36 MAC Pt. 1, R. 4.3
Wireless Access
Cite as 36 Miss. Admin. Code Pt. 1, R. 4.3
Wireless Access
A. Each agency must ensure that all Wireless Local Area Networks (WLANS) are
configured securely.
1. Authorize each type of wireless access prior to allowing such connections by
establishing and maintaining a secure configuration process for network
devices such as the access point and switches supporting the wireless access.
2. Protect wireless access using secure network management (TLS, SSH) and
communication protocols (WPA2 and WPA3).
3. Utilize the Advanced Encryption Standard (AES) for wireless access.
4. Each agency must ensure that their wireless deployment encryption keys are
rotated regularly and frequently (at least every 6 months). Further, all
encryption keys should be changed if wireless access must be revoked (such
as after termination or transfer of an employee).
5. ITS recommends disabling wireless access on devices that do not have a
business purpose for wireless access.
6. ITS recommends disabling peer-to-peer wireless network capabilities on
wireless clients.
7. ITS recommends configuring wireless access on client machines that do have
an essential wireless business purpose, to allow access only to authorized
wireless networks and to restrict access to other wireless networks.
8. ITS recommends ensuring that wireless networks use authentication protocols
such as Extensible Authentication Protocol-Transport Layer Security
(EAP/TLS) to provide credential protection and mutual authentication.
9. ITS recommends disabling wireless peripheral access of devices (such as
Bluetooth), unless such access is required for a documented business need.
B. Each agency must ensure that guest/public users are not permitted access to the state
network resources.
1. Agencies wishing to provide Internet access to a guest user must utilize one of
the following approved methods:
i.
Installing separate equipment and a separate circuit for guest users.
Contact ITS for more information on this method of connectivity.
ii.
Tunneling guest user traffic to an ITS DMZ via a wireless controller
solution implemented by ITS. Contact ITS for more information on
this method of connectivity.
2. Both methods require:
i.
No ports opened inbound to guest users.
ii.
All guest user traffic must be filtered.