Jump to content

Small Home Private Network Setup

Go to solution Solved by vlamnire,

From a ICT student with a networking systems and design minor try first changing the username and password to remote into the router (don't leave it as admin/password) and set a custom SSID, set it to not broadcast (optional but remember this hides it from the list of anyone searching for a wireless network so you have to manually enter the SSID in whatever device you're connecting with), set the password to a secure one that's WPA2, disable WPS button/function if it has one -- on some routers there is a security risk where a brute-force attack can break the code and connect, if you want to and if it allows you to set up a MAC address whitelist or MAC address filter to only allow the MAC address of your devices to connect so even if someone does somehow get in if they don't have the right MAC address they cannot do anything.  Downside of MAC address filtering is when you get a new device you have to add it to the list via another device before connecting. 

 

Miscellaneous things can include disabling remote management via browser, SSH and Telnet, so it won't allow outside IP addresses to try and connect, turn on your router firewall and review those settings.  If you want ultimate control try seeing if there is an alternative firmware for your router like DD-WRT.

 

For a common evil-doer out there a complex password to connect is sufficient.

The solution is set up WPA2 personal and be happy. Or connect everything through ethernet. 

 

I don't see what you're worried about. 

 

Even if somebody went through thte trouble of cracking your wifi password, then what? They can use your internet access. Big deal. Maybe you have a NAS sharing some movies and music. They're going to listen and realize that you have shit taste in music. So what?

Link to post
Share on other sites

The solution is set up WPA2 personal and be happy. Or connect everything through ethernet. 

 

I don't see what you're worried about. 

 

Even if somebody went through thte trouble of cracking your wifi password, then what? They can use your internet access. Big deal. Maybe you have a NAS sharing some movies and music. They're going to listen and realize that you have shit taste in music. So what?

If i do connect everything through ethernet, what do I need to do to be secure then? Like what settings and configurements do I need to do? I don't doubt WPAII but I like adding more security to be sure and overkill etc

Link to post
Share on other sites

I see, so this network, it coexists long side of the main one? Is it like a different map then and different security sets? Like can you go into detail how that's setup? 

if you have a halfway decent router it will allow you to set up multiple wireless networks, the Asus one I have will even let me set up certian wireless networks to only be avalible for a certian time frame or during a certian time of day. It uses and different password and the devices on the guest network doesn't have access the home network.

"Science and technology revolutionize our lives, but memory, tradition and myth frame our response."

Arthur M. Schlesinger

Link to post
Share on other sites

if you have a halfway decent router it will allow you to set up multiple wireless networks, the Asus one I have will even let me set up certian wireless networks to only be avalible for a certian time frame or during a certian time of day. It uses and different password and the devices on the guest network doesn't have access the home network.

Dude that's fucking awesome, is the GUI friendly? Could you post a picture? 

Link to post
Share on other sites

Dude that's fucking awesome, is the GUI friendly? Could you post a picture? 

router%20screenpic.jpg

 

I plan on upgrading my router soon, this is actually one of the lower end asus routers, I want to get me a wireless ac gigabit router.

"Science and technology revolutionize our lives, but memory, tradition and myth frame our response."

Arthur M. Schlesinger

Link to post
Share on other sites

-snip

 

I plan on upgrading my router soon, this is actually one of the lower end asus routers, I want to get me a wireless ac gigabit router.

 

Man I should get something like that in the future, that looks awesome. Asus has some nice GUI stuff, I really like their BIOS software. Any negatives you've had with it? 

Link to post
Share on other sites

-snip

 

I plan on upgrading my router soon, this is actually one of the lower end asus routers, I want to get me a wireless ac gigabit router.

Oh, and if my understanding is correct, correct me if I'm wrong, it sounds like it's possible to have the wireless network completely separate from the wired one? Like having the wired connections private while having the wireless public to each other? 

Link to post
Share on other sites

The solution is set up WPA2 personal and be happy. Or connect everything through ethernet. 

 

I don't see what you're worried about. 

 

Even if somebody went through thte trouble of cracking your wifi password, then what? They can use your internet access. Big deal. Maybe you have a NAS sharing some movies and music. They're going to listen and realize that you have shit taste in music. So what?

 

He could use the internet access to download illegal stuff.

 

I can't tell if you're serious or trolling, but what he said does sound pretty useful, if otherwise please do explain

As said before finding a WiFi without SSID is super easy.

It is also possible to spoof the MAC of an allowed device and to insert the MAC into the attackers network card.

If somebody has the power and or money to break an eight digit WPA2 password this won't stop him at all.

Link to post
Share on other sites

 

He could use the internet access to download illegal stuff.

  As said before finding a WiFi without SSID is super easy.

It is also possible to spoof the MAC of an allowed device and to insert the MAC into the attackers network card.

If somebody has the power and or money to break an eight digit WPA2 password this won't stop him at all.

Okay the MAC spoof thing, you mean get an allowed MAC address, so a whitelisted MAC address, and set that address that they found onto a device that they want to connect? That's a pretty nice attack plan, but how would that be done and how can I cover something like that? Obviously both ends would have to be encrypted, so the router, and the device. But how would you encrypt both? Let's say a laptop for the device running Windows 

 

edit - ohhhh wait wait wait, I think I get it, it's not the devices really, it's the connection itself as well, so for a wireless connection using WPAII should be enough, and for a wired connection, would there be anything necessary for that? 

Link to post
Share on other sites

Okay the MAC spoof thing, you mean get an allowed MAC address, so a whitelisted MAC address, and set that address that they found onto a device that they want to connect? That's a pretty nice attack plan, but how would that be done and how can I cover something like that? Obviously both ends would have to be encrypted, so the router, and the device. But how would you encrypt both? Let's say a laptop for the device running Windows 

 

edit - ohhhh wait wait wait, I think I get it, it's not the devices really, it's the connection itself as well, so for a wireless connection using WPAII should be enough, and for a wired connection, would there be anything necessary for that? 

There's 802.1x, but I doubt it will be worth it on a home network.

Link to post
Share on other sites

what's that

 

If you don't know what something means, just click-drag to select it and right click, it'll bring up this context menu with a really handy option that you can see highlighted in blue.

 

Teach a man to fish and stuff....

post-268960-0-17859600-1452532676_thumb.

Link to post
Share on other sites

If you don't know what something means, just click-drag to select it and right click, it'll bring up this context menu with a really handy option that you can see highlighted in blue.

 

Teach a man to fish and stuff....

Some people can teach better than others. You're kind of a dick. 

Link to post
Share on other sites

Some people can teach better than others. You're kind of a dick. 

 

Yeah, maybe I am.

 

But you're expecting somebody to sit at their computer and type an explanation of an advanced security protocol because you don't feel like taking the 0.5 seconds required to bring up another tab with the answer to the question that you asked; so what does that make you?

 

In fact, in the time that it took you to click "quote", type those two words and click "post", you could have brought up the search and read the automatically generated explanation that Google provides.

Link to post
Share on other sites

Yeah, maybe I am.

 

But you're expecting somebody to sit at their computer and type an explanation of an advanced security protocol because you don't feel like taking the 0.5 seconds required to bring up another tab with the answer to the question that you asked; so what does that make you?

 

In fact, in the time that it took you to click "quote", type those two words and click "post", you could have brought up the search and read the automatically generated explanation that Google provides.

Doesn't sound like you read my comment. Because people with experience for example, the people here, can give a better explanation and definition than ones out there. 

Link to post
Share on other sites

Man I should get something like that in the future, that looks awesome. Asus has some nice GUI stuff, I really like their BIOS software. Any negatives you've had with it? 

no, just if you get an asus make sure you do a firmware update if it is and older model, they had a security flaw in their firmware about a year and half ago. The firmware update is easy to do though, and setup was very easy to do. 

"Science and technology revolutionize our lives, but memory, tradition and myth frame our response."

Arthur M. Schlesinger

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×