<DOC>
<DOCID>Wireless_rewrite.doc.txt</DOCID>
<AUTHOR>Paul Bonamy & Justin Schruner</AUTHOR>
<TEXT>
Wireless access points are great.  You can connect to the Internet from anywhere in your room, or check for Facebook activity while eating dinner at the Galley.  But, if its not configured correctly, the very same access point that gives you the freedom to roam around can get you kicked off the LSSU Campus Network (ResNet), possibly for good.

The average wireless access point can be used with no configuration whatsoever, which is great for setting up a network in the middle of the Australian Outback, but not so useful in a crowded environment like a dorm room.  To understand why, we need to take a look at what that wireless access point is actually doing.

Networks of all kinds, including the Internet, work by passing around little packages of information called packets.  Each packet has the address of the person (computer) its going to, and a return address, so the receiver knows how to get in touch with the sender.  Think of letters flowing through a post office, and youre on the right track.

Most of these packets are being carried over wires of some sort, like letters in mail trucks.  Your wireless access point receives the packets for you coming in on the wired network, and throwing them through the air to your computer (think a terminal taking mail from trucks and loading it onto airplanes).

Mail gets where its going, and you can surf the Net from you bed.  No problem, right?  Well, yes and no.  The trouble starts when we take a look at how an access point is normally configured.  

By default, access points work in what is referred to as router mode.  Basically, a router tries to make life easier on the network post office by getting an address from the post office, and then assigning a bunch of totally different addresses to all of the people behind it.  That way, the post office can deliver a bunch of peoples mail to the same address, rather than needing to give all of those people different addresses.  Its like the way mail is delivered to Brady, Osborn, and the Village.  The Housing Office receives all of the mail for those dorms, and then sends it on to the people living there, rather than forcing some poor postal work to deal with all of those mailboxes individually.

Why is having the access point set up as a router such a problem if it seems like such a handy feature?  Simple; theres no way for the post office to tell where that mail is going to end up.  In the context of the ResNet, LSSUs Information Technology department is the post office.  Theyre in charge of assigning addresses to all of the computers on the ResNet, and making sure those packets of mail get to them.  IT also maintains a master list of all the addresses theyve assigned, and to whom the address was assigned.  So, when they get a call saying somebody at address something-or-other is misbehaving, please do something about it, they can look up address something-or-other in their list, and see Oh, thats Joe Bob McGees address.  Lets stop his mail until we can figure out whats going on.  Joe Bob eventually realizes that his mail isnt being delivered (his Internet connection is down), and calls IT to get things straightened out.  Problem solved.

Or it would be, except that your access point still has its default settings.  When you connect to the ResNet using your access point the first time, you have to sign in, remember?  Once you sign in, IT knows that the address it gave your access point belongs to you.  No problem, youre the one doing the surfing, right?  Well, maybe not.  

By default, access points also have their security settings turned off.  That means that anyone who wants to can connect to your access point without even asking your permission.  So that guy down the hall who always seems to have the latest music a week before it comes out can connect to the Internet through your access point without letting you know hes doing it.  But when the RIAA finally catches up with him, the address they have for him is the one IT gave to your access point, which means you get your Internet connection cut off, even though you didnt do anything wrong.

You can, however, keep this from happening.  You have the power to change your access points default settings, keeping the guy down the hall from getting you in trouble.  Youll have to do a little research to find out to change your access points settings, but once youre there, heres what you want to do:

Look for an option to turn off your access points DHCP server.  The DHCP server is the part of the access point responsible for handing out addresses to machines behind it.  By turning off the DHCP server, and thereby switching the access point out of router mode, you force all of the machines behind your access point to get address from IT, rather than your access point, so IT knows that its whats-his-name causing trouble.  

If you cant find DHCP server settings for your access point, look for an option to switch the access point into Bridge mode.  This does basically the same thing as shutting off the DHCP server, and should keep you from being shut down for someone elses misuse of the network.

If theres no way to stop your access point from playing router, or youd prefer to have it routing things, youre other option is to turn on encryption.  Look for a setting labeled either Security or Encryption and set it to either WAP or, if thats not available, WEP.  By turning on encryption youll force anyone trying to connect to your access point to enter a password you entered when you switched on encryption, and that should stop most people from getting in.

Should you be uncomfortable trying to reconfigure your access point, the other option is to find a friendly geek to help you out.  While geeks can be found throughout campus, the best places to find one in short order is in one of the CAS computer labs.  Check CAS 209A for a computer science or computer networking major, or stop into CAS 209B & C for an engineer.  They should be able to help you on your way to safer browsing.

</TEXT></DOC>
