Bring Your Own Device
Scalable wireless network solution for financial services company

THE challenge...
Our client is a global financial group which has recently grown through the acquisition of several wealth management organisations. Their requirement was for a solution which could support both corporate and privately-owned Wi-Fi devices across all of their UK offices using the existing Cisco Unified Wireless Network infrastructure. In addition to this a key business requirements was for low administrational overhead.
CACI delivered a scalable wireless network solution design that met all of our customer’s business requirements. The solution allows employees to self-register multiple Wi-Fi devices for Internet access, including those of contractors and guests. This flexible approach is delivered whilst maintaining a high level of network security and regulatory risk mitigation.
The solution...
There are several aspects to delivering a BYOD solution that is highly secure yet also offers minimal administration. CACI were met with a number of challenges throughout the duration of this project, including;
- Geographically diverse office locations;
- Disparate Wireless Network infrastructure management platforms;
- Establishing effective security policies for several types of users and devices;
- Securely transporting guest traffic across the corporate LAN and WAN to a DMZ;
- Enabling a logging and audit solution which meets regulatory risk requirements.
- The strategy proposed and adopted by the business was for all Wi-Fi devices to be provided with Internet access only. Â This approach allowed CACI to successfully navigate challenges and meet the project objectives.Â
The key elements of the solution were as follows:
- Two wireless network SSIDs:
- Automatically delivered WLAN profiles for EAP-TLS authentication of managed devices
- Web-login using printed account details and instructions for unmanaged devices
- All WLAN traffic is securely tunnelled to a DMZ area using anchor WLAN controllers;
- New web-proxy service allowing greater scalability and improved logging;
- Redesign of URL filtering and firewall rules for Wi-Fi clients;
- Cisco Access Control System v5.3 for 802.1X authentication of wireless clients using EAP-TLS;
- MobileIron MDM solution for mobile device WLAN profile and SCEP certificate delivery;
- Entrust Public Key Infrastructure (Certificate Authority);
- Cisco Guest NAC Server used for hotspot account sponsorship by all UK business divisions;
- All Wi-Fi support provided via Intranet support site, with link for hotspot account self-service;
- Branded support site, user instructions and hotspot web-login;
- Trusted certificates used by web-login hosts to avoid untrusted certificate errors for web browsers.


