Question:
how to secure a wireless network?
1970-01-01 00:00:00 UTC
how to secure a wireless network?
Four answers:
Prithvi
2006-04-24 15:33:48 UTC
Its Easy Follow These Steps....



Add wireless lan card to computer

Get a router

search for network in coumputer

Setup network by wizard in My Network Places

Give a Workgroup Name

Give different IP address

thats all
christyeliask
2006-04-24 12:01:35 UTC
Businesses and home users are quickly adopting wireless networking—and for good reason. Here are nine security techniques you can implement right now.





1. Control your broadcast area. Many wireless APs (access points) let you adjust the signal strength; some even let you adjust signal direction. Begin by placing your APs as far away from exterior walls and windows as possible, then play around with signal strength so you can just barely get connections near exterior walls. This isn't enough, though. Sensitive snooping equipment can pick up wireless signals from an AP at distances of several hundred feet or more. So even with optimal AP placement, the signal may leak. Keep reading.



2. Lock each AP. A lot of people don't bother changing the defaults on their APs, and maintaining the default administrator password (like admin for Linksys products) makes your system a good target. Use a strong password to protect each AP. For tips on creating substantial passwords, go to www.pcmag.com/passwords and click on Password Dos and Don'ts.



3. Ban rogue access points. If an AP is connected to your home or office network, make sure you or the network administrator put it there. Bob in Accounting isn't likely to secure his rogue AP before he connects it. Free software like NetStumbler (www.netstumbler.com) lets you sweep for unauthorized APs.



4. Use 128-bit WEP. Passively cracking the WEP (Wired Equivalent Privacy) security protocol is merely a nuisance to a skilled hacker using Linux freeware like AirSnort (http://airsnort.shmoo.com). Still, the protocol does at least add a layer of difficulty.



5. Use SSIDS wisely. Change the default Service Set Identifiers (SSIDs) for your APs, and don't use anything obvious like your address or company name. For corporate setups, buy APs that let you disable broadcast SSID. Intruders can use programs such as Kismet (www.kismetwireless.net) to sniff out SSIDs anyway (by observing 802.11x management frames when users associate with APs), but again, every bit of inconvenience helps.



6. Limit access rights. Chances are, not everyone in your building needs a wireless card. Once you determine who should take to the airwaves, set your APs to allow access by wireless cards with authorized MAC addresses only. Enterprising individuals can spoof MAC addresses, however, which brings us to the next tip.



7. Limit the number of user addresses. If you don't have too many users, consider limiting the maximum number of DHCP addresses the network can assign, allowing just enough to cover the users you have. Then if everyone in the group tries to connect but some can't, you know there are unauthorized log-ons.



8. Authenticate users. Install a firewall that supports VPN connectivity, and require users to log on as if they were dialing in remotely. The Linksys BEFSX41 router ($99 list) is a great choice for this. Tweak the settings to allow only the types of permissions that wireless users need.



As a side benefit, VPNs help prevent users from being fooled by malicious association attacks. In this type of assault, the perpetrator sets up a machine that pretends to be an authorized AP, in the hope that someone will be tricked into logging on. If you connect to an AP and don't get the VPN log-on prompt you expect, you know something's amiss.



9. Use RADIUS. Installing a RADIUS server provides another authentication method. The servers tend to be expensive, but there are open-source options, such as FreeRADIUS (www.freeradius.org), for UNIX-savvy administrators.
Raleigh Mark
2006-04-24 11:58:20 UTC
Follow the instructions that came with it to "Turn on WEP encryption." Basically, you will give the router a password that is only known by the computers you intend to give access to. Only computers who know the password (don't make it a default or obvious one) will be able to access the wireless network.
Haseeb Uddin
2006-04-24 05:01:16 UTC
Well there are two major ways, if you want to keep your wireless network private. First of all, add a HEX 64bit, or 128bit (recommended) key into the router. Refer to router help to enable that. Once you've done that, I advise you to restrict your IP addresses on the router.

For example, if you want to connect five computer to your wireless network, go to your DHCP server settings and decrease the IP address assigning range to 5 except 254, for example 192.168.1.2 to 192.168.1.6. This way, even if someone finds out your HEX passphrase, he/she cannot connect to your router, because an IP address to them will not be supplied by your router. Once you have done too, bind the IP addresses of your computer, with the MAC address to your LAN card. The process seems complicated, but it is not. Refer to your help of the router. It will help you go through it.


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...