{"id":92780,"date":"2020-08-30T19:42:10","date_gmt":"2020-08-30T17:42:10","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/osobennosti-zashhity-besprovodnyh-i-provodnyh-setej-chast-2-kosvennye-mery-zashhity"},"modified":"2020-08-30T19:42:10","modified_gmt":"2020-08-30T17:42:10","slug":"osobennosti-zashhity-besprovodnyh-i-provodnyh-setej-chast-2-kosvennye-mery-zashhity","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/osobennosti-zashhity-besprovodnyh-i-provodnyh-setej-chast-2-kosvennye-mery-zashhity","title":{"rendered":"Features of securing wireless and wired networks. Part 2 \u2014 Indirect protective measures","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Features of securing wireless and wired networks. Part 2 \u2014 Indirect protective measures\" src=\"\/wp-content\/uploads\/2020\/08\/98625bbefd1ce79a419ec724562d3969.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p><em>Continuing the discussion on methods to enhance network security. In this article, we will address additional security measures and the organization of more secure wireless networks.<\/em><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<p><\/p>\n<h2 id=\"predislovie-ko-vtoroy-chasti\">Preface to Part Two<\/h2>\n<p><\/p>\n<p>In the previous article <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/zyxel\/blog\/516508\/\"><strong>\u00abFeatures of Protecting Wireless and Wired Networks. Part 1 \u2014 Direct Protection Measures\u00bb<\/strong><\/a><\/noindex> we talked about WiFi security issues and direct methods to protect against unauthorized access. Obvious measures to prevent traffic interception were discussed: encryption, hiding the network, and MAC filtering, as well as specialized methods like combating Rogue APs. However, besides direct protection methods, there are also indirect ones. These are technologies that not only help improve communication quality but also contribute to enhanced security.<\/p>\n<p><\/p>\n<p>Two main features of wireless networks: remote contactless access and the radio spectrum as a broadcast medium for data transmission, where any signal receiver can eavesdrop on the airwaves, and any transmitter can disrupt the network with meaningless transmissions and simply create radio interference. This, among other issues, adversely affects the overall security of the wireless network.<\/p>\n<p><\/p>\n<p>One cannot rely solely on security. There\u2019s still work to be done, specifically data exchange. From this perspective, there are many other concerns regarding WiFi:<\/p>\n<p><\/p>\n<ul>\n<li>coverage gaps (\"white spots\");<\/li>\n<li>the influence of external sources and neighboring access points on each other.<\/li>\n<\/ul>\n<p><\/p>\n<p>As a result, due to the aforementioned issues, signal quality decreases, communication stability wanes, and data transfer speeds drop.<\/p>\n<p><\/p>\n<p>Naturally, advocates of wired networks will happily point out that when using wired and, even more so, fiber-optic connections, such problems do not occur.<\/p>\n<p><\/p>\n<p>The question arises: can these issues be resolved without resorting to drastic measures like reconnecting all dissatisfied users to the wired network?<\/p>\n<p><\/p>\n<h2 id=\"gde-nachalo-vseh-problem\">Where do all these problems begin?<\/h2>\n<p><\/p>\n<p>At the time when office and other WiFi networks were emerging, they typically followed a simple algorithm: one single access point was placed in the center of the perimeter to maximize coverage. If the signal strength was insufficient for distant areas, a boosting antenna was added to the access point. A second access point was rarely added, such as for a remote executive office. That was about all the improvements.<\/p>\n<p><\/p>\n<p>This approach had its reasons. Firstly, in the early days of wireless networks, the equipment was expensive. Secondly, installing more access points meant facing questions that had no answers at the time. For example, how to organize seamless client switching between points? How to combat mutual interference? How to simplify and organize point management, for example, simultaneous application of bans\/permissions, monitoring, and so on. Therefore, it was much simpler to operate on the principle: the fewer devices, the better.<\/p>\n<p><\/p>\n<p>At the same time, an access point placed on the ceiling broadcasted in a circular (to be precise, rounded) diagram.<\/p>\n<p><\/p>\n<p>However, the shapes of architectural structures do not fit well into rounded signal propagation diagrams. Therefore, the signal barely reaches certain areas, needing amplification, while in other areas, the broadcast exceeds the perimeter and becomes accessible to outsiders.<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Features of securing wireless and wired networks. Part 2 \u2014 Indirect protective measures\" src=\"\/wp-content\/uploads\/2020\/08\/0020ab189634ee1e0b5fdb8b783d60da.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p><em>Figure 1. Example of coverage using a single point in an office.<\/em><\/p>\n<p><\/p>\n<p><em><strong>Note<\/strong>. This is a rough approximation that does not take into account obstacles to propagation, as well as signal directionality. In practice, the shapes of diagrams for different models of points may vary.<\/em><\/p>\n<p><\/p>\n<p>The situation can be improved by using more access points.<\/p>\n<p><\/p>\n<p>Firstly, this will allow for more effective distribution of transmitting devices across the area of the room.<\/p>\n<p><\/p>\n<p>Secondly, it provides the ability to lower the signal level, preventing it from exceeding the office or other object's perimeter. In this case, to capture the traffic of the wireless network, one needs to approach the perimeter almost closely or even enter its boundaries. A malicious actor operates similarly to intrude into the internal wired network.<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Features of securing wireless and wired networks. Part 2 \u2014 Indirect protective measures\" src=\"\/wp-content\/uploads\/2020\/08\/f4a2b2d75790a459fe2e0de477e4fa05.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p><em>Figure 2. Increasing the number of access points allows for better coverage distribution.<\/em><\/p>\n<p><\/p>\n<p>Let's take another look at both figures. The first clearly shows one of the main vulnerabilities of wireless networks \u2014 signals can be caught from a considerable distance.<\/p>\n<p><\/p>\n<p>In the second figure, the situation isn't as dire. The more access points there are, the more effective the coverage area becomes, and the signal strength barely exceeds the perimeter, roughly speaking, the boundaries of an office, building, or other possible objects.<\/p>\n<p><\/p>\n<p>An attacker will have to sneak closer to intercept the relatively weak signal \"from the street\" or \"from the corridor,\" and so on. This requires getting close to the office building, perhaps standing under the windows. Alternatively, they might try to gain access to the office building itself. In any case, this increases the risk of being \"spotted\" on surveillance cameras or being seen by security. At the same time, it significantly reduces the timeframe for an attack. This can hardly be called \"ideal conditions for a hack.\"<\/p>\n<p><\/p>\n<p>Of course, there remains one more \"original sin\": wireless networks broadcast in an accessible range that can be intercepted by any clients. Indeed, a WiFi network can be compared to an Ethernet hub, where the signal is sent to all ports simultaneously. To avoid this, ideally, each pair of devices should communicate on its own frequency channel that no one else should interfere with.<\/p>\n<p><\/p>\n<p>Here are the main issues summarized. Let's consider ways to solve them.<\/p>\n<p><\/p>\n<h2 id=\"sredstva-zaschity-pryamye-i-kosvennye\">Protection measures: direct and indirect<\/h2>\n<p><\/p>\n<p>As already mentioned in the previous article, achieving perfect protection is not possible in any case. However, it is possible to make carrying out an attack as difficult as possible, making the result unprofitable in relation to the effort expended.<\/p>\n<p><\/p>\n<p>Conditionally, protection measures can be divided into two main groups:<\/p>\n<p><\/p>\n<ul>\n<li>direct traffic protection technologies, such as encryption or MAC filtering;<\/li>\n<li>technologies originally designed for other purposes, for example, to increase speed, but which indirectly complicate life for attackers.<\/li>\n<\/ul>\n<p><\/p>\n<p>The first group was discussed in the first part. However, we also have additional indirect measures. As mentioned earlier, increasing the number of access points allows for a lower signal level and creates a more uniform coverage area, which complicates life for potential intruders.<\/p>\n<p><\/p>\n<p>Another aspect is that increasing data transfer speeds facilitates the implementation of additional security measures. For example, a VPN client can be installed on each laptop, allowing data to be transmitted even within the local network over encrypted channels. This will require some resources, including hardware, but the level of protection is significantly enhanced.<\/p>\n<p><\/p>\n<p>Below, we describe technologies that can improve network performance and indirectly increase security levels.<\/p>\n<p><\/p>\n<h2 id=\"kosvennye-sredstva-uluchsheniya-zaschity--chto-mozhet-pomoch\">What indirect means can enhance security?<\/h2>\n<p><\/p>\n<h3 id=\"client-steering\">Client Steering<\/h3>\n<p><\/p>\n<p>The Client Steering feature initially encourages client devices to use the 5GHz band. If this option is unavailable, they can still utilize the 2.4GHz band. For outdated networks with few access points, most operations are conducted in the 2.4GHz range. For the 5GHz frequency band, a single access point setup is often inadequate. This is because signals at higher frequencies have more difficulty penetrating walls and navigating obstacles. The usual recommendation is to ensure guaranteed connectivity in the 5GHz range by maintaining direct visibility to the access point.<\/p>\n<p><\/p>\n<p>In modern standards 802.11ac and 802.11ax, the availability of more channels allows for multiple access points to be installed at closer distances, reducing power while not losing and even gaining in data transmission speed. Ultimately, using the 5GHz band complicates things for intruders but improves connection quality for clients within range.<\/p>\n<p><\/p>\n<p>This feature is presented:<\/p>\n<p><\/p>\n<ul>\n<li>in Nebula and NebulaFlex access points;<\/li>\n<li>in firewalls with controller functionality.<\/li>\n<\/ul>\n<p><\/p>\n<h3 id=\"auto-healing\">Auto Healing<\/h3>\n<p><\/p>\n<p>As mentioned above, the perimeter contours of the room do not fit well into rounded diagrams of access points.<\/p>\n<p><\/p>\n<p>To solve this problem, first, you need to use the optimal number of access points, and second, reduce mutual interference. However, simply taking and manually lowering the transmitter power\u2014such straightforward intervention can lead to signal degradation. This will be particularly noticeable if one or more access points fail.<\/p>\n<p><\/p>\n<p>Auto Healing allows for rapid adjustment of power without sacrificing reliability and data transmission speed.<\/p>\n<p><\/p>\n<p>When using this feature, the controller checks the status and operability of the access points. If one of them fails, neighboring points are instructed to increase their signal power to fill the 'white spot.' Once the access point is back online, neighboring points are instructed to decrease their signal power to reduce mutual interference.<\/p>\n<p><\/p>\n<h3 id=\"besshovnyy-wifi-rouming\">Seamless WiFi roaming<\/h3>\n<p><\/p>\n<p>At first glance, this technology is hard to classify as enhancing security\u2014on the contrary\u2014it facilitates the switch of clients (including potential intruders) between access points within the same network. But when two or more access points are used, it is essential to ensure smooth operation without unnecessary issues. Furthermore, if an access point is overloaded, it struggles with protection functions such as encryption, leading to delays in data exchange and other undesirable outcomes. In this regard, seamless roaming is a significant aid in flexibly distributing load and ensuring uninterrupted operation in a secure mode.<\/p>\n<p><\/p>\n<h3 id=\"nastroyka-porogovyh-znacheniy-urovnya-signala-dlya-podklyucheniya-i-otklyucheniya-besprovodnyh-klientov-signal-threshold-ili-signal-strength-range\">Setting signal threshold values for connecting and disconnecting wireless clients (Signal Threshold or Signal Strength Range)<\/h3>\n<p><\/p>\n<p>When using a single access point, this function is essentially irrelevant. However, when multiple points managed by a controller are operational, it is possible to organize mobile distribution of clients among different APs. It's worth noting that controller features are available in many router series from Zyxel: ATP, USG, USG FLEX, VPN, ZyWALL.<\/p>\n<p><\/p>\n<p>The devices mentioned above have a function to disconnect clients connected to an SSID with a weak signal. 'Weak' means that the signal is below the threshold set on the controller. Once a client is disconnected, it will send a probe request to find another access point.<\/p>\n<p><\/p>\n<p>For example, if a client is connected to an access point with a signal below -65dBm, and the disconnection threshold for the station is -60dBm, in this case, the access point will disconnect the client with that signal level. The client will then initiate a reconnect procedure and connect to another access point with a signal greater than or equal to -60dBm (the station's signal threshold).<\/p>\n<p><\/p>\n<p>This plays an important role when using multiple access points. It prevents the situation where a large number of clients cluster around one access point while others remain idle.<\/p>\n<p><\/p>\n<p>In addition, it is possible to restrict connections from clients with weak signals, likely located outside the room's perimeter, for example, behind a wall in a neighboring office, which allows this function to be considered as an indirect method of protection.<\/p>\n<p><\/p>\n<h3 id=\"perehod-na-wifi-6-kak-odin-iz-putey-povysheniya-urovnya-bezopasnosti\">Transitioning to WiFi 6 as one of the ways to enhance security levels<\/h3>\n<p><\/p>\n<p>We have already discussed the advantages of direct protection measures in a previous article. <strong>\u00abFeatures of Protecting Wireless and Wired Networks. Part 1 \u2014 Direct Protection Measures\u00bb<\/strong>.<\/p>\n<p><\/p>\n<p>WiFi 6 networks provide higher data transfer speeds. On one hand, the new group of standards allows for increased speeds, and on the other, it enables placing even more access points in the same area. The new standard allows for lower power consumption to transmit at higher speeds.<\/p>\n<p><\/p>\n<p><strong>Increasing data exchange speeds<\/strong>.<\/p>\n<p><\/p>\n<p>The transition to WiFi 6 implies an increase in data exchange speeds up to 11Gb\/s (modulation type 1024-QAM, 160 MHz channels). At the same time, new devices supporting WiFi 6 have greater performance. One of the main challenges when implementing additional security measures, such as a VPN tunnel for each user, is the drop in speed. With WiFi 6, it will be easier to apply additional security systems.<\/p>\n<p><\/p>\n<h3 id=\"bss-coloring\">BSS Coloring<\/h3>\n<p><\/p>\n<p>Previously, we mentioned that a more uniform coverage helps reduce WiFi signal penetration beyond the perimeter. However, with the continued rise in the number of access points, even using Auto Healing may not be enough, as 'foreign' traffic from a neighboring point will still penetrate the reception area.<\/p>\n<p><\/p>\n<p>When using BSS Coloring, the access point marks (colors) its data packets. This allows ignoring the influence of neighboring transmitting devices (access points).<\/p>\n<p><\/p>\n<h3 id=\"uluchshennyy-mu-mimo\">Improved MU-MIMO<\/h3>\n<p><\/p>\n<p>The 802.11ax also has significant improvements in MU-MIMO (Multi-User \u2014 Multiple Input Multiple Output) technology. MU-MIMO allows an access point to exchange data with multiple devices simultaneously. However, in the previous standard, this technology could only support groups of four clients on one frequency. This made transmission easier but reception harder. WiFi 6 utilizes multi-user MIMO 8\u00d78 for both transmission and reception.<\/p>\n<p><\/p>\n<p><em><strong>Note.<\/strong> The 802.11ax standard increases the size of MU-MIMO groups in the incoming stream, ensuring more efficient WiFi network performance. Multi-user outgoing MIMO channels are a new addition to 802.11ax.<\/em><\/p>\n<p><\/p>\n<h3 id=\"ofdma-orthogonal-frequency-division-multiple-access\">OFDMA (Orthogonal frequency-division multiple access)<\/h3>\n<p><\/p>\n<p>This new method of channel access and management is based on technologies that have already been tested in LTE cellular technology.<\/p>\n<p><\/p>\n<p>OFDMA allows sending more than one signal over the same line or channel simultaneously by assigning a time interval for each transmission and applying frequency division. As a result, not only does the speed increase due to better channel utilization, but security is also enhanced.<\/p>\n<p><\/p>\n<h2 id=\"rezyume\">Summary<\/h2>\n<p><\/p>\n<p>WiFi networks are becoming increasingly secure each year. The use of modern technologies allows for an acceptable level of protection.<\/p>\n<p><\/p>\n<p>Direct protection methods in the form of traffic encryption have proven to be quite effective. We also can't forget about additional measures: MAC filtering, hiding network identifiers, and Rogue AP Detection (Rogue AP Containment).<\/p>\n<p><\/p>\n<p>However, there are also indirect measures that improve the collaborative operation of wireless devices and enhance data exchange speed.<\/p>\n<p><\/p>\n<p>The use of new technologies allows for a decrease in signal levels from access points, creating more uniform coverage, which positively affects the overall health of the wireless network, including its security.<\/p>\n<p><\/p>\n<p>Common sense suggests that all means are acceptable to enhance security: both direct and indirect. This combination makes life as difficult as possible for attackers.<\/p>\n<p><\/p>\n<h2 id=\"poleznye-ssylki\">Useful links:<\/h2>\n<p><\/p>\n<ol>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/t.me\/zyxelru\">Zyxel Telegram chat<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.zyxel.com\/ru\/ru\/ci_general_20191031_520516.shtml\">Zyxel Equipment Forum<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCcNN2UCEz1e49PEaAisN5ow\">A lot of useful videos are available on the Zyxel channel (YouTube)<\/a><\/noindex><\/li>\n<li>Features of protecting wireless and wired networks. Part 1 \u2014 Direct protective measures<\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCcNN2UCEz1e49PEaAisN5ow\">Wi-Fi or twisted pair \u2014 which is better?<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCcNN2UCEz1e49PEaAisN5ow\">Synchronization of Wi-Fi access points for collaborative work<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCcNN2UCEz1e49PEaAisN5ow\">Wi-Fi 6: Does the new wireless standard matter for the average user, and if so, why?<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCcNN2UCEz1e49PEaAisN5ow\">WiFi 6 MU-MIMO and OFDMA: Two pillars of your future success<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCcNN2UCEz1e49PEaAisN5ow\">The future of WiFi<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCcNN2UCEz1e49PEaAisN5ow\">Using multi-gigabit switches as a compromise philosophy<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCcNN2UCEz1e49PEaAisN5ow\">Two in one, or migrating the access point controller to the gateway<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCcNN2UCEz1e49PEaAisN5ow\">WiFi 6 is already here: what the market offers and why we need this technology<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCcNN2UCEz1e49PEaAisN5ow\">Improving Wi-Fi Performance. General Principles and Useful Tips<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCcNN2UCEz1e49PEaAisN5ow\">Improving Wi-Fi Performance. Part 2. Equipment Features<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCcNN2UCEz1e49PEaAisN5ow\">Improving Wi-Fi Performance. Part 3. Placement of Access Points<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCcNN2UCEz1e49PEaAisN5ow\">Synchronization of Wi-Fi access points for collaborative work<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCcNN2UCEz1e49PEaAisN5ow\">My two cents: Wi-Fi today and tomorrow<\/a><\/noindex><\/li>\n<\/ol>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/zyxel\/blog\/516914\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u043e\u0434\u043e\u043b\u0436\u0430\u0435\u043c \u0440\u0430\u0437\u0433\u043e\u0432\u043e\u0440 \u043e \u043c\u0435\u0442\u043e\u0434\u0430\u0445 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u044f \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0441\u0435\u0442\u0435\u0439. \u0412 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043f\u043e\u0433\u043e\u0432\u043e\u0440\u0438\u043c \u043e \u0434\u043e\u043f\u043e\u043b\u043d\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u0445 \u043c\u0435\u0440\u0430\u0445 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0431\u043e\u043b\u0435\u0435 \u0437\u0430\u0449\u0438\u0449\u0435\u043d\u043d\u044b\u0445 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0439. \u041f\u0440\u0435\u0434\u0438\u0441\u043b\u043e\u0432\u0438\u0435 \u043a\u043e \u0432\u0442\u043e\u0440\u043e\u0439 \u0447\u0430\u0441\u0442\u0438 \u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u00ab\u041e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0438 \u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0439. \u0427\u0430\u0441\u0442\u044c 1 \u2014 \u041f\u0440\u044f\u043c\u044b\u0435 \u043c\u0435\u0440\u044b \u0437\u0430\u0449\u0438\u0442\u044b\u00bb \u0448\u043b\u0430 \u0440\u0435\u0447\u044c \u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430\u0445 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0441\u0435\u0442\u0438 WiFi \u0438 \u043f\u0440\u044f\u043c\u044b\u0445 \u043c\u0435\u0442\u043e\u0434\u0430\u0445 \u0437\u0430\u0449\u0438\u0442\u044b \u043e\u0442 \u043d\u0435\u0441\u0430\u043d\u043a\u0446\u0438\u043e\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0434\u043e\u0441\u0442\u0443\u043f\u0430. \u0411\u044b\u043b\u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":92781,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-92780","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/osobennosti-zashhity-besprovodnyh-i-provodnyh-setej-chast-2-kosvennye-mery-zashhity\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0438 \u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0439. \u0427\u0430\u0441\u0442\u044c 2 \u2014 \u041a\u043e\u0441\u0432\u0435\u043d\u043d\u044b\u0435 \u043c\u0435\u0440\u044b \u0437\u0430\u0449\u0438\u0442\u044b | ProHoster\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/osobennosti-zashhity-besprovodnyh-i-provodnyh-setej-chast-2-kosvennye-mery-zashhity\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-08-30T17:42:10+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-08-30T17:42:10+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Features of protecting wireless and wired networks. Part 2 \u2014 Indirect protective measures | ProHoster","description":"","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/osobennosti-zashhity-besprovodnyh-i-provodnyh-setej-chast-2-kosvennye-mery-zashhity","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0438 \u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0439. \u0427\u0430\u0441\u0442\u044c 2 \u2014 \u041a\u043e\u0441\u0432\u0435\u043d\u043d\u044b\u0435 \u043c\u0435\u0440\u044b \u0437\u0430\u0449\u0438\u0442\u044b | ProHoster","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/osobennosti-zashhity-besprovodnyh-i-provodnyh-setej-chast-2-kosvennye-mery-zashhity","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-08-30T17:42:10+00:00","article:modified_time":"2020-08-30T17:42:10+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"92780","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:01:24","updated":"2022-09-30 00:38:24","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/92780","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=92780"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/92780\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/92781"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=92780"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=92780"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=92780"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}