|
|
|
12-22-2012, 09:42 AM
|
Postid: 182215
|
|
Registered User
Join Date: Jul 2001
Posts: 363
|
Wireless option needed
I need to add a wireless component to my LAN, but because of PCI compliance issues, I need to find something secure. (That may not exist, but I need to try!)
Anyone have any good options for me to check out? I'm basically looking for a router I can plug into my current network & extend it to a couple of wireless devices (iPod, printer) or one I can just add by itself, but keep secure.
Thanks!
|
|
|
12-22-2012, 12:16 PM
|
Postid: 182216
|
|
Site Owner
Join Date: Nov 2003
Location: Orlando, FL
Posts: 1,141
|
Re: Wireless option needed
Just about any router with WPA2 is about as secure as you can get right now if you are using WiFI in general.
http://www.wi-fi.org/discover-and-learn/security
Always make sure you change the default SSID, and admin passwords for the router as soon as you get one.
Also, many routers now have a MAC Address Whitelist feature, in which you can list all the devices in you location that you want to connect, and it will refuse connections to all others regardless of if they have the right WPA2 credentials. Of course, the MAC Address can be spoofed, but at least it is another layer of protection.
I also found these if you haven't already seen:
http://revolutionwifi.blogspot.com/2...hieve-pci.html
https://www.pcisecuritystandards.org...Guidelines.pdf
John
__________________
Klaatu: I won't resort to threats, Mr. Harley. I merely tell you the future of your planet is at stake.
The Day the Earth Stood Still (1951)
|
|
|
12-26-2012, 03:29 PM
|
Postid: 182222
|
|
Site Owner
Join Date: Jul 2001
Location: where the boat is: Chesapeake Bay
Posts: 722
|
Re: Wireless option needed
A wireless component of a LAN that includes customer credit card data is a bad idea. You need much more than just a wireless router. You're going to need a serious firewall, and put the wireless bits between the inside network and your Internet connection.
You have a huge liability if you don't do this right.
__________________
dave
S/V Auspicious
lying Annapolis MD
On the eighth day there were regular expressions.
--me
|
|
|
12-26-2012, 04:10 PM
|
Postid: 182223
|
|
Systems Administrator
Join Date: Aug 2001
Location: Orlando, FL
Posts: 2,986
|
Re: Wireless option needed
It is certainly possible to do wifi securely.
WPA2 with radius authentication is probably the best choice between security and convenience (the advantage of the radius authentication is that each user has their own key rather than just using a single key for everyone).
Personally, I like to run OpenVPN over my wifi. It is faster than WPA2, is much easier to upgrade if a vulnerability is ever found, and it is what I would use if I was on someone else's wifi and therefore I can use the same configuration whether my netbook and phone are at home or anywhere else.
__________________
Kevin
|
|
|
12-26-2012, 05:07 PM
|
Postid: 182224
|
|
Registered User
Join Date: Jul 2001
Posts: 363
|
Re: Wireless option needed
I already meet my PCI compliance, both the annual review & monthly scans, so my LAN is configured properly for compliance. I will use WPA2 security, and I see that the AP I bought does have RADIUS support as well as MAC address filtering. There are only going to be 2 devices accessing the wireless signal (an iPod and a wireless printer) so it should be easy to monitor & control.
Thanks for the advice & links, all very helpful!
|
|
|
12-26-2012, 05:19 PM
|
Postid: 182225
|
|
Systems Administrator
Join Date: Aug 2001
Location: Orlando, FL
Posts: 2,986
|
Re: Wireless option needed
Don't trust the MAC address filtering. It is trivial for an attacker to set whatever MAC address they want.
It sounds like you just want plain WPA2. You don't need the Radius authentication. The main purpose of that is so that each user has their own key so that when someone leaves you just delete their access rather than having to give everyone who remains a new key or staying with the key that someone who doesn't work there anymore knows.
__________________
Kevin
|
|
|
12-26-2012, 06:39 PM
|
Postid: 182226
|
|
Registered User
Join Date: Jul 2001
Posts: 363
|
Re: Wireless option needed
OK, sounds good, thanks again!
|
|
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 visitors)
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT -4. The time now is 12:25 AM.
|
| |
|
|
|