Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

How do I create two wireless networks on one overall network?

Posted on 2011-09-17
11
Medium Priority
?
703 Views
Last Modified: 2012-06-27
How would I create one overall network that incorporates two wireless networks?  One of the wireless networks need to be protected for employees, the other is an unprotected network for public use.
0
Comment
Question by:CHIEF31
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
  • +2
11 Comments
 
LVL 21

Expert Comment

by:Papertrip
ID: 36555517
So you mean you want 2 individual wireless networks, one with intranet and internet access, and one with only internet?  Or do you mean 2 internet-only networks, one encrypted and one not?

What are you using for wireless AP's?  What are you using for overall routing?

0
 
LVL 4

Expert Comment

by:duffme
ID: 36555971
Create two separate wireless networks that use different IP ranges of the same larger network.  These could be two different subnets if you are routing where each wireless network connects to the 'core' network.  Or these could be two address ranges in the same subnet.  You could use VLANs to separate the traffic.  Since the one is for public use I would suggest using two segments to better protect the employee network. Have the public wifi network connect to a DMZ or outside of the corporate network. You can find wireless APs or routers with dual radios, but since you are talking public and business networks I should think it best to keep these wired separately unless security isn't a major concern.
0
 
LVL 9

Accepted Solution

by:
Lance_P earned 378 total points
ID: 36556021
We use cisco for our Core networking and Aruba to manage our Wireless.

We have a seperate VLAN for the different wireless networks which help in sending the right kind of traffic to the right destination.

Work VLAN, which aloows only domain computers to authenticate through radius, users cannot change this setting and it cannot be manually added. It is controlled through GP.

Guest network, this VLAN has access only to the internet. No access to the internal network. Controlled by user name and password, managed by Aruba.

WPA based network for internal mobile phone users. Since they needed it, a separate wifi network using WPA so that the network is stored permanently on their phones. Of course no one has access to this password except IT.

SO basically, If you have a wireless controller this will solve your problem in a more manageable way. If not your will have a long road ahead of you.
0
Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

 

Author Comment

by:CHIEF31
ID: 36556836
What type of equipment would I need to purchase to create the VLAN and about how much would it cost?
0
 
LVL 26

Assisted Solution

by:Fred Marshall
Fred Marshall earned 372 total points
ID: 36556858
Check out this paper that lays out what can be done. Multiple-Subnets.pdf
0
 
LVL 9

Expert Comment

by:Lance_P
ID: 36556971
How much it would cost would depend on how much you can spend, and how complex the network should be (Security wise).

You could do it with a Layer 3 switch to configure the VLAN's and use any wireless controller to configure the WiFi networks.

Alternatively you could also look at some boxes like Sonicwall. They offer boxes which can terminate your DSL lines as well as have built in Wifi Support. These boxes also have guest network support. It depends on the number of users you have to choose the right box.

0
 
LVL 9

Assisted Solution

by:Lance_P
Lance_P earned 378 total points
ID: 36556987
http://www.sonicwall.com/us/products/TZ_Series.html#tab=compare

The TX 210 is recommended for a small business. How many users do you have? 40 - 60 users? this should be fine. If it is 150+ then you might need to look at a more professional solution.

I use Sonicwall which is why I can recommend it.
0
 

Author Comment

by:CHIEF31
ID: 36557345
There are less that 20 users.  There will only be two wireless networks.  One secure wireless network for the employees and one unsecure network for the customers.  
0
 
LVL 26

Assisted Solution

by:Fred Marshall
Fred Marshall earned 372 total points
ID: 36557363
The paper I sent you covers two ways to do it.  One with 2 routers and 1 with 3 routers.  These can be simple commodity routers...... likely one is the ISP router
0
 
LVL 4

Expert Comment

by:duffme
ID: 36557570
+1 on each of the proposals above.  The only thing I would add is to think about your customer/guest/internet-only access.  If it will truly be public then be sure to configure the guest net outside of the firewall or as a DMZ segment; a device such as the sonicwall will generally have the firewall built in and allow for proper segmentation.  Otherwise you can configure basic security on the guest net to prevent strangers and risky traffic...
0
 

Author Closing Comment

by:CHIEF31
ID: 36557657
Thank you everyone for your help.  This should get me started.
0

Featured Post

Get your Disaster Recovery as a Service basics

Disaster Recovery as a Service is one go-to solution that revolutionizes DR planning. Implementing DRaaS could be an efficient process, easily accessible to non-DR experts. Learn about monitoring, testing, executing failovers and failbacks to ensure a "healthy" DR environment.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This paper addresses the security of Sennheiser DECT Contact Center and Office (CC&O) headsets. It describes the DECT security chain comprised of “Pairing”, “Per Call Authentication” and “Encryption”, which are all part of the standard DECT protocol.
What monsters are hiding in your child's room? In this article I will share with you a tech horror story that could happen to anyone, along with some tips on how you can prevent it from happening to you.
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question