Networking Forums

Networking Forums > Wireless Networking > Wireless Internet > WiFi security settings

Reply
Thread Tools Display Modes

WiFi security settings

 
 
dsmcd
Guest
Posts: n/a

 
      04-02-2004, 09:36 PM
Hello...

I'm setting up a wireless network behind the firewall at
our corporate office. There's a DHCP server on the network,
so I need to be very careful with my security.

I was wondering if someone could improve on my setup.

Linksys WAP54G Access Point with...
-Non standard AP Name
-Static IP - within our private ip space (10.x.x.x)
-Non-standard SSID
-Channel 6 (default)
-SSID not broadcast
-WPA Pre-Shared Key (9 chars - upp/lower letters, and
numbers)
-TKIP
-Group Key Renewal 300 seconds (default)
-Filtering MAC addresses - only permitting known MACs

And of course a non-standard password for the web based
config utilities. Adapter cards may be a mix of
Linksys/Netgear/and whatever laptops came with. Win98/2k/XP
clients.

I'm willing to spend more money if necessary (RADIUS
server?).

Any suggestions? Any improvements?

Thx,
D.

 
Reply With Quote
 
 
 
 
Chuck
Guest
Posts: n/a

 
      04-02-2004, 10:35 PM
On Fri, 02 Apr 2004 21:36:34 GMT, dsmcd <*email_address_deleted*> wrote:

>Hello...
>
>I'm setting up a wireless network behind the firewall at
>our corporate office. There's a DHCP server on the network,
>so I need to be very careful with my security.
>
>I was wondering if someone could improve on my setup.
>
>Linksys WAP54G Access Point with...
>-Non standard AP Name
>-Static IP - within our private ip space (10.x.x.x)
>-Non-standard SSID
>-Channel 6 (default)
>-SSID not broadcast
>-WPA Pre-Shared Key (9 chars - upp/lower letters, and
>numbers)
>-TKIP
>-Group Key Renewal 300 seconds (default)
>-Filtering MAC addresses - only permitting known MACs
>
>And of course a non-standard password for the web based
>config utilities. Adapter cards may be a mix of
>Linksys/Netgear/and whatever laptops came with. Win98/2k/XP
>clients.
>
>I'm willing to spend more money if necessary (RADIUS
>server?).
>
>Any suggestions? Any improvements?
>
>Thx,
>D.


D.,

Did you disable remote management on the router (do you need to use it?)? Is
the router management password non-trivial (complex / non-guessable)? If you
need to keep remote management, I would make the password very complex, and
regularly changed.

Have you enabled the router logs? Do you have procedures to examine them
regularly?

Do you have software firewalls on the computers?

Other than that, your setup looks pretty tight to me.

Please learn to munge your email address properly, to keep yourself a bit safer
when posting to open forums. Protect yourself and the rest of the internet -
never post your address unmunged.
http://www.mailmsg.com/SPAM_munging.htm

Cheers,
Chuck
Paranoia comes from experience - and is not necessarily a bad thing.
 
Reply With Quote
 
dsmcd
Guest
Posts: n/a

 
      04-02-2004, 11:09 PM
Chuck <(E-Mail Removed)> wrote:
>On Fri, 02 Apr 2004 21:36:34 GMT, dsmcd
><*email_address_deleted*> wrote:
>
>>Hello...
>>
>>I'm setting up a wireless network behind the firewall at
>>our corporate office. There's a DHCP server on the
>>network,
>>so I need to be very careful with my security.
>>
>>I was wondering if someone could improve on my setup.
>>
>>Linksys WAP54G Access Point with...
>>-Non standard AP Name
>>-Static IP - within our private ip space (10.x.x.x)
>>-Non-standard SSID
>>-Channel 6 (default)
>>-SSID not broadcast
>>-WPA Pre-Shared Key (9 chars - upp/lower letters, and
>>numbers)
>>-TKIP
>>-Group Key Renewal 300 seconds (default)
>>-Filtering MAC addresses - only permitting known MACs
>>
>>And of course a non-standard password for the web based
>>config utilities. Adapter cards may be a mix of
>>Linksys/Netgear/and whatever laptops came with.
>>Win98/2k/XP
>>clients.
>>
>>I'm willing to spend more money if necessary (RADIUS
>>server?).
>>
>>Any suggestions? Any improvements?
>>
>>Thx,
>>D.

>
>D.,
>
>Did you disable remote management on the router (do you
>need to use it?)?


>Did you disable remote management on the router (do you
>need to use it?)?


No, and not sure.

Is
>the router management password non-trivial (complex /
>non-guessable)? If you
>need to keep remote management, I would make the password
>very complex, and
>regularly changed


Yes, and yes..
>
>Have you enabled the router logs? Do you have procedures
>to examine them
>regularly?


Yes, and yes.
>
>Do you have software firewalls on the computers?


No. We have the netscreen firewall at the wired network's
perimeter.
>
>Other than that, your setup looks pretty tight to me.


Good to hear.


>Please learn to munge your email address properly, to keep
>yourself a bit safer
>when posting to open forums.


Usually do. This time the defaults got gunged up.

Thx,
D.

 
Reply With Quote
 
Louis De Pointe Du Lac
Guest
Posts: n/a

 
      04-03-2004, 07:18 AM
if you can find out how many machines you have connected to the network,
taking advantage of the DHCP server, count them and then enter that figure
into the DHCP pool size, this stops unwanted connections. if you find after
doing that, that there is a problem, with a couple of machines or one,
connecting, just up that figure by one, till all are ok.


HTH

Louis

"dsmcd" <(E-Mail Removed)> wrote in message
news:C1lbc.60$(E-Mail Removed)...
> Hello...
>
> I'm setting up a wireless network behind the firewall at
> our corporate office. There's a DHCP server on the network,
> so I need to be very careful with my security.
>
> I was wondering if someone could improve on my setup.
>
> Linksys WAP54G Access Point with...
> -Non standard AP Name
> -Static IP - within our private ip space (10.x.x.x)
> -Non-standard SSID
> -Channel 6 (default)
> -SSID not broadcast
> -WPA Pre-Shared Key (9 chars - upp/lower letters, and
> numbers)
> -TKIP
> -Group Key Renewal 300 seconds (default)
> -Filtering MAC addresses - only permitting known MACs
>
> And of course a non-standard password for the web based
> config utilities. Adapter cards may be a mix of
> Linksys/Netgear/and whatever laptops came with. Win98/2k/XP
> clients.
>
> I'm willing to spend more money if necessary (RADIUS
> server?).
>
> Any suggestions? Any improvements?
>
> Thx,
> D.
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Settings Bill T. Wireless Networks 3 01-20-2008 01:22 PM
WLAN internet security settings Jeff Wireless Networks 4 01-06-2006 08:33 PM
Cannot access security settings in Win 2003 Mikey_N Windows Networking 13 01-29-2005 04:31 AM
Wireless security settings help Jim Wireless Networks 1 11-04-2004 08:21 PM
Wireless Security Settings Jim Wireless Networks 2 08-20-2004 03:28 AM



1 2 3 4 5 6 7 8 9 10 11