Lecture 13 - Wireless Network & Firewall

Updated 4 Oct 2026

Outline

  • Wireless Introduction
    • Elements of wireless network
    • Wireless Links
    • Network characteristics
  • WiFi: 802.11 Wireless LANs
    • Standards (b/g/n/ac/ax)
    • Channel/Frequency (2.4 GHz, 5 GHz)
      • เดี๋ยวนี้ก็เริ่มมี 6G แล้ว
    • AP (SSID)
    • CSMA/CA
    • Security
  • Ways to Protect Your Network
  • Firewalls and IDS

1. Wireless Introduction

Elements of a Wireless Network

  • Wireless Hosts — laptop, smartphone, IoT devices
    • Equipment that wants to connect to the network
    • ต้องมี Network Adapter (ลองเข้าไปดู iPhone 17 specs ว่า support อะไรบ้าง)
    • Run applications
    • May be stationary (non-mobile) or mobile
    • ⚠️ Wireless does not always mean mobility!
  • Base Station (Access Point)
    • Typically connected to wired network
    • Acts as a relay — responsible for sending packets between the wired network and wireless hosts in its coverage area
    • Examples: cell towers, 802.11 access points
      • WiFi → Access Point, Cell Phone → Cell Tower เรียกต่างกันนะ
  • Wireless Link
    • Typically connects mobiles to a base station; also used as backbone links
    • Multiple access protocol coordinates link access
    • Various transmission rates, distances, and frequency bands
      • ถ้าเขียนว่า 900 MHz จริง ๆ แล้วมันไม่ใช่เป๊ะ ๆ นะ มันก็เป็น range อยู่ 900 - 985 งี้
      • บางทีอาจจะเบ่ง 900 - 985 เป็นหลาย slot ให้หลาย ๆ operator
  • Connection Modes
    • Infrastructure Mode — base station connects mobiles into wired network; supports handoff (mobile changes base station while maintaining connection)
    • Ad-hoc Mode — no base stations; nodes transmit only to other nodes within link coverage; nodes self-organize and route among themselves

คิดเหมือนบ้านกับร้านสะดวกซื้อ: Infrastructure mode = ต้องผ่านเคาน์เตอร์ (AP) ก่อนออกไปโลกภายนอก, Ad-hoc = เพื่อนบ้านคุยกันตรงๆ โดยไม่ผ่านใคร


  • Decreased Signal Strength — radio signal attenuates as it travels through matter (path loss)
  • Interference from Other Sources — 2.4 GHz band is shared by many devices (WiFi, cellular, motors)
  • Multipath Propagation — signal reflects off objects/ground, arriving at destination at slightly different times

สัญญาณวิทยุเหมือนเสียงตะโกน — ยิ่งไกลยิ่งเบาลง, มีสิ่งกีดขวางก็เสียหาย, และก้องสะท้อนได้

แล้วถ้าเราเปลี่ยน Channel หรือ Frequency หนีบ้านอื่นได้มั้ย แล้วมันจะได้ไม่ interfere


Contents

SNR: Signal-to-Noise Ratio

  • Larger SNR = easier to extract signal from noise (a "good thing")
  • Recommended SNR values:
    • Data networks: ≥ 20 dB
    • Voice applications: ≥ 25 dB

SNR (dB)=Received Signal Power−Noise Floor\text{SNR (dB)} = \text{Received Signal Power} - \text{Noise Floor}

BER: Bit Error Rate

BER=Number of errorsTotal number of bits sent\boxed{BER = \frac{\text{Number of errors}}{\text{Total number of bits sent}}}

  • Indicates the performance of a data link — lower BER = better

SNR vs BER Tradeoffs

  • Increase power → Increase SNR → Decrease BER
  • Given SNR: choose physical layer that meets BER requirement with highest throughput
  • SNR may change with mobility → dynamically adapt physical layer (modulation technique, rate)
  • Modulation schemes (higher = faster but needs better SNR):
    • BPSK — 1 Mbps
    • QAM16 — 4 Mbps
    • QAM256 — 8 Mbps

เหมือนการพูดในห้องเสียงดัง: ถ้าเสียงรบกวนมาก ต้องพูดช้าลงและชัดขึ้น (เลือก modulation ต่ำ) แต่ถ้าเงียบพอ พูดเร็วได้เลย (QAM256)


2. WiFi: 802.11 Wireless LANs

802.11 Standards

StandardYearMax Data RateRangeFrequency
802.11b199911 Mbps30m2.4 GHz
802.11g200354 Mbps30m2.4 GHz
802.11n (WiFi 4)2009600 Mbps70m2.4, 5 GHz
802.11ac (WiFi 5)20133.47 Gbps70m5 GHz
802.11ax (WiFi 6)202014 Gbps70m2.4, 5 GHz
802.11af201435–560 Mbps1 kmUnused TV bands (54–790 MHz)
802.11ah2017347 Mbps1 km900 MHz
  • All standards use CSMA/CA for multiple access
  • Both infrastructure and ad-hoc versions exist

Frequency Bands: 2.4 GHz vs 5 GHz


Property2.4 GHz5 GHz
Data RateSlowFast
CoverageLong distanceShort distance
Channels14 channels23 channels
Channel OverlapOverlappingNo overlapping
Standards802.11b, g, ax802.11a, n, ac, ax

2.4 GHz = ช้าแต่ไกล เหมือนสัญญาณวิทยุ FM. 5 GHz = เร็วแต่ใกล้ เหมือน Bluetooth ที่ไวแต่ต้องอยู่ใกล้ๆ

2.4 GHz Channel vs Frequency

  • Each channel is 20 MHz wide, spaced 5 MHz apart
  • Only channels 1, 6, and 11 are truly non-overlapping

5 GHz Channel vs Frequency

  • More channels, no overlap
  • Some channels require DFS (Dynamic Frequency Selection) due to TDWR (Terminal Doppler Weather Radar) conflict

802.11 LAN Architecture

  • BSS (Basic Service Set) — aka "cell"
    • Wireless hosts + Access Point (AP) in infrastructure mode
    • AP = base station
  • SSID (Service Set Identifier) — the name of a Wi-Fi network (sequence of characters)


Associating with an AP (Arriving Host Process)

  1. Scan channels — listen for beacon frames (contain AP's SSID + MAC address)
  2. Select AP to associate with
  3. Authenticate (if required)
  4. Run DHCP to get IP address in AP's subnet

Passive vs Active Scanning

Passive ScanningActive Scanning (hidden SSID)
Step 1Beacon frames sent from APsHost broadcasts Probe Request
Step 2Host sends Association Request to chosen APAPs send Probe Response
Step 3AP sends Association ResponseHost sends Association Request to chosen AP
Step 4—AP sends Association Response

Passive = นั่งรอฟังว่ามี WiFi อะไรบ้าง. Active = ตะโกนถามก่อนว่า "ใครอยู่บ้างไหม?" ใช้เมื่อ SSID ถูกซ่อน


802.11 Frame Addressing

| frame control | duration | address1 | address2 | address3 | seq control | address4 | payload | CRC |
  • Address 1 — MAC of wireless host or AP receiving this frame
  • Address 2 — MAC of wireless host or AP transmitting this frame
  • Address 3 — MAC of router interface to which AP is attached
  • Address 4 — Used only in ad-hoc mode

Example: H1 → Internet via AP → Router R1

FrameAddress 1Address 2Address 3
802.11 WiFi frameAP MAC addrH1 MAC addrR1 MAC addr
802.3 Ethernet frameR1 MAC addrAP MAC addr—

CSMA/CA: Multiple Access Protocol

Why Not CSMA/CD?

  • 802.11 has NO collision detection!
    • High transmitting signal + weak received signal due to fading → hard to sense
    • Cannot detect all collisions (hidden terminal problem)
  • Goal: avoid collisions → CSMA/CA (Collision Avoidance)

CSMA/CA Sender Algorithm

1. If channel idle for DIFS → transmit entire frame (no CD)
2. If channel busy → start random backoff timer
   - Timer counts down while channel is idle
   - Transmit when timer reaches 0
   - If no ACK received → increase backoff interval, repeat step 2
  • DIFS (DCF Interframe Spacing) — continuously idle time before transmitting
  • SIFS (Short Interframe Spacing) — waiting time before sending ACK/CTS

CSMA/CA เหมือนการประชุมที่สุภาพ: รอจนคนพูดเสร็จ + รอ DIFS เพิ่ม แล้วค่อยพูด ถ้าชนกันก็รอ random แล้วพูดใหม่

RTS/CTS: Collision Avoidance Enhancement

  1. Sender sends small RTS (Request-to-Send) packet to AP via CSMA
  2. AP broadcasts CTS (Clear-to-Send) in response
  3. All nodes hear CTS → defer their transmissions
  4. Sender transmits data frame
  5. AP sends ACK
  • RTSs may still collide, but they're short → less wasted bandwidth than full data collision

RTS/CTS เหมือนการจองคิว: บอก AP ก่อนว่าจะส่ง, AP ประกาศให้ทุกคนรู้ว่า "A กำลังส่ง หยุดรบกวน", ทุกคนหยุดรอ


802.11 Mobility within same subnet


H1 remains in same IP subnet: IP address can remain same switch: which AP is associated with H1?

  • self-learning : switch will see frame from H1 and “remember” which switch port can be used to reach H1

Advanced Capabilities

Rate Adaptation

  • Base station + mobile dynamically change transmission rate as SNR varies
  • SNR ↓ → BER ↑ → switch to lower rate (lower modulation) with lower BER

Power Management

  • Node-to-AP: Node tells AP: "I am going to sleep until next beacon frame"
  • AP holds frames for sleeping nodes
  • Beacon frame contains list of mobiles with pending frames
  • Node wakes up before next beacon, checks if frames are waiting → sleep or stay awake

3. 802.11 Wireless Security

Security Challenges

  • External business requirements (guests, contractors)
    • office_2.4G, office_5G, office_guest, office_iot
  • Growing use of mobile/endpoint devices
  • Use of untrusted devices, networks, apps
  • Interaction with cloud-based systems
  • Use of untrusted contents

Signal Hiding Techniques

  • Turn off SSID broadcasting (hidden SSID)
  • Use cryptic/non-default SSID names
  • Reduce signal strength (place AP away from windows and external walls)
  • Use directional antennas

Encryption Enhancement Techniques

  • Use encryption (WPA2)
  • Enable anti-virus, anti-spyware, firewall
  • Enable password for joining
  • Use multiple SSIDs (e.g., separate guest network)
    • Isolation → equipment that connected to SSID can have internet access, but not to local network at all!
    • เหมาะกับพวก SSID for guests อะ!

WEP vs WPA vs WPA2

PropertyWEPWPAWPA2
Data EncryptionRC4 (Rivest Cipher)TKIPAES
AuthenticationShared KeyShared Key & 802.1XShared Key & 802.1X
Data IntegrityCRC-32Message Integrity CodeCBC-MAC
Key ManagementNoneDynamic session keyDynamic session key
Release Year199920032004
Should use?❌ No (crackable in ~5 min)⚠️ Only if WPA2 unavailable✅ Yes

WPA Details

  • Released 2003 as replacement for WEP's security flaws
  • Uses RC4 algorithm properly with dynamic/rotating keys per frame → minimizes shared secret key exposure
  • Improved data encryption + stronger user authentication

WPA2 Details

  • Based on IEEE 802.11i standard
  • 2 versions: Personal & Enterprise
  • Primary enhancement: AES (Advanced Encryption Standard) algorithm
  • Personal mode — uses PSK (Pre-Shared Key); no separate user authentication
  • Enterprise mode — requires separate user authentication via EAP protocol

WEP = กุญแจบ้านที่ทำสำเนาได้ง่ายมาก. WPA = เปลี่ยนรหัสทุกครั้งที่ใช้. WPA2 = ใช้ AES ซึ่งเป็น encryption ระดับ military


4. Ways to Protect Your Network: Firewall

What is a Firewall?

  • Firewall — a security system that monitors and controls incoming/outgoing network traffic based on predetermined security rules
  • Installed between the internal network and the rest of the Internet
  • Can be hardware or software

Why Firewalls?

  1. Prevent DoS attacks — e.g., SYN flooding (attacker creates many bogus TCP connections, exhausting resources)
  2. Prevent illegal modification/access of internal data
  3. Allow only authorized access to the internal network
  4. Privacy and Stealth — using a "Drop" policy makes your network invisible to port scans (connections simply time out)

Key Functions

  • Packet Filtering — checking source, destination, and type of data
  • Access Control — allowing specific users or applications to access certain resources
  • Threat Prevention — blocking known malicious sites or unauthorized pings

Inbound vs Outbound Rules

  • Inbound rules — protect against incoming traffic (keeping hackers out): disallowed connections, malware, DoS attacks
  • Outbound rules — protect against outgoing traffic originating inside the network (prevent a compromised node from becoming a weapon)


Firewall Strategies

a) Blacklisting Strategy

  • Default policy: ACCEPT (allow all)
  • Continuously insert rules to DROP malicious packets
  • Use case: outbound (for flexibility)

b) Whitelisting Strategy

  • Default policy: DROP (block all)
  • Continuously insert rules to ACCEPT good packets
  • Use case: inbound (common), outbound (maximum control)

Blacklisting = ประตูเปิดอยู่ แต่มีรายชื่อคนห้ามเข้า. Whitelisting = ประตูปิดอยู่ แต่มีรายชื่อคนที่ให้เข้าได้เท่านั้น


Firewall Zones / Network Segmentation

  • Group network assets into logical zones based on Trust Level
  • Assign devices to a zone → define how traffic flows between zones (instead of per-IP rules)

Three Zones

ZoneTrust LevelContentsPolicy
Untrusted Zone (WAN/Internet)ZeroPublic internetAssume everything is malicious; only specific inspected traffic allowed in
DMZ (Demilitarized Zone)Low–MediumWeb Server, Mail Server, DNS, FTPCan talk to internet; cannot initiate connections to internal network
Trusted Zone (LAN/Internal)HighEmployee workstations, internal servers, sensitive dataCan access internet & DMZ; heavily shielded from inbound requests
![[Pasted image 20260423153858.pngcenter500]]

Inter-Zone Traffic Flow (Zone Matrix)

From ZoneTo ZoneDefault ActionLogic
TrustedUntrustedAllowUsers accessing the internet
UntrustedTrustedBlockPreventing external attacks
UntrustedDMZAllow (Filtered)Letting customers see your web server
DMZTrustedBlockIf web server is hacked, attacker stays in DMZ

DMZ เหมือน "ลานด้านหน้าปราสาท": แขกภายนอกเข้าได้ แต่เข้าปราสาท (Internal) ไม่ได้


Types of Firewalls

TypeSecurity LevelHow It Operates
Stateless Packet FilteringBasicInspects individual packets based on IP address and port number
Stateful InspectionModerateTracks the "state" of active connections to verify incoming data was actually requested
Next-Generation (NGFW)HighAdds deep packet inspection, antivirus, encrypted traffic inspection, Application Awareness (Layer 7)
Proxy FirewallVery HighActs as middleman; external user never connects directly to your network

Stateless Packet Filtering

  • Filters packet-by-packet; no memory of past packets
  • Decision based on:
    • Source/Destination IP address
    • TCP/UDP source/destination port numbers
    • ICMP message type
    • TCP SYN, ACK bits

Examples

  • Block all UDP traffic and Telnet:
    • Drop packets with IP protocol = 17 (UDP) AND source or dest port = 23
  • Block external TCP connection initiations:
    • Drop inbound TCP segments with ACK = 0 → prevents external clients from initiating connections, but allows internal clients to connect out

Access Control List (ACL) Format

| action | source addr | dest addr | protocol | source port | dest port | flag bit |

Example ACL rules:

ActionSourceDestinationProtocolSrc PortDst PortFlag
allow222.22/16outside 222.22/16TCP> 102380any
allowoutside 222.22/16222.22/16TCP80> 1023ACK
allow222.22/16outside 222.22/16UDP> 102353—
allowoutside 222.22/16222.22/16UDP53> 1023—
denyallallallallallall

📋 ACL อ่านจากบนลงล่าง เหมือน if-else chain: match rule แรกที่ตรง แล้วหยุด

Common Stateless Filtering Policies

PolicyFirewall Rule
No outside web accessDrop all outgoing packets to any IP, port 80
No incoming TCP connections (except public web server)Drop all incoming TCP SYN to any IP except 130.207.244.203, port 80
Block web radio (bandwidth protection)Drop all incoming UDP except DNS and router broadcasts
Anti-Smurf (DoS prevention)Drop all ICMP to broadcast address (e.g. 130.207.255.255)
Stealth Mode (prevent traceroute)Drop all outgoing ICMP TTL expired traffic

Stateful Packet Filtering

  • Stateless flaw: admits packets that "make no sense" (e.g., ACK packet with no prior TCP connection)
  • Stateful inspection: tracks state of every TCP connection
    • Monitors connection setup (SYN) and teardown (FIN)
    • Verifies incoming/outgoing packets match established sessions
    • Times out inactive connections → stops admitting packets

🔒 Stateful = จำได้ว่าใครเคยโทรมาก่อน ถ้าไม่เคยโทร แต่รับสายกลับ ก็ผิดปกติ


Example: ACL Policy Table (Full)

PolicyDirectionProtocolSourceDestinationActionLogic
No Outside Web AccessOutboundTCPInternal LANAny (Port 80)DROPBlock unencrypted browsing
Public Web HostingInboundTCPAnyWeb Server (Port 80)ALLOWOnly hole in inbound shield
Default Inbound BlockInboundTCP (SYN)AnyAnyDROPPrevents unauthorized new connections
Bandwidth ProtectionInboundUDPAnyInternal LANDROPBlocks web-radio streaming
Anti-Smurf (DoS)InboundICMPAnyBroadcast IPDROPStops amplification attacks
Stealth ModeOutboundICMP TTL ExpiredInternal LANAnyDROPHides network topology from traceroute

Firewall Examples

Linux iptables

  • Consists of 3 chains: INPUT, FORWARD, OUTPUT
  • Each chain has a default policy + individual rules (applied top to bottom)
Chain INPUT (policy ACCEPT)
  DROP  icmp  *  *  192.178.18.0/24  0.0.0.0/0    ← Drop all ICMP from 192.178.18.0 network
  DROP  tcp   *  *  192.178.18.10    0.0.0.0/0    ← Drop all TCP from 192.178.18.10

Chain FORWARD (policy ACCEPT)
  DROP  udp  *  *  192.178.18.10  0.0.0.0/0
  DROP  udp  *  *  0.0.0.0/0     192.178.18.10

Chain OUTPUT (policy DROP)
  ACCEPT  icmp  *  *  0.0.0.0/0  0.0.0.0/0       ← Allow all ICMP output

AWS: Network ACL + Security Groups

  • Uses defense-in-depth: both Network ACLs (subnet level) and Security Groups (instance level)
  • A misconfiguration in one layer won't fully expose the host
Internet Gateway → Route Table → Network ACL → Public Subnet → Security Group → Instance

5. Intrusion Detection Systems (IDS)

Firewall Limitations

  • Operates on TCP/IP headers only
  • No correlation check among multiple sessions

IDS Capabilities

  • Deep Packet Inspection — looks at packet contents (checks character strings against known virus/attack database)
  • Correlation analysis across multiple packets:
    • Port scanning detection
    • Network mapping detection
    • DoS attack detection

IDS Functions (NIDS Components)

ComponentDescription
Network Traffic ProcessingConvert traffic into network parameter patterns (signatures)
Anomaly DetectionMatch input signatures vs normal traffic signatures → detect zero-day attacks
Signature MatchingMatch input signature vs known threat signature patterns
Threat ClassificationClassify threat based on signature matching
Threat ReportingReport/log the threat
Prevention SystemAct based on threat detected (IPS functionality)

Types of IDS

  • Host-based IDS (HIDS) — examines activity on an individual system (mail server, web server)
    • Sources: audit log, file modification, syslog, kernel logs, error/event logs, SNMP trap
  • Network-based IDS (NIDS) — examines activity on the network itself
    • Sources: Packet Capture (PCAP), port mirroring

IDS Placement

  • Multiple IDS sensors at different locations = different types of checking
  • IDS sensors typically placed:
    • Inside the internal network (detects insider threats)
    • In the DMZ (monitors public-facing servers)

IDS เหมือนกล้องวงจรปิด: Firewall คือประตู (บล็อคก่อน), IDS คือกล้องที่คอยดูว่ามีอะไรผิดปกติภายในหรือเปล่า


Summary

TopicKey Points
Wireless Network ElementsWireless hosts, Base station (AP), Wireless link, Infrastructure/Ad-hoc mode
Wireless Link IssuesPath loss, interference, multipath propagation
SNR/BERHigher SNR = lower BER; adapt modulation to conditions
802.11 Standardsb(11Mbps) → g(54Mbps) → n(600Mbps) → ac(3.47Gbps) → ax(14Gbps)
Frequencies2.4GHz = long range slow; 5GHz = short range fast
CSMA/CASense before transmit, random backoff, no CD; RTS/CTS optional
Wireless SecurityWEP (broken) → WPA (TKIP) → WPA2 (AES, preferred)
FirewallControls traffic based on rules; hardware or software
Firewall StrategiesBlacklisting (ACCEPT default) vs Whitelisting (DROP default)
ZonesUntrusted (WAN) / DMZ / Trusted (LAN)
Firewall TypesStateless → Stateful → NGFW → Proxy
IDSDeep packet inspection; Host-based or Network-based

Final exam: Homework ip calculation แน่นอน, CIDR, VLSM (ต้องทำแน่นอน), configure routing, homework very important, series of question คำถามต่อกันเรื่อย ๆ
design ip → use that ip to configure routing
Allowed 1 A4 paper.