Might not solve the Internet pipe issue but, how about shortening the lease 
duration, to knock off inactive devices quicker?

Regards,

Don Guyer
Catholic Health East - Information Technology
Enterprise Directory & Messaging Services
3805 West Chester Pike, Suite 100, Newtown Square, Pa  19073
email: [email protected]
Office:  610.550.3595 | Cell: 610.955.6528 | Fax: 610.271.9440
For immediate assistance, please open a Service Desk ticket or call the 
helpdesk @ 610-492-3839.



-----Original Message-----
From: Kurt Buff [mailto:[email protected]] 
Sent: Wednesday, February 06, 2013 2:36 PM
To: NT System Admin Issues
Subject: OT: Guest network security

All,

Quite some time ago, I set up an unsecured guest VLAN in our network, providing 
wireless access to all of the sundry devices that staff and visitors carry. I 
set up a small FreeBSD machine to serve IP addresses via DHCP, and that was 
dead simple.

It is a layer2 VLAN, traversing our backbone, and terminating on our corporate 
firewall.

However, there are now other tenants in our building, and the subnet is getting 
too much bandwidth and address consumption - the range I set up is completely 
filled, and the VLAN is consuming about half of our Internet pipe, which is far 
too much for my comfort.

I suspect the other tenants are leeching.

What I've read of captive portals seems to indicate that the portal is part of 
the firewall. I could be wrong about that, though. Regardless, the corporate 
firewall will not be allowed to be part of this solution.

The only other alternative I see right now is to set up a password on the SSID, 
and have the front desk hand it out to guests, after mailing it to staff, and 
I'm getting pushback on that from my manager.

Does anyone have some ideas I could pursue on this?

Thanks,

Kurt

~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ 
<http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

---
To manage subscriptions click here: 
http://lyris.sunbelt-software.com/read/my_forums/
or send an email to [email protected]
with the body: unsubscribe ntsysadmin

Confidentiality Notice:
This e-mail, including any attachments is the
property of Catholic Health East and is intended
for the sole use of the intended recipient(s). 
It may contain information that is privileged and
confidential.  Any unauthorized review, use,
disclosure, or distribution is prohibited. If you are
not the intended recipient, please delete this message, and
reply to the sender regarding the error in a separate email.
 

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

---
To manage subscriptions click here: 
http://lyris.sunbelt-software.com/read/my_forums/
or send an email to [email protected]
with the body: unsubscribe ntsysadmin

Reply via email to