Question on Aironet 1400 with Visitor and Employee VLANs

May 16, 2006 2 Replies

I have configured my aironet with a Visitor and a Guest SSID/VLAN but I have not done anything else. The problem is that I want to completely isolate visitors by connecting their VLAN to my internet router in front of our firewall which is a PIX 501 but that would mean no nat, dhcp, or dns. My plan is to purchase a Linksys router/firewall and to connect a hub to the router and then connect the PIX and Linksys in Parallel. This way the linksys would do NAT and DHCP for visitors and they would never need access to anything on my network. Any suggestions?



Thanks



Here is the way i do it;

-Access-point -Guest SSID/VLAN no encryption , no authentication

-Coreswitch -Vlan Guest -ip helper-address to allow dhcp request -acl denying access to local lan and permitting anything else

-PIX -aaa authentication include ip inside [dchp pool for guest] 0.0.0.0

0.0.0.0 local -username guest password blabla encrypted privilege 2

So when the guests connects to the AP, they gets an IP from the DHCP. Then they have to initiate whatever http request , to be authenticated by the PIX. Once authentication is done they have full access ( not only http).

I post the username / password in conference rooms , and change it monthly. If you don't put any authentication at all, your internet bandwidth may get stolen by unauthorised visitors from outside the building.

Depending on your switch environment , it may be possible for you to have a simple solution without adding any hardware.

Hello mcaissie

Thanks for some great advice. I mistakenly said Aironet 1400 when I meant 1231. Anyway, I am considering EAP-TLS for staff who bring in laptops from home. I do not want to force them to join the domain and I want only a little admin work but I want good security. If you have any ideas I would appreciate hearing them.

thanks

mcaissie wrote:

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required