Networking Forums

Networking Forums > Network Hardware > Home Networking > Advise needed on adding wireless access

Reply
Thread Tools Display Modes

Advise needed on adding wireless access

 
 
newsbenny2@spampot.com
Guest
Posts: n/a

 
      04-06-2005, 08:29 AM
I currently have a fixed wired installation at home. The broadband
comes via a cable modem which is attached to a NAT router which then
carries connections to various rooms in the house. There are a couple
of Windows desktop machines and a Linux web/file/mail server connected
at all times. I've configured the NAT router so that only the web &
mailservers are open to the outside world.

The wife now wants WiFi - not just for ourselves, but to allow visitors
to surf on their own PCs.

Now, if I just attach a wireless access point to the NAT router, I'm
going to make all our internal windows/samba shares visible to any
attached computer, right? (The samba shares are all user/password
protected, the windows shares I'm not too sure about). Plus I don't
like the idea of our internal network traffic being potentially
sniffable.

But if I put another NAT router between the cable modem and the
existing NAT router, and attach the wireless access point to this (the
new NAT router) then I've screwed any chance of share access to our own
(non-visitor) wireless PCs.

So, what's the solution here? Do I need 2 wireless access points? One
for internal users and one for visitors? Or is there some fancy
technology to let me achieve what I want with just the one?

Thanks in advance for all advice.

Best regards, Ralph.

 
Reply With Quote
 
 
 
 
Conor Turton
Guest
Posts: n/a

 
      04-06-2005, 09:14 AM
In article <(E-Mail Removed) .com>,
says...

> Now, if I just attach a wireless access point to the NAT router, I'm
> going to make all our internal windows/samba shares visible to any
> attached computer, right? (The samba shares are all user/password
> protected, the windows shares I'm not too sure about). Plus I don't
> like the idea of our internal network traffic being potentially
> sniffable.
>
> But if I put another NAT router between the cable modem and the
> existing NAT router, and attach the wireless access point to this (the
> new NAT router) then I've screwed any chance of share access to our own
> (non-visitor) wireless PCs.
>
> So, what's the solution here? Do I need 2 wireless access points? One
> for internal users and one for visitors? Or is there some fancy
> technology to let me achieve what I want with just the one?
>
> Thanks in advance for all advice.


THe "double NAT" way is frought with problems. Change your router for
something like a F5D7230-4 Belkin Wireless Router with 4 LAN ports. The
Belkin router allows you to set access/deny by IP address for all
services individually.

Mine does it on:

WWW HTTP, TCP Port 80, 3128, 8000, 8080, 8001
E-mail Sending SMTP, TCP Port 25
News Forums NNTP, TCP Port 119
E-mail Receiving POP3, TCP Port 110
Secure HTTP HTTPS, TCP Port 443
File Transfer FTP, TCP Port 21
MSN Messenger TCP Port 1863
Telnet Service TCP Port 23
AIM AOL Instant Messenger, TCP Port 5190
NetMeeting H.323, TCP Port 1720
DNS UDP Port 53
SNMP UDP Port 161, 162
VPN-PPTP TCP Port 1723
VPN-L2TP UDP Port 1701
TCP All TCP Port
UDP All UDP Port

...as well as user defined ports.

--
Conor

Windows & Outlook/OE in particular, shipped with settings making them
as open to entry as a starlet in a porno. Steve B
 
Reply With Quote
 
NBT
Guest
Posts: n/a

 
      04-06-2005, 02:03 PM
(E-Mail Removed) wrote:
> I currently have a fixed wired installation at home. The broadband
> comes via a cable modem which is attached to a NAT router which then
> carries connections to various rooms in the house. There are a couple
> of Windows desktop machines and a Linux web/file/mail server connected
> at all times. I've configured the NAT router so that only the web &
> mailservers are open to the outside world.
>
> The wife now wants WiFi - not just for ourselves, but to allow visitors
> to surf on their own PCs.
>
> Now, if I just attach a wireless access point to the NAT router, I'm
> going to make all our internal windows/samba shares visible to any
> attached computer, right? (The samba shares are all user/password
> protected, the windows shares I'm not too sure about). Plus I don't
> like the idea of our internal network traffic being potentially
> sniffable.
>
> But if I put another NAT router between the cable modem and the
> existing NAT router, and attach the wireless access point to this (the
> new NAT router) then I've screwed any chance of share access to our own
> (non-visitor) wireless PCs.
>
> So, what's the solution here? Do I need 2 wireless access points? One
> for internal users and one for visitors? Or is there some fancy
> technology to let me achieve what I want with just the one?
>
> Thanks in advance for all advice.
>
> Best regards, Ralph.
>

1 WAP
1 Router
Give all home users Static IP's, allow DHCP for visitors over small IP
range.
S/ware firewalls on all Home machines with home users in a "Trusted"
zone which allows sharing and all other IP's in a "Blocked" zone.
Make sure wireless system is encrypted and "Key" is changed frequently
(bear in mind that visitors allowed to use your network will have it's
details stored on their machines when they leave)
Make sure all "Shares" are password protected.

NBT
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
(RD) Expert advise needed Den Windows Networking 2 02-28-2007 06:40 AM
Help Please - Legal advise needed. ISP in breach of contract & wondering how to pursue. WillC Broadband 15 09-27-2006 06:19 AM
Wireless Network help/advise needed please pafos Wireless Networks 1 01-21-2006 04:30 PM
Setting Up A Basic WLAN - Help/Advise Needed... Steven Wireless Internet 2 09-06-2004 01:46 AM
Advise on adding wireless to home LAN Kev Wireless Internet 5 04-28-2004 07:43 AM



1 2 3 4 5 6 7 8 9 10 11