republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » Linksys » [Tomato] Wireless Filter Block list not enforced
Search Topic:
Uniqs:
481
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
[DD-WRT] Tx rate for dd-wrt »
« New PC & OS (Vista 64)-New Router also?  
AuthorAll Replies

Lalaland

join:2009-06-22

[Tomato] Wireless Filter Block list not enforced

Hi I'm running Tomato 1.25 on my 54GL as my main AP and using a WDS network so I can bridge my pc using an old wireless router as a glorified wireless card (too much heartbreak with wireless usb adaptors and PCI cards). Of course this limits me to WEP encryption and some of my neighbours have been hopping on, I've been adding them to the wireless filter list but they still sometimes get connected.

Does it only apply to the DHCP service and they're using fixed IPs?
If so is there another way to block them?
Is it just a time sensitive thing (ie that service starts after they get given an IP)?

Any help greatly appreciated

upb
Premium
join:2004-03-15
Carriere, MS
·AT&T Southeast

said by Lalaland See Profile :

Does it only apply to the DHCP service and they're using fixed IPs?
If so is there another way to block them?
Is it just a time sensitive thing (ie that service starts after they get given an IP)?
If they're cracking your WEP password, you must have some serious script kiddies nearby. In any case, there is another place you can block them in Tomato, and it might be worth a try.

Under the "Access Restriction" menu, you can set up a rule which by default blocks all computers from internet access, except those whose MAC addresses you have listed there. You choose "all day", "every day", "normal access restriction", "all except", and "block all internet access". You then list the MAC addresses of all machines allowed to use the Internet. Do not list IP addresses, even though it's acceptable.

This blocks anyone who manages to associate with your wireless access point from reaching the net, unless they can figure out the MAC address of one of your computers and spoof it. You should be able to at least discourage them from hanging around.

That, of course, still leaves them connected to your LAN — not a good thing — and should be used as a fallback defense. Have you used "Basic -> Wireless Filter" to set up allowed MAC addresses? That's the first place you really ought to go if you do MAC filtering (which provides only weak protection).

I'd try to figure out how to eventually move to WPA or WPA2, because that's the only really good way to have a secure WAP.

Good luck.

Lalaland

join:2009-06-22

reply to Lalaland
Hi upb I have a black list setup on my tomato box in the wireless filter section for convenience as I've just been adding them in as I see them. I've just noticed that I'd never enabled WEP on the other router, I should have checked this right off the bat and it seems to have solved my issues. Very silly of me but I somehow got it into my head that the WDS setup would mean that the security I set up on tomato would magically be respected by the other router too. Since I've enabled WEP on the other box they've gone away.

Looks like I've fallen victim to failing to use Occham's Razor (security edition), when the explanation is widespread skilled script kiddies or a security failure it's probably the latter. Thanks for your assistance upb!
-
Forums » Equipment Support » Hardware By Brand » Linksys[DD-WRT] Tx rate for dd-wrt »
« New PC & OS (Vista 64)-New Router also?  


Sunday, 08-Nov 09:24:56 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [156] Cable Uncapper Faces Criminal Charges
· [140] AT&T Sues Verizon Over 3G Ads
· [112] Why Run Fiber When You Can Run Ads That Pretend You Do?
· [108] Comcast Is Simply Getting Huge
· [92] Apple Cooking Up New $30 A Month TV Service?
· [82] Bits Of ACTA Agreement Leaking Out
· [80] Will 'Three Strikes' Come To The United States?
· [78] Verizon To Double Smartphone ETFs?
· [76] Verizon: Droid Tethering Will Cost $30 Extra
· [73] Comcast, NBC Deal Almost Complete
Most people now reading
· Game console [General Questions]
· [WIN7] Windows 7 Driver Updates - Gung-ho or Gunshy? [Microsoft Help]
· [Need Info] Looking for backup software... [Software]
· What is the spell hit cap for a lvl 80 full arcane spec mage [World of Warcraft]
· Hit and run [General Questions]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Know when to run! [Home Repair & Improvement]
· NO ONE knows what's wrong with my line! [TekSavvy]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]