Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 28 guests and 2 members online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Wirelessarrow a petri-dish bridge
EH-Net
May 19, 2013, 12:30:53 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: a petri-dish bridge  (Read 4129 times)
0 Members and 1 Guest are viewing this topic.
notgeekenough
Newbie
*
Offline Offline

Posts: 2


View Profile
« on: January 03, 2009, 07:31:49 PM »

I've posted this question on two forums (DD-WRT, Linux) with no response. It has to do with manufacturers forcing insecurity of wireless lans. It seems like no matter how much you want, you can't truly secure you're WLAN unless you use a minimal # of devices. Right now, I'm running WPA2/AES which two laptops, a Wii and a linksys camera can use and a wired server. All the kids have DSs which can only connect with WEP and I would like to set up RADIUS which would remove the Wii and camera. What I would like to do is buy a cheap wireless AP and set up WEP for the Wii, camera and DS (can these be hacked?). This AP would would limit traffic to/from its stations and "bridge" with the primary secure AP in such a way that the laptops and wired server would not be affected. Sort of like a petri dish, any bad thing created on the secondary AP could not escape. The secondary would have be to able to negotiate with RADIUS. I don't know if this is possible. Any ideas?
Logged
jason
Hero Member
*****
Offline Offline

Posts: 1012



View Profile WWW
« Reply #1 on: January 04, 2009, 10:07:43 AM »

You could likely do this with one of the linux firewall distros like ipcop or smoothwall. Just setup an additional interface for the less secure wireless connection and place whatever specific limits on it that you need.
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« Reply #2 on: January 05, 2009, 09:36:30 AM »

I agree. That least common denom. theory makes the weakest link in the chain your highest possible security posture. Here's a thought from an architectural standpoint. Don't just use another AP. Get a full wireless router, and put them on a different subnet. You can dumb it down to WEP and still use the same radius server for auth. Or, since it is only 3 devices, don't worry about radius and just set them up on the dumbed down router using MAC filtering as well. Many routers now also come with a nice little feature that disallows anyone connected via the wireless network from accessing the control panel. This makes it so that only those with physical access to your network via the wired LAN can make changes to your router's settings.

Hope this helps,
Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.067 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.