Free wireless security planning tool. Compare WEP/WPA/WPA2/WPA3, select 802.11 standards, plan antenna placement, and generate deployment guides.
Wireless security planning designs the authentication, encryption, and access control framework for Wi-Fi networks to protect against unauthorized access, eavesdropping, and network-based attacks. As wireless networks have become the primary connectivity method for most organizations, securing them is as critical as securing wired infrastructure — but more challenging because radio signals extend beyond physical boundaries.
A wireless security plan addresses protocol selection (WPA3, WPA2-Enterprise), authentication architecture (802.1X, RADIUS), network segmentation (guest, corporate, IoT), and monitoring for rogue access points and wireless attacks.
| Protocol | Encryption | Authentication | Security Level | Status |
|---|---|---|---|---|
| WEP | RC4 (broken) | Open/Shared Key | None — crackable in minutes | Deprecated, never use |
| WPA | TKIP (weak) | PSK or 802.1X | Low — TKIP vulnerabilities | Deprecated |
| WPA2-Personal | AES-CCMP | Pre-Shared Key (PSK) | Medium — PSK can be cracked offline | Acceptable for home/small office |
| WPA2-Enterprise | AES-CCMP | 802.1X (RADIUS) | High — per-user authentication | Recommended for organizations |
| WPA3-Personal | AES-CCMP | SAE (Simultaneous Authentication of Equals) | High — resistant to offline attacks | Recommended when supported |
| WPA3-Enterprise | AES-256-GCMP | 802.1X with 192-bit security | Very High — CNSA-aligned | Recommended for high security |
| Network | Purpose | Security Controls |
|---|---|---|
| Corporate | Employee devices with full network access | WPA2/3-Enterprise, 802.1X, certificate auth, NAC |
| Guest | Visitor Internet access only | WPA2-Personal or captive portal, isolated VLAN, no internal access |
| IoT/OT | Cameras, sensors, building systems | Dedicated VLAN, MAC filtering, no Internet access unless required |
| BYOD | Personal employee devices | Separate SSID, limited access, MDM enrollment required |
WPA3 adds Simultaneous Authentication of Equals (SAE) which replaces the PSK 4-way handshake, making it resistant to offline dictionary attacks. It also provides forward secrecy (past sessions cannot be decrypted if the password is later compromised), individualized data encryption, and 192-bit security suite for enterprise environments.
WEP uses RC4 encryption with a 24-bit Initialization Vector (IV) that repeats frequently, allowing key recovery in minutes with freely available tools. It has no key management mechanism, uses CRC-32 which is not cryptographically secure, and provides no protection against replay attacks. WEP has been deprecated since 2004.
Omni-directional antennas radiate equally in all directions and suit general office coverage. Directional antennas (Yagi, parabolic) focus signal in one direction for point-to-point links or targeted coverage. Panel antennas provide wide-angle directional coverage for hallways or warehouses. Choice depends on coverage area shape and interference requirements.
A rogue AP is an unauthorized wireless access point connected to your network, either planted by an attacker or installed by an employee without approval. Rogue APs bypass network security controls and can provide an entry point for attackers. Detection strategies include wireless IDS, periodic scanning, and 802.1X port authentication.
802.11ax (Wi-Fi 6/6E) operates on 2.4/5/6 GHz bands with speeds up to 9.6 Gbps using OFDMA and MU-MIMO. 802.11be (Wi-Fi 7) adds 320 MHz channels, 4096-QAM modulation, and multi-link operation for speeds up to 46 Gbps. Wi-Fi 7 is ideal for high-density environments and latency-sensitive applications.
Build and test firewall rulesets with an interactive rule editor. Craft test packets to trace through rules, toggle stateless vs stateful inspection, view connection state tables, and analyze rule match statistics. Includes pre-built rulesets for web servers, DMZ, and corporate LAN.
Calculate IPv4/IPv6 subnets instantly. Get network ranges, subnet masks, usable hosts & CIDR notation. Free professional tool - no registration needed.
Comprehensive database of common network ports and their associated services