mirror of
https://github.com/netbox-community/netbox.git
synced 2026-01-12 05:20:31 +01:00
new Wireless LANs security modes #6465
Closed
opened 2025-12-29 19:41:00 +01:00 by adam
·
6 comments
No Branch/Tag Specified
main
update-changelog-comments-docs
feature-removal-issue-type
20911-dropdown
20239-plugin-menu-classes-mutable-state
21097-graphql-id-lookups
feature
fix_module_substitution
20923-dcim-templates
20044-elevation-stuck-lightmode
feature-ip-prefix-link
v4.5-beta1-release
20068-import-moduletype-attrs
20766-fix-german-translation-code-literals
20378-del-script
7604-filter-modifiers-v3
circuit-swap
12318-case-insensitive-uniqueness
20637-improve-device-q-filter
20660-script-load
19724-graphql
20614-update-ruff
14884-script
02496-max-page
19720-macaddress-interface-generic-relation
19408-circuit-terminations-export-templates
20203-openapi-check
fix-19669-api-image-download
7604-filter-modifiers
19275-fixes-interface-bulk-edit
fix-17794-get_field_value_return_list
11507-show-aggregate-and-rir-on-api
9583-add_column_specific_search_field_to_tables
v4.5.0
v4.4.10
v4.4.9
v4.5.0-beta1
v4.4.8
v4.4.7
v4.4.6
v4.4.5
v4.4.4
v4.4.3
v4.4.2
v4.4.1
v4.4.0
v4.3.7
v4.4.0-beta1
v4.3.6
v4.3.5
v4.3.4
v4.3.3
v4.3.2
v4.3.1
v4.3.0
v4.2.9
v4.3.0-beta2
v4.2.8
v4.3.0-beta1
v4.2.7
v4.2.6
v4.2.5
v4.2.4
v4.2.3
v4.2.2
v4.2.1
v4.2.0
v4.1.11
v4.1.10
v4.1.9
v4.1.8
v4.2-beta1
v4.1.7
v4.1.6
v4.1.5
v4.1.4
v4.1.3
v4.1.2
v4.1.1
v4.1.0
v4.0.11
v4.0.10
v4.0.9
v4.1-beta1
v4.0.8
v4.0.7
v4.0.6
v4.0.5
v4.0.3
v4.0.2
v4.0.1
v4.0.0
v3.7.8
v3.7.7
v4.0-beta2
v3.7.6
v3.7.5
v4.0-beta1
v3.7.4
v3.7.3
v3.7.2
v3.7.1
v3.7.0
v3.6.9
v3.6.8
v3.6.7
v3.7-beta1
v3.6.6
v3.6.5
v3.6.4
v3.6.3
v3.6.2
v3.6.1
v3.6.0
v3.5.9
v3.6-beta2
v3.5.8
v3.6-beta1
v3.5.7
v3.5.6
v3.5.5
v3.5.4
v3.5.3
v3.5.2
v3.5.1
v3.5.0
v3.4.10
v3.4.9
v3.5-beta2
v3.4.8
v3.5-beta1
v3.4.7
v3.4.6
v3.4.5
v3.4.4
v3.4.3
v3.4.2
v3.4.1
v3.4.0
v3.3.10
v3.3.9
v3.4-beta1
v3.3.8
v3.3.7
v3.3.6
v3.3.5
v3.3.4
v3.3.3
v3.3.2
v3.3.1
v3.3.0
v3.2.9
v3.2.8
v3.3-beta2
v3.2.7
v3.3-beta1
v3.2.6
v3.2.5
v3.2.4
v3.2.3
v3.2.2
v3.2.1
v3.2.0
v3.1.11
v3.1.10
v3.2-beta2
v3.1.9
v3.2-beta1
v3.1.8
v3.1.7
v3.1.6
v3.1.5
v3.1.4
v3.1.3
v3.1.2
v3.1.1
v3.1.0
v3.0.12
v3.0.11
v3.0.10
v3.1-beta1
v3.0.9
v3.0.8
v3.0.7
v3.0.6
v3.0.5
v3.0.4
v3.0.3
v3.0.2
v3.0.1
v3.0.0
v2.11.12
v3.0-beta2
v2.11.11
v2.11.10
v3.0-beta1
v2.11.9
v2.11.8
v2.11.7
v2.11.6
v2.11.5
v2.11.4
v2.11.3
v2.11.2
v2.11.1
v2.11.0
v2.10.10
v2.10.9
v2.11-beta1
v2.10.8
v2.10.7
v2.10.6
v2.10.5
v2.10.4
v2.10.3
v2.10.2
v2.10.1
v2.10.0
v2.9.11
v2.10-beta2
v2.9.10
v2.10-beta1
v2.9.9
v2.9.8
v2.9.7
v2.9.6
v2.9.5
v2.9.4
v2.9.3
v2.9.2
v2.9.1
v2.9.0
v2.9-beta2
v2.8.9
v2.9-beta1
v2.8.8
v2.8.7
v2.8.6
v2.8.5
v2.8.4
v2.8.3
v2.8.2
v2.8.1
v2.8.0
v2.7.12
v2.7.11
v2.7.10
v2.7.9
v2.7.8
v2.7.7
v2.7.6
v2.7.5
v2.7.4
v2.7.3
v2.7.2
v2.7.1
v2.7.0
v2.6.12
v2.6.11
v2.6.10
v2.6.9
v2.7-beta1
Solcon-2020-01-06
v2.6.8
v2.6.7
v2.6.6
v2.6.5
v2.6.4
v2.6.3
v2.6.2
v2.6.1
v2.6.0
v2.5.13
v2.5.12
v2.6-beta1
v2.5.11
v2.5.10
v2.5.9
v2.5.8
v2.5.7
v2.5.6
v2.5.5
v2.5.4
v2.5.3
v2.5.2
v2.5.1
v2.5.0
v2.4.9
v2.5-beta2
v2.4.8
v2.5-beta1
v2.4.7
v2.4.6
v2.4.5
v2.4.4
v2.4.3
v2.4.2
v2.4.1
v2.4.0
v2.3.7
v2.4-beta1
v2.3.6
v2.3.5
v2.3.4
v2.3.3
v2.3.2
v2.3.1
v2.3.0
v2.2.10
v2.3-beta2
v2.2.9
v2.3-beta1
v2.2.8
v2.2.7
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
v2.1.6
v2.2-beta2
v2.1.5
v2.2-beta1
v2.1.4
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.10
v2.1-beta1
v2.0.9
v2.0.8
v2.0.7
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v2.0.0
v2.0-beta3
v1.9.6
v1.9.5
v2.0-beta2
v1.9.4-r1
v1.9.3
v2.0-beta1
v1.9.2
v1.9.1
v1.9.0-r1
v1.8.4
v1.8.3
v1.8.2
v1.8.1
v1.8.0
v1.7.3
v1.7.2-r1
v1.7.1
v1.7.0
v1.6.3
v1.6.2-r1
v1.6.1-r1
1.6.1
v1.6.0
v1.5.2
v1.5.1
v1.5.0
v1.4.2
v1.4.1
v1.4.0
v1.3.2
v1.3.1
v1.3.0
v1.2.2
v1.2.1
v1.2.0
v1.1.0
v1.0.7-r1
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3-r1
v1.0.3
1.0.0
Labels
Clear labels
beta
breaking change
complexity: high
complexity: low
complexity: medium
needs milestone
netbox
pending closure
plugin candidate
pull-request
severity: high
severity: low
severity: medium
status: accepted
status: backlog
status: blocked
status: duplicate
status: needs owner
status: needs triage
status: revisions needed
status: under review
topic: GraphQL
topic: Internationalization
topic: OpenAPI
topic: UI/UX
topic: cabling
topic: event rules
topic: htmx navigation
topic: industrialization
topic: migrations
topic: plugins
topic: scripts
topic: templating
topic: testing
type: bug
type: deprecation
type: documentation
type: feature
type: housekeeping
type: translation
Mirrored from GitHub Pull Request
No Label
type: feature
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/netbox#6465
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @rfl64 on GitHub (May 9, 2022).
NetBox version
v3.2.2
Feature type
Data model extension
Proposed functionality
should be possible add WPA Enterprise security modes like EAP-TLS, PEAP, and so on. thanks
https://www.securew2.com/solutions/wpa2-enterprise-and-802-1x-simplified
Use case
Enterprise authentication and encryption methods used in Wireless Lans on Enterprise
Database changes
new items on Auth cipher and certificate or preshared key options.
External dependencies
https://www.securew2.com/solutions/wpa2-enterprise-and-802-1x-simplified
@DanSheps commented on GitHub (May 10, 2022):
What are you proposing to add? I see you linked to a website but we expect a minimum amount of effort to be put into FR's, and in a instance like this, that means you need to at lease provide the additional details without requiring maintainers or volunteers to click through to determine the model.
@rfl64 commented on GitHub (May 10, 2022):
items to add to security modes when Enterprise security is selected would be:
EAP-MD-5
EAP-TLS
EAP-TTLS
EAP-FAST
EAP-SIM
EAP-AKA
LEAP
PEAP
they are all different security mechanisms used in Wireless Lans
thanks in advance
@DanSheps commented on GitHub (May 11, 2022):
Yes, but where?
They don't fit with the wireless types (WPA, WPA-Enterprise, etc)
They also don't 100% fit with encryption types.
Also, these typically aren't defined on the controller or AP, but are instead a function of what the supplicant (laptop, desktop, etc) and authenticator (ISE, Clearpass, Packet fence, freeradius, etc) support and are configured for. For example, I can't just turn off TEAP on my AP's.
I think you might actually need something to specifically model your 802.1x/WPA-Enterprise settings beyond the WLAN model
@rfl64 commented on GitHub (May 11, 2022):
I think netbox is an inventory, a source of truth as defined in documentation with information of all related to networks and devices. WLANs are not related to a particular device registered in netbox but is a property, functionality or service on a network.
Just like VLANs than are not attached to a single switch.
Of course, APs are network bridges than links two media types (wired and wireless). Point of view used in WLANs and encryption type in netbox does not apply to enterprise networks because in enterprise networks other security types, like described, are used. WPA, WPA2 and WPA3 are home user WLANs and all they share an unique shared key (PSK).
It doesn't matter which device is authenticator (AP/switch), supplicant or authentication server (ISE, NAC, FreeRadius, etc), if netbox wants to hold information about WLANs and its properties, described enterprise security types are needed.
May be just with a listbox with different security types would be enought, without specifiying if using certificates. Also, if using an shared secret for Radius AP authentication, a field for store that shared secret would be appreciated.
In my opinion, netbox is a awesome tool. Thanks for all your work.
@DanSheps commented on GitHub (May 11, 2022):
The big difference here is VLANs are attached to a switch. The wireless model replicates what are attached to AP's or stations and not what is configured on the client or server for authentication as that is outside the scope of what the wireless model is intended for.
I agree, but there is a "WPA-Enterprise" option in there to cover that.
Again, EAP-*/TEAP/LEAP is not a function of the wlan but of the configuration of the supplicant and authentication server, which is why it is inappropriate to store that information on the wlan model.
Again, this doesn't work. Mainly because your radius configuration can be one of the following:
(EAP-TTLS, PEAP-MSCHAPv2, TEAP)
or
(EAP-TTLS)
or
(PEAP-MSCHAPv2, TEAP, LEAP)
or
any number of other combinations.
WLAN is the wrong place to store your authentication server settings for your wireless deployment. We currently don't have a correct place for it, which is why this would likely require a new model and also why that given that this is a niche enough case it likely won't be included in core.
@jeremystretch commented on GitHub (May 18, 2022):
This was covered by working group when we first designed WLAN support, and @DanSheps provides a good summary of why the proposed change is untenable. It's something we could potentially add to NetBox, but as Dan notes this will likely require a new field or model and warrants a deeper discussion.
If you'd like, you're welcome to start a discussion to see if you can collaborate with other NetBox users to come up with a detailed implementation proposal, which can then be submitted as a new FR.