From owner-freebsd-net@FreeBSD.ORG Wed Feb 6 19:47:43 2013 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.FreeBSD.org [8.8.178.115]) by hub.freebsd.org (Postfix) with ESMTP id 382C19C8 for ; Wed, 6 Feb 2013 19:47:43 +0000 (UTC) (envelope-from kurt.buff@gmail.com) Received: from mail-ee0-f48.google.com (mail-ee0-f48.google.com [74.125.83.48]) by mx1.freebsd.org (Postfix) with ESMTP id B69F53FB for ; Wed, 6 Feb 2013 19:47:42 +0000 (UTC) Received: by mail-ee0-f48.google.com with SMTP id t10so889092eei.7 for ; Wed, 06 Feb 2013 11:47:36 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:x-received:in-reply-to:references:date:message-id :subject:from:to:cc:content-type; bh=RzFvqAeMQr2DAF/Rwz1+jf617SnhMy14UWCEx4Yx1xs=; b=gU/G2OvkWTgNHApgk7s3PFmfw9VksHsHPhA3Pb6DmAYXu7eHCJiqJMOplh6eb9zSfg SVFKIchqnmblWPZxP1y+KOxWXHgrpiJ5jI3McswNPB6uYbvtILY0aKwLwZBZ2WWfEAdT md4LcoABt8UOVkscKfVIrpAVLGriQ2G5h/6gQ824PCZcDUA+F+KDHhfzBq+yvG0KFOjr gISQxlbPro/E8Zqmd1y2zJqkNfoBwdc+r1K4z7JJI+yt6Hmxs15wRAEfKUNhd6cFjJGa i6HOTwGawie2OEzET0sBhRADmYxirNYDKthNZRLCTbZe/1cRBpMGQN2Q7KtP+EWD1/Ma p0JA== MIME-Version: 1.0 X-Received: by 10.14.203.3 with SMTP id e3mr100623514eeo.9.1360180056458; Wed, 06 Feb 2013 11:47:36 -0800 (PST) Received: by 10.14.124.79 with HTTP; Wed, 6 Feb 2013 11:47:36 -0800 (PST) In-Reply-To: References: Date: Wed, 6 Feb 2013 11:47:36 -0800 Message-ID: Subject: Re: Guest network on corporate LAN - options for security From: Kurt Buff To: Adam Vande More Content-Type: text/plain; charset=UTF-8 Cc: freebsd-net@freebsd.org X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 06 Feb 2013 19:47:43 -0000 On Wed, Feb 6, 2013 at 11:38 AM, Adam Vande More wrote: > On Wed, Feb 6, 2013 at 1:29 PM, Kurt Buff wrote: >> >> All, >> >> If this isn't the right list for this, please let me know. >> >> Quite some time ago, I set up an unsecured guest VLAN in our network, >> providing wireless access to all of the sundry devices that staff and >> visitors carry. I set up a small FreeBSD machine to serve IP addresses >> via DHCP, and that was dead simple. >> >> However, there are now other tenants in our building, and the subnet >> is getting too much bandwidth and address consumption - the range I >> set up is completely filled, and the VLAN is consuming about half of >> our Internet pipe, which is far too much for my comfort. >> >> I suspect the other tenants are leeching. >> >> Does anyone have ideas on how I can leverage that FreeBSD box to control >> this? > > > If it were me, I would consider replacing the FreeBSD Box with PfSense. It > has a lot of managment features built in so if you're looking to get those > without a big time sink otherwise, something like that is the way to go. Thanks. I'll take a look at that. Kurt