• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Wireless untrusted access point on a trusted wired network...

harrkev

Senior member
I was hoping that somebody could give me some help here...

Here is my setup... I have a wired network of trusted machines and trusted users in one group. I want to add a wireless access point, but this wireless access point should ONLY have access to the internet, and NOT to my network shares (files, printers, etc.).

Here is what I have available:

[*]XP-Pro machine sharing a printer, and serving as a terminal server (using a hack). Also runs Ubuntu.
[*]Win 98SE machine.
[*]Network Storage Box (D-Link DSM-G600)
[*]Linksys BEFSR41 router
[*]Linksys BEFSX41 router (not currently being used)
[*]Linksys WAP11 access point.

I can think of two approaches:

APPROACH ONE
Somehow allow the WAP11 to connect ONLY to the internet. I cannot for the life of me figure out how to do this. I suppose that I could daisy-chain both of my routers together in order to accomplish this, but that seems rather crude.

APPROACH TWO
The other way is to simply harden the wired network. But this presents some problems. My wired network is trusted. Only my wife and myself have access. As a result, we use weak passwords. We do this because my wife would STRONGLY resist having to use a strong password. I can easily beef up sercurity on my NAS box by choosing a strong password. I can set the firewall on the XP machine to allow terminal server access to only the 98 machine. But I am not sure how to restrict the sharing of the printer. So, if I go for approach two, here is the key question:

Using XP-Pro, how can I have administrator accounts with weak passwords, yet only share files and printers using strong passwords?

** Edit **
What I would LIKE to do is to add a new user called "Remote" or something, and give it a strong password. Then, set up printer sharing to work ONLY through the "Remote" name/password. However, that would require mucking around with security policies, which might easily brick my XP install. So, I would need moron-proof step-by-step instructions.
** End Edit **

Older version of Windows used to have an option to have individual passwords on shares, but XP seems to only allow shares using user account username/passwords.

Any ideas?

 
Two Routers Crude? I do not know what is crude about it, 2 pieces, 3 pieces, it is all Blue plastic anyway.

However segregation is the best and the smoothest for the Network.

One Router goes to the modem, and the WAP is plug into it. The second Router is connected through the Wan into a regular port o the first Router. The wired to be ultra safe computers are connected to the second Router.

Here how, Network Segregation - Adding security to Wireless Network (or to any peer to peer Network).

:sun:
 
Well, I was hoping to be able to not have two boxes, two power supplies, etc.

But if that is the best way, then that is what I will do.

PS: Thanks for the link.
 
I like that option. The only problem is getting my NAS box to understand NetBEUI. Oh well.

Well, I guess that I will go the "two router" path.

Unless -- anybody knows of some cheap (around $50 or so) hardware that can support VLAN out of the box. I understand that custom firmware can do this for the Linksys WRT54G, although it is not exactly user-friendly to set up.
 
Can you configure a wireless router to have a DMZ type thing so the connections from it only go back out and don't cross over into the other zone that would have the wired connections?

Just another idea.
 
This is possible on Cisco 1200 series ap's, but you probably don't want to invest in what's required to set that up.
 
Back
Top