Open AP: WLan encryption without preshared key...?

Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware
Author Message
qriff
DD-WRT Novice


Joined: 04 Jul 2006
Posts: 3

PostPosted: Tue Jul 04, 2006 19:57    Post subject: Open AP: WLan encryption without preshared key...? Reply with quote
We would like to run an open access point with traffic encryption to protect anonymous users from airsnorting...

Is it possible to enable wlan encryption without the requirement of a preshared key...?

How/Why...?

What does DD-WRT / Wireless / Advanced Settings / Authentication Type
do with the options Auto and Preshared key...?

The Help definition doesn't actually say anything about the setting, just stating the obvious:
Code:

The default is set to Auto, which allows either Open System or Shared Key authentication to be used. For Open System authentication, the sender and the recipient do NOT use a WEP key for authentication. For Shared Key authentication, the sender and recipient use a WEP key for authentication. If you want to use only Shared Key authentication, then select Shared Key.


Why would it only be possible to use Authentication Type = Auto with WEP...?

When setup described above the client cant acquire an ip-address.


Last edited by qriff on Tue Jul 04, 2006 21:26; edited 2 times in total
Sponsor
qriff
DD-WRT Novice


Joined: 04 Jul 2006
Posts: 3

PostPosted: Tue Jul 04, 2006 21:24    Post subject: Reply with quote
And would a publicly published preshared key defeat the purpose for individual traffic encryption...?
wlan
DD-WRT User


Joined: 07 Jun 2006
Posts: 181
Location: BULGARIA

PostPosted: Tue Jul 04, 2006 22:55    Post subject: Reply with quote
As I know, the Authentication Type is always open when you use WPA AES, and the shared key is used only from WEP and shared key is more secure than Open type for WEP. But if you can, use highest security level - WPA2 AES with strong 63 key and small renew intervall. If you can't use WPA2 - use WPA1 - AES. Do not use TKIP - that isn't secure enough and will slow down your overall network speed. WEP is easy to hack. Do not use it.

Use WPA2 AES or WPA AES, 63 key, smaller than 3600 renew intervall.
Use MAC filter List anyway, and If you don't have troubles with disabled ssid, then leave it disable.

Secure level:
1. WPA2 RADIUS / WPA2 AES
2. WPA RADIUS / WPA AES
3. WPA TKIP
4. WEP 128
5. WEP 64
qriff
DD-WRT Novice


Joined: 04 Jul 2006
Posts: 3

PostPosted: Wed Jul 05, 2006 2:25    Post subject: Reply with quote
What does "Authentication Type is (always) open" mean...?
That is my question.
I would like to not use a preshared key but still have the encryption.

This is something I have never figured out with WLan's... how to run an open AP/Hotspot and provide anonymous users with a protected connection to the AP itself...
DKP
DD-WRT Novice


Joined: 06 Jun 2006
Posts: 11

PostPosted: Wed Jul 05, 2006 2:58    Post subject: Reply with quote
authentication is what it takes for a client to "associate." For example, with WEP and open authentication, a client can associate with an AP without knowing the WEP. they can't send or recieve traffic, because it is encrypted, but they can technically "connect."

Shared key requires them to provide the wep key before the AP even considers them connected.

I am fairly certain that WPA and WEP Radius require open authentication because of the challenge/responce required to establish the encryption. If it were shared key, the client would not be able to connect enough to even attempt a handshake.

I don't really understand what this option was intended to do. The ONLY use i have seen is it stops injection based wep-cracking when you have 0 legitimate clients associated.

So if the HAVE to use WEP PSK, turn it on, otherwise go WPA2-AES. Keep in mind, WPA is only as strong as its passphrase.
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum