djones Posted May 31, 2010 Posted May 31, 2010 The requirements: House with ajoining holiday let; Currently with dial-up access but new ADSL line now going in; Owners want wifi access for their two laptops in and around property in addition to wired access for one desktop; Wifi access to be provided for guest use in and around property but separated from accessing owner's private network; In past days I have done similar by using IPCOP to separate the networks, each with their own wifi AP with different SSIDs, and have the IPCOP going out to a single router/modem. However, I'd rather stick with a single, small, appliance type solution if possible. They need to buy a router/modem anyway for the new ADSL line so I was looking at the Netgear DGN2000 as it has the ability to set multiple SSIDs but I'm not sure if this then separates them into VLANs - if not, I can't see the point of multiple SSIDs unless you have devices that can't use higher security methods. What would you do to achieve the required result?
OllieC Posted May 31, 2010 Posted May 31, 2010 I'd recommend grabbing a router that can run DD-WRT (Linksys WRT54 series ftw). In the past I've had my main SSID (WPA2) and then a second with WEP for my sister's DS, this was on a different VLAN and could only access the internet and had MAC filtering. Take a look at this Multiple BSSIDs with DD-WRT - Interactive HowTo Slightly different/less comprehensive from the official DD-WRT site VLAN Detached Networks each with Wireless and Internet - DD-WRT Wiki It can probably be done with Tomato firmware as well although I wouldn't know where to start with that.
djones Posted June 3, 2010 Author Posted June 3, 2010 I've not had a good track record with Linksys equipment (probably just unlucky) but could be persuaded to look again. I would also prefer to go with a solution that had 802.11n and gigabit ports built in too.
kmount Posted June 3, 2010 Posted June 3, 2010 I think you'll struggle finding a cheap gigabit adsl all in one router. My advice would be to echo the DD-WRT suggestion (recently done this myself) and if you need gigabit (why if there's only 1 hard wired PC?) put a switch in behind the router to provide this. 1
OllieC Posted June 3, 2010 Posted June 3, 2010 Linksys WRT320N Wireless-N Dual-band Gigabit Router - Ebuyer That'll run DD-WRT, 802.11n and gigabit. You can use any old ADSL router as the modem... the DD-WRT router will deal with the connection, as in, the connection settings will go into the router rather than the modem. 2
djones Posted June 3, 2010 Author Posted June 3, 2010 (edited) OK, changing the plan slightly... The areas that guests and owners will need to pick up a WiFi signal are physically separate so I will probably need to put in a separate AP for guest access. How would this change opinions? Are there any modem/routers that are able to firewall off specific LAN ports? ... if you need gigabit (why if there's only 1 hard wired PC?) ... One desktop PC but potentially network attached CCTV (in some guise) in the near-ish future. However, this will probably end up needing a separate switch anyway! Edited June 3, 2010 by djones
Geoff Posted June 3, 2010 Posted June 3, 2010 Anything running DD-WRT understands what VLANs are. Just do it that way. 1
OllieC Posted June 3, 2010 Posted June 3, 2010 Anything running DD-WRT understands what VLANs are. Just do it that way. I was going to mention DD-WRT again but didn't want to sound like I was going on about it, haha. DD-WRT is the ultimate geek home networking toy. I'd hate to not have it. 1
djones Posted June 4, 2010 Author Posted June 4, 2010 Ok, Ok - you've sold me on Linksys and DD-WRT! How about this then: ADSL -> old Netgear DG834G router (with WiFi disabled) -> WRT320N with DD-WRT (in main house for owners WiFi and wired devices) -> WAP610N (or other similar/suitable AP in holiday let for guest access). Guest access on different SSID and using DD-WRT to route, on separate VLAN, directly to the internet bypassing owner's LAN. How does that sound? Just another thought - if any IP cameras were plugged diretly into the LAN ports of the DG834, would they be viewable internally on the owner's LAN? Thanks for sticking with me on this one!
Geoff Posted June 8, 2010 Posted June 8, 2010 Your above plan looks sound. As for the IP Cameras, put them on a separate VLAN and IP range and use the DG834G to setup a static route between that VLAN/IP range and the Owners VLAN/IP Range. Keeps everything neat. 1
pwds Posted June 8, 2010 Posted June 8, 2010 I just bought a Netgear DGN3300 router with 802.11N and it does prevent traffic from the "guest" networks (you can have two- one b/g and one n) from pinging or connecting to traffic on the wired or wireless restricted networks. There are different DHCP servers for each SSID but I haven't actually tested if traffic is VLANed by the router or if it's the VLAN on the ProSafe switch that sits behind it that keeps them from accessing my wired equipment. I'll test changing the subnets on a guest and trusted wireless laptop this evening and see if I can ping or connect in either direction to see if this is VLAN security or just using different subnets. As far as I can tell though, the guest network heads straight out to the internet with no LAN access. 1
djones Posted August 7, 2010 Author Posted August 7, 2010 @pwds: Did you discover anything definitive?
djones Posted October 27, 2010 Author Posted October 27, 2010 (edited) Your above plan looks sound. As for the IP Cameras, put them on a separate VLAN and IP range and use the DG834G to setup a static route between that VLAN/IP range and the Owners VLAN/IP Range. Keeps everything neat. I have setup DD-WRT on the WRT320N connected to the dg834g (in modem only mode). DD-WRT successfully passes on the login details and the DG834G connects. However, as PPPoE (which is what I have setup to pass login details) has a maximum MTU of 1492 and XP/7 use a default of 1500, I have run into issues whilst browsing some sites (usually larger domains or those using https). It had me stumped for ages! As soon as I changed the MTU in XP/7 everything worked smoothly. I have the guest WiFi setup correctly and clients connected to that on their own dedicated VLAN etc, etc. as intended however, they will also need to have the MTU settings changed which is not an acceptable solution in this case. Therefore, is there another way of connecting the DG834G and DD-WRT that will enable me to have the DG834G connect on its own and then route everything to DD-WRT (thus avoiding the need to alter MTU values) which will then do the necessary in terms of VLANs, DHCP, etc for the connected LAN clients? Edited October 27, 2010 by djones
Geoff Posted October 28, 2010 Posted October 28, 2010 Use DHCP option 26 to inform your clients of the non-default MTU required to use your network. 2
mac_shinobi Posted October 28, 2010 Posted October 28, 2010 Will get shot down in flames no doubt for this but what about the apple airport extreme base station Apple - AirPort Extreme - Features - 802.11n Wi-Fi Not sure how it does the wireless with ref to using a VLAN or what exactly but you enable the guest account and it seperates your main wifi network from the guest one.
drevil Posted October 28, 2010 Posted October 28, 2010 The requirements: House with ajoining holiday let; Currently with dial-up access but new ADSL line now going in; Owners want wifi access for their two laptops in and around property in addition to wired access for one desktop; Wifi access to be provided for guest use in and around property but separated from accessing owner's private network; In past days I have done similar by using IPCOP to separate the networks, each with their own wifi AP with different SSIDs, and have the IPCOP going out to a single router/modem. However, I'd rather stick with a single, small, appliance type solution if possible. They need to buy a router/modem anyway for the new ADSL line so I was looking at the Netgear DGN2000 as it has the ability to set multiple SSIDs but I'm not sure if this then separates them into VLANs - if not, I can't see the point of multiple SSIDs unless you have devices that can't use higher security methods. What would you do to achieve the required result? How about a Draytek Vigor 2820Vn? You can have 4 SSIDs with differing levels of encryption and each wireless network can be throttled up and downstream. It's a bit pricey but will do the job well and you can lots more with it if you want to.
djones Posted October 28, 2010 Author Posted October 28, 2010 Use DHCP option 26 to inform your clients of the non-default MTU required to use your network. Thanks, I didn't know you could do that!
djones Posted October 28, 2010 Author Posted October 28, 2010 How about a Draytek Vigor 2820Vn? You can have 4 SSIDs with differing levels of encryption and each wireless network can be throttled up and downstream. It's a bit pricey but will do the job well and you can lots more with it if you want to. Unfortunately, the guest WiFi needs to be provided via an additional Access Point so using the one wireless router and having multiple SSIDs is not going to work as the range just isn't enough. That's why I need to implement something that can VLAN certain ports in order to plug an AP into it.
djones Posted October 28, 2010 Author Posted October 28, 2010 Ok, this is where I'm upto... Unfortunately, connecting using PPPoE from DD-WRT (on the WRT320N) via the DG834G (in modem only mode) presented another problem. The ISP requires PPPoA and using PPPoE instead, causes the connection speed to be throttled drastically (10Mbps down to 1Mbps). Therefore, I have reverted the DG834G to normal (modem & router) mode and used this to handle the ADSL connection via PPPoA. The DG834G has an internal IP of 192.168.0.1, NAT and DHCP enabled. The WRT320N is connected to the DG834G via its WAN port and gets a WAN IP address of 192.168.0.2 via DHCP. Its internal IP address is still 192.168.1.1 as default. The WRT320N then hands out IP addresses via DHCP in the 192.168.1.0 range. There is also an additional VLAN setup with its own DHCP handing out addresses in the 192.168.3.0 range via a Wireless Access Point plugged into port 4 of the WRT320N. This all seems to work fine: no need to change default MTU values on clients; guests (clients on 192.168.3.0 subnet) cannot access PCs/resources on main 192.168.1.0 subnet; all clients (regardless of subnet) have full internet access at the correct speed; However, guests (192.168.3.0 subnet) can access both routers' webadmin GUIs and presumably (although I haven't tested it) anything plugged into the DG834G's remaining ports (192.168.0.0 subnet). Is there a way of preventing this? Something along the lines of dropping requests to 192.168.0.1 (or the entire 192.168.0.0 subnet) and 192.168.1.1 if they originate from anything on the 192.168.3.0 subnet. Is this possible? And finally, can anyone foresee any issues with this setup? Double NAT (although I confess to not really understanding if this even happens and whether it is bad if it does!)?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now