Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 21 guests and 2 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Wirelessarrow a petri-dish bridge
Ethical Hacker Community Forums
January 08, 2009, 03:38:22 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: a petri-dish bridge  (Read 294 times)
0 Members and 1 Guest are viewing this topic.
notgeekenough
Newbie
*
Offline Offline

Posts: 2


View Profile
« on: January 03, 2009, 07:31:49 PM »

I've posted this question on two forums (DD-WRT, Linux) with no response. It has to do with manufacturers forcing insecurity of wireless lans. It seems like no matter how much you want, you can't truly secure you're WLAN unless you use a minimal # of devices. Right now, I'm running WPA2/AES which two laptops, a Wii and a linksys camera can use and a wired server. All the kids have DSs which can only connect with WEP and I would like to set up RADIUS which would remove the Wii and camera. What I would like to do is buy a cheap wireless AP and set up WEP for the Wii, camera and DS (can these be hacked?). This AP would would limit traffic to/from its stations and "bridge" with the primary secure AP in such a way that the laptops and wired server would not be affected. Sort of like a petri dish, any bad thing created on the secondary AP could not escape. The secondary would have be to able to negotiate with RADIUS. I don't know if this is possible. Any ideas?
Logged
jason
Sr. Member
****
Offline Offline

Posts: 363


Aut Viam Inveniam Aut Faciam


View Profile WWW
« Reply #1 on: January 04, 2009, 10:07:43 AM »

You could likely do this with one of the linux firewall distros like ipcop or smoothwall. Just setup an additional interface for the less secure wireless connection and place whatever specific limits on it that you need.
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2435


Editor-In-Chief


View Profile WWW
« Reply #2 on: January 05, 2009, 09:36:30 AM »

I agree. That least common denom. theory makes the weakest link in the chain your highest possible security posture. Here's a thought from an architectural standpoint. Don't just use another AP. Get a full wireless router, and put them on a different subnet. You can dumb it down to WEP and still use the same radius server for auth. Or, since it is only 3 devices, don't worry about radius and just set them up on the dumbed down router using MAC filtering as well. Many routers now also come with a nice little feature that disallows anyone connected via the wireless network from accessing the control panel. This makes it so that only those with physical access to your network via the wired LAN can make changes to your router's settings.

Hope this helps,
Don
Logged

CISSP, MCSE, CEH, Security+ SME
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.048 seconds with 24 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
How many security events including conferences and training do you attend a year:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2009 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.