Security – Preventing local network access on wireless network

internetlocal-area-networkSecuritywifi

On our current network, we have a wireless router and a gigabit 16-port switch. If a machine connects to the wireless network, they have access to all of the local machines in the network. This can be a security risk as it is a PC repair shop and we leave machines still connected to the network.

What I would like to do is, using a separate wireless router (in this case the Netgear WGT624), setup an internet only wireless network and then possibly disable the wireless network on the main wireless router.

I have setup a Windows Server 2008 R2 machine which runs DNS and DHCP along with AD, Sharepoint Services, MDT and WDS. Active Directory is only really used for MDT.

How would I go about, or how would you recommend I set it up in this way?

Best Answer

You can just place the NAT routers in series, one behind the other. The first NAT closest to the Internet connection can be the wireless with access to only the Internet. The second NAT can contain the wired network and its wireless capabilities can be disabled as well.

This configuration will protect the wired network from the wireless network. Just ensure that both NAT networks are not on conflicting IP plans.