Hotspot Blended Into Private Work Lan Environment

  • I do not see a search function for the forums so I’m just going to ask with a new topic.

    I have a client who wishes to provide a hotspot to customers over their existing DSL connection. What I want to do is create a DMZ zone where all the business computers/servers will be behind our firewall. So I would end up with the following scenario.

    -DSL Modem WAN side Public IP address

    -DSL Modem LAN side private IP 10.0.0.1

    -Modem luckily has a 4 port switch on the back so one port to my firewall which NATs the 10.0.0.2 address into 192.168.x.x for the network behind the firewall

    -Another port from the DSL Modem would go directly to the new wireless router.

    -Public wireless router WAN IP 10.0.0.3

    -Public wireless router LAN IP (NAT) 192.168.100.1

    So a few questions.

    #1 – is the above layout going to be okay??

    #2 – Could I simplify the Public Wireless router setup by just configuring it as an AP rather than a router? Does DD-WRT allow this configuration while still supporting HotSpot?? Seems like that would ease a hop to the internet and might make it easier to add future APs.

    #3 – If I was thinking of multiple APs should I consider Open Mesh vs. DDWRT??

    #4 – Should I create a specific firewall rule to flat out block everything from the Public Wireless Router IP range to be extra sure some high school kids don’t start pounding my firewall trying to get through??

    Thanks in advance for your input and suggestions.

    SP

    The topology you described indicates the new wireless router (I guess this is the one that will run the hotspot) is connected directly to the modem. “Another port from the DSL Modem would go directly to the new wireless router.” In that case I don’t understand what you mean by “Public wireless router LAN IP” is NATed to 192.168.100.1? I understand the firewall would do the NATing, not the modem? In either case, the hotspot should still work fine as long as it gets internet. If you place the router behind the firewall you would need to open the folowing ports, as per this article: http://hotspotsystem.com/deskpro/kb_article.php?ref=3580-WCBN-3010

    2 The router needs to be in AP mode for the hotspot to function, don’t use repeater mode, and don’t plug any repeaters behind the router as the hotspot won’t work properly!

    3 You should consider the differences between the two firmwares. DDwrt gives you more management options, while open mesh gives you cloudtrax, an easy to use, but restricted web based interface. Open mesh is easier to install then ddwrt, and there is a strict method to configuring the routers when used in a chain, especially with WDS.

    4 By design firewalls block incoming connection from the public interface, unless it is traffic in response to a connection that was initiated from the secure network. See context based access control: http://en.wikipedia.org/wiki/Context-based_access_control

    I guess it ends up being 3 NAT ranges total but what you said makes sense. I don’t think I described it enough, but in my head it makes sense. 😉

    In essence though I would have a 10.x.x.x network around the DSL modem, a 192.168.100.x network for behind the HotSpot and a 192.168.50.x network behind my firewall for the office equipment. However reading your comment makes me think that the 192.168.100.x network won’t be necessary with the wireless in AP mode. That would put the Hotspot connected devices into the 10.x.x.x network which ultimately should be fine as long as I have some separation in the DMZ.

    I am way more familiar with DDWRT so I think I will stick with that. I believe DDWRT supports WDS but I think for now we are focused on just having one AP in main hall of the facility. It we feel like it is warranted we may add a 2nd AP over our outdoor pool in the future. I don’t want anyone using this AP to access our business network so I will just avoid the firewall port issue but that is good to know for the future.

    I am going to work this up and give it a shot. Thanks.

    On a side note. I like the DDWRT enabled Buffalo wireless routers. Should I consider one that supports the HotSpotWRT firmware?? Obviously all the DDWRT enabled models have the HotSpot feature built in. I just checked my home router and even my WZR-HP-G300NH has it. What are the pros/cons of the HotspotWRT??

    HotspotWRT is based on Coova. It has about half the features that ddwrt has, but a major advantage is that it supports mac authentication. However it does not have the ability to broadcast dual SSIDs like DDwrt. I invite you to flash one of your routers and discover the firmware.

0 0

You must be logged in to reply to this topic.