Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Linksys BEFSR41 - BEFW11S4 Security Set Up

Status
Not open for further replies.

snyph

Technical User
Jul 7, 2003
1
US
I have been trying a few setup arrangements with my two Linksys routers. I have a BEFSR41 4-port router and a BEFW11S4 (V.2) Wireless Router with 4-port switch.

Before I explain what I'm trying to do, first, I really, really want to use both routers. I could probably chuck out the BEFSR41 and just use the wireless one...but that would be too easy.

I would like the WAN (from a Motorola SurfBoard Cable Modem) to come into the Wireless router. Ideally, the wireless router would have DHCP running and all the normal goodies.

I would like to connect my BEFSR42 to the wireless router as follows: from the wireless router port number 1 to the wired router WAN port. Then I would like to set up the wired router with DHCP (starting at a different number like 192.168.1.100). All my office LAN equipment would then be connected to the wired router, and the only thing connected to the wireless router would be the wired router.

My thinking is this, and please let me know if I'm way off here: I can accept wireless connections this way which can then use the internet and all that stuff. But, any connected wireless client can not go down into the wired routers LAN. I would just set up a MAC filter or something along those lines on the wired router and filter out all MACs other than the wireless routers MAC. Perhaps just do an IP filter.

Perhaps I'm making this too complicated... Any suggestions?

Thanks in advanced...

snyph
 
Let me offer a different perspective.

The BEFSR41 and the WRT54G are the Linksys' Golden Geese, and they will receive the firmware updates and support that the BEFW11S4 (V2), a product no longer made, will never have.

And, security is not going to come from how you cable the devices.

And, I hate double NAT schemes.

Identify first where port forwarding is an issue. This is likely to be on the wired side of things.

I would treat the BEFW11S4 as if it were just an access point with DHCP enabled.

I would give it a fixed IP in the wired router address space, with a Gateway address the wired router; enable "routing" instead of "Gateway", and assign it a private subnet addressing scheme different than the wired LAN. Now connect its uplink port to a regular wired port on the BEFSR41.

The wired router would connect to the modem. It would use a different subnet scheme than the wired clients.

The wireless router should use standard security measures regarding SSID, MAC filters if possible, and WEP. Change the administrator username and passwword, and disable remote administration.

The wired router should have the administrator username and password changed, and disable remote administration.

Done.


 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top