Solved

Internet for Guests

Posted on 2014-02-02
4
271 Views
Last Modified: 2014-03-02
Hello Experts,

We have a Cisco Switch 3750G configured with 10 L3 VLANS. I am going to introduce Internet ADSL Router for guests only.

I have 5 AP distributed. The AP's will have 2 SSID  Guest and Corporate).

What would be the best way to setup network for guests to access internet only, while isolating our internal network subnet?
0
Comment
Question by:cciedreamer
  • 2
4 Comments
 
LVL 5

Accepted Solution

by:
dinkytoy101 earned 500 total points
Comment Utility
Couple of possible options:

1. If only the only thing to guest -> internet then make them all the same layer 2 vlan and the default gateaway on the ADSL router. The 3750 is just passing them through so no access to the rest of the network. Quick and easy.

2. Not sure if the 3750 supports it but you could create a Guest VRF and route their traffic separately. More complex but scalable solution.

Not sure how you are handling any firewall/security bits though.
0
 
LVL 15

Expert Comment

by:The_Warlock
Comment Utility
You can probably get away with using web authentication for the guest users and EAP for those on the Internal wlan. There are alot of different ways to achieve the same goal. Below you will find two examples listed but ultimately it comes down to your needs and your equipment available and or its capabilities. I hope this helps.

http://www.cisco.com/en/US/docs/wireless/technology/guest_access/technical/reference/4.1/GAccess_41.html


http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a008070ba8f.shtml
0
 
LVL 3

Author Comment

by:cciedreamer
Comment Utility
Thank you experts for the response.

From the above comments I have got 2 options

Option 1 ( no money involved) : Create a Vlan on the Switch without layer 3 ip addressing.
and Connect the router to this vlan. Then configure AP's SSID be in this vlan. The client will get the DHCP IP address from the router and it will be there defaul gateway

Option 2 ( money involved): This could be achieved by getting WLC. which is currently not our requirement. But I would be interested to know how much it can cost me to use for other customers lets say they have AP's more than 100.

Thanks
0
 
LVL 3

Author Closing Comment

by:cciedreamer
Comment Utility
I am going with Option 1
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Introduction This article explores the design of a cache system that can improve the performance of a web site or web application.  The assumption is that the web site has many more “read” operations than “write” operations (this is commonly the ca…
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now