Wired Network Security: wired network security, but wireless network security, is difficult to prevent. For a wireless network that uses air as a bridge, security issues need to be prevented in advance without any backup. All kinds of encryption methods should be used as far as possible to ensure the security of your wireless network.
If you do not know enough about wireless network security, let's give you a practical example: A friend of mine recently "wireless, he picked up his book and connected the internet in the living room much faster than the AP! Do you know the reason? The original wireless Internet access signal in the living room came from the neighbor's house !! To find out the cause, it is very likely that the wireless construction of the neighbor's house is the same as that of a friend's house, and the wireless network security of the neighbor's house is also threatened because encryption is not adopted!
Of course, the above example is also an unintentional coincidence. However, we have to pay attention to the current network environment! The security of wired networks has been widely used to prevent readers. How can we prevent potential wireless network security risks?
Analysis and Solution of common security problems
Question 1: How to prevent unauthorized users from accessing the service in the preceding example?
Solution: 1. Use the latest identity authentication measures to prevent unauthorized user access. We know that wireless signals are transmitted in the air, so it will inevitably spread to other areas that do not want to arrive, as long as they are within the signal coverage range, illegal users can obtain wireless network data without any physical connection. Therefore, they must prevent illegal terminal access and data leakage.
2. Prevent using the MAC address of the NIC. Each wireless network card has a unique MAC address. If we set an Access Control table based on the MAC address for the AP), we can ensure that only registered devices can Access the network.
Question 2: How to Prevent Access from illegal AP access?
Solution: The legality verification and regular site review of the AP can be used to prevent the vulnerability. When a Wireless AP is connected to a wired hub, an illegal AP attack occurs. An illegally installed AP may endanger valuable resources of the wireless network. Therefore, the validity of the AP must be verified. Therefore, this should be taken into account when purchasing an AP. In this verification process, not only does the AP need to confirm the legality of the wireless user, but the wireless terminal device must also verify whether the AP is a false access point before communication.
Proposal on Comprehensive Prevention of Wireless Network Security
I. In the case at the beginning of this article, wireless access points are not in a closed environment. Therefore, you should first pay attention to the reasonable placement of the Access Point antenna. In order to limit the signal transmission distance outside the coverage area. Do not place the antenna near the window because the glass cannot block the signal. You 'd better place the antenna in the center of the area to be covered and minimize signal leakage to the ceiling. Of course, completely controlling signal leakage is almost impossible, so other measures need to be taken.
2. After processing the signal antenna problem, add a "protective film" to it, that is, the wireless encryption protocol Wired Equivalent Privacy and WEP must be used ). It is a standard method for encrypting traffic on wireless networks and complies with the 802.11b standard. Despite its major flaws, such protocol standards still help block occasional intrusion of hackers and complement each other.
3. disable DHCP and SNMP settings. Disabling DHCP makes sense for wireless networks. If this measure is adopted, hackers will undoubtedly become more difficult to crack your IP address, subnet mask, and other required TCP/IP parameters ). No matter how hackers use your access point, they still need to figure out the IP address. For SNMP settings, either disable or change the public and dedicated shared strings. Without this measure, hackers can use SNMP to obtain important information about your network.
4. Use the access list, which is also called the access control list ). We recommend that you use this feature to further ensure your wireless network security. However, note that not all wireless access points are supported. This feature allows you to specify which machines are allowed to connect to the access point. Access Points that support this feature sometimes use the Common File Transfer Protocol (TFTP) to regularly download the updated list, which is very useful.
5. Use both wireless and wired policies. Wireless Network security is not a separate network architecture. It requires the cooperation of various programs and protocols. Policies that combine wired and wireless network security can maximize the security level. For example, integrated single user ID and password are used when we access the network through wired or wireless methods.