Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

How secure is captive portal authentication?

This thread has been viewed 4 times
  • 1.  How secure is captive portal authentication?

    Posted Mar 17, 2019 08:26 AM

    Airheads,

     

    I have some secuirty quries for Captive portal based guest solutions

     

    Over wireless, After captive portal authentication (without mac-auth),

    1. Will there be any 4-way handshake between client and AP after authentication?

    2.If 4-way handshake, will cppm provide MSK(master session key) to authenticator?

    3.If there is no 4-way handshake, will the traffic be open and visible if do packet capture?

    4.Adding Mac-authentication to this improves any security(interms of encryption)?

     

     

    Thanks a lot!!

     



  • 2.  RE: How secure is captive portal authentication?

    Posted Mar 17, 2019 08:56 AM

    It really depends on how the SSID has been configured.

     

    If it is an Open SSID with captive portal authentication (usual worksflow for guest networks), yes, traffic over Wi-Fi will not be encrypted and can be sniffed.

     

    Mac auth is still an authentication mechanism. An SSID with no encryption and MAC auth can still be sniffed.

     

    Unless you select an Encryption method for the SSID, data can be sniffed.



  • 3.  RE: How secure is captive portal authentication?

    Posted Mar 17, 2019 09:10 AM

    Thanks Jaybee,

     

    For enterprise guest network, is there any method to encrypt data except onboard, onguard and preshared key?

     

     



  • 4.  RE: How secure is captive portal authentication?

    EMPLOYEE
    Posted Mar 17, 2019 10:23 AM
    Enhanced Open, but there are very few clients.


  • 5.  RE: How secure is captive portal authentication?

    Posted Feb 28, 2020 08:33 AM

    Hi,

     

    Some time late to this post. Here we are talking about traffic after captive portal authentication, and I am clear it will be unencrypted. What about the interchange of username and password at the moment of captive portal authentication? Will they be encrypted or unencrypted if we are using HTTPS captive portal?

     

    Regards,

    Julián



  • 6.  RE: How secure is captive portal authentication?

    EMPLOYEE
    Posted Feb 28, 2020 10:16 AM

    It is encrypted when you use HTTPs, but I would not use anything besides 802.1x encryption when it comes to employee usernames and passwords.  802.1x also requires properly configured clients, otherwise it is vulnerable to man in the middle attacks.