msch-prv@bluewin.ch hath wroth:
>Hi, is it possible to create distinct networks (2..3) using a single
>router and IP connection?
Yes, but don't bother. You have bigger problems.
>We currenty have a wireless LAN working and plan on renting some rooms
>to students who want to hook up to the web. Because the foreseeable
>stay will be short, we do not want to add an additional ADSL line.
>
>To preserve security, I thought of adding dedicated LAN networks and
>assign them to each student. Would that work? Is there a simple
>work-around?
>
>TIA for any suggestions, Mark
This is a very common problem that has been solved many time by
everything from coffee shop wireless networks to schools. The basic
problem is that 802.11 wireless is bridging, not routeing. Therefore,
the wireless really knows nothing about IP addresses and dividing a
network by subnets. It can divide a network using VLAN's, but that
becomes an administrative problem.
The basic requirement is to isolate each connection. It's sometimes
called "AP isolation" or more correctly "client isolation". This
prevents any packets from going between clients. Everything goes to
or from the internet.
The way the local college does it may be a bit of overkill.
http://resnet.ucsc.edu
Users are assigned an IP address via a DHCP server. The MAC address
of their router or PC/Mac is stored in a RADIUS authentication
database. Individual users must also authenticate with the RADIUS
server to get past the router. Most residents have cheap routers,
with the MAC address of the router setup as registered hardware. They
can do whatever they want behind their own router.
I'm not sure what you mean by a "short stay". If that's only a few
days, then I would look into a commercial (or home made) wireless
hotspot system.
http://wireless.wikia.com/wiki/Wi-Fi...etup_a_hotspot
If it's more like several months of the skool year, then something
more like the previously mentioned university system would be more
appropriate.
--
Jeff Liebermann
jeffl@comix.santa-cruz.ca.us
150 Felker St #D
http://www.LearnByDestroying.com
Santa Cruz CA 95060
http://802.11junk.com
Skype: JeffLiebermann AE6KS 831-336-2558