Go Back   Wireless and Wifi Forums > Other Networking > Security
Register FAQ Forum Rules Members List Calendar Search Today's Posts Advertise Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-06-2007, 08:39 AM
Junior Member
 
Join Date: Jul 2007
Posts: 3
Default Hotspot Security?

hi everyone.
here's my first question. any help would be appreciated.

i have had to implement a wireless hotspot in my friends hotel a month or two before i planned. obviously, this hasn't allowed me the time to study up on the security of the hotspot.

the equipment we are using is:

AP's are colubris cn3200 with cn320 for repeaters
switches are dell powerconnects 2724's which are managed
router is draytek 2950 (their latest enterprise class)

access required is:

1. secure encrypted access for hotel lan & staff. easily implemented with mac & wpa. this goes to vlan1 which allows access to the hotels private lan and internet

2. guest access to just the internet. again, it is easily implemented using dhcp and a https logon with no mac or wep/wpa encryption. this goes to vlan2 which only allows access to the internet.

all of the above clients cannot talk to each other and can only talk to the access point itself. all AP's are firewalled.

the question then......
am i as secure as i can be?
Reply With Quote
  #2 (permalink)  
Old 03-21-2008, 09:36 AM
Member
 
Join Date: Mar 2008
Posts: 31
Default

Hotspot Safety for Business Users

We illustrated five common-sense steps that anyone can take to defeat most Wi-Fi hotspot threats. Unfortunately, many users still insist on skinny-dipping in shark-infested hotspot waters. The only reliable way for employers to manage associated business risk is to define, monitor, and enforce hotspot acceptable use policies.

Something old, something new
Many companies have policies governing secure remote access to corporate networks. Those policies and related countermeasures are an excellent starting point for securing business hotspot use. However, they must be extended to deal with risks unique to Wi-Fi.

Before Wi-Fi, remote workers used dial-up or broadband to reach corporate networks. Because those links connected business assets to the public Internet, measures were needed to deflect unsolicited inbound traffic and ensure data confidentiality. As a result, many workers are now required to use anti-virus, personal firewall, and a VPN tunnel when connecting from afar. ......
Wifi pune, Wi-fi Pune, Pune Unwire - Hotspot Safety for Business Users


Thanks
Reply With Quote
  #3 (permalink)  
Old 02-21-2009, 10:37 PM
Junior Member
 
Join Date: Feb 2009
Posts: 10
Default

The WPA2 AES network for the hotel staff should be WPA2 Enterprise that implements a FreeRadius server - it can better withstand a bruteforce attack. It is the most secure way to prevent intrusions. Also, the freeradius server can also act as an authentication server for LAN clients as well (if you don't have a Domain server with Radius authentication).

In addition, you can have your Workstations VPN over LAN to an OpenVPN server (on LAN) so that all traffic is encrypted across the network if you don't have DES ethernet security. You also want encryption for your guest clients connections so they can securely browse the Internet - also use Radius and provide a system that will generate keys for the duration of the guest's visit - WPA encrypts the Data and not just the connection.

Also, find some way of detecting Jasager Fon networks that can do session Hijacking. You don't want your guests to be preyed upon by a malicious guest or employee that uses Web Browser session hijacking to get personal login information - and yes SSL/TLS certificates can be spoofed and many people will accept an invalid certificate. It is very easy for a hacker to grap info with a Jasager Router and a 3G mobile phone/laptop card. Radius Security for guests is half the work.
http://www.digininja.org/jasager/

You can also get a Napera Switch. It has many security features like Windows NAP verfication, and has some of the best enterprise Radius security.
Napera N24 Appliance - Secure Network Access Protection

Last edited by pender; 02-21-2009 at 10:51 PM..
Reply With Quote
  #4 (permalink)  
Old 11-18-2009, 10:58 AM
Junior Member
 
Join Date: Nov 2009
Location: Manchester, UK
Posts: 11
Cool

Hi,

Thanks for sharing the cool link.
The website has a fresh appearance and it appealed to me.
Just read the article and it really is interesting.

Keep sharing such cool links and information.

Regards
Ben Thomas
__________________
Business Telephone Systems
Reply With Quote
  #5 (permalink)  
Old 12-31-2009, 02:23 PM
Junior Member
 
Join Date: Dec 2009
Posts: 3
Default Hotspot Security?

Try a personal vpn using tcp port 443. It works most but not all of the time. If it works then it will continue to work and won't get blocked as the traffic looks like SSL traffic on port 443 which is legitimate.........








_____________
Tweak Change Windows 7 logon screen
Reply With Quote
  #6 (permalink)  
Old 02-19-2010, 03:22 PM
Junior Member
 
Join Date: Feb 2010
Location: U.K
Posts: 11
Default

Many consumers realize that hotspots can be risky, but fail to take even the most basic precautions. Why? Some underestimate the dangers, while others lack the financial and IT support enjoyed by corporate users. Fortunately, anyone can protect himself or herself by taking a few simple, cost-free steps. To look steps for Hotsspot Security
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Vulnerability in ... Security Alert comp.security.misc 0 01-26-2007 10:40 AM
Corrupt NTFS filesystem Citizen Bob alt.comp.hardware 144 11-11-2006 07:38 PM
FBI Monitoring Your Computer And Reading Material re. Patriot Act tightwad alt.computer.security 2 11-08-2005 09:21 AM
The Sidewinder G2 Security Appliance includes the only firewall that has never had a CERT advisory posted against it Ipeefreely alt.computer.security 5 10-08-2005 09:15 PM
Call For Chapter - Book in Enterprise IT Security : Invitation for chapter proposal Francine HERRMANN comp.security.misc 0 08-29-2005 05:00 PM


All times are GMT. The time now is 02:38 AM.



Powered by vBulletin® Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 PL2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45