Re: Secure and unsecure install problem

Morgan Davis <[email protected]>
Newsgroups gmane.network.wireless.seattle.general
Message-ID <[email protected]>
You're sending unencrypted traffic to the internet?

The goal of WEP here is to prevent the guests from sniffing the
traffic between machines on the office network and to prevent them
from directly accessing/attacking them by preventing them from
associating.

Anything you send out to the internet is already insecure and subject
to sniffing/spoofing. I personally make sure anything I care about is
encrypted at the network, transport or application layer (POP3/S,
SMTP/S, S/MIME, SSL, SSH, IPSec). My general web browsing isn't all
that interesting nor sensitive.


On Wed, 02 Mar 2005 15:20:55 -0800, Ken Caruso <[email protected]> wrote:
> Comment in line.
> 
> On Wed, 2005-03-02 at 15:16 -0800, Morgan Davis wrote:
> >           DSL
> >             |
> >             | (wan port of router1 to DSL))
> >             |
> > ROUTER1 (open)
> >  |  |  |  |  |
> >             |
> >             |
> >             |  (wan port of router2 to switch port of router1)
> >             |
> > ROUTER2  (WEP/WPA)
> >  |  |  |  |  |
> >
> 
> I Connect to Router1 via the wireless ( I am a guest). I arp spoof
> (http://www.monkey.org/~dugsong/dsniff/ ) router2 into thinking that I
> am default gateway for that network. I am now intercepting all of
> router2's traffic for sniffing, man in the middle attacks etc...
> 
> >
> > All of the users whom have the key can associate or plug into ROUTER2,
> > they will have access to each other and will NAT through to the switch
> > side of ROUTER1, where they can NAT again to the internet. Guests will
> > be able to connect to ROUTER1 eith wired or wirelessly, and they can
> > get access to the internet, but they will not be able to go backward
> > through router2 to get to the office equipment or users. The only
> > thing that needs to be changed on router2 after enabling encryption is
> > the network address (so it doesn't overlap with router1). It's cheap,
> > simple and provides protection of the internal users from the guests.
> >
> >
> > On Wed, 2 Mar 2005 14:54:24 -0800, Casey Halverson
> > <[email protected]> wrote:
> > > I don't understand what segmenting internal users and external users on
> > > two different access points will accomplish.  All the hosts will be able
> > > to interact through your wired segment.  There is no security benefit in
> > > this design.
> > >
> > >
> > > > -----Original Message-----
> > > > From: [email protected]
> > > > [mailto:[email protected]] On Behalf Of Scott Bradford
> > > > Sent: Monday, February 28, 2005 11:07 AM
> > > > To: [email protected]
> > > > Subject: Secure and unsecure install problem
> > > >
> > > > Hello all... need some suggestions
> > > >
> > > > I have an office environment that I want to have a "closed"
> > > > wireless system
> > > > for our laptops and an "open" wireless for guests.   I want
> > > > them to be able
> > > > to associate into it without me going in and babysitting them
> > > > all the time.
> > > > Only way I can think to do this is.....
> > > >
> > > > dsl - wired router  -  ap1    secure
> > > >                           -  ap2   unsecure
> > > >
> > > > Since I can set the IPs, the "wired"  router will "block" one
> > > > AP from the
> > > > other.   Set one to channel 1, dhcp on full blast...  set the
> > > > second to
> > > > channel 11, turn on web, and go on with my life
> > > >
> > > > Comments or suggestions appreciated
> > > >
> > > >
> > > > _______________________________________________
> > > > Talk mailing list
> > > > [email protected]
> > > > http://seattlewireless.net/mailman/listinfo/talk
> > > >
> > > _______________________________________________
> > > Talk mailing list
> > > [email protected]
> > > http://seattlewireless.net/mailman/listinfo/talk
> > >
> > _______________________________________________
> > Talk mailing list
> > [email protected]
> > http://seattlewireless.net/mailman/listinfo/talk
> 
>
_______________________________________________
Talk mailing list
[email protected]
http://seattlewireless.net/mailman/listinfo/talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.