Securing Wireless The Draconian Way
As I sit here awaiting my final exam (and essay) submission for the semester, I have to wonder what is to become of my interest connection once the iiNet case is over.
Here’s the situation. I live near a station, so it’s a relatively high traffic area for people, cars, and the combination of people sitting in cars. At such a stage I might not be worried, but the increase in mobile telephones with WiFi capabilities starts to cause a problem. This network has been hit at least six times in the last year, with obvious brute force attempts resulting in my shutting down the main Access Point. The back-up access point (a WEP ’secured’ device) runs on a network with a limited number of IP addresses, distributed within a random IP range, with just enough room for the devices, which have static ARP tables (written to ‘locked’ flash media in the system administering the limited network connectivity). Naturally, I’m not worried about someone hacking the WEP network, as the only internet connection it has is to my ISP’s (iiNet’s) FTP mirror — if they hack into the network and download Linux that’s fine with me, my ISP, the government, AFACT, and pretty much everyone except Apple and Microsoft who would rather have their business. Jokes aside, I’m still worried.
Our old WiFi system was based off iiNet’s 4 port WiFi Belkin Router. For those in the know, I refer to the dreadfully outdated white hunk of plastic which locked up half the time (until the more recent release which just caused it to live in a state of constant ‘random’ connectivity for WiFi). Now I am faced with a problem of securing my equipment here. The network runs two primary APs (neither are the Belkin all-in-[I]-wonder-[why I bought this]). One is a Netgear WAG102, which is the ‘WEP’ system (put in place for a Phillips Pronto, for those who care), and the other shall remain unnamed (due to the constant threat of firmware bugs — ordinarily I have no fear, but this is serious). As a result of the latter AP (the primary AP), which runs on the main LAN, I must rethink my routing situation.
(more...)