Jump to content

Securing my wireless network


Chris
 Share

Recommended Posts

I want [after a year] to secure my wireless network so that only the computers I want can have access to the internet and my network.

I have the Netgear DG834G router and have my Desktop connected via the LAN. My Laptop is connected on the Wifi [Centrino].

I've just setup Wireless Station Access List* which seemed simple enough.

Hower I also want some form of encryption over the wireless. To which I seem to have three options available:

Which one do you think?

*By default, any wireless PC that is configured with the correct SSID will be allowed access to your wireless network. For increased security, you can restrict access to the wireless network to only allow specific PCs based on their MAC addresses. From the Wireless Settings menu, click the Setup Access List button to display the Wireless Station Access List menu.

Link to comment
Share on other sites

I want [after a year] to secure my wireless network so that only the computers I want  can have access to the internet and my network.

I have the Netgear DG834G router and have my Desktop connected via the LAN. My Laptop is connected on the Wifi [Centrino].

I've just setup Wireless Station Access List* which seemed simple enough.

Hower I also want some form of encryption over the wireless. To which I seem to have three options available:

Which one do you think?

*By default, any wireless PC that is configured with the correct SSID will be allowed access to your wireless network. For increased security, you can restrict access to the wireless network to only allow specific PCs based on their MAC addresses. From the Wireless Settings menu, click the Setup Access List button to display the Wireless Station Access List menu.

WEP

Link to comment
Share on other sites

Hmmm I'v read the opposite, WPA is better? :(

EDIT: Doh it's right there on the router setup pages:

WEP - WEP (Wired Equivalent Privacy), if used, encrypts data before transmission. This provides greater security and privacy. All Wireless Stations need to use the same settings (WEP Key size and WEP key).

WPA-PSK - This version of WPA uses a PSK (Pre-shared Key) for authentication, so you don't need a Radius Server. All Wireless stations need to use the same PSK (Pre-shared Key). Data transmissions are encrypted using a 256 Bit key derived from the PSK. This key changes regularly, providing greater protection. WPA is more secure than WEP, and should be used if possible.

EDIT: WPA is not supported on the b centrino?

EDIT: 128bit, WEP'ed...

Link to comment
Share on other sites

Turn off "broadcast SSID" If that option is avaliable.( Mines a Belkin)

It is possible to make your wireless network nearly invisible. By turning off the broadcast of the SSID, your network will not appear in a site survey. Site Survey is a feature of many wireless network adapters on the market today. It will scan the "air" for any available network and allow the computer to select the network from the site survey. Turning off the broadcast of the SSID will help increase security.
Link to comment
Share on other sites

Turning of SSID can cause more problems than it solves. It does nothing for security. Tools like Kismet can detect cloaked SSIDs. In general cloaking your SSID is not worth the grief. Use WEP with the longest key it supports (usually 128 or better)

Heres the crunch, is there anyone else local to you with a wifi network? If so, and they have SSID activated your network will ALWAYS try to login into that network. Its what wifi does, it searches out SSID. Leave SSID active.

Link to comment
Share on other sites

Mine works fine with SSID off Spikeychris. No offence but surely it's better not to "advertise" what you have as it will invite intrusions? I'm unaware whether my neighbours have a network, so I couldn't comment on that.

One thing I'd like to say in general is the lack of instructions that came with my router to make it secure was disgusting:( A quick set-up guide and away you go.

Link to comment
Share on other sites

Bear in mind that WEP can be cracked with free utilities available on the Internet. It takes some time, but can be done.

On Corporate Networks, wireless connections are often treated as untrusted, and are only given access to a VPN/Firewall device. They can only access the internal network after authenticating with a VPN connection.

It wouldn't be too expensive to set up at home, using not as sophisticated equipment, I don't think, if you want me to look into that option.

Make sure you're running software firewalls on all wireless PC's.

You may also be able to set up MAC Address Filtering, where only MAC Addresses you've entered are allowed to connect.

Sorry I didn't respond sooner! Been very busy at work.

Sincerely,

Link to comment
Share on other sites

Bear in mind that WEP can be cracked with free utilities available on the Internet.  It takes some time, but can be done.

On Corporate Networks, wireless connections are often treated as untrusted, and are only given access to a VPN/Firewall device.  They can only access the internal network after authenticating with a VPN connection.

It wouldn't be too expensive to set up at home, using not as sophisticated equipment, I don't think, if you want me to look into that option.

Make sure you're running software firewalls on all wireless PC's. 

You may also be able to set up MAC Address Filtering, where only MAC Addresses you've entered are allowed to connect. 

Sorry I didn't respond sooner!  Been very busy at work.

Sincerely,

MAC filtering was done first...

VPN....well no i'm not that desperate :lol:

Link to comment
Share on other sites

How could I take offence Bluecow its nice talking to you, and you have a valid point. If you are offered that choice in the setup menu it would seem the sensible thing to do but I personally don't like it. M$ don't recommend it either. I have tried it in the past and the problems it caused were horrendous.

Chris

Good link Chris :thumbup: Do you know what the manufacturs of routers reccomend out of interest????

Link to comment
Share on other sites

Well, Microsft reckon that you should follow the below....

• Use access points only rather than ad-hoc, peer-to-peer networks

• Change the default SSID to something more obscure. Don't use a name that identifies your organisation

• If possible and if your access point allows it, restrict wireless access to normal office hours

• Use MAC filtering. Each network card has a unique code called a MAC address. You can set access points to restrict access to certain, trusted MAC addresses

• Switch on and use the built-in encryption to prevent eavesdropping

• Restrict the ability of users (and network administrators) to set up 'quick and dirty' wireless networks, even temporarily. One rogue access point can undo all the good work you do on the others

• Make sure all your other security measures - passwords etc. - are in place so that you have a second line of defence against intruders

You have a Belkin, is it 802.11g? if so your SSID will be 'belkin54g' Thats the first thing I would change.

Link to comment
Share on other sites

Lot's of info about wireless! The convenience comes at pretty great cost, which most people aren't aware of. I'm glad people here are doing whatever's possible to secure it. :)

With free utilities like NetStumbler (I won't provide a link, but you can track it down if you're interested), and AirCrack (again, track it down yourself if interested), unencrypted traffic between computers can be observed, and any traffic should be treated as suspect.

The VPN idea might not be to practical for home use, especially since you probably want the PC's to talk to each other via their wireless connections.

If I find more info on securing home wireless I'll post here too. All great stuff from the WindowsForum community. :)

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy