WLAN guidelines

Connection of wireless network access to the university network of the University of Kassel by users

The University of Kassel’s campus network is operated by the Data and Telecommunications Department at the IT Service Center. In addition to ongoing upgrades and expansions, a wide range of measures is necessary to ensure that this highly complex data network operates as smoothly and securely as possible. These measures range from planning (security, ease of maintenance, redundancies) to operations (configuration, network management, fault alerts, on-call service) to security organization with various firewall functionalities (basic protection against eavesdropping and misuse).

Also integrated into these operational and security concepts are all points of contact that connect the university network to the outside world. In addition to the connection to the global Internet (Internet gateway), this includes the operation of telephone gateways (dial-up via modem or ISDN for university staff and students) as well as the wireless network infrastructure for mobile or temporary connections to the university network.

However, the introduction of Wi-Fi networks (wireless networks) inevitably also covers areas that do not belong to the University of Kassel (wireless coverage extending beyond the property boundaries). Furthermore, all visitors to the university campus could use the communication capabilities of the Wi-Fi networks without authorization and without being detected. Furthermore, the security measures defined in the transmission standards for Wi-Fi networks are completely inadequate and offer neither reliable protection against unauthorized use nor against eavesdropping or tampering with communications (e.g., password theft).

To ensure the proper operation of Wi-Fi networks, the IT Service Center has implemented a VPN gateway (VPN = Virtual Private Network). This VPN gateway encrypts the wireless connection and authenticates users via their UniAccount. This ensures that only authorized and registered individuals can log in and that data is transmitted securely (encrypted).

All departments or units at the University of Kassel, as well as institutions connected to the university network that wish to operate their own wireless access points with a connection to the university network, must set up the connection and client authentication via the central VPN connection (described above). Any other mode of operation poses a significant threat to the security of the university network and all users and thus violates the university-wide mandatory Terms of Use for the Information Processing and Communications Infrastructure of the University of Kassel (IT Terms of Use).

The IT Service Center offers support in planning wireless network cells and setting up suitable access points. As a general rule, plans for Wi-Fi connections should be coordinated in advance with the Data and Telecommunications Department at the IT Service Center (appropriate devices, VLAN-capable connection, unnecessary redundancies with existing or planned access points, and the like). Unless products from the same manufacturer as the access points installed by the IT Service Center (currently the LANCOM series from LANCOM Systems) are used, the selection of equipment (various VPN options, support for centralized management, etc.) must also be coordinated with the IT Service Center in advance. The ITS is responsible for setting up the access points.