Jump to content

bob_uk2k

Members
  • Posts

    10
  • Joined

Reputation

10 Good

1 Follower

About bob_uk2k

Personal Information

  • Biography
    6 Years engineer at Net-Ctrl deaing in Network Security
  • Occupation
    Senior Technical Engineer
  • Location
    Ipswich
  • X
  • Homepage
    http://www.robneeds.com

Employer (optional)

  • Company Represented
    Net-Ctrl Limited
  1. Hi Steve, That Cisco almost seems to be there for the sake of being there. I would suspect you can do all internal vlan routing within the HP chassis with IP routing enabled and assigning IP addresses to the vlans. I can only imagine the Juniper goes the to Cisco for a local breakout of another network is the Juniper has maybe an extra voip vlan or something like that on it otherwise it could probably plug direct. I generally have a gateway vlan on the core switch that the firewall nic plugs into and then I'd add a vlan interface on to the smoothwall that matches the boyd vlan id on the core switch so that it's only switched by the internal switching. Robert
  2. Hi, I agree with Boardguy, you will need a dns server those 2 other ssids that is a dedicated dns server which still gets answers from the internet on the client's behalf but has a local zone for your FDQN to force the client's lookup to get the response you want. Robert
  3. Hi, Usually upgrades are rock solid however as with any early release it's worth waiting. The 7.0 was pulled the other day due to an issue and a 7.0.1 was brought out. Also when going up to 7x there was a note about LDAP changes which I bypassed only to find I could no longer use ldap admins to get into the unit so I would suggest for 7x wait a little longer and make sure you have a local admin to fix issues once upgraded. Robert
  4. Hi, Palo Alto are advertising they can take care of this in PANOS 6: https://www.paloaltonetworks.com/documentation/60/pan-os/newfeaturesguide/content-inspection-features/url-filtering-translation-site-filtering-enhancement.html#45310 https://live.paloaltonetworks.com/docs/DOC-7281 It looks like you will also need to SSL decrypt as everyone's turning SSL on these days you've got to pull it apart to take a look inside. Robert
  5. Jose, Have you done away with the netgear and nortel at the office in question and placed just a Cisco in there? Robert
  6. Hi, You shouldn't need to specify the ZD in the access point, if it's a layer two network the access points will find the ZD without any further help. Rob
  7. Are all the access points on the same layer 2 network? What version of code are you now running? Can an access point ping the ZD IP address? Do the access points get an IP from dhcp or are they staticly applied? Rob
  8. Hi Si, She's all over at as always. As I say you can run them all standalone but you do loose quite a lot of benefits of the central controller as you would with any non domestic wireless solution that has "fat" access points. The controller is there in all of them for a good reason. It's also uncommon in my experience to have anyone run more than one access point without a controller as what you save on the controller is lost on the administration overhead. Rob
  9. Hi Si, They work just as well as standalone APs, you get all the internal technology and if you had just one it wouldn't make a lot of sense to have a controller however if you go 3 -4 access point you really need to have a controller in the middle who will manage the access points, control users centrally report to you. If access points operate on their own they don't know about each other only that there is another guy on the same ssid. You won't have any challenging of users on the network by 802.1x, captive portal pages etc. Robert
  10. Hi Rich, Robert from Net-Ctrl here. The Ruckus is very easy to setup. The Zone Director (ZD) which is the brains behind it all needs a static IP so you know where to find it with your web browser then all the access points should be left to get an IP from DHCP, they will find their own way back to the ZD. The ZD will give the access points the config you setup in the ZD and the firmware they need also. In the ZD you can setup one SSID or more which can let people on the network directly or challenge them with various methods to find out who they are all of which is fairly stright forward to do. Most people are very happy to see how good the start up wizard is on the ZD and once that's done the rest sorts it's self. Robert
×
×
  • Create New...