Enterprise Network Architecture for Wireless VPN Tunneling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise networks face challenges in securely managing access to network applications and services, particularly in restricting unauthorized access while allowing limited access to unauthenticated users, especially in large-scale environments with numerous remote sites.
Innovation Solution
The implementation of a centralized enterprise network architecture that includes a central site with a termination device managing a restricted network segment and remote sites with authorized and unauthorized access WLANs, utilizing GRE-over-IP tunneling to segregate and secure communications, with a database mapping wireless communication devices to VLANs and tunnels, allowing only authorized devices to access the restricted network segment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized security policy management is implemented across multiple remote sites, then security control and access restriction are improved, but network infrastructure complexity and deployment difficulty increase
Solution Approach 1:
The network is segmented into virtual LANs (VLANs) that are mapped to specific tunnels, creating distinct security zones. Each remote site is divided into authorized and unauthorized access WLANs, allowing granular security control without increasing overall system complexity. The segmentation enables centralized management of security policies across distributed locations.
Solution Approach 2:
A centralized database serves as an intermediary between wireless communication devices and the network infrastructure. This database stores mapping information between devices, WLANs, VLANs, and tunnels, automatically routing traffic according to security policies without requiring complex local configuration at each remote site.
2Reliability
If unauthorized users are completely restricted from accessing the enterprise network, then network security is improved, but legitimate guest access requirements are not met
Solution Approach 1:
Different quality of service and access rights are assigned to different WLANs within the same physical network. Authorized access WLANs provide full network access while unauthorized access WLANs provide limited internet-only access. This local differentiation allows simultaneous coexistence of secure internal network access and flexible guest access without compromising overall security.
Solution Approach 2:
The network traffic is segmented into different virtual LANs based on user authorization status. Unauthorized users are confined to a separate VLAN that provides internet access but is isolated from the internal enterprise network, while authorized users access a different VLAN with full network privileges.
3Ease of operation
If IP routing is implemented at each remote site to handle broadcast/multicast communications, then communication functionality is improved, but device complexity and processing overhead increase
Solution Approach 1:
The centralized database automatically handles broadcast and multicast communication routing by maintaining mapping information between WLANs, VLANs, and tunnels. Remote site devices do not need to perform complex routing decisions; instead, the system self-manages traffic distribution based on pre-configured mappings, reducing processing overhead at remote locations.
Data Source
AI summary
An enterprise network is provided which includes a central site, a network and a remote site communicatively coupled to the central site over the network. The central site includes a first termination device in communication with a restricted network segment including at least one server. The remote site includes an infrastructure device, an authorized access wireless local area network (WLAN), and an unauthorized access WLAN. The infrastructure device comprises a second termination device which communicates with the first termination device over the network. The authorized access WLAN allow communications with the central site via the second termination device over a tunnel coupling the first termination device to the second termination device, whereas the unauthorized access WLAN allows communications with the network via the second termination device.


