Dynamic reserve WLAN based on authentication availability
An electronic device (such as an access point) that dynamically provides a reserve wireless local area network (WLAN) having a reserve service set identifier (SSID) is described. During operation, the electronic device may provide a WLAN having an SSID, where access to services in a network via the WLAN is gated by authentication performed by a computer. Note that the computer may include a controller of the electronic device or an authentication computer. When the computer is offline or communication with the computer is unavailable, the electronic device may dynamically provide the reserve WLAN having the reserve SSID, where access to a subset of the services in the network via the reserve WLAN is gated by second authentication performed by the electronic device. Moreover, the services may include sensitive (or more-secure) and insensitive (or less-secure) services, and the subset of the services may include the insensitive services.
1 . An electronic device, comprising:
one or more interface circuits configured to communicate with a computer;
a processor coupled to the one or more interface circuits; and
memory, coupled to the processor, configured to store program instructions, wherein, when executed by the processor, the program instructions cause the electronic device to perform operations comprising:
providing a wireless local area network (WLAN) having a service set identifier (SSID), wherein access to services in a network via the WLAN is gated by authentication performed by the computer; and
when the computer is offline or communication with the computer is unavailable, dynamically providing a reserve WLAN having a reserve SSID, wherein access to a subset of services in the network via the reserve WLAN is gated by a second authentication performed by the electronic device,
wherein, when no electronic devices are connected to the reserve WLAN having the reserve SSID, dynamically turning off the reserve WLAN having the reserve SSID.
2 . The electronic device of claim 1 , wherein the electronic device comprises an access point.
3 . The electronic device of claim 1 , wherein the computer comprises a controller of the electronic device or an authentication computer.
4 . The electronic device of claim 3 , wherein the authentication computer comprises a RADIUS server or an authentication, authorization, and accounting (AAA) server.
5 . The electronic device of claim 1 , wherein the services comprise sensitive or more-secure and insensitive or less-secure services, and the subset of the services comprises the insensitive or less-secure services.
6 . The electronic device of claim 1 , wherein the second authentication is less secure than the authentication.
7 . The electronic device of claim 6 , wherein the second authentication comprises pre-shared-key (PSK) authentication.
8 . The electronic device of claim 1 , wherein the operations comprise, when the computer is online or communication with the computer is available, dynamically turning off the reserve WLAN having the reserve SSID.
9 . The electronic device of claim 1 , wherein the operations comprise, when the computer is online or communication with the computer is available and at least a second electronic device is connected to the reserve WLAN having the reserve SSID, only allowing an additional electronic device to connect to the WLAN having the SSID.
10 . A method for dynamically providing a reserve wireless local area network (WLAN) having a reserve service set identifier (SSID), the method comprising:
sending a first WLAN identifier associated with a first SSID for authentication by an authentication server to authorize access to a first set of network resources;
monitoring reachability of the authentication server;
in response to determining that the authentication server is unreachable, sending a second WLAN identifier associated with a reserve SSID while continuing to send the first WLAN identifier associated with the first SSID;
receiving, via the reserve SSID, an association request from a client device;
locally authenticating the client device at an access point, independent of the authentication server; and
responsive to successfully locally authenticating the client device, assigning the client device a restricted network access policy that permits access to a second set of network resources that is a subset of the first set of network resources.
11 . The method of claim 10 , wherein monitoring reachability of the authentication server comprises determining that the authentication server is unreachable based on an absence of a received heartbeat message from the authentication server during a time interval.
12 . The method of claim 10 , wherein locally authenticating the client device comprises performing pre-shared-key (PSK) authentication based on a credential stored at the access point.
13 . The method of claim 10 , wherein assigning the restricted network access policy comprises at least one of assigning a restricted virtual local area network (VLAN), applying a filter identifier, or applying a role-based access policy that blocks access to one or more sensitive services while permitting access to one or more insensitive services.
14 . The method of claim 10 , further comprising:
after determining that the authentication server is reachable, suppressing acceptance of new client associations via the reserve SSID while maintaining the restricted network access policy for client devices currently associated via the reserve SSID.
15 . The method of claim 14 , further comprising:
turning off the reserve WLAN by terminating broadcast of the reserve SSID in response to determining that no client devices are associated via the reserve SSID.
16 . A method for dynamically providing a reserve wireless local area network (WLAN) having a reserve service set identifier (SSID), comprising:
providing, by an electronic device, a WLAN having an SSID, wherein access to services in a network via the WLAN is gated by authentication performed by a computer; and
when the computer is offline or communication with the computer is unavailable, dynamically providing the reserve WLAN having the reserve SSID, wherein access to a subset of the services in the network via the reserve WLAN is gated by a second authentication performed by the electronic device; and
when the computer is online or communication with the computer is available, dynamically turning off the reserve WLAN having the reserve SSID.
17 . The method of claim 16 , wherein the computer comprises a controller of the electronic device or an authentication computer.
18 . The method of claim 16 , wherein the services comprise sensitive or more-secure and insensitive or less-secure services, and the subset of the services comprises the insensitive or less-secure services.
19 . The method of claim 16 , wherein the second authentication is less secure than the authentication.
20 . The method of claim 16 , wherein the electronic device comprises an access point.