Traditionally to separate my wireless low-security network from my high security wired one of a few linux boxen I've used two el cheapo routers in a double nat config (cable modem -> wireless router -> wired router -> desktops).
This allows me to have services like samba open on the wired network, and to allow access to them from the wireless network by poking a hole for the ssh port and making wireless users authenticate over ssh. Having read the article recently about vlans it seems that there should be a cleaner way using them to implement this security model. How would I set up a router and vlan-capable switch to (1) completely separate the wireless and wired traffic, while (2) allowing the wireless network access to the wired one through ssh?
Thanks in advance for any clues for the vlan noob.
This allows me to have services like samba open on the wired network, and to allow access to them from the wireless network by poking a hole for the ssh port and making wireless users authenticate over ssh. Having read the article recently about vlans it seems that there should be a cleaner way using them to implement this security model. How would I set up a router and vlan-capable switch to (1) completely separate the wireless and wired traffic, while (2) allowing the wireless network access to the wired one through ssh?
Thanks in advance for any clues for the vlan noob.