I Have a Wifi manageable switch. I have 10 users to whom i want to provide wifi connection. what kind of rule i have to make in my TMG so that all thse users automatically receives IP from wifi switch.  Should i need to create DHCP rule in TMG firewall?

I Have a Wifi manageable switch. I have 10 users to whom i want to provide wifi connection. what kind of rule i have to make in my TMG so that all thse users automatically receives IP from wifi switch.

Should i need to create DHCP rule in TMG fir

January 16th, 2014 8:56am

Hi,

Thank you for your post here.

Do you mean that TMG is between wifi switch and wifi users?

If yes, you should create an access rule to allow DHCP traffic go through the TMG.

And if you need wifi users can access internet, you still need create access rules for thess users

Best Regards

Quan Gu

Free Windows Admin Tool Kit Click here and download it now
January 18th, 2014 2:03pm

Exactly wifi switch is between wifi users and TMG.

well i made a rule:

Source : Local. Destination : Wifi ip address Range. Protocol: DHCP(request)

Source : Wifi ip address range. Destination: External. DHCP(reply)

so please let me know that it will work or not??

and one more thing should i need to set proxy on my wifi router??

January 20th, 2014 7:31am

Hi,

Thank you for your update.

  1. If your Wifi router has been set to obtain IP via DHCP, you should create access rule as you did above
  2. Where is your DHCP server? If your DHCP server is wifi router itself. You do not need to create access rule to allow DHCP for WIFI
    clients. If DHCP server is located in the other side of TMG, You need to
    configure DHCP replay agent to help you

Best Regards

Quan Gu 

Free Windows Admin Tool Kit Click here and download it now
January 20th, 2014 9:00pm

Hi,


Thanks for the answer.

First of all i am going to tell you what i have did in firewall policy

Step 1: I am not using any DHCP server. TMG is a standalone server.

Step 2: I create an Address range for wifi clients range from 10.0.0.181 to 10.0.0.182

Step 3: I made a rule as i mentioned above.

Step 4: I configured my Router with an IP 10.0.0.181 S/M : 255.0.0.0

thats all what i have did. Now what i get from your answer is

As u mentioned that i dont need to have any DHCP rule if my wifi router is itself a DHCP server.so i will disable the rule. i will perform it nd will let you know. Kindly keep helping me because your suggestions is very much helpful for me.

January 21st, 2014 7:46am

Hi,

I think your topology like this:

TMG-------------WIFI AP--------------- WIFI clients

You WIFI AP act as DHCP server which service for WIFI clients.

Some additional issue that you should take care of:

  1. WIFI AP (Switch) should work under FAT AP mode.
  2. WIFI AP should be  your WIFI clients default gateway
  3. The relationship between WIFI AP and TMG should be route(it means that there must be 3-layer relationship not 2-layer)
  4. I create an Address range for wifi clients range from 10.0.0.181 to 10.0.0.182------- Why you only define two IPs for WIFI clients? If the ip 10.0.0.181 is APs ip and this ip is also the default gateway for WIFI client, right?
  5. I cannot see any IP range used to connect TMG and WIFI AP
  6. WIFI AP should create a default route which next-hop points to TMG.
  7. TMG need to create a route for WIFI clients subnet and its next-hop should be the IP address which is used to connect TMG by AP.
  8. TMG should create an access rule to allow the IP range used by WIFI clients.

In general, the whole process like this:

WIFI client want to access internet, it should reach its default gateway (WIFI AP, also act as DHCP server) at first. Then AP would forward the traffic to TMG based on it default route. TMG could help to forward the packets to the destination. When the packets come back, TMG could forward the traffic to WIFI AP based on it static route (should be created on step7).

Hope it is helpful for you.

Best Regards

Quan Gu


Free Windows Admin Tool Kit Click here and download it now
January 22nd, 2014 12:51am

Hi,

I think your topology like this:

TMG-------------WIFI AP--------------- WIFI clients

You WIFI AP act as DHCP server which service for WIFI clients.

Some additional issue that you should take care of:

  1. WIFI AP (Switch) should work under FAT AP mode.
  2. WIFI AP should be  your WIFI clients default gateway
  3. The relationship between WIFI AP and TMG should be route(it means that there must be 3-layer relationship not 2-layer)
  4. I create an Address range for wifi clients range from 10.0.0.181 to 10.0.0.182------- Why you only define two IPs for WIFI clients? If the ip 10.0.0.181 is APs ip and this ip is also the default gateway for WIFI client, right?
  5. I cannot see any IP range used to connect TMG and WIFI AP
  6. WIFI AP should create a default route which next-hop points to TMG.
  7. TMG need to create a route for WIFI clients subnet and its next-hop should be the IP address which is used to connect TMG by AP.
  8. TMG should create an access rule to allow the IP range used by WIFI clients.

In general, the whole process like this:

WIFI client want to access internet, it should reach its default gateway (WIFI AP, also act as DHCP server) at first. Then AP would forward the traffic to TMG based on it default route. TMG could help to forward the packets to the destination. When the packets come back, TMG could forward the traffic to WIFI AP based on it static route (should be created on step7).

Hope it is helpful for you.

Best Regards

Quan Gu


January 22nd, 2014 8:49am

Hi,

I think your topology like this:

TMG-------------WIFI AP--------------- WIFI clients

You WIFI AP act as DHCP server which service for WIFI clients.

Some additional issue that you should take care of:

  1. WIFI AP (Switch) should work under FAT AP mode.
  2. WIFI AP should be  your WIFI clients default gateway
  3. The relationship between WIFI AP and TMG should be route(it means that there must be 3-layer relationship not 2-layer)
  4. I create an Address range for wifi clients range from 10.0.0.181 to 10.0.0.182------- Why you only define two IPs for WIFI clients? If the ip 10.0.0.181 is APs ip and this ip is also the default gateway for WIFI client, right?
  5. I cannot see any IP range used to connect TMG and WIFI AP
  6. WIFI AP should create a default route which next-hop points to TMG.
  7. TMG need to create a route for WIFI clients subnet and its next-hop should be the IP address which is used to connect TMG by AP.
  8. TMG should create an access rule to allow the IP range used by WIFI clients.

In general, the whole process like this:

WIFI client want to access internet, it should reach its default gateway (WIFI AP, also act as DHCP server) at first. Then AP would forward the traffic to TMG based on it default route. TMG could help to forward the packets to the destination. When the packets come back, TMG could forward the traffic to WIFI AP based on it static route (should be created on step7).

Hope it is helpful for you.

Best Regards

Quan Gu


Free Windows Admin Tool Kit Click here and download it now
January 22nd, 2014 8:49am

i have received an error code 12206: proxy chain loop. when i am trying to connect my wifi router through WAN port. how to resolve it
January 27th, 2014 12:54am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics