Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Need some wireless recommendations
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
Spawn of Lovechild
Apprentice
Apprentice


Joined: 03 Feb 2004
Posts: 253
Location: Århus, Denmark

PostPosted: Thu Mar 11, 2004 12:40 pm    Post subject: Need some wireless recommendations Reply with quote

Since I just moved to an apartment with my gf I've been wanting to setup a wireless network to share our 100Mbit internet connection - but since I never worked with wireless technology before I wanted to ask some advice first.

I need to a wireless router, a PCMCIA card and a PCI card - for price efficiency I figured I would go for 54Mbit technology.

This is what I've been looking at

Router:
http://www.giga-byte.com/Communication/Products/Products_Wireless_GN-B49G.htm
or
http://www.netgear.co.uk/html/prod_wireless_802_11_g_wgr614.htm

PCMCIA card:
http://www.netgear.com/products/prod_details.php?prodID=120

PCI card:
http://www.netgear.co.uk/html/prod_wireless_802_11_g.htm#wg511
or
http://www.netgear.com/products/prod_details.php?prodID=212

I'm slighty worried about security on such an open setup, other than that I need the PCI card to have a Linux driver (the PCMCIA card is for a Windows XP laptop so that should just work out of the box).
_________________
Proud to be a 22 year old Infidel, GNOME lover and member of LIK.
Back to top
View user's profile Send private message
nielchiano
Veteran
Veteran


Joined: 11 Nov 2003
Posts: 1287
Location: 50N 3E

PostPosted: Thu Mar 11, 2004 1:21 pm    Post subject: Reply with quote

Some toughts: if you go wireless, don't expect to get much more than 20Mbps real speed... the 802.11g standard does indeed give 54Mbps, but that's raw, without all overhead and wireless handshaking.

As you said, as soon as you go wireless, you have an open network. However if you configuer it well it can get better:

  • Don't transmit the SSID. This is an information a client NEEDS to know to log on. Setting this option will make the access point (router) not broadcast it. A hacker can however still sniff the air and grab the SSID when one of your clients log on.
  • switch to a non-default channel. This will not help much... but it might stop the interference from neighbouring WLANS
  • {I can't believe I have to say this} CHANGE THE DEFAULT PASSWORD of your router to something difficult
  • add WEP. This gives an additional layer of security. To be realy sure it works, you need to change (automaticaly or manualy) the WEP key daily. By just sniffing a busy-WEP-WLAN you can distillate the WEP key in about a week.


Those are specific WLAN items. you can also add VPN support and other kinds of encryption.

about the hardware: Sorry, i don't know enough about them to give good advice
Back to top
View user's profile Send private message
viperlin
Veteran
Veteran


Joined: 15 Apr 2003
Posts: 1319
Location: UK

PostPosted: Thu Mar 25, 2004 2:00 am    Post subject: Reply with quote

for an accesspoint i got a Netgear WG602 v2, it has some interface bugs so i can only change certain things with IE :-( but other than that it's great with WPA support too.

For a Card get an Orinoco chipset card, they are the best and easyest to work with.

Security:
Enable Mac Address Filtering.

Enable WPA (Connection denied unless correct password is specified, this can be stored on the laptop so i just ran /dev/urandom into hexdump, added some capitals and had a nice long 30 char password (i think it can take something like 86 characters). That will keep people out of the network.

Enable WEP to prevent info being intercepted.

Broadcasting SSID will not matter with WPA enabled, feel free to broadcast a cool'ly named SSID, mine is Rlyeh from Midian Mythology.

Have Wireless Fun! if your paranoid put the AP in a DMZ, and for jebus's sake change the password!!!
Back to top
View user's profile Send private message
MacMasta
Guru
Guru


Joined: 18 Apr 2002
Posts: 545
Location: Anchorage, AK

PostPosted: Thu Mar 25, 2004 2:22 am    Post subject: Reply with quote

Remember that WEP is only trustworthy if you can guarantee that nobody will be able to sniff much data; it's weak against large-dataset attacks, so breaking it isn't that terribly fast.

And IPSec is your friend...get happy with ssh tunnels, and you're as secure as can be.


~Mac~
Back to top
View user's profile Send private message
viperlin
Veteran
Veteran


Joined: 15 Apr 2003
Posts: 1319
Location: UK

PostPosted: Thu Mar 25, 2004 9:59 am    Post subject: Reply with quote

the probability of me generating enough IV WEP packets is a bit incorrect for just a 1 person user, that would take months to crack with the amount of traffic i use (occasionally slashdot, mainly used for instant messaging, it's a 233Mhz laptop.....)

today i hope to be placing the accesspoint in a DMZ, with a port 22 pinhole to my main PC and my server, therefor the only connections allowed to my LAN are port 22's :-)
Back to top
View user's profile Send private message
Sir_Chancealot
n00b
n00b


Joined: 08 Jan 2004
Posts: 63

PostPosted: Fri Mar 26, 2004 3:00 am    Post subject: Reply with quote

Go with the Netgear. I haven't used the wireless features, but I have put enough of them in for people to know that they are the best quality at the price you are looking at. I actually have some Netgear Firewalls running at some business sites. Believe it or not, one site switched out from a PIX firewall because of the issues we were having. The Netgear firewall I currently used has been on continiously for about 90 days now (battery backup! :) ), and I haven't had any problems.

I cannot say enough good things about Netgear when you don't want to spend large amounts of money.

Whatever you do, DO NOT buy D-Link or Linksys, because I have had nothing but trouble from them (and I've put in a LOT of low-cost routers/firewalls for smaller clients).

Oh, one other thing. Don't try and complicate your network by adding a DMZ. I thoroughly explained why a DMZ doesn't offer that much more protection for the type of setup that you have in another thread, so I will only repeat a very small portion of it here. Suffice it to say that if you need to access the server setting in the DMZ from behind the firewall, it's much better to just put it behind the firewall, and use port-forwarding to the server.

I've installed 4 Netgear router/firewalls recently, and there hasn't been one complaint.
Back to top
View user's profile Send private message
xmit
Apprentice
Apprentice


Joined: 02 Apr 2003
Posts: 158
Location: Hamburg, Germany

PostPosted: Sat Mar 27, 2004 9:43 am    Post subject: Reply with quote

I highly recommend the Linksys WRT54G. It is open source and linux based. There is already a lot modified firmware around with added features and security. Feel free to make your own, you have the full control. The WRT54G is cheap, works (at least for me) and it is fun.

The manufacturer:
http://www.linksys.com/products/product.asp?grid=33&scid=35&prid=601
Modified firmware:
http://www4.ncsu.edu/~bdferris/linksys_wrt54g/index.html
Some good information, probably good frimware but no longer for free:
http://www.sveasoft.com/modules/phpBB2/index.php
Even a litte distribution:
http://www.batbox.org/wrt54g-linux.html
The firmware I actually prefer:
http://h.vu.wifi-box.net/

Do you really want a closed source router and firewall?! :wink:

Concerning Cardbus (PCMCIA) I recommend an intersil prism54 based device, e.g. a Netgear WG511 (not WG511T!). Because these chips actually have the best linux support. http://www.prism54.org/, especially http://www.prism54.org/supported_cards.php
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum