Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Home wireless network without WEP???
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
stgreek
Apprentice
Apprentice


Joined: 18 Jan 2004
Posts: 155
Location: Guildford, UK

PostPosted: Fri Mar 26, 2004 7:08 pm    Post subject: Home wireless network without WEP??? Reply with quote

Hi. I am setting up my home network, consisting of two thinkpads and a desktop. As we all know, wifi and linux don't like each other and I've been having a lot of problems trying to set up my minipci cards for WEP. Now I know that a few people in my block have wifi nets ( I pick up 3 apart from mine) so I wanted to ask the following question:

How secure will my home network be without WEP? My SSID has been set to not broadcast from day 1, so I want to know if there is a way for people to scan and find my network.

Thanks
_________________
The day Microsoft makes something that doesn't suck is probably the day that they start making vacuum cleaners
Back to top
View user's profile Send private message
UberLord
Retired Dev
Retired Dev


Joined: 18 Sep 2003
Posts: 6835
Location: Blighty

PostPosted: Fri Mar 26, 2004 7:24 pm    Post subject: Reply with quote

If you install MAC filtering on the AP then they can't access your network resources but they can sniff the data going wirelessly.
_________________
Use dhcpcd for all your automated network configuration needs
Use dhcpcd-ui (GTK+/Qt) as your System Tray Network tool
Back to top
View user's profile Send private message
echo6
Guru
Guru


Joined: 04 Jan 2003
Posts: 587

PostPosted: Fri Mar 26, 2004 9:29 pm    Post subject: Reply with quote

IMHO wireless is horrendously insecure. Don't put anything on the wireless network that is sensitive. If you can enable WEP do so, frequently change the keys (a pain I know but necessary if you want some security). MAC filter where ever you can, but don't rely upon it for security. Even MACs can be spoofed! Use RARP if you can. Setup the wireless network in a "DMZ", put the access point outside of the firewall of your own LAN and appropriately manage the firewall to the internet. Be mindful of the capability of a wireless user on your WLAN, e.g.if they get access and use your WLAN for illicit purposes who gets the blame?
Back to top
View user's profile Send private message
flybynite
l33t
l33t


Joined: 06 Dec 2002
Posts: 620

PostPosted: Sat Mar 27, 2004 6:45 am    Post subject: Reply with quote

Any wep can be cracked, mac filtering is easily spoofed... What I would do is use a VPN such as freeswan/openswan. You can then only allow encrypted traffic on the wireless portion of your network to enter you lan/wan. Works with windows too....

Nate Carlson has a howto, but it's not plug n play....

http://www.natecarlson.com/linux/ipsec-x509.php#wireless
Back to top
View user's profile Send private message
ZeNTuRe
n00b
n00b


Joined: 24 Jan 2004
Posts: 69

PostPosted: Sat Mar 27, 2004 7:16 am    Post subject: Reply with quote

Make an IPsec tunn and restrict MACs, so they can only sniff encrypted packets.
_________________
Did they touch God or did they touch the Sun?
Back to top
View user's profile Send private message
stgreek
Apprentice
Apprentice


Joined: 18 Jan 2004
Posts: 155
Location: Guildford, UK

PostPosted: Sat Mar 27, 2004 11:20 am    Post subject: Reply with quote

First of all, thanks for all the replies. I am a complete noob when it comes to networking, so please bear with me.

I will try mac filtering for the network, but echo6's idea looks a little difficult for me to implement. Now, I will not be using any of my computers as any kind of server, so could you please tell me how to add a few rules to iptables to make them a bit more secure from intruders? I have never used iptables, and I have all the default options check on 2.6.3 kernel. Thanks a lot for your help.

Stavros
_________________
The day Microsoft makes something that doesn't suck is probably the day that they start making vacuum cleaners
Back to top
View user's profile Send private message
echo6
Guru
Guru


Joined: 04 Jan 2003
Posts: 587

PostPosted: Sat Mar 27, 2004 12:46 pm    Post subject: Reply with quote

stgreek wrote:
echo6's idea looks a little difficult for me to implement.
LOL..actually IPSec and VPN is probably harder, having just taken a look at the how to etc. I would seriously consider installing Smoothwall on an old computer www.smoothwall.org then configure your network around that.

What wireless equipment have you got, what connection have you got to the internet? What do you want to access from the notebooks? Are you looking at file printer sharing or just simple access to the internet?
Back to top
View user's profile Send private message
stgreek
Apprentice
Apprentice


Joined: 18 Jan 2004
Posts: 155
Location: Guildford, UK

PostPosted: Sat Mar 27, 2004 3:07 pm    Post subject: Reply with quote

Using a separate machine is unfortunately not possible. Also, I cannot directly connect a computer to the modem due to space, which is why I have the wi-fi setup. I am mainly interested in accessing the internet from all of them, and also being able to read/write files from the desktop harddrive from all the linux machines. Each machine has its own printer, so printing is not a concern.

My equipment:

D-Link DI-614+ wireless router (600/128 Cable line)
Shuttle SN45G SFF PC with internal crappy usb prism2.5 wi-fi card
Thinkpad T23 with D-Link 650+ (gf, running win2k, just needs internet access and no sharing)
Thinkpad X31 with internal Mini-Pci Cisco 350 (also have a spare Agere minipci, don't know if it works though)
Thinkpad X23 with PCMCIA Cisco 340

The idea is that I mainly use the desktop for things like dvd/cd/tv-ripping, graphics/animation design, bittorent and then move the files to the laptops for post-processing/viewing.

Any help will be much appreciated
_________________
The day Microsoft makes something that doesn't suck is probably the day that they start making vacuum cleaners
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum