Solved

Configuring Guest Access

Posted on 2007-11-20
1
943 Views
Last Modified: 2013-11-09
I'm needing help configuring a wireless guest network. I've never setup a vlan and need some guidance. We have HP 420 wireless access points (with the default ssid using 802.1x), HP 5400 switches (running at layer 2); and Cisco 2800 series routers. Right now everyone is on default vlan 1. I want to make the guest vlan 5.  
The router seems to be the big question for me. How do I configure the router for the new vlan and how do I word the ACL to limit the guest users?
0
Comment
Question by:gaskew
1 Comment
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 20331265
Can't help with the HP switch, but make sure you set the port that the router connects into as a trunk port and include vlan 1 and vlan 5.

On the router, setup a vlan subinterface:

interface Fastethernet 0/0.5
 encap dot1q 5
 ip address 10.20.30.1 255.255.255.0
 ip nat inside
 access-group 101 in

Add whatever IP subnet you are assigning to the guest wireless vlan to the nat acl:

access-list 1 permit 10.20.30.0 0.0.0.255  <= guest vlan
access-list 1 permit 10.10.10.0 0.0.0.255  <= internal LAN
ip nat inside source list 1 interface serial0/0/0 overload  <== whatever you have already

To restrict access between the networks, define acl 101 that gets applied to the interface:
 access-list 101 deny ip 10.20.30.0 0.0.0.255 10.10.10.0 0.0.0.255
 access-list 101 permit ip any any

Done

0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

This article is a step by step guide on how to create a basic PTP link using Ubiquiti airOS devices. This guide can be used on the following Ubiquiti AirMAX devices. Nanostation, Bullets, AirBridge, Nanobeam, NanoBridge to name a few. Please review …
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now