Network Security – how should an open wireless access point be run beside a safe network?



So, let’s say we want to have an open wireless access point for some reason. (Maybe offering it to guests if you’re a business?) There are certainly a lot of BAD ways to give open wireless access. As we’ve seen in this series so far, it could be quite easy to hijack all connections in a network using arp spoofing. If you run business machines on a network you do NOT by any means want an open access point on the same subnet. Here are some possibilities though…..


Let’s say we’ve got a dsl modem/router that gives out addresses in the 192.168.1 range of addresses. Further, let’s say we’ve got a firewall/router setup providing a “safe network with a 192.168.0. range of addresses. So, what are our options?

Access point plugged into 192.168.0. range…. bad idea, the clients could hijack network traffic using arp poisoning.

Wireless router plugged into 192.168.0. range (with clients in the 192.168.2 range) Interesting thought. ARP poisoning would not be possible, but it would be possible for 192.168.2 clients to scan and access tcp services in the 192.168.0. range (which is upstream.) the router would basically prevent tcp access INTO the wireless address subnet, but would not prevent “browsers” working their way out.

So, we could plug and access point into the main dsl/router and give wireless clients a 192.168.1…. address? The only problem with this is that traffic from the firewall to the dsl router could be hijacked using arp spoofing by any of the wireless clients.

So, here the best option seems to be this…. wireless ROUTER plugged into 192.168.1 dsl/router which means the wireless clients can be assigned addresses within their subnet (192.168.2 for instance.) So, the best setup for a side by side safe and “wide open” network seems to be a “Y” configuration…

Safe Net and Unsafe Net are peers with different “internal” subnets. (So they’re each behind a router/firewall)

And the router to the world is upstream for both the safe and the unsafe routers.

Related Posts

Blog Traffic Exchange Related Posts
  • Network Security guide for the home or small business network - Part 11 - Why? Alright, so you're still reading this series and you're thinking. Look, I'm not protecting national security secrets. All I'm doing is (running a business|emailing my grandkids|using the web for research). True, good point. You're not at the defense department. OK. Let's say you just use your computer for email and......
  • Network Security - Arp spoofing series I think I've wrapped up the series on arp spoofing and it's implications for network security. I know there's nothing earth shattering here, most network security types are well aware of the problems (and perhaps aware of more sophisticated solutions?). For some though, this series is likely an eye opener......
  • Network security - what does arp spoofing mean for wireless? So, if you haven't already had enough cause to tighten your wireless security.... we've been talking about arp poisoning (spoofing) and the basic conclusion is that IF an attacking machine is on the same subnet as your machine (same IP address range), they can "own" all traffic from you machine......
Blog Traffic Exchange Related Websites
  • [How To] Jailbreak iOS 5.0.1 & Preserve Baseband Using sn0wbreeze v2.8b11 Apple recently seeded iOS 5.0.1 final version to the public. This version fixes battery issues & some security issues. @iH8sn0w has updated his jailbreak tool sn0wbreeze to support iOS 5.0.1. You can use sn0wbreeze to preserve baseband and unlock using ultrasn0w or Gevey sim on iPhone 4. sn0wbreeze v2.8b11 is......
  • free SANS webcasts powered by vLive! The SANS Institute <Webcast@sans.org wrote: Please join us in the upcoming weeks for the following informative, free SANS webcasts powered by vLive!, the SANS Institute's online learning platform: WEBCAST 1 Internet Storm Center: Threat Update WHEN: Wednesday, May 11, 2011 at 1:00 PM ET (1700 UTC/GMT) FEATURING: Johannes Ullrich https://www.sans.org/webcasts/isc-threat-update-20110511-94088......
  • Bartley Cavanaugh Golf Course, Sacramento, CA Bartley Cavanaugh Golf Course is located in: Sacramento, CA Phone: 916-665-2020 Website: http://www.bartleycavanaugh.biz Course History: This public course was named in honor of a city manager from Sacramento and first opened its doors in 1995. It's been a popular course ever since and combines some great values with challenging play.......
PDF24    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site