Welcome Guest. | Log In| Register | Membership Benefits

  • Email this page E-mail
  • |  Print Print
  • |   Bookmark and Share
  • icon

How To Secure Your Home Wireless Network: Part V


The fifth segment of of Chapter 2 from the book 'Home Network Security Simplified,' which details how to make sure that your home PC wireless network is secure



Here are Part I, Part II, Part III, and Part IV.

WPA Encryption Example
To compare enabling WEP encryption to how WPA encryption is enabled, let's take an example of WPA (this time, we pick 8F37ahr43K as our example pre-shared key). Enabling WPA encryption is a lot like enabling WEP encryption, except you must make one additional decision: You must decide how long an encryption key will be allowed to be used before a new key is assigned. The lower the value, the less time a hacker has to try to "crack" the key. For example if you set the value to 1800 seconds (which is 30 minutes for you nonmath majors), a key is used for 30 minutes and then the wireless router and wireless NIC create a new key. If a hacker "cracks" the key within 30 minutes (which is pretty tough to do), the key will only be valuable for the remainder of the 30 minutes before it is switched to an entirely new key, and the hacker would have to start all over.

First, here's an example of setting up WPA on the wireless router:
  1. On the Wireless Security subtab again (See Figure 20), select Pre-Shared Key on the line labeled Security Mode. (On some Linksys products, the selection is called WPA Pre-Shred Key).
  2. Select either TKIP (For WPA1) or AES (for WPA2). If your wireless router and all wireless NICs support AES mode, select it because it is more secure. If any of them do not, select TKIP. You cannot configure some with TKIP and some with AES.
  3. On the line labeled WPA Shared Key, enter the pre-shared key you made up (in our example, 8F37ahr43K).
  4. On the line labeled Group Key Renewal, enter the number of seconds that you want the key to be used before changing it (See Figure 20). We chose 1800 (which is 30 minutes) for this example.
  5. Click Save Settings.


Figure 20. Enabling WPA Encryption on the Wireless Router

Very Important: So how long should you set the key renewal period for? There is no great answer, although if you have the value set too low (1 to 2 minutes, for example) it could cause connectivity issues for some NICs. We recommend following manufacturer recommendations (or defaults).

With WPA, we also then need to tell the super-secret password to each of the devices with wireless cards so that they know how to decode the conversations with the wireless router. Here is an example for a Linksys WPC54GS Wireless-G PCMCIA laptop NIC:

  1. Launch the WLAN Monitor Utility, similar to the example earlier where we enabled WEP on a USB-connected wireless NIC.
  2. For the Encryption Method, choose Pre-Shred Key (See Figure 21). (On some Linksys products it is called WPA Pre-Shared Key). Click Next.
  3. On the line labeled Encryption, select TKIP (for WPA1) or AES (for WPA2). On the line labeled Passphrase, enter the key phrase you made up (See Figure 22). In our example, we chose 8F37ahr43K. Click Next.

  4. Figure 21. Choose WPA Pre-Shared Keyr


    Figure 22. Enter the WPA Passphrase

  5. In the confirmation window that appears, double-check that Encryption is set to Pre-Shared Key, and then click Save (See Figure 23).

  6. Figure 23. Conform New WPA Settings

  7. Click the Link Information tab. If you entered everything correctly, the Signal Strength and Link Quality should reappear as green bars (See Figure 24).

    If not, you probably entered something incorrectly.


Figure 24. You are Successfully Connected!

Continue setting up each NIC with the super-secret password, each time checking to see whether the connection is reestablished to the wireless router.

Troubleshooting Tips: Wireless Encryption
If any of the computers do not reestablish communication, items to check include the following:

  • Make sure the encryption method chosen on both the wireless router and all wireless NICs is the same.
  • Make sue the passphrase for WEP key generation (or WPA) is entered exactly the same on both the wireless router and all wireless NICs. The passphrase is case sensitive, which means that "p" is different than "P." Take care to make sue the entered phrase matches exactly, including lowercase and uppercase letters.
  • If all else fails, disable encryption on both the wireless router and all wireless network adapters, reverify the connections without encryption turned on, and then start the encryption setup from scratch.
  • Read the Troubleshooting and Wireless Security chapters in the installation manuals that came with the Linksys wireless router and Linksys wireless NICs.


Page 2: 
1 | 2 Next Page »


Subscribe to RSS


Advertisement






Get InformationWeek in Print

Apply for a free 52-week subscription to InformationWeek (a $199 value)



NOTE: Offer valid for U.S., U.S. possessions, & Canada only.