Security – Securing Guest Wireless Network

Securitywifi

I need to setup a guest wireless network at the office for visitors to connect to. What are your recommendations in terms of how to secure it without putting too much of a support burden on myself?

I'd prefer to keep it an open access point, so I don't have to support users who can't figure out how to input the password correctly. However, if I don't, should I use WPA or WPA2? Will I have compatibility issues at all if I use WPA2?

What is the best way to isolate the users from the network itself. I guess the most foolproof way is to just put that access points(s) on its own DSL connection. What are my other options?

How do most of you secure your guest wireless networks?

Best Answer

The recommended way for doing this is to use a DMZ configuration. You can maintain an open wireless connection to allow guests to easily connect to it. However, there are a few things that you will want to control.

  1. Place your wifi connection in the dmz zone and treat its connections as potentially hostile. This means configuring your firewall to block incoming connections to your local network and allowing only certain connections through to the internet (e.g. http/https).
  2. Place the wifi devices on a different subnet and network range than your local network. This will force the computers to route packets through your firewall device. Ensure that the wireless network is physically disconnected from the local network.

  3. (Optional) Implement some sort of radius authentication, maybe using chilispot or something similar. This will allow you some sort of authentication. You can use this to better control the use of your wifi. Guests may be given a username/password login for use during their stay.

Hope this gives you some ideas.