We help IT Professionals succeed at work.

Guest SSID config on Cisco AP

458 Views
Last Modified: 2015-02-18
Here is the scenario:
I have two Cisco AP's  and one Fortigate Firewall. The AP's are directly connected to the inside zone of Fortigate firewall 60D.
Model of CIsco AP: AIR-SAP702i-N-K9
Model of Fortigate Firewall is: Fortigate 60D.

On Fortigate firewall 60D, we have 8 ports facing inside network, one is connected to outside network(to ISP) and other is connected to DMZ.

Here I wish to configure Guest SSID and User SSID on Cisco AP which is in standalone mode.  I have configured User SSID and both are working fine. The inside network is 192.168.1.0/24 and Gateway is 192.168.1.99.

Need help to configure Guest SSID on AP and the changes required on the Fortigate firewall. Assume Port 1 & 2 are connected to Cisco AP.

Thanks
Sub
Comment
Watch Question

some oneNetwork Architect
CERTIFIED EXPERT
Top Expert 2014
Commented:
This one is on us!
(Get your first solution completely free - no credit card required)
UNLOCK SOLUTION
Subhashis SahooTechnical Consultant

Author

Commented:
As for domain users, we have a SSID created and need to configure for Guest. The domain users are in default vlan 1.
Pls correct me if I am wrong:
We need to create one more vlan for Guests users on Fortigate firewall.
Create a Guest SSID on both AP's. Associate to the Guest Vlan and map it to the port.
make the port as trunk port on Fortigate firewall (connected to AP) allowing both the vlans to pass through.
Create access rules on Fortigate firewall 60 D.
Assume the domain users are in subnet 192.168.1.0/24. gateway of firewall is 192.168.1.99. and Guest Users to be in 172.168.10.0/24

My question:
How do we make it as trunk port on Forigate firewall 60D. Any documents supporting the config for Fortigate 60 D will be helpful,.

Thanks
Subhashis
This one is on us!
(Get your first solution completely free - no credit card required)
UNLOCK SOLUTION
Unlock the solution to this question.
Join our community and discover your potential

Experts Exchange is the only place where you can interact directly with leading experts in the technology field. Become a member today and access the collective knowledge of thousands of technology experts.

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.