Go Back   Velocity Reviews > Newsgroups > Wireless Networking
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Wireless Networking - MAC address filtering

 
Thread Tools Search this Thread
Old 01-26-2006, 04:39 AM   #1
Default MAC address filtering


OK, I'm trying to understand basic security..all I have is a di 524 with two
desktops connected via ethernet.. And then i have one laptop connected via
wireless.. Besides using WEP, I want to add MAC filtering.. My question, does
the MAC address stay the same when the laptop "log's on" or does it change
like an IP?. I was going to clone the MAC address and add it to the permit
this MAC address access to the network under mac filter rules

Do I make sense?


=?Utf-8?B?bWlrZXkgYiBmcm9tIHNk?=
  Reply With Quote
Old 01-26-2006, 10:35 AM   #2
Sooner Al [MVP]
 
Posts: n/a
Default Re: MAC address filtering
The client MAC address stays the same. Note, however, that MAC Address
Authentication is *NOT* a strong security measure. MAC addresses can be
easily spoofed.

--
Al Jarvi (MS-MVP Windows Networking)

Please post *ALL* questions and replies to the news group for the
mutual benefit of all of us...
The MS-MVP Program - http://mvp.support.microsoft.com
This posting is provided "AS IS" with no warranties, and confers no
rights...


"mikey b from sd" <> wrote in message
news:9C8726AE-14B2-4956-BB38-...
> OK, I'm trying to understand basic security..all I have is a di 524 with
> two
> desktops connected via ethernet.. And then i have one laptop connected via
> wireless.. Besides using WEP, I want to add MAC filtering.. My question,
> does
> the MAC address stay the same when the laptop "log's on" or does it change
> like an IP?. I was going to clone the MAC address and add it to the permit
> this MAC address access to the network under mac filter rules
>
> Do I make sense?





Sooner Al [MVP]
  Reply With Quote
Old 01-27-2006, 01:19 AM   #3
=?Utf-8?B?bWlrZXkgYiBmcm9tIHNk?=
 
Posts: n/a
Default Re: MAC address filtering


"Sooner Al [MVP]" wrote:

> The client MAC address stays the same. Note, however, that MAC Address
> Authentication is *NOT* a strong security measure. MAC addresses can be
> easily spoofed.
>



Well, I got this gem of an idea from the linksys website.. But this where
I'm comming from: When the laptop starts, it is presented with 3 different
wirelss access "possibilities" that are located in my neighborhood. So I'm a
little bit stingy and would rather not share my 1.5 meg DSL line..

So what do you suggest?

Thnaks, mb sd


=?Utf-8?B?bWlrZXkgYiBmcm9tIHNk?=
  Reply With Quote
Old 01-28-2006, 03:22 PM   #4
__spc__
 
Posts: n/a
Default Re: MAC address filtering

"mikey b from sd" <> wrote in message
news:9C8726AE-14B2-4956-BB38-...
> OK, I'm trying to understand basic security..all I have is a di 524 with
> two
> desktops connected via ethernet.. And then i have one laptop connected via
> wireless.. Besides using WEP, I want to add MAC filtering.. My question,
> does
> the MAC address stay the same when the laptop "log's on" or does it change
> like an IP?. I was going to clone the MAC address and add it to the permit
> this MAC address access to the network under mac filter rules
>
> Do I make sense?


Each network adaptor has a unique MAC address. All data packets sent by
WiFi include the MAC address, so anyone sniffing can grab that info, then
spoof it.

The best security is to have a strong WPA-PSK TKIP or better still, WPA-PSK
AES, passphrase, like "tlshuo891ixkaiuo22", or if you can get it to work,
include some other characters like "&" "£" "%" "!" etc.




__spc__
  Reply With Quote
Old 01-28-2006, 05:56 PM   #5
=?Utf-8?B?bWlrZXkgYiBmcm9tIHNk?=
 
Posts: n/a
Default Re: MAC address filtering
Ok, thanks for response.. Let me ask a couple more questions..

A) When you say that the machine code or MAC addreses can be "sniffed" are
you saying that the laptop is broadcasting it's MAC address or is it comming
from the router itself?

B)The D-Link 512 offers WPA or WPA2 for security options with PSK or EAP.
The help page doesn't explain the differences.. As for the passphrase, is
there a limit on the character length that can be used for the passphrase?

C) And for my dumb ignorant question: It seems to me that if one enables 128
bit security, the charcter length in the Key entry should be somewhat
sufficient when using WEP. I suppose if somebody was parked outside my house
for several days, they could eventually crack it.. How about if I turn down
the antenna transmit power?

thanks for your time.

"__spc__" wrote:

>
> "mikey b from sd" <> wrote in message
> news:9C8726AE-14B2-4956-BB38-...
> > OK, I'm trying to understand basic security..all I have is a di 524 with
> > two
> > desktops connected via ethernet.. And then i have one laptop connected via
> > wireless.. Besides using WEP, I want to add MAC filtering.. My question,
> > does
> > the MAC address stay the same when the laptop "log's on" or does it change
> > like an IP?. I was going to clone the MAC address and add it to the permit
> > this MAC address access to the network under mac filter rules
> >
> > Do I make sense?

>
> Each network adaptor has a unique MAC address. All data packets sent by
> WiFi include the MAC address, so anyone sniffing can grab that info, then
> spoof it.
>
> The best security is to have a strong WPA-PSK TKIP or better still, WPA-PSK
> AES, passphrase, like "tlshuo891ixkaiuo22", or if you can get it to work,
> include some other characters like "&" "£" "%" "!" etc.
>
>
>



=?Utf-8?B?bWlrZXkgYiBmcm9tIHNk?=
  Reply With Quote
Old 01-29-2006, 10:19 AM   #6
__spc__
 
Posts: n/a
Default Re: MAC address filtering

"mikey b from sd" <> wrote in message
news:B49C5AAA-C5E1-4F82-9163-...
> Ok, thanks for response.. Let me ask a couple more questions..
>
> A) When you say that the machine code or MAC addreses can be "sniffed" are
> you saying that the laptop is broadcasting it's MAC address or is it
> comming
> from the router itself?


All data packets sent from the laptop contain the MAC address (so that the
router can route the data correctly, I believe).

> B)The D-Link 512 offers WPA or WPA2 for security options with PSK or EAP.
> The help page doesn't explain the differences.. As for the passphrase, is
> there a limit on the character length that can be used for the passphrase?


WPA-PSK TKIP is WPA and WPA-PSK AES is WPA2

Within reason, I don't think that there's a limit on the WPA passphrase -
it's not like WEP which has to have certain length keys depending on the
bit-level of encryption.

> C) And for my dumb ignorant question: It seems to me that if one enables
> 128
> bit security, the charcter length in the Key entry should be somewhat
> sufficient when using WEP. I suppose if somebody was parked outside my
> house
> for several days, they could eventually crack it.. How about if I turn
> down
> the antenna transmit power?


Probably, and probably. But why not use WPA?

> thanks for your time.


[snip]

You're welcome.




__spc__
  Reply With Quote
Old 01-29-2006, 09:23 PM   #7
Lem
 
Posts: n/a
Default Re: MAC address filtering
mikey b from sd wrote:

> Ok, thanks for response.. Let me ask a couple more questions..
>
> A) When you say that the machine code or MAC addreses can be "sniffed" are
> you saying that the laptop is broadcasting it's MAC address or is it comming
> from the router itself?
>
> B)The D-Link 512 offers WPA or WPA2 for security options with PSK or EAP.
> The help page doesn't explain the differences.. As for the passphrase, is
> there a limit on the character length that can be used for the passphrase?
>
> C) And for my dumb ignorant question: It seems to me that if one enables 128
> bit security, the charcter length in the Key entry should be somewhat
> sufficient when using WEP. I suppose if somebody was parked outside my house
> for several days, they could eventually crack it.. How about if I turn down
> the antenna transmit power?
>
> thanks for your time.
>
> "__spc__" wrote:
>
>
>>"mikey b from sd" <> wrote in message
>>news:9C8726AE-14B2-4956-BB38-...
>>
>>>OK, I'm trying to understand basic security..all I have is a di 524 with
>>>two
>>>desktops connected via ethernet.. And then i have one laptop connected via
>>>wireless.. Besides using WEP, I want to add MAC filtering.. My question,
>>>does
>>>the MAC address stay the same when the laptop "log's on" or does it change
>>>like an IP?. I was going to clone the MAC address and add it to the permit
>>>this MAC address access to the network under mac filter rules
>>>
>>>Do I make sense?

>>
>>Each network adaptor has a unique MAC address. All data packets sent by
>>WiFi include the MAC address, so anyone sniffing can grab that info, then
>>spoof it.
>>
>>The best security is to have a strong WPA-PSK TKIP or better still, WPA-PSK
>>AES, passphrase, like "tlshuo891ixkaiuo22", or if you can get it to work,
>>include some other characters like "&" "£" "%" "!" etc.
>>
>>
>>


WEP is easier to crack than you might think, 128 bits notwithstanding:
http://www.tomsnetworking.com/Sections-article118.php


Lem
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
I have become rich in 30 days lemony-snicket A+ Certification 2 09-07-2009 03:01 PM
This is incredible! jc_ice DVD Video 1 08-13-2006 10:47 AM
Address Bus and External Data Bus Confusion LoXodonte A+ Certification 1 04-18-2006 10:09 PM
Nearest netflix shipping facility address is wrong ics83 DVD Video 13 12-07-2005 03:15 AM
Address Book Question smackedass A+ Certification 0 10-29-2005 01:34 AM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46