Page 1 of 1

WiFi and LAN ports on separate, unroutable subnets?

Posted: Wed Sep 01, 2010 4:29 pm
by Dschinghis
Love Gargoyle, use it at home and I'm completely satisfied. However, I'm considering using it for a small medical practice to handle their networking and I can't find a way to configure it the way I'd like.

Here in the States, there are some pretty stringent laws about patient record privacy. The internal network which connects the servers housing the patient records needs to be a completely separate subnet from the WLAN. I'm trying to keep costs and complexity down as much as possible, so I'd prefer to do this with a single piece of hardware (thinking ASUS WL-500gp).

Is there any way to configure Gargoyle to keep the WLAN and LAN subnets completely separate? It needs to be able to offer unrestricted WAN access to anyone connecting over wifi while offering no means of routing packets between the WLAN and LAN for HIPPA compliance.

Sorry if this has been covered before, I searched and didn't turn anything up. I appreciate any input people may have.

Cheers!

Re: WiFi and LAN ports on separate, unroutable subnets?

Posted: Wed Sep 01, 2010 5:28 pm
by pbix
I have a saying that with time and money anything is possible.

The trouble here is that a second router costs about $40 so what can you do for $40 in a medical office if you consider the value of the item it takes to do it? How about practially nothing.

There is no way to do this using Gargoyle UI on a single router. But Gargoyle in based on OpenWRT and there is almost nothing that cannot be accomplished using scripts and configuration run from the command line. The trouble is you will exceed your $40 budget in labor costs in the time it takes Obama to reduce your medicare payments.

Now if you are the curious network guru type like many of us are you can investigate the power of OpenWRT and after a few weeks you can get this to work.

If you want the fast, cheap and easy way buy a second router. Use one for the Wifi access and the other for your protected LAN.