Re: [WIRELESS-LAN] SSID names

2017-02-21 Thread Jonathan Waldrep
they trust the most. We did this, and the answer was clear. -- Jonathan Waldrep Network Engineer Network Infrastructure and Services Virginia Tech On Tue, Feb 21, 2017 at 4:06 PM, Adam T Ferrero <a...@temple.edu> wrote: > > These have served us pretty well. We only have a mac auth

Re: [WIRELESS-LAN] Xbox 360 connection issues? - Aruba

2017-01-11 Thread Jonathan Waldrep
to connect to older models to know if this made any difference (we're using 225/224s and 215/214s in the residential halls). Newer 360s seem to connect just fine. -- Jonathan Waldrep Network Engineer Network Infrastructure and Services Virginia Tech On Wed, Jan 11, 2017 at 9:26 AM, Williams, Jess

Re: [WIRELESS-LAN] EAP-TLS

2017-08-16 Thread Jonathan Waldrep
ed on Android 7 (maybe even 7.1) and up, so it isn't going to help a lot of people *today*, but is definitely will in the future. -- Jonathan Waldrep Network Engineer Network Infrastructure and Services Virginia Tech ** Participation and subscription information for this EDUCAUSE Cons

Re: [WIRELESS-LAN] EAP-PEAP risk/benefit assessment

2017-07-11 Thread Jonathan Waldrep
to the compromised user's financial records, email, or anything else. -- Jonathan Waldrep Network Engineer Network Infrastructure and Services Virginia Tech On Mon, Jul 10, 2017 at 8:24 PM, Mike King <m...@mpking.com> wrote: > Marcelo, > > If windows 7 is just 4%, what is your highest perce

Re: [WIRELESS-LAN] ArubaOS 8.X Experiences

2017-06-08 Thread Jonathan Waldrep
that a large auditorium is an ideal location for this, due to a lot of overlapping coverage. If you have a one-off office with a single AP, there will be ~2 minute outage when the AP reboots. Disclaimer: I haven't gotten any road time with 8.x outside of a lab, yet. -- Jonathan Waldrep Network Engineer

Re: [WIRELESS-LAN] Re-authentication times for guest wireless solutions

2018-05-10 Thread Jonathan Waldrep
not have to log in again, as long as their account is valid. Side note, we also use eduroam as our primary wireless network. Anyone with valid eduroam credentials will just connect automatically. -- Jonathan Waldrep Network Engineer Network Infrastructure and Services Virginia Tech On Thu, May 10

Re: [WIRELESS-LAN] Eduroam and Govroam

2018-01-04 Thread Jonathan Waldrep
spital and firehouse, etc. As for the security side, fire my previous comment toward the public entities. -- Jonathan Waldrep Network Engineer Network Infrastructure and Services Virginia Tech On Thu, Jan 4, 2018 at 3:20 PM, Jeffrey D. Sessler <j...@scrippscollege.edu> wrote: > I’m not speaking

Re: [WIRELESS-LAN] WLC interface groups?

2019-08-29 Thread Jonathan Waldrep
back. We implemented it, and haven't looked back. The short of it is VLAN pooling (or interface groups) doesn't actually buy you anything except a lot of complexity. [1] https://community.arubanetworks.com/t5/Validated-Reference-Design/Single-VLAN-Architecture-for-WLAN/ta-p/508698 -- Jonathan

Re: [WIRELESS-LAN] [External] [WIRELESS-LAN] Google Home Different SSIDs

2019-12-12 Thread Jonathan Waldrep
With the chromecast setup (which may or may not be the same as the Google Home), it would give you an error message if it wasn't on the same SSID, but then work anyways. It's been a while since I worked with it though, so their setup software may have changed. -- Jonathan Waldrep Network Engineer

Re: [WIRELESS-LAN] [External] [WIRELESS-LAN] Chromecasts and App on Phones

2020-01-27 Thread Jonathan Waldrep
. https://community.arubanetworks.com/t5/Validated-Reference-Design/Single-VLAN-Architecture-for-WLAN/ta-p/508698 -- Jonathan Waldrep Network Engineer Network Infrastructure and Services Virginia Tech On Mon, Jan 27, 2020 at 2:23 PM Carson, Dennis wrote: > We do use public ip sp

Re: [WIRELESS-LAN] EAP-TLS using ADCS and/or SecureW2

2020-02-07 Thread Jonathan Waldrep
etwork connection break after 2 years, for no apparent reason, is a frustrating user experience. Using your own PKI/CA does not have this restriction. -- Jonathan Waldrep Network Engineer Network Infrastructure and Services Virginia Tech On Thu, Feb 6, 2020 at 9:26 PM Turner, Ryan H wrote: >

Re: [WIRELESS-LAN] EAP-TLS using ADCS and/or SecureW2

2020-02-12 Thread Jonathan Waldrep
want_ one. That is a security decision that your group will have to make. All security involves trade-offs, and trade-offs are subjective. -- Jonathan Waldrep Network Engineer Network Infrastructure and Services Virginia Tech On Wed, Feb 12, 2020 at 3:14 PM Cappalli, Tim (Aruba) wrote: > > When

Re: [WIRELESS-LAN] Article: Android 11 tightens restrictions on CA certificates

2020-09-11 Thread Jonathan Waldrep
ty.cert.X509Certificate) [6] https://github.com/GEANT/CAT-Android [7] https://github.com/GEANT/CAT-Android/issues/37 -- Jonathan Waldrep Network Engineer Network Infrastructure and Services Virginia Tech ** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If

Re: [WIRELESS-LAN] Aruba 8.7 code.

2020-10-14 Thread Jonathan Waldrep
t; dhcp scope option 43. We were already doing controller discovery based on DHCP options, so we didn't see this. -- Jonathan Waldrep Network Engineer Network Infrastructure and Services Virginia Tech ** Replies to EDUCAUSE Community Group emails are sent to the entire community list

Re: [WIRELESS-LAN] iOS 14 Causing ARP Spoofing Events on Aruba Controllers

2020-09-22 Thread Jonathan Waldrep
and get a new address. From the controller's perspective, it just looks like a totally new device, not something spoofing. I could be missing something, though. -- Jonathan Waldrep Network Engineer Network Infrastructure and Services Virginia Tech ** Replies to EDUCAUSE Community Group e

Re: [WIRELESS-LAN] XPS 15 Laptop - Killer Networking NIC Experience

2020-07-20 Thread Jonathan Waldrep
is issue to me (issues at home and on-campus) - latest drivers, > etc. Trying to determine if recommending an alternate card preferable - or > tweaking some of the driver sets might be best. > Christopher Johnson > Wireless Network Engineer > Office of Technology Solutions | Illinois

Re: [WIRELESS-LAN] MAC Randomization, a step further...

2020-07-20 Thread Jonathan Waldrep
list. If you want to reply only to the person who sent the message, copy and > paste their email address and forward the email reply. Additional > participation and subscription information can be found at > https://www.educause.edu/community<https://nam01.safelinks.protection.ou

Re: [WIRELESS-LAN] Weak Security

2020-12-02 Thread Jonathan Waldrep
It is worth noting that WPA2 requires AES/CCMP support, where TKIP is optional. To give an idea of clients that support it, WPA2 support was added in Windows XP SP3 (2008), possibly with a hotfix before that. On 02/12/2020 10:39, James Helzerman wrote: Hi. Our first roll out for 802.1x used

Re: [WIRELESS-LAN] Recommendations on Combo Wi-Fi/Bluetooth Adapters

2020-11-18 Thread Jonathan Waldrep
will be best served by getting the latest drivers directly from Intel. It is worth noting this is currently the only path to a Wi-Fi 6 client. It is dirt cheap, so I really don't see a reason to not go with it. -- Jonathan Waldrep Network Engineer Network Infrastructure and Services V

Re: [WIRELESS-LAN] [EXTERNAL] [WIRELESS-LAN] Clearpass onboarding redirect not working on Safari

2020-11-17 Thread Jonathan Waldrep
ive portals, which is why the option to bypass that detection exists. -- Jonathan Waldrep Network Engineer Network Infrastructure and Services Virginia Tech ** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person w

Re: [WIRELESS-LAN] [External] Re: [WIRELESS-LAN] [External] Re: [WIRELESS-LAN] [External] Re: [WIRELESS-LAN] android 11 upcoming changes Feb 15th 2021

2021-02-02 Thread Jonathan Waldrep
XVCI6Mn0%3D%7C1000=6nMz5DAhMlYZdQzNRXAQb4ZeJODQMiogGMkDLH7fcaU%3D=0> > > ** > Replies to EDUCAUSE Community Group emails are sent to the entire community > list. If you want to reply only to the person who sent the message, copy and > paste their email address and forward the

Re: [WIRELESS-LAN] WPA3/OWE as campus solution?

2021-04-21 Thread Jonathan Waldrep
security model does not rely on layers 1 and 2, so the federated access is more valuable. -- Jonathan Waldrep Network Engineer Network Infrastructure and Services Virginia Tech On Wed, Apr 21, 2021 at 5:15 PM Jonathan Waldrep wrote: > I keep trying to reply to this thread with my thoughts a

Re: [WIRELESS-LAN] WPA3/OWE as campus solution?

2021-04-21 Thread Jonathan Waldrep
where a technical solution to a non-technical problem doesn't end up hurting the user. -- Jonathan Waldrep Network Engineer Network Infrastructure and Services Virginia Tech On Wed, Apr 21, 2021 at 3:22 PM Jennifer Minella wrote: > Ooh Lee what a great thread! I didn’t have a chance yester

Re: [WIRELESS-LAN] android 11 upcoming changes Feb 15th 2021

2021-02-10 Thread Jonathan Waldrep
ps://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity=04%7C01%7Cmathieu.sturm%40HOGENT.BE%7C4888106b756d4547bf0508d8cd1fc4e6%7C5cf7310e091a4bc5acd726c721d4cccd%7C1%7C0%7C637484883645458658%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLC

Re: [WIRELESS-LAN] android 11 upcoming changes Feb 15th 2021

2021-02-10 Thread Jonathan Waldrep
d4547bf0508d8cd1fc4e6%7C5cf7310e091a4bc5acd726c721d4cccd%7C1%7C0%7C637484883645468653%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000=g2UeXFyFPK8cobBFjIfjRid0dH6CTmabGJDQqyHQGpk%3D=0> > > ** > Replies to EDUCAUSE Community Group e

Re: [WIRELESS-LAN] Microsoft Windows 10 CRL Check on 802.1x Authentication

2021-04-14 Thread Jonathan Waldrep
be dragons ahead that I am completely unaware of. -- Jonathan Waldrep Network Engineer Network Infrastructure and Services Virginia Tech ** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message,

Re: [WIRELESS-LAN] 802.1X, onboarders, continued

2021-04-16 Thread Jonathan Waldrep
the general wireless network into a wide-open WLAN, relying > on other controls to provide security? I'll tackle this one in a follow up to your more recent thread. -- Jonathan Waldrep Network Engineer Network Infrastructure and Services Virginia Tech ** Replies to EDUCAUSE Co

Re: [WIRELESS-LAN] WPA3/OWE as campus solution?

2021-04-16 Thread Jonathan Waldrep
n can be found at > https://www.educause.edu/community > > ** > Replies to EDUCAUSE Community Group emails are sent to the entire community > list. If you want to reply only to the person who sent the message, copy and > paste their email address and forward the email reply.

Re: [WIRELESS-LAN] WPA3/OWE as campus solution?

2021-04-16 Thread Jonathan Waldrep
nks. [1]: https://library.educause.edu/topics/policy-and-law/calea -- Jonathan Waldrep Network Engineer Network Infrastructure and Services Virginia Tech ** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent t

Re: [WIRELESS-LAN] WPA3/OWE as campus solution?

2021-04-22 Thread Jonathan Waldrep
e, and I'll say it again. The challenges to getting rid of a captive portal are not technical. I know it sounds like a bold statement, but I really think we are seeing the beginnings of the end for captive portals and MAC auth. That end might still be 10 years out, but it is coming. -- J

Re: [WIRELESS-LAN] eduroam CAT Config/Cert Renewal with New Root

2021-08-13 Thread Jonathan Waldrep
om/InCommonRSAServerCA_2.crt [2]: http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt -- Jonathan Waldrep Network Engineer Network Infrastructure and Services Virginia Tech ** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person