ajbritton Posted August 5, 2005 Posted August 5, 2005 I wondered what everyone is doing to make sure their wireless networks are reliable and secure? Any preferences for b/g or a? Anyone using IAS and a PKI based RADIUS setup???? Alternatively, any trustes suppliers/installers of wireless networks?
Geoff Posted August 5, 2005 Posted August 5, 2005 WEP is pointless. As is MAC filtering. At a minimum use WPA. If your buying new kit look for WPA2. On the infrastructure end, if you have W2k3 then you can do everything there. Check out the whitepapers on the microsoft site. Otherwise consider recycling an old box as a Linux solution.
Guest metalmonkey Posted August 6, 2005 Posted August 6, 2005 I disagree with Geoff on the comment about MAC filtering being pointless. We've had unsecured 11mb wireless for years in certain areas and have now moved to 54mb secured. When we started setting it up about 5 months ago, we planned for full security + encryption. However, following many, oh so many hours of hair pulling, screaming, shouting and crying, we found the only solution that suited us was for MAC filtering. The biggest problem we found was our laptop rebuild turn around, along with user profiles. Our teachers laptops are RM notebooks but non-RM CC3 and we found the WPA and WEP security settings would often lose the security keys. Combined with us applying the right security key (quite litterally 3 people watching one person push a key every 3 seconds or so, confirming we entered it correctly) but the thing wouldn't accept it. After we gave up for the evening and left it, we came in the next morning to find it had suddenly gained access. (we arn't using cheap stuff either. We use HP gear) We also find that because teachers want to take laptops home, use home internet ect, it is our policy to have a domain profile and a local profile with linked/shared My Docs. Setting the keys twice per laptop, per user was just plain annoying and time consuming, especially for our staff when they already have domain access on their desktops so we'd have to change their passwords to setup their profile with the correct key. I'm sure there are ways around these issues I've listed, we found Mac filtering the best solution, as we no longer have to worry about security. We just use a bar code reader to enter the Mac address into the WAP's (though I admit, there are lots to do, but nothing copy and paste can't help with) when the laptops are purchased. My suggestion is to try them all and see what you prefer.
Dos_Box Posted August 6, 2005 Posted August 6, 2005 Another problem whic is rapidly gaining in frequency is the sheer bloody-mindedness of some wi-fi chipsets in wanting to communicate with other manufacturers kit. I am seeing on almost a weekly basis now visitors trying in vain to join out wi-fi setup which uses WEP (unless someone is willing to sit outside your office all day capturing packets I wouldn't worry to much about security fears! I have 3 different manufacturers base-stations just to ensure some connectivity for them in the event of faffage (v. to faff).
ajbritton Posted August 6, 2005 Author Posted August 6, 2005 Some interesting opinions. Has anyone actually set up the Microsoft reccomended methode using IAS as a RADIUS server with certificates for authentication? I downloaded a mountain of documentation from MS, but never found the time to read it.
StewartKnight Posted August 7, 2005 Posted August 7, 2005 I guess I must have it easy, because all of this is overkill at my school. The walls are so thick that the radius is neglible, and on top of that, if you don't know the proxy address, you can't get on the network anyway. Am I being naive, or are you all being over cautious?
E1uSiV3 Posted August 8, 2005 Posted August 8, 2005 Well ive got a bunch of Cisco kit, and so far it works with everything ive thrown at it, as for WPA, i have had the whole system running WPA with PEAP (via a RADIUS server) and it was totally seamless, the only downside being the client must have a cert before it can join the network, but i use group policy to deploy them at the end of a RIS. Sadly, not all my gear is 11g yet so i had to stop dreaming and turn off WPA for now, and am running unsecured at the moment
tarquel Posted August 15, 2005 Posted August 15, 2005 wireless? whats that? lol seriously tho, currently no demand for wireless here, but will mac filter when the time comes as there wont be many laptops/desktops attached wirelessly and the locals would know how to packet capture, let alone do anything with the packets so that aint a prob cheers N.
russdev Posted August 15, 2005 Posted August 15, 2005 also good idea is fit timer sockets on the boxes so that they go off at night and in hols..... We have got wireless with wep and mac filtering but next week hopfuly going to look into securing it more befor going live to the laptops.. russ
russdev Posted August 17, 2005 Posted August 17, 2005 ok is there anyway to laptops connecting to network via wireless access point to stop it picking up ips from dhcp server... russ
ChrisH Posted August 17, 2005 Posted August 17, 2005 You can ipconfig /setclassid to set machines to a certain ID I believe. If you did this with your current machines with a startup script then left some kind of dummy scope for the ones not set. All off the top of my head btw so may not all be true
Dos_Box Posted August 17, 2005 Posted August 17, 2005 I think some AP's have facilities to block certain services working through them. I'll check my Buffalo and D-Link kit for you tomorrow.
Geoff Posted August 18, 2005 Posted August 18, 2005 I disagree with Geoff on the comment about MAC filtering being pointless. It takes about 5 seconds to dump traffic from an active AP and observe an 'authorised' MAC address. Windows generally doesn't offer the flexiblity to change you MAC address on the fly (some cards allow it via their drivers) but Linux, BSD, Mac OS X would not blink at such a request. Even more depressing, with a correctly configured Linux machine a malicious user can pretend to be the AP. wi-fi setup which uses WEP (unless someone is willing to sit outside your office all day capturing packets I wouldn't worry to much about security fears!) Try running Wepcrack or Airsnort against your AP's and see how long they last.
tarquel Posted August 22, 2005 Posted August 22, 2005 Thanks geoff - every munchkin will be breaking everyones wifi neworks now lmfao N.
nuttygeek Posted September 29, 2005 Posted September 29, 2005 Hi can i recommend very highly hp procurve kit including there power over ethernet kit we have been running it for about a year now. Hp is basically cheap cisco kit from what i can see, there networking kit for wired is great as well check it out. We also use 3 com kit as its very easy to configure and was in place before i arrived. The other kit for a good price that i would recommend is linksys which i use myself at home and is great kit for a great price. For protection well i use WPA-PSK TKIP which does the job for me but just remember this 'no matter how secure you think something is the is always away around it all we/you can do it reduce the risk' this applys to anything not just wireless. NuttyGeek
mac_shinobi Posted September 29, 2005 Posted September 29, 2005 You can have wireless but you're not having my brains !! @ "reliable and secure " -- Turn of the wireless point and make everyone use an ethernet cable
Ric_ Posted September 29, 2005 Posted September 29, 2005 @Gecko: It's surpising how many people will happily sit next to a data point using their laptop over a wireless connection. What's less surprising is the number of people that complain about speed issues while performing the above.
mac_shinobi Posted September 29, 2005 Posted September 29, 2005 @ Ric : It's funny how they complain about the speed but I wonder how much they contribute towards the costs of the IT equipment so considering they are pretty much getting it for free I dont quite understand why they complain :-S Did I miss something ?
kingswood Posted September 29, 2005 Posted September 29, 2005 You could turn off the wireless access point and make people use cables. However, that kind of defeats the push for mobility (the new buzzword of course). I think that wireless offers great promise but as with everything is more marketing than reality. At our school we use wireless. At least I think we do- not many teachers use it at all, and those that do get such a weak signal that it isn't worth sniffing at. So we have this tension between the perceived need for more mobility and the security and performance issues that wireless brings to the table. Sometimes it isn't just a perceived need for mobility either. We have a trolley of laptops (wireless) and the freedom this kind of thing brings is amazing for both students and staff. Without this wireless solution, our main tower block would cost us more to cable and get ready for ethernet than it would to allow a wireless connection for two or three lessons a week! Just my 2p. Paul
mac_shinobi Posted September 29, 2005 Posted September 29, 2005 with mobility also comes risks as I am sure you all already know , because then things tend to go for a walk abouts putting it mildy aka getting stolen So saying security issues is not just related to people getting a hold of sensitive data either I guess at the end of the day it all depends on what is more important and weighing up the pro's and cons of the "Mobility" and figuring out which is more important
kingswood Posted September 29, 2005 Posted September 29, 2005 In education Gecko, it is the integration of IT and curriculum that is important and delivering that in a way that meets the needs of both students and staff. So, that being the case, yes you have to weigh up security and cost with flexible IT provision, but you also have to consider this alongside educational requirement. In our case mobility hasn't led to lack of security necessarily. Lack of security led to stolen laptops. That's because when people speak of "mobility" they are really talking about data that travels with you- freedom to access your information wherever you are. Apparently some schools do this via PDAs. Same thing. Mobility. So- what's more important is education- after all, that's what I think I am here to support. The technology has to fit the educational needs of the school. How I deliver this is probably up for debate, but in the end the solution offered despite its inherent security concerns, works for the students and makes life for staff easier when they need to teach a lesson in IT in a location that doesn't allow for a wired connection. Paul
mac_shinobi Posted September 29, 2005 Posted September 29, 2005 So curriculum is more important then admin ? Must have something to do with 114 boxes to move lol J/K. Anyway good reply
sahmeepee Posted October 13, 2005 Posted October 13, 2005 It takes about 5 seconds to dump traffic from an active AP and observe an 'authorised' MAC address. Windows generally doesn't offer the flexiblity to change you MAC address on the fly (some cards allow it via their drivers) but Linux, BSD, Mac OS X would not blink at such a request. Even more depressing, with a correctly configured Linux machine a malicious user can pretend to be the AP. I couldn't agree more. Most people are surprised how far away signals can be picked up. We use WPA-PSK at the moment. WPA-PSK has been broken to some degree, but it's still "strong enough". I'd like to move to something centrally managed if possible, partly to make life easier and partly because pre-shared keys are intrinsically Bad.
russdev Posted October 13, 2005 Posted October 13, 2005 here we had a test access poibt mainly to do some research ino how many would need and where. BECTA is starting to say that wireless should not replace wired n/w but enhance it and you should cover at leeast 50% of school. when we do it it will be done via linux box acting security server Russ
theshirt Posted October 13, 2005 Posted October 13, 2005 We have been banging our heads on this one for a while. Until July everything was kushti. We hadn't bothered about channels used WEP encription and were having no problems, Oh happy days. Since September oh and moving from a linux server to Win server 2003 things just havn't been right. The Access points keep dropping out and trying to get more than 10 laptops logged on in a class is impossible. We had hoped to have over 100 Laptops in use across the school most of them are gathering dust. Be careful with HP procurve 420 ours needed 4 firmware upgrades before it did what the book in the box said it would do By the way this teacher does know how to plug in a USB mouse but knows when he is beat and when to ask friends for their help theshirt
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now