03-21-2023 10:53 AM
Hi
I have corporate wireless network and I need to separate wireless network from LAN, I am asking is there anyway that let corporate wireless clients to access internet from public DNS without accessing LAN network, I mean that I consider them as external network clients, and if I can what is needed to accomplish this
Thank you
03-21-2023 11:25 AM
- You may configure the DHCP server for these clients to let them use the intended DNS servers ,
M.
03-21-2023 01:33 PM
Thank you marce1000, but could you explain more, is there option we can use and what are the things we should do to accomplish it
03-21-2023 01:09 PM
If you need to separate wireless from the local LAN, it's not DNS. You need to use acl's or a firewall and block traffic from the wireless subnet(s) to the wired subnet(s) and vice versa.
03-21-2023 01:30 PM
Thank you Scott Actually I am using ACL right now but I want to know if there is such option like playing with DNS to ease it, means clients will be considered as external clients and no affect come from them even if no ACL configured
03-21-2023 01:42 PM
If there is routing between the wireless subnet(s) and the wired subnet(s), then there is no isolation between the two. DNS doesn't matter, it matters is on a wireless subnet, you are blocking all internal subnets and only allowing internet, then just configure DHCP to use one of the public dns servers that are available. DNS servers do not isolate wired and wireless nor does it isolate wired and wired or wireless and wireless.
Look at it this way, if you don't have acl's in place a devices from wireless can ping, rdp, ssh, telnet, etc. to a wired device and not have to use DNS. A device from either subnet would be able to scan and use nmap or other tools to discover devices on another subnet. By using ip and not dns!!!
03-21-2023 01:44 PM
Put it this way... if a wireless device was assigned a public dns (Google 8.8.8.8), it doesn't mean a user can't change that to use an internal dns server. That is why you use acl's and or firewalls to allow of block specific traffic.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: