This is a read-only archive. No new posts or registrations. Privacy Page
Hardware

need help with security for wireless connections

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I live in an apartment. My wife & I each have a computer with a router that allows both of us to connect to the internet. However I can see other networks that apparently are apartments nearby. Most, not all, have a lock icon next to their network name. There is not a lock next to our network name. I fear my network is absolutely open for anyone to access. How in the world do I get this fixed and secure? Many thanks for any help you can give.
what make and model router is it? if you've still got the manual look in the section about setting up wireless security basically you've got 3 options….WEP, WPA, and MAC filtering WEP and WPA are both encryption schemes that require you to enter a "passcode" to connect to the router wirelessly…the setup of either is pretty simple… MAC filtering is a method of access control that involves you making a list of acceptable MAC addresses (the hardware id of your wireless card that cannot be changed) that the router will look for…if it sees something that doesn't match that list…it get's blocked i'd suggest using a combination of either WEP or WPA as well as MAC filtering also turning off the SSID broadcast is a good idea…this means that your wireless router won't advertise it's name…so anyone wanting to connect will have to know the name…so change the name of the network too
ftp://ftp.dlink.com/Gateway/di624_revC/Ma…_manual_106.zip there's a link directly to the manual…

page 13 on the PDF is the first section that mentions security (basic info about what's available)

page 25 mentions the use of MAC filtering


so basically…follow the steps for connecting to and logging into the router

then navigate to the screen shown on page 13 of the manual…you'll want to change the SSID to something that you can use to differentiate this network from other networks (i don't see an option to not broadcast the SSID…but i'll keep looking), ..then you're going to want to click the radio button to enable WEP…change the encrytpion level to 128…leave the key type as HEX…it looks like this router DOESN"T automatically supply the key…so go here to generate a hex key for your system…that's it for that section

now you can initiate a wireless connection on one of the machines…..when you locate your wireless network in the list…connect to it…it will ask for that HEX WEP key that you just put into the router…enter that and you should be connected

next go to page 25 of the manual and navigate to the screen shown…this will allow you to set up MAC filtering….choose the "allow MAC addresses listed below" option….you should see a list at the bottom of all the MAC addresses that y our router knows about…these should be the ones from your computers….to double check…go to each machine that's connected to the router and press the start button, then run, then type "cmd" (without the quotes) then type "ipconfig /all" (again…no quotes) in the command window that opens up..the section that says "physical address" is the MAC address of that interface
First, MAC filtering will not put a "lock" icon on your network as viewed by any scanner. Only WEP or WPA will do this.
Second, MAC filtering has to be one of the worst security measures you could implement. It would take me roughly fifteen seconds to identify and spoof a MAC address on your wireless LAN.

If your network adapters and your router both support WPA2 – use it.
If you have to use WEP, use 128-bit encryption and a long key.

The Six Dumbest Ways to Secure a Wireless LAN
George Ou
http://blogs.zdnet.com/Ou/index.php?p=43

First, MAC filtering will not put a "lock" icon on your network as viewed by any scanner. Only WEP or WPA will do this.
Second, MAC filtering has to be one of the worst security measures you could implement. It would take me roughly fifteen seconds to identify and spoof a MAC address on your wireless LAN.

while i do not dissagree that MAC filtering is pretty weak….i DO disagree with the suggestion to ignore it completely…#1 yes..it's easy to spoof a MAC…IF you know how to do it and IF there aren't other unprotected networks around that are easier to connect to….the vast majority of computer users DON"T know how to spoof a MAC address…and the ones that do…probably know how to crack at least a WEP key


also from the manual….the OPs router seems to only support WEP (didn't see settings for WPA or WPA2)
when I open the D-Link screen on my computer by going to http://192.168.0.1 …. I don't get the same screen that shows on page 13 of the Di624 manual. I can see in the manual that the WIRELESS button has been pressed. When I click the WIRELESS button on my screen I get a page that looks like this: Wireless Settings ……… These are the wireless settings for the AP (Access point) portion. Wireless Radio - On Off
SSID: and the name I have designated for my home network is listed here
Channel: 6 Auto select
Super G Mode without Turbo (selected in the drop down window)
Extended Range Mode - Disabled has been selected
WMM Function - Disabled has been selected
802.11g only mode - Disabled has been selected
SSID Broadcast - Enabled has been selected
Security - Disable has been selected from the drop down window
Enabling extended range mode will not allow to disable SSID Broadcast mode
Super G with Dynamic Turbo only operates in Channel 6.

That's all it says.

SSID Broadcast - Enabled has been selected
Security - Disable has been selected from the drop down window

there's the bit you want to concentrate on

i suggest turning off the SSID broadcast….however this means you'll need to remember what the wireless network is called to connect

the security drop down menu should have some things in it…could you list what those things are?
the Security drop down menu has the following options: disable WEP WPA WPA2 Plus I clicked the "Disabled" radio button next to SSID Broadcast.
When I clicked the drop down window next to "Security" and saw the WEP option I then clicked that. And the exact same screen opened up that was on pg 13 of the manual. I then selected: Authentication: shared key WEP Encription: 64 bit Key Type: ASCII Key 1: xxxxxx And I think this is all I can do right now. Except of course check on my wife's laptop to see if she can access the network.
well…the 128 bit key would be better than the 64 bit and if your computers' wireless cards support wpa that would be better than WEP and IF your computers' wireless cards support WPA2 then that would be better than WPA…but we'd need to know what make and model wireless cards you've got

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI