One network, two segments, one wifi, one wired

waxhits

Honorable
Jan 27, 2014
4
0
10,510
Hello,
I would like to set up two segments on a network for a small business office, about 10 workstations.

One segment can access the network via wifi, and the other one by a wired connection.

The computers that plug into the wired segment are going to be used to process credit card numbers, and for security reasons they can't be seen or accessed by the computers connected to the wifi segment.

Can I go about setting this up with some kind of "y" configuration, or do I need to go the VLAN route?

Any help would be appreciated.

Thanks!
 
Solution
If you use commercial switches it is possible to filter traffic based on ports.

With consumer stuff you will need to in effect use different vlans/subnets since the firewalls can only restrict at the ip level not at the port level. Even then you will likely need to run a router with dd-wrt to get vlan support.

You might be able to use a router that allows for guest wireless. By default the guest wireless can only access the internet no access is allowed to the main wireless or lan network.
If you use commercial switches it is possible to filter traffic based on ports.

With consumer stuff you will need to in effect use different vlans/subnets since the firewalls can only restrict at the ip level not at the port level. Even then you will likely need to run a router with dd-wrt to get vlan support.

You might be able to use a router that allows for guest wireless. By default the guest wireless can only access the internet no access is allowed to the main wireless or lan network.
 
Solution

waxhits

Honorable
Jan 27, 2014
4
0
10,510
Got it. Thanks Bill, that is helpful. The other part of the equation I forgot to mention is that we are using a gateway modem. The router behind it is a Linksys E1200 v2. I still need to flash the dd-wrt firmware to it, but basically we want to use that router to create two segments, one wireless and one wired.

With that said, do I need to create a static IP on the gateway?

 
That router support guest wireless with factory firmware. You should be able to move all your users over to the guest wireless. The users on the guest wireless can only see each other and the internet. The other wireless network may be possible to disable if you don't want it otherwise you could just put in a key and tell nobody.