Solved

Network security  wire lan vs wlan

Posted on 2010-09-06
23
857 Views
Last Modified: 2013-11-12
Hi,

I have server, client pcs, switches all connected using wired LAN.

Now i would like to add WLAN to our site. This WLAN cannot view any share file or information in wired LAN.

First i think about seperate both network but it cost a bomb to setup WLAN seperately.

Then i think about share one connection on both wired LAN and WLAN.  But how can i seperate both IP and how to make sure that worms come from WLAN will not enter my wired LAN network. Since im using one switch for both network and does it run if two different ip scheme connect to it?

Please advise. Any best solution you can think of to solve this problem?

 
0
Comment
Question by:tankergoblin
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 9
  • 5
  • 5
  • +2
23 Comments
 
LVL 18

Expert Comment

by:Jerry Miller
ID: 33615162
You can connect the WLAN adapter to the same network switch without the wireless clients seeing the rest of the network.  Make sure that the wireless adapter is also a DHCP server and has an IP range outside of your wired network. The wireless adapter will have an IP in the wired network for switch connectivity, but its internal facing IP will be in the wireless range.

For example, wired range 192.168.0.1-192.168.0.254, wireless range 192.168.1.1-192.168.1.255 subnet mask for both 255.255.255.0.
0
 
LVL 3

Expert Comment

by:MARTiN
ID: 33615334
Your network switch should be able to cope with two networks without any problem.
Question is if your router can hande two networks and route them properly.
Or when you say switch do you actually mean router? What kind of router do you use?
0
 
LVL 7

Author Comment

by:tankergoblin
ID: 33615357
MARTiN: when i say switch i mean swicth

Is there any router that can route two network properly?

jmiller1979: is that mean i need to configure ip for client?
0
Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

 
LVL 22

Expert Comment

by:Jakob Digranes
ID: 33615440
looks like we've been through this earlier.
First of all - when it comes to security, if this is very important - do it properly.
And properly segmentation of wireless networks is to use a router/firewall with the ability to use either VLANs or routing between multiple IP-subnets - which would be a router above home-networking, but most business class firewalls do have this capability.

since you only have a wireless AP without router functionality, you cannot create a different IP network for the wireless clients, as they would not know where to send data to internet.

Designing a network with ability to separate wired and wireless networks doesn't cost too much.
Check prices in your region the following equipment:
http://www.fortinet.com/products/fortigate/50B.html - firewall with VLAN support
http://h10144.www1.hp.com/products/switches/HP_ProCurve_Switch_1700_Series/overview.htm - swithc with VLAN support

Then create to VLANs on firewall
VLAN 10 - Wired network - 192.168.10.0/24
VLAN 20 - Wireless network - 172.20.0.0/24

Then connect wireless AP with IP 172.20.0.2, and Fortigate with IP 172.20.0.1 and configure DHCP to hand out addresses from 172.20.0.10 - 172.20.0.50 and in firewall, DENY all traffice from VLAN 20 to VLAN 10, and allow traffic from VLAN 20 to WAN

And for wired network, configure Fortigate with IP 192.168.10.1 and server with 192.168.10.2 and deny all traffice from VLAN 10 to VLAN 20 and allow all traffic from VLAN 10 to WAN
0
 
LVL 7

Author Comment

by:tankergoblin
ID: 33615599
Can i use like router/modem to do this? Any brand that come with firewall/router/modem that is suitable for this project.
0
 
LVL 22

Expert Comment

by:Jakob Digranes
ID: 33615723
no
not all routers have VLAN capabilities.
What router do you have?
0
 
LVL 7

Author Comment

by:tankergoblin
ID: 33615942
Aztech?
0
 
LVL 7

Author Comment

by:tankergoblin
ID: 33615945
fortinet is very expensive stuff. any opensource i can use?
0
 
LVL 3

Expert Comment

by:MARTiN
ID: 33615956
Maybe this is something for you http://www.wifi.com.ar/english/cdrouter/
0
 
LVL 22

Expert Comment

by:Jakob Digranes
ID: 33615966
any of these?
http://www.aztech.com/prod_adsl.html
I see some of them has DMZ support. How this is configured varies between models.
Some let you create a different Zone with a different IP-address subnet, others only let you direct traffic from WAN to an existing computer on your LAN.

You can look at some Linksys routers and go for Tomato firmware, but have no overview of any of these firmwares has VLAN support
0
 
LVL 7

Author Comment

by:tankergoblin
ID: 33615992
Ok can i know any cheap equipment that can do this vlan?
0
 
LVL 7

Author Comment

by:tankergoblin
ID: 33616010
MARTiN: download from rapid share need to pay?
0
 
LVL 22

Expert Comment

by:Jakob Digranes
ID: 33616030
As MARTiN says; if you have a spare computer with several network cards, you can install/run a Linux router/firewall

you could look into a wireless router instead of a wireless AP, that way you can have different IP for wired and wireless without using VLANs. Since in any sense, you need a Router. If DLink is an option, look into the DIR-622 or similar
0
 
LVL 3

Expert Comment

by:MARTiN
ID: 33616040
No there's a "Free" option as well, you just need to wait a minute or so before download begins.
0
 
LVL 3

Expert Comment

by:MARTiN
ID: 33616065
0
 
LVL 7

Author Comment

by:tankergoblin
ID: 33618777
question. example
internet-- router/modem(110.23.2.1) fa 0/1------------------------switch(vlan)--pc(110.23.2.5)
                   |                                                                                                          |---pc(110.23.3.5)
                   |____fa 0/2 (110.23.2.2)router/modem fa 0/1(110.23.3.1)__|
 
 
My question is can normal router like dlink or aztech setup interface to connect btw router to create vlan? the reason i connect router together is because i need internet connection for both network.
 
 
0
 
LVL 12

Expert Comment

by:profgeek
ID: 33630929
My router (Netgear Rangemax WNDR3700) does what you are wanting to do because it has a buiilt-in "guest" network that you set up separately.  It will not allow clients attached to that network to access anything on the LAN.  It also has wireless for the LAN, but you can set that up with security.  The guest network can also be set up with security, if you want, or just left unsecured as a true guest network.  Here is a link to the router:

http://www.amazon.com/gp/product/B002HWRJY4/ref=oss_product

This might do what you want for $150 with easy setup.
0
 
LVL 7

Author Comment

by:tankergoblin
ID: 33633169
Does it has repeater feature for wireless ?
0
 
LVL 12

Expert Comment

by:profgeek
ID: 33633217
Not sure what you mean by "repeater feature."
0
 
LVL 3

Expert Comment

by:MARTiN
ID: 33633879
You could use a D-Link DWL-G710 Externder to repeat the signal. Although it only supports 802.11g standard. (54Mbit)
0
 
LVL 7

Author Comment

by:tankergoblin
ID: 33634255
MARTiN: dlink has feature profgeek: mention above?
0
 
LVL 12

Expert Comment

by:profgeek
ID: 33635641
If you need a repeater, you'll need to buy a separate device, as mentioned by MARTiN.  The router itself is the base and has pretty good range.  If you need longer range, you have to install a separate repeater device to extend the signal range.  What kind of range are you needing?
0
 
LVL 22

Accepted Solution

by:
Jakob Digranes earned 500 total points
ID: 33635723
looks like this Q has wandered a bit off its original topic
What's the decision on separating wired and wireless LAN?
- will you go for a wireless router or a VLAN infrastructure

remember that some Guest Network integrated routers, which is not a part of a VLAN infrastructure, only separates the wireless networks apart, and only gives the user on guest network internet access, but the wireless router thinks that the internet access starts with the Wireless routers gateway address, which might be the address the wireless router has on your LAN, so you need to configure firewall rules as well to prevent traffic originating from wireless router of reaching wired LAN on inside
0

Featured Post

Retailers - Is your network secure?

With the prevalence of social media & networking tools, for retailers, reputation is critical. Have you considered the impact your network security could have in your customer's experience? Learn more in our Retail Security Resource Kit Today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article we have discussed about the OS X EI Capitan and how to fix Wi-Fi issue in OS X El Capitan. We have explained how to delete system level preferences and create a new Wi-Fi location to resolve Wi-Fi issue.
Using in-flight Wi-Fi when you travel? Business travelers beware! In-flight Wi-Fi networks could rip the door right off your digital privacy portal. That’s no joke either, as it might also provide a convenient entrance for bad threat actors.
This Micro Tutorial will show you how to maximize your wireless card to its maximum capability. This will be demonstrated using Intel(R) Centrino(R) Wireless-N 2230 wireless card on Windows 8 operating system.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question