Re: WLAN in a secure SME environment

From: Ansgar -59cobalt- Wiechers (bugtraq_at_planetcobalt.net)
Date: 11/04/04

  • Next message: Randy Golly: "RE: Security job for IT professional"
    Date: Thu, 4 Nov 2004 15:08:40 +0100
    To: security-basics@securityfocus.com
    
    

    On 2004-11-03 Shaineel Singh wrote:
    > I am in the process of providing a solution for an SME that currently
    > employs both wired and wireless clients. I can provide rudimentary
    > security for the WLAN by hardcoding MAC addresses on the AP and
    > disabling DHCP amongst other methods.
    >
    > My question to the list is this, besides making sure that very little
    > information is sent via cleartext in wireless mode to circumvent
    > wireless sniffing, etc. what sorts of methods could I use to
    > effectively segregate the WLAN and LAN? We are talking about a M$
    > environment with winXP being the operating system on most laptops and
    > workstations. Would it be easier to just have a VPN setup when clients
    > are forced to use wireless as their access method?

    A VPN over the WLAN and separation of wired and wireless network
    segments with a filtering router between them is the *only* way to a
    secure WLAN.

    Regards
    Ansgar Wiechers

    -- 
    "Those who would give up liberty for a little temporary safety
    deserve neither liberty nor safety, and will lose both."
    --Benjamin Franklin
    

  • Next message: Randy Golly: "RE: Security job for IT professional"

    Relevant Pages

    • Re: 169 IP conflict on wireless!
      ... but software upgrades and future WLAN features are mentioned ... accessing it from a wireless device. ... Have you used the web browser interface to complete a router setup? ... on a wired connection you should be able to connect to it by typing ...
      (microsoft.public.windows.vista.networking_sharing)
    • Sonicwall TZW questions
      ... My basic setup is that LAN and WLAN (wireless LAN) users will be able to ... Only company PCs are on the LAN, but the WLAN is public and is accessible by ... Is this a bug in the TZW? ... When WGS is turned on (and I have at least one WGS ...
      (comp.security.firewalls)
    • Re: Completely OT, but need help!
      ... If I ask Vista to diagnose the problem it tells me that the WLAN is ... the latest WLAN drivers from Medion's web-site - but when I try to ... I regularly have wireless problems. ... It is probably a good idea to download the most up to date wireless driver ...
      (uk.legal)
    • Re: Doesnt anyone Know anything about roaming?
      ... I assume you use WZC on the Windows XP clients (and not a third party WLAN ... Then the selection of the SSID is done by WZC, ... make sure everything you buy conforms to the dominant wireless ... >> you can mix brands, operating systems, even network a Mac to a Windows PC ...
      (microsoft.public.internet.radius)
    • [Full-Disclosure] Re: (AUSCERT AA-2004.02) AUSCERT Advisory - Denial of Service Vulnerability
      ... problem, which affects almost every network as Ethernet, WLAN, but also ... > PDA and a commonly available wireless networking card may cause ... > that makes identification and localisation of the attacker difficult. ...
      (Full-Disclosure)

  • Quantcast