Re: Secure and unsecure install problem

Morgan Davis <[email protected]>
Newsgroups gmane.network.wireless.seattle.general
Message-ID <[email protected]>
I would agree that your design is a far more sophisticated solution
that takes additional security considerations into account. I did make
some assumptions about the original poster - namely a small office
situation where avoiding cost and complexity of the config would be
important.

The choice of placing your "internal" wireless network outside or in
the DMZ and having users VPN in is an effective way to minimize
breaches. The way I have been dealing with guest/vendor access in many
larger installations is to create a separate SSID on the AP's, have
that go to a separate VLAN that goes out to the internet by way of a
DSL or cable line (completely separate from the main internet
connection). $30-50 a month and I really don't care much about what
goes on there nor do I have to manage it much (which is priceless).


On Wed, 2 Mar 2005 15:29:20 -0800, Casey Halverson
<[email protected]> wrote:
> I give Ken's parallel NAT solution a thumb's up compared to a tiered
> double NAT approach.
> 
> Although a slightly larger office, I have to accommodate guests as well.
> I create another SSID on my Cisco 1200 AP.  This SSID can be assigned to
> a specific VPN and even given its own WEP key or other security policy.
> 
> But in my particular environment, I chose not to place our internal LAN
> out on the airwaves.  When you use WiFi, you are put on an external
> network with public addresses, and an ACL blocking incoming connections
> and certain outgoing ports.  It uses a WEP key to avoid
> casual/accidental associations from other businesses/persons in the
> area.  In order to access the corporate network, you must VPN in from
> this segment.  To avoid giving the WEP key to vendors, I sometimes will
> create small pockets of network access using another SSID, and tear them
> down when they leave.  I avoid using WEP with guests to keep things very
> simple.
> 
> I also have an ACL and bridge setting on all my Cisco 1200's to prevent
> peer-to-peer communication either between users on the same access point
> or users on two different access points.  This prevents worm infections
> as well as people attempting to access other windows workstations on
> this segment.  This is very important because we don't need WiFi as an
> additional infection vector.  Also, sometimes users forget to turn off
> their WiFi cards and "dual home" their machines at their desks...this
> migitates other security risks such as using a laptop via WiFi as a jump
> off point into the internal LAN.
> 
> 
> > -----Original Message-----
> > From: [email protected]
> > [mailto:[email protected]] On Behalf Of Ken Caruso
> > Sent: Wednesday, March 02, 2005 2:57 PM
> > To: SeattleWireless Talk List
> > Subject: Re: Secure and unsecure install problem
> >
> > Reall the best way to do this IMHO in the following (if you
> > have more than one ip address available on your DSL line):
> >
> >       DSL-Modem
> >           |
> >        --Switch----
> >        |          |
> >     OpenAP/Router   WEP AP/Router
> >
> > This makes the following assumptions:
> > 1. You can get more than one ip on your DSL line (most
> > commercial class ones will, even some residential)
> >
> > 2. Both Access Points are routers/nat/firewall capable.
> >
> > 3. You have an extra switch or hub lying around.
> >
> > Having your internal users router piggyback on the open
> > router is not really a best practice since ultimately all of
> > your internal users traffic is dependent on the security of
> > the open router which is open for anyone to connect to.
> >
> > In regards to your intial proposed solution where each ap is
> > plugged into your "wired router", does your wired router
> > support some sort of access control list? Or were you
> > planning on just having them use different ip ranges,
> > thinking that they would not see each other or be able to
> > connect to each other?
> >
> > -Ken
> >
> >
> > On Wed, 2005-03-02 at 14:13 -0800, Morgan Davis wrote:
> > > I would set up with two wireless routers back to back like this:
> > >
> > > dsl --- open-router ---- wep router
> > >
> > > The internet/wan port on the wep enabled router would plug
> > into on of
> > > the switch ports of the unsecured (open) router. The office users
> > > would be protected from access by the open users, and all
> > will able to
> > > access the internet. Routers seem to just as cheap as plain AP's
> > > nowadays. I wouldn't put them on top of each other,
> > separate them by a
> > > few feet. Additionally setup the office users to have their
> > AP listed
> > > first in preferred networks page of Windows.
> > >
> > >
> > > On Mon, 28 Feb 2005 13:07:25 -0600, Scott Bradford
> > <[email protected]> wrote:
> > > > Hello all... need some suggestions
> > > >
> > > > I have an office environment that I want to have a
> > "closed" wireless system
> > > > for our laptops and an "open" wireless for guests.   I
> > want them to be able
> > > > to associate into it without me going in and babysitting
> > them all the time.
> > > > Only way I can think to do this is.....
> > > >
> > > > dsl - wired router  -  ap1    secure
> > > >                           -  ap2   unsecure
> > > >
> > > > Since I can set the IPs, the "wired"  router will "block"
> > one AP from the
> > > > other.   Set one to channel 1, dhcp on full blast...  set
> > the second to
> > > > channel 11, turn on web, and go on with my life
> > > >
> > > > Comments or suggestions appreciated
> > > >
> > > > _______________________________________________
> > > > Talk mailing list
> > > > [email protected]
> > > > http://seattlewireless.net/mailman/listinfo/talk
> > > >
> > > _______________________________________________
> > > Talk mailing list
> > > [email protected]
> > > http://seattlewireless.net/mailman/listinfo/talk
> >
> > _______________________________________________
> > Talk mailing list
> > [email protected]
> > http://seattlewireless.net/mailman/listinfo/talk
> >
> _______________________________________________
> Talk mailing list
> [email protected]
> http://seattlewireless.net/mailman/listinfo/talk
>
_______________________________________________
Talk mailing list
[email protected]
http://seattlewireless.net/mailman/listinfo/talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.