Solved

Questions about Cisco Wireless setup.

Posted on 2008-06-17
3
279 Views
Last Modified: 2013-11-09
Hello Experts,
We are implementing a wireless warehouse inventory scanning system and I would like to make it as secure as possible.
Network Infrastructure is Dell layer2 switches - one subnet.
Access Points are Cisco AP1242AG

1) I would like to restrict the wireless hand-held scanner devices to only certain LAN IP's, Is this possible? Example please.

2) I would like to allow laptops to connect to the same AP's but restrict them to only the Internet, Is this possible? Example please.

3) I would like to use the same SSID's on all AP's for the hand-held scanners as well as the laptop access with the same restrictions, Is this possible? Example please.

4) Recommendations?

Let me know if any more detail is needed.
Thanks
0
Comment
Question by:Starrett2005
  • 2
3 Comments
 
LVL 5

Expert Comment

by:rslqld
Comment Utility
1) Depending on number of hand-held devices, static DHCP leases may be your best bet. Assuming you have a central DHCP server or router, just add the leases there and configure each AP to perform DHCP pass-through via web interface or CLI.

2) Those Cisco APs have support for ACLs - create an ACL to permit IP traffic to your internal subnet, and the final entry in the ACL to deny all other destinations.

3) You can do this - any APs that have overlaping signal are best set 5 channels apart to prevent interference - e.g. AP1 is on channel 6 and is within range of AP2 so put AP2 on channel 11.
0
 

Author Comment

by:Starrett2005
Comment Utility
1) I would like to restrict the wireless hand-held scanner devices to only certain LAN IP's, Is this possible? Example please.
A) Depending on number of hand-held devices, static DHCP leases may be your best bet. Assuming you have a central DHCP server or router, just add the leases there and configure each AP to perform DHCP pass-through via web interface or CLI.
Q) (15 devices)Would the restriction to the application server IP be done with ACL's as well?

2) I would like to allow laptops to connect to the same AP's but restrict them to only the Internet, Is this possible? Example please.
A) Those Cisco APs have support for ACLs - create an ACL to permit IP traffic to your internal subnet, and the final entry in the ACL to deny all other destinations.
Q) Do I need multiple VLANs for different restrictions on SSID's? And if so, do my network switches need to support VLAN trunking on the ports the Aironet are connected?

3) I would like to use the same SSID's on all AP's for the hand-held scanners as well as the laptop access with the same restrictions, Is this possible? Example please.
A) You can do this - any APs that have overlaping signal are best set 5 channels apart to prevent interference - e.g. AP1 is on channel 6 and is within range of AP2 so put AP2 on channel 11.
Q) Will this be OK if all Aironet AP's are configured as root? I'm hoping the same SSID will prevent an connection poblems when a device moves into range of another AP.
0
 

Accepted Solution

by:
Starrett2005 earned 0 total points
Comment Utility
More research on my questions reveals that the Cisco wireless controller will provide better functinality than just using the WAP devices themselves. At this time we are not ready to purchase the controllers.
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

I have had so many issues with my Vodafone 3G card (Novatel Merlin u630, provided by French carrier SFR) on Windows XP laptops that I thought I would create an help page for other users (I solved the issues). First issue, with my IBM/Lenovo lapto…
This article is split into background info to start and actual review at bottom: Some time ago I wanted to sell a system with both wired and wireless capability but at minimum expense.  Having visited my trusted online auction I was pleasantly su…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now