Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Enthusiast Zone > Networking > Wired and wireless with Airport basestation

Wired and wireless with Airport basestation
Thread Tools
Fresh-Faced Recruit
Join Date: Feb 2003
Location: Norway
Status: Offline
Reply With Quote
Apr 13, 2003, 12:30 PM
 
I'm thinking of getting an Airport Extreme basestation, and have a couple of questions I hope you guys could help me with.

Today I use a FreeBSD box as a firewall and router for both my wired and wireless network. The two networks are defined as two seperate NAT'ed subnets, and I have a mix of DHCP and static IP assignmens. The wireless network does not use WEP, but is encrypted with IPSec (racoon). My internet connection is SDSL with a static IP.

The FreeBSD box is also a web/database server. In addition to this I have a Win2K TS server which is accessed from specific outside clients with port forwarding on the FreeBSD box. The other computers are a couple of Win2K on 100Mbps, a Dell and a TiBook on 802.11b.

As you might guess, I'm thinking of replacing the FreeBSD box with an AE basestation. But I need to know how much functionality I will lose or gain.

My questions are as follows:
* Will the AE station route both my wireless and wired network if I connect a switch to the LAN port?
* Will I be able to define the two nets as seperate subnets and do firewalling between them?
* Can I do a mix of static and dynamic IP assignments? (ie reserve an IP in the dhcp scope)
* Can Wep/RADIUS/Leap replace IPSec as security on my wireless network? Will it work on both OSX and Win?
* I understand the AE station can do portforwarding, so there wont be a problem having www/ssh/ts servers on the inside serving content to the outside?
* How much can I restrict the client computers access to the outside? For instance, can I restrict "non-authenticated" wireless clients to just port 80?

I would like to keep the FreeBSD box as it's quite flexible and works very well, but unfortunately it will have to be replaced. So, will an AE basestation do what I want?
     
Mac Elite
Join Date: Sep 2000
Location: Los Angeles
Status: Offline
Reply With Quote
Apr 13, 2003, 02:12 PM
 
Originally posted by weirded:
* Will I be able to define the two nets as seperate subnets and do firewalling between them?
* How much can I restrict the client computers access to the outside? For instance, can I restrict "non-authenticated" wireless clients to just port 80?
These are the only two I am not sure about. I have an Asante wireless router FR3002AL and it can restrict wireless clients to LAN, WAN or both. I don't know if the AEBS does this. You might want to check out some other manufacturers' models like Asante, Netgear etc. You may find that these are more configurable than Apple's.
     
weirded  (op)
Fresh-Faced Recruit
Join Date: Feb 2003
Location: Norway
Status: Offline
Reply With Quote
Apr 13, 2003, 03:09 PM
 
Originally posted by aaanorton:
These are the only two I am not sure about.
Does this mean it can do all the other stuff?

I have an Asante wireless router FR3002AL and it can restrict wireless clients to LAN, WAN or both. I don't know if the AEBS does this. You might want to check out some other manufacturers' models like Asante, Netgear etc. You may find that these are more configurable than Apple's.
Yeah, I'm looking at some alternatives, but it seems like those that are available here are either more expensive or doesn't have 802.11g. But if the AE can do everything except the things you mention I can probably work around the other limitations. Like restrict WAN<=>LAN access by requiring IPsec on LAN clients, or something similar.
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 05:52 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2