Click to See Complete Forum and Search --> : Bridge security


jstiltner
11-14-2002, 04:06 PM
Ok guys,
Myself and a coworker of myne have an arguement about a temporary wireless bridge that I am planning to install.
Basically he wated the screen savers and since leo and patrick said that wep wasent any good and they downed linksys stuff he thinks that there is no way to secure the link while what I am planning on is as follows

beaconing off
mac adress filter to only allow to specified MAC addresses
128 bit wep
point to point bridge mode on both ends
open system authentication
using an linksys wap11

can you tell me who is right, I am saying that this will be pretty well secure because it will not accept clients, and they would have to spoof their mac which can be done only in clients that I know of and not in bridges.

Also the screen savers told him that the reason a (example) cisco gear costs more than linksys is that they are more secure, I have attemped to tell him that brand means nothing, if it is only and access point and doesent include vpn hardware in it then it will be no more secure.

The wep key should be reletavly hard to decypher aslo, because the level of traffic on this network will be reletavly low, and moderate early in the mornings, there will be ~8 computers doing internet classes which include streaming audio over this link.

so what do you guys(and gals) think about my assesment of the situation?

tnx for any input,:D

P.S.
I work for an k-12 instution and as such am limited on funds and I dident think that ~$500 each would be nessary for the bridges and would be wasteful, This is why I selected the $119 each Linksys Wap11, This is just a temporary situation anyway

Jerry Coleman
11-14-2002, 07:53 PM
Justin,

I never said that just because it has Cisco on the case and cost more that it would be better. It's just I believe you get what you pay for. We have spent a huge amount of money to get our network as secure as it is now and I have spent a LOT of sleepless nights planning and installing all of it. To place a wireless anything on the same network that could possibly touch the computer that prints my paycheck makes me feel uneasy.


What I want to do is place the wireless network on the outside of our firewall and let you go to town. On this side, I really don't care what happens because all of our servers live in our trusted zone.

Just by having a firewall don't make us 100% secure from the creatures that lurk in the night. I realize this, but having wireless anything on a PRIVATE network is just plain crazy.

I'm okay with the idea of having wireless within our network. just not the trusted zone.

don't have a cow man. We both can have the best of both worlds. ;)

Jerry Coleman
Network Administrator
Buchanan County Public Schools

WiFiNERD
11-25-2002, 11:46 AM
If the clients only need to access each other then there is no need to plug it in to the network. If there is a need for the wirelss clients to access the internet then build a linux distro firewall (www.freesco.org or www.ipcop.org or even http://www.zelow.no/floppyfw/) and place that between the wap11 and the network. I agree with your co-worker (Jerry?) that it is a bad idea to place wireless anything on a wired network no matter the security measures you've taken. If you read the other threads you can still pickup the SSID Broadcast while a client is associating. The 128bit encryption is fine but if you've taken all the other measures of security is there really a need to slow it down too? 64bit is more than enough when you are using a MAC filter and no broadcast. These are my thoughts in a nutshell.