Wireless Router Security Who Am I? Tom Tirrell BSEE Computer Engineering, UofM Ann Arbor MSEE Computer Engineering/Communication Theory, Wayne State, Detroit Applications of computers in industry was my profession Networking computers is my hobby
Wireless Router Security Home Wireless Networks Or What I Won’t be Talking about Today Network Interface Modem Wireless Router Signal from ISP Satellite Radio Fiber Optic Cable Co-axial Cable Outside “Box” Satellite Dish I3812 NID (fiber) Green Metal Box NID to Modem wires Coax Telephone wire 2-Wire Modem/Router Cable Modem Telephone Modem LAN Cable
Wireless Router Security Home Wireless Networks Part 2 Or What I will be Talking About Today 2-Wire Modem/Router Wireless Router
Wireless Router Security An inSSIDer view of Wireless Networks
Wireless Router inSecurity An inSSIDer view of Wireless Networks
Wireless Router inSecurity This House is Unlocked
Wireless Router Security Authentication Protocols Open – not an option, anyone can connect Shared – one step up from really bad, requires a key to log on WEP – Fair, better than nothing, but “gone in 60 seconds” WPA– Better, still has similar weaknesses as WEP WPA2 – Best, state of the art, for now
Wireless Router Security Five Necessary Steps and One Cool Idea Go to the router configuration page in your browser: xxx.xxx 1.Set a unique password for router configuration. 2.Set a unique Network Name (SSID) 3.Set Security or Authentication Type to WPA2-Personal(PSK)-AES 4.Set a unique Key as large as is convenient. 5.Disable Wi-Fi Protected Setup (WPS) 6.Disable SSID Broadcast
Wireless Router Security There is a tradeoff between compatibility, convenience and levels of security. There is no tradeoff between whether or not to use security. Even older and less secure methods are better than no security at all. Modern methods of encryption may not be compatible with older devices. Check the manuals on your network devices to see what levels of security they can use. Select the highest security level that you can and then see if all the devices on your network can still connect. If not, back down a level until everything works. The Tradeoff
Wireless Router Security Linksys WRT54g Wireless Router You can download manuals for Linksys/Cisco routers at this URL: aspx?pid=80&vw=1&articleid=22501
Wireless Router Security Linksys WRT54g Wireless Router In your browser, go to
Wireless Router Security Linksys WRT54g Wireless Router You will be asked for a User Name and Password. If you know what they are, enter them now. If you don’t know it, try the default user name and password which are: Default User Name : blank Default Password: admin
Wireless Router Security Linksys WRT54g Wireless Router If none of these work, press the “reset” button on the back of the router.
Wireless Router Security Linksys WRT54g Wireless Router
Disable Wi-Fi Protected Setup (WPS)
Linksys WRT54g Wireless Router Network Name (SSID)
Linksys WRT54g Wireless Router Network Name (SSID)
Linksys WRT54g Wireless Router Security Mode
Linksys WRT54g Wireless Router Encryption
Linksys WRT54g Wireless Router Passphrase/Wireless Key
Linksys WRT54g Wireless Router Router Password
Wireless Router Security ATT 2-Wire Router Configuration In your browser, go to
ATT 2-Wire Router Configuration Router Configuration Web Page
ATT 2-Wire Router Configuration Wi-Fi Protected Setup??
ATT 2-Wire Router Configuration Saving Settings, system Password.
ATT 2-Wire Router Configuration Default System Password
ATT 2-Wire Router Configuration System Password Failed!
ATT 2-Wire Router Configuration Password Hint
ATT 2-Wire Router Configuration Resetting You System Password
ATT 2-Wire Router Configuration Password Accepted, Configuration Saved
Wireless Router Security Network Name (SSID)
Wireless Router Security SSID Broadcast
ATT 2-Wire Router Configuration Enable Wireless Security
ATT 2-Wire Router Configuration Authentication/Encryption Type
ATT 2-Wire Router Configuration Wireless Key
ATT 2-Wire Router Configuration Wireless Key
ATT 2-Wire Router Configuration Save Your Settings
Wireless Router Security SSID Broadcasting Disabled
Wireless Router Security SSID Broadcasting Disabled
Wireless Router Security SSID Broadcasting Disabled
Wireless Router Security I Can’t Do this! If you can’t secure your network as described above, there are still choices you can make. In order of increasing cost: 1.Turn off your router when you aren’t using it. 2.Use only wired connections. Disable the wireless access point. All wireless routers have at least a couple of wired LAN inputs. 3.Don’t share sensitive files across the network. Don’t use shared disk drives or folders. 4.Update your wireless adapter to one that can use a better security method.
Wireless Router Security References 1.Wikipedia articles on WEP, WPA, Wireless Security, Wi-Fi Protected Access and the IEEE standard 2.The Home WLAN website at WPA.htmlhttp:// WPA.html 3.“Applied Cryptography”, 2 nd edition, by Bruce Schneier, Wiley & Sons, “Principles of Communication: Systems, Modulation and Noise”, Ziemer and Tranter, Houghton Mifflin, Institute of Electrical and Electronic Engineers (IEEE) Wireless Network Standard “Networking Bible”, Barrie Sosinsky, Wiley, “Cryptography Engineering”, Nies Ferguson, Bruce Schneier, Tadayoshi Kohno, Wiley Publishing, 2010
Wireless Router Security Wireless Modes network standards protocol Release [6] [6] Freq. (GHz) Bandwidth (MHz) Data rate Data rate per stream (Mbit/s) [7] [7] Allowable MIMO streams MIMO Modulation Approximate indoor range [citation needed]citation needed Approximate outdoor range [citation needed]citation needed (m)(ft)(m)(ft) —Jun , 21DSSSDSSS, FHSSFHSS aSep , 9, 12, 18, 24, 36, 48, 54 1OFDM [A] [A] ——5,00016,000 [A] [A] bSep , 111DSSS gJun , 9, 12, 18, 24, 36, 48, 54 1 OFDMOFDM, DSSS DSSS nOct / , 14.4, 21.7, 28.9, 43.3, 57.8, 65, 72.2 [B] [B] 4OFDM [8] [8] 40 15, 30, 45, 60, 90, 120, 135, 150 [B] [B] [8 [8
Wireless Router Security 2.4 GHz Channels Spread Spectrum modulation causes the radio energy to spread across several channels. Due to the high frequency, short distance, this is usually not a problem You can select a set of non-overlapping channels when you have several routers The most common is channels 1, 6 and 11 as shown here. In North America, only channels 1-11 are used