Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.internet.wireless
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 11-24-2007, 07:03 PM
Les Cargill
Guest
 
Posts: n/a
Default WRT54G questions


Is it sufficient to use the option "Permit only PCs listed to access the
wireless network"* to restrict access to my wireless router, or should I
be turning the wireless interface off when not in use?

*in the web-based management client.

This option appears to use a positive file of MAC addresses, and
only those will get a link.

I've also turned off SSID broadcast, am using WPA2 Personal/AES .
"Personal" looks like it means "don't rely on a RADIUS
server." Yes?

Application is a very simple home network.

Not trying to be paranoid, just cautious.

--
Les Cargill

Reply With Quote
  #2 (permalink)  
Old 11-24-2007, 08:56 PM
Bob Willard
Guest
 
Posts: n/a
Default Re: WRT54G questions

Les Cargill wrote:

>
> Is it sufficient to use the option "Permit only PCs listed to access the
> wireless network"* to restrict access to my wireless router, or should I
> be turning the wireless interface off when not in use?
>
> *in the web-based management client.
>
> This option appears to use a positive file of MAC addresses, and
> only those will get a link.
>
> I've also turned off SSID broadcast, am using WPA2 Personal/AES .
> "Personal" looks like it means "don't rely on a RADIUS
> server." Yes?
>
> Application is a very simple home network.
>
> Not trying to be paranoid, just cautious.
>
> --
> Les Cargill


The most important thing you can do to "secure" a wireless LAN is to
enable WPA (not WEP) on the router and on the clients; and, to use
a long, non-obvious, shared key. If you are particularly sensitive,
you may want to change the key monthly (or daily or hourly or ...);
changing the key is a PITA, proportional to the number of stations
(router & wireless PCs) you have.

Permit only PC listed helps a bit, but since a perp can easily
duplicate the MAC of one of your allowed PCs, that doen't do much.

Turning off SSID broadcasts doesn't add much security, and will cause
some problems when your clients go up&down. The SSID can be captured
even if not broadcast.

Turning off the wireless side of your router is, IMHO, extreme. I don't
have much faith in PC software to recover properly from being turned
off&on, or from having its link-partner coming&going.
--
Cheers, Bob

Reply With Quote
  #3 (permalink)  
Old 11-24-2007, 09:51 PM
Les Cargill
Guest
 
Posts: n/a
Default Re: WRT54G questions

Bob Willard wrote:
> Les Cargill wrote:
>
>>
>> Is it sufficient to use the option "Permit only PCs listed to access
>> the wireless network"* to restrict access to my wireless router, or
>> should I be turning the wireless interface off when not in use?
>>
>> *in the web-based management client.
>>
>> This option appears to use a positive file of MAC addresses, and
>> only those will get a link.
>>
>> I've also turned off SSID broadcast, am using WPA2 Personal/AES .
>> "Personal" looks like it means "don't rely on a RADIUS
>> server." Yes?
>>
>> Application is a very simple home network.
>>
>> Not trying to be paranoid, just cautious.
>>
>> --
>> Les Cargill

>
> The most important thing you can do to "secure" a wireless LAN is to
> enable WPA (not WEP) on the router and on the clients; and, to use
> a long, non-obvious, shared key. If you are particularly sensitive,


Nah :) Just a bit new to 802.11 and trying to research best
practices.... a foreign node showed up while I was initially
configuring the wireless router.

> you may want to change the key monthly (or daily or hourly or ...);


The present key reminds me a CHAP challenge string. Is there a reference
for this?

The WRT54G supports having a new node "learn" by plugging in wired, so
it's not too much of a hardship.

> changing the key is a PITA, proportional to the number of stations
> (router & wireless PCs) you have.
>
> Permit only PC listed helps a bit, but since a perp can easily
> duplicate the MAC of one of your allowed PCs, that doen't do much.
>
> Turning off SSID broadcasts doesn't add much security, and will cause
> some problems when your clients go up&down. The SSID can be captured
> even if not broadcast.
>


Fair enough.

> Turning off the wireless side of your router is, IMHO, extreme. I don't
> have much faith in PC software to recover properly from being turned
> off&on, or from having its link-partner coming&going.


Good to know. Thanks, Bob.

--
Les Cargill

Reply With Quote
  #4 (permalink)  
Old 11-25-2007, 12:56 AM
Adair Winter
Guest
 
Posts: n/a
Default Re: WRT54G questions

HAHALOL I guess no one told you how to flip the internet switch?
I guess not.. sucks for you.. maybe one day you will be kind enough to ASK
your neighbor if you can use his internet OR buy your own.]

Adair

"Les Cargill" <lcargill@cfl.rr.com> wrote in message
news:474875a1$0$16511$4c368faf@roadrunner.com...
>
> Is it sufficient to use the option "Permit only PCs listed to access the
> wireless network"* to restrict access to my wireless router, or should I
> be turning the wireless interface off when not in use?
>
> *in the web-based management client.
>
> This option appears to use a positive file of MAC addresses, and
> only those will get a link.
>
> I've also turned off SSID broadcast, am using WPA2 Personal/AES .
> "Personal" looks like it means "don't rely on a RADIUS
> server." Yes?
>
> Application is a very simple home network.
>
> Not trying to be paranoid, just cautious.
>
> --
> Les Cargill




Reply With Quote
  #5 (permalink)  
Old 11-25-2007, 02:15 AM
Les Cargill
Guest
 
Posts: n/a
Default Re: WRT54G questions

Adair Winter wrote:
> HAHALOL I guess no one told you how to flip the internet switch?


??? I'm posting this message thru the WRT54G.

> I guess not.. sucks for you.. maybe one day you will be kind enough to ASK
> your neighbor if you can use his internet OR buy your own.]
>


I have a cable modem connection that I pay for hooked to the WRT54G.
Check the path and From: on any of my messages - they all match.

> Adair
>
> "Les Cargill" <lcargill@cfl.rr.com> wrote in message
> news:474875a1$0$16511$4c368faf@roadrunner.com...
>> Is it sufficient to use the option "Permit only PCs listed to access the
>> wireless network"* to restrict access to my wireless router, or should I
>> be turning the wireless interface off when not in use?
>>
>> *in the web-based management client.
>>
>> This option appears to use a positive file of MAC addresses, and
>> only those will get a link.
>>
>> I've also turned off SSID broadcast, am using WPA2 Personal/AES .
>> "Personal" looks like it means "don't rely on a RADIUS
>> server." Yes?
>>
>> Application is a very simple home network.
>>
>> Not trying to be paranoid, just cautious.
>>
>> --
>> Les Cargill

>
>


--
Les Cargill

Reply With Quote
  #6 (permalink)  
Old 11-25-2007, 01:59 PM
Adair Winter
Guest
 
Posts: n/a
Default Re: WRT54G questions

How foolish of me. That post was meant for the thread above this one with
the subject "wireless help".
Sorry.

Adair

"Les Cargill" <lcargill@cfl.rr.com> wrote in message
news:4748dadc$0$2357$4c368faf@roadrunner.com...
> Adair Winter wrote:
>> HAHALOL I guess no one told you how to flip the internet switch?

>
> ??? I'm posting this message thru the WRT54G.
>
>> I guess not.. sucks for you.. maybe one day you will be kind enough to
>> ASK your neighbor if you can use his internet OR buy your own.]
>>

>
> I have a cable modem connection that I pay for hooked to the WRT54G. Check
> the path and From: on any of my messages - they all match.
>
>> Adair
>>
>> "Les Cargill" <lcargill@cfl.rr.com> wrote in message
>> news:474875a1$0$16511$4c368faf@roadrunner.com...
>>> Is it sufficient to use the option "Permit only PCs listed to access the
>>> wireless network"* to restrict access to my wireless router, or should I
>>> be turning the wireless interface off when not in use?
>>>
>>> *in the web-based management client.
>>>
>>> This option appears to use a positive file of MAC addresses, and
>>> only those will get a link.
>>>
>>> I've also turned off SSID broadcast, am using WPA2 Personal/AES .
>>> "Personal" looks like it means "don't rely on a RADIUS
>>> server." Yes?
>>>
>>> Application is a very simple home network.
>>>
>>> Not trying to be paranoid, just cautious.
>>>
>>> --
>>> Les Cargill

>>
>>

>
> --
> Les Cargill




Reply With Quote
  #7 (permalink)  
Old 11-25-2007, 02:10 PM
Les Cargill
Guest
 
Posts: n/a
Default Re: WRT54G questions

Adair Winter wrote:
> How foolish of me. That post was meant for the thread above this one with
> the subject "wireless help".
> Sorry.
>
> Adair
>


ROFL! No problem. I had actually wondered if that had happened.


> "Les Cargill" <lcargill@cfl.rr.com> wrote in message
> news:4748dadc$0$2357$4c368faf@roadrunner.com...
>> Adair Winter wrote:
>>> HAHALOL I guess no one told you how to flip the internet switch?

>> ??? I'm posting this message thru the WRT54G.
>>
>>> I guess not.. sucks for you.. maybe one day you will be kind enough to
>>> ASK your neighbor if you can use his internet OR buy your own.]
>>>

>> I have a cable modem connection that I pay for hooked to the WRT54G. Check
>> the path and From: on any of my messages - they all match.
>>
>>> Adair
>>>
>>> "Les Cargill" <lcargill@cfl.rr.com> wrote in message
>>> news:474875a1$0$16511$4c368faf@roadrunner.com...
>>>> Is it sufficient to use the option "Permit only PCs listed to access the
>>>> wireless network"* to restrict access to my wireless router, or should I
>>>> be turning the wireless interface off when not in use?
>>>>
>>>> *in the web-based management client.
>>>>
>>>> This option appears to use a positive file of MAC addresses, and
>>>> only those will get a link.
>>>>
>>>> I've also turned off SSID broadcast, am using WPA2 Personal/AES .
>>>> "Personal" looks like it means "don't rely on a RADIUS
>>>> server." Yes?
>>>>
>>>> Application is a very simple home network.
>>>>
>>>> Not trying to be paranoid, just cautious.
>>>>
>>>> --
>>>> Les Cargill
>>>

>> --
>> Les Cargill

>
>


--
Les Cargill

Reply With Quote
Sponsored Links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Wrt54G questions laptopman1984 Wireless Networking Discussion 1 08-19-2006 09:21 AM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 10-19-2005 05:37 AM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 08-30-2005 05:26 AM
Couple Linksys WRT54G Questions for you Experts frankdowling1@yahoo.com alt.internet.wireless 10 08-26-2005 12:04 PM
REVIEW: "CISSP Practice Questions Exam Cram 2", Michael C. Gregg Robert Michael Slade alt.computer.security 0 08-22-2005 06:19 PM


All times are GMT. The time now is 07:07 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45