Well the Netgear router is also wireless and there is 3 WAP's connected to a network switch.
Seems that i need an extra firewall device to protect the internal network especially SBS.
DHCP was on the router and now on SBS
You can make sure that your DHCP services on your server is set to only respond to the local segment of IP addresses. Also, it is also possible that you have enabled DHCP services to come from your router itself. Be sure that router DHCP services are disabled as this is best practices with a Windows SBS.
Additionally, you should make sure that all incoming ports from the WAN side of your network are blocked except for the ports you want open. For instance, by blocking the port 67 incoming from WAN to LAN/DMZ, you will prevent the request from even reaching your LAN in the first place.
Remote users connect to a WAP through a switch in their office which connect to a WAP at our main office.
The WAP @ main office is connected to our main switch.
The Netgear router is also wireless for internal use but it is protected by WEP and shared secret.
So my question: How does someone get an IP address from the SBS DHCP if all WAP's have shared secrets etc.
Ok.But how do people connect to a WiFi is the SSID is not being broadcast under available wireless network list?
I have checked myself and none of the WAP's broadcast their SSID's but yet still foreign computers appear in SBS DHCP?
It's possible you have some outside person intentionally accessing your network. Hiding your SSID and using WEP don't really protect your wireless network. There are many free programs that still show your SSID even if you are not "broadcasting" it. Also, someone might have seen the SSID before you hid it.
I would recommend changing the SSID again, enabling WPA instead of WEP, possibly blocking wireless access by MAC address of the NICs that should access it, and ensuring any AP or router that has WAN access is properly configured to block outside incoming traffic.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.