Gentoo Archives: gentoo-user

From: Saphirus Sage <saphirus497@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Locking down a wireless network
Date: Thu, 29 Jan 2009 21:02:19
Message-Id: 49821955.8030700@gmail.com
In Reply to: Re: [gentoo-user] Locking down a wireless network by Paul Hartman
1 Paul Hartman wrote:
2 > On Thu, Jan 29, 2009 at 2:39 PM, Grant <emailgrant@×××××.com> wrote:
3 >
4 >>>> My Gentoo router's wireless network is encrypted via WPA and doesn't
5 >>>> DHCP. I'd like to take this a step further in case my WPA key gets
6 >>>> hacked. Can I issue only certain IPs to certain MAC addresses?
7 >>>>
8 >>>> Does WPA2 require hardware support?
9 >>>>
10 >>> I don't think so. It should just be a driver/firmware update if you've
11 >>> got some device that supports WPA and not WPA2. The AES encryption of
12 >>> WPA2 requires a little more hardware power than WEP or WPA normally
13 >>> uses, but I don't think it needs any special chip or anything like
14 >>> that.
15 >>>
16 >>> You can also do VPN over your wifi connection, and require it for
17 >>> access to the rest of your network or the internet. At least then if
18 >>> someone hacks your wireless key, they still can't do anything without
19 >>> having your VPN certificate.
20 >>>
21 >> Actually, VPN would rule out my wifi cell phone I bet.
22 >>
23 >
24 > Maybe not -- I don't know what kind of phone you've got. I have a
25 > Nokia N95 which runs Symbian OS 9 and there are 3 VPN clients that I
26 > know of (and the first one is free):
27 >
28 > http://www.businesssoftware.nokia.com/mobile_vpn_downloads.php
29 > http://www.ncp-e.com/en/vpn-szenarien-produkte/vpn-produkte/secure-entry-client.html
30 > http://www.symvpn.com/Products/ProductInfo.aspx?ProductId=17
31 >
32 > I believe Windows Mobile devices have VPN support built in, but I've
33 > never tried it. For iPhone or other phone OS i have no idea as I've
34 > never actually used them.
35 >
36 > Paul
37 >
38 >
39 The iPhone has support for L2TP, PPTP and minor support for IPSec (if
40 ti's through cisco), all standard in the firmware releases.