Solved

Creating a VLAn for open wireless connectivity

Posted on 2011-03-17
3
540 Views
Last Modified: 2013-12-27
I work in a law firm and we currently have the wireless locked down. I would like to create a open connection using the same wireless access points that are already in place. I am using Netgear ProSafe WG102 access points and a Cisco ASA 5505 router. Is the easiest and best thing to do in this situation to vreate a VLAN and let the open security connection use the new VLAN?

I have a Cisco guy that can configure the new VLAN on the router but after that I get kind of lost on how to go about setting everything up. I am very new to VLAN's but would appreciate any information you could provide. The WAP's do support VLANS and also have the option to Enable 802.1Q VLAN

Below is a screen shot of the WAP setup just to show you the options.

No. Profile Name SSID Security VLAN Status
1 NETGEAR COMPANYNAME WPA/WPA2 - PSK 1 Enable
2 NETGEAR1 NETGEAR - 1 None 2 Disable
3 NETGEAR2 NETGEAR - 2 None 3 Disable
4 NETGEAR3 NETGEAR - 3 None 4 Disable
5 NETGEAR4 NETGEAR - 4 None 5 Disable
6 NETGEAR5 NETGEAR - 5 None 6 Disable
7 NETGEAR6 NETGEAR - 6 None 7 Disable
8 NETGEAR7 NETGEAR - 7 None 8 Disable
0
Comment
Question by:jseadrew
  • 2
3 Comments
 
LVL 4

Expert Comment

by:Jerry Mills
ID: 35157851
I would create a VLAN on the ASA 5505 and connect the open connection to it.  You must create ACL's to control traffic to keep it off your office lan.  

I am assuming you only wish to let visitors have an internet access point.  I correct - consider connecting to the PUBLIC side directly with a wireless router if you have an available IP address.
0
 

Author Comment

by:jseadrew
ID: 35157891
Yes, only visitors would use the open connection.
So once the VLAN is setup in the Cisco you would suggest getting a seperate wireless router and configure it for open access? I do have an external address I coud use.
0
 
LVL 4

Accepted Solution

by:
Jerry Mills earned 500 total points
ID: 35157944
I would suggest not using the ASA 5505.  Put an inexpensive switch in front of the ASA 5505 - reconnect the 5505 and then connect your wireless router to the switch and use the public address - bypassing the ASA all together.    Total security and you don't need to mess with the ASA 5505.
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

Suggested Solutions

Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
This paper addresses the security of Sennheiser DECT Contact Center and Office (CC&O) headsets. It describes the DECT security chain comprised of “Pairing”, “Per Call Authentication” and “Encryption”, which are all part of the standard DECT protocol.
This Micro Tutorial will show you how to maximize your wireless card to its maximum capability. This will be demonstrated using Intel(R) Centrino(R) Wireless-N 2230 wireless card on Windows 8 operating system.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now