Tom's Hardware > Forum > General Networking > Network General Discussions > Security of multiple VLANs and WiFi

Security of multiple VLANs and WiFi

Forum General Networking : Network General Discussions - Security of multiple VLANs and WiFi

Tom's Hardware: Over 1.4 million members in 6 different countries available to answer all your high-tech questions. Sign up now! Its free!
Word :    Username :           
 

Archived from groups: comp.dcom.lans.ethernet (More info?)

 

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

In the following configuration,

[x]-----O-------O
switch WAP station

the switch supports multiple VLANs per segment and the Wireless Access
Point is an Apple Airport Extreme. At first glance, my impression is
that the WAP is not capable of routing, but I have not confirmed this.

It seems to me that I could obtain better security if I were to place
the WAP in one VLAN and the station in another (which grabs its IP
address from a DHCP server behind the switch). My reasoning is that I
could place the WAP inside a firewalled VLAN and allow management access
only to that VLAN.

I'm not terribly familiar with the way WAPs work (they're essentially
bridges, correct?), so I'm curious to know if such a configuration would
actually work, if indeed the WAP is *not* a router.

Moreover, I have to wonder if this design would actually result in the
security I'm after. Couldn't an attacker simply sniff the segment
between the WAP and the station(s), including traffic on the opposite
VLAN to which they are connected?

- --
Anthony Chavez http://anthonychavez.org/
mailto:acc@anthonychavez.org jabber:acc@jabber.anthonychavez.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (Darwin)

iD8DBQFCJ4dzbZTbIaRBRXERAr2SAJ42rQmh/bXgfYCnVRRyWWw81OjDngCeMIrm
zxSQ63lh2BIUBvchC7jVej4=
=CkEy
-----END PGP SIGNATURE-----

Sponsored Links
Register or log in to remove.
Tom's Hardware > Forum > General Networking > Network General Discussions > Security of multiple VLANs and WiFi
Go to:

There are 863 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Sponsored links
  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them