Showing posts with label WPA2-AES. Show all posts
Showing posts with label WPA2-AES. Show all posts

Saturday, October 15, 2016

WEP vs WPA

WEP vs WPA

The best way to secure your wireless network is to change the type of encryption that your computer uses to send data. The three most common choices for encrypting your data are WEPWPA, and WPA2. This guide describes these different types of encryption so that you can decide which is the best choice for your network.

WEP

WEP (Wired Equivalent Privacy) was introduced in 1999 and at first, it was thought to be as secure as a wired network. WEP uses a password to create a static encryption key that it then uses to encrypt data sent over the web. This means that the same key is used for all of the information or "packets" you send over the air waves during a session. This static key becomes a big problem with security because a key that doesn't change is much easier to attack than one that is constantly changing. WEP is not a "wired equivalent," as it's name suggests; it can be cracked in less than a minute by a commonplace hacker. Unfortunately, a lot of older routers have WEP as their default choice.

WPA and WPA2

Due to the major inefficiencies of WEP, WPA (Wi-Fi Protected Access) became available. WPA was the intermediate step between WEP and WPA2 and was not intended to be used indefinitely. WPA uses a type of temporary encryption key that changes with each packet sent over the web. Also, WPA enables your router to automatically reject any packets that it receives out of order. This is good because it prevents hackers from injecting packets onto your network which is one of the primary means of getting in.


In 2006 WPA2 became mandatory in all new Wi-Fi devices. WPA2 replaced WPA's temporary key with a superior government level security encryption. This upgraded encryption uses AES (Advanced Encryption Standard) thought to be uncrackable at this point. WPA2 is considered very secure.

WPA2 Modes

WPA2 has several different versions to choose from:
·   WPA2-Personal is sometimes referred to as WPA-PSK (Wi-Fi Protected Access Pre-Shared Key). With WPA2-Personal, you set up a password in your router which you share with those you want to have access to your network. This password is entered through the computer or device that is connecting to your Wi-Fi network. We recommend this security mode for home networks.
·   WPA2-Enterprise is used for businesses only.
·   WPA/WPA2 Mixed Mode may also be a choice in your particular router. This means your router uses WPA2 if possible but falls back on WPA when needed. Due to WPA2 being a much safer choice, we recommend not using this mode. If you have devices that are not compatible with WPA2, we recommend updating your equipment to better protect yourself against unwanted security attacks.
Both WPA and WPA2 require the use of a strong password, it is recommended that you use a password of at least 20 characters, including symbols and numbers. Check out this guide to learn more about how to create a strong password.

Recommended Wi-Fi Settings

The security of the information you send over the internet should be of top priority. We recommend using WPA2-Personal whenever possible since it has the strongest encryption. WPA should be a far second choice and WEP should not even be considered a choice. If you have a router newer than 2006 you should have a firmware upgrade that allows for WPA2-Personal, which we highly recommend upgrading to. If you have an older router, made before 2006, you may want to consider upgrading your device to a newer one that can be better secured.
Also note, that after changing your router to a different encryption type, you will need to re-configure all of your wireless devices to your network. Devices like wireless printers, phones, music players, gaming consoles, and wireless televisions may need to have their settings changed and be re-connected to you network.

Friday, September 18, 2015

Point To Point Communication for IP Camera

Point To Point with Nano Tp-LocoM5

Many Installers are requesting methods to connect their Security Systems. From running cable race ways in commercial buildings to installing conduit above or below ground in residential installations, running wired connections can take a lot of time – which equals more money to spend in labor. This article can serve as a guide on how to maximize the use of our Nano Station Loco M5. In this article we will be going to be utilizing an IP Megapixel system.

Example: IP camera System
Items Needed:-
TP-Loco M5
Any IP camera
Any NVR
Category 5, 5e or 6 Cable / Patch Cables
PoE Switch

Before installing any hardware we first need to configure the Nanos. Lets start by Configuring the Nano that will act as an Access Point. This is the one that will be located at the Main Network.
Nano (Access Point)
Navigate to http://192.168.1.20 on your web browser. If you get this page . Click on “Continue to this website (not recommended)”
This is the correct page you should see displayed on your browser. Once you are here you can log in using UBNT as Username and Password.
Select your Country and agree to the terms of use by ticking the radio button.
Once you have gained access to the Main GUI, navigate to the Wireless Tab
Match the Settings displayed.
Wireless Mode: Access point
WDS : Enabled
SSID: UBNT_Bridge
Security : WPA2-AES
Preshared KEY: UBNT2014
Hit Change but not apply.
Network Mode: Bridge
Static Ip: 192.168.1.159
Match your Gateway as well as the DNS server. In this example we left this out as many networks are different.
Finally hit apply.
Once you have applied the settings your Nano will restart and you can install the Access Point at the Main location where the Main network is.
Nano (Station)
Lets go ahead and open an internet browser.
Navigate to http://192.168.1.20
Use the following credentials to log in.
Username: UBNT Password: UBNT
Select your Country & Language
Check the radio button to Agree the terms of use as.
Once you are loge in navigate to the Network Tab
Use the Following settings
Wireless Mode: Station
WDS : Enabled
SSID: UBNT_Bridge
Security : WPA2-AES
Preshared KEY: UBNT2014
Navigate to Network
Use the Following settings
Network Mode: Bridge
Static Ip: 192.168.1.160
Match your Gateway as well as the DNS server in this example we left this out as many networks are different.
Navigate to the Ubiquity tab
Make sure to match these settings and hit apply.
Once you have completed both Nanos you can install them making sure that they both have line of sight between the devices, some minor adjustments can be done to ensure a good connection.
The Nano’s will lock onto the network by themselves or you can click on the SELECT button this will open up a tab that will display any Access Points in the area select the correct one and lock onto it.
Once you have completed setting up your Point to Point Bridge we can focus on the location.
In this illustration you can see that the Nano (Access Point) is in line of sight with the Nano (Station) that has an IP camera connected to it.
The Connections are simple

Site Side
1.        Connect the camera that you need to add into your Main network onto its own PoE Switch “POE Port”
2.        Attach the “LAN” Cable on the single port PoE switch to the “LAN” on the PoE switch from the Nano (Site)
3.        Attach the “PoE” Cable to the Nano Station “LAN” port.
Main Side
1.        Connect the Nano Station to its PoE switch  (“LAN” to “PoE”)
2. Attach an Ethernet cable from your Router LAN port to the “LAN” port located on the Nano stations PoE switch.

*NVR connections are simple simply attach your NVR to the Router  by attaching a cable in between the LAN port on the NVR to the LAN port of your router.

Mounting Options:
The Nanos come already designed to be attached to a pole, there is a supplied Nylon Zip Ties.

Troubleshooting Tips:
If you have successfully connected all of the devices and you cannot seem to ping your camera on any device on the Station side, make sure that the WDS is enabled in both the AP and Station.
If signal is poor you can use the AirView Application to check your signals. If you are not that tech savvy you can use the Signal bars behind the units or simply log in to both and tweak your nano’s position.
Once you have completed mounting your camera and Nano stations as well as configuring your Nano’s, your system should be up and running.
Also, to view your cameras outside your network, some port forwarding is needed. Ports that need to be opened are 37777,37778 and HTTP ports.
Back to Top