08-04-2009 07:08 AM - edited 07-03-2021 05:54 PM
Is there an example that somebody can give me to setup a guest wireless network that only has access to the internet through a vlan that does not use a wireless controller? I am looking for any suggestions.
Thank you
Solved! Go to Solution.
08-04-2009 08:35 AM
Here is an example using ACL's to create a guest network. This prevents internal users from accessing internal private addresses and allows them to the internet.
interface Vlan199
description Guest
ip address 10.97.199.1 255.255.255.0
ip access-group 199 in
ip helper-address 10.xx
ip helper-address 10.xx
access-list 199 permit eigrp any any
access-list 199 permit udp any any eq bootps
access-list 199 deny ip any 10.0.0.0 0.255.255.255
access-list 199 deny ip any 172.16.0.0 0.15.255.255
access-list 199 deny ip any 192.168.0.0 0.0.255.255
access-list 199 permit ip any any
08-04-2009 07:31 AM
We use VRF on our 6500's, combined with WiSM's (in the 6500's), to shunt guest network traffic straight out to the inTARwebs. The Guest network definition on the WiSM is a different VLAN than the private network.
08-04-2009 07:37 AM
I have a 1231 AP connected to a 2960 switch which is connected to a 2811 router. I am using RADIUS to authenicate the users on the AD controller. I do not have a 6500 switch
Thank you
08-04-2009 08:35 AM
Here is an example using ACL's to create a guest network. This prevents internal users from accessing internal private addresses and allows them to the internet.
interface Vlan199
description Guest
ip address 10.97.199.1 255.255.255.0
ip access-group 199 in
ip helper-address 10.xx
ip helper-address 10.xx
access-list 199 permit eigrp any any
access-list 199 permit udp any any eq bootps
access-list 199 deny ip any 10.0.0.0 0.255.255.255
access-list 199 deny ip any 172.16.0.0 0.15.255.255
access-list 199 deny ip any 192.168.0.0 0.0.255.255
access-list 199 permit ip any any
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: