# Wireless Network Security: Wi-Fi Security, WPA3, Rogue AP and Evil Twin Risks

**URL:** https://securesys.com.tr/en/learning/network-security/wireless-network-security-wpa3-rogue-ap

![Wireless Network Security: Wi-Fi Security, WPA3, Rogue AP and Evil Twin Risks](/images/bilgi-merkezi/covers/cover-network-07.webp)

Wireless networks provide great convenience in terms of user experience.

However, at the same time they remove the physical boundaries of the corporate network.

While reaching the wired network mostly requires reaching a physical network port inside the office, the Wi-Fi signal can carry beyond the building.

For this reason the attacker does not need to connect a cable physically to the corporate wireless network.

Being within a sufficient signal coverage area can be enough for some attack scenarios.

This situation makes wireless security one of the critical components of corporate network security.

In corporate Wi-Fi security the fundamental question should not be only:

**"Is our Wi-Fi password strong?"**

it should not be this.

The real questions are these:

#### Who is connecting?

#### Which device is connecting?

#### Which authentication method is being used?

#### Which network segment is the device placed in?

#### Are fake access points being detected?

#### Is wireless traffic being monitored?

Particularly in structures where a shared PSK is used, a single Wi-Fi password being known by dozens or even hundreds of users can create a serious management problem.

When an employee leaves the organization they can continue to know the password.

The password can be passed on to other people.

It can become difficult to determine which user made which connection.

For this reason modern corporate Wi-Fi security:

#### Shared Password

from this approach

#### Identity-Based Wireless Access

is developing towards this model.

### What Is Wi-Fi Security?

Wi-Fi Security is the protection of wireless network access with authentication, encryption, segmentation and monitoring controls.

The aim;

unauthorized access,

traffic interception,

identity theft,

rogue access point usage

and wireless attacks

is to reduce these.

### Why Is a Wireless Network a Different Risk Area?

On a wired network a physical connection is needed.

In a Wi-Fi environment, however, communication takes place over radio frequency.

For this reason the physical boundaries are less definite.

### What Is the Wireless Attack Surface?

It is all the components of the Wi-Fi infrastructure that can be targeted by an attacker.

For example:

Access Point

Wireless Controller

SSID

Authentication Infrastructure

RADIUS Server

Client Device

### What Is an SSID?

SSID:

#### Service Set Identifier

is the visible name of the Wi-Fi network.

### Does Hiding the SSID Provide Security?

No.

A hidden SSID is not a strong security control.

### What Is a Hidden SSID?

It is the Wi-Fi network name not being broadcast directly in the beacon frames.

### Can a Hidden SSID Still Be Detected?

Yes.

It can be detected with wireless traffic analysis.

### What Is Wi-Fi Authentication?

It is the user or device being verified before reaching the wireless network.

### What Is Wi-Fi Encryption?

It is the encryption of wireless traffic over the radio.

### Are Authentication and Encryption the Same Thing?

No.

Authentication:

#### Who is connecting?

Encryption:

#### How is the traffic protected?

they answer these questions.

### What Is WEP?

WEP:

#### Wired Equivalent Privacy

is an old wireless security standard.

### Is WEP Secure?

No.

It must not be used on modern corporate networks.

### What Is WPA?

WPA:

#### Wi-Fi Protected Access

is the wireless security standard developed to reduce the security weaknesses of WEP.

### What Is WPA2?

WPA2 is the Wi-Fi security standard that has been widely used for many years.

### Is WPA2 Still Used?

Yes.

However, the correct configuration and authentication model is important.

### What Is WPA2-Personal?

It is the Wi-Fi model in which a Pre-Shared Key is used.

### What Is PSK?

PSK:

#### Pre-Shared Key

is the authentication model in which all users or devices connect to the network through a shared password.

### Why Is a Shared PSK Risky?

Because the password:

can be shared,

can be forgotten,

can remain with former employees,

can reduce accountability.

### What Is WPA2-Enterprise?

WPA2-Enterprise is the Wi-Fi model that provides user or device based authentication using 802.1X and RADIUS.

### Why Is Enterprise Wi-Fi Stronger?

Every user or device can perform separate identity verification.

### What Is WPA3?

WPA3 is the modern wireless security standard designed with the aim of improving Wi-Fi security.

### What Is WPA3-Personal?

It is the WPA3 model that uses SAE authentication on personal Wi-Fi networks.

### What Is SAE?

SAE:

#### Simultaneous Authentication of Equals

is the WPA3-Personal authentication mechanism.

### Why Is SAE Important?

It can provide stronger protection than WPA2-PSK against offline password guessing attacks.

### What Is WPA3-Enterprise?

It is the WPA3 model that provides strong authentication and encryption features in enterprise Wi-Fi environments.

### Where Is WPA3-Enterprise Used?

Corporate:

Laptop

Mobile Device

Managed Endpoint

it can be used on devices such as these.

### What Is the Fundamental Difference Between WPA2 and WPA3?

WPA3 aims to offer stronger modern authentication and encryption features.

### Is Using WPA3 Enough on Its Own?

No.

Identity, segmentation and monitoring are needed as well.

### What Is Transition Mode?

It is the transition mode that allows WPA2 and WPA3 clients to be supported at the same time.

### Can Transition Mode Be Risky?

Because of legacy compatibility the security level can fall.

### What Is PMF?

PMF:

#### Protected Management Frames

is the mechanism that provides protection for certain Wi-Fi management frames.

### What Is a Management Frame?

They are the frames used for the management of the wireless connection.

### Why Is PMF Important?

It can help to reduce spoofed management frame attacks.

### What Is a Deauthentication Attack?

It is the attacker trying to disconnect clients from the access point by sending fake deauthentication frames.

### Why Is a Deauth Attack Performed?

To force users to establish a connection again,

to create a service disruption

or to make certain wireless attack scenarios easier

it can be used for these.

### Does PMF Reduce Deauthentication Attacks?

Yes.

Protected Management Frames help to reduce these risks.

### How Is 802.1X Used on Wi-Fi?

The client connects to the access point.

The Access Point / Controller:

Authenticator

works as this.

Authentication:

RADIUS

is carried out through this.

### The Enterprise Wi-Fi Flow

Client

↓

Access Point

↓

Wireless Controller

↓

RADIUS

↓

Identity Store

↓

Access Decision

### What Does RADIUS Do on Wi-Fi?

Authentication

Authorization

Accounting

it provides these functions.

### Why Is EAP Used on Wi-Fi?

It is the 802.1X authentication framework.

### Is EAP-TLS Strong for Wireless Security?

Yes.

It can provide certificate-based mutual authentication.

### How Does EAP-TLS Work?

A client certificate

and

a server certificate

mutual authentication can be performed using these.

### What Is the Advantage of EAP-TLS?

It can reduce the password theft risk.

### What Is Certificate-Based Wi-Fi?

It is the Wi-Fi structure in which the client authenticates with a certificate instead of or in addition to a password.

### Can a Machine Certificate Be Used?

Yes.

It is a strong method for managed corporate devices.

### Can a User Certificate Be Used?

Yes.

It can be applied according to the architecture.

### Why Is PKI Important for Wi-Fi Security?

It provides certificate lifecycle management.

### Should the Server Certificate Be Validated?

Definitely.

### Why Is Server Certificate Validation Critical?

It helps to prevent the client from sending credentials to a fake authentication server.

### What Is Evil Twin?

Evil Twin is the fake wireless access point attack that imitates a legitimate Wi-Fi network.

### How Does Evil Twin Work?

The attacker can broadcast an SSID that resembles the organization's Wi-Fi.

For example the real SSID:

Corporate-WiFi

The fake SSID:

Corporate-WiFi

The client can connect to the wrong access point.

### Why Is Evil Twin Dangerous?

The attacker:

credential capture,

traffic interception,

phishing,

session manipulation

can try attacks such as these.

### Are Evil Twin and Rogue AP the Same?

No.

### What Is a Rogue Access Point?

It is an access point connected to the corporate network without permission or running without permission.

### What Is Evil Twin?

It is the attacker-controlled access point that imitates the legitimate Wi-Fi.

### What Is an Unauthorized AP?

It is a wireless access point not approved by the security team.

### How Does a Rogue AP Occur?

An employee can connect their own access point to a network port.

### Why Is a Rogue AP Risky?

It can create an uncontrolled wireless entry point to the corporate network.

### What Is Wireless IDS?

WIDS:

#### Wireless Intrusion Detection System

is the security system that helps to detect suspicious behaviour in the wireless environment.

### What Is WIPS?

WIPS:

#### Wireless Intrusion Prevention System

is the system that can provide prevention capabilities as well as detecting wireless threats.

### What Can WIDS/WIPS Detect?

Rogue AP

Evil Twin

Unauthorized SSID

Deauthentication Attack

Suspicious Wireless Device

### What Is Wireless Monitoring?

It is the continuous monitoring of the radio environment and Wi-Fi activity.

### What Is RF Monitoring?

It is the monitoring of the wireless activity in the radio frequency environment.

### What Is a Wireless Sensor?

It is the sensor that monitors Wi-Fi traffic and RF activity.

### Can an Access Point Be Used as a WIDS Sensor?

On some enterprise wireless platforms, yes.

### What Is a Dedicated Wireless Sensor?

It is the device used only for wireless security monitoring.

### What Is Wireless Threat Detection?

It is the identification of malicious or unauthorized behaviour in the Wi-Fi environment.

### How Is Rogue AP Detection Performed?

Wireless scanning,

network correlation,

MAC address analysis

methods such as these can be used.

### What Is a BSSID?

A BSSID is the MAC-like identity that identifies a particular access point radio interface.

### What Is an ESSID?

It is the SSID concept used in the structure in which more than one access point serves the same Wi-Fi network name.

### How Is Evil Twin Detection Performed?

The SSID is the same but:

the BSSID,

the certificate,

the signal behaviour,

the infrastructure relationship

can be different.

### What Is Wireless Fingerprinting?

It is the analysis of the behavioural characteristics of an access point or a client.

### What Is a Wi-Fi Client?

It is the device that connects to the wireless network.

### What Is Wireless Client Isolation?

It is the blocking of clients on the same Wi-Fi network from reaching one another directly.

### Why Is Client Isolation Important?

Particularly in a guest Wi-Fi environment it reduces the lateral movement risk.

### What Is Guest Wi-Fi?

It is the separate wireless network used to provide internet access to guest users.

### Should Guest Wi-Fi Be Separated From the Corporate Network?

Yes.

### How Should Guest Wi-Fi Be Segmented?

Guest SSID

↓

Guest VLAN

↓

Firewall

↓

Internet Only

Corporate Network

↓

DENY

### Should Guest Wi-Fi and Employee Wi-Fi Be on the Same VLAN?

No.

### Should Client Isolation Be Used on Guest Wi-Fi?

On a risk basis it is a strong control.

### What Is a Captive Portal?

It is the web portal on which the guest user logs in or registers before internet access.

### Does a Captive Portal Provide Security?

It provides identity and guest management.

However, it does not take the place of encryption and segmentation.

### What Is Sponsor Approval?

It is guest access being approved by an employee of the organization.

### What Is Guest Account Expiration?

It is guest access closing automatically at the end of a certain period.

### What Is BYOD Wi-Fi?

It is personal devices reaching corporate resources over the wireless network.

### Should BYOD Be Admitted to the Corporate Wi-Fi?

A special policy must be applied on a risk basis.

### How Can BYOD Segmentation Be?

BYOD SSID

↓

BYOD VLAN

↓

Restricted Access

### Should BYOD Device Posture Be Checked?

If possible, yes.

### How Is NAC Used in Wi-Fi Security?

NAC;

identity,

device type,

posture,

role

can provide dynamic access according to this information.

### How Does Dynamic VLAN Assignment Work on Wi-Fi?

Over the same SSID different users can be assigned to different VLANs.

### An Example

Employee

→

Corporate VLAN

Contractor

→

Contractor VLAN

Guest

→

Guest VLAN

IoT

→

IoT VLAN

### Can a Single SSID Use Multiple VLANs?

Yes.

It can be possible with identity-based policy.

### Should the Number of SSIDs Be Very High?

An unnecessary number of SSIDs can create RF overhead and operational complexity.

### What Is a Corporate SSID?

It is the wireless network used for corporate users.

### What Is an IoT SSID?

It can be the SSID that provides separate wireless access for IoT devices.

### Why Is IoT Wi-Fi Security Difficult?

IoT devices:

May not support 802.1X.

May not support the modern WPA standard.

May not support certificate authentication.

### What Is a Legacy Wireless Device?

It is a device that uses old Wi-Fi security standards.

### What Should Be Done With a Legacy Wi-Fi Device?

It can be kept in a separate segment or its replacement can be planned.

### Can WPA2-PSK Be Used for IoT?

In some scenarios it may be necessary.

However, the risk must be reduced with network segmentation.

### What Is Private PSK?

It is the approach of assigning a different PSK for each user or device.

### What Is PPSK?

Private Pre-Shared Key is the use of a device or user based PSK instead of a shared password.

### What Is DPSK?

It is the Dynamic Pre-Shared Key approach.

### What Is the Advantage of PPSK?

It can reduce the sharing of a single common Wi-Fi password.

### What Is PSK Rotation?

It is the Wi-Fi password being changed at certain periods.

### Why Is Changing a Shared PSK Difficult?

All the devices may need to be reconfigured.

### How Does Enterprise Wi-Fi Reduce This Problem?

User/device based authentication is used.

### What Is Wireless Network Segmentation?

It is the directing of different SSIDs and user types to separate VLANs/security zones.

### What Is Wi-Fi VLAN Mapping?

It is the mapping between the SSID or user role and the VLAN.

### What Is a Wireless Firewall Policy?

They are the network security rules applied to Wi-Fi user traffic.

### Should a Wi-Fi User Receive Full Access to the Internal Network?

No.

### What Is Wireless Least Privilege?

It is the Wi-Fi user being given only the necessary resource access.

### Can Employee Wi-Fi Reach the Server Network?

It must be limited according to the business requirement.

### Should Access From Wi-Fi to the Management Network Be Given?

It must be limited as far as possible.

### Should Administrators Use Wi-Fi?

For critical administration a dedicated secure management path can be preferred.

### What Is a Management SSID?

It can be the special wireless network reserved for network management.

### Is a Management SSID Secure?

When strong authentication and segmentation are not used it can be risky.

### What Is a Wi-Fi Controller?

It is the system that manages enterprise access points centrally.

### What Is a Wireless LAN Controller - WLC?

It is the controller that manages access point configuration, roaming and wireless policies centrally.

### Why Is WLC Security Important?

If it is compromised a broad wireless infrastructure can be affected.

### How Should the WLC Management Interface Be Protected?

Management VLAN

MFA

ACL

Secure Protocol

it must be protected with these.

### Should the WLC Be Open to the Internet?

As far as possible, no.

### How Should the Access Point Management Interface Be Protected?

It must be reachable only from the authorized management network.

### Should the Default AP Password Be Used?

No.

### Should the Access Point Firmware Be Up to Date?

Yes.

### What Is Wireless Firmware Management?

It is the management of the AP and controller software update lifecycle.

### Is an End-of-Life Access Point Risky?

Yes.

It may no longer receive new security updates.

### What Is Wireless Hardening?

It is the strengthening of the Wi-Fi infrastructure with secure configuration.

### What Does Wireless Hardening Contain?

Legacy Protocol Disable

Strong Authentication

Secure Management

Segmentation

Logging

Monitoring

### What Is a Weak Cipher?

It is an old encryption algorithm that no longer provides sufficient security.

### Should TKIP Be Used?

It must be avoided in modern environments.

### What Is AES?

It is a modern encryption algorithm.

### What Is CCMP?

It is one of the encryption modes used in Wi-Fi security.

### What Is GCMP?

It is one of the encryption modes used within the scope of modern Wi-Fi security.

### Should Wi-Fi Authentication Failure Logs Be Monitored?

Yes.

### What Is Wireless Brute Force?

It is a large number of password attempts being made on Wi-Fi authentication.

### What Is a WPA PSK Offline Attack?

It is offline password guessing being performed over captured authentication material.

### Why Is a Strong PSK Important?

It provides protection against weak password guessing attacks.

### Does SAE Reduce the Offline Dictionary Attack Risk?

It provides stronger protection than the WPA2-PSK approach.

### What Is a Wireless Handshake?

It is the messaging that occurs during the authentication/encryption setup between the client and the access point.

### What Is Wireless Packet Capture?

It is the recording of Wi-Fi frames for analysis.

### What Is Monitor Mode?

It is the operating mode that allows the wireless adapter to listen to the Wi-Fi frames around it.

### Are Promiscuous Mode and Monitor Mode the Same?

No.

Monitor mode can work at the wireless frame level.

### What Is a Channel?

It is the frequency band section in which Wi-Fi communication takes place.

### Is 2.4 GHz Different in Terms of Security?

Even though the basic security mechanism is the same, the coverage and interference are different.

### What Is 5 GHz?

It is a higher frequency band.

### What Is 6 GHz Wi-Fi?

It is the frequency band used in new generation Wi-Fi technologies.

### What Is Wi-Fi 6?

It is the modern Wi-Fi generation based on IEEE 802.11ax.

### What Is Wi-Fi 6E?

It is the version of Wi-Fi 6 that supports the use of the 6 GHz spectrum.

### What Is Wi-Fi 7?

It is the new generation high performance wireless networking standard.

### Is a New Wi-Fi Standard Automatically Secure?

No.

The security configuration is still critical.

### What Is Wireless Roaming?

It is the client passing from one access point to another while continuing the connection.

### What Is Fast Roaming?

It is the reduction of the roaming authentication time.

### What Is 802.11r?

It is the Fast BSS Transition standard.

### Does Fast Roaming Affect Security?

An incorrect or old configuration can create risk.

### What Is Wireless Mesh?

It is the wireless topology in which access points provide network connectivity through one another.

### What Is Mesh Backhaul Security?

It is the secure protection of the communication between mesh nodes.

### What Is a Wireless Bridge?

It is the system that connects two network segments to each other over Wi-Fi.

### Why Is an Unauthorized Wireless Bridge Risky?

It can bypass network segmentation boundaries.

### Is a Mobile Hotspot Risky?

A corporate endpoint connecting to a personal hotspot can reduce security visibility.

### Can a Personal Hotspot Create a Bridge to the Corporate Network?

In some incorrect configurations or usage patterns it can create risk.

### What Is Wi-Fi Direct?

It is the technology that allows devices to establish direct wireless communication without an access point.

### Should Wi-Fi Direct Be Addressed in the Security Policy?

According to the risk level, yes.

### Is Bluetooth Part of Wi-Fi Security?

Even though it is a separate wireless technology it can be evaluated together within the scope of the endpoint attack surface.

### What Is Wireless NAC?

It is the use of NAC for Wi-Fi authentication and access policy.

### What Is Wireless 802.1X?

It is Wi-Fi user/device authentication being performed over 802.1X.

### What Is Wireless RADIUS Accounting?

It is the recording of user connection activity through RADIUS accounting.

### Should Wi-Fi Logs Be Sent to the SIEM?

Yes.

### Which Wireless Logs Are Important?

Authentication Failure

Rogue AP Detection

New Device

SSID Connection

Admin Change

### Wireless SOC Use Cases

Rogue AP

Evil Twin

Repeated Authentication Failure

Unauthorized Device

New AP Detected

### Do Wi-Fi Authentication Logs Provide User Identity?

If enterprise authentication is being used, yes.

### Why Is Attribution Difficult With a Shared PSK?

All users use the same credential.

### Is Wireless Threat Intelligence Used?

Network threat intelligence does not provide Wi-Fi identity directly but it can be correlated with malicious destination traffic.

### Is Wireless NDR Possible?

When wireless client traffic passes to the wired network it can be analyzed by NDR.

### What Is the Difference Between Wireless IDS and NDR?

WIDS focuses on radio/wireless layer threats.

NDR focuses on network traffic behaviour.

### How Do Wi-Fi and the Firewall Work Together?

SSID:

Corporate

↓

VLAN

↓

Firewall

↓

Authorized Resources

### What Is Wireless East-West Traffic?

It is the traffic Wi-Fi clients make with internal resources or with one another.

### Does Client Isolation Reduce East-West Traffic?

It can limit client-to-client traffic.

### Is There a Wi-Fi Lateral Movement Risk?

Yes.

A compromised wireless endpoint can attack the internal network.

### Does Wireless Segmentation Reduce Lateral Movement?

Yes.

### What Can a Compromised Wi-Fi Client Do?

Network discovery,

credential attack,

lateral movement

it can try these.

### Should the Wi-Fi Endpoint Be Protected With EDR?

On managed endpoints, yes.

### Why Is Wi-Fi Device Posture Important?

It ensures that not only an authorized but a healthy device connects.

### What Is Wireless Zero Trust?

It is the access model in which connecting to the Wi-Fi does not provide automatic trust.

### How Is Zero Trust Wi-Fi Designed?

Identity

Device Certificate

Posture

Dynamic Policy

these can be used.

### Should a User Who Connects to the Wi-Fi Be Considered Trusted?

No.

### What Is Identity-Based Wi-Fi?

It is network policy being applied through user/device identity instead of a shared password.

### What Is Role-Based Wi-Fi Access?

It is different network access being given according to the user role.

### What Is Context-Aware Wi-Fi?

It is the inclusion of device, user, location or risk information in the access decision.

### What Is Adaptive Wireless Access?

It is the Wi-Fi access policy being changed dynamically as the risk changes.

### What Is Wireless Incident Response?

It is the response process applied when a wireless attack or unauthorized access is detected.

### What Should Be Done If a Rogue AP Is Detected?

The device must be verified,

its physical location must be determined,

its network connection must be investigated,

and if it is unauthorized it must be removed.

### What Should Be Done If an Evil Twin Is Detected?

The affected users,

credential exposure,

SSID behaviour,

certificate validation

must be examined.

### What Should Be Done If a Deauthentication Attack Is Detected?

The source and the affected APs/clients must be examined, and the PMF and WIDS/WIPS controls must be reviewed.

### What Is Wireless Forensics?

It is the analysis of Wi-Fi event and packet information for the purpose of incident investigation.

### Is Wireless Packet Capture Used for Forensics?

Yes.

### What Is a Wireless Security Assessment?

It is the evaluation of the Wi-Fi infrastructure in terms of security configuration and exposure.

### What Is a Wireless Penetration Test?

It is the testing of wireless network security controls within an authorized scope.

### What Does a Wireless Security Assessment Examine?

SSID

Encryption

Authentication

Segmentation

Rogue AP

Management Security

### Why Is a Wi-Fi Penetration Test Necessary?

It can help to identify configuration weaknesses and unauthorized access paths.

### What Is a Wireless Coverage Survey?

It is the measurement of the Wi-Fi signal coverage in the physical environment.

### What Is a Site Survey?

It is the analysis of wireless coverage, interference and access point placement.

### What Is a Security Site Survey?

It is the survey that also evaluates security risks such as how far the signal carries outside the building.

### Should the Wi-Fi Signal Carry Outside the Building?

The minimum necessary coverage can be targeted according to the operational requirement.

### Is Excessive RF Coverage Risky?

It can increase the possibility of an attacker reaching the wireless network from a distance.

### What Is AP Power Tuning?

It is the optimization of the access point transmit power level.

### What Is a Wireless Security Baseline?

It is the minimum security standard the organization wants applied on all its Wi-Fi infrastructure.

### An Example of a Wireless Security Baseline

WPA2/WPA3 Enterprise

802.1X

RADIUS

PMF

Guest Isolation

Central Logging

### Is a Wi-Fi Configuration Backup Necessary?

Yes.

Controller and AP configurations must be backed up securely.

### What Is Wireless Change Management?

It is the controlled management of SSID, VLAN, authentication and security configuration changes.

### Why Is a Wi-Fi Change Log Important?

It helps to track unauthorized or incorrect configuration changes.

### Should the Wireless Admin Use MFA?

If possible, yes.

### Should the Wireless Admin Use a Shared Account?

No.

### Can AAA Be Used for Wireless Management?

Yes.

Central AAA systems such as RADIUS or TACACS+ can be used.

### Can TACACS+ Be Used for WLC Management?

According to platform support, yes.

### Wireless Security KPIs

For example:

Enterprise Authentication Coverage

Rogue AP Count

Unknown Client Count

WPA3 Adoption

Guest Access Count

### Wireless Security KRIs

Shared PSK Usage

Legacy Encryption

Unauthorized AP

EOL Access Point

Unsegmented Guest Wi-Fi

### What Should a Wireless Security Dashboard Show?

Active Clients

SSID Usage

Authentication Failure

Rogue AP

Security Alerts

### The Most Frequently Made Mistakes in Wireless Security

The mistakes frequently encountered in organizations are these:

- Using a single shared Wi-Fi password
- Using WEP or old security protocols
- Not evaluating WPA2/WPA3 Enterprise
- Not performing server certificate validation
- Not separating the guest network from the corporate network
- Not using guest client isolation
- Giving BYOD devices broad access
- Placing IoT devices on the corporate VLAN
- Not performing rogue AP monitoring
- Not evaluating the Evil Twin risk
- Not using PMF
- Opening the WLC management interface to broad access
- Not updating access point firmware
- Not sending Wi-Fi logs to the SIEM
- Not performing a wireless security assessment
- Not evaluating RF coverage from a security point of view

### Wireless Security Checklist

- Is WEP completely disabled?
- Is WPA2/WPA3 being used?
- Has Enterprise Wi-Fi been evaluated?
- Is 802.1X active?
- Is RADIUS redundant?
- Is EAP-TLS being used?
- Is certificate validation correct?
- Is PMF active?
- Has the use of a shared PSK been limited?
- Is the guest SSID on a separate VLAN?
- Is the guest network internet-only?
- Is client isolation active?
- Is there BYOD segmentation?
- Is the IoT SSID separate?
- Is there rogue AP detection?
- Is WIDS/WIPS active?
- Is WLC management secure?
- Is the firmware up to date?
- Do the wireless logs go to the SIEM?
- Is a wireless pentest being carried out?

### Wireless Security Maturity Model

#### Level 1 - Shared Wi-Fi

All users use a shared PSK.

#### Level 2 - Segmented Wi-Fi

The guest, employee and IoT networks have been separated.

#### Level 3 - Enterprise Authentication

802.1X and RADIUS are used.

#### Level 4 - Wireless Threat Detection

WIDS/WIPS, posture and dynamic access are applied.

#### Level 5 - Zero Trust Wireless

Identity, device certificate, posture and continuous risk are evaluated together.

### Frequently Asked Questions

#### What is Wi-Fi Security?

Wi-Fi Security is the approach of protecting wireless network access with authentication, encryption, segmentation and monitoring controls.

#### What is WPA2?

WPA2 is the widespread security standard used for authentication and encryption on Wi-Fi networks.

#### What is WPA3?

WPA3 is the Wi-Fi security standard that improves modern wireless authentication and encryption features.

#### What is WPA2-Enterprise?

It is the enterprise wireless model that provides user/device authentication through 802.1X and RADIUS.

#### What is WPA3-Enterprise?

It is the WPA3 model that provides advanced authentication and encryption on corporate wireless networks.

#### What is PSK?

Pre-Shared Key is the shared or device-based key used to reach the Wi-Fi.

#### What is SAE?

Simultaneous Authentication of Equals is the WPA3-Personal authentication mechanism.

#### What is PMF?

Protected Management Frames is the mechanism that protects some Wi-Fi management frames against spoofing and deauthentication attacks.

#### What is a Rogue AP?

It is a wireless access point not authorized by the organization.

#### What is Evil Twin?

It is the fake access point attack that imitates a legitimate Wi-Fi network.

#### What is WIDS?

Wireless Intrusion Detection System helps to detect suspicious activities in the wireless environment.

#### What is WIPS?

Wireless Intrusion Prevention System is the system that can detect wireless threats and take measures in certain situations.

#### How should Guest Wi-Fi be made secure?

It must be separated from the corporate network, internet-only access must be applied with a firewall and client isolation must be used where necessary.

#### Should a shared password be used on corporate Wi-Fi?

As far as possible identity-based 802.1X/RADIUS authentication should be preferred.

### Conclusion: Corporate Wi-Fi Security Is Much More Than a Strong Password

For years wireless security was evaluated through the question:

**"Is our Wi-Fi password strong?"**

through that question.

However, on modern corporate networks this approach is not sufficient.

Because a shared Wi-Fi password:

does not provide user identity,

does not provide device identity,

does not provide role-based access,

does not provide posture checking,

makes accountability difficult.

Instead of this the modern wireless security approach:

**Identity → Device → Authentication → Segmentation → Monitoring**

must use this chain.

When a device connects to the wireless network, knowing the correct password alone should not be enough.

In structures where it is possible:

**802.1X + RADIUS + Certificate-Based Authentication**

the use of these forms a strong enterprise wireless security approach.

Then the user or the device:

Employee VLAN,

Guest VLAN,

BYOD VLAN,

IoT VLAN

must be directed to appropriate segments such as these.

At the same time the organization must monitor not only its own access points but the surrounding wireless environment as well.

Because the attack does not always come through a legitimate AP.

#### Rogue AP

and

#### Evil Twin

threats such as these can come from outside the corporate Wi-Fi architecture.

For this reason a strong Wi-Fi security model:

**Protect + Authenticate + Segment + Monitor + Detect**

must be thought of in this way.

The most important principle is this:

**Being able to reach the Wi-Fi signal should not mean being able to reach the corporate network.**

The goal of modern Wireless Security is:

**"Whoever knows the password connects."**

from this approach

**"Whoever's identity and device are verified reaches only the resource they need."**

to move to this approach.
