by CONNECTtoVT-Wireless, is an unencrypted, captive portal wireless network designed to set up connecting to VT-Wireless. Internet access is not available on it. Connections to VT-Wireless are secure by default, and has one of two different methods to connect.
  
 
== Select a connection method ==
 
== Select a connection method ==
Line 23: Line 23:
 
| Most devices
 
| Most devices
 
|-
 
|-
| [[VT_WLAN]]
+
| CONNECTtoVT-Wireless
| Weak ([[w:Captive portal|Captive portal]])
+
| None to Medium ([[PEAP-MSCHAPv2]])
| No
+
| Yes
| Negligible
+
| Simplest
| All devices
+
| Most devices
 
|}
 
|}
  
 
The best option is [[EAP-TLS]], which provides strong, two-way authentication to ensure that neither you or the authentication server can be impersonated. Unfortunately, setting up EAP-TLS can be somewhat involved because it requires a certificate to be installed on the device.
 
The best option is [[EAP-TLS]], which provides strong, two-way authentication to ensure that neither you or the authentication server can be impersonated. Unfortunately, setting up EAP-TLS can be somewhat involved because it requires a certificate to be installed on the device.
  
[[VT_WLAN]] is an unsecured captive portal wireless network. It requires no set up at all, but you must log in with your PID and password every time you connect. Since it is not secure, it is simple for any and all unencrypted traffic on the network to be sniffed by anyone within range and is also vulnerable to deauthentication attacks. Its use is discouraged in most cases.
+
Using [[PEAP-MSCHAPv2]] is less secure as the authentication method can be broken with sufficient resources in a short ammount of time. However the authentication is encrypted and the encryption key is authenticated and it is significantly simpler to set up and use.
 +
 
 +
CONNECTtoVT-Wireless is an unsecured captive portal wireless network. It is used for setting up VT-Wireless on your device. The network is locked down to only allow access to pages that help connect the user to VT-Wireless. It uses [[XpressConnect]].
  
 
{| class='wikitable' width='40%'
 
{| class='wikitable' width='40%'

Revision as of 16:18, 29 July 2013

Since the fall of 2008, there have been two wireless networks on campus. One network, called VT-Wireless, encrypts all traffic and is secured with EAP-TLS or PEAP-MSCHAPv2. The other network, called VT_WLAN. In July, 2013 VT_WLAN was superseded by CONNECTtoVT-Wireless, is an unencrypted, captive portal wireless network designed to set up connecting to VT-Wireless. Internet access is not available on it. Connections to VT-Wireless are secure by default, and has one of two different methods to connect.

Select a connection method

Network Authentication Encrypted Setup Support
VT-Wireless Strong (EAP-TLS) Yes Involved Many devices (Laptops and Android devices)
VT-Wireless None to Medium (PEAP-MSCHAPv2) Yes Simple Most devices
CONNECTtoVT-Wireless None to Medium (PEAP-MSCHAPv2) Yes Simplest Most devices

The best option is EAP-TLS, which provides strong, two-way authentication to ensure that neither you or the authentication server can be impersonated. Unfortunately, setting up EAP-TLS can be somewhat involved because it requires a certificate to be installed on the device.

Using PEAP-MSCHAPv2 is less secure as the authentication method can be broken with sufficient resources in a short ammount of time. However the authentication is encrypted and the encryption key is authenticated and it is significantly simpler to set up and use.

CONNECTtoVT-Wireless is an unsecured captive portal wireless network. It is used for setting up VT-Wireless on your device. The network is locked down to only allow access to pages that help connect the user to VT-Wireless. It uses XpressConnect.

Select a method for setup instructions
EAP-TLS PEAP-MSCHAPv2

Network Information Sources