csd-team 13 oasis v.2. introduction oasis v.1 isps share access network security choice for...

23
CSD-Team 13 Oasis v.2

Upload: lydia-wilson

Post on 15-Jan-2016

220 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

CSD-Team 13

Oasis v.2

Page 2: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Introduction

Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the current solution

Page 3: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Current Solutions

Access based on MAC-address, easy to crack

No encryption over the wireless link No easy-to-use interface to add ISPs

Page 4: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Our Solution

Takes advantage of the latest technologiesEverything that supports 802.1X (Win XP,

Linux, Mac OS X)Highest security provided by hardware

Supports legacy hardware/softwareEverything that supports PPTP

Page 5: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Our Solution

Easy-to-use interface to add ISPs Few requirements for ISPs Easy-to-use for end-user

Page 6: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Oasis

ISP1 ISP2 ISP3

AP

Network OP

web-based

Radius-FreeRadius Database-SQL VLAN Monitor-Cacti Management server

Oasis Server

Page 7: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Oasis

ISP1 ISP2 ISP3

AP

Network OP

web-based

SupplicantSupplicant

Page 8: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Oasis

ISP1 ISP2 ISP3

AP

Network OP

web-based

Supplicant

[email protected]

Identifies ISPWhich server?Which VLAN?

[email protected]

Page 9: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Oasis

ISP1 ISP2 ISP3

AP

Network OP

web-based

Supplicant

[email protected]

RADIUS server

ISP

userYes

Yes VLAN

Page 10: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Oasis

ISP1 ISP2 ISP3

AP

Network OP

web-based

Client

[email protected]

Fall back server

PPTP

802.1X

Fallback VLAN

Page 11: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Oasis

ISP1 ISP2 ISP3

AP

Network OP

web-based

Client

[email protected]

Page 12: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Oasis

ISP1 ISP2 ISP3

AP

Network OP

web-based

Client

[email protected]

SNMP

SNMPSNMPSNMP

Page 13: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Front-end to RRDToolFront-end to RRDTool

SNMP supportSNMP support

Store data into MySQL DBStore data into MySQL DB

Done in PHPDone in PHP

Integrating into OASIS v.2Integrating into OASIS v.2 ScriptsScripts

Page 14: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the
Page 15: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Testing @ KistaIP

Tested both native and fallback Tested with different platforms Tested with switches and access points

Page 16: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Current KistaIP

VLANs used to seperate the ISPs. Short lease time IP address User chooses the ISP via web page. Switched to VLAN depends on selection

Page 17: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Native setup

Page 18: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Fallback setup

Page 19: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Problems faced

DHCP plugin to look for a DHCP server. DNS information doesn’t receive from ISP. Default route and Routing tables. Access points need additional features. Certificate Issues

Page 20: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Accomplishments

Management Server using XMLRPCConfiguration of FreeRADIUS

Management Interface Fallback Server

Transparent for ISPs Cacti integration Successful test with two ”fake” ISPs

Page 21: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Problems and limitations

Complicated setup Hardware configuration

Adding ISP requires reconfiguration of switches/access points

Fallback is limited by hardware supportFor wireless, needs multiple BSSIDs or multiple

APsFor wired, needs ”unauth vlan”

Page 22: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Future work

Packaging Certificates Automatic hardware configuration Local services

Page 23: CSD-Team 13 Oasis v.2. Introduction Oasis v.1 ISPs share access network Security Choice for end-users Compatible with legacy systems Problems with the

Team Members:

Ang Ma

Lucas Díez

Pratheepan Gunaratnam

Mikael Pettersson

Sasikumar Purushothaman

Thanks!

And Questions?