How to Secure Your Wireless Network

Written by:  • Edited by: Bill Bunter
Updated Oct 14, 2010
• Related Guides: Strong Passwords | Wireless Network

Wireless networks are becoming increasingly commonplace, but a surprising large number of them are insecure. This article explains the steps you need to take in securing your wireless network.

Wireless networks are extremely convenient, but that convenience comes at a price: security. With a traditional wired network, data is channelled through cables and cannot be easily intercepted. With a wireless network, data is beamed through the sky and can be more easily intercepted – unless, that is, you have appropriate security measures in place. This article explains how to secure a wireless network against attack.

Before outlining the steps you should take to secure a wireless network, let’s quickly look at a couple of things that you probably don’t want to do: namely, disabling SSID broadcasting and enabling MAC filtering. The SSID is the name of your wireless network and its broadcast to enable people to easily find and connect to your network. Numerous websites – in fact, just about every website - recommend disabling SSID broadcasting (if the bad guys can find it they can hack it, right?) and enabling MAC filtering. However, MAC filtering is so easily bypassed as to render it almost completely redundant. With regards to SSID broadcasting, more about that in our article Why You Shouldn’t Disable Your SSID Broadcast.

So, if you shouldn't enable Mac filtering and you shouldn't disable SSID broadcasting, what should you do? Read on!

  1. Use encryption. To stop outsiders being able to data this transmitted over your wireless network, the data should be encrypted. There are 3 wireless encryption standards: WEP, WPA and WPA2. WEP is the oldest and most easily cracked standard, so ideally you should use WPA or, better yet, WPA2.
  2. Change the default account names and passwords. The majority of access points (APs) use default account names/passwords set by the manufacturer that are known to one and all. Change them to something unique and be sure to use strong passwords.
  3. Segment your network. Even when best practice is adhered to, a wireless network will be less secure than a wired network. Segmentation creates a barrier between the physical network and wireless network – by using a firewall, for example - and enables you to control access/communication between them. Unfortunately, this can be a somewhat complex job and, unless you have a fair amount of in-house expertise, you’ll probably need to retain the services of a consultant.
  4. Authenticate users. RADIUS provides you with far more control over access to the WLAN. For more information, visit Microsoft's overview on securing wireless LANs with certificate services and the FreeRADIUS Project.
  5. Update your firmware. The manufacturers of AP devices often release firmware updates to fix bugs and security vulnerabilities. So, keep your firmware updated.

Security is only as strong as its weakest link, and that is often the wireless network. In simple environments, the network can probably be DIY’d; however, security matters do become more challenging in complex environments and in such cases the best advice may well be to leverage the expertise of a consultant.

One final bit of advice: the value of securing your own wireless network will be eroded if your data is bounced in unencrypted form over other networks. Educate your users and make sure that they are aware of the risks associated with connecting to an insecure network.


Comments

Showing all 4 comments
 
antivithe Oct 15, 2010 6:43 AM
antivirus review
Virus scanner and Antivirus software reviews and comparison.Despite security improvements of operating systems the internet is not becoming a safer place. Compared to a simple Antivirus, an Internet Security Suite offers comprehensive security protection for your computer.
hanzen Oct 14, 2010 6:13 AM
Nice Guide regarding SSID
thank you so much for this accurate guide. i am so confused about wireless security especially on ssid broadcasting since many websites suggested to disable ssid which i think is inappropriate. now i am more confident enough to enable ssid on my wireless network.
Charlie Sep 10, 2010 12:20 AM
Broadcast
Would disabling the broadcasting still be bad if you utilized it with a password on the network?
Andrew Bruce Apr 11, 2010 6:49 PM
Thanks--from a CISSP (hopefully!)
Thanks very much for this info--I consider myself somewhat of a security guru and I had never considered that disabling SSID and enabling MAC filtering is actually a Really Bad Set of Ideas. I'm going to look at RADIUS (although I better not take the wireless down--wife will kill me :)

Cheers and thanks again.
 
blog comments powered by Disqus
Email to a friend