>    Your dialup,dsl nor cable modem are secure either. Having a nat router
> only provides a very basic level of security. So why would you care if your
> wireless link is secure or not? Yeah running a isp is no joke and having
> something secure is ideal but if your customers don't ask for it then why
> bother? dialup customers have no clue that they are wide open on the net!

Wired network securty is significantly different than wireless network
security. DSL, dialup, Cable can easily rely on the physical security and
trust on the phone/cable network.

Especially with the wireless, the operator has to at least authenticate the
client before the access is authorized. If you skip this part, you end up
providing free service to all. Once the initial access authentication is
done, you need to make sure client packets are authenticated. Or else, again
someone might steal the service of an already authenticated client by
spoofing packets. Encryption of the packets can be optional from the
operators perspective, as this is solely about privacy. But providing this
is highly recommended, as the subscribers will demand it.



> The CPE issues frustrates me; one of the major reasons I'm not rushing out
> to do a WISP.  I'd like a CPE with an IPsec or PPTP client, all customer
> <-> WiPOP traffic would be encrypted/secure/marketing foo; no need to worry
> about the latest 802 dot whatever standard or f/w upgrade.  I can only get

If you don't want the latest 802 dot stuff, you can use what we are
developing at IETF. Please see PANA Working Group web page at
http://ietf.org/html.charters/pana-charter.html . This is a
work-in-progress: the spec is not finished and there are no implementations
yet. The idea is to carry EAP above IP for client-network authentication.
Initial authentication can be followed by bootstraping of IPsec for
per-packet authentication and encryption.

Alper

> this cost down to $350 (from antenna to customers wired NIC).  Even rich
> 'Bay Area' people with 2nd 'cabin' home (use to $100 setup DSL/cable) won't
> go for that cost.
> 
> My favorite CPE is SmartBridge's TOTAL AirBridge, check it out (~$450);
> still no IPsec/PPTP though ;(
> 
> --On Thursday, April 10, 2003 15:15:21 -0600 Bob Knight <[EMAIL PROTECTED]>
> wrote:
> 
>> Hi - as a community wireless coop (lcwireless.org), we've considered the
>> support and CPE issues.
> 
> 
> --
> Matt Peterson         another.geek.without.a.life
> [EMAIL PROTECTED]       http://matt.peterson.org/
> -------------------------------------------------
> --
> general wireless list, a bawug thing <http://www.bawug.org/>
> [un]subscribe: http://lists.bawug.org/mailman/listinfo/wireless
> 
> ---
> 
> Checked by AVG anti-virus system (http://www.grisoft.com).
> Version: 6.0.470 / Virus Database: 268 - Release Date: 4/8/2003
> 
> ---
> Outgoing mail is certified Virus Free.
> Checked by AVG anti-virus system (http://www.grisoft.com).
> Version: 6.0.470 / Virus Database: 268 - Release Date: 4/8/2003
> 
> 
> --
> general wireless list, a bawug thing <http://www.bawug.org/>
> [un]subscribe: http://lists.bawug.org/mailman/listinfo/wireless
> 

--
general wireless list, a bawug thing <http://www.bawug.org/>
[un]subscribe: http://lists.bawug.org/mailman/listinfo/wireless

Reply via email to