How It Works; Security Issues - Colubris Networks CN3000 Administrator's Manual

Table of Contents

Advertisement

Chapter 6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Customizing the public access interface - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Chapter 6

How it works

Although the remote login page feature enables you to host the public access login page
on a remote web server, authentication of customers is still performed by the CN3000
via a RADIUS server. To accomplish this, the remote web server must send customer
login information back to the CN3000. There are two ways to accomplish this: basic
remote login or using the NOC-based authentication feature.
The following diagram shows the sequence of events for a typical customer session
when using remote login.
Customer
Non-authenticated
customer attempts to
browse an external
Web site via the WLAN.
Customer clicks to
continue.
Customer logs in.
Customer login info
is sent.
Customer's web browser
is redirected to the
Welcome page.

Security issues

• It is recommended that the web server hosting the remote login page be secured with
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 123 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
CN3000
Request is intercepted.
Service Announcement
page is returned.
Web browser is redirected.
Login info is sent to
the RADIUS server.
HTML redirect is sent to
the customer's browser
pointing it to the
Welcome page
SSL (requires an SSL certificate from a well-know CA), to ensure that customer logins
are secure. Without SSL security, logins are exposed and may be compromised,
enabling fraudulent use of the network.
RADIUS server
Login approved.
Customer configuration
settings are returned.
Web server hosting
remote login page
Login page is sent.
HTML redirect is sent to
the customer's browser
pointing it to the CN3000.
(This page could be
hosted on a different
web server.)
Web server sends
the Welcome page
with URL of originally
requested web site.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents