Jump to content

Recommended Posts

Posted

I wondered what everyone is doing to make sure their wireless networks are reliable and secure? Any preferences for b/g or a? Anyone using IAS and a PKI based RADIUS setup????

 

Alternatively, any trustes suppliers/installers of wireless networks?

Posted

WEP is pointless. As is MAC filtering. At a minimum use WPA. If your buying new kit look for WPA2.

 

On the infrastructure end, if you have W2k3 then you can do everything there. Check out the whitepapers on the microsoft site. Otherwise consider recycling an old box as a Linux solution.

Guest metalmonkey
Posted

I disagree with Geoff on the comment about MAC filtering being pointless. We've had unsecured 11mb wireless for years in certain areas and have now moved to 54mb secured. When we started setting it up about 5 months ago, we planned for full security + encryption.

 

However, following many, oh so many hours of hair pulling, screaming, shouting and crying, we found the only solution that suited us was for MAC filtering.

 

The biggest problem we found was our laptop rebuild turn around, along with user profiles. Our teachers laptops are RM notebooks but non-RM CC3 and we found the WPA and WEP security settings would often lose the security keys. Combined with us applying the right security key (quite litterally 3 people watching one person push a key every 3 seconds or so, confirming we entered it correctly) but the thing wouldn't accept it. After we gave up for the evening and left it, we came in the next morning to find it had suddenly gained access. (we arn't using cheap stuff either. We use HP gear)

 

We also find that because teachers want to take laptops home, use home internet ect, it is our policy to have a domain profile and a local profile with linked/shared My Docs. Setting the keys twice per laptop, per user was just plain annoying and time consuming, especially for our staff when they already have domain access on their desktops so we'd have to change their passwords to setup their profile with the correct key.

 

I'm sure there are ways around these issues I've listed, we found Mac filtering the best solution, as we no longer have to worry about security. We just use a bar code reader to enter the Mac address into the WAP's (though I admit, there are lots to do, but nothing copy and paste can't help with) when the laptops are purchased.

 

My suggestion is to try them all and see what you prefer.

Posted
Another problem whic is rapidly gaining in frequency is the sheer bloody-mindedness of some wi-fi chipsets in wanting to communicate with other manufacturers kit. I am seeing on almost a weekly basis now visitors trying in vain to join out wi-fi setup which uses WEP (unless someone is willing to sit outside your office all day capturing packets I wouldn't worry to much about security fears! I have 3 different manufacturers base-stations just to ensure some connectivity for them in the event of faffage (v. to faff).
Posted
Some interesting opinions. Has anyone actually set up the Microsoft reccomended methode using IAS as a RADIUS server with certificates for authentication? I downloaded a mountain of documentation from MS, but never found the time to read it.
Posted
I guess I must have it easy, because all of this is overkill at my school. The walls are so thick that the radius is neglible, and on top of that, if you don't know the proxy address, you can't get on the network anyway. Am I being naive, or are you all being over cautious?
Posted
Well ive got a bunch of Cisco kit, and so far it works with everything ive thrown at it, as for WPA, i have had the whole system running WPA with PEAP (via a RADIUS server) and it was totally seamless, the only downside being the client must have a cert before it can join the network, but i use group policy to deploy them at the end of a RIS. Sadly, not all my gear is 11g yet so i had to stop dreaming and turn off WPA for now, and am running unsecured at the moment
Posted

wireless? whats that?

 

lol ;)

 

seriously tho, currently no demand for wireless here, but will mac filter when the time comes as there wont be many laptops/desktops attached wirelessly and the locals would know how to packet capture, let alone do anything with the packets so that aint a prob :D

 

cheers

N.

Posted

also good idea is fit timer sockets on the boxes so that they go off at night and in hols.....

 

We have got wireless with wep and mac filtering but next week hopfuly going to look into securing it more befor going live to the laptops..

 

russ

Posted

You can ipconfig /setclassid to set machines to a certain ID I believe. If you did this with your current machines with a startup script then left some kind of dummy scope for the ones not set.

All off the top of my head btw so may not all be true :D

Posted
I disagree with Geoff on the comment about MAC filtering being pointless.

 

It takes about 5 seconds to dump traffic from an active AP and observe an 'authorised' MAC address. Windows generally doesn't offer the flexiblity to change you MAC address on the fly (some cards allow it via their drivers) but Linux, BSD, Mac OS X would not blink at such a request.

 

Even more depressing, with a correctly configured Linux machine a malicious user can pretend to be the AP.

 

wi-fi setup which uses WEP (unless someone is willing to sit outside your office all day capturing packets I wouldn't worry to much about security fears!)

 

Try running Wepcrack or Airsnort against your AP's and see how long they last.

  • 1 month later...
Posted

Hi can i recommend very highly hp procurve kit including there power over ethernet kit we have been running it for about a year now. Hp is basically cheap cisco kit from what i can see, there networking kit for wired is great as well check it out.

We also use 3 com kit as its very easy to configure and was in place before i arrived. The other kit for a good price that i would recommend is linksys which i use myself at home and is great kit for a great price.

For protection well i use WPA-PSK TKIP which does the job for me but just remember this

 

'no matter how secure you think something is the is always away around it all we/you can do it reduce the risk'

 

this applys to anything not just wireless.

 

NuttyGeek

Posted

@Gecko: It's surpising how many people will happily sit next to a data point using their laptop over a wireless connection.

 

What's less surprising is the number of people that complain about speed issues while performing the above. ;)

Posted

@ Ric :

 

It's funny how they complain about the speed but I wonder how much they contribute towards the costs of the IT equipment so considering they are pretty much getting it for free I dont quite understand why they complain :-S

 

Did I miss something ?

Posted

You could turn off the wireless access point and make people use cables. However, that kind of defeats the push for mobility (the new buzzword of course). I think that wireless offers great promise but as with everything is more marketing than reality.

 

At our school we use wireless. At least I think we do- not many teachers use it at all, and those that do get such a weak signal that it isn't worth sniffing at. So we have this tension between the perceived need for more mobility and the security and performance issues that wireless brings to the table.

 

Sometimes it isn't just a perceived need for mobility either. We have a trolley of laptops (wireless) and the freedom this kind of thing brings is amazing for both students and staff. Without this wireless solution, our main tower block would cost us more to cable and get ready for ethernet than it would to allow a wireless connection for two or three lessons a week!

 

Just my 2p.

 

Paul

Posted

with mobility also comes risks as I am sure you all already know , because then things tend to go for a walk abouts putting it mildy aka getting stolen :)

 

So saying security issues is not just related to people getting a hold of sensitive data either :p

 

I guess at the end of the day it all depends on what is more important and weighing up the pro's and cons of the "Mobility" and figuring out which is more important :)

Posted

In education Gecko, it is the integration of IT and curriculum that is important and delivering that in a way that meets the needs of both students and staff. So, that being the case, yes you have to weigh up security and cost with flexible IT provision, but you also have to consider this alongside educational requirement.

 

In our case mobility hasn't led to lack of security necessarily. Lack of security led to stolen laptops. That's because when people speak of "mobility" they are really talking about data that travels with you- freedom to access your information wherever you are. Apparently some schools do this via PDAs. Same thing. Mobility.

 

So- what's more important is education- after all, that's what I think I am here to support. The technology has to fit the educational needs of the school. How I deliver this is probably up for debate, but in the end the solution offered despite its inherent security concerns, works for the students and makes life for staff easier when they need to teach a lesson in IT in a location that doesn't allow for a wired connection.

 

Paul

  • 2 weeks later...
Posted

It takes about 5 seconds to dump traffic from an active AP and observe an 'authorised' MAC address. Windows generally doesn't offer the flexiblity to change you MAC address on the fly (some cards allow it via their drivers) but Linux, BSD, Mac OS X would not blink at such a request.

 

Even more depressing, with a correctly configured Linux machine a malicious user can pretend to be the AP.

 

I couldn't agree more. Most people are surprised how far away signals can be picked up. We use WPA-PSK at the moment. WPA-PSK has been broken to some degree, but it's still "strong enough". I'd like to move to something centrally managed if possible, partly to make life easier and partly because pre-shared keys are intrinsically Bad.

Posted

here we had a test access poibt mainly to do some research ino how many would need and where.

 

BECTA is starting to say that wireless should not replace wired n/w but enhance it and you should cover at leeast 50% of school.

 

when we do it it will be done via linux box acting security server

 

 

Russ

Posted

We have been banging our heads on this one for a while. Until July everything was kushti. We hadn't bothered about channels used WEP encription and were having no problems, Oh happy days.

 

Since September oh and moving from a linux server to Win server 2003 things just havn't been right. The Access points keep dropping out and trying to get more than 10 laptops logged on in a class is impossible.

 

We had hoped to have over 100 Laptops in use across the school most of them are gathering dust.

 

Be careful with HP procurve 420 ours needed 4 firmware upgrades before it did what the book in the box said it would do

 

By the way this teacher does know how to plug in a USB mouse but knows when he is beat and when to ask friends for their help

 

theshirt

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...