-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


mOjO wrote:
> A more expensive WAP (I know Cisco does, not sure about Proxim) will
> allow you to run multiple SSID's off the same unit. (i.e. one
> unprotected and the other protected)  Then I think you could go so far
> as to assign different VLAN's to each wireless network.  pfSense should
> recognize the VLAN's and allow you to define different rules (Most of
> this is speculation, someone might prove me wrong here.)  Or potentially
> a VLAN capable managed switch could allow you to separate the two
> networks, isolating them and allowing you to pipe them through different
> interfaces on pfSense.
> 
> very speculative but something to look into...

The Colubris MSC units do precisely that. From their interface one
creates a 'virtual AP'.  It can support multiples of these virtual AP's
and each can have a very separate config: different SSID, different
encryption policy, different authentication, etc.  All of this on a
single radio. Typically each of the virtual AP's tags the traffic with a
different VLAN; so you then run it to something like pfsense that can
sort it.

A typical application is to set up one virtual AP with the public SSID
and a second one with an un-broadcast SSID and WPA for each of the
employees. Since the traffic leaving is on separate vlan's you can then
set rules in pfsense to disallow the 'public' traffic to 'staff' LAN.

Caveat: I got hired to suss this out for a WISP. It is working on my
bench right now; but we haven't beat on it hard yet.

> Jonathan Woodard wrote:
>> I'm hoping someone can help me with this and save me some time. It's a
>> bit complicated to explain so bear with me. I have also enclosed a
>> diagram of the layout and my idea to give you a better idea.
>>
>>
>> I maintain the network for a local library. Currently, they have a
>> wired network and one AP. The AP is both used by the public for
>> Internet and also by the employees. I would like to separate this. I
>> do not like the idea of someone coming in and having access to the
>> private network with a laptop I can't lockdown. My inital plan was the
>> enclosed diagram with 2 AP's, one secured for private use and one open
>> for public use. However, I am wondering if this is the only option, if
>> not, is it the best option? I am comfortable with networks but there
>> always seems to be capabilities I am unaware of that I would like to
>> experiment with.
>>
>> I wonder if there is some way in Pfsense to separate the 2
>> (public/private) on the one AP? I am thinking not since I want to
>> secure one and not the other but I would just like verification on this.
>>
>> Can I install 2 supported wireless cards and separate them that way?
>> This would be really cool since everything is still in the one box.
>>
>>
>> On a semi-side note. Can anyone give me any experience on Pfsense as
>> an AP? I realize this possibly is based on the particular card but, on
>> average, how do you feel it compares to a typical home AP (range,
>> connection stability, etc.)
>>
>> Thank you for all your help. I have never found a more helpful group
>> of people as the people in this project. Between the forums, IRC,
>> mailing lists and everything else I have always found an answer to any
>> problems. I am certain that this will, over time, put Pfsense above
>> all others.
>>
>> Jonathan
>>
>>
>>
>> ------------------------------------------------------------------------
>>
>> ------------------------------------------------------------------------
>>
>> ---------------------------------------------------------------------
>> To unsubscribe, e-mail: [EMAIL PROTECTED]
>> For additional commands, e-mail: [EMAIL PROTECTED]

- --
Eric W. Bates
[EMAIL PROTECTED]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (FreeBSD)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFElsQpD1roJTQ4LlERAndNAKCYYQXHYkoVbk8YrYLuL+R9JhXVUQCdFl37
apFptt59NY1HCcD613h44IY=
=j3WN
-----END PGP SIGNATURE-----

---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to