RE: Secure and unsecure install problem
"Casey Halverson" <[email protected]>
| Newsgroups | gmane.network.wireless.seattle.general |
|---|---|
| Message-ID | <[email protected]> |
I give Ken's parallel NAT solution a thumb's up compared to a tiered double NAT approach. Although a slightly larger office, I have to accommodate guests as well. I create another SSID on my Cisco 1200 AP. This SSID can be assigned to a specific VPN and even given its own WEP key or other security policy. But in my particular environment, I chose not to place our internal LAN out on the airwaves. When you use WiFi, you are put on an external network with public addresses, and an ACL blocking incoming connections and certain outgoing ports. It uses a WEP key to avoid casual/accidental associations from other businesses/persons in the area. In order to access the corporate network, you must VPN in from this segment. To avoid giving the WEP key to vendors, I sometimes will create small pockets of network access using another SSID, and tear them down when they leave. I avoid using WEP with guests to keep things very simple. I also have an ACL and bridge setting on all my Cisco 1200's to prevent peer-to-peer communication either between users on the same access point or users on two different access points. This prevents worm infections as well as people attempting to access other windows workstations on this segment. This is very important because we don't need WiFi as an additional infection vector. Also, sometimes users forget to turn off their WiFi cards and "dual home" their machines at their desks...this migitates other security risks such as using a laptop via WiFi as a jump off point into the internal LAN. > -----Original Message----- > From: [email protected] > [mailto:[email protected]] On Behalf Of Ken Caruso > Sent: Wednesday, March 02, 2005 2:57 PM > To: SeattleWireless Talk List > Subject: Re: Secure and unsecure install problem > > Reall the best way to do this IMHO in the following (if you > have more than one ip address available on your DSL line): > > DSL-Modem > | > --Switch---- > | | > OpenAP/Router WEP AP/Router > > This makes the following assumptions: > 1. You can get more than one ip on your DSL line (most > commercial class ones will, even some residential) > > 2. Both Access Points are routers/nat/firewall capable. > > 3. You have an extra switch or hub lying around. > > Having your internal users router piggyback on the open > router is not really a best practice since ultimately all of > your internal users traffic is dependent on the security of > the open router which is open for anyone to connect to. > > In regards to your intial proposed solution where each ap is > plugged into your "wired router", does your wired router > support some sort of access control list? Or were you > planning on just having them use different ip ranges, > thinking that they would not see each other or be able to > connect to each other? > > -Ken > > > On Wed, 2005-03-02 at 14:13 -0800, Morgan Davis wrote: > > I would set up with two wireless routers back to back like this: > > > > dsl --- open-router ---- wep router > > > > The internet/wan port on the wep enabled router would plug > into on of > > the switch ports of the unsecured (open) router. The office users > > would be protected from access by the open users, and all > will able to > > access the internet. Routers seem to just as cheap as plain AP's > > nowadays. I wouldn't put them on top of each other, > separate them by a > > few feet. Additionally setup the office users to have their > AP listed > > first in preferred networks page of Windows. > > > > > > On Mon, 28 Feb 2005 13:07:25 -0600, Scott Bradford > <[email protected]> wrote: > > > Hello all... need some suggestions > > > > > > I have an office environment that I want to have a > "closed" wireless system > > > for our laptops and an "open" wireless for guests. I > want them to be able > > > to associate into it without me going in and babysitting > them all the time. > > > Only way I can think to do this is..... > > > > > > dsl - wired router - ap1 secure > > > - ap2 unsecure > > > > > > Since I can set the IPs, the "wired" router will "block" > one AP from the > > > other. Set one to channel 1, dhcp on full blast... set > the second to > > > channel 11, turn on web, and go on with my life > > > > > > Comments or suggestions appreciated > > > > > > _______________________________________________ > > > Talk mailing list > > > [email protected] > > > http://seattlewireless.net/mailman/listinfo/talk > > > > > _______________________________________________ > > Talk mailing list > > [email protected] > > http://seattlewireless.net/mailman/listinfo/talk > > _______________________________________________ > Talk mailing list > [email protected] > http://seattlewireless.net/mailman/listinfo/talk > _______________________________________________ Talk mailing list [email protected] http://seattlewireless.net/mailman/listinfo/talk