Solved

How to segment all wireless traffic

Posted on 2014-10-09
12
179 Views
Last Modified: 2014-11-03
We have a wireless access point that is in our network and is dishing out 192.0.0.0 addresses to any wireless device attached to it. The only issue is that one can access our 10.0.0.0 domain network.
We want all traffic that rides on the wireless to only be for internet access only.

What do we have to do? Do we have to do NATing of some sort to make sure that nothing on the 10.0.0.0 scheme is accessible?
0
Comment
Question by:Robert Mohr
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 4
12 Comments
 
LVL 24

Expert Comment

by:DMTechGrooup
ID: 40371909
All depends how you have it connected.  If you have a smart switch you could use VLans.  If it is connected to a firewall as the default gateway and the firewall is high end enough you could deny a route from one subnet to the other.  Or you could use a switch and split the internet before it goes into firewall and have two separate networks.

Would need more information on how you have the entire thing connected.  Equipment, etc.
0
 

Author Comment

by:Robert Mohr
ID: 40373117
My wireless device connects to Port 2 on the switch.
Could I create a VLAN on Port 2 only and then in the wireless device point to that VLAN?

If this is the right way to do it, then I could need to know how to create this VLAN within the switch.
0
 

Author Comment

by:Robert Mohr
ID: 40373166
Any thoughts on how to create a VLAN on a SMC6750L2 TigerSwitch using the web interface on a single port during production hours?  I think if I can accomplish this then the wireless access point will be simple.
0
Surfing Is Meant To Be Done Outdoors

Featuring its rugged IP67 compliant exterior and delivering broad, fast, and reliable Wi-Fi coverage, the AP322 is the ideal solution for the outdoors. Manage this AP with either a Firebox as a gateway controller, or with the Wi-Fi Cloud for an expanded set of management features

 
LVL 24

Expert Comment

by:DMTechGrooup
ID: 40373493
What type of firewall are you using? make/model
0
 

Author Comment

by:Robert Mohr
ID: 40373793
Why do you need the firewall?
Shouldn't the switch and wireless be the only things that need to be configured?
0
 
LVL 24

Expert Comment

by:DMTechGrooup
ID: 40373881
Something has to do your routing
0
 

Author Comment

by:Robert Mohr
ID: 40373953
Cisco 2900
0
 
LVL 24

Expert Comment

by:DMTechGrooup
ID: 40373969
I havent worked with your switches for this.  If it were me I would use the router and create an access list to deny subnet b access to subnet a type thing.
0
 

Author Comment

by:Robert Mohr
ID: 40374003
OK. Thank-you.
0
 
LVL 27

Expert Comment

by:Dr. Klahn
ID: 40374102
Build a DMZ.  Put the WAP in the DMZ.  Then put a second firewall in the DMZ, and run the 10.0 network behind the second firewall.  The WAP then cannot get through the second firewall into the 10.0 network.

If the installation in question is not large, the second firewall can be a consumer-grade product without wireless capability.  Or a wireless firewall with the WiFi turned off.

Schematically:  Internet modem connects to firewall 1.  Firewall 1 serves WAP and firewall 2.  Firewall 2 serves the 10.0 network.  The WAP is on the inside of firewall 1 and can get to the internet, but on the outside of firewall 2 and so cannot get to the 10.0 network.

Cost, around $30 if you use a consumer-grade firewall.
0
 

Accepted Solution

by:
Robert Mohr earned 0 total points
ID: 40410740
We ended up creating a completely different subnet altogether on one available interface and as long as the WAN had that gateway associated it didn't matter what IP the devices had on the wifi LAN side. It works great and all traffic is segregated.
0
 

Author Closing Comment

by:Robert Mohr
ID: 40419023
We went a different route
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

As companies replace their old PBX phone systems with Unified IP Communications, many are finding out that legacy applications such as fax do not work well with VoIP. Fortunately, Cloud Faxing provides a cost-effective alternative that works over an…
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
This Micro Tutorial will show you how to maximize your wireless card to its maximum capability. This will be demonstrated using Intel(R) Centrino(R) Wireless-N 2230 wireless card on Windows 8 operating system.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

761 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question