PDA

View Full Version : Little bit of network setup advice.....



AmEv
06-12-2012, 03:11 PM
My dad wants my help configuring the WiFi setup for the local Scout summer camp.

What he wants:
One network with a blocked SSID and password, for the head staff. Unrestricted access. Simple enough.

One network with its name broadcasted, but still password protected. Restrict the amount of data that can go through. (possibly disable pictures?) For the leaders, but not for the youth. That's where I need your help.

What I have:
Two wireless routers
An IBM tower
The necessary cables

What I've thought of so far:

Hook the one wireless router directly into the modem.

Plug the 2nd router's Internet port into the 1st router.
Disable the DHCP service on it.
Make the IBM tower the DHCP server. When the leaders use it, it goes through the tower, then through the WAN port. This way, we can make sure that one doesn't hog the daily bandwidth to themselves.


I'm open to other ideas and solutions.

AmEv
06-14-2012, 04:35 PM
OK, got PFSense installed. Got into the Web GUI.

Let's see if I can figure this out in a week...

AmEv
06-15-2012, 05:10 PM
OK, that's weird.

I found that the best way to filter is THROUGH the computer, via two network cards.

However, it seems to disable the onboard network card when I try to insert a PCI card.

Gonna see what happens when I put in 2 PCI cards (or should I?)...

slaveofconvention
06-15-2012, 05:54 PM
The onboard network card shouldnt disable - thats just odd - more than one PCI card should still do the trick tho but I've never seen that happen and I have added gigabyte cards to pc's with 10.100 onboard in the past, then used the 10/100 port to download the drivers for the 10/100/1000

AmEv
06-15-2012, 06:10 PM
Yeah, it pops up with "Resource conflict in PCI device 'Network Adapter'" on the BIOS.

Got 2 PCI 10/100 cards installed. Seeing if it chews me out then.

AmEv
06-15-2012, 08:32 PM
OK, the onboard network card worked again. No need for 2.

Now, what's the best way in PFSense to enable limited Internet access based on device MAC address?
(Don't want it based on IP address, as that's easy to spoof on mobile devices. MAC address is harder, if not impossible, to spoof on mobile devices.

AmEv
06-15-2012, 11:17 PM
And it is routing SUCCESSFULLY!
In fact, I'm typing through it right now!


No conflicts, no noticeable lag, just waiting for final settings.
IBM's acting as the DHCP server.


All I need to do now is set it up so that it cuts off after so many megabytes of data consumed.

AmEv
06-16-2012, 01:43 PM
OK, today's the last day I can work on it...


It seems what I want is a "quota". Unfortunately, Google isn't being my friend right now.