Skip to main content
Home Forums Network Security Considerations — #2 Network Security Considerations — #2
Post #2 by Brit Ben
Post
Quote:
Originally posted by tioga:
I have a new linksys wireless access point/router with an ethernet connection to a iMac 350 running OS 9.2.2., and a wireless connection to a windoze 98 PC.

Before I start changing the security stuff on this network I have some questions:

1. Do I want or need the ZoneAlarm Pro software and PC Cillin offered on the linksys site? If so, is it compatible with both the Mac and PC?

2. Do I want to enable WEP and, if so, what settings would be reasonable? Though not obsessed with security, I'd like to minimize unauthorized intrusions and hacking.

3. Any other security measures/considerations for a new network (run by an utterly inexperienced administrator)?

Thanks in advance for the advice, concerns, recommendations, etc.


I'm starting by assuming that you are a home user, at home. If you're running this on a corporate lan, err, you deserve whatever happens (job-wise)

1. Skipped, I see no use in either of these.

2. Yes, its there, and if nothing else will help deter the casual stumbler from accessing your network. If a hacker wants in, they're in regardless of WEP. There are plenty of tools on the internet to assist, and I have demonstrated these at meetings to prove they work, complete with reading someone else's email out loud to much laughter.

3. If you're parranoid, and money is irrelevant, get a small firewall/vpn devide, phyically attached to the service provider ethernet port, and then run absolutely everything wireless on the "insecure" side, with a VPN client running on your PC. This part stops people sniffing your traffic on the wireless lan. You then need to tell your router, or the firewall not to forward any traffic that doesn't originate from a VPN client. This stops someone stealing your bandwidth. Finally, you need to configure the firewall to prevent people doing bad things to your network. These boxes will set you back about $300, and a good start is sofaware (www.sofaware.com). I am truly paranoid, and run a full blown checkpoint firewall-1 implementation at home. The logs from this device alone make for all the reference I need when presenting on network security. (I'm biased since I am a Checkpoint Certified Security Engineer)

Just because you think you're paranoid, doesn't mean that they *aren't* watching you.
Ben.
mp.ls