- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SSID config for wireless payment devices
Hi,
Im working on researching the best config/best practice for creating an SID specifically for wireless payment devices. We want to keep the VLAN for these devices isolated from the rest of the network. So these questions are specifically for wireless payment devices Ingenico iSMP4 Companion
1- I want to use MAC based access control that uses RADIUS server. It says there is no encryption for this but im assuming that's just for the authentication part of not, not the actual traffic. Would this be the best option to use for payment devices?
2- What's the difference between MAC based access control and the Enterprise option?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We use PSK with WPA2, I don't think the Mac based access control has encryption at all for association so MAC addresses can be sniffed and copied, so isn't suitable. We keep them on a separate VLAN and then out to the acquirer. They are Ingenico devices and this works well. Make sure you have the latest devices as the previous gen couldn't roam due to a firmware bug.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How many devices are you taking about and over how many stores?
How many people will be setting them up?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We're looking at around 56 devices.
I will be configuring the network part of it and my coworker will be setting up the devices
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi. Sorry did you have a suggestion?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Im assuming you use the Layer 3 roaming, do you have a separate VLAN for the payment devices or do you use your data VLAN?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We use bridge mode to a VLAN that only has the payment devices on.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
1. MAC-based Access Control with RADIUS
You're right—MAC-based authentication itself isn’t encrypted, but the actual traffic can still be encrypted with WPA2/WPA3. While this setup works for payment devices, consider adding other layers like 802.1X for stronger security, as MAC addresses can be spoofed.
2. MAC-based vs. Enterprise Authentication
MAC-based: Authenticates by device MAC address. It’s simpler but less secure.
Enterprise (802.1X): Uses credentials (certificates, usernames) for authentication, offering stronger security and encryption, including during the authentication phase.
For the best security with isolated payment VLANs, Enterprise authentication (802.1X) is the recommended option, though it’s more complex.
