cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
933
Views
10
Helpful
5
Replies

Do not broadcast SSID

RaymondLi
Level 1
Level 1

We just bought a Cisco 1100 Access Point 802.11g and up and running correctly. However, I cannot find any setting in the configuration webpage not to broadcast the SSID. This will make that the normal users do not discover our AP in their auto scanning unless they know our SSID. Can someone tell me where the setting is.

Thanks,

Ray

5 Replies 5

gamccall
Level 4
Level 4

Well, to start with, SSID name is *not* a security feature. Turning SSID broadcast off in order to protect your network is about as useful as removing the street numbers from your house in order to protect your television: it does nothing to slow down burglars while also inconveniencing legitimate guests.

If you want to secure your network, secure it- turn on WEP, or better yet WPA. Since the SSID name is broadcast in standard data packets anyway, the only way to protect the SSID name is to encrypt it... and if you're going to encrypt your traffic there's no point in also hiding the SSID name.

With that said, if you're using the web GUI on an IOS AP, the option to disable "Broadcast SSID in Beacon" is under the Express Setup tab.

gamccall

Many thanks for your useful and good advice. I have used WEP 128-bit encrytion. Does it encryts the SSID already?

You mentioned WPA is better encrytion and I am unsure if all Wi-Fi devices in notebook pc have this feature built-in and how to configure it. Any further information on it is appreciated.

Thanks,

Ray

WEP will protect your network from casual bystanders. This is true whether you have SSID broadcast turned on or off.

WEP will not protect your network from determined intruders. This is true whether you have SSID broadcast turned on or off.

WPA with 802.1x and TKIP will protect your network from just about anything. This is true whether you have SSID broadcast turned on or off.

Don't get hung up on the SSID. It's not a security tool, it's just an identifier. Decide how much security you need, and implement the appropriate encryption and authentication tools. Leave the SSID on.

Thanks for your clear suggestion. I will start to look at WPA with 802.1x and TKIP.

Ray

All good points stressed above.

If you have more then one AP, that may be why u would want to name them.. keep in mind not to use your companys name in the naming, makes it real easy for intruders who are searching for your company.

Review Cisco Networking for a $25 gift card