News: No news.
 
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
August 01, 2010, 06:02:22
Pages: [1]
  Print  
Topic: client isolation wired network  (Read 2867 times)
« on: October 04, 2007, 19:23:40 »
frank *
Posts: 22

Hello folks,
do anybody know a way to support client isolation at wired networks
which little bit prevents one client communicating with another client ?

thanks
greets frank
 
Logged
« Reply #1 on: October 28, 2007, 17:49:24 »
frank *
Posts: 22

Static VLAN is a possibility ?
One port is connected to monowall , each other port is a different VLAN?
Has anyone tried this together with CP?
Logged
« Reply #2 on: July 18, 2008, 00:43:13 »
tikay.event *
Posts: 7
198210800 info@tikay-event.de

Some Switches have a function called client isolation. This function creates an extra VLAN for every port und merges them to one port. With a L3-Switch and VLANs you can do this, too.
Logged
« Reply #3 on: July 18, 2008, 01:19:34 »
cmb
Administrator
*****
Posts: 824

The only way to do this is via capabilities of your switch. Communication within a network does not touch your default gateway so the firewall cannot control it.
Logged

« Reply #4 on: January 27, 2010, 19:16:03 »
tcook *
Posts: 1

Currently the only way to achieve this is with your switch if it supports pvlan's (private vlans). Although Nomadix has an interesting way of doing this. Their router responds and masquerades to all arp requests. So it answers as all mac addresses unless it it added to a list. This in effect causes client isolation. Pretty cool idea if you ask me.
Logged
« Reply #5 on: May 31, 2010, 19:23:26 »
tcarcur *
Posts: 1

I've been looking for a way for m0n0wall to handle client isolation.

I know the GuestGate switch creates a new VLAN for each DHCP client. Since the GuestGate has only 1 LAN port, like most m0n0wall configurations, I figured that maybe m0n0wall can be set up this way.

Does someone know if m0n0wall can dynamically create VLANs for DHCP clients while retaining the CP on all VLANs? Or, if at least client isolation this way is possible.
Logged
« Reply #6 on: July 26, 2010, 23:44:22 »
momothefox *
Posts: 23

i did it by assigning sub net different from the Sub net of LAN
for example /24. while LAN sub net is /16
so if LAN IP address is 192.168.0.1/16
clients assigned 192.168.1.0/24 cannot communicate with clients assigned 192.168.2.0/24.
this on IP level only, and this needed to modify m0n0wall image to allow assigning special Sub net mask for Clients.

regards.
Mohammed.
Logged

Mohammed Ismail
 
Pages: [1]
  Print  
 
Jump to:  

Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC