Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Simplified guest access

Reading the Cisco Guest access deployment senarios again becomes a little unclear.

Lets assume 3 scenarios.

1 Small office

4 access points

1 2106 controller

This will give simpl guest access terminate the guest vlan in an adsl router and a web auth page and use the wlc to manage guest client access

2 Multiple small offices

2 offices each with 2 APs

2106 in each och office

The guest access woul have to be terminatin a 4402 12 as I cant use 3rd 2106 to terminate and originate the guest access? The 2106s locally will pass the guest access through.

3 Large enterprise.

5 4404 controllers

Would I simply use a 4402 to terminate and distribute the guest acccess as a central guest database.

I have deliberately not mentioned DMZ as to simp[lify the scenarios.


Hall of Fame Super Silver

Re: Simplified guest access

First look at the traffic flow. If you have a decent conection back to the central location and this is the only internet connection, then tunneling traffic back via local or h-reap would be the best bet. If the offices have thier own internet dsl, adsl, etc, then maybe sending the traffic out at the local sites would be your best choice. It also goes hand in hand with how you will desing the wlan for their internal users and devices not including guest. You can design this many ways, but it will come down to if you place wlc's in each location vs. centralized deployment.

*** Please rate helpful posts ***
CreatePlease to create content