Networking Forums

Networking Forums > Wireless Networking > Wireless Internet > WRT54G questions

Reply
Thread Tools Display Modes

WRT54G questions

 
 
Les Cargill
Guest
Posts: n/a

 
      11-24-2007, 06:03 PM

Is it sufficient to use the option "Permit only PCs listed to access the
wireless network"* to restrict access to my wireless router, or should I
be turning the wireless interface off when not in use?

*in the web-based management client.

This option appears to use a positive file of MAC addresses, and
only those will get a link.

I've also turned off SSID broadcast, am using WPA2 Personal/AES .
"Personal" looks like it means "don't rely on a RADIUS
server." Yes?

Application is a very simple home network.

Not trying to be paranoid, just cautious.

--
Les Cargill
 
Reply With Quote
 
 
 
 
Bob Willard
Guest
Posts: n/a

 
      11-24-2007, 07:56 PM
Les Cargill wrote:

>
> Is it sufficient to use the option "Permit only PCs listed to access the
> wireless network"* to restrict access to my wireless router, or should I
> be turning the wireless interface off when not in use?
>
> *in the web-based management client.
>
> This option appears to use a positive file of MAC addresses, and
> only those will get a link.
>
> I've also turned off SSID broadcast, am using WPA2 Personal/AES .
> "Personal" looks like it means "don't rely on a RADIUS
> server." Yes?
>
> Application is a very simple home network.
>
> Not trying to be paranoid, just cautious.
>
> --
> Les Cargill


The most important thing you can do to "secure" a wireless LAN is to
enable WPA (not WEP) on the router and on the clients; and, to use
a long, non-obvious, shared key. If you are particularly sensitive,
you may want to change the key monthly (or daily or hourly or ...);
changing the key is a PITA, proportional to the number of stations
(router & wireless PCs) you have.

Permit only PC listed helps a bit, but since a perp can easily
duplicate the MAC of one of your allowed PCs, that doen't do much.

Turning off SSID broadcasts doesn't add much security, and will cause
some problems when your clients go up&down. The SSID can be captured
even if not broadcast.

Turning off the wireless side of your router is, IMHO, extreme. I don't
have much faith in PC software to recover properly from being turned
off&on, or from having its link-partner coming&going.
--
Cheers, Bob
 
Reply With Quote
 
Les Cargill
Guest
Posts: n/a

 
      11-24-2007, 08:51 PM
Bob Willard wrote:
> Les Cargill wrote:
>
>>
>> Is it sufficient to use the option "Permit only PCs listed to access
>> the wireless network"* to restrict access to my wireless router, or
>> should I be turning the wireless interface off when not in use?
>>
>> *in the web-based management client.
>>
>> This option appears to use a positive file of MAC addresses, and
>> only those will get a link.
>>
>> I've also turned off SSID broadcast, am using WPA2 Personal/AES .
>> "Personal" looks like it means "don't rely on a RADIUS
>> server." Yes?
>>
>> Application is a very simple home network.
>>
>> Not trying to be paranoid, just cautious.
>>
>> --
>> Les Cargill

>
> The most important thing you can do to "secure" a wireless LAN is to
> enable WPA (not WEP) on the router and on the clients; and, to use
> a long, non-obvious, shared key. If you are particularly sensitive,


Nah Just a bit new to 802.11 and trying to research best
practices.... a foreign node showed up while I was initially
configuring the wireless router.

> you may want to change the key monthly (or daily or hourly or ...);


The present key reminds me a CHAP challenge string. Is there a reference
for this?

The WRT54G supports having a new node "learn" by plugging in wired, so
it's not too much of a hardship.

> changing the key is a PITA, proportional to the number of stations
> (router & wireless PCs) you have.
>
> Permit only PC listed helps a bit, but since a perp can easily
> duplicate the MAC of one of your allowed PCs, that doen't do much.
>
> Turning off SSID broadcasts doesn't add much security, and will cause
> some problems when your clients go up&down. The SSID can be captured
> even if not broadcast.
>


Fair enough.

> Turning off the wireless side of your router is, IMHO, extreme. I don't
> have much faith in PC software to recover properly from being turned
> off&on, or from having its link-partner coming&going.


Good to know. Thanks, Bob.

--
Les Cargill
 
Reply With Quote
 
Adair Winter
Guest
Posts: n/a

 
      11-24-2007, 11:56 PM
HAHALOL I guess no one told you how to flip the internet switch?
I guess not.. sucks for you.. maybe one day you will be kind enough to ASK
your neighbor if you can use his internet OR buy your own.]

Adair

"Les Cargill" <(E-Mail Removed)> wrote in message
news:474875a1$0$16511$(E-Mail Removed)...
>
> Is it sufficient to use the option "Permit only PCs listed to access the
> wireless network"* to restrict access to my wireless router, or should I
> be turning the wireless interface off when not in use?
>
> *in the web-based management client.
>
> This option appears to use a positive file of MAC addresses, and
> only those will get a link.
>
> I've also turned off SSID broadcast, am using WPA2 Personal/AES .
> "Personal" looks like it means "don't rely on a RADIUS
> server." Yes?
>
> Application is a very simple home network.
>
> Not trying to be paranoid, just cautious.
>
> --
> Les Cargill



 
Reply With Quote
 
Les Cargill
Guest
Posts: n/a

 
      11-25-2007, 01:15 AM
Adair Winter wrote:
> HAHALOL I guess no one told you how to flip the internet switch?


??? I'm posting this message thru the WRT54G.

> I guess not.. sucks for you.. maybe one day you will be kind enough to ASK
> your neighbor if you can use his internet OR buy your own.]
>


I have a cable modem connection that I pay for hooked to the WRT54G.
Check the path and From: on any of my messages - they all match.

> Adair
>
> "Les Cargill" <(E-Mail Removed)> wrote in message
> news:474875a1$0$16511$(E-Mail Removed)...
>> Is it sufficient to use the option "Permit only PCs listed to access the
>> wireless network"* to restrict access to my wireless router, or should I
>> be turning the wireless interface off when not in use?
>>
>> *in the web-based management client.
>>
>> This option appears to use a positive file of MAC addresses, and
>> only those will get a link.
>>
>> I've also turned off SSID broadcast, am using WPA2 Personal/AES .
>> "Personal" looks like it means "don't rely on a RADIUS
>> server." Yes?
>>
>> Application is a very simple home network.
>>
>> Not trying to be paranoid, just cautious.
>>
>> --
>> Les Cargill

>
>


--
Les Cargill
 
Reply With Quote
 
Adair Winter
Guest
Posts: n/a

 
      11-25-2007, 12:59 PM
How foolish of me. That post was meant for the thread above this one with
the subject "wireless help".
Sorry.

Adair

"Les Cargill" <(E-Mail Removed)> wrote in message
news:4748dadc$0$2357$(E-Mail Removed)...
> Adair Winter wrote:
>> HAHALOL I guess no one told you how to flip the internet switch?

>
> ??? I'm posting this message thru the WRT54G.
>
>> I guess not.. sucks for you.. maybe one day you will be kind enough to
>> ASK your neighbor if you can use his internet OR buy your own.]
>>

>
> I have a cable modem connection that I pay for hooked to the WRT54G. Check
> the path and From: on any of my messages - they all match.
>
>> Adair
>>
>> "Les Cargill" <(E-Mail Removed)> wrote in message
>> news:474875a1$0$16511$(E-Mail Removed)...
>>> Is it sufficient to use the option "Permit only PCs listed to access the
>>> wireless network"* to restrict access to my wireless router, or should I
>>> be turning the wireless interface off when not in use?
>>>
>>> *in the web-based management client.
>>>
>>> This option appears to use a positive file of MAC addresses, and
>>> only those will get a link.
>>>
>>> I've also turned off SSID broadcast, am using WPA2 Personal/AES .
>>> "Personal" looks like it means "don't rely on a RADIUS
>>> server." Yes?
>>>
>>> Application is a very simple home network.
>>>
>>> Not trying to be paranoid, just cautious.
>>>
>>> --
>>> Les Cargill

>>
>>

>
> --
> Les Cargill



 
Reply With Quote
 
Les Cargill
Guest
Posts: n/a

 
      11-25-2007, 01:10 PM
Adair Winter wrote:
> How foolish of me. That post was meant for the thread above this one with
> the subject "wireless help".
> Sorry.
>
> Adair
>


ROFL! No problem. I had actually wondered if that had happened.


> "Les Cargill" <(E-Mail Removed)> wrote in message
> news:4748dadc$0$2357$(E-Mail Removed)...
>> Adair Winter wrote:
>>> HAHALOL I guess no one told you how to flip the internet switch?

>> ??? I'm posting this message thru the WRT54G.
>>
>>> I guess not.. sucks for you.. maybe one day you will be kind enough to
>>> ASK your neighbor if you can use his internet OR buy your own.]
>>>

>> I have a cable modem connection that I pay for hooked to the WRT54G. Check
>> the path and From: on any of my messages - they all match.
>>
>>> Adair
>>>
>>> "Les Cargill" <(E-Mail Removed)> wrote in message
>>> news:474875a1$0$16511$(E-Mail Removed)...
>>>> Is it sufficient to use the option "Permit only PCs listed to access the
>>>> wireless network"* to restrict access to my wireless router, or should I
>>>> be turning the wireless interface off when not in use?
>>>>
>>>> *in the web-based management client.
>>>>
>>>> This option appears to use a positive file of MAC addresses, and
>>>> only those will get a link.
>>>>
>>>> I've also turned off SSID broadcast, am using WPA2 Personal/AES .
>>>> "Personal" looks like it means "don't rely on a RADIUS
>>>> server." Yes?
>>>>
>>>> Application is a very simple home network.
>>>>
>>>> Not trying to be paranoid, just cautious.
>>>>
>>>> --
>>>> Les Cargill
>>>

>> --
>> Les Cargill

>
>


--
Les Cargill
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Couple Linksys WRT54G Questions for you Experts frankdowling1@yahoo.com Wireless Internet 10 08-26-2005 11:04 AM
Linksys WRT54G Setup And Security Questions Pitch16 Wireless Internet 1 04-03-2004 03:42 AM
2 questions about the Linksys WRT54G router operation M. B. Wireless Internet 1 02-06-2004 05:55 AM
LinkSys WRT51AB 5 GHz and WRT54G Questions Excalibur Wireless Internet 0 01-31-2004 06:58 PM
LinkSys WRT54G 54G Wireless Router Config Questions. SSeaW Wireless Internet 9 11-20-2003 04:45 AM



1 2 3 4 5 6 7 8 9 10 11