Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Aironet 1200 Radius and Public Hotspot

A client has an Aironet 1200 AP and currently they have Radius set up to allow Microsoft domain users access to the LAN. They now want to set up public access to the internet for guests as well.

Our initial thought was to set up another SSID and ACL the ports we would allow the guests to use. I can't seem to find any documentation that shows me how to do this... and I'm not very familiar with the 1200 or Cisco for that matter.

Further, it appears that VLAN's might be a requirement in this scenario, and this isn't possible with our current hardware.

I need to allow domain users access to the LAN resources via secure Radius authentication. I need to allow anyone off the street access to the internet and deny access to anything on the LAN. I need to do this with one Aironet 1200.

Can anyone help?

Aironet Software Version: 12.3(7)JA

5 REPLIES
Silver

Re: Aironet 1200 Radius and Public Hotspot

To configure RADIUS-based VLAN access control. For example, if the WLAN setup is such that all VLANs use IEEE 802.1x and similar authentication mechanisms for WLAN user access, the user can hop from one VLAN to another by changing the SSID and successfully authenticating to the access point. However, this process may not be ideal if the wireless user is to be confined to a particular VLAN.Refer the follwoing URL for more information about vlan on 1200 AP

http://www.cisco.com/en/US/products/hw/wireless/ps430/products_configuration_guide_chapter09186a00800e02cb.html

New Member

Re: Aironet 1200 Radius and Public Hotspot

I have been told that we can't use VLAN's with our current switches and router. Unless the VLAN is used only inside of the 1200, this isn't an option for us. Can this be done without VLAN's?

Hall of Fame Super Silver

Re: Aironet 1200 Radius and Public Hotspot

If you can't configure vlans on a switch and your router doesn't support 802.1q trunking, you can't configure vlans on the access point. The reason being, each ssid will be mapped to a vlan and the access point switch port will have to be trunked.

-Scott
*** Please rate helpful posts ***
New Member

Re: Aironet 1200 Radius and Public Hotspot

So is it possible to do this without creating VLAN's?

Hall of Fame Super Silver

Re: Aironet 1200 Radius and Public Hotspot

There is no way you can do this if you are limited to a single subnet. You have to be able to define your acl's on a interface, usually from your guest subnet to you inside network. Since you have a single subnet, guest users will acquire DHCP from the same subnet as your current wireless users. this is what you don't want. you have to get a l3 switch or a router that supports 802.1q trunk.

-Scott
*** Please rate helpful posts ***
1381
Views
0
Helpful
5
Replies
CreatePlease login to create content