When DePaul University in Chicago first made wireless connectivity available to students and staff, the wireless network used basic wired equivalent privacy (WEP) authentication as an extension of traditional hard-wired networking ports already available in offices, classrooms, labs, libraries and other areas. This Wi-Fi connectivity allowed faculty, students and staff with laptops to move around campus with ease while staying connected to the network. Security and information services (IS) management, however, became a nightmare.
“DePaul originally distributed complex WEP keys to end-users, which caused confusion, lost keys and lots of calls to the help desk,” says Joe Salwach, associate vice president for information services.
As a security protocol for wireless networks, WEP solutions have also been prone to exposure to malicious threats due to inherent authentication vulnerabilities. Salwach noted emerging studies in which WEP had been broken within a few minutes of passive eavesdropping by an attacker. While DePaul is taking extra precautions beyond WEP, the use of secure applications, such as SSL, on top of the wireless network became imperative. DePaul decided it needed to phase out its existing wireless network deployed with WEP for a more secure wireless authentication solution.
“The turning point came when we decided to implement about 100 access points in a residence hall at our Lincoln Park campus,” says Salwach. “We wanted to provide wireless coverage to the students living in our halls in addition to their existing wired connectivity.
“Since we’re so geographically dispersed, we didn’t want to manage distributed boxes. We wanted to centrally control it out of only one campus,” says Salwach. After ruling out an IPSec VPN approach, because it would require hands-on installation and maintenance of clients on widely distributed and unmanaged student machines, DePaul chose to evaluate SSL VPN solutions that could enable users to easily set up and connect via the…