Subscribe to our RSS Feeds
Hello, this is a sample text to show how you can display a short information about you and or your blog. You can use this space to display text or image introduction or to display 468 x 60 ads and to maximize your earnings.

Wednesday, August 11, 2010

Wireless Internet Service Providers

Wireless internet service providers offer you the service of the broadband wireless internet. Classification of providers by the technology they use and what they are offering to you as a client.

Wireless internet service providers (WISPs) are the providers of broadband wireless internet.

Below are the most common types of wireless internet providers:

1) WiFi providers
2) Satellite internet providers
3) WiMAX providers
4) Mobile internet access or cellular internet providers

Every type of wireless internet providers has its advantages and disadvantages. Before choosing, learn about each of them and what they offer to you.

My opinion is that Mobile internet access or cellular internet providers are now the best choice. They have the largest coverage. In every area where there is coverage for your cellular phone, there is also coverage for internet access. This option is also cheap, because you get packet transfer along with your voice service. The biggest problem is the quality of service and the bandwidth. The new standards offer much wider bandwidth and better QoS so mobile internet access is becoming even more competitive.

WiFi providers are the best option, if you look for bandwidth and reliability. But there is no signal in private places like your home. WiFi is available at public places like airports, hotels, coffee shops, Internet Cafes, restaurants. This kind of access is called WiFi Hot spot.

The problem with WiMAX is that such providers are still very rare. WiMAX and WiFi are similar technologies. Though WiMAX has much wider range than WiFi, it uses the frequency spectrum which requires licensing. This means that WiMAX provider needs to buy a license from the government.

Satellite internet providers are the best option for isolated areas. In every inch of the world you could use Satellite internet access if you have the proper equipment. The most significant issue with satellite internet is the price. Satellite internet access is the most expensive among all.

When we talk about billing system, the most common option is monthly fee and the other option is pay as you go wireless.


Tuesday, August 10, 2010

Troubleshooting Wireless Networks

This article is not relevant if:

* Your equipment never installed correctly.
* You have no Internet connection, even wired. (See Troubleshooting When There is No Internet Access.)
* You can access some Internet programs, but not others. (MTU, Partial Loss of Internet Connection or Cannot Log on to AOL Through Router)
* Your connection only drops at times. (Internet Connections Drops Repeatedly)
* There are abnormal LEDs (no power light, test light that won't go off, port lights that won't come on). Consult the manuals for light problems.

1. Download and install the latest software for your device. Visit the product page for your NETGEAR device.

2. Each wireless device must have the same settings:

* SSID : This is case sensitive. (Netgear is different from NETGEAR). The default SSID for Netgear wireless device was changed from "wireless" to "NETGEAR".
* Channel: The wireless channels are 1 to 11 (1 to 13 in some countries)
* Mode: The wireless mode should be set to either ad hoc or infrastructure. See Choosing Between Ad Hoc and Infrastructure Mode
* Encryption. You have these options for encryption:
o Don't use any
o Use WEP What is WEP?
o Use WPA-PSK What is WPA?
o Use WPA
o Some equipment allows you to use VPN What is VPN?
* Enable wireless access point.
* If Access Control List (ACL) is enabled on your router, make sure the MAC address of the wireless adapter is included in that list.

3. When configuring a router:

* The username must include a whole address like smartsue@example.com — NOT just "smartsue".
* After making changes, click Apply!

4. If the signal strength indicator is red, see Improving Wireless Range. Any color but red is acceptable.

5. If you have enable security and having problem connecting, disable security by setting encryption to "None" and try connecting again.

6. For Windows 95 and Windows 98, look in the Windows Device Manager to see if the NETGEAR equipment has a yellow exclamation mark (an IRQ conflict). Instructions applying to generally to Windows systems are in Resolving IRQ Conflicts. If you have an IRQ conflict, resolve it first.

Fixing Wireless connectivity (including AirPort) problems: Dropouts, slow speed, more

Troubleshooting issues with wireless connectivity can be tricky. There are a bevy of potential causes for drops in the connection, slow-downs in throughput and sporadic signal loss. As such, it's best to take a shotgun approach, throwing a number of possible fixes at the problem and hoping one sticks.

We've gathered some of the most common workarounds, listed below, along with indications for when they are most likely applicable. Issues addressed include:

  • Repeated dropouts (Connection lapses sporadically)
  • Poor wireless throughput (Slow network speed)
  • Router [AirPort Base station included] not recognized (doesn't appear in available networks)
  • Cannot connect to router [AirPort Base station included] ("Error joining network" message may be displayed)
  • No Internet Access (router can be connected to from client systems, but Internet access fails)
  • Built-in AirPort hardware not recognized
  • System will not automatically reconnect to network after sleep
  • Weak reception (poor signal strength)

Note, however, that some workarounds listed for specific issues may also work for other AirPort issues. Run through the entire list of solutions if those associated with problems you are experiencing are unsuccessful.

Toggle firmware [Useful for: repeated dropouts, poor wireless throughput]

Toggling of firmware versions (the edition of controller software stored on your wireless router) is perhaps the most successful fix for dropouts from virtually all wireless router models. By "toggling firmware," we mean trying different versions available from your manufacturer until one provides a more stable connection. In other words, a user's first attempt should always be use of the latest firmware version, but sometimes older versions provide better stability.

Unfortunately, the trick is in locating appropriate firmware updates. You can usually find the different firmware editions on a router manufacturer's Web site, but some vendors fail to offer the updates or old versions in Mac-based installer packages.

For Apple Base stations, the process is as easy as downloading and installing the desired firmware edition on an AirPort Express or Extreme Base station. Apple maintains older firmware versions on its download page, and they are easily applied from a familiar installer interface.

To check which AirPort Base station firmware revision you currently have installed, use the following process:

  • Launch AirPort Admin Utility (located in Applications/Utilities)
  • Select the appropriate Base station in the left-hand pane
  • The firmware will appear on the right side, as follows: "Apple Base Station... "

Toggling AirPort Extreme firmware The latest AirPort Extreme firmware version is 5.7 and this edition should be used primarily. However, the most commonly successful solution for constant AirPort Extreme dropouts is a downgrade of firmware to version 5.5.1. Reverting (or updating to) this edition of the firmware has eliminated dropouts for a surprisingly high number users.

In order to install firmware version 5.5.1, simply download the package, launch the updater application and follow the on-screen instructions, selecting your afflicted Base station.

A quick caveat: Downgrading your firmware potentially poses some significant security risks that should not be overlooked. By reverting, you'll also lose the enhancements made in the latest firmware edition, including purported performance enhancements.

Still, the astounding success with which this workaround has been applied makes it a good option for users who cannot reasonably use their AirPort Extreme Base stations for extended periods of time.

Toggling AirPort Express firmware The latest firmware edition for the AirPort Express is version 6.3, and should be used primarily. Like the AirPort Extreme, however, some AirPort Express units can benefit from a firmware downgrade to version 6.1.1. The instructions for installation are the same: simply download the AirPort Express 6.1.1 Firmware package, launch the updater application and follow the on-screen instructions, selecting your afflicted Base station.

The same security/enhancement caveats apply.

Turn router (including AirPort Base Stations) off, then on [Useful for: repeated dropouts, no Internet access]

In some cases, turning a wireless router (including AirPort Base Stations) off, then back on -- usually by unplugging then re-connecting to power -- re-establishes proper operation in the event of a dropout. This is a method of recovery rather than obviation, however.

Performing a hard reset of your router (including AirPort Base Stations) [Useful for: repeated dropouts, no Internet access]

This is an easy workaround, an is effective in a surprisingly high number of problematic cases where AirPort Base Stations will not appear in the AirPort Admin utility or refuses to allow Internet access.

Instructions for performing a hard reset involves first unplugging your Base Station from power and the active network connection, then following the instructions in the following Knowledge Base documents:

Note that after performing a hard reset you will need to connect your Mac to the Base Station via a wired (Ethernet) connection in order to re-configure it and apply the proper networking configuration via AirPort Admin Utility.

If your third-party router has a reset button, try using it for a similar effect.

Turn off wireless encryption (WEP, WPA) [Useful for: cannot connect to router, slow wireless throughput] If you have repeated problems connecting your your wireless router, try turning off any wireless encryption methods in place. For AirPort Base stations, this can be accomplished using the AirPort Admin Utility (located in Applications/Utilities).

Switching channels [Useful for: repeated dropouts, no Internet access, weak reception]

In some cases (especially when interference is at play) switching channels on your AirPort Base station or third-party router can improve reception weakened by various causes. In order to switch channels on AirPort Base stations, use this process (from Knowledge Base article #166641):

  1. Open AirPort Admin Utility, located in /Applications/Utilities.
  2. Select the appropriate (afflicted) base station and click Configure.
  3. Enter the base station password if necessary.
  4. Click AirPort, and then choose a new channel from the Channel pop-up menu.

Consult your third-party router's manual for information on switching channels. This can usually be accomplished by accessing the router's configuration page -- open a browser and enter the address 192.168.1.1.

Turn "Distribute IP Addresses" off [Useful for: router not recognized, cannot connect to router]

If you are having problems where your AirPort Base station or router is unrecognized and connected to a DSL/Cable modem, the issue may be attempted distribution of IP addresses from the AirPort Extreme Base Station, resulting in a conflict with the distribution of IP addresses from the DSL/Cable modem -- a situation which can be fixed by using the AirPort Admin Utility to turn "Distribute IP Addresses" off.

Select "Make Changes to existing AirPort Base Station [Useful for: router not recognized]

When you experience an issue where the desired wireless network looks as though it is accessible (through the AirPort menu item or the Internet Connect application), but delivers the message "There was an error joining (name of network), the most commonly successful workaround is to open the AirPort Setup Assistant (located in Applications/Utilities), then click "Make changes to existing AirPort Base Station". You will be prompted for your WEP or WPA password if one exists.

After saving the settings -- even if no actual changes were made -- AirPort access is restored in some cases.

Disable Remote configuration [Useful for: slow wireless throughput]

If you are experiencing inordinately slow transfer speeds through your AirPort Base station though a strong signal exists, you may want to try this workaround which involves disabling remote configuration on AirPort Base Stations upgraded with the firmware included in the AirPort 4.2 updater package -- resulting in the removal of a potential speed bottleneck introduced with the new firmware.

This workaround is accomplished via the following process:

  1. Open the AirPort Admin Utility (located in Applications/Utilities)
  2. Select the desired Base Station from the availability list
  3. Go to the "Base Station Options" tab
  4. Click on "WAN Ethernet Port"
  5. Uncheck the box next to "Enable Remote Configuration."
  6. Save your AirPort Base Station settings

Delete all "Preferred Network" listings then re-establish [Useful for: router not recognized, cannot connect to router]

One surprisingly effective AirPort Base station-specific fix for an inability to connect to wireless networks involves deleting all stored preferred networks, then re-establishing any used listings. Here's the process:

  1. Open System Preferences and select the "Network" pane
  2. Select "AirPort" and click "Configure"
  3. In the "By default, join:" pull-down menu, select "Preferred networks"
  4. Delete the network(s) you regularly use from the list
  5. Launch the "Keychain Access" application located in Applications/Utilities.
  6. Click on the "Kind" filter at the top, and look for "AirPort network password" entries. Delete them.
  7. Restart, or log out then back in.
  8. Repeat steps 1-3, this time re-adding your regularly used AirPort networks to the list using the " " button.
  9. Restart or log out then back in.
Reset PMU/SMC/NVRAM for AirPort card power issues [Useful for: Built-in AirPort hardware not recognized]

Some data suggests that a power-related issue may be at play in the issue of AirPort cards not being recognized.

In these cases, resetting your Mac's power management unit (PMU) for PowerPC-based Macs or system management controller (SMC) for Intel-based Macs may be helpful.

Instructions for resetting the PMU for various PowerPC-based Mac models are contained in the following Knowledge Base articles:

  1. Mac Mini
  2. PowerBook and iBook
  3. Power Mac G5

Instructions for resetting the SMC for various Intel-based Mac models are contained in the following Knowledge Base articles:

Resetting NVRAM may also resolve some AirPort-related power issues.

In order to perform this process, shut down your Mac, then start it back up while immediately holding the following keys: Command, Option, P and R. Hold the keys down until the computer restarts and you hear the startup sound for the third time.

Turning AirPort card off then on [Useful for: no Internet access, cannot connect to router]

You may want to try turning your internal AirPort card off then back on if you are having access issues. This can be accomplished through the AirPort menu item, or using Internet Connect (located in the Applications folder)

Check for/quit third-party wireless applications (monitors/sniffers) [Useful for: slow wireless throughput, repeated dropouts]

Some third-party applications that manipulate or otherwise interact with the wireless connection may cause problems -- particularly an issue where speed vacillates quickly between normal and dismal throughput.

Among the implicated applications are older versions of coconutWiFi.coconutWiFi is an application displays you a small aqua-bubble at the top of your screen which indicates whether or not. you're in range of a wireless network. Current versions of the application do not exhibit this bug.

Reverting to older AirPort kernel extensions [Useful for: slow wireless throughput, router not recognized]

f you are experiencing dire AirPort connectivity issues after a major system update (incremental Mac OS X update or Security Update), and have exhausted all other workarounds, you can try reverting to older version of the AirPort kernel extension via the following steps: [WARNING: This workaround is risky because you should not generally mix and match kernel extensions after updates. You will also lose any AirPort-related refinements brought about by the most recent update and new conflicts can ensue. Still, in a bind, it can restore wireless connectivity where other workarounds fail.]

  1. Download the Mac OS X combo updater directly precedent to your current system version if you applied an incremental Mac OS X update (e.g. Mac OS X 10.4.9), or your current system version if you applied a security update from Apple's download page.
  2. Download and install the shareware application Pacifist
  3. Drag the Mac OS X combo installer package (e.g. MacOSXUpd10.4.9Intel.pkg) onto the Pacifist application icon.
  4. Click the triangle next to System to expand it
  5. Click the triangle next to Library to expand it
  6. Click the triangle next to Extensions to expand it
  7. Scroll down and find the file AppleAirPort.kext. Drag it to your Desktop or another location (you will have to enter your administrator password)
  8. On your Mac OS X startup drive, navigate to /System/Library/Extensions and locate a similarly named file (AppleAirPort.kext). Move it to another location for safe keeping.
  9. Now drag the file from step 7 (the one that you retrieved from the Mac OS X combo install package) into the /System/Library/Extensions directory on your startup, in effect replacing the newer file (installed by the AirPort updater) with and older copy -- you will have to enter an administrator password.
  10. Restart your Mac

Remove kernel extensions (Mac OS X 10.3.9) [Useful for: slow wireless throughput, router not recognized]

If you are running Mac OS X 10.3.9 and are experiencing this issue, navigate to /System/Library/Extensions and drag the following files (if they exist) to the Desktop or another location outside the System folder:

  • AppleAirport2.kext
  • AppleAirportFW.kext

Restart your Mac and check for restoration of AirPort connectivity

"Keep Looking for recent networks" [Useful for: router not recognized]

In some cases, selecting "Keep looking for recent networks" in the Network pane of System Preferences can resolve an inability to connect to local networks.

Change security protocol [Useful for: repeated dropouts, slow wireless throughput]

In some cases, WEP key-based access can provide better speeds when compared to the more secure WPA standard, or vice versa. Try switching to a different protetction method if you are having issues with one.

This setting can be changed on AirPort base stations by using the AirPort Admin Utility (located in Applications/Utilities) to configure the target base station.

Delete then re-establish wireless network [Useful for: system will not automatically re-connect to network after sleep]

You may need to delete then re-establish any encrypted AirPort network configurations in order to take advantage of automatic reconnection capabilities after sleep or restart.

Move SystemConfiguration folder [Useful for: weak reception]

Moving the folder SystemConfiguration located in /Library/Preferences, to the Desktop then restarting can resolve some connectivity issues. This workaround appears to be effective because of permissions problems that can affect the SystemConfiguration folder, and the therein contained com.apple.airport.preferences.plist file. Note that this workaround will require you to re-enter network configuration settings and may cause other lapses in functionality.

Watch for device interference [Useful for: weak reception, slow wireless throughput]

Other wireless devices operating on the same spectrum can cause interference with your AirPort connection. In fact, 2.4 GHz wireless phones and even household microwaves can cause lapses in connection or drops in speed. For information on which devices can cause interference, see Knowledge Base article #58543.

Turn on Interference robustness [Useful for: weak reception, slow wireless throughput]

Try turning on the Interference robustness option -- accessible in the AirPort menubar item, or by selecting "AirPort" from the Network pane of System Preferences then clicking "Options..."

Delete specific .plist files [Useful for: System will not automatically reconnect to network after sleep, slow wireless throughput, cannot connect to router]

Try deleting the following files from the ~/Library/Preferences/ directory (this is the Library directory within your User folder):

  • com.apple.internetconfig.plist
  • com.apple.internetconfigpriv.plist
  • com.apple.internetconnect.plist


Monday, August 9, 2010

Hotspot (Wi-Fi)

A hotspot is a site that offers Internet access over a wireless local area network through the use of a router connected to a link to an Internet service provider. Hotspots typically use Wi-Fi technology for the wireless network. Hotspots may be found in coffee shops and various other public establishments throughout much of North America and Europe.

History

Public access wireless local area networks (LANs) were first proposed by Brett Stewart at the NetWorld+Interop conference in The Moscone Center in San Francisco in August 1993. Stewart did not use the term hotspot but referred to publicly accessible wireless LANs. Stewart went on to found the companies PLANCOM in 1994 (for Public LAN Communications, which became MobileStar and then the HotSpot unit of T-Mobile USA) and Wayport in 1996.

The term HotSpot may have first been advanced by Nokia about five years after Stewart first proposed the concept.[citation needed]

During the dot-com period in 2000, dozens of companies had the notion that Wi-Fi could become the payphone for broadband. The original notion was that users would pay for broadband access at hotspots.

Both paid and free hotspots continue to grow. Wireless networks that cover entire cities, such as municipal broadband have mushroomed. WiFi hotspots can be found in remote RV / Campground Parks across the US.

Many business models have emerged for hotspots. The final structure of the hotspot marketplace will ultimately have to consider the intellectual property rights of the early movers; portfolios of more than 1,000 allowed and pending patent claims are held by some of these parties.

Uses

The public can use a laptop, Wi-Fi phone, or other suitable portable device to access the wireless connection (usually Wi-Fi) provided. Of the estimated 150 million laptops, 14 million PDAs, and other emerging Wi-Fi devices sold per year for the last few years, most include the Wi-Fi feature.

For venues that have broadband Internet access, offering wireless access is as simple as purchasing one AP, in conjunction with a router and connecting the AP to the Internet connection. A single wireless router combining these functions may suffice.

Locations

Hotspots are often found at restaurants, train stations, airports, military bases, libraries, hotels, hospitals, coffee shops, bookstores, fuel stations, department stores, supermarkets, RV parks and campgrounds, public pay phones, and other public places. Many universities and schools have wireless networks in their campus.

Types

Free Wi-Fi hotspots

Free hotspots operate in two ways:

* Using an open public network is the easiest way to create a free HotSpot. All that is needed is a Wi-Fi router. Private users of wireless routers can turn off their authentication requirements, thus opening their connection, intentionally or not, for sharing by anyone in range. The disadvantage is that access to the router cannot be controlled.

* Closed public networks use a HotSpot Management System to control the HotSpot. This software runs on the router itself or an external computer. With this software, operators can authorize only specific users to access the Internet, and they often associate the free access to a menu or to a purchase limit. Operators are also now able to limit each user's available bandwidth - each user is therefore restricted to a certain speed to ensure that everyone gets a good quality service. Often this is done through Service Level Agreements.

Commercial hotspots

A commercial hotspot may feature:

* A captive portal / Login Screen that users are redirected to for authentication and payment
* A payment option using credit card, PayPal, iPass, or other payment service
* A walled garden feature that allows free access to certain sites
* Service_oriented_provisioning to allow for improved revenue

Many services provide payment services to hotspot providers, for a monthly fee or commission from the end-user income. ZoneCD is a Linux distribution that provides payment services for hotspots who wish to deploy their own service.

Hotspots that intend to offer both for fee and free internet access may want to look at Amazingports and their implementation of Service_oriented_provisioning

Major airports and business hotels are more likely to charge for service. Most hotels provide free service to guests; and increasingly small airports and airline lounges offer free service.

Roaming services are expanding among major hotspot service providers. With roaming service the users of a commercial provider can have access to other provider's hotspots with extra fees, in which such a user will be usually charged on the basis of access-per-minute. Roaming agreements can be hard to negotiate with larger providers such a Boingo, so smaller hotspots usually use an aggregator such as www.gowifi.com to access these networks.

FON is a European company that allows users to share their wireless broadband and sells excess bandwidth to outside users (Aliens). Since this may breach users terms of service, FON has agreements with many broadband providers / ISPs.

Security concerns

Some hotspots authenticate users. This does not secure the data transmission or prevent packet sniffers from allowing people to see traffic on the network.

Some vendors offer virtual private network (VPN) as a security option. This solution is expensive to scale

Also, it may still not be secure as only the connection between user and network is shielded, and the network itself is not.

Some vendors provide a download option that deploys WPA support. This conflicts with enterprise configurations at large enterprises that have solutions specific to their internal WLAN.

A "poisoned/rogue hotspot" refers to a free public hotspot set up by identity thieves or other malicious individuals for the purpose of "sniffing" the data sent by the user. Such identity thieves will have access to the MAC address of the connecting terminal, which individually identifies the hardware. By examining packets sent, they may attempt to decipher passwords, login names, or other sensitive information.

Security fix for wireless

Things are looking up on the wireless-networking front.

First and foremost, it looks as though a relatively quick and painless fix may be in the offing for the security problems hanging over the hot wireless technology known as 802.11 -- a.k.a. Wi-Fi, or wireless Ethernet or, depending on your vendor, AirThis or AirThat.
In recent months, you'll recall, cryptographers have identified a series of flaws in the options the IEEE 802.11 spec provides for protecting network traffic from snoopers.

Last month the problem reached crisis proportions, when a team of internationally renowned experts published a paper detailing a gaping hole in WEP, the standard's data-encryption scheme. At least two teams of programmers quickly followed up by posting downloadable programs that make it easy to exploit the newly revealed flaw.

Now, you may not care whether anyone is eavesdropping on your e-mail and Web surfing. Or you may calculate, as I usually do, that you're safe simply because no one is likely to care enough about your boring existence to bother.

But if you're not willing to run that risk, the only prudent assumption at this point, as I noted here last week, is that anything you send over 802.11 is vulnerable to interception -- even if you have all the protocol's standard security mechanisms turned on.

As a team of scientists at NASA's Ames Research Center put it in a press release they issued last week to announce their own home-grown solution, they "decided not to depend on any security provisions bundled with 802.11b products." Instead, they began from "the premise that the network itself provides no reliable authentication and no security from eavesdropping."

(Of course, NASA can afford to take that position, because it has staffers who can develop their own alternative. All they needed, according to the release, was an off-the-shelf PC, some freeware Unix utilities and 40 hours of coding by two security experts. For those of us who don't have such talent at hand, the choices for now are badly flawed security or none at all. In that context "badly flawed" is probably preferable if you're concerned at all about privacy.)

TGI TO THE RESCUE: Even before WEP's vulnerability became public knowledge, the IEEE committee responsible for the 802.11 specification had a task force known as Task Group i developing plans to beef up the standard's security section.

But one of the schemes they were planning, known as WEP2, turned out to be just as vulnerable as the original version to the hack disclosed last month. An alternative encryption technology they were proposing was much more secure, but probably would not have worked on existing 802.11 cards. And the access- control scheme they were working on would require a special back-end authentication server -- something few small offices, let alone home users, are likely to have or want to get involved with.

As recently as a month ago, it appeared that products incorporating the improved security standard -- called 802.11i -- wouldn't be available until the second quarter of next year, or even later. And there were serious doubts as to whether cards and base stations manufactured before that would be upgradable to the new standard.

Here's where we finally get to the good news I promised: In response to the crisis, TGi convened a special session in Seattle last week. Four proposals were submitted for fixing the WEP problem, and while they differ in detail, they're sufficiently similar that it shouldn't be hard to hammer out a single unified plan, according to Dennis Eaton, vice chairman of the Wireless Ethernet Compatibility Alliance, the trade association that represents 802.11 vendors.

All four proposals provide a secure solution to all of the vulnerabilities so far identified, according to Eaton, who also chairs the alliance's technical and security committees. All four would work automatically, transparent to users. And they should have little or no negative effect on network speed, he said.

All four plans were also designed to work on existing Wi-Fi cards and base stations or access points, with only software and firmware updates required, according to Eaton said. (Of course, he hastened to add, backward compatibility is "not a done deal" -- there can't be any guarantees until a unified proposal is completed and tested -- but "we're trying like heck" to deliver it.)

As to timing, the group voted unanimously to offer its interim solution without waiting for the full, next-generation security spec to be completed. With luck the fix should be ready this fall.

That may mean it will never be part of an official wireless standard, but under that scenario TGi would hand it off to the 802.11 trade group, which would make it part of the test suite it uses as the criterion for awarding its "Wi-Fi" compatibility certification. Because virtually all vendors of 802.11 products already submit them to that process, the alliance's endorsement would make the security fix a de facto standard.

In other words, if all goes well, the current crisis could be just a bad memory within a matter of months -- perhaps in time for the holiday gift- shopping season. Last year Bill Gates reportedly gave 802.11 cards as Christmas presents. This year tens of thousands may follow his example -- and the recipients shouldn't have to worry about anyone intercepting their mail.

THE BIG GUN: Meanwhile, 802.11 also got a double-barreled endorsement from Intel last week.

The chipmaker has marketed 802.11 products for corporate customers since last year, but for the consumer market it was until recently committed to a rival technology called HomeRF. Last week, however, Intel announced a full line of consumer 802.11 products, which it will market as the AnyPoint II Wireless series.

The line includes a PC Card for notebooks, a USB adapter for desktops and a gateway or base station, all of which are competitively priced. (Details at www.intel.com/anypoint.)

(By the way, I erred a few weeks ago in saying that cards are useless without a base station. Any desktop or notebook PC with both an 802.11 card and a wired Internet connection can function as a base station. I don't usually recommend that approach because it means that PC has to be on for anyone else to get online wirelessly, but it does save some money.)

I haven't yet had a chance to try the Intel products -- they won't actually be in the stores for another week or two -- but I was impressed with what I saw in a demo last week. The setup software is the simplest I've seen this side of Apple's.

For now, Intel's products use only the flawed security mechanisms in the current 802.11 spec, but the company has paid attention to the problem. The products are the first I know of that ship with WEP encryption turned on. And while many vendors' software provides a default network ID, which most users never change and which hackers therefore have no trouble guessing, Intel's software prompts the user during setup to provide a unique name.

An even more important indicator of the company's enthusiasm for 802.11 came from Sean Maloney, a rising star in the company's management who recently assumed the tile of executive vice president and general manager of Intel Communications Group.

In a meeting with reporters at last week's Intel Developer Forum, he declared that 802.11 has already won out as the standard for the wireless portions of the giant Ethernet network he predicted will eventually circle the globe. "Bluetooth," he said, "is in full retreat."

(Intel's PR staffers later called to explain that he was talking only about Internet access and that Intel still views Bluetooth as a complementary technology with an important role to play for other applications, such as connecting phones and handheld organizers. But Maloney himself didn't bother to make any such distinction.)

He also suggested that Intel is likely to get into the business of making 802.11 chips. It won't bother with the current version, called 802.11b, but 802.11a, a faster version expected to come to market next year, "starts to look very interesting," and Intel already has hundreds of engineers working on it.

Given Intel's resources and experience in high-volume chip production, that sounds like a challenge for the current leader in the fledgling 802.11a market,

a Sunnyvale startup called Atheros Communications. But Intel's commitment should also mean declining prices, continuing technical progress and mainstream support for a technology that's already the most exciting innovation to hit computing in many a year.

Wireless Firewall Gateway White Paper

1. Introduction

With the deployment of wireless network access in the workplace, the requirement for a more enhanced security design emerges. Wireless technology offers a more accessible means of connectivity but does not address the security concerns involved with offering this less restrained service. In order to facilitate management of this network, maintain a secure network model, and keep a high level of usability, a multi-functional device to do these tasks must be placed in the wireless environment.

2. Design Objectives

The WFG (Wireless Firewall Gateway) is designed to take on several different roles in order for the process to be near transparent to the user. Since the wireless network is considered to be an untrusted environment, access is restricted in order to limit the amount of damage that can be inflicted on internal systems and the Internet if an intruder invokes an attack. This impedes the convenience of the wireless service to users who wish to access external sites on the Internet. Since unknown users are difficult to identify and hold accountable for damages, a method of user authentication is needed to ensure that the user takes responsibility for their actions and can be tracked for security concerns. A trusted user can then gain access to services and the commodity Internet from which unauthenticated users are blocked.

Keeping simplicity in mind, the WFG acts as a router between a wireless and external network with the ability to dynamically change firewall filters as users authenticate themselves for authorized access. It is also a server responsible for handing out IP addresses to users, running a website in which users can authenticate, and maintaining a recorded account of who is on the network and when.

Users of the wireless network are only required to have a web browser if they wish to authenticate and dynamic host configuration (DHCP) software, which comes standard on most operating systems. Minimal configuration is required by the user, allowing support for a variety of computer platforms with no additional software. The idea is to keep the wireless network as user-friendly as possible while maintaining security for everyone.

3. Internals

Given the multiple functionalities and enhanced security required for this device, a PC running OpenBSD Unix was chosen with three interfaces on different networks: wireless, external (gateway), and internal (management). The following sections elaborate upon the services that constitute the device's various roles:

3.1 Dynamic Host Configuration Protocol (DHCP) Server

DHCP is used to lease out individual IP addresses to anyone who configures their system to request one. Other vital information such as subnet mask, default gateway, and name server are also given to the client at this time. The WFG uses a beta DHCPv3 open-source server from the Internet Software Consortium with the additional ability to dynamically remove hosts from the firewall access list when DHCP releases a lease for any reason (client request, time-out, lease expiration, and so on). Configuration files for the server are located in /etc and follow the ISC standard (RFC) format. However, the server executable is customized and does not follow these standards. If the server needed to be upgraded, then the source code would need to be re-customized as well.

The DHCP server is configured to only listen on the subnet interface of the wireless network. This prevents anyone from the wired network to obtain a wireless IP address from this server. As an added security measure, packet filters prevent any DHCP requests coming in on any other interfaces.

3.2 IP Filtering

Stateful filtering is accomplished using OpenBSD's IPF software. IP routing is enabled in the kernel state allowing for the packet filtering to occur between the wireless and external network interfaces. Static filters are configured on boot up in the /etc/ipf.rules file and are designed to minimize remote access to the WFG. Only essential protocols such as NTP, DNS, DHCP, and ICMP are allowed to reach the system. This builds a secure foundation for the restricted environment. For the users who do not require an authenticated session, access is granted to selected servers for email, VPN, and web. Where applicable, packet filtering is done at a transport layer - UDP or TCP, to allow for stateful inspection of the traffic. This adds a higher level of security by not having to explicitly permit dynamic or private port sessions into the wireless network.

The same script that authenticates a user over the web also enables their access to the unrestricted environment. When a user connects to the web server, their IP address is recorded and upon successful login, gets pushed to the top of the firewall filter list, permitting all TCP and UDP connections out of the wireless network for that IP address.

In order to prevent succeeding users from being allowed trusted access when the IP address is recycled, the in-memory database software removes the firewall filter permit rule whenever the user's next lease binding state is set to free, expired, abandoned, released, or reset. The DHCP server will not issue the same IP address until it frees the lease of the last client. This helps avoids the security issue of someone hijacking an IP address that's been authenticated and using it after the valid user is no longer using the wireless service

3.3 Web Authentication

The need for web-based authentication is necessary so that any user running any platform can gain access to the wireless network. Apache (open-source) web server is designed to securely handle this task. The server implements Secure Socket Layer (SSL) for client/server public-and-private key RSA encryption. Connecting to the web server via HTTP automatically redirects the client browser to use HTTPS. This ensures that the username and password entered by a user will not be sent in clear text. To further increase security, the SSL certificate is signed by Verisign, a trusted Certificate Authority (CA), which assures that an attacker is not imitating the web server to retrieve a user's password information.

A website is setup where a user can go to type in their username and password information. This site displays the standard government system access warning and shows the IP address of the user's system (using PHP). Once a user has typed their username and password at the website where prompted, a Perl/CGI script then communicates with a Radius server with RSA's MD5 digest encryption to determine if the information submitted is correct. If the account information matches what is in the Radius database, then commands to allow their IP address, obtained through the Apache environment variables, are added to the IPF access rules. If the user is not found in the Radius database, or if the password entered is incorrect, a web page stating "Invalid Username and Password" is displayed to the user. If everything is successful, the user is notified of their privileged access.

3.4 Security

Every step is taken to ensure that a desirable security level is maintained both on the WFG system and the wireless network while not hindering functionality and usability. Only hosts connecting from the wireless network can access the web server. For system management purposes, Secure Shell (OpenSSH) connections are permitted from a single, secured host. All other methods of direct connection are either blocked by the firewall filters or denied access through the use of application-based TCP wrappers.

Users' authentication information is encrypted throughout the process: SSL encryption with a certificate signed by a trusted CA between the client's web browser and the server, and MD5 digest encryption between the web server and the Radius system for account verification.

Logs are kept for all systems, which gain access to both the restricted and authorized network. The DHCP server keeps a record of what MAC address (NIC address) requests an IP address and when it is released, then passes that information to syslog. Syslog then identifies all logging information from DHCP and writes it to /var/log/dhcpd. Additionally, any user who attempts to authenticate via the web interface has their typed username and source IP address logged with the current time along with whether or not they were successful. When a lease on an IP address expires and is removed from the firewall filters, it is noted with the authentication information in /var/log/wireless. These logs are maintained by the website script and DHCP server software, not syslog. Combined, it is possible to identify who is on the network at a given time - either by their userid, or by their burned-in physical address, for auditing purposes.

With the DHCP server managing the firewall filters, it is possible for a user to manually enter a static IP address and authenticate, with the permit rule never being removed. To prevent this, the CGI script reads in the dhcpd.leases file and determines if the source IP address, obtained through the environment variable $ENV{'REMOTE_ADDR'}, has an active lease. If no lease is found, or if the lease is expired or abandoned, authentication is denied.

For an optimal security solution, the use of Virtual Private Networks (VPN) is recommended. Since implementation of this solution requires VPN software to be installed and configured on each wireless client, it is beyond the scope of this whitepaper.

Wireless Internet Service

Homes, schools and businesses connect to the Internet today using a variety of different methods. One method, wireless Internet service, provides Internet access to customers without the need for underground copper, fiber, or other forms of commercial network cabling.

Compared to more established wired services like DSL and cable, wireless technology brings added convenience and mobility to computer networks. The below sections describe each popular type of wireless Internet service available.

Satellite Internet

Introduced in the mid 1990s, satellite became the first mainstream consumer wireless Internet service. Satellite access initially worked only in one direction, for downloading information. Subscribers needed to install a standard dialup modem and use a telephone line in conjunction with the satellite to make a functional system. Newer forms of satellite service remove this limitation and support full two-way connectivity.

Compared to other forms of wireless Internet service, satellite enjoys the advantage of availability. Requiring only a small dish antenna, satellite modem and subscription plan, satellite works in almost all rural areas not serviced by other technologies

However, satellite also offers relatively low performing wireless Internet. Satellite suffers from high latency (delay) connections due to the long distance signals must travel between Earth and the orbiting stations. Satellite also supports relatively modest amounts of network bandwidth.

Public Wi-Fi Networks

Some municipalities have built their public wireless Internet service using Wi-Fi technology. These so-called mesh networks join numerous wireless access points together to span larger urban areas. Individual Wi-Fi hotspots also provide public wireless Internet service in select locations.

Wi-Fi is a low-cost option relative to other forms of wireless Internet service. Equipment is inexpensive (many newer computers have the needed hardware built in), and Wi-Fi hotspots remains free in some locales. Availability can be a problem, however. You won't find public Wi-Fi access in most suburban and rural areas.

Fixed Wireless Broadband

Not to be confused with either satellite Internet or Wi-Fi hotspots, fixed wireless is a type of broadband that utilizes mounted antennas pointed at radio transmission towers.

Cell phones have existed for decades, but only recently have cellular networks evolved to become a mainstream form of wireless Internet service. With an installed cellular network adapter, or by tethering a cell phone to a laptop computer, Internet connectivity can be maintained in any area with cell tower coverage.

Older cellular communication protocols allowed for only very low speed networking. Newer 3G cell technologies like EV-DO and UMTS promise to deliver network speeds closer to those of DSL and other wired networks.

Many cellular providers sell Internet subscription plans separate from their voice network contracts. Generally speaking, mobile broadband service will not function without having an Internet data subscription in place from some provider.

WiMax is a relatively new form of wireless Internet. It utilizes base stations similar to cellular networks, but WiMax is designed specifically to provide data access and services rather than voice phone communications. When it becomes more mature and widely deployed, WiMax promises to offer full roaming capability and much higher performance networking than satellite at a lower cost.