NetStumbler.org Forums

Go Back   NetStumbler.org Forums > Newbie Lounge
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 09-28-2004   #1 (permalink)
purplemonkey
Registered Member
 
Join Date: Sep 2004
Posts: 1
Question New Wi-Fi install

Hi all,

Sorry to be a complete Newb to this, but then we all got to start somewhere right? Ok onto the real brain teaser question.

We have a LAN-WAN setup at our offices, this LAN-WAN has worldwide reach. We have a VPN dial in solution for all remote workers.
I have been asked to setup a wireless install for external visitors, and internal visitors. At the moment, we provide LAN cables which people can use to access out LAN. Any external visitors have to report to IT to have their laptop scanned before using, although there is no control over this!

I'm thinking of setting up an ADSL connection with wireless access points around the meeting rooms. To make it easy to use I'm not going to use any security, no WEP keys, no MAC address registering etc.

I would like to know if people have done this before, what problems did you encounter? We are a central London office, and I'm a bit worried about people out side the building using this Wi-Fi lan for there own ends. I don't want to use WEP due to the overheads in setting every visitor up with the key etc..

All being well with this ADSL seperate LAN install, I would like to setup a Wi-Fi hotspot in this office on the main LAN, but tied down with security, the thought being this would be for people here who are not visiting but are mobile.

Look forward to your thoughts.
Tim.
purplemonkey is offline   Reply With Quote
Old 09-28-2004   #2 (permalink)
Madhadder
General "Noob Basher"
 
Madhadder's Avatar
 
Join Date: Apr 2002
Location: Munich, Germany
Posts: 1,620
The only way (Correct way) to do this is with some enterprise class gear
such as the Cisco Aironet family.

1. Setup Wifi on your switchs/routers in it's own VLAN, seperate from your
internal Office stuff.
2. Setup an Aironet accesspoint and turn on WEP/LEAP etc. on the AP
3. Buy some Aironet Client PCMCIA cards for the IT Dept to hand out.
4. Lock access to the net to ONLY those cards that are authroized.

This way all "Visitors" must go to the IT Dept. to get the lappy scanned
and the PCMCIA cards/client installed...
__________________
Legends may sleep, but they never die!!!!
Madhadder is offline   Reply With Quote
Old 09-28-2004   #3 (permalink)
Thorn
Did you do the math?
 
Thorn's Avatar
 
Join Date: Apr 2002
Location: Villa Straylight
Posts: 10,084
Quote:
Originally Posted by purplemonkey
Hi all,

Sorry to be a complete Newb to this, but then we all got to start somewhere right? Ok onto the real brain teaser question.

We have a LAN-WAN setup at our offices, this LAN-WAN has worldwide reach. We have a VPN dial in solution for all remote workers.
I have been asked to setup a wireless install for external visitors, and internal visitors. At the moment, we provide LAN cables which people can use to access out LAN. Any external visitors have to report to IT to have their laptop scanned before using, although there is no control over this!

I'm thinking of setting up an ADSL connection with wireless access points around the meeting rooms. To make it easy to use I'm not going to use any security, no WEP keys, no MAC address registering etc.

I would like to know if people have done this before, what problems did you encounter? We are a central London office, and I'm a bit worried about people out side the building using this Wi-Fi lan for there own ends. I don't want to use WEP due to the overheads in setting every visitor up with the key etc..

All being well with this ADSL seperate LAN install, I would like to setup a Wi-Fi hotspot in this office on the main LAN, but tied down with security, the thought being this would be for people here who are not visiting but are mobile.

Look forward to your thoughts.
Tim.
Using a ASDL line for the visitor WLAN would be a very good idea. That keeps the system completely seperate, and there is no more chance of an attack to the main LAN than any other external attack. To prevent unauthorized people using it, you can do things such as a simple logon using a product like NoCat (nocat.net), and use correct AP placement and RF design to minimize the RF footprint outside the premises. Having some generic guest accounts on the authorization server would be easy, and could be changed as needed or on a rotating basis such as weekly, monthly, etc.

As far as the internal WLAN, you should NEVER place it on the same net as the LAN. It should be a separate network in and of itself. Mobile workers within the office should access the wired LAN via VPN as if they are external. The reason fo this is security. MAC filtering is trival to defeat (less than 1 minute) and WEP can de overcome with relative ease (depending on the WLAN's traffic levels). You should also consider using a product that will has a better encryption such as Funk Odyssey.
__________________
Thorn
"I'm The Doctor. I'm a Time Lord. I am from the planet Gallifrey in the constellation Kasterborous. I'm 903 years old and I am the man who is going to save your lives and all 6 billion people on the planet below... You got a problem with that?"
Thorn is offline   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Google
 
Web NetStumbler.org

All times are GMT -7. The time now is 07:11 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 ©2007, Crawlability, Inc.


All messages express the views of the author and are for entertainment purposes only. Netstumbler.org cannot be held responsible for the authenticity of the content or the actions of its members. By using this site and its services, you warrant that you will not post any messages that are discriminating, obscene, hateful, threatening, or otherwise violates any laws and you release Netstumbler.org from any future claims of any kind whatsoever including, but not limited to, addiction and loss of productivity. All forum messages, private messages and any other content are properties of Netstumbler.org. Even if publicly available, personal or copyrighted information are not to be posted without the consent of the owner. Distribution of licensed and copyrighted materials in any way not endorsed by the copyright owner is strictly prohibited. You may not use this site and its resources to spam other sites or individuals or perform any action that violates any law. Items sold or bought in the For Sale forum are sold as is and no warranty or insurance of any kind is provided. Netstumbler.org cannot be held responsible for the outcome of any transactions and no warranty of any kind is provided, either express or implied. Vulgar words are not allowed in the subject lines ; they may be used in the message body in any forum. The Administrator, Super Moderators and Moderators of Netstumbler.org have the right to remove, edit, move or close any thread for any reason and to reveal your identity and other known information in the event of a complaint or legal action arising from any message posted by you.