|
[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]
|
Re: [PLUG] OT: Large Wireless Network on the Cheap
|
- From: Jason Costomiris <jcostom@gmail.com>
- To: plug@lists.phillylinux.org
- Subject: Re: [PLUG] OT: Large Wireless Network on the Cheap
- Date: Thu, 14 Oct 2004 19:00:18 -0400
- Domainkeys-signature: a=rsa-sha1; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:reply-to:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:references; b=MNFzCyNrTlRFNCUgTLHHlS+sszIaDw7XnhjFaA5biCW2eed363cIau8soMjIpvnWWK5v8TEaJUSwzK+mma0+noU3wT8skS8+aLekUFcAD5bENzQS4SYJ6TNrkuWiSx/ilaW1SHv1WRLnlleY/61dN2LeBj7ChD7EFCzjKKKweTU
- Reply-to: plug@lists.phillylinux.org
- Sender: plug-admin@lists.phillylinux.org
On Thu, 14 Oct 2004 12:46:01 -0400, Paul <gyoza@comcast.net> wrote:
> Crackers connecting to the access point could attack the clients
> directly through their unencrypted channels. I'm assuming that most
> clients do not have their own firewalls. (Is that a reasonable
> assumption?) The access point would have to restrict access to the VPN
> port only to protect against that. Again, there's that trade-off
> between convenience and security since non-VPN clients would not be able
> to use the network.
Not necessarily.. Let's see...
Linux clients - iptables
Mac OS X clients - ipfw (configured with a few check boxes in the
Network Control Panel)
Windoze - any personal firewall
*BSD - ipfw/pf/etc.
Did I miss any? Your VPN should be configured to force all traffic
over the VPN, and with a firewall in place on the WLAN side of the
network, your firewall shouldn't allow inbound connections to the
system. Not ideal, but it would work.
You could step it up a bit with MAC filtering, but you know how far
that gets you..
--j
--
Want a gmail invite? Help me get a free iPod for my wife.
http://www.freeiPods.com/default.aspx?referer=9913261
No cost to you, free iPod for her, gmail invite for you.
___________________________________________________________________________
Philadelphia Linux Users Group -- http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion -- http://lists.phillylinux.org/mailman/listinfo/plug
|
|