Greetings,
I could use some advice please.
A friend of mine owns a small nonprofit that has grown over the years. He’s been doing all the networking for all the computers as time allows and asked for help in overhauling it. I went and took a look.
His network is really managed in two different and very separate ways. LAN and wireless. They don’t really mix/interact well.
The LAN is essentially managed with the internet providers switch. It’s crazy simple.
The wireless is one cable from the LAN into an Apple Airport Extreme. From the back of that it goes into a switch. Any “LAN” devices that actually need to talk to the wireless network are plugged in here. Also, this building is old and made with thick brick and metal between the walls so signal is crap. He has a cable running out to half a dozen more Airport Extreme’s spread out every other room upstairs and downstairs. Where he couldn’t run a cable, he bridged via wifi (just one of these fortunately).
Security is nearly non-existent.
Essential computers, IOT, staff, volunteers, guests - all on the same network and everything is DHCP (including the apple wireless devices) so who knows what IP any device is going to have day to day. Even the Airport Extreme’s shift IP’s occasionally.
It’s a mess.
What I’m thinking about, is taking a good low-power system that I’ve got and starting with IPFire as the base system for firewall and network. I know I can address some of his concerns around QOS and security with IPFire as the device provided to him is basic-garbage. However, the wireless? I’m a bit stumped.
He’s a non-profit and doesn’t have a lot of excess cash nor budget. Even though the Airport Extremes are old, it’s what he’s got and can’t simply replace all of them. The Airport Extremes appear to be /very/ limited in what they can do and I’m not sure how to tie them into the same network as the LAN even with IPFire.
But even if I can get the Airport Extreme’s to work (or I end up with a miracle budget to replace with a device I can put OpenWRT on), I’m not sure how to address the concerns about a separate wifi for essential devices and a guest network for personal staff devices, volunteers, guests. When I’ve done this in the past it has been on a very small scale and my house is the biggest deployment of it. I’ve always setup one physical wireless device for trusted devices on Green or Blue and a second physical wireless device with the captive portal, QOS, filters, ect on the Orange interface. If I don’t have the budget to replace the existing wireless, I certainly don’t have the budget to double the wireless devices (not to mention running all that cable!). But if I put the wifi on the same network as the LAN (which is part of the hopeful plan as it would really help him to communicate with everything on his network from his laptop) then we are back to the same issue with all the devices talking on the same network that really shouldn’t be talking to each other.
I’ve never done this before, but let’s suppose I can replace the wireless devices with something I can put OpenWRT on. At that point, I think I can set up multiple wireless networks with VLAN’s so that there is separation from trusted and untrusted devices. And I’m pretty confident I can even configure it so that devices can hop between wireless AP’s without issues. However, I’m not sure at all how I’d tie those multiple wireless SSIDs/vlans back into IPFire so that one is on Green/Blue and the other is on Orange. Maybe that’s the wrong approach entirely.
Any thoughts or advice?
Is trying to continue to use Airport Extreme’s futile or could I actually make this work?
How challenging is it to take a single AP plugged into IPFire and split two wireless SSID’s to Blue and Orange (or maybe there is a better way to capture portal untrusted devices and put them on a separate network path with the same SSID??) ?
I’d appreciate any thoughts/help/guidance. Especially if there is a better way to design a solution.
[edit] I was searching for the wrong terms earlier. The “suggested topics” after I posted linked to one that pointed to this wiki page for VLANs wiki.ipfire.org - Zone Configuration . That seems simple enough. IF I can replace the wireless devices with OpenWRT then assigning a VLAN per wireless SSID and mapping that VLAN to different zones should be pretty easy. I think… haven’t done it yet.
I would still appreciate advice on the best way to approach this problem and if anyone has recommendations that might allow me to keep the existing wireless apple hardware.
Thanks!