webby74 Posted April 1, 2011 Posted April 1, 2011 Right, I maybe putting two much thought into this but having trouble making sense.... To explain... We have recently installed a secondary internet connection in our office. We have our internet provided by the local authority but when it comes to looking for software, drivers, resources etc everything is blocked. So after much complaining to SMT we've got a standard broadband connection with a Belkin router just for IT Support. Now since then I've got to thinking it would be handy if we could access this internet connection when I take my macbook around the school. Now to do this is as simple as turning of DHCP on the Belkin router, adding the router via ethernet to the network and pointing devices to this router for internet access? Would this work and would I be able to use our school wireless to connect to the new internet connection? At first I thought it would be simple, but can't seem to get it straight in my head. I would be grateful for advice. Andrew
GrumbleDook Posted April 1, 2011 Posted April 1, 2011 One of the things to be careful over is that you are likely to find that it is in the ToS of the LA connection that you cannot have 2 feeds running on the network at the same time. The main reason for this is not about LA control, but a term of the connections many LAs and RBCs have with JA.NET ... if people do have 2 lines then it is usually in a fail-over mode ... the LA line runs until it fails and then the network fails over to the other line (a number of firewall appliances will manage this for you, including Cisco and Watchguard kit). To have 2 separate and concurrent connections, used for different services, then you are looking at the use of firewalls and VLANs to segregate traffic. It can be done and keep everyone happy, but it is chunk of work. I do know a few places who have done this, but they had the in-house expertise to do it ... and enough money for the extra / upgraded hardware too. If you do go ahead with it I would be interested to see any documentation ... I know a few academies who are moving away from RBCs and are looking at getting multiple lines in from different providers for different tasks. One of the things stopping them is the pain to configure their LAN.
budgester Posted April 1, 2011 Posted April 1, 2011 Depends how you network is set up. But couldn't you just use a different default gateway for your laptop ? I.e Rest of the school default gateway = LEA Broadband Router IP settings Allocated by DHCP. You laptop default gateway = belkin router. IP static and manually entered into your laptop.
FN-GM Posted April 1, 2011 Posted April 1, 2011 I think the best way would be to setup a small proxy server on a pc. Have 2 network cards. One in the main school and the other in your belkin lan. Just point your machines to that proxy on your main lan that you want to use the outside line for. Z
dhicks Posted April 1, 2011 Posted April 1, 2011 Now to do this is as simple as turning of DHCP on the Belkin router, adding the router via ethernet to the network and pointing devices to this router for internet access? Would this work and would I be able to use our school wireless to connect to the new internet connection? Yes, it's that simple and yes, you should be able to connect via wireless. Remember to make sure you assign your router an internal address that your machines can see, i.e. something on the same subnet. Of course, anyone who found your second gateway could also point their browser at it, thus bypassing any filtering. You could, maybe, connect the unfiltered line directly to your desktop PC and remote in to your desktop from your laptop around the school or perhapse use a VPN connection between the two. If you do want to load-balance/failover between two lines then the ZeroShell router/firewall Linux distribution will do that for you for free, you'll just need to provide something with three network ports in. You would probably want some local filtering on your ADSL line, too, of course.
glennda Posted April 1, 2011 Posted April 1, 2011 We have it here - we have an old desktop sitting between the 2nd line and our network running squid and dansguardian - we then just set our proxy to that and it routes out through that router rather then our LEA line. We then have it so that only Me, my boss, and teh other tecs have access through it. (we added dansguardian for accountablity etc) 1
chinesewhispers Posted April 1, 2011 Posted April 1, 2011 Use an old box and put Smoothwall Express on it (Express Open Source Firewall Project). From memory: Secondary Internet (ADSL) -> Belkin (you could leave DHCP on as it will NOT connect directly to your network, otherwise you need to set your red IP to one in the same subnet as the Belkin LAN IP) -> Red connection on Smoothwhall | Green connection on Smoothwall -> network. Go for a closed setup, then open the ports outbound as you see fit. You can restrict the IP addresses that are allowed to use it (restrict it to those you will assign manually to your own machines), and on those machines, change your gateway to that green IP of the Smoothwall. You'll need to config your Belkin before wiring it like this as you won't have access easily after this wiring. Let me know if you need further info, or check the SWE community forums. (community.smoothwall.org • Index page) Mark 1
Mr.Ben Posted April 1, 2011 Posted April 1, 2011 I have a similar set up - we have a separate connection for our Cafe WiFi (The cafe is open to the public). I have set up the router with DCHP enabled, but I have separated traffic with a VLAN. As we have a managed Wireless network I am able to set up a new SSID and connect it only to the second VLAN.
webby74 Posted April 1, 2011 Author Posted April 1, 2011 Thanks for all your replies! Its now working. Spent the afternoon setting it up. As suggested above I disabled DHCP, connected it via ethernet network, and gave it a static IP. I've manually configured IT Support devices with static IPs and point them to the Belkin Router. I've tested it round the school and can successfully access everything on the network and connected to the unfiltered internet. It's always nice when you achieve something successfully, thanks guys
webby74 Posted April 1, 2011 Author Posted April 1, 2011 We have it here - we have an old desktop sitting between the 2nd line and our network running squid and dansguardian - we then just set our proxy to that and it routes out through that router rather then our LEA line. We then have it so that only Me, my boss, and teh other tecs have access through it. (we added dansguardian for accountablity etc) Interesting that you say you've done this. Can I ask what led you to this? Does it filter much if anything? Here its only myself and a part time tech who can access this connection. Cheers Andrew
GrumbleDook Posted April 1, 2011 Posted April 1, 2011 Interesting that you say you've done this. Can I ask what led you to this? Does it filter much if anything? Here its only myself and a part time tech who can access this connection. Cheers Andrew Except there is nothing to stop someone else with a laptop in the area using a well-known tool to see where your traffic is going, set up their own device with a static address on a LAN port and plug it into your network, getting unfiltered access to everything. They can spoof MAC address if you are using ACLs too.
dhicks Posted April 1, 2011 Posted April 1, 2011 getting unfiltered access to everything If it's the case that they want this connction to access specific sites they could just use Squid with a whitelist to let them through to the sites they want and nothing else.
glennda Posted April 1, 2011 Posted April 1, 2011 Except there is nothing to stop someone else with a laptop in the area using a well-known tool to see where your traffic is going, set up their own device with a static address on a LAN port and plug it into your network, getting unfiltered access to everything. They can spoof MAC address if you are using ACLs too. exactly that reason - somebody clever trying to get around our filters (although they can't change there proxy) and also incase somebody turns around and says they saw me on dodgy sites - i can then turn around and say look through the logs. just covering my own backside.
dhicks Posted April 1, 2011 Posted April 1, 2011 and also incase somebody turns around and says they saw me on dodgy sites - i can then turn around and say look through the logs. Spoof MAC address, obtain IP from DHCP, visit dodgy website, say "I saw Sir on dodgy website"...
glennda Posted April 1, 2011 Posted April 1, 2011 Spoof MAC address, obtain IP from DHCP, visit dodgy website, say "I saw Sir on dodgy website"... it only works from a set ip range and also it authenticates against ad so that it needs credentials aswell.
tom_newton Posted April 1, 2011 Posted April 1, 2011 Everyone who suggested some sort of access control device between your network and the open internet has the right sort of idea - accountability and authentication are key there.
dhicks Posted April 1, 2011 Posted April 1, 2011 it authenticates against ad so that it needs credentials aswell. Ah - solves that problem :-)
IanT Posted April 1, 2011 Posted April 1, 2011 I did this at my last place, we had LA Broadband and had a Be* Internet line dedicated for IT and other services, put a PIX firewall in and just pointed our default gateway on same subnet too it, boom! worked!
budgester Posted April 1, 2011 Posted April 1, 2011 Except there is nothing to stop someone else with a laptop in the area using a well-known tool to see where your traffic is going, set up their own device with a static address on a LAN port and plug it into your network, getting unfiltered access to everything. They can spoof MAC address if you are using ACLs too. Seriously in a secondary school,if someone.. A. has the time to do this B. has the skills to do this C. has the access to the network to do this D. Can be bothered to do this E. Manages to do this. Then... A. Why aren't they doing there own job ? B. Employ them as an IT tech pretty damn sharpish. C. There are probably more things to worry about on your network than unfiltered internet access. 1
glennda Posted April 1, 2011 Posted April 1, 2011 Its not the staff that we worry about - what if kids could get onto the internet unfiltered? also sorts of issues then arise.
budgester Posted April 1, 2011 Posted April 1, 2011 If the kids can run network sniffing software, change network settings and spoof macs on normal classroom PC's I'd still say you have bigger problems than unfiltered internet access. And if the kids are bringing there own laptops in, then the chances are they probably have a smart phone or mobile dongle, that will give them unfiltered internet access anyway.
climo Posted April 1, 2011 Posted April 1, 2011 Do you use a proxy server for your LEA link? Set up another proxy server on an old PC using something free like smoothwall express. connect 'external' ethernet to the unfiltered router and give it an IP in the same range. Connect 'internal' ethernet to school's lan, with an internal range IP address. Simply change your proxy server to the smoothwall when needing unfiltered access. In my school staff/students all use IE and have 'disable changing proxy settings' set up in Group Policy but I don't
glennda Posted April 2, 2011 Posted April 2, 2011 If the kids can run network sniffing software, change network settings and spoof macs on normal classroom PC's I'd still say you have bigger problems than unfiltered internet access. And if the kids are bringing there own laptops in, then the chances are they probably have a smart phone or mobile dongle, that will give them unfiltered internet access anyway. in my case it's not to block the kids but to protect myself against allegations of wrong doing by members of staff.
GrumbleDook Posted April 4, 2011 Posted April 4, 2011 If the kids can run network sniffing software, change network settings and spoof macs on normal classroom PC's I'd still say you have bigger problems than unfiltered internet access. And if the kids are bringing there own laptops in, then the chances are they probably have a smart phone or mobile dongle, that will give them unfiltered internet access anyway. Most of which now come with data quotas ... why use your own quota when you have another connection to leech from?
m8ttysmith Posted April 4, 2011 Posted April 4, 2011 Thanks for all your replies! Its now working. Spent the afternoon setting it up. As suggested above I disabled DHCP, connected it via ethernet network, and gave it a static IP. I've manually configured IT Support devices with static IPs and point them to the Belkin Router. I've tested it round the school and can successfully access everything on the network and connected to the unfiltered internet. It's always nice when you achieve something successfully, thanks guys So now you have got it working will you be mentioning it to your LA who have the other connection coming in. I use to work for a LA and if a school was attatching a secondary connection A) not on the LA network and B) was unmanaged by the LA we would instantly disconnect them. Alot of LA's have to sign upto Government Connect which means they have to have full management and visability of what is going on, on there network. So by adding a connection yourself you are potentially putting the whole LA at risk.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now