cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
303
Views
0
Helpful
0
Replies

Wireless Router off of ASA 5505

Clay Gentry
Level 1
Level 1

Greetings all, first time poster here.

I am "alright" with Cisco config but I need in knowing if I can do the following:

We have ASA 5505s. Sec+ license, VPNs connecting the ASAs- branch offices. DHCP and DNS for the network are both served up by a Windows Domain Controller behind one of the firewalls. The firewalls are the gateways. Small network- as of now around 60 IP connected devices. With wireless setup I'd envision adding 60 devices to the entire network at max.

We would like to set up a wireless router for the office, one for each, I have never configured a wireless router with a firewall before.

The way I envision it is with 2 SSID on each, one for employees "Company" with access to the internal network and external and one for "Guest" with only access to the external network (no access to internal) and only ports 80 and 443 open.

As of now only one VLAN is on the ASA's. I would configure two more on the same interface, the interface facing the wireless. One VLAN for "Company" and one for "Guest". I would have to set up a trunk on that interface I believe to allow to have two VLANs.

I would configure VLAN Company to have access to the current VLAN. Additionally, configure this VLAN to use the DHCP and DNS of the internal network. 

Then configure VLAN Guest to have a security level of 50. The current VLAN has a security level of 100.

Here is where I have an issue:

I would configure DNS pointing to google as I do not know my ISPs DNS server.

Then where do I configure DHCP? On the ASA, can that be done only on one interface? I do not want it to affect my current network. Or can I set DHCP up on the wireless router and have my ASA as the gateway. Preferably not the same IP gateway as my internal network.

Unsure of what wireless router we might get? I need one that is VLAN I believe. Any suggestions. Low to medium price range. I would like to another Cisco device but that may not align with the budget.

Appreciate any help. Thank you. 

0 Replies 0