Unconfigured Ad Widget

Collapse

which manages guest network - access point or router?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • high_revs
    Calguns Addict
    • Feb 2006
    • 7753

    which manages guest network - access point or router?

    getting tired of having to give the password for any occassional guest that comes around and needs (justifiably) internet access. usually I'll circle around all the wifis and change the password after because my rt-n56u doesn't have guest capabilities.

    instead of getting another router with guest capability (like a rt-n65u) and /or turning my rt-n56u into another ap to extend my range (if possible with its own ssid for guests), are there any access points out there that have guest capability out of the box? i won't have to do do any wifi bridging since i have a spare lan port i can put in the living room or even in the central place of the home. my rt-n56u can be a ap but not sure it can be an ap with its own ssid for guest. basically not sure it can be a dedicated for guest only i can power down since i don't need it all the time.

    reading so far, it seems i gotta go with a dd-wrt fix on a linksys router (threw my old wrt-54g's sometime back since they just kind stopped working properly w/o reboot and had dd-wrt on them).

    what i'm not sure is it the router that actually handles the "guest" network or can an AP do it? recommendations for one?

    my router reaches as far as the garage. don't need to extend it really. that or there isn't another solution other than getting another one with guest or just another rt-n56u if i can turn this current one into an ap with it's own ssid.
  • #2
    ocabj
    Calguns Addict
    • Oct 2005
    • 7924

    DD-WRT has the ability to do 'guest' wifi, in that you can create multiple SSIDs, with different encryption types, and then run multiple DHCP instances, to serve out different subnets/VLANs to each SSID, and then bridge them so they can get outbound.

    If all you are concerned about is people knowing your wifi password, then you can just light up another AP on your network and plugged into your switch/router, and give that AP it's own SSID and password. Assuming the AP you use also has DHCP services, then you can set it up to serve out separate address space from your primary network address space, but then I'm not entirely sure if you can get the AP to route traffic from itself to your router's address space.

    Distinguished Rifleman #1924
    NRA Certified Instructor (Rifle and Metallic Cartridge Reloading) and RSO
    NRL22 Match Director at WEGC

    https://www.ocabj.net

    Comment

    • #3
      Peter.Steele
      Calguns Addict
      • Oct 2010
      • 7351

      I've got a Netgear WNDR4500. It's got two separate routers in it, one for guest, and one for trusted stuff. You can combine them if you need to, for a network setup where you've got multiple wireless adapters in a single machine, and get double the throughput.

      It's pretty badass.

      I wouldn't spend the money that they want, though. I got mine as a beta-test item. It's got way more features than I'd use day-to-day if I had to pay for them.
      NRA Life Member

      No posts of mine on Calguns are to be construed as legal advice, which can only be given by a lawyer.

      sigpic

      Comment

      • #4
        high_revs
        Calguns Addict
        • Feb 2006
        • 7753

        thanks ocabj. i had dd-wrt setup for a couple of wrt-54g when i used one as a wireless bridge. i coudln't remember a guest setup with that old setup i had. i wasn't sure if i can get just another ap that can have it's own ssid. or ap would 'extent' the ssid used by the router. plus with my router, i use static dhcp. i figure the ap would have it's own ssid.

        you do hit the nail there re: ip assignments. that was another thing i was tyring to figure out. would my main router just give the ap one IP #. and then for the ap, i can setup a different ip range completely. not that it matters, i also use a switch where everything goes to, and the switch goes to the router.

        i'll have to find a dd-wrt compatible 802.11n that's pretty low price and still reliable even if it's just for those "occasions". (will be off when we don't have visitors since when we do, they're usually out of town'ers that stay at least a night or 2).

        guess nothing like just diving into it and figuring it out. if costs of an ap are running high'ish, i might as well get another router that has a guest and turn my rt-n56u (non dd-wrt compatible though) into an ap and tinker from there.

        Comment

        • #5
          esskay
          Senior Member
          • Oct 2005
          • 2304

          You could buy a used one, or set an alert on slickdeals or fatwallet and keep an eye out for good deals.
          WTS: Ewbank AKM & NDS-4 AK receivers, Custom Chief AJ Ruger Mini-14

          WTS: Oakley SI Shoes

          WTS KAC rail panels

          WTS: MGI Hydra Modular AR Lower

          Comment

          • #6
            ke6guj
            Moderator
            CGN Contributor - Lifetime
            • Nov 2003
            • 23725

            Originally posted by ocabj

            If all you are concerned about is people knowing your wifi password, then you can just light up another AP on your network and plugged into your switch/router, and give that AP it's own SSID and password. Assuming the AP you use also has DHCP services, then you can set it up to serve out separate address space from your primary network address space, but then I'm not entirely sure if you can get the AP to route traffic from itself to your router's address space.
            in that case, you'd be better served to plug in a second router instead of an AP. on the guest router, plug the WAN port into the main LAN, and change the network ID on the gues router to something other than that of the LAN.

            So, if you main network was 192.168.1.0, you'd set the guest network to have 192.168.2.0. that way, the guest router would have its own DHCP server assigning 2.x addresses to the guest clients and the router would be able to easily route internet traffic from the 2.x client to the 1.0 network and then to the internet.

            there is a slight possibility that a 2.x client could try to hack your 1.x resources with that setup since you won't have any access restrictions but that would work for a basic setup. If that is important, we could do some subnet mask adjustments to make it so that the guest router (and its clients) had no access to any 1.x resources other than the main router.
            Jack



            Do you want an AOW or C&R SBS/SBR in CA?

            No posts of mine are to be construed as legal advice, which can only be given by a lawyer.

            Comment

            • #7
              the86d
              Calguns Addict
              • Jul 2011
              • 9587

              Unless you can run both on different channels, I would suggest a separate AP/router on a different channel, and this would limit congestion, as there are only 3 channels in the US that don't overlap 1, 6, and 11... and you could set each to a different spectrum, as I understand it:

              Comment

              • #8
                Ricky-Ray
                Veteran Member
                • Jan 2010
                • 3161

                I upgraded my router to an Asus RT-66. You can create several "guest" networks if you wanted to.

                Ray

                "If you lead your life the right way, the karma will take care of itself. The dreams will come to you." - Randy Paush, Carnegie Mellon University

                Comment

                • #9
                  Fizz
                  Senior Member
                  • Feb 2012
                  • 1473

                  I have a Linksys EA3500 at home that does this.

                  You enable the checkbox for guest networks. By default it's unsecured (to the AP), when they try to go anywhere they'll be redirected to a login page that you provide them with the guest password to access. Basically, if you've ever used Starbucks wifi and clicked on the Terms of Service when trying to go to a site... it does that.

                  This traffic is VLAN'ed off so those joined to the guest network can't see primary LAN nodes (your computers, printers, etc.).

                  When the guests leave, just turn it off. Or just leave it on?

                  If you setup a separate AP and plug it into one of the LAN ports on your current router or switch, yeah you can control who has wireless access by giving it a different SSID and password. However, your 'main' router will still be what's issuing DHCP addresses. You'll be putting guests on the same subnet as your other devices. Which, may or may not be a concern for you, but understand that this is the case. With higher end stuff you can VLAN this stuff off... but let's not get into that for a home setup (your equipment wont support it).

                  Also, even if you were to say setup another router behind your router, issuing a different subnet, it doesn't necessarily stop security exposures.

                  For what you want, I'd honestly just go with a guest wifi enabled router. Leave it on, print out cards you can hand to people with the password.

                  Comment

                  • #10
                    Fizz
                    Senior Member
                    • Feb 2012
                    • 1473

                    Originally posted by ke6guj
                    there is a slight possibility that a 2.x client could try to hack your 1.x resources with that setup since you won't have any access restrictions but that would work for a basic setup. If that is important, we could do some subnet mask adjustments to make it so that the guest router (and its clients) had no access to any 1.x resources other than the main router.
                    I get where you're going with this. On the WAN interface of the guest router, assign it say a static 192.168.1.2 with a 255.255.255.252 subnet. It'll send any requests outside of that to the gateway then to nowheresville.

                    But, I think in the grand scheme administrating this solution (and getting it working for someone who isn't interested in becoming a network engineer) might be a bit cumbersome.

                    Comment

                    • #11
                      ke6guj
                      Moderator
                      CGN Contributor - Lifetime
                      • Nov 2003
                      • 23725

                      Originally posted by Fizz
                      I get where you're going with this. On the WAN interface of the guest router, assign it say a static 192.168.1.2 with a 255.255.255.252 subnet. It'll send any requests outside of that to the gateway then to nowheresville.
                      yup, you nailed it. I glossed over it in my post so that if it was an issue that he needed to block those guests from being able to see his main network, that we could further expand on it.

                      But, I think in the grand scheme administrating this solution (and getting it working for someone who isn't interested in becoming a network engineer) might be a bit cumbersome.
                      correct, unless you have a firm knowledge of networks and subnet masking, I would not recommend that in the normal course of business unless you did have someone there to walk you through it.
                      Jack



                      Do you want an AOW or C&R SBS/SBR in CA?

                      No posts of mine are to be construed as legal advice, which can only be given by a lawyer.

                      Comment

                      • #12
                        Darryl Licht
                        CGN/CGSSA Contributor
                        • Dec 2012
                        • 2259

                        I agree that creating 2 separate subnets might solve the OPs issue... but that would require a second router if he uses his current AP to extend existing wireless network.

                        Many of the newer routers have dual network capabilities, support wireless N, IPv6, and have better security. Id just pick up a new Linksys/Cisco model and be EASILY done with it for years to come. Beware of no name inexpensive routers. Cisco is a name you know you can trust!
                        "Laws that forbid the carrying of arms...disarm only those who are neither inclined nor determined to commit crimes. Such laws make things worse for the assaulted and better for the assailants; they serve rather to encourage than prevent homicides, for an unarmed man may be attacked with greater confidence than an armed one.
                        --Thomas Jefferson
                        Politics is the art of looking for trouble, finding it everywhere, diagnosing it incorrectly and applying the wrong remedies. --Groucho Marx

                        Comment

                        • #13
                          ke6guj
                          Moderator
                          CGN Contributor - Lifetime
                          • Nov 2003
                          • 23725

                          I would agree that in most cases a new router with Guest Access would probably be best, but if you have a spare router laying around, or find one on sale for $20, it might be an option instead of buying that new fancy router.
                          Jack



                          Do you want an AOW or C&R SBS/SBR in CA?

                          No posts of mine are to be construed as legal advice, which can only be given by a lawyer.

                          Comment

                          Working...
                          UA-8071174-1