Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


June 2002

Securing 802.11 Wireless Networks


RSS
Subscribe to Windows IT Pro | See More Internet Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
SideBar    Monitoring Encrypted Traffic

Use Win2K Routing and Remote Access and PPTP or IPSec to tighten security

Wireless networking has quickly become the most exciting networking technology of this decade. No longer limited to propeller heads and weekend data warriors, wireless networks have hit the mainstream. Anyone who's explored wireless security features, though, knows how little security such networks inherently provide. Frequent warnings and white papers demonstrate the security weaknesses in the Wired Equivalent Privacy (WEP) standard, which is a part of the 802.11b and 802.1x wireless LAN (WLAN) protocols. Yet many administrators assume that their wireless network signal is too remote or too contained (e.g., within a building) to be open to attack. However, resources such as NetStumbler.com (http://www.netstumbler.com) and Peter Shipley's "Open WLANS" presentation (http://www.dis.org/filez/openlans.pdf) give accounts of accessing thousands of wireless Access Points (APs) while war driving (i.e., automatically scanning for wireless networks while driving through an area).

The 802.11b wireless standard (the most popular and most widely available standard) has two general configuration settings that don't provide the protection some administrators think they do. First, systems administrators sometimes have the mistaken impression that Service Set Identifiers (SSIDs) relate to security. SSIDs aren't security related, although you can use them to administratively segregate wireless users into smaller, more logical networks. SSIDs aren't meant to be kept secret or private, hence using them won't contribute to the security of your wireless network. To facilitate connections by users, OSs such as Windows XP report all the SSIDs they find. Second, many administrators use WEP keys to configure rudimentary wireless encryption. These keys come in two sizes: 40-bit and 128-bit. (For information about WEP encryption, read Eric Janszen's article "Understanding Basic WLAN Security Issues" at http://www.80211planet.com/columns/article/0,,1781_937241,00.html.) Obviously, the 128-bit key is the stronger choice, but WEP has substantial weaknesses, so I suggest that you instead rely on a VPN tunnel to provide all the encryption you need. This solution works well in a Windows 2000 network.

Three Models of Connectivity
You have three models that build on each other to provide wireless network connectivity in a Win2K network. First, you can use the Internet Connection Sharing (ICS) service and create a DHCP scope on a Win2K server to set up a basic wireless gateway. To secure wireless traffic and provide minimal encryption protection, the second model adds Win2K's Routing and Remote Access service and PPTP to the first model. To take advantage of the strongest security commercially available today, the third model replaces PPTP with IP Security (IPSec) as an encryption option.

In the first and simplest model, you connect your AP to a Win2K computer running the ICS service. (For more information about ICS, see "Related Articles in Previous Issues" at http://www.winnetmag.com, InstantDoc ID 24873.) You install the DHCP service and create a DHCP scope for your wireless clients, then run the ICS Wizard on the Internet-facing computer. The result is a wireless Internet gateway for your users (and anyone else within a short distance of your AP).

However, this model provides no security to your wired network or wireless clients. To secure your new wireless connection, you need to make a few changes to your environment, such as installing a VPN server and adding encryption. You want to make sure that any data transmitted across your wireless networks remains confidential and that would-be intruders can't arbitrarily connect to your network or observe the data you're passing.

The second model uses PPTP to encrypt your wireless data. Using the 128-bit Microsoft Point-to-Point Encryption (MPPE) that comes with Win2K's Routing and Remote Access implementation might be ample protection for your network. Encrypting data with 128-bit MPPE inside a Generic Routing Encapsulation (GRE) tunnel provides enough protection to stop the casual or unskilled war driver. However, MPPE doesn't provide mutual authentication of client and server or the strong 168-bit Triple DES (3DES) encryption that you get through Microsoft's implementation of IPSec over Layer Two Tunneling Protocol (L2TP).

The majority of security researchers agree that IPSec currently offers the best protection for wireless encryption. Therefore, the third (and most secure) model uses IPSec rather than PPTP.

To set up a wireless network that uses IPSec, you first need to plan a stub network (i.e., a child network that uses a subset of the parent network's IP addresses but is segregated from the parent network by a router or gateway device) and set up DHCP and Routing and Remote Access. You need the stub network to give clients a means to connect to your wireless network. The wireless clients can use a statically assigned IP address to attach to one of your wireless network's APs; to assign addresses dynamically, you can offer a DHCP service in the stub network. The only resource available to clients on the wireless network is a Routing and Remote Access server. Any wireless clients that want access to your internal network must first connect, encrypt, and authenticate, similar to any Routing and Remote Access client that connects from across the Internet.

   Previous  [1]  2  3  4  Next 


Top Viewed ArticlesView all articles
CES 2009: Ballmer Announces Windows 7, Windows Live, Live Search Milestones

During his first-ever Consumer Electronics Show (CES) 2009 keynote address last night in Las Vegas, Microsoft CEO Steve Ballmer announced the pending public availability of a feature-complete Windows 7, the final version of Windows Live Essentials, and ...

10 Reasons Not to Deploy Windows Vista

The decision to upgrade to Vista has to make business sense, but many companies find the costs in training and application compatibility problems outweigh any benefits Vista brings. ...

10 Reasons to Deploy Windows Vista

The decision to upgrade your XP systems to Vista is simple when you consider features such as easier backup, a great desktop search, and vastly improved security options. ...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events Security Summit

Virtualization Forum: Optimizing Storage, Networks, Desktops, and Security

Cloud Computing Forum: Integrating Software, Server and Storage as a Service into Your Enterprise IT Delivery Model

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2009 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing