Advanced VLAN and DHCP configuration

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
skot.fortin
DD-WRT Novice


Joined: 18 Dec 2010
Posts: 15

PostPosted: Sat Dec 18, 2010 22:13    Post subject: Advanced VLAN and DHCP configuration Reply with quote
At the school district I am employed at we are looking at upgrading our wireless access points (WRT54Gv8's) to DD-WRT for its advanced functionality. I have played around with flashing the system and setting up virtual SSIDs and setting the antennas to be Tx/Rx but we need to have the following:

2 SSIDs, one "Secure" and one "Guest"
-The "Secure" SSID will have its DHCP come from a Windows server
-The "Guest" SSID will have its DHCP hosted by the Wireless Access Point
-The "Secure" SSID will have internet provided through the main gateway (SonicWall) and have access to server and printer resources
-The "Guest" SSID will have internet provided through an alternate internet subscription (cheap Comcast or Time Warner link) and will not have access to printer or server resources. This will be filtered by an old SonicWall and we want the Internet traffic to flow directly to this SonicWall and not affect registered computers.
-The "Guest" SSID force the user to agree to a network registration page before they are allowed to access the Internet.

Any guidance would be very appreciated. So far I am very impressed with DD-WRT and its many features for lower-quality (our) access points.

Scott
Sponsor
iso
DD-WRT Novice


Joined: 31 Aug 2006
Posts: 16
Location: West Chester, PA

PostPosted: Mon Dec 20, 2010 19:19    Post subject: Reply with quote
skot.fortin, checkout the two links here. phuzi0n helped me out with a similar config.

Multiple WLAN's wifi
http://www.dd-wrt.com/wiki/index.php/Multiple_WLANs

Multiple WLANs + Coverage
http://www.dd-wrt.com/phpBB2/viewtopic.php?t=84320
phuzi0n
DD-WRT Guru


Joined: 10 Oct 2006
Posts: 10141

PostPosted: Tue Dec 21, 2010 0:37    Post subject: Reply with quote
Btw I made this page to explain how to reconfigure 100mbit models so to avoid VLAN 0 so that they can be trunked with other equipment. I'll be explaining more about trunking soon but for now there's dozens of forum posts you can look up.

http://www.dd-wrt.com/wiki/index.php/Reconfigure_VLANs_for_802.1q_Compatibility

_________________
Read the forum announcements thoroughly! Be cautious if you're inexperienced.
Available for paid consulting. (Don't PM about complicated setups otherwise)
Looking for bricks and spare routers to expand my collection. (not interested in G spec models)
skot.fortin
DD-WRT Novice


Joined: 18 Dec 2010
Posts: 15

PostPosted: Wed Jan 05, 2011 3:59    Post subject: Reply with quote
OK,

So I get the setting up Virtual SSIDs and configuring security on those but bridging and VLANs are where I get a little confused.

http://www.dd-wrt.com/wiki/index.php/Reconfigure_VLANs_for_802.1q_Compatibility

On that page it says to configure them all to be assigned to bridge "LAN" but should I add the other bridges to the ports. Say I set up an outside Comcast link to come in and we want the traffic only operates on VLAN 5. I would, under VLAN 5, check Ports 1,2,3,4 and assign them to br1 (the guest bridge) right? Or would it still be LAN? br1 would then be assigned to the virtual SSID, "School Guest"

The regular LAN for trusted communication to our regular outside link would go on br0 and say VLAN 1. This means the non-virtual SSID "School Secure" would be bridged to br0 which is assigned to ports 1,2,3,4 on VLAN1.

Does that sound right?

Thank you ahead of time for your help, you guys are gods.

Scott
phuzi0n
DD-WRT Guru


Joined: 10 Oct 2006
Posts: 10141

PostPosted: Thu Jan 06, 2011 16:49    Post subject: Reply with quote
That page is just to configure the foundation for VLAN trunking. Afterwards you have to choose which VLAN's you want each port in and configure at least one of the ports to be tagged. The tagged port will be in all the VLAN's that you want carried through the trunk (1 and 5). VLAN 1 will be the VLAN for the main LAN and VLAN 5 will be bridged with the VAP in br1 so that the traffic from all the VAP's gets carried through the trunk ports to the other gateway.
_________________
Read the forum announcements thoroughly! Be cautious if you're inexperienced.
Available for paid consulting. (Don't PM about complicated setups otherwise)
Looking for bricks and spare routers to expand my collection. (not interested in G spec models)
skot.fortin
DD-WRT Novice


Joined: 18 Dec 2010
Posts: 15

PostPosted: Fri Jan 07, 2011 2:02    Post subject: Reply with quote
Perfect, that makes sense.

Now I assign br1 (the one connecting the VAP to VLAN 5) to interface wl0.1 and VLAN 5, correct?

Also, I see there is a "Tagging" button on

http://www.dd-wrt.com/wiki/index.php/Multiple_WLANs#Separating_the_WLAN.27s

Do I set that up?
phuzi0n
DD-WRT Guru


Joined: 10 Oct 2006
Posts: 10141

PostPosted: Fri Jan 07, 2011 17:00    Post subject: Reply with quote
skot.fortin wrote:
Also, I see there is a "Tagging" button on

http://www.dd-wrt.com/wiki/index.php/Multiple_WLANs#Separating_the_WLAN.27s

Do I set that up?

No, use the VLAN page to enable tagging on the trunk port and put the port in both VLAN's.

_________________
Read the forum announcements thoroughly! Be cautious if you're inexperienced.
Available for paid consulting. (Don't PM about complicated setups otherwise)
Looking for bricks and spare routers to expand my collection. (not interested in G spec models)
skot.fortin
DD-WRT Novice


Joined: 18 Dec 2010
Posts: 15

PostPosted: Fri Jan 07, 2011 22:44    Post subject: Reply with quote
OK, thanks,

This is what I got so far:

SSIDs
Security
VLANs
NetworkConfig

The switch is configured for VLAN 4 to be the secure wireless and VLAN 5 to be the public wireless.

Not sure if I have that bridging right...
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum