RE: Secure and unsecure install problem

"Casey Halverson" <[email protected]>
Newsgroups gmane.network.wireless.seattle.general
Message-ID <[email protected]>
I give Ken's parallel NAT solution a thumb's up compared to a tiered
double NAT approach.

Although a slightly larger office, I have to accommodate guests as well.
I create another SSID on my Cisco 1200 AP.  This SSID can be assigned to
a specific VPN and even given its own WEP key or other security policy.

But in my particular environment, I chose not to place our internal LAN
out on the airwaves.  When you use WiFi, you are put on an external
network with public addresses, and an ACL blocking incoming connections
and certain outgoing ports.  It uses a WEP key to avoid
casual/accidental associations from other businesses/persons in the
area.  In order to access the corporate network, you must VPN in from
this segment.  To avoid giving the WEP key to vendors, I sometimes will
create small pockets of network access using another SSID, and tear them
down when they leave.  I avoid using WEP with guests to keep things very
simple.  

I also have an ACL and bridge setting on all my Cisco 1200's to prevent
peer-to-peer communication either between users on the same access point
or users on two different access points.  This prevents worm infections
as well as people attempting to access other windows workstations on
this segment.  This is very important because we don't need WiFi as an
additional infection vector.  Also, sometimes users forget to turn off
their WiFi cards and "dual home" their machines at their desks...this
migitates other security risks such as using a laptop via WiFi as a jump
off point into the internal LAN.




> -----Original Message-----
> From: [email protected] 
> [mailto:[email protected]] On Behalf Of Ken Caruso
> Sent: Wednesday, March 02, 2005 2:57 PM
> To: SeattleWireless Talk List
> Subject: Re: Secure and unsecure install problem
> 
> Reall the best way to do this IMHO in the following (if you 
> have more than one ip address available on your DSL line):
> 
> 	DSL-Modem
>    	    |
>  	 --Switch----
>  	 |          |
>     OpenAP/Router   WEP AP/Router
> 
> This makes the following assumptions:
> 1. You can get more than one ip on your DSL line (most 
> commercial class ones will, even some residential)
> 
> 2. Both Access Points are routers/nat/firewall capable.
> 
> 3. You have an extra switch or hub lying around.
> 
> Having your internal users router piggyback on the open 
> router is not really a best practice since ultimately all of 
> your internal users traffic is dependent on the security of 
> the open router which is open for anyone to connect to.
> 
> In regards to your intial proposed solution where each ap is 
> plugged into your "wired router", does your wired router 
> support some sort of access control list? Or were you 
> planning on just having them use different ip ranges, 
> thinking that they would not see each other or be able to 
> connect to each other? 
> 
> -Ken
> 
> 
> On Wed, 2005-03-02 at 14:13 -0800, Morgan Davis wrote:
> > I would set up with two wireless routers back to back like this:
> > 
> > dsl --- open-router ---- wep router
> > 
> > The internet/wan port on the wep enabled router would plug 
> into on of 
> > the switch ports of the unsecured (open) router. The office users 
> > would be protected from access by the open users, and all 
> will able to 
> > access the internet. Routers seem to just as cheap as plain AP's 
> > nowadays. I wouldn't put them on top of each other, 
> separate them by a 
> > few feet. Additionally setup the office users to have their 
> AP listed 
> > first in preferred networks page of Windows.
> > 
> > 
> > On Mon, 28 Feb 2005 13:07:25 -0600, Scott Bradford 
> <[email protected]> wrote:
> > > Hello all... need some suggestions
> > > 
> > > I have an office environment that I want to have a 
> "closed" wireless system
> > > for our laptops and an "open" wireless for guests.   I 
> want them to be able
> > > to associate into it without me going in and babysitting 
> them all the time.
> > > Only way I can think to do this is.....
> > > 
> > > dsl - wired router  -  ap1    secure
> > >                           -  ap2   unsecure
> > > 
> > > Since I can set the IPs, the "wired"  router will "block" 
> one AP from the
> > > other.   Set one to channel 1, dhcp on full blast...  set 
> the second to
> > > channel 11, turn on web, and go on with my life
> > > 
> > > Comments or suggestions appreciated
> > > 
> > > _______________________________________________
> > > Talk mailing list
> > > [email protected]
> > > http://seattlewireless.net/mailman/listinfo/talk
> > >
> > _______________________________________________
> > Talk mailing list
> > [email protected]
> > http://seattlewireless.net/mailman/listinfo/talk
> 
> _______________________________________________
> Talk mailing list
> [email protected]
> http://seattlewireless.net/mailman/listinfo/talk
> 
_______________________________________________
Talk mailing list
[email protected]
http://seattlewireless.net/mailman/listinfo/talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.