Introduction to wireless security settings

Source: Internet
Author: User

1. Pay attention to the AP Login Password

For network experts, it is not difficult to perform some wireless security settings, but for most users, it is not very familiar with these settings, so let's start with the basics. To ensure the security of your wireless LAN, you must change the default password of Your Wireless AP or Wireless Broadband Router.

As you know, the login usernames and passwords of many Wireless AP or wireless broadband routers are "admin" by default or the manufacturer's English names are abbreviated as "TP-LINK, SMC, and so on ", in this way, any user can easily enter Your Wireless AP or Wireless Broadband Router to set up and modify information. What's more interesting is that users who know more about broadband can also obtain your broadband password. Therefore, it is best to change the default login password to your own easy-to-remember password, so that illegal users can easily control Your Wireless AP or Wireless Broadband Router.

2. Pay attention to SSID settings

The full name of SSIDSSID is ServiceSetIdentifier. It is the domain name shared by a group of wireless regional network devices. The same SSID must be set for each node in the wireless network for mutual transmission. Therefore, the wireless workstation must display the correct SSID, which is the same as the SSID of the Wireless AP or Wireless Broadband Router to access the Wireless AP or Wireless Broadband Router; if the displayed SSID is different from that of the Wireless AP or Wireless Broadband Router, the Wireless AP or Wireless Broadband Router will reject the access through the service area.

Therefore, the SSID can provide a simple password authentication mechanism to ensure wireless network security. In addition, the SSID can be used to distinguish different networks and can contain up to 32 characters. The network adapter can access different networks with different SSID settings. The SSID is usually broadcast by a Wireless AP or a Wireless Broadband Router, you can automatically find the SSID in the current wireless area through the wireless network card or the scanning function provided by Windows XP.

As you know, to control the security of wireless networks, You can generally start with access control and data encryption. The access control ensures that only authorized users can access sensitive data, and the SSID is like this. In actual settings, most Wireless AP or wireless broadband routers are "Allowed to broadcast SSID" by default when leaving the factory, to make the wireless LAN more secure, you can enter the configuration page of the Wireless AP or Wireless Broadband Router, set the SSID to "do not broadcast SSID", so that other users want to automatically enter your wireless LAN, you must manually enter the correct "SSID" to enter the network, which ensures the security of the LAN.

Of course, SSID control is not omnipotent. for multi-user wireless systems, especially public wireless systems, its security is also difficult to completely guarantee, because users need to configure their own client systems, this allows many people to know the SSID, which is easy to share with malicious illegal users. Some wireless network adapters have strong functions and can query the SSID on the wireless network. At present, some manufacturers' products support the "ANY" Special login method, as long as the wireless network adapter on the computer is in the signal coverage of the Wireless AP or Wireless Broadband Router, it will automatically connect to the Wireless AP or Wireless Broadband Router, which is a test of the SSID security.

3. Set MAC Filtering

What is MAC? Different from IP addresses, MACMediaAccessControl and Media Access Control), an address is the physical address of a network adapter and the identifier used to identify a LAN computer. The length is 48-bit binary, from 12 00 ~ 0FFH consists of hexadecimal numbers. Each hexadecimal number is separated by a hyphen (-). The MAC address of a wired network card or a wireless network card is unique in the world, therefore, the MAC address and preset network ID are used to limit which NICs and access points can be connected to the network, ensuring network security. For illegal recipients, it is very difficult to intercept the signals from the wireless LAN, which can effectively prevent hacker and intruder attacks.

By using the MAC function, you can set a MAC address list for users with wireless network card access permission under each Wireless AP or Wireless Broadband Router in the wireless LAN. the MAC address is not in the list, wireless AP or Wireless Broadband Router will reject the access request.

Of course, you need to manually enter the address one by one. Therefore, this method requires that the MAC address list in the Wireless AP or Wireless Broadband Router must be updated at any time, and the scalability is poor. Therefore, it is only suitable for small networks.

In addition, attackers can easily steal MAC addresses by using network listening methods. Of course, if there are too many Wireless AP or wireless broadband routers in the wireless network, in order to achieve the unified MAC address authentication for all Wireless AP or wireless broadband routers in the enterprise, the current Wireless AP or Wireless Broadband Router also supports centralized Radius Authentication for the MAC address of the wireless Nic.

4. Set WEP Encryption

To achieve wireless network security, access control alone is definitely not good, and data encryption is also essential. Data Encryption ensures that the transmitted data can only be received and understood by the expected users, currently, WEP is a common data encryption method.

WEPWiredEquivalentPrivacy) the encryption technology is derived from the RSA Data Encryption technology named RC4, which can meet users' high-level network security requirements. WEP uses the RC4 encryption algorithm of the shared key. The length of the key is initially 40 characters and 5 characters), and later increases to 128 characters and 13 characters). Some new devices support 152-bit encryption. With static WEP encryption, you can set up four wepkeys and use Dynamic. When WEP encryption is used, WEPKey changes with time.

WEP encryption uses static secret keys, and WLAN terminals use the same key to access the wireless network. WEP also provides the authentication function. When the encryption function is enabled and the client tries to connect to the AP, the AP sends a ChallengePacket to the client, the client uses the shared key to encrypt the value and send it back to the access point for authentication and comparison. Only when the value is correct can the client be authorized to access network resources.

It should be noted that not all wireless network cards support the WEPKEY encryption method of 128 bits or more. Some old wireless network cards may only support the encrypted method of 40 bits or 64 bits, others are not supported at all. Therefore, when setting the WEP encryption for Wireless AP or Wireless Broadband Router, you need to set the number of encrypted bits based on the wireless Nic.

In short, the purpose of WEP-based shared key authentication is to achieve access control, but its authentication information is easy to forge. However, the user's encryption key must be the same as the AP's key, and all users in the same service area share the same key. Because the time-consuming and difficult to replace the key at the same time, the key is usually rarely changed, if a user loses the key, the entire network may be compromised.

In addition, because shared key authentication uses the encrypted authentication query text to prove that you are aware of the shared key, the RC4 algorithm has a weakness. If attackers listen to the authentication response, then you can determine the RC4 password stream used to encrypt the response. Therefore, attackers can counterfeit the authentication by listening for a successful authentication. Enabling shared key authentication actually reduces the overall security of the network and makes it easier to guess the WEP Key.

In short, for general users, although the SSID, MAC, and WEP Security Settings all have their inherent shortcomings, for general users of domestic or commercial wireless networks, the above three wireless security settings have basically ensured the data security of the wireless network. Therefore, they are very practical.

Edit recommendations]

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.