News: This forum is now permanently frozen.
Pages: [1]
Topic: Client isolation  (Read 4031 times)
« on: February 08, 2011, 19:50:22 »
sidvel *
Posts: 6

I use Monowall with capitive portal access to public hotspot, but people have access to lan, it would be nice to have access only to wan. I tried to block the view between rules with customers without success.
« Reply #1 on: February 09, 2011, 11:10:44 »
Manuel Kasper
Administrator
*****
Posts: 364

This is definitely possible (assuming your captive portal runs on an optional interface). How did you set up your firewall rules?
« Reply #2 on: February 10, 2011, 00:38:52 »
sidvel *
Posts: 6

Thanks for the reply, I do not use optional lan, only wan connected via PPPOE in ADSL modem, and Lan connected to 20 access points with a 24-port switch.

 I tried using the blocking rule: * LAN net * LAN net *


« Reply #3 on: February 10, 2011, 04:19:17 »
iridris ***
Posts: 145

If all of your AP's are on the same switch, there's not much you can do at the firewall level.  Is it a managed switch?  If so you may be able to use the switch to prevent each AP from talking to each other somehow (possibly with VLANs?).
« Reply #4 on: February 10, 2011, 07:22:31 »
sidvel *
Posts: 6

Hi, It isnĀ“t a managed switch. I believe the firewall is able to prevent communication network defined in the DHCP range Monowall, I've seen some hotspots that windows 7 show internet only, in my case it shows the local network and internet conexion. I believe the local network is necessary for the autentication of capitive portal. I'm stay with 5 systems running at 3 years and very satisfied with the results and established, just this security issue that still could not solve, but with the help of everyone here at the forum I'm sure I will get.
« Reply #5 on: June 17, 2011, 16:36:17 »
momothefox *
Posts: 49

by sub-netting the network.
i modified and Image , and could have an option in ISC DHCP server up in GUI , to assign certain sub-net mask to clients, as /30.
i hope the hidden options in DHCP to appear in the GUI, and some useful options to be added.
regards

Mohammed Ismail
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines