Re: Wireless Access Point on external router?



I think I need VPN for a couple of reasons. If these could be accomplished
with RWW (without adding extra client PCs to the office), how could I
accomplish that?
There are a couple of employees that work remotely. I want to give them full
access to network features, like shares, backup and exchange.
There is also an external contractor who is working on a couple pieces for
the web site. The production site is hosted by a third-party service but the
development site is local, on the SBS server. The contractor needs access to
the local web root and to SQL. Is this possible through RWW (again, without
decating an extra client PC at the office)?
Thanks,
Ari

"Cris Hanna [SBS-MVP]" wrote:

Why do you need VPN as opposed to RWW?

--
Cris Hanna [SBS-MVP]
-------------------------------------------------
Microsoft MVPs
Independent Experts (MVPs do not work for MS)
Real World Answers
---------------------------------------------------------
Please do not contact me directly regarding issues

"doucettea" <doucettea@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:D0CF64B7-F286-4FD6-A11A-BF11A0F0BD6B@xxxxxxxxxxxxxxxx
Dave,
In the article you linked to about setting up 802.11x on SBS for the WAP,
there is a caveat that VPN might not work. Of course, I would like to have
VPN and good wireless security, so is there a workaround? How likely is
VPN
to stop working (we do use ISA 2004)?
The article mentions that using RADIUS would fix this, but that it would
be
used instead of Windows Authenticaion for VPN connections?
What does this mean, practically?
The article also mentions that getting a RADIUS server would be necessary.
We don't have an additional server available. Are the "free RADIUS
servers"
mentioned by the article OK?
I guess I'm starting to get into something more involved than I expected
for
setting up secure wireless and having VPN connectivity. Am I overly
concerned?
Thanks,
Ari

"Dave Nickason [SBS MVP]" wrote:

I don't use Linksys WAPs at the office, but I do use them at home, and at
the homes of anyone I support for wireless. I've been completely happy
with
them.

At the office, I've wanted to use a commercial quality WAP instead of a
home-quality device. I use 3Coms, and I'm very happy with them. I've
got
to say, for the one or two users at home and the six or so at the office,
I
haven't really seen a difference in reliability or functionality between
the
two brands. I've recently seen a lot of favorable comments about DLink,
but
don't have any personal experience with them.

With wireless, every device has to support the settings you want to use.
I
recommend getting one with a good range of features so it doesn't become
the
weak point in your deployment plans. Specifically, I would not purchase
a
device that does not support "WPA2 Enterprise" security.


"doucettea" <doucettea@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:A9ECBBC4-0089-4B09-834A-939C1702F463@xxxxxxxxxxxxxxxx
Thank you, Dave. I'm using SBS premium, ISA, 2 NICs. So, per your
suggestion,
I shouldn't put the WAP outside of ISA. Instead, I should put the WAP
on
the
internal switch.
Can you recommend a good (cheap, for small home-based office) WAP? Is
the
Linksys WRT54gL the way to go for the WAP (as it is recommended in
other
recent posts)?
Is the Dlink di804hv OK for the router/firewall (since I'm also using
ISA)?
It is also recommended in other posts.

Thanks again,
Ari

"Dave Nickason [SBS MVP]" wrote:

Is this SBS Standard or Premium? If it's Premium, I would not use a
device
outside of ISA to provide LAN access. If you're using the router as
the
firewall device, without ISA, then you can use a combination wireless
device
such as a Sonicwall. I'd be reluctant to use a low-priced NAT device
in
this way.

What I think would be the best practice: get a good quality
non-wireless
firewall that you're comfortable with. Get a separate WAP and install
it
with these instructions. This will give you the appropriate security
for
both the perimeter and the internal wireless network.

Configuring Secure Wireless Network Access with Microsoft® Windows®
Small
Business Server 2003
http://home.comcast.net/~clearviewtc/


"doucettea" <doucettea@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:52DA73CF-66B8-4831-BE3C-AB429F8E8ABF@xxxxxxxxxxxxxxxx
Hi all,
Is it possible to use the wireless access from a router/firewall
between
the
SBS external NIC and the cable modem for access to the internal
network?
I need to get a new router/firewall to put between the SBS and the
cable
modem b/c VPN isn't working through the current one. I'd also like
to
replace
the WAP we've been using because it doesn't have the gratest
security
(it
currently connects by cat5 to the switch on the internal network).
Could
all
of this be accomplished with one device (like the Linksys WRT54gL)?
Or
do
I
need to buy a new router/firewall (Dlink di804hv ?) and then add the
WAP
to
the switch on the inside (still go with the Linksys)?
Thanks,
Ari









.



Relevant Pages

  • Re: Wireless Access Point on external router?
    ... Why do you need VPN as opposed to RWW? ... In the article you linked to about setting up 802.11x on SBS for the WAP, ... VPN and good wireless security, ... Is the Dlink di804hv OK for the router/firewall (since I'm also using ...
    (microsoft.public.windows.server.sbs)
  • Re: Wireless Access Point on external router?
    ... As Owen says in the document, that configuration will break VPN. ... imagine that you're going to want to put in a second server to do RADIUS ... In the article you linked to about setting up 802.11x on SBS for the WAP, ... VPN and good wireless security, ...
    (microsoft.public.windows.server.sbs)
  • Re: Wireless Access Point on external router?
    ... In the article you linked to about setting up 802.11x on SBS for the WAP, ... VPN and good wireless security, ... I shouldn't put the WAP outside of ISA. ...
    (microsoft.public.windows.server.sbs)
  • Re: Industry Standard Security and guest wifi access best practice
    ... VPN use-This is something I want to rule out from the start. ... don't support WPA, and if they did then rule out changing the key ever. ... Use WPA to encrypt wireless traffic, ... Connection is simple for the end user and requires no VPN client ...
    (alt.internet.wireless)
  • Re: VPN vs. Cisco LEAP for wireless security ?
    ... use the wireless, and then (assuming you have adequate user account password ... the latest version of the client and access point ... VPN does nothing to guard the front door, so to speak--which is what the ... > Does it make sense use VPN to provide wireless security in my ...
    (microsoft.public.security)