Solved

Dedicated DHCP Address

Posted on 2007-11-22
8
838 Views
Last Modified: 2012-06-21
We have been "told" to setup a "client" Wireless Access point so visitors can be given  the  "password" and have internet access when in the office.

We have attached a Netgear WN802T to the network which people can connect to without any problems.

The problem,

When a visitor connects they are givern a IP address from the companies DHCP servers.  These
address do not have internet access as we use a proxy server and only certain IP's have external firewalls access. I need a way of ensuring the Access Point gives out a certain range of IP's via DHCP that can be allowed direst internet access.

Thankyou in advance

0
Comment
Question by:SGPIT
  • 4
  • 2
8 Comments
 
LVL 13

Expert Comment

by:dhoffman_98
Comment Utility
You should be able to set up your wireless access point with NAT. That's Network Address Translation. Most current access points have this capability and will have their own internal DHCP server. You can have this server give out addresses on a private subnet just to be used for your wireless users that connect to that access point. Then all traffic coming from that access point to your companies network would appear to be coming from the same IP Address, but the NAT router in the Access Point keep control of making sure that the right information is returned to the right session.

If all of the traffic appears to be coming from the one IP Address, then it's easy enough on your network to create a rule that allows that one address to get through to the Internet.

In this configuration, you would assign the AP a specific address that you would configure on the company firewall to allow access. Then enable the NAT configuration on the AP, and assign a new range of addresses on the AP's DHCP server to assign only to wireless clients.
0
 

Author Comment

by:SGPIT
Comment Utility
"You should be able to set up your wireless access point with NAT"

Not on the WN802T, its purely a "access point only" (as I understand).

2will have their own internal DHCP server"

No internal DHCP Server, hence the problem.  It passes the requests to the internal DHCP Servers without a problem but "unless I know" the visitors mac address then they fail to get internat access.



0
 
LVL 13

Expert Comment

by:dhoffman_98
Comment Utility
Then I'm sorry. You might want to go back to the people that gave you those requirements and ask them to pay another 40-50 dollars for an access point that can do NAT translations.
0
How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

 
LVL 4

Expert Comment

by:wally2k7
Comment Utility
Can you not connect the access point to the outside world directly, I assume all they need is the internet not internal lan connection. That would still pose a problem on the DNCP side however. A wireless router to replace your current access point. Bypass the network completely and connect straight into your external internet connection. That should do the triclk, ?? :-S maybe.

Am I going anywhere near the right direction??

Regards, Rich
0
 

Author Comment

by:SGPIT
Comment Utility
"Can you not connect the access point to the outside world directly, I assume all they need is the internet not internal lan connection. "

The access point are used for internal and external access.  Depending on their assigned IP the firewall then allows/dis-allows internet access.

Is there a "cost effective" acces spoint that has "inbuilt" dhcp.

Thankyou
0
 
LVL 13

Expert Comment

by:dhoffman_98
Comment Utility
"Is there a "cost effective" acces spoint that has "inbuilt" dhcp"

Yes... very cost effective. Check out Linksys, Dlink, Motorola...
I have a few Linksys BEFSR41's. They have a 4 port switch as well as the wireless connectivity. One port is used for connecting to your LAN. Then the router provides Network Address Translation (NAT) and built-in DHCP. The addresses given out are on their own private subnet (192.168.1.x) and the gateway and DNS information are automatically sent to the clients. The LAN side can be set static, so your firewall configuration can be set up so that clients that come from that source address automatically get the proper access to the Internet.

The BEFSR41 is only 802.11b, so it only supports 11Mbits. I wouldn't suggest that to anyone now. Instead check out the WRT54G which is 802.11g. Here's some information I copied from the product info page at Best Buy (where the unit costs only $69.99).

Product Features:
- Wireless-G networking (54g) allows stepped-up data transfer speeds while maintaining worry-free compatibility with 802.11b networks
- Up to 54 Mbps data transfer rates — almost 5 times more than typical 802.11b rates
- 2.4GHz wireless frequency (802.11g- and 802.11b-compliant)
- Compatible with 802.11b networks (at 11 Mbps)
- Share high-speed broadband Internet access plus files and printers among multiple computers, with or without wires
- Built-in 4-port 10/100 Ethernet switch with auto speed sensing
- Capable of up to 128-bit WEP (Wired Equivalent Privacy) encryption
- Advanced security with NAT technology, VPN pass-through and MAC or IP address filtering
- Ability to act as DHCP (Dynamic Host Configuration Protocol) server for existing network (a new computer can be added to network without manually assigning it a unique IP address)
- Easy browser-based configuration utility


0
 
LVL 13

Accepted Solution

by:
dhoffman_98 earned 500 total points
Comment Utility
Rindi,

I think more than enough sufficient information was provided to mark this as a force accept instead of abandoned.
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Join & Write a Comment

Suggested Solutions

I have had so many issues with my Vodafone 3G card (Novatel Merlin u630, provided by French carrier SFR) on Windows XP laptops that I thought I would create an help page for other users (I solved the issues). First issue, with my IBM/Lenovo lapto…
This article is a step by step guide on how to create a basic PTP link using Ubiquiti airOS devices. This guide can be used on the following Ubiquiti AirMAX devices. Nanostation, Bullets, AirBridge, Nanobeam, NanoBridge to name a few. Please review …
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now