Security Basics mailing list archives

Re: Need opinion on Wireless network setup.


From: "Paul Kurczaba" <paul () myipis com>
Date: Fri, 30 Jul 2004 16:39:29 -0400

Wireless networks, even with WEP or MAC address control, should always be
treated as an "internet" zone. You should then have a VPN solution in place
to access the internal nework, whether it be L2TP, IPSec, or PPTP.

-Paul Kurczaba
----- Original Message ----- 
From: "Chad Thomsen" <chad.thomsen () bramespecialty com>
To: <security-basics () securityfocus com>
Sent: Thursday, July 29, 2004 9:20 AM
Subject: Need opinion on Wireless network setup.


I am fairly new to the wireless world but have done a lot of research into
it and have played around with it both at home at here at work.  I have
implemented a wireless access point using 128 bit wep key for now.  I am
getting ready to implement a system based on example one (or maybe example
2) of the following white paper:

http://www.microsoft.com/downloads/details.aspx?FamilyID=0f7fa9a2-e113-415b-
b2a9-b6a3d64c48f5&DisplayLang=en

The only thing really wrong that I noticed was there was not firewall (setup
with VPN) between the access point and the rest of the network?  Is this a
real necessity?

Thanks,
Chad Thomsen, MCSE, CCNA
Network Administrator




---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
any course! All of our class sizes are guaranteed to be 10 students or less
to facilitate one-on-one interaction with one of our expert instructors.
Attend a course taught by an expert instructor with years of in-the-field
pen testing experience in our state of the art hacking lab. Master the
skills
of an Ethical Hacker to better assess the security of your organization.
Visit us at:
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------




---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off 
any course! All of our class sizes are guaranteed to be 10 students or less 
to facilitate one-on-one interaction with one of our expert instructors. 
Attend a course taught by an expert instructor with years of in-the-field 
pen testing experience in our state of the art hacking lab. Master the skills 
of an Ethical Hacker to better assess the security of your organization. 
Visit us at: 
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


Current thread: