|
Wireless Network Security Fundamentals
Q: What is Infrastructure Mode?
A: Infrastructure Mode is where wireless clients (computers)
talk to each other via an Access Point (like a wireless router). This
is as opposed to AdHoc Mode where clients (computers) talk to each other
directly (there is no device between them like a wireless router).
Q: What is Ad Hoc Mode?
A: An ad-hoc network is where all the wireless clients talk
directly to each other. This is as opposed to Infrastructure Mode where
clients talk to each other through an Access Point
Is your wireless network secure? The current generation of wireless
products provide several network security features, however, they
require specific action on your part for implementation. All of
the steps below should be followed to ensure wireless network security.
If your hardware does not support any one of the following settings
you should strongly consider an upgrade to one that does.
- Change the default SSID
- Disable the SSID Broadcasting feature
- Change the default password for Administrator access
- Enable MAC Address Filtering
- Change the SSID periodically
- Enable WEP 128-bit Encryption
- Change the WEP encryption keys periodically
For information on implementing these security features refer to
the User Guide for your specific hardware or you may contact
us and we can do it for you!
Security Audit
We can perform an audit of your wireless network to see
if it is properly configured against intrusion. If it needs
to be secured we can do it for you.
Call us today to set up an appointment!
678-793-9669
|
SSID
Most wireless networking devices will give you the option of broadcasting
the SSID. While this option could be convenient for allowing friends
or customers to easily access your network, it will also allow anyone
to privately see and then log onto your wireless network (including
hackers).
So, do not broadcast the SSID. Wireless networking products
come with a default SSID set by the factory. Hackers know this and can
check it against your network even if you disable SSID broadcast.
So change your SSID to something unique and not something related to
your company or the networking products you use and turn off SSID
broadcasting. This will make it much harder to hack into your network.
Change your SSID regularly so that any hackers who have gained access
to your wireless network will have to start from the beginning in trying
to break in.
Change the Default Password to Your Wireless Device (Router or WAP)
If a hacker gets into your connection it is very easy to get into your
wireless device and modify the settings and making it easier to compromise
your network. Change the factory default password and user name.
MAC Address Filtering
Enable MAC Address filtering in your wireless access point (WAP) or
wireless Router setup. MAC Address filtering will allow you to provide
access to only those wireless nodes with certain MAC Addresses that
you designate. This makes it much harder for a hacker to access your
network with a random MAC Address.
- Obtain the MAC address of your wireless nodes (i.e. a laptop or
wireless printer)
- Put that MAC address into the WAP (or wireless Router) MAC Address
Filtering menu
- Keeps out run-of-the-mill wardrivers
Wired Equivalent Privacy (WEP)
WEP is often looked upon as a panacea for wireless security concerns.
This is overstating WEP's ability. Again, this can only provide enough
security to make a hacker's job more difficult. However, there are several
ways that WEP can be maximized:
- Use the highest level of encryption possible for your wireless
device
- Use a "Shared" Key (don't click the check box "This
key is provided for me automatically")
- Use multiple WEP keys
- Change your WEP key several times throughout the year
If you are transmitting sensitive data over your network, encryption
should be used. These security recommendations should help keep your
mind at ease while you are enjoying the most flexible and convenient
technology wireless products have to offer.
Security Audit
We can perform an audit of your wireless network to see
if it is properly configured against intrusion. If it needs
to be secured we can do it for you.
Call us today to set up an appointment!
678-793-9669
|
|