Re: Secure and unsecure install problem
Ken Caruso <[email protected]>
| Newsgroups | gmane.network.wireless.seattle.general |
|---|---|
| Message-ID | <1109805655.20903.28.camel@akira> |
Comment in line. On Wed, 2005-03-02 at 15:16 -0800, Morgan Davis wrote: > DSL > | > | (wan port of router1 to DSL)) > | > ROUTER1 (open) > | | | | | > | > | > | (wan port of router2 to switch port of router1) > | > ROUTER2 (WEP/WPA) > | | | | | > I Connect to Router1 via the wireless ( I am a guest). I arp spoof (http://www.monkey.org/~dugsong/dsniff/ ) router2 into thinking that I am default gateway for that network. I am now intercepting all of router2's traffic for sniffing, man in the middle attacks etc... > > All of the users whom have the key can associate or plug into ROUTER2, > they will have access to each other and will NAT through to the switch > side of ROUTER1, where they can NAT again to the internet. Guests will > be able to connect to ROUTER1 eith wired or wirelessly, and they can > get access to the internet, but they will not be able to go backward > through router2 to get to the office equipment or users. The only > thing that needs to be changed on router2 after enabling encryption is > the network address (so it doesn't overlap with router1). It's cheap, > simple and provides protection of the internal users from the guests. > > > On Wed, 2 Mar 2005 14:54:24 -0800, Casey Halverson > <[email protected]> wrote: > > I don't understand what segmenting internal users and external users on > > two different access points will accomplish. All the hosts will be able > > to interact through your wired segment. There is no security benefit in > > this design. > > > > > > > -----Original Message----- > > > From: [email protected] > > > [mailto:[email protected]] On Behalf Of Scott Bradford > > > Sent: Monday, February 28, 2005 11:07 AM > > > To: [email protected] > > > Subject: Secure and unsecure install problem > > > > > > Hello all... need some suggestions > > > > > > I have an office environment that I want to have a "closed" > > > wireless system > > > for our laptops and an "open" wireless for guests. I want > > > them to be able > > > to associate into it without me going in and babysitting them > > > all the time. > > > Only way I can think to do this is..... > > > > > > dsl - wired router - ap1 secure > > > - ap2 unsecure > > > > > > Since I can set the IPs, the "wired" router will "block" one > > > AP from the > > > other. Set one to channel 1, dhcp on full blast... set the > > > second to > > > channel 11, turn on web, and go on with my life > > > > > > Comments or suggestions appreciated > > > > > > > > > _______________________________________________ > > > Talk mailing list > > > [email protected] > > > http://seattlewireless.net/mailman/listinfo/talk > > > > > _______________________________________________ > > Talk mailing list > > [email protected] > > http://seattlewireless.net/mailman/listinfo/talk > > > _______________________________________________ > Talk mailing list > [email protected] > http://seattlewireless.net/mailman/listinfo/talk _______________________________________________ Talk mailing list [email protected] http://seattlewireless.net/mailman/listinfo/talk