Solved

Internet for Guests

Posted on 2014-02-02
4
283 Views
Last Modified: 2014-03-02
Hello Experts,

We have a Cisco Switch 3750G configured with 10 L3 VLANS. I am going to introduce Internet ADSL Router for guests only.

I have 5 AP distributed. The AP's will have 2 SSID  Guest and Corporate).

What would be the best way to setup network for guests to access internet only, while isolating our internal network subnet?
0
Comment
Question by:cciedreamer
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 5

Accepted Solution

by:
dinkytoy101 earned 500 total points
ID: 39827701
Couple of possible options:

1. If only the only thing to guest -> internet then make them all the same layer 2 vlan and the default gateaway on the ADSL router. The 3750 is just passing them through so no access to the rest of the network. Quick and easy.

2. Not sure if the 3750 supports it but you could create a Guest VRF and route their traffic separately. More complex but scalable solution.

Not sure how you are handling any firewall/security bits though.
0
 
LVL 15

Expert Comment

by:Robert Sutton Jr
ID: 39827703
You can probably get away with using web authentication for the guest users and EAP for those on the Internal wlan. There are alot of different ways to achieve the same goal. Below you will find two examples listed but ultimately it comes down to your needs and your equipment available and or its capabilities. I hope this helps.

http://www.cisco.com/en/US/docs/wireless/technology/guest_access/technical/reference/4.1/GAccess_41.html


http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a008070ba8f.shtml
0
 
LVL 3

Author Comment

by:cciedreamer
ID: 39828792
Thank you experts for the response.

From the above comments I have got 2 options

Option 1 ( no money involved) : Create a Vlan on the Switch without layer 3 ip addressing.
and Connect the router to this vlan. Then configure AP's SSID be in this vlan. The client will get the DHCP IP address from the router and it will be there defaul gateway

Option 2 ( money involved): This could be achieved by getting WLC. which is currently not our requirement. But I would be interested to know how much it can cost me to use for other customers lets say they have AP's more than 100.

Thanks
0
 
LVL 3

Author Closing Comment

by:cciedreamer
ID: 39898248
I am going with Option 1
0

Featured Post

Flexible connectivity for any environment

The KE6900 series can extend and deploy computers with high definition displays across multiple stations in a variety of applications that suit any environment. Expand computer use to stations across multiple rooms with dynamic access.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Hit router interface limit 7 76
SMPS issue 1 71
Cisco TACACS+ appliance run same IOS as Cisco routers/switches 7 76
can you connect modem to 2 routers 42 24
If you are thinking of adopting cloud services, or just curious as to what ‘the cloud’ can offer then the leader according to Gartner for Infrastructure as a Service (IaaS) is Amazon Web Services (AWS).  When I started using AWS I was completely new…
In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

732 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question