Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Configuring Guest Access

Posted on 2007-11-20
1
947 Views
Last Modified: 2013-11-09
I'm needing help configuring a wireless guest network. I've never setup a vlan and need some guidance. We have HP 420 wireless access points (with the default ssid using 802.1x), HP 5400 switches (running at layer 2); and Cisco 2800 series routers. Right now everyone is on default vlan 1. I want to make the guest vlan 5.  
The router seems to be the big question for me. How do I configure the router for the new vlan and how do I word the ACL to limit the guest users?
0
Comment
Question by:gaskew
1 Comment
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 20331265
Can't help with the HP switch, but make sure you set the port that the router connects into as a trunk port and include vlan 1 and vlan 5.

On the router, setup a vlan subinterface:

interface Fastethernet 0/0.5
 encap dot1q 5
 ip address 10.20.30.1 255.255.255.0
 ip nat inside
 access-group 101 in

Add whatever IP subnet you are assigning to the guest wireless vlan to the nat acl:

access-list 1 permit 10.20.30.0 0.0.0.255  <= guest vlan
access-list 1 permit 10.10.10.0 0.0.0.255  <= internal LAN
ip nat inside source list 1 interface serial0/0/0 overload  <== whatever you have already

To restrict access between the networks, define acl 101 that gets applied to the interface:
 access-list 101 deny ip 10.20.30.0 0.0.0.255 10.10.10.0 0.0.0.255
 access-list 101 permit ip any any

Done

0

Featured Post

How our DevOps Teams Maximize Uptime

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us. Read the use case whitepaper.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Connect two buildings 6 47
Home internet speed 20 30
Site cannot be reached ONLY when connected to modem 18 32
snmp v2 configuration on a switch 3 14
The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
This paper addresses the security of Sennheiser DECT Contact Center and Office (CC&O) headsets. It describes the DECT security chain comprised of “Pairing”, “Per Call Authentication” and “Encryption”, which are all part of the standard DECT protocol.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question