PDA

Bekijk de volledige versie : Securing the WL-700



Martypapa
23-03-2007, 12:00
Hi all - just bought the wl-700 and is absolutely in love with the thing. I'm intending to use it for work, pulling my project files from it wherever I might set up for work at home any given day (moving around a lot from room to room).

My question is this: I need the router for internet access and mail, and for storing files locally. I don't need it for wan to lan access at all. How can I make sure that the stored stuff is as protected from the outside as it possibly can?

I've enabled the firewall, but apart from that left everything at default.

Waiting to move anything to it before I know it's safe. Tnx for any answers in advance :)

mumsoft
25-03-2007, 15:57
Hi all - just bought the wl-700 and is absolutely in love with the thing. I'm intending to use it for work, pulling my project files from it wherever I might set up for work at home any given day (moving around a lot from room to room).

My question is this: I need the router for internet access and mail, and for storing files locally. I don't need it for wan to lan access at all. How can I make sure that the stored stuff is as protected from the outside as it possibly can?

I've enabled the firewall, but apart from that left everything at default.

Waiting to move anything to it before I know it's safe. Tnx for any answers in advance :)

Hi, It's a bit like I want to have it. There is not much to find about this subject, so lets try to get a little discussion. So far, I have enabled UBSA (User Based Share Access), created a user with password and made a CIFS/NFS and WEB share for MYSHARE1. (If I disable WEB, the router shoots "There is no share!" to me when I try to open the shares via the webinterface.). I have authorised the user for this share. Now he can go there after login.
I have another share, only NFS, without an authenticated user. I can mount this share as root without a password. Now I HOPE this is not possible from the WLAN and WAN interfaces, but I'm not shure.

Secondly, I enabled the WAN -> LAN filter in the Firewall. I just DROP everything not specified, and I did not specify anything, so I HOPE no-one will be able to reach the Asus from the WAN side, while I am still able to surf through it.

I you don't need the WLAN interface, you could disable the radio. (Wireless -Advanced). But if you want it, make sure you enable encryption better that WEB.

So far, so good.
Marc

Martypapa
26-03-2007, 23:56
Hi Marc, tnx for joining this thread. Yes, the info is a bit scant.

I'm using WEB, but at the same time I'm not broadcasting the network name and I've also blocked anyone but a select few computers from connecting.

I've disabled the external FTP-access (someone in another thread wrote something about the content on the router being accessible by anyone knowing the IP as a default).