Solved

setting up security on Netgear N300 wifi router

Posted on 2012-04-04
8
1,963 Views
Last Modified: 2012-04-10
I setup a new Netgear N300 router and gave my business the defaults...basically nothing.  I need some assistance as far as setting up some type of security on this thing.  I turned on the wifi which comes predefined with a key, no problem there, but I wanted to know what else I can setup on the wired section.
0
Comment
Question by:vulture71
8 Comments
 
LVL 6

Expert Comment

by:Patrick Tallarico
Comment Utility
What firmware are you running?  There is an updated version that has a different interface than the older version.
0
 

Author Comment

by:vulture71
Comment Utility
Not really sure, I left the client side already.  

Can you tell me in general?
0
 

Author Comment

by:vulture71
Comment Utility
Hello stpmt11,

I just upgraded my N300 router to version:  V1.1.1.72.  What other security features can I use?
0
Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

 
LVL 78

Expert Comment

by:David Johnson, CD, MVP
Comment Utility
setup the wireless with wpa2
you  may want to restrict the mac addresses that can access it
TURN OFF or DISABLE QSS it is broken easier than WEP to gain access.
change the administrator name and password from the defaults.
change the SSID from the defaults. Mine is "RCMP_SECURITY_VAN"
0
 
LVL 44

Expert Comment

by:Darr247
Comment Utility
Which model do you have, specifically?
I searched on netgear's website for "N300" and when the list got to a dozen different models I stopped trying to narrow it down without asking.

WNXR2000
DGNB2100
WNB2100
WNR2200
DGN2200
DGN2200M
WNA3100
WNA3100M
DGND3300
DGN3500
WNR3500
WNR3500L

I use WPA2/AES on the main and guest SSIDs of my WNR3500L running SamKnows firmware, without any problems.

Netgear assumes if the person has physical access to the router so they can plug in a network cable to it, they're supposed to be able to have network access.
What kind of restrictions were you hoping to make on the wired ports?  
You could always epoxy the LAN ports closed... that would secure them.
0
 
LVL 61

Accepted Solution

by:
btan earned 500 total points
Comment Utility
Minimally go for wpa2/psk and use not broadcast ssid where possible to avoid unnecessary snooping and attempt to break system via bruorce. This especially if you are allowingcontractor into the wlan as well or public facing. It can be a bridge point into corporate lan, so do segregate these two lan physically if possible through single switch vlan since there is allowing config to vlan hop or bridge.

Have access control list configured to allow trusted and known MAC address for authentication reach. To avoid rogue devices or ap attempting bridge to our ap. Kind of whitelisting. Also change all default admin and user account esp when they can be found easily in admin guide public available.

Some netgear links....also need user security savvy as well

 http://support.netgear.com/app/answers/detail/a_id/112/~/secure-your-wireless-network%3A-wpa%2Fwpa2-(recommended)
 http://support.netgear.com/app/answers/detail/a_id/13112
 http://support.netgear.com/app/answers/detail/a_id/1104/~/guide-to-internet-security
0
 
LVL 44

Expert Comment

by:Darr247
Comment Utility
In my opinion, not broadcasting the SSID just makes it a more-attractive target for hackers.
Then they'll spend days brute forcing the WPA2 security 4 times per minute, because the 'hidden' SSID can be sniffed when authorized users connect to it.
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now