guest access only internet

Unanswered Question
Apr 4th, 2009
User Badges:

I have Cisco 1230AP's providing access to my LAN for laptop users. The encryption is via WPA. I now need to setup my guests/visitors - keeping them away from my LAN and internal network and they can only (guest) use internet but all employs should use intranet & internet . How can I do this? Do I just setup a 2nd SSID or do I need to implement some type of VLAN? My switch is 3750 managed AND my internet is terminet on firwall.Thanks for your help...

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Scott Fella Sat, 04/04/2009 - 08:56
User Badges:
  • Super Silver, 17500 points or more
  • Hall of Fame,

    The Hall of Fame designation is a lifetime achievement award based on significant overall achievements in the community. 

  • Cisco Designated VIP,

    2017 Wireless

If you are running autonomous AP's then you can create another ssid and another vlan. Configure the switchport the ap is connected to as a dot1q trunk with the native vlan being the subnet the ap management ip is on. Then force that guest vlan to your FW. Don't configure any L3 interface on your internal, but on your FW for the guest. At least you can isolate the guest vlan until it hits your FW where you can create your policies.


http://www.cisco.com/en/US/docs/wireless/access_point/12.3_7_JA/configuration/guide/s37ssid.html



Actions

This Discussion

 

 

Trending Topics - Security & Network