Re: Addin a WAP on to the network

Tech-Archive recommends: Speed Up your PC by fixing your registry



Correct - but we're concentrating less on the WAP and more on ISA.
The idea being to illustrate the pro & con of using ISA to separate the WLAN from the LAN.
...of course, whether there are more pro than con depends on your perspective...

SBS folks tend to lean toward task simplicity and there are no wizards used in this session.
We're talking about the deep guts of wireless security and ISA technologies.
By the time we've finished, the audience will have all the facts they need to deploy a more secure WLAN using ISA 2006.
ISA 2004 can be used, but you don't get the extra-kewl flood mitigation that ISA 2006 brings to the table.

BTW, there is a special item being announced at the end of the session.
All I can say for now is that it gets this ISA fanatic all little-girl-giggly...

--
--
Jim Harrison [ISA SE]
Read the help, books and articles!

This posting is provided "AS IS" with no warranties, and confers no rights.

"Dave Nickason [SBS MVP]" <gwdibble@xxxxxxxxxxxxxxxxxxxxxx> wrote in message news:OJHe4bXiGHA.5088@xxxxxxxxxxxxxxxxxxxxxxx
Jim - I don't have time to watch the livemeeting, but I think you bring up a
very good point in that we're maybe talking about 2 different things?

Owen's article is about how to add wireless for domain member PCs to access
the LAN wirelessly. It works the way you guys do it - certificates and IAS.

With the livemeeting method, you're preventing wireless access to the LAN,
right?

I just assumed that Attila was looking for LAN access, which in retrospect
wasn't a very good assumption. So Attila, if you're looking for guest
Internet access as opposed to secure access for your own client PCs, ignore
my post.

BTW, I have a TZ170 non-wireless where I have a public (guest) WAP plugged
into the OPT port and isolated from the LAN with firewall rules. AFAIK you
should be able to configure the TZ170 to provide separate guest access,
isolated from your LAN, just by configuring firewall rules. For that, you'd
have to read the Sonicwall manual or contact them if the setup is not
obvious.


"Jim Harrison (MSFT)" <jmharr@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:OZzdt1QiGHA.836@xxxxxxxxxxxxxxxxxxxxxxx
<plug type="shameless">
This is where our presentation gets kewler - we're ISA-lating the WLAN
from the LAN.
</plug>

--
--
Jim Harrison [ISA SE]
Read the help, books and articles!

This posting is provided "AS IS" with no warranties, and confers no
rights.

"Dave Nickason [SBS MVP]" <gwdibble@xxxxxxxxxxxxxxxxxxxxxx> wrote in
message news:%23957FRMiGHA.2208@xxxxxxxxxxxxxxxxxxxxxxx
It should work with any access point with an IP on your internal network.

"Sal Candela" <SalCandela@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:D0D8D283-7F1B-4EDD-94BE-1CDDFB17EF6B@xxxxxxxxxxxxxxxx
Question - will this also work with a router/access point (sonic TZ 170
wireless) or do you need a seperate access point?

Thanks in advance for your help.

--
Sal Candela


"Dave Nickason [SBS MVP]" wrote:

See http://home.comcast.net/~clearviewtc/ for a great article
contributed
by
Owen Williams. This is the most secure way to add wireless to your SBS
network.


"Attila" <acsokai((@))gtnconsultig.com> wrote in message
news:uLOkTnohGHA.1000@xxxxxxxxxxxxxxxxxxxxxxx
I would like to add a WAP to the SBS 2003 Pro network. Could some point
me
to a good document that helps me set this up in ISA 2004?

Thanks,
Attila










.



Relevant Pages

  • Re: Force All to use firewall Client ONLY
    ... Remove all the browser's proxy settings. ... Definition which will only be true if the ISA is doubling as the LAN Router. ... Create an anonymous Access Rule for HTTP/HTTPS/FTP that only applies to ...
    (microsoft.public.isa)
  • Re: ISA 2004 and Wireless
    ... For wireless on the LAN side, it wouldn't be ISA. ... Just follow the steps for 802.1X authentication. ...
    (microsoft.public.windows.server.sbs)
  • Re: general question on design options
    ... Behind that I have my ISA, ... How do you get the VPN connections that terminate on the Cisco to get past ... DMZ and not the LAN. ...
    (microsoft.public.isa)
  • Re: ISA server (second post)
    ... Terence Liu ... | Edition antivirus and all the LAN is checked for viruses. ... Can it access Internet in your old SBS LAN? ... Is the ISA firwewall client installed on the PC? ...
    (microsoft.public.windows.server.sbs)
  • Re: VNC to Remote Site
    ... this when the remote site first when live. ... Which is what made me think "Is ISA blocking the VNC port of 5900 maybe??". ... > private connection to another "LAN" via using a device from BT Equipment. ... > Microsoft Internet Security & Acceleration Server: ...
    (microsoft.public.isa.configuration)