Try to reduce the uncertainty of WiFi or any other type of networking technology in just 10 points is a utopia, but it never hurts to use this list as a basis in our facilities.
Rule 1: Discretion
Avoid posting unnecessarily the presence of WiFi installation. Be sure to change the SSID of your equipment and not leave the factory next. Also if possible, disable the beacon (beacon) SSID. Try
install antennas access point (AP) and levels of computing power to prevent the arrival of the signal to areas where coverage is not desired or required.
Rule 2: Protect cloning
Today it is easy to "convert" a device for presenting himself as another device (impersonation). Lost or stolen devices are also a threat. Filtering by address Media Access Control (MAC) is an authentication method that can be used individually. It must always be accompanied by a separate authentication method of the devices, such as usernames and passwords, existing network directories or other authentication schemes.
Rule 3: Encrypt the data privacy Want
is normal. For this, the wirelessly transmitted data must be encrypted. Basic encryption provided by WiFi, called WEP, is relatively weak in all its forms and its maintenance is costly and inefficient. Complementary to this method is advisable to use technologies proven effective in networks such as IPSec with 3DES encryption. Always try to use standard security frameworks that facilitate interoperability.
Rule 4: Filter data
This rule is actually not unique to wireless networks, but is useful remember this: Limit and monitor you can go to the wireless network traffic. A firewall is the ideal tool for this task. If the wireless network will be used for a particular purpose, such as access to specific enterprise resources, then configure packet filters to data from the wireless network can not reach unwanted places.
Rule 5: Limit physical access to the access points
Avoid deploy APs on desks or other places that can be easily accessed. Visitors curious, unscrupulous or careless employees can easily move, replace or reset the APs. Security can not be guaranteed if not careful here.
Rule 6: Keep your eyes open
actively monitors the settings of the AP. It is not sufficient to configure an AP correctly. Once configured, the AP must remain properly configured. Consider that it is easy for someone to run a hardware reset on an AP that is placed on a desk or ceiling. To actively monitor the configuration of the AP, can ensure that the AP is automatically reconfigured to such events that may occur.
Rule 7: Check
clandestine teams
In many places the APs can be easily installed by employees and outsiders and threatening against the policies of network security. Maintain an active policy of WiFi transmissions detection rate with sniffer software is a critical operational requirement for security
Rule 8: Extreme care if you do not use access points
In a wireless network operating in Ad Hoc mode ( or peer to peer), an attacker can leak out and gain access to the grid by using a legitimate customer point of entry cone. Products known as personal firewall or firewall software complemented with other network management tools to actively track and manage the client before allowing access through wireless LAN is a good prevention.
Rule 9: Control the use of bandwidth
Failure to comply with this rule exposes it to Denial of Service (DoS) or an inefficient use of bandwidth in the best. There are several ways to regulate the use of bandwidth but keep in mind that most basic WiFi equipment give no solution so far. This is not really a problem if you put this functionality in other appropriate parts of its network.
Rule 10: Time is money
Whenever possible, management implements policies in real time. On many occasions WiFi networks are widespread. For example whole covering campus and incorporate multiple global sites. Security policies (eg lists of valid users and access rights) to change course. These changes should be reflected in real time via the wireless network to reduce the window of opportunity for the intrusion, and more importantly, facilitate the immediate closure of security breaches detected.
Source ...
0 comments:
Post a Comment