Solved

Questions about Cisco Wireless setup.

Posted on 2008-06-17
3
282 Views
Last Modified: 2013-11-09
Hello Experts,
We are implementing a wireless warehouse inventory scanning system and I would like to make it as secure as possible.
Network Infrastructure is Dell layer2 switches - one subnet.
Access Points are Cisco AP1242AG

1) I would like to restrict the wireless hand-held scanner devices to only certain LAN IP's, Is this possible? Example please.

2) I would like to allow laptops to connect to the same AP's but restrict them to only the Internet, Is this possible? Example please.

3) I would like to use the same SSID's on all AP's for the hand-held scanners as well as the laptop access with the same restrictions, Is this possible? Example please.

4) Recommendations?

Let me know if any more detail is needed.
Thanks
0
Comment
Question by:Starrett2005
  • 2
3 Comments
 
LVL 5

Expert Comment

by:rslqld
ID: 21810015
1) Depending on number of hand-held devices, static DHCP leases may be your best bet. Assuming you have a central DHCP server or router, just add the leases there and configure each AP to perform DHCP pass-through via web interface or CLI.

2) Those Cisco APs have support for ACLs - create an ACL to permit IP traffic to your internal subnet, and the final entry in the ACL to deny all other destinations.

3) You can do this - any APs that have overlaping signal are best set 5 channels apart to prevent interference - e.g. AP1 is on channel 6 and is within range of AP2 so put AP2 on channel 11.
0
 

Author Comment

by:Starrett2005
ID: 21812153
1) I would like to restrict the wireless hand-held scanner devices to only certain LAN IP's, Is this possible? Example please.
A) Depending on number of hand-held devices, static DHCP leases may be your best bet. Assuming you have a central DHCP server or router, just add the leases there and configure each AP to perform DHCP pass-through via web interface or CLI.
Q) (15 devices)Would the restriction to the application server IP be done with ACL's as well?

2) I would like to allow laptops to connect to the same AP's but restrict them to only the Internet, Is this possible? Example please.
A) Those Cisco APs have support for ACLs - create an ACL to permit IP traffic to your internal subnet, and the final entry in the ACL to deny all other destinations.
Q) Do I need multiple VLANs for different restrictions on SSID's? And if so, do my network switches need to support VLAN trunking on the ports the Aironet are connected?

3) I would like to use the same SSID's on all AP's for the hand-held scanners as well as the laptop access with the same restrictions, Is this possible? Example please.
A) You can do this - any APs that have overlaping signal are best set 5 channels apart to prevent interference - e.g. AP1 is on channel 6 and is within range of AP2 so put AP2 on channel 11.
Q) Will this be OK if all Aironet AP's are configured as root? I'm hoping the same SSID will prevent an connection poblems when a device moves into range of another AP.
0
 

Accepted Solution

by:
Starrett2005 earned 0 total points
ID: 25308569
More research on my questions reveals that the Cisco wireless controller will provide better functinality than just using the WAP devices themselves. At this time we are not ready to purchase the controllers.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
belkin wifi stick 12 95
WiFi card or   "Wireless to Ethernet bridge" 3 61
Multiple Wireless Networks, Same SSID 8 116
OpenELEC on Raspberry PI 3 Tethered Access Point 4 428
This article is split into background info to start and actual review at bottom: Some time ago I wanted to sell a system with both wired and wireless capability but at minimum expense.  Having visited my trusted online auction I was pleasantly su…
This article is a step by step guide on how to create a basic PTP link using Ubiquiti airOS devices. This guide can be used on the following Ubiquiti AirMAX devices. Nanostation, Bullets, AirBridge, Nanobeam, NanoBridge to name a few. Please review …
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question