Acesess wireless configuration point

Selasa, 29 Juni 2010

There are two wireless devices, one type of wireless Access Point (AP) and a longer Wireless Cable / DSL Router. Both these devices have not functioned optimally, it arises directly curiosity to configure the AP. Models and brands of wireless devices is not mentioned, being unable fee from the vendor and allows for exploration to be accessed more easily by the existing illegal in the area around the office he .. he ..

The first configuration done to the AP, there is the password, the default password has been changed, no need to ask the previous configurator, find ways to do factory reset to default settings on google.com, can some information from the forum / mailing list, after a try finally returned to the AP configuration initial setting.

AP Interface to set the settings done by entering the IP address of the AP device through the browser, some configuration done, such as by:
  1. Adjust so that the AP can serve as a DHCP server
  2. Try features Wired Equivalent Privacy (WEP) and Wi-Fi Protected Access (WPA)
  3. Regulate access based on who accessed the device MAC Address
  4. etc.
Several configurations are made is not working properly, for example, even though the DHCP server has been set, the AP does not provide IP in accordance with the allocation specified.

Firmware Upgade
Typically such devices have firmware AP will provide a firmware upgrade to make improvements, even with firmware upgrades will be no additional or new functions. Simply search for the latest firmware for the AP in the vendor website. Apparently there have been several releases of the old firmware on the AP, download the latest firmware version. Download the firmware is in the form of executable file, run the file and decompresses it will generate the README file and firmware updates.

the upgrade process can be done easily, which is done directly through a browser, enter the firmware update file, then click sumbit, in less than one minute upgrade process is completed and the new firmware directly attached. Reset to default factory settings in accordance Vendor recommendations in the README file.

Firmware upgrade gives very satisfactory results, ie the DHCP server is working properly and providing additional facilities / new wireless device now functions into three types:
  1. Access Point (default functionality)
  2. Client Bridge Mode
  3. Repeater Mode
AP and Computer Server
Today the AP has been functioning well and properly, then there is a desire to set up a computer to be used as a server that will provide functionality for:
  1. User management
  2. Access Management
  3. Proxy and Firewall
  4. Authentication management
  5. Recording the log / history access
  6. Provide billing feature

wireless security


Wireless network or a wireless network is often referred to as fairly easy to set up, and also feels very comfortable, especially if we want to be able to walk way around the home or office with a portable computer but still could still access the internet network. However, since the wave of wireless use, it will be easier to hack into than wired connections. There are a few tips here to secure the wireless network.

The following steps steps

1. Using Encryption.

Encryption is the first security measure, but many wireless access points (WAPs) do not use encryption as a default. Although many WAP has Wired Equivalent Privacy (WEP) protocol, but not enabled by default. WEP does have some holes in securitynya, and an experienced hacker would be able to open it, but it's still better than no encryption at all. Be sure to set the WEP authentication method to "shared key" rather than "open system". To "open system", he did not encrypt data, but only authenticate the client. Change the WEP key as often as possible, and use 128-bit WEP compared with the 40-bit.

2. Use Strong Encryption.
Because of the weakness of the existing weaknesses in WEP, then it is advisable to use a Wi-Fi Protected Access (WPA) as well. To use WPA, WAP had to the support. The client side must also be able to support WPA .

3. Change the Default Administrator Password.
Many plants now use the same password for all administrative WAP their products. The default password is usually already known to the hackers, which can be used to change the settings on your WAP. The first thing that must be done in the WAP configuration is changing the default password TSB. Use at least eight characters, any combination of letters and numbers, and do not use the word of words in the dictionary.


4. Turn off SSID Broadcasting.

Service Set Identifier (SSID) is the name of our wireless network. By default, the SSID of the WAP will be in the broadcast. This will make users easy to find these networks, because the SSID will appear in the list of available wireless networks that exist on the client. If the SSID is turned off, users must know the SSID of his first bit can be connected with the network.


5. Turn off When Not Used WAP.
The way this one seems very simple, but few companies or individuals do it. If we have users who only connect at certain times only, there is no reason to run a wireless network at any time and provides an opportunity for intruders to carry out his evil intentions. We can turn off the access point when not in use.

6. Change the default SSID. Factories provide a default SSID.
Usefulness of the SSID broadcast is turned off to prevent anyone else know the name of our network, but if you still use the default SSID, will not be difficult for us to guess the SSID of the network.

7. Using MAC Filtering.
Most WAP (not the cheap cheap of course) will allow us to use the filter media access control (MAC). This means we can create a "white list" of computers may access the computer that our wireless network, based on the MAC or physical address of the network card in each pc. Connections from the MAC is not in the list will be rejected. This method is not always safe, because it is still possible for a hacker sniffing packets that we do transmit via the wireless network and get a valid MAC address from one user, and then used it to make a spoof. But MAC filtering will make an intruder difficulties that are still very good candidate.

8. Isolating Wireless Network from the LAN.
To protect the cable from the internal network threats coming from the wireless network, it is important to make a wireless DMZ or perimeter network is isolated from the LAN. This means installing a firewall between the wireless network and LAN. And for wireless clients that require access to the internal network, he must first authenticate to the RAS server or use VPN. This provides an extra layer for protection.

9. Wireless Signal controls.
802.11b WAP transmits waves of up to approximately 300 feet. But this distance can be added by replacing with a better antenna. By using high-gain antenna, we can get more distance. Directional antenna will transmit signals in a particular direction, and pancarannya not circular as in omnidirectional antennas that are usually found on the package setandard WAP. In addition, by selecting the appropriate antenna, we can control distance and direction signals to protect themselves from intruders. In addition, there are several settings that can be WAP signal strength and direction through the WAP config.

10. Emit waves at different frequencies.
One way to hide from hackers who often use technologies 802.11b / g is more popular is to use 802.11a. Because 802.11a works on frequencies different (ie the frequency of 5 GHz), NICs are designed for working on technology that is popular not be able to capture the signals

 
FaceBlog © Copyright 2009 NETWORK COMPUTER | Blogger XML Coded And Designed by Edo Pranata