Re: WPA and DHCP



On 13 Apr 2007 06:09:28 -0700, "Alister" <alister.gcs@xxxxxxxxxxxxx>
wrote in <1176469768.759260.89010@xxxxxxxxxxxxxxxxxxxxxxxxxxxx>:

Wonder if anyone can help.

On our office network (Active Directory, DHCP, DNS etc) we have three
NETGEAR WN802T used as
access points for laptops onto the network. These AP's are secured
using WPA-PSK with a long and
complicated key, and they have had default ssid's, passwords etc
changed.
Looking through DHCP on the Server I noticed two address leases from
computers outside our domain.

Trying to narrow down the likely culprits, I wonder is it likely to be
someone with access to the WPA key
or is WPA still not secure enough to stop unauthorized access?

WPA is still secure with a strong passphrase.
Might they have been wired to your network?

Question: Should WPA stop the DHCP server offering leases through the
Access points?

Yes. Your passphrase might have been compromised, or those might be old
leases. Suggest you clear the DHCP server, change your key
(passphrase), and see what happens. And consider switching to RADIUS,
thereby avoiding the problems of a shared key.

--
Best regards, FAQ for Wireless Internet: <http://Wireless.wikia.com>
John Navas FAQ for Wi-Fi: <http://wireless.wikia.com/wiki/Wi-Fi>
Wi-Fi How To: <http://wireless.wikia.com/wiki/Wi-Fi_HowTo>
Fixes to Wi-Fi Problems: <http://wireless.wikia.com/wiki/Wi-Fi_Fixes>
.



Relevant Pages

  • Re: Wi-Fi: Essential Checklist
    ... on a public network, securing my own network isn't going to reduce my ... The computer is secure, but the transport ... You have to run VPN to secure traffic on an open wireless ... John Navas FAQ for Wi-Fi: ...
    (alt.internet.wireless)
  • Re: Wi-Fi: Essential Checklist
    ... "If I configure my computer to be secure regardless of the network ... John Navas FAQ for Wi-Fi: ...
    (alt.internet.wireless)
  • Re: Verizon Android Phones Flood onto craigslist
    ... In this area there is WiFi all over the place. ... I'd say about 98% of residential wi-fi is secure, though I see about 5% of homes have both a secure network and a network labeled "guest." ... When I go to the HMO to take the kids for an appointment of pick up a prescription, there is Wi-Fi. ...
    (alt.cellular.verizon)
  • Re: Static IPs and WRT54gs?
    ... On both wired and wireless clients. ... Using DHCP, however, is often quite worthwhile. ... I don't need DHCP simply because this is going to be a small network at ... John Navas FAQ for Wi-Fi: ...
    (alt.internet.wireless)
  • Secure DHCP
    ... One of the servers is DHCP, all the WS are DHCP clients. ... What is the best way to secure the network that if a guest is coming to the ...
    (microsoft.public.windows.server.general)