Home > Networking Tips > Wireless Networks > Securing teleworker wireless LANs
Networking Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WIRELESS NETWORKS

Securing teleworker wireless LANs


by Lisa Phifer, VP, Core Competence
04.08.2003
Rating: -4.44- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


[TABLE]

For years, companies have wrestled with security risks introduced by teleworkers. According to ITAC, one in five U.S. employees spent some time working from home in 2001. Growth is being accelerated by residential broadband services -- In-Stat/MDR estimates that 14% of U.S. homes now have cable modem or DSL. High-speed, always-on connections make working from home more palatable, but they also increase risk by adding new territory that must be defended from abuse and attack.

Today, residential wireless LANs are tossing fresh fuel on this smoldering fire. According to In-Stat/MDR, six million Wi-Fi home nodes were sold in 2002, projected to reach 33 million by 2006. Wireless LANs make Internet connection, printer and file sharing among PCs in the home much easier. But when one of those nodes is a teleworker desktop or laptop, securing the WLAN becomes a corporate concern.

Expanding the security gap

Teleworker PCs connected to the Internet were always at risk, but broadband exacerbated this by expanding the window of opportunity. Teleworkers connected to home WLANs open that window even wider. Some new risks resulting from lax home WLAN security include the following.

Filling that gap

What can companies do to avoid these pitfalls and encourage safer use of teleworker wireless LANs?

  • Choose the right hardware for the job. Terminology can be confusing, and many teleworkers don't understand the difference between a wireless AP and router, or between a router with an integrated

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Wireless LAN Advisor
    Understanding wireless antennas -- Part 2
    Understanding wireless antennas - part 1
    Signs of WLAN intrusion
    On the horizon: News from 802.11-Planet
    Consolidating control using WLAN switches
    Upgrading to Wi-Fi protected access
    Wireless adapters for your PDA
    Wireless options for your PDA
    Configuring service set identifiers
    Migrating to 802.11g

    Wireless Networks
    Rogue access points: Preventing, detecting and handling best practices
    Persistent, secure connections for roaming WiMAX, 3G and 802.11x
    Securing embedded 802.11n devices
    802.11n's impact on WLAN security
    Set up secure wireless networks with 802.11x, access points and bridges
    How to use Netsh WLAN to configure Windows Server 2008 and Windows Vista wireless connections from the CLI
    How to avoid the WPA wireless security standard attack
    IEEE 802.11w protects wireless LAN management frames
    Measure wireless network performance using testing tool iPerf
    How to prioritize wireless traffic

    Wireless LAN Implementation
    802.11n wireless LAN access point market: Who's really in second place?
    Wireless LAN security: SonicWall joins crowded WLAN market
    Stolen laptop recovery using remote access and wireless network SSIDs
    Distributed antenna systems and WLAN: A network management burden
    Wireless AP SSID and channel configuration for a distribution network
    Solid 802.11n deployment prepares medical center for future demands
    How 802.11n wireless APs in Greenfield mode affect nearby networks
    How to create a Wi-Fi hotspot
    Beamforming, RF management key to 802.11n wireless LAN success
    Set up secure wireless networks with 802.11x, access points and bridges

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    802.11a  (SearchNetworking.com)
    Asynchronous Pulsed Radiated Incident Light  (SearchNetworking.com)
    cognitive radio  (SearchNetworking.com)
    direct sequence spread spectrum  (SearchNetworking.com)
    frequency-hopping spread spectrum  (SearchNetworking.com)
    phase-locked loop  (SearchNetworking.com)
    radio frequency  (SearchNetworking.com)
    wireless mesh network  (SearchNetworking.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary


    VPN gateway or VPN pass-through.

  • Enable basic 802.11 security. MAC access control lists, shared key authentication, and WEP aren't perfect, but they are still useful as a first line of defense. In a small, self-contained WLAN, shared keys and ACLs are manageable. Supply guidance on how to pick good SSID and key values, when to update keys, etc.

  • Harden wireless devices. Teach teleworkers to change or disable unused listening ports and configure hard-to-guess passwords. Connect only with known APs, disabling Windows XP's ability to connect to any non-preferred network.

  • Extend existing desktop security measures. For example, reconfigure VPN client policies to also apply to wireless adapters, and identify wireless router VPN pass-throughs that are compatible with your VPN client.

  • If you don't use VPN on the WLAN, consider other options to increase protection for sensitive traffic. For example, use SSL webmail instead of POP or encrypted screen sharing instead of cleartext remote desktop access.

  • Rethink home network trust. Sharing printers and files may be acceptable on a residential Ethernet that's protected from the Internet by a firewall/router. Doing so over wireless probably is not. Help teleworkers to identify new sources of risk.

  • If you haven't already, get started now. Home WLAN adoption is now growing faster than enterprise WLAN use. If your workers carry laptops or have PCs at home, odds are excellent that you already have at least a few teleworkers using wireless.

    Rate this Tip
    To rate tips, you must be a member of SearchNetworking.com.
    Register now to start rating these tips. Log in if you are already a member.




    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



  • Networking Solutions for Business

    Alcatel-Lucent Network Business Communications Solutions

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts