Controllerless Networks

last person joined: 2 days ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

SSID Failed PCI Compliance

This thread has been viewed 0 times
  • 1.  SSID Failed PCI Compliance

    Posted Jun 27, 2014 05:13 PM

    2.1.1 Change vendor-supplied defaults for wireless environments. A device fails if the passphrases, SSIDs or other security-related settings are on a list of forbidden values. This list includes common manufacturer defaults.

     

    Could it be the name or if the SSID contains "GUEST"?



  • 2.  RE: SSID Failed PCI Compliance

    EMPLOYEE
    Posted Jun 27, 2014 05:22 PM
    Are you using a pre-shared key?

    Sent from Surface Pro


  • 3.  RE: SSID Failed PCI Compliance

    Posted Jun 27, 2014 05:50 PM

    Did you change the admin password on the IAP?



  • 4.  RE: SSID Failed PCI Compliance

    Posted Jun 27, 2014 07:04 PM

    Yes what is the CDE Subnets/SSIDs on the report? Maybe if I exclude Guest..

     

    EDIT: Nope still failed

     Report.PNG



  • 5.  RE: SSID Failed PCI Compliance

    Posted Jun 27, 2014 07:29 PM

    There isn't a list in the PCI-DSS of pre or pro-scribed settings, just this:

    2.1.1
    For wireless environments connected to the cardholder data
    environment or transmitting cardholder data, change wireless
    vendor defaults, including but not limited to default wireless encryption
    keys, passwords, and SNMP community strings.

     I don't know what Aruba's tool checks for, so I can't really tell you what else to look at.

    So better go back and check that you're on WPA2 and using a good key.

    Also move to SNMP3 with good keys if you haven't already.



  • 6.  RE: SSID Failed PCI Compliance

    Posted Jun 27, 2014 05:22 PM

    Can you provide more detail?

     

    -What tool generated this audit?

    -Does that tool offer a list of "forbidden values"?

    -What version of InstantOS?



  • 7.  RE: SSID Failed PCI Compliance

    Posted Jun 27, 2014 05:24 PM

    PCI Compliance Report from Aruba Central

     

    Yes, using a pre-shared key on guest wireless/VLAN

     



  • 8.  RE: SSID Failed PCI Compliance

    EMPLOYEE
    Posted Jun 27, 2014 05:27 PM
    Is the PSK a well known word?


  • 9.  RE: SSID Failed PCI Compliance

    Posted Jun 27, 2014 05:33 PM

    probably but includes numbers/uppercase - should I change and run scan again?