Add wireless router for internet access only

Posted on 2009-02-17
Medium Priority
Last Modified: 2013-11-09
I have an existing LAN setup with a Linksys BEFSR81 router.  I would like to add a Netgear WGR614 router for wireless access only to the internet.   I'd like the existing users on the Linksys router to maintain internet and LAN access.   Simply put, I want to segregate wireless users and only give them the ability to access the internet.

Currently have the Linksys router plugged into the Business Gateway from our ISP.  The Netgear router is plugged from Netgear WAN port to Linksys LAN port.  I do not want to reconfigure existing LAN nor do I want to place the Netgear router in between the ISP gateway and the Linksys router even though I'm sure this would solve the problem.

Existing Linksys router LAN settings:
router IP:
Subnet mask:

The Netgear WAN settings are set to the same subnet but outside the range of the Linksys DHCP server.  I've set the Netgear LAN to a different subnet but it still has access to Linksys LAN.
Question by:gcpllc
  • 2
  • 2
LVL 88

Expert Comment

ID: 23663997
Just connect the router to your LAN through it's WAN port and enable it's internal DHCP server. This should prevent access to the LAN itself but it'll work as gateway to the internet.

Expert Comment

ID: 23664129
If you place the Netgear behind the Linksys, then no matter what, any crafty user will be able to access the LAN of the Linksys.  You see, the Netgear will have a 192.168.1.x ip address, which places it on the same subnet as your Linksys LAN.  Of course. you will have to turn on DHCP on the Netgear in order for wireless users to get ip and gateway information.  Anyone can do a traceroute and see what the next hop ip address is.  They can then start port scanning away.
So, based on the equipment that you have, you will need to place the Netgear in front of the Linksys.  This will solve the issue of preventing the wireless users from accessing your LAN.
Now with regard to the ip address scheme, there is no big deal there.  Just make sure that the Netgear LAN addressing is something else, like 192.168.25.x.  The Netgear will get the public ip address from your cable modem, and the Linksys will now get a 192.168.25.x ip for its WAN address.  The LAN of the Linksys remains unchanged.

Author Comment

ID: 23664395
rindi:  When the WAN port of the Netgear is plugged into an available LAN port, users still can see the LAN.  But I agree, that I originally thought that this would work.

API NOC:  your comments about visitbility with a tracert are well taken.   I was hoping there was way to manually set the Netgear as 'private' allowing internet only, but these off the shelf routers don't allow enough in the way of rules settings.  

If I do put the Netgear in front of the Linksys, I will have to set the Netgear with my static IP settings from my ISP, but what will this do to my port forwarding?  Can I port forward from my Netgear to a computer connected to my Linksys and therefore on a different subnet?

Accepted Solution

API_NOC earned 2000 total points
ID: 23664902
Yes, this is possible.  You can put the Linksys in the DMZ of the Netgear and do the port forwarding.  Another way, which will double the effort is to put port forwarding on the Netgear to the 192.168.25.x ip of the Linksys, and then again do the port forward to the LAN side of the Linksys 192.168.1.x

Author Comment

ID: 23695747
Ahh, yes, I should have thought about setting the 2nd router on the DMZ.  Thanks for the help.  I'll bite the bultet and put the wireless router in front of the wired router.  

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Hello , This is a short article on how would you go about enabling traceoptions on a Juniper router . Traceoptions are similar to Cisco debug commands but these traceoptions are implemented in Juniper networks router . The following demonstr…
This program is used to assist in finding and resolving common problems with wireless connections.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question