Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Networking Forum > Security and Firewalls
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Security and Firewalls Protecting you against unwanted people and programs

Reply
 
LinkBack Thread Tools
Old 10-24-2009, 09:08 PM   #1 (permalink)
Registered User
 
Join Date: Oct 2009
Posts: 4
OS: WinXP-PRO/SP3


Exclamation Configure public AP via private Network.

I am having a problem configuring an access point thats on a public network , via the private network.

I know the firewall prevents public users from accessing the private network, (serigation) but its also seems to prevent private users from accessing the public network, thus I cant access the access points IP web control panel.

The only way for me to configure the AP is to plug it into the private, which is a huge security risk , as anyone who logs in would then be on private side.

Anyways, how can I create a firewall rule that will allow me to reach the access points IP from private, but not unprotect it from public?

Last edited by rdlockrey; 10-24-2009 at 09:11 PM.
rdlockrey is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 10-25-2009, 10:57 AM   #2 (permalink)
Manager, Networking Forums
 
johnwill's Avatar
 
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 41,572
OS: Windows 7, XP-Pro, Vista, Linux


Blog Entries: 1
Re: Configure public AP via private Network.

I think you want your cake and eat it too! If you have a rule that allows you through, what stops other people from doing the same thing?

Of course, with the limited network information provided, we may be barking up the wrong tree...
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up!

Microsoft MVP - Windows Desktop Experience
johnwill is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 10-25-2009, 03:19 PM   #3 (permalink)
Registered User
 
Join Date: Oct 2009
Posts: 4
OS: WinXP-PRO/SP3


Question Re: Configure public AP via private Network.

yeah I see your point...

I think what I was saying on my original post is how do administrators manage access points on the private network? I am a tech, however advanced networking is not speciality.

I wonder if the problem might actually be caused by how the DHCP issues IP's. The gateway issues private IPs in a different range then public, however the Access points default (static) IP is not within the range of public IPs but is within range of private which could explain the problem

Anywho..the gateway is pretty well using default settings, and the only active firewall rules are one that blocks public (auth) from accessing Private (local) then another that blocks WAN.

So I guess the question is..

1) should the access point have a static IP in the publics IP range?


2) Are firewall rules stop traffic in both directions or can they be configured to apply to only the originating source?

example:
Well use the rule that blocks all public traffic from accessing private network.

Lets say a client from the private network pings a public client (assuming it responds) is the response is actually blocked since the direction of the response is going to private, or does the gateway permit the traffic since the originating request came from the private network.

I suppose I need to get a good book on advanced networking management, before this I never used access points or gateways, and I fear leaving the wrong port open could be like christmas to a bored hacker.

Anyways thanks for your help,

Last edited by rdlockrey; 10-25-2009 at 03:22 PM.
rdlockrey is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 10-26-2009, 08:57 AM   #4 (permalink)
Manager, Networking Forums
 
johnwill's Avatar
 
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 41,572
OS: Windows 7, XP-Pro, Vista, Linux


Blog Entries: 1
Re: Configure public AP via private Network.

An WAP should have an address in the subnet that your network runs on, it certainly shouldn't have a public IP address.

Normally, outgoing traffic is not blocked unless you specifically configure it, otherwise you'd never be able to do anything on your network!

The WAP receives wireless traffic and passes it without comment on to the network, since any connections to the WAP are considered to be on the private network. The security of the WAP is the encryption, that should be WPA or better. Also, in a network with a server, you'd likely want to run a RADIOS server and use 802.1X Authentication for any connections. Your WAN gateway is your router or firewall appliance, depending on the network.

To get more specific would require knowing a lot more about the network topology.
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up!

Microsoft MVP - Windows Desktop Experience
johnwill is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 10-27-2009, 05:46 PM   #5 (permalink)
Registered User
 
Join Date: Oct 2009
Posts: 4
OS: WinXP-PRO/SP3


Re: Configure public AP via private Network.

Well unless im confused more then I thought, I dont think WPA security is the problem, since the admin machine is on LAN, and the entire network works fine the only thing I cant do is access the WAPs control panel.

I am using local authentication for the public network. Heres the equipment and scheme I have (attached).

In fact I even tried to disable the serigation rule and that didnt work, which puzzles me. I then gave the wap a static IP within range, and that didnt work either, yet If I unplug either WAP from public, then plug it into private all problems are resolved, and I can access them fine.

I then logged in via wireless connection directly to each wap (public) then tried its IP, and the same thing, nothing, like the gatway is redirecting me to no-no land, yet authentication and internet works fine from both WAPs.

I just dont get it, whats going on here?
Attached Images
File Type: bmp scheme.bmp (470.3 KB, 2 views)
rdlockrey is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 03:05 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85