Re: IPsec wifi link in ad-hoc mode



On Thu, 25 Sep 2008 17:51:28 +0000, Fabrice Delente wrote:
I set up my two laptops to communicate in wifi ad-hoc mode.???

One of the laptops (192.168.1.3) acts as a router and a DNS server for
the other (192.168.1.4).

As I don't want anybody to use my router as a gateway, I must secure it.

I enabled a WEP encryption key between the two of them, but it's hardly
extremely secure.

Why not switch to TKIP/WPA or WPA2? As you're talking about laptops, this
should be doable (it wouldn't if you had an old AP that only supports
WEP).

So I set up an IPsec link between them; it works ok, but I don't know if
it's enough to guarantee that nobody can hijack my connection, using my
gateway to spam/spoof/etc.

As long as the laptop acting as AP only accepts IPSec traffic (more
specifically, authenticated IPSec traffic) you should be quite safe.
However, wireless networks are still quite vulnerable to other types of
attacks (for instance, even with WEP/WPA/WPA2, one can still force
clients to disconnect even without prior knowledge of the keys).

How can I make sure that only 192.168.1.4 connects to 192.168.1.3? Must
I/can I do IP filtering? MAC addresses filtering?

IP filtering and MAC address filtering are just small bandages and are
easy to spoof.

Wkr,
Sven Vermeulen
.



Relevant Pages

  • Re: Airport dropping connection
    ... filtering, and the MAC address of the computer from which you connect ... is not allowed, the computer will *appear* to be connected, but the router ... Have you examined the Airport passwordstored in your MacBook ...
    (comp.sys.mac.portables)
  • Wireless MAC address filtering
    ... My older Linksys wireless AP router can only do WEP security, so when I got my new HP laptop with built-in WiFi I decided to add wireless MAC address filtering to my router. ...
    (comp.sys.laptops)
  • Re: Blocking a computer from a wireless router.
    ... I don't have a great knowledge of how to break security systems. ... MAC addresses are sent unencrypted. ... Because it's a pain in the posterior having to tweak the router every ... expert" has MAC address filtering enabled. ...
    (alt.internet.wireless)
  • Re: Wireless MAC address filtering
    ... I got my new HP laptop with built-in WiFi I decided to add wireless ... MAC address filtering to my router. ...
    (comp.sys.laptops)
  • Re: Wireless MAC address filtering
    ... After some unsuccessful search for the laptop's WiFi ... MAC address, I discovered that my router can actually display the active MAC ... addresses even if the filtering is not set. ...
    (comp.sys.laptops)