Community discussions

MikroTik App
 
someuser
Member Candidate
Member Candidate
Topic Author
Posts: 102
Joined: Tue Apr 13, 2010 7:05 am

https or wpa2

Sun Jan 23, 2011 8:26 pm

Hi,
I have a small hotspot with a customer that wants to do sensitive data access online.
He wants to be connected via a secured "https" access point.
For the interim, i've given him a wpa2 key. So he is the only one at the moment that can connect.
Can one suggest the best way to lock down an AP so that users connect securely.
Untill I enable https on the hotspot server profile. Is this the best method?
And what's the best approach to tell the customer he's secure.
Basically what's the difference in level of security between having an https connection and giving the customer a WPA2 connection?

Thanks
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26922
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia
Contact:

Re: https or wpa2

Mon Jan 24, 2011 8:55 am

https hotspot only ensures that the person's login+password is sent securely. His data (browsing etc) will not be encrypted. Use WPA2 for the maximum security. It will encrypt all traffic that's going over the Wifi connection with a very strong encryption.
 
someuser
Member Candidate
Member Candidate
Topic Author
Posts: 102
Joined: Tue Apr 13, 2010 7:05 am

Re: https or wpa2

Mon Jan 24, 2011 9:04 am

I guess I was confusing https hotspot with https activitated on a Wireless Access point.

Thanks Normis
 
Feklar
Forum Guru
Forum Guru
Posts: 1724
Joined: Tue Dec 01, 2009 11:46 pm

Re: https or wpa2

Mon Jan 24, 2011 5:24 pm

Data is data to an access point or a router, you don't "activate" HTTPS on an access point unless it is for the management interface which will make no difference to the end user. Layer2/3 devices only really ever look at the packet headers to determine where to send that data and don't pay attention to the payload of that packet.

So by setting up WPA2 on the access point you have fulfilled his request as Normis has said. For more security for the end user on the access point, be sure to turn off default forwarding. This will prevent other end users from trying to connect to his computer over the access point itself.

Who is online

Users browsing this forum: No registered users and 17 guests