ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Locking down your wireless network

Jonathen Yarden

Published: 25 Apr 2005 18:30 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Unfortunately, most corporations that have already deployed wireless access chose usability over security, just like most software companies. In addition, many organisations don't consider the fact that wireless access doesn't really offer any advantages over wired access in many cases.

In fact, it can actually introduce new problems. I can't tell you how many times I've witnessed 802.11b wireless network problems caused entirely by the use of 2.4-GHz wireless phones, often from wireless PBX systems.

Despite my own personal disdain for wireless network access, wireless networks are now in the corporate environment, and enterprise deployments are increasing. However, I strongly advise organisations to use this strategy when deciding whether to go wireless: Use wireless networking only in cases where wired access is impossible, not just as a simple or trendy alternative.

And while security should be a primary factor in this decision, keep in mind that there are more than just security-related reasons for staying wired. For example, wired networks can handle significantly higher bandwidth, as well as offer better security, because they don't broadcast packets of information.

But if bandwidth isn't a concern, and the powers-that-be are convinced that wireless is the way to go, rest assured that it is possible to make wireless access much more secure without depending on WEP. Two methods for accomplishing this include using protocols such as PPTP or L2TP and enforcing access controls with usernames and passwords or some other authentication method. Add IPSec to the mix, and you've got both access control and end-to-end encryption that's more secure than wired network access. But keep in mind that this solution is still prone to interference.

Of course, some people will argue that 802.11i features all of this security provided by WPA — WEP's expected replacement — as well as better interference control. While this is great news, 802.11i is no use to anyone until there are plans to replace all existing wireless networking equipment or upgrade the firmware, if that's even possible.

In addition, remember that no matter what security technologies or standards emerge, there will always be someone out there trying to break it — and that includes WPA. In my experience, you can deploy Gigabit Ethernet access at a lower cost, and it provides both superior security and bandwidth irrespective of data encryption.

If wireless access is your only alternative, explore the use of PPTP/L2TP and IPSec on your existing infrastructure before deciding to replace or upgrade existing 802.11a and 802.11b equipment. While it's not "pretty" from a technological point of view, it's quite functional, and it just might prove to be more secure than 802.11i. As for me, I'll stick with wired networks.

Jonathan Yarden is the senior UNIX system administrator, network security manager, and senior software architect for an American regional ISP.

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
119 out of 233 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Security Consultant - Leeds - 60000

This is a technical IT Security role, focusing on Data Encryption, Operational Security and Trust Models, Physical Security methods, Firewalls, ...

Spanish Speaking Data Network Engineer- London- Training- Cisco- 37k

Wireless standards IEEE 802.11A/B/G standards and wireless encryption techniques such as WEP, WPA and Radius Authentication. Spanish Speaking Data ...

Wireless Specialist Sales 28k Cheshire

My client, a regional leading wireless provider is currently looking for a talented wireless communications salesman to promote their product ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Password manager - portable or online

Yes, we have lots of passwords - bank accounts, e-mails, computers, domains, instant messengers, you name it - and we need them all. We may forget them and we do. I am not talking about... More

Post a comment

Mobile Open Source: A Torrent of Impli...

Mobile Open Source: A Torrent of Implication Author: Eric Everson, Founder MyMobiSafe.com There is a change working its way through the wireless industry that is fraught with the... More

Post a comment

WinMo Handsets Get Facebook: Shhh Don’...

WinMo Handsets Get Facebook: Shhh Don’t Tell Your Boss! Eric Everson, Founder MyMobiSafe.com For those whose lives have come to revolve around their social networking it would seem... More

Post a comment