10 ways to wireless security

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

8. Isolate the wireless network from the rest of the LAN
To protect your wired internal network from threats coming over the wireless network, create a wireless DMZ or perimeter network that's isolated from the LAN. That means placing a firewall between the wireless network and the LAN. Then you can require that in order for any wireless client to access resources on the internal network, he or she will have to authenticate with a remote access server and/or use a VPN. This provides an extra layer of protection.

9. Control the wireless signal
The typical 802.11b WAP transmits up to about 300 feet. However, this range can be extended by a more sensitive antenna. By attaching a high gain external antenna to your WAP, you can get a longer reach but this may expose you to war drivers and others outside your building. A directional antenna will transmit the signal in a particular direction, instead of in a circle like the omnidirectional antenna that usually comes built into the WAP. Thus, through antenna selection you can control both the signal range and its direction to help protect from outsiders. In addition, some WAPs allow you to adjust signal strength and direction via their settings.

10. Transmit on a different frequency
One way to "hide" from hackers who use the more common 802.11b/g wireless technology is to go with 802.11a instead. Since it operates on a different frequency (the 5 GHz range, as opposed to the 2.4 GHz range in which b/g operate), NICs made for the more common wireless technologies won't pick up its signals. Sure, this is a type of "security through obscurity" — but it's perfectly valid when used in conjunction with other security measures. After all, security through obscurity is exactly what we advocate when we tell people not to let others know their social security numbers and other identification information.

A drawback of 802.11a, and one of the reasons it's less popular than b/g, is that the range is shorter: about half the distance of b/g. It also has difficulty penetrating walls and obstacles. From a security standpoint, this "disadvantage" is actually an advantage, as it makes it more difficult for an outsider to intercept the signal even with equipment designed for the technology.

Talkback

Another option that people should consider is to provide an additional open unencrypted free access to the internet. Restrict the access to LAN resources by providing an additional authentication step. If necessary, restrict the bandwith allocated to the free access so as not to degrade the other users access.

Someone who is trying to access "your network" is probably simply trying to get an internet connection. So simply make it easy for them to get one. Most likely they will then be happy and not spend days trying to break through your security... at which point they would have full access to all your sensitive information.

via Facebook 3 October, 2005 10:05
Reply

Providing an additional unsecured Wi-Fi access to the internet might stop casual intruders. Maybe a corporation with a huge amount of bandwidth could spare a little to support such an approach but what of the small business or home user? Do you really have bandwidth to spare? Do you trust strangers to share your connection? In an age of cyberterrorism, internet fraud, spam and paedophilia do you really want to allow others to use your bandwidth for their unapproved and possibly nefarious activities? I don't... I certainly don't want the police turning up on my doorstep having determined my WAN IP address is linked to crimes. I don't want to explain 'it wasn't me' as someone dismantles my PC. I enjoy the benefits of wireless access but I want the exclusivity of Ethernet. It's my bandwidth, mine all mine.

via Facebook 3 October, 2005 14:45
Reply

Hi,
I regard myself as tolerably PC literate and act as the PC 'help desk' for my village. In your opening line you state state 'wireless networking is easy to set up'. I agree. However, I suggest you should have then said setting up wireless security is a nightmare and takes us back to the worst days of poor instructions and indecipherable geeky words. There is no common methodology for setting up security. If you get it wrong it can be incredibly difficult to go back and start again because you cannot get the laptop to talk to the router to make the changes. OK, I hear you say connect via an ethernet/USB cable, Where does it tell you to do this - usually by thought transfer or similar.
My advice to most people is enable wirelss securituy at your peril. It might work for a while then you go out log on to somewhere else and guess what, you get home and you cannot log on no matter what you do unless you remove all security and start again.
I would plead for a real campaign to make the wireless router companies write user 'wizards' which hide all the geeky stuff and make it simple to set up. Llike you I do believe it is necessary to enable security. However, for the moment in our quiet rural village its open house for wirelss users.
Simon
scwyatt@tiscali.co.uk

via Facebook 7 October, 2005 11:26
Reply

I agree with 'Anonymous iTV Consultant' completely. I have a wireless network at home with 3 devices on it, which was an absolute doddle to set-up.

Then came the security configuration and despite being very PC literate I couldn't even begin to configure the security because whatever I tried effectively 'broke' the wireless connection.

I PM website production and if a site is unusable by Joe Public you can bet that it's a resounding failure, so I'd very much like someone to tell me why PC software companies get away with building unusable rubbish that seems designed specifically to leave security holes through the average user not being able to configure it.

via Facebook 18 October, 2005 14:20
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

5 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

13 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

14 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

15 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

17 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

19 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

20 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

20 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

20 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

22 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

23 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

1 day ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint