What's new

Access Point Security

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

tlgalenson

New Around Here
I have a Belkin WiFi router that I was using as an Access Point. It was hooked through a multi-port 10/100/1000 box to an ATT Dsl single port router (2Wire) that has a firewall, dhcp, nat, etc.

The Belkin/AP is setup with WPA2 and a long encrypted password and a shorter "guest" encypted password. The guest password allows access to the internet but doesn't allow printing/filesharing.

It occurred to me that the WiFi/AP doesn't have any kind of firewall. So if someone cracked my WiFi/WPA2 and logged on then there is only my pc's software firewalls to protect them.

So I got going and discovered something called "router cascading" on the Belkin website, which if I am reading it correctly, the Belkin article has you perform by 1) setting the IP address of the 2nd router to something besides the primary router/gateway 2) Disabling the DCHP on the 2nd router 3) plugging the primary router LAN directly into the 2nd router LAN port (not the WAN port).

So it now looks like the Belkin router which is basically my WiFi box now has a Firewall/NAT between it and the WiFi side of things. And my hardwire connections are now Firewalled on both the WiFi and the WAN sides of things.

So the last questions are: 1) Do I now really have a router-based firewall all the way around my home office setup? 2) Am I letting my drive-by paranoia getting the better of me?

Tom M.
 
1. The 2wire is providing the NAT and spi firewall for your network. (Not the belkin)
2. Yes.
 
What he said.

If you actually wanted more security, you'd want WAN to LAN port from the 2nd router to the first. Then you at least have double NATing and the firewalling from the secondary router in the mix. Otherwise LAN to LAN there is nothing interceeding.

Yes, you are being overly paranoid. Short of the NSA, no one is likely to crack your network over wireless without spending some very significant amounts of time and attention to do it if you are using WPA2 with AES encryption with a non-dictionary vulnerable password longer than 8 characters.

More likely if anyone was targetting it, it would be over the internet using one of the many likely vulnerabilities that your router has. More likely something like changing your router DNS settings for Man-in-the-middle attacks or what not. A second router or firewall behind the first isn't really going to help with that.
 

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top