Google Search

Google

Monday, October 1, 2007

Wireless Network Security

Here are some tips on wireless network security. Read and implement them in your wireless network. Wireless network security is important, don't overlook it!

Change Factory Default Username and Password on Wireless Router

This is the first task you must do to better secure your wireless router. Factory default username and password must be changed when you start to configure the router. Those username and password are known publicly, so don’t leave it as default setting.

If you don’t believe, download some router manuals from vendor website, you would be able to find all these information…

Here are some examples of default username and password of wireless router from different vendors:

Linksys default username:(leave it blank) password:admin
Dlink default username:admin password:(leave it blank)
Netgear default username:admin password:password

Note: A good password is composed of number, alphabet (upper case/lower case) and symbol.

Change Factory Default SSID on Wireless Router

Please also change factory default SSID of wireless router. Same as default username and password, it would be easy for people to know the default SSID even though you have disabled SSID broadcasting. The only information they need is your wilreless router model.

So, always assign the SSID that not easily to guess, and don’t use your name, pet’s name or home address as SSID. Quick suggestion, you can try to use the name that is unique and only known among family members but not others.

Again, here are some examples of default SSID of wireless router from different vendors:

Linksys factory default SSID:linksys
Dlink factory default SSID:default
Netgear factory default SSID:NETGEAR

Disable SSID Broadcast

By default, most wireless router will broadcast the SSID to all wireless devices. That means your neighbour can detect the SSID you use in your network and gain access to your network with a computer equipped with wireless network adapter.

If you really want to broadcast the SSID, please make sure you enable WPA2 encryption and MAC address filtering to limit the access to your network.

Enable WPA2 Encryption

Don’t forget to enable WPA2 encryption to encrypt the network traffic and improve wireless network security. For most of the latest routers, WPA2 encryption is supported. So far, WAP2 is the best and strongest encryption among WEP, WPA and WPA2 encryptions.

If you are using old wireless router that only support WPA/WEP encryption, try to upgrade the router firmware to have WPA2 support. Just go to the vendor website and check what’s the latest firmware for your router. This is because WPA/WEP encryption is not secured and can be cracked after gathering enough network traffic. Check out here on how to crack the WPA/WEP encryption key.

Note: If so bad that no WPA2 support even after upgrading to latest firmware, then use WPA or WEP encryption. It’s better then no encryption at all. :o)

Enable MAC Address Filtering

You can enable MAC address filtering to allow the computers with specific MAC address to join the wireless network only. This is one of the methods to enhance wireless network security from unauthorized access.

In order to make it work, you need to define a list of MAC address that are allowed to join the network. If you are not too sure how to check MAC address, kindly click here to learn how to check MAC address of network card.

Disable Wireless Router Administration by Wireless Client

It’s advisable to disable wireless router administration by wireless clients. This means you can only access and change the router configuration after wire connecting your computer to router.

Note: You should also use https (with encryption) method to access your router administration webpage instead of http (without encryption).

Disable Remote Wireless Router Administration

Don’t enable remote wireless router administration from Internet unless you really need it. Other Internet users would be able to find and hack your router through bruteforce password cracking or security exploits.

Note: Have a check on this feature although it’s usually disabled by default.

That's all for wireless network security tips.. I would recommend you to check how to secure Ethernet wired network after this wireless network security reading. You would find additional information on securing wireless network.

No comments: