Jason Costomiris on 14 Oct 2004 23:01:02 -0000


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] OT: Large Wireless Network on the Cheap

  • From: Jason Costomiris <jcostom@gmail.com>
  • To: plug@lists.phillylinux.org
  • Subject: Re: [PLUG] OT: Large Wireless Network on the Cheap
  • Date: Thu, 14 Oct 2004 19:00:18 -0400
  • Domainkeys-signature: a=rsa-sha1; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:reply-to:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:references; b=MNFzCyNrTlRFNCUgTLHHlS+sszIaDw7XnhjFaA5biCW2eed363cIau8soMjIpvnWWK5v8TEaJUSwzK+mma0+noU3wT8skS8+aLekUFcAD5bENzQS4SYJ6TNrkuWiSx/ilaW1SHv1WRLnlleY/61dN2LeBj7ChD7EFCzjKKKweTU
  • Reply-to: plug@lists.phillylinux.org
  • Sender: plug-admin@lists.phillylinux.org

On Thu, 14 Oct 2004 12:46:01 -0400, Paul <gyoza@comcast.net> wrote:
> Crackers connecting to the access point could attack the clients
> directly through their unencrypted channels.  I'm assuming that most
> clients do not have their own firewalls.  (Is that a reasonable
> assumption?)  The access point would have to restrict access to the VPN
> port only to protect against that.  Again, there's that trade-off
> between convenience and security since non-VPN clients would not be able
> to use the network.

Not necessarily..  Let's see...

Linux clients - iptables
Mac OS X clients - ipfw (configured with a few check boxes in the
Network Control Panel)
Windoze - any personal firewall
*BSD - ipfw/pf/etc.

Did I miss any?  Your VPN should be configured to force all traffic
over the VPN, and with a firewall in place on the WLAN side of the
network, your firewall shouldn't allow inbound connections to the
system.  Not ideal, but it would work.

You could step it up a bit with MAC filtering, but you know how far
that gets you..

--j


-- 
Want a gmail invite?  Help me get a free iPod for my wife.
http://www.freeiPods.com/default.aspx?referer=9913261
No cost to you, free iPod for her, gmail invite for you.
___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug