Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.internet.wireless
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 08-16-2007, 03:39 PM
barry@sme-online.com
Guest
 
Posts: n/a
Default Re: where to place AP on network

On Aug 15, 9:32 pm, Joe Mickelson <i...@not-here.com> wrote:
> Is it ok to put an access point behind a firewall as opposed to before
> it (on the outside)?
>
> If my users want to connect to the network, they have to authenticate
> and get authorization which I'm guessing a router would route the Auth
> & Auth requests to a Radius server on a dmz, but then it seems like
> they wouldn't have all the normal protection of entering through the
> firewall as a normal user would.
>
> So where should the wifi normally be on a small LAN, inside, or
> outside, DMZ of a LAN? Pros/cons?


Largely, it's a question of what you want to protect. A firewall
protects
your users' pcs from attacks from the outside, if properly configured,
notwithstanding attacks from compromised hosts inside. (Personal
firewalls are a Good Thing.)

Your local "normal" users should, in fact, be _behind_ the firewall,
to
provide max protection and control "bots" connectivity with outside.

An AP behind the firewall can be an entry path for intruders, unless
you secure it as you mention with WPA and in your case a Radius
server.

A major issue is what you wish wirelessly-connected users to be
able to access internally. E.g. having clients access windows
network shares via NAT router is a no-go in my experience with
two different NAT routers, wired and wireless. Unless maybe you
have them share the _same_ virtual lan. ("Wireless routers" are
typically AP, bridge, and router.)

What I mean by that is to not have the AP serve as a router for them
but as a connection to its bridged network ports. The AP would have
an IP in the same range as the servers, and issue IPs in that same
range via DHCP. The router's WAN port would be unused. Care
would be required in configuring AP's range of IPs to issue,
obviously among other IP parms.

Understanding IP is critical here

HTH,
J


Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Sound card crippled network, suggestions? sienk700@gmail.com alt.comp.hardware 4 08-06-2007 08:25 PM
HELP Regarding Network Design and Equipments udi alt.internet.wireless 1 07-29-2007 08:38 PM
wireless on the network bridge problem ivan.delic@gmail.com alt.internet.wireless 4 12-30-2006 09:46 PM
How to share wired Internet connection in hotel using two wireless PCs Cindy alt.internet.wireless 33 09-10-2006 03:52 AM
problem veiwing other computers in home network (wlan) Matija alt.internet.wireless 12 10-09-2005 10:13 PM


All times are GMT. The time now is 04:43 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45