This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
|
technical:ppsk-overview [2022/10/20 20:33] admin [Large deployments] |
technical:ppsk-overview [2022/10/21 13:37] (current) admin |
||
|---|---|---|---|
| Line 11: | Line 11: | ||
| * The option for each device to be assigned to a predefined VLAN after authentication. | * The option for each device to be assigned to a predefined VLAN after authentication. | ||
| - | ===== Usage ===== | + | ===== Advantages |
| Your next question might be //"OK, so why would I want to use this feature?"// | Your next question might be //"OK, so why would I want to use this feature?"// | ||
| + | |||
| + | * The Private PSK allows you to use secure, device-bound credentials. | ||
| + | * This allows clients to securely authenticate and join the network using a **specific device and PSK combination**. | ||
| + | * This enhances security and deployment flexibility for headless IoT devices. | ||
| + | * Optional dynamic VLAN assignment further enhances the security and manageability. | ||
| + | * RADIUSdesk is used to centrally manage device and PSK matching. | ||
| + | * A PSK on the device owner' | ||
| + | * A more granular option will be a PSK on the device owner. | ||
| + | * Finally there is an option for a PSK on the device itself. | ||
| + | * Other features included with RADIUSdesk are available also to use: | ||
| + | * Future date activation. | ||
| + | * Expiry date. | ||
| + | * Time slots when the network can be used by the device. | ||
| + | * One SSID can support all these features. | ||
| + | * Using one SSID improves bandwidth utilization and provides a simplified user experience. | ||
| + | * The easy to use on-boarding Captive Portal minimize support calls. | ||
| + | |||
| + | |||
| + | ===== Implementation ===== | ||
| + | |||
| * We will split this into two categories. One for small deployments and another for large deployments. | * We will split this into two categories. One for small deployments and another for large deployments. | ||
| ==== Small deployments ==== | ==== Small deployments ==== | ||
| + | {{: | ||
| * In a small deployment you need a minimum of one Access Point. | * In a small deployment you need a minimum of one Access Point. | ||
| + | * Private PSK is also supported in the mesh networks managed by MESHdesk. | ||
| * You don't need any VLAN aware equipment, the VLAN assignment will be internal. | * You don't need any VLAN aware equipment, the VLAN assignment will be internal. | ||
| * You will typically have: | * You will typically have: | ||
| Line 26: | Line 48: | ||
| * Includes small offices or home deployments | * Includes small offices or home deployments | ||
| - | ==== Large deployments ==== | + | ==== Large deployments |
| - | * With large deployments you can potentially have hundreds | + | {{: |
| + | * With large deployments you can potentially have thousands | ||
| * These deployments will include working together with other components to provide an integrated solution. | * These deployments will include working together with other components to provide an integrated solution. | ||
| * You will typically have | * You will typically have | ||
| Line 35: | Line 58: | ||
| * A firewall that hosts multiple networks, each of which is linked to a different VLAN. | * A firewall that hosts multiple networks, each of which is linked to a different VLAN. | ||
| * Includes Multiple Dwelling Units (MDU), Schools, hotels and conference facilities and WiFi networks with IOT devices. | * Includes Multiple Dwelling Units (MDU), Schools, hotels and conference facilities and WiFi networks with IOT devices. | ||
| + | |||
| + | <WRAP center round info 100%> | ||
| + | * You might have noticed that the Access Points in the picture are the Aruba AP105. | ||
| + | * RADIUSdesk provides a solution for networking and does not sell hardware. | ||
| + | * The Aruba AP105 along with many other older and current hardware are supported by OpenWrt and can thus be used in your deployment. | ||
| + | * No vendor lock-in :-) | ||
| + | </ | ||
| + | |||
| + | |||
| + | ===== Why not 802.1x? ===== | ||
| + | * WPA2 Enterprise are definitely more secure but there are two issues which usually turn people off from implementing it. | ||
| + | * Certificate management. The Certificate Authority (CA)'s certificate needs to be installed on the client connecting. | ||
| + | * Not all WiFi devices support it. | ||
| + | * Many IOT devices do not support WPA2-Enterprise | ||
| + | * Many printers and WiFi cameras do not support WPA2-Enterprise. | ||
| + | * RADIUSdesk along with MESHdesk and APdesk however also offer WPA2 Enterprise support should you wish to rather implement it instead of Private PSK. | ||
| + | |||