"Mike in Nebraska" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Hello again. This IS the same case I've been wrestling with for over a
> year. The diagram is found here:
> http://s323.photobucket.com/albums/n...elessSetup.jpg
The wireless devices need to be on different channels.
The firewalls are backwards. It needs to be:
LAN---[firewall]---Guest Network---[firewall]---<Internet>
Not....
Guest Network---[firewall]---LAN---[firewall]---<Internet>
I doubt I can help with this one. There are just way to many things that
you are doing that I would never do,...it does not matter if you
"can",...and it does not matter if the manufacture says "it can",...I would:
1. never use a "wireless router" in anything except its "normal" mode.
2. never use any AP as both a bridge and an AP at the same time.
3. I would never even use a "wireless router" in this case to begin with.
The "routers" are *Firewalls* and I would separate the job of Firewall from
the job of "wireless device" in this case.
What I would do:
Every device would have a clearly define "job". They would not wear
"mulitple hats"
1. Use two *wired* Firewalls "back-to-back". This creates a back-to-back
DMZ between the two Firewalls which would serve as the Guest network.
2. I would hang an AP on the DMZ (Guest) network for the guests to use.
This would only be available in or near the building it is physically in.
There is no "good" way to bridge this one over the campus unless you wanted
to bridge evey building *twice* (once for each network) or start mixing
VLANs into and already confusing situation.
3. The Main building's LAN would then be behind the second Firewall and
would still be *wired* at this point. Then I would hang separate APs and a
Bridge off of the LAN
4. I would use "real" wireless Bridges between the buildings to link them.
The LAN within each building would be *wired* downstream of the Bridge. I
would then hang and AP off of the building's wired LAN downstream of the
Bridge.
I believe this is the same description I recommended a year ago except that
I don't think there was a Guest Network at the time.
--
Phillip Windell
www.wandtv.com
The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------