AirTight Networks  SpectraGuard

Review : Wireless threats meet their match

AirTight’s updated SpectraGuard Enterprise offers superior location-based protection

Written by Dave Bailey

Larger Image

AirTight Networks’ SpectraGuard Enterprise (SGE) version 5.5 wireless intrusion prevention system is excellent for testing and maintaining the security of wireless networks.

Among the new features in this latest version is a location-based policy management system, which is designed to make it easier to manage geographically dispersed SGE deployments. This is also intended to help managed security service providers to provide wireless security for different organisations. Another key addition is integrated support for Cisco’s Wireless LAN Controller systems.

The hardware for SGE consists of AirTight’s SpectraGuard wireless sensors and the SGE appliance. We set up a system using an SGE SA-200 appliance and three sensors covering our labs area. Connecting to the appliance for the first time fires up a 12-step initial configuration wizard. This allows users to set up SMTP servers for email alerts, and lets them choose which servers to send syslog messages and Simple Network Management Protocol trap alerts to.

We then set up automated policies to deal with unauthorised access points (APs) trying to connect to the network, unauthorised clients trying to authenticate with authorised APs and authorised clients trying to connect with unauthorised APs.

Initially, we turned the event-generation and intrusion-prevention systems off, so we could monitor what wireless infrastructure was out there. SGE’s web GUI makes it easy for users to see and categorise wireless devices over the air. The system immediately detected our test network’s 3Com AP7250 AP and displayed details of its various settings.

After several days monitoring the environment around our wired network, we logged 36 APs and 213 wireless clients, with over half the APs being Cisco ones. Most of the APs were 802.11b/g devices. Of the remainder, three were 802.11a units, one was a pre-draft 802.11n AP and one was a 802.11b-only type. Sixteen APs were using WEP for security, while four had WPA and four had WPA2 security enabled, with the rest having no security enabled whatsoever.

We then checked to see what kind of events were being generated. We weeded out trivial events and focused on critical ones, like an authorised client trying to connect to an “evil twin” AP.

With AirTight’s intrusion prevention system enabled, SGE 5.5 allowed us to respond to critical security events by either blocking or degrading unwanted communications between authorised and unauthorised devices.

Product overview

Best prices

Ratings

  • Overall rating: 5
  • Features: n/a
  • Performance rating: n/a
  • Value for money: n/a
  • Average user rating:
Rate this product

Verdict

AirTight's SpectraGuard Enterprise 5.5 is a top-notch system for securing firms' wireless infrastructure, but setting up the policies can be time consuming.

Pros: Very good user interface; comprehensive policy configuration.

Cons: Setup requires a fair amount of wireless security expertise

Tags:

See also:

image: Buffalo DD-WRT GUI Router

Review: Buffalo DD-WRT GUI Router

Build your own hotspots with this affordable Wifi router   More...

Review: Mini BlackBerry adds Wi-Fi support

RIM’s BlackBerry 8120 is more compact than other models, but compromises on its keypad   More...

Advertisements

Do you agree?

Advertisement

IT white papers

Search vnunet IThound

Top categories

Advertisement

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Spotlight

Computer mouse

Computer mouse heading for extinction

Humble input device being usurped by touch screens and facial...  More...

Sony Vaio SR

Sony unveils Vaio business notebooks

Three new laptops aimed at 'out and about professionals'   More...

Advertisement

Firefox

Firefox gets security tune-up

Flaws patched for versions 2 and 3   More...

Apple iPhone 3G

Hold off on iPhone 3G, says analyst

Corporates should consider new handset a 'beta release'   More...

Advertisement