WiFi Security?

The_Unbeliever

Honorary Master
Joined
Apr 19, 2005
Messages
103,196
Disable WPS

On some routers WPS cannot be disabled. This is a major flaw regarding security.

See the following two links :

WiFi routers security test

WPS are intrisically unsafe

Should you need to have wifi on a business network, put the wifi router on another network segment, and set this segment up so that it cannot route to your normal network.

A Smoothwall with a PURPLE segment will do the job just fine by segmenting your WiFi network from your normal network.
 
Last edited:

creeper

Executive Member
Joined
Nov 18, 2010
Messages
5,463
I just set up WPA2 & change the pass. For a residential house that is more than adequate. If its a business then its a completely different ball game...



I agree with the above on the whole, but some extra commentary:

3. Should be disabled by default anyway on well known router brands
5. Unconvinced. Extra hassle for no benefit imo
6. For a residential setup I don't see the point. Would make sense for small offices I guess.
7. Disagree. Some devices can't connect to hidden SSID & it won't stop anyone who can bypass

I should've mentned that my list is for the super paranoid. ;)
 

nomdeplume

Active Member
Joined
May 13, 2006
Messages
79
Some devices can't connect to hidden SSID

Have not personally had a problem with this and see no harm in hiding the SSID.

Changing your range from the standard 192.168.0&1 to 172.16 with static IP and no DHCP

If you have static IP and queues set a catch all for any unwanted guests.
 

HavocXphere

Honorary Master
Joined
Oct 19, 2007
Messages
33,155
I should've mentned that my list is for the super paranoid. ;)
Of course. Yeah I can see how people might want more security. To me I just aim for a solid calculated risk between cost/benefit. Others might define the optimal balance between the two differently.

Have not personally had a problem with this and see no harm in hiding the SSID.

Changing your range from the standard 192.168.0&1 to 172.16 with static IP and no DHCP

If you have static IP and queues set a catch all for any unwanted guests.
Interesting approach.
 
Top