FutureQuest, Inc. FutureQuest, Inc. FutureQuest, Inc.

FutureQuest, Inc.
Go Back   FutureQuest Community > General Site Owner Support (All may read/respond) > General Computing
User Name
Password  Lost PW

Reply
 
Thread Tools Search this Thread Display Modes
Old 12-22-2012, 09:42 AM   Postid: 182215
Buck
Registered User

Forum Notability:
328 pts: An Honor To Be Around
[Post Feedback]
 
Join Date: Jul 2001
Posts: 363
Wireless option needed

I need to add a wireless component to my LAN, but because of PCI compliance issues, I need to find something secure. (That may not exist, but I need to try!)

Anyone have any good options for me to check out? I'm basically looking for a router I can plug into my current network & extend it to a couple of wireless devices (iPod, printer) or one I can just add by itself, but keep secure.

Thanks!
Buck is offline   Reply With Quote
Old 12-22-2012, 12:16 PM   Postid: 182216
johnfl68
Site Owner
 
johnfl68's Avatar

Forum Notability:
975 pts: Dignified Competence!
[Post Feedback]
 
Join Date: Nov 2003
Location: Orlando, FL
Posts: 1,141
Re: Wireless option needed

Just about any router with WPA2 is about as secure as you can get right now if you are using WiFI in general.

http://www.wi-fi.org/discover-and-learn/security

Always make sure you change the default SSID, and admin passwords for the router as soon as you get one.

Also, many routers now have a MAC Address Whitelist feature, in which you can list all the devices in you location that you want to connect, and it will refuse connections to all others regardless of if they have the right WPA2 credentials. Of course, the MAC Address can be spoofed, but at least it is another layer of protection.


I also found these if you haven't already seen:

http://revolutionwifi.blogspot.com/2...hieve-pci.html

https://www.pcisecuritystandards.org...Guidelines.pdf

John
__________________
Klaatu: I won't resort to threats, Mr. Harley. I merely tell you the future of your planet is at stake.
The Day the Earth Stood Still (1951)
johnfl68 is offline   Reply With Quote
Old 12-26-2012, 03:29 PM   Postid: 182222
skolnick
Site Owner
 
skolnick's Avatar

Forum Notability:
117 pts: Helpful Contributor
[Post Feedback]
 
Join Date: Jul 2001
Location: where the boat is: Chesapeake Bay
Posts: 722
Re: Wireless option needed

A wireless component of a LAN that includes customer credit card data is a bad idea. You need much more than just a wireless router. You're going to need a serious firewall, and put the wireless bits between the inside network and your Internet connection.

You have a huge liability if you don't do this right.
__________________
dave

S/V Auspicious
lying Annapolis MD

On the eighth day there were regular expressions.
--me
skolnick is offline   Reply With Quote
Old 12-26-2012, 04:10 PM   Postid: 182223
 Kevin
Systems Administrator
 
Kevin's Avatar
 
Join Date: Aug 2001
Location: Orlando, FL
Posts: 2,986
Re: Wireless option needed

It is certainly possible to do wifi securely.

WPA2 with radius authentication is probably the best choice between security and convenience (the advantage of the radius authentication is that each user has their own key rather than just using a single key for everyone).

Personally, I like to run OpenVPN over my wifi. It is faster than WPA2, is much easier to upgrade if a vulnerability is ever found, and it is what I would use if I was on someone else's wifi and therefore I can use the same configuration whether my netbook and phone are at home or anywhere else.
__________________
Kevin
Kevin is offline   Reply With Quote
Old 12-26-2012, 05:07 PM   Postid: 182224
Buck
Registered User

Forum Notability:
328 pts: An Honor To Be Around
[Post Feedback]
 
Join Date: Jul 2001
Posts: 363
Re: Wireless option needed

I already meet my PCI compliance, both the annual review & monthly scans, so my LAN is configured properly for compliance. I will use WPA2 security, and I see that the AP I bought does have RADIUS support as well as MAC address filtering. There are only going to be 2 devices accessing the wireless signal (an iPod and a wireless printer) so it should be easy to monitor & control.
Thanks for the advice & links, all very helpful!
Buck is offline   Reply With Quote
Old 12-26-2012, 05:19 PM   Postid: 182225
 Kevin
Systems Administrator
 
Kevin's Avatar
 
Join Date: Aug 2001
Location: Orlando, FL
Posts: 2,986
Re: Wireless option needed

Don't trust the MAC address filtering. It is trivial for an attacker to set whatever MAC address they want.

It sounds like you just want plain WPA2. You don't need the Radius authentication. The main purpose of that is so that each user has their own key so that when someone leaves you just delete their access rather than having to give everyone who remains a new key or staying with the key that someone who doesn't work there anymore knows.
__________________
Kevin
Kevin is offline   Reply With Quote
Old 12-26-2012, 06:39 PM   Postid: 182226
Buck
Registered User

Forum Notability:
328 pts: An Honor To Be Around
[Post Feedback]
 
Join Date: Jul 2001
Posts: 363
Re: Wireless option needed

OK, sounds good, thanks again!
Buck is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 visitors)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:25 AM.


Running on vBulletin®
Copyright © 2000 - 2019, Jelsoft Enterprises Ltd.
Hosted & Administrated by FutureQuest, Inc.
Images & content copyright © 1998-2019 FutureQuest, Inc.
FutureQuest, Inc.