Page 1 of 1

Building just got wireless, they turned on WEP

Posted: Sun Sep 11, 2011 9:04 pm
by rbeede
We just got Internet and wireless in our ward building. Yeah!

The ISP was DSL as it was the cheapest. Sadly Internet access in our area is much higher in price compared to other areas so we only got 1.5mbps/896kbps speeds.

In addition to the ISP provided modem we got an ASA firewall and Cisco wireless access point. Interesting enough they enabled WEP encryption versus WPA or none.

Has anyone else had WEP versus WPA enabled for their units?

I asked the FM group about this, but they said changing to WPA would require paying a service tech and cost more money so they weren't going to do it. I thought CHQ managed the devices and configuration though?

They mentioned they weren't worried about the security, but I know from experience the things are easy to crack. For now I've enabled the firewall on the local clerk computer to act as a shield.

Posted: Sun Sep 11, 2011 9:31 pm
by russellhltn
If you've got Cisco WAP, then I'd contact GSD about getting the encryption changed over.

Posted: Mon Sep 12, 2011 12:23 am
by jdlessley
Interesting, since the preferred security protocol is WPA2 or as a minimum WPA (See wiki article Wireless networking (meetinghouse) - Wireless network security). But that can be remedied as RussellHltn suggests.

Posted: Mon Sep 12, 2011 6:59 am
by harddrive
jdlessley wrote:Interesting, since the preferred security protocol is WPA2 or as a minimum WPA (See wiki article Wireless networking (meetinghouse) - Wireless network security). But that can be remedied as RussellHltn suggests.

It's also interesting that you got an ASA, when I thought the church was only providing the Cisco 881W, but I would contact Global Service Desk about your issue.

Posted: Sun Sep 18, 2011 9:55 am
by bradhokanson
Yeah...that is odd. The FMs cant purchase anything but the 881w from the estore so I would wonder where they got their equipment. What model AP did they provide you?

GSD scripts all the PIX 501s and ASA 5505s. The 881ws are all self activated and GSD can do some basic troubleshooting to assist if there are issues.

Posted: Sun Sep 18, 2011 5:05 pm
by rbeede
It is a Cisco WAP.

I think we got some old hardware to save money. The firewall is a Cisco ASA 5505 v05.

Posted: Sun Sep 18, 2011 5:34 pm
by russellhltn
There could be reasons for the older firewall, but I don't think the church has ever used WEP.

Posted: Sun Sep 18, 2011 6:39 pm
by jdlessley
RussellHltn wrote:There could be reasons for the older firewall, but I don't think the church has ever used WEP.
The church used the WEP protocol with the Cisco Aironet 1200 series WAPs prior to 2008 when Odyssey Client software was used as the wireless manager. The script installed on the WAPs used WEP security protocol with "moroni" as the SSID.

The Cisco Aironets can be rescripted to the LDS Access SSID and will include the change to WPA or possibly WPA2 (I can't recall if WPA2 is supported on the Aironet WAP) security protocol.