Page 46 / 80 Scroll up to view Page 41 - 45
36
Improving Security
Linksys E-Series
36
How do I know if my network is secure?
If you configured your router using Cisco Connect, your network is secure°
During setup, Cisco Connect creates a name for your network, enables industry-
standard WPA/WPA2 wireless security, and assigns a highly secure password for
your wireless network and the administrator’s account°
To confirm that your network is secure:
1.
Run Cisco Connect°
2.
In the upper-right corner of the screen, check for the green light that
indicates your router is online and secure° If the green light is on, no
additional action is required to secure your network°
Network security following a manual
setup
If you configured your router manually (not recommended), you must manually
configure security°
To manually set your router’s password:
Administration > Management
1.
Log into the browser-based utility (see “How to open the browser-based
utility” on page 21)°
2.
Click the
Administration
tab, then click the
Management
page°
3.
In the
Router Access
section, enter a secure password for your router,
then re-enter the password to confirm it° Your password should be
at least eight characters in length° The most secure type of password
should include a mix of uppercase and lowercase letters, numbers, and
punctuation°
4.
Click
Save Settings
at the bottom of the screen°
To manually set your router’s network name (SSID):
Wireless > Basic Wireless Settings
1.
Log into the browser-based utility (see “How to open the browser-based
utility” on page 21)°
2.
Click the
Wireless
tab, then click the
Basic Wireless Settings
page°
3.
For
Configuration View
, select
Manual
°
4.
Enter a new network name in the
Network Name (SSID)
field, then click
Save Settings
at the bottom of the screen°
Improving Security
Page 47 / 80
37
Improving Security
Linksys E-Series
To manually set your router’s wireless security settings:
Wireless > Wireless Security
1.
Log into the browser-based utility (see “How to open the browser-based
utility” on page 21)°
2.
Click the
Wireless
tab, then click the
Wireless Security
page°
3.
Select your preferred security type from the
Security Mode
drop-down
list For most home networks, we recommend
WPA2/WPA Mixed Mode
°
4.
Enter a passphrase (security key) for your wireless network in the
Passphrase
field° The most secure type of security key should include a
mix of uppercase and lowercase letters, numbers, and punctuation°
5.
Click
Save Settings
at the bottom of the screen°
How to set up wireless security using
Wi-Fi Protected Setup
Why would I use Wi-Fi Protected Setup?
Wi-Fi Protected Setup™ is a feature
of your router that makes it easy to add devices to your wireless network° If you
have network devices, such as wireless printers, that support Wi-Fi Protected
Setup, then you can use Wi-Fi Protected Setup to add the devices°
Wi-Fi Protected Setup activity light
The power indicator light on the back of the router (or on top for the E4200)
indicates the status of Wi-Fi Protected Setup while you are connecting devices°
When Wi-Fi Protected Setup is connecting a network device, the light
flashes slowly°
If there is an error, the light flashes quickly for two minutes° Wait until it
stops flashing, then try again°
When Wi-Fi Protected Setup has finished connecting a device, the light
is continuously lit °
Wait until the light is continuously lit before starting the next Wi-Fi
Protected Setup session°
Connect network devices using one of the three methods below°
NOTE
Wi-Fi Protected Setup configures one device at a time° Repeat the
instructions for each device that supports Wi-Fi Protected Setup°
Connecting a device using the Wi-Fi Protected Setup
button
Use this method if your device has a Wi-Fi Protected Setup button or prompts
you to press the Wi-Fi Protected Setup button on your router°
To connect a device using the Wi-Fi Protected Setup button:
Wireless > Basic Wireless Settings
1.
Press the
Wi-Fi Protected Setup
button on the network device you are
connecting to°
2.
Press the
Wi-Fi Protected Setup
button on the back of the router°
- OR -
a.
Log into the browser-based utility (see “How to open the browser-
based utility” on page 21)°
b.
Click the
Wireless
tab, then click the
Basic Wireless Settings
page°
c.
Click
Wi-Fi Protected Setup
°
d.
Click the
Wi-Fi Protected Setup
button in the router’s
Wi-Fi Protected
Setup
screen°
e.
After the device has been configured, click
OK
°
Page 48 / 80
38
Improving Security
Linksys E-Series
How to connect a device using its Wi-Fi Protected
Setup PIN
Use this method if your device has a Wi-Fi Protected Setup
PIN
(Personal
Identification Number)°
To connect a device using the device’s Wi-Fi Protected Setup PIN:
Wireless > Basic Wireless Settings
1.
Log into the browser-based utility (see “How to open the browser-based
utility” on page 21)°
2.
Click the
Wireless
tab, then click the
Basic Wireless Settings
page°
3.
Click
Wi-Fi Protected Setup
°
4.
Enter the PIN from the device into the
PIN
field on the router’s
Wi-Fi
Protected Setup
screen, then click
Register
°
5.
After the device has been connected, click
OK
°
How to connect a device using the router’s Wi-Fi
Protected Setup PIN
Use this method if your client device asks for the router’s PIN°
To connect a device using the device’s Wi-Fi Protected Setup PIN:
Wireless > Basic Wireless Settings
1.
Log into the browser-based utility (see “How to open the browser-based
utility” on page 21)°
2.
Click the
Wireless
tab, then click the
Basic Wireless Settings
page°
3.
Click
Wi-Fi Protected Setup
°
4.
On the client device, enter the PIN listed on the router’s
Wi-Fi Protected
Setup
screen° It is also listed on the bottom of the router° In the example
below, the router’s PIN is 32744781°
5.
Follow the device’s instructions to complete setup°
How to connect a device manually
If you have devices that do not support Wi-Fi Protected Setup, note the wireless
settings in the
Basic Wireless Settings
screen, then manually configure those
devices°
For each wireless network, the Network Name (SSID), Security, and Passphrase
are displayed at the bottom of the screen°
Page 49 / 80
39
Improving Security
Linksys E-Series
How to control access to your wireless
network
Why would I need to control access to my wireless network?
If you used
Cisco Connect to configure your router, your wireless network is already secure°
By default, Cisco Connect enables industry-standard
WPA
(Wi-Fi Protected
Access) security using WPA2/WPA mixed mode° Cisco Connect configures your
network with a complex, 10-character password that is almost impossible
to compromise° If you set up your wireless network manually and have not
enabled wireless security, your wireless network will be an “open” network that
almost anyone nearby with a Wi-Fi-enabled device could access°
What is MAC filtering?
The best way to secure your wireless network is to use
Cisco Connect to automatically configure and secure it° However, if you choose
not to use the built-in security features of your router, you can still control
access to your wireless network using MAC filtering°
Every network device has a unique, 12-digit
MAC
(Media Access Control)
address° Using MAC filtering, you can allow only known MAC addresses onto
your network° You can also exclude specific MAC addresses or deny them
access to your wireless network°
Example
: Because each MAC filtering configuration is unique, the following
procedure uses the simplified example of setting up MAC filtering to allow one
wireless device access to the network°
To set up MAC filtering to allow one wireless device access to your
network:
Wireless > Wireless MAC Filter
1.
Log into the browser-based utility (see “How to open the browser-based
utility” on page 21)°
2.
Click the
Wireless
tab, then click the
Wireless MAC Filter
page°
3.
Click
Enabled
°
4.
Select
Permit
°
TIP
You can also use MAC filtering to prevent specific PCs from
accessing your network by selecting
Prevent
° However, it’s easier
to permit only known devices than to exclude unknown devices°
5.
Click
Wireless Client List
° A separate window opens and displays the
currently connected devices° In the example below, the only device
permitted onto the network is the MacBook° However, two other devices
are also connected to the network°
6.
Next to the device entry, select
Save to MAC Address Filter List
, then
click
Add
° The Mac Address Filter List is updated with the MAC address of
the device you added°
Page 50 / 80
40
Improving Security
Linksys E-Series
7.
Click
Save Settings
at the bottom of the page°
8.
Click
Wireless Client List
again to check the updated device list° Only
the device you selected remains on the network°
How to improve security using the built-in firewall
Why would I need to change my security settings?
By default, the firewall
settings in your router have been optimized for most home environments, so
no changes are needed° The
SPI
(Stateful Packet Inspection) firewall is enabled
by default° In addition, anonymous Internet requests and IDENT requests are
filtered by default° All web filters are disabled, because enabling them may
cause problems for sites that depend on ActiveX controls, Java, or cookies°
To change your firewall settings:
Security->Firewall
1.
Log into the browser-based utility (see “How to open the browser-based
utility” on page 21)°
2.
Click the
Security
tab, then click the
Firewall
page°
3.
Select each setting that you want to change°
TIP
For descriptions of the filters, click
Help
on the right side of the
screen° More complete descriptions are included below°
SPI Firewall Protection
—This helps protect your local network from
Internet threats° This option is enabled by default°
CAUTION
To help protect your network, you should keep this option enabled°
Filter Anonymous Internet Requests
—This filter blocks Internet
requests from unknown sources such as ping requests° This option is
enabled by default°
Filter Multicast
—Multicasting allows a single transmission to
simultaneously reach specific recipients within your local network°
Select this option to block multicasting° This option is disabled by
default°
Filter Internet NAT Redirectio
n—This filter prevents a local computer
from using a URL or Internet IP address to access the local server° Select
this option to enable the filter° This option is disabled by default°
Filter IDENT (Port 113)
—This filter prevents port 113 from being
scanned by devices from the Internet° This option is enabled by
default°
Proxy
- This filter blocks the use of Internet proxy servers° To deny
proxy requests, select this option° Proxy access is allowed by default°
Java
- This filter blocks Java, so you may not be able to access Java
content on websites° To deny Java requests, select this option° Java
content is allowed by default°
ActiveX
- This filter blocks ActiveX, so you may not be able to access
ActiveX content on websites° To deny ActiveX requests, select this
option° ActiveX content is allowed by default°
Cookies
- This filter blocks cookies, which are data stored on your
computer and used by websites when you interact with them° To deny
cookie requests, select this option° Cookie usage is allowed by default°
4.
Click
Save Settings
to update your changes°

Rate

4.5 / 5 based on 2 votes.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top