Hey Guys,
I work for a school district and I'm in the process of testing a public WiFi network for use by parents and other guests at one of our school sites. We have HP ProCurve 420 WAPs which do VLAN tagging beautifully. I have the VLAN configured for the public network and everything works as expected.
Now, I need to set up ACL's so that any users on the public WiFi network (10.42.x.x) can only access the Internet. We do not want them to be able to access any other network resources. The path web (port 80) traffic will take out to the Internet is 10.42.x.x > 10.255.255.1 > 10.1.1.3 (our Squidguard filter). The path all other traffic will take out to the Internet is 10.42.x.x > 10.255.255.1 > 10.1.1.1 (our PIX)
What would be the best way to approach this?
I work for a school district and I'm in the process of testing a public WiFi network for use by parents and other guests at one of our school sites. We have HP ProCurve 420 WAPs which do VLAN tagging beautifully. I have the VLAN configured for the public network and everything works as expected.
Now, I need to set up ACL's so that any users on the public WiFi network (10.42.x.x) can only access the Internet. We do not want them to be able to access any other network resources. The path web (port 80) traffic will take out to the Internet is 10.42.x.x > 10.255.255.1 > 10.1.1.3 (our Squidguard filter). The path all other traffic will take out to the Internet is 10.42.x.x > 10.255.255.1 > 10.1.1.1 (our PIX)
What would be the best way to approach this?