Navigation: Jump to content areas:


Pro Quality. Fan Perspective.
Login-facebook
Around SBN: This Week In GIFs

Wifi Tech Doc

i'm going to go ahead and build out the guest network at the IP level and the VLAN9 level. try to work it all the way through to the outside. Will NAT some 192.168.9.0. so, eth2 on the PIX is now tagged VLAN9, but I realize I cant be putting it on the same 192.168.9.0 segment. so now I'm making it be on the same class C that the internal managment i/f is on. but a different subnet. so: 192.168.32.97/255.255.255.252 for a branch switch, router interface: (i.e. mo-3524,fa0/24) switchport mode trunk switchport trunk encapsulation dot1q switchport trunk allowed vlan all dhcp out some 192.168.xx.0 addresses on vlan 9 2620 int fa0/0.9 192.168.xx.1 encapsulation dot1q 9 in the PIX, add a route for the branch's guest network c:\usr\doc\WIFI-vlan-moving-into-production.vsd SC-AP1 vlan 1 native [infrastructure, (not used in SSID)] vlan 2 .57 [SSID=sainthelens, staff, DHCP from SPRUCE] vlan 3 198.207.188 [SSID=handheld, DHCP from somewhere?] vlan 9 192.168.57 [SSID=guest, DHCP from sc-72] with a new web-filter access rule in the pix, directing all port 80 traffic at the websense filter, now the 192.167.57 network should be completely web filtered. some things to fix remain: -- protecting our own general network from the guest laptops. -- VLAN9 interface for the PIX -- also access rules in the PIX to prevent any access to our internal hosts, except public ones -- allowing for other protocols to be used on the guest vlan -- https -- possible other web ports, i.e. 8080 -- anything else we want to offer by policy? SMTP,POP,chats etc, VPN, FTP, ssh alright. guest shouldn't need any EAP/PEAP TLS TKS stuff. but we're going to use IAS/radius. probably have to The default channel setting for the wireless device radios is least congested; at startup, the wireless device scans for and selects the least-congested channel. For most consistent performance after a site survey, however, we recomend that you assign a static channel setting for each access point. The channel settings on the wireless device correspond to the frequencies available in your regulatory domain. See Appendix A, "Channels and Antenna Settings," for the frequencies allowed in your domain. http://www.cisco.com/en/US/products/hw/wireless/ps4570/products_configuration_guide_chapter09186a0080341d17.html "If you are using the 802.1x supplicant provided by Microsoft, the idle time out will be longer than the settings in RADIUS/AP and DSA- 3100. Except for the idle timer, there is no way for the user to logoff from 802.1x Access Point in the current 802.1x implementation by Microsoft." -- Dlink DSA3100 manual

Do you like this story?


User Tools

Welcome to the SB Nation blog devoted to all things Phoenix Suns.

FanPosts

Community blog posts and discussion.

Recommended FanPosts

417645_122115147913687_122115027913699_63363_1431084468_n_small
Phoenix Suns Jerseys

Recent FanPosts

Beardson_small
Knicks fan totally looking to poach free agents from your team
L_small
How to win a championship...
Phxchip_small
More 2012-2013 Ideas: Power Forward Spot
Small
What kind of one-sided trade can you envision?
Phxchip_small
What Free Agents to Go After???
Cat-s_1__small
How was kobe not ejected after going for Faried's head?!?
Phxchip_small
Possible Plan to Help Thin Out Our Roster Needs
1300861821-62_small
Thank You BSOTS. Thank You Phoenix Suns.
Cat-s_1__small
The Quest for the Ring...

+ New FanPost All FanPosts >

Friend Us On Facebook

Follow us on Twitter

Follow BrightSideSun on Twitter

RSS Feeds

Bright Side Of The Sun Feeds


Managers

Seth_twitter_pic_4_small Seth Pollack

13531_1236944896270_1608674153_605227_1328752_n_small Wil Cantrell

Editors

Gortat_1_small East Bay Ray

Authors

Eutychus_logo_small Eutychus

1216horry-autosized258_small Alex Laugan

Photo_small 7footer