How to protect a wireless connection from unauthorized access

Here are the basic rules for protecting a wireless network.

Follow FullPress on Google

Add us to your preferred sources.

Follow this source on Google

– Always keep in mind that a wireless network is by its very nature always interceptable and vulnerable. The radio waves emitted by your antennas are broadcast into the ether and can reach anywhere, even where we wouldn’t want them to. Never feel 100% safe; a security system considered impregnable today might be compromised tomorrow. – Turn off the ADSL Wireless Router or Access Point when not in use: regardless of whether it is protected or not, you will avoid leaving it exposed to malicious actors even when you are not using it. Some devices, though unfortunately not all, also have the capability to limit connections by time slots, so you could restrict access only during working hours. Moreover, on many Access Points it is possible to set the transmission power. Reduce it to the minimum possible, thereby limiting the operational range only to what is indispensable. If you manage to lower the power without harming wireless network performance, you will avoid further unauthorized connections. – Disable SSID broadcast: this way you will avoid occasional connections from those within your network range. Of course, your clients must have first set and saved a default connection with the Access Point’s name (i.e., the SSID), otherwise even they will no longer be able to connect. – Change the access password to your Access Point’s administrative panel. Many new devices have a default password known by various attack tools, or even disabled by default. This is to prevent intruders from accessing the administrative panel. – Enable MAC address filtering for wireless cards connecting to the network. Each wireless card tags the packets transmitted in the ether with a unique code identifying the card itself, which is detected by the access point and can be managed to grant or deny connection to various clients. However, be careful not to consider yourself safe just because this list is set; the MAC Address can be easily spoofed with some IT knowledge, so an intruder could break into your network simply by masquerading and gain system access. – Disable the DHCP server on the Access Point (or Wireless Router) and change the device’s default IP address; in fact, change the addressing throughout your local network if possible, and in the network settings of the PCs that need to connect, enter the data manually. The DHCP server is the mechanism that automatically assigns IPs to all connected computers. While convenient for you, it’s also convenient for anyone wanting to connect illicitly. For static IP configuration on the entire local network, use addresses like 10.0.0.0 with netmask 255.0.0.0 to make it as difficult as possible to find the correct IPs. – Install a hardware firewall that allows, among other functions, granular control over all network traffic, and can notify you by email via alerts (for example, Zyxel ZyWALL 5 UTM, though there are many others). If you have little money to spend and an old PC to repurpose, you could install a Linux distribution made specifically to create a powerful firewall. Two distributions I can recommend are IPCOP (available at www.ipcop.org) and Endian Firewall (available at www.efw.it). Once installed and configured to your needs, one of these operating systems will transform your PC into a powerful and versatile firewall. Between the two, Endian Firewall, while free software, is commercially supported by the producing company (which is located in the province of Bolzano) and offers professional product support. – Activate encryption systems. Current systems are WEP, WPA, and WPA2. These systems rely on shared keys that must be set both on the Access Point (and naturally also on the Wireless Router) and on the client PC. Avoid WEP (Wired Equivalent Protocol) carefully; it is the oldest system and has already been cracked. WPA (Wi-Fi Protected Access) is a transitional protocol, introduced to remedy vulnerabilities of the previous one, based on a subset of the 802.11i specifications and sharing the RC4 encryption algorithm with WEP. For home or small office use, WPA-PSK is implemented. The recommended choice, provided all network devices support it, is WPA2. It is the most recent chronologically, specifically developed to provide a security layer for communications based on the 802.11 standard, and uses the AES cryptographic algorithm, which stands for Advanced Encryption Standard. Always remember to set the longest and most complicated encryption key possible, including special and unusual characters.

Pubblicato in

Se vuoi rimanere aggiornato su How to protect a wireless connection from unauthorized access iscriviti alla nostra newsletter settimanale

Be the first to comment

Leave a Reply

Your email address will not be published.


*