Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

Restrict network access until user authenticated against remote database.

Posted on 2004-03-31
Last Modified: 2010-04-08

I want to set up a wireless network which will allow users to access only one internet website where they can buy surfing time.  Once they have an account, I want the firewall at the access point to allow them to surf the internet freely.

I think this will require rewriting the firewall in the access point restricting access based on MAC address, but how do I go about doing this.  Setting up the central database is no trouble, but how do I get the firewall to talk to it?

Many thanks,

Question by:benlinton
  • 2
  • 2
  • 2
  • +2
LVL 57

Expert Comment

by:Pete Long
ID: 10722909
Hi benlinton,
Im unsure to be honest but if your using cisco firewall you can certainly get it to authenticate to an RSA Radius server on your network, you just nees to work out how to assign the RSA access licences to the clients?


Author Comment

ID: 10722944
I was wanting to reprogramme a netgear wireless router such as:


but don't know if this is possible.  

Basically, this machine gives you a web based controlpanel where you can add MAC addresses to a trusted list.  I want to allow all MAC address access to my billing website, but then only allow full internet access to MAC addresses I have in my database as having paid.

Is that clearer?!!

Many thanks,

LVL 79

Expert Comment

ID: 10723514
Have you looked at something like this D-Link gateway

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

LVL 23

Expert Comment

by:Tim Holman
ID: 10723691
You could use one generic SSID that allow users access only to your payment server network - eg

Then, another SSID could be used (with authentication) to provide the global Internet access that they require (running on another network, eg
LVL 20

Accepted Solution

What90 earned 500 total points
ID: 10729338
Why not just set up a proxy server account for each user once they have joined and paided?
They enter a username and password (on the proxy server of your choice) once they connect to the default web page.

That way the proxy server authenicates the user and allows them access to the Internet.
You can place any further rules on the proxy server.

Most of the hot spot zones ISP's use a similar method.

Saves all this MAC madness ;-)


Author Comment

ID: 10730007
And is it easy to get the proxy server to talk to a central database?  Sounds promising...!
LVL 20

Expert Comment

ID: 10730569
The database I've seen it work with is Active Directory and ISA 2000. Works very nicely. I'm sure there are bespoke apps that fit the picture if you don't want to use the Ms route.
LVL 79

Expert Comment

ID: 10807710
Are you still working on this? Do you need more information?

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
only allowed to specific websites - web filtering 3 282
TMG 2010 Deployment 3 97
Firewall connection 10 72
Filezilla server wont allow me to connect to it 2 57
Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

790 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question