<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Guest Access Secure Enough? in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/guest-access-secure-enough/m-p/1042096#M12940</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The reason why using like setting up acl's on the wlc is because it really doesn't work as well depending on your rules.  ACL's are better managed on the L3 interface.&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Sep 2008 18:55:20 GMT</pubDate>
    <dc:creator>Scott Fella</dc:creator>
    <dc:date>2008-09-24T18:55:20Z</dc:date>
    <item>
      <title>Guest Access Secure Enough?</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-secure-enough/m-p/1042093#M12937</link>
      <description>&lt;P&gt;Equipment: 2106 controller, 1131AG, WCS 5.1.151&lt;/P&gt;&lt;P&gt;Internal users: Connect to 192.168.x.x network as normal wired users would.  Authenticate through a radius server connected to AD.  WPA2 used. Vlan1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Guest Users: Connect to controller through web-auth, DHCP on controller, Vlan2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL Guest rules (In sequence):&lt;/P&gt;&lt;P&gt;1. Permit  SourceIP 0.0.0.0 / 0.0.0.0 Destination IP 192.168.1.5/255.255.255.255 (firewall)&lt;/P&gt;&lt;P&gt;2.  Deny SourceIP 0.0.0.0 / 0.0.0.0  Destination IP 192.168.0.0/255.255.0.0&lt;/P&gt;&lt;P&gt;3.  Permit  SourceIP 0.0.0.0 / 0.0.0.0 Destination IP 0.0.0.0 / 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that the suggested method for the guest Wlan is to be in the DMZ on a separate controller.  As each location has its own firewall/internet connection I find this solution expensive, an administrative nightmare, and probably overkill.  My question is:  Is my guest access secure enough with web-auth, separate vlan, and the access control list?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 23:31:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-secure-enough/m-p/1042093#M12937</guid>
      <dc:creator>toddgermana</dc:creator>
      <dc:date>2021-07-03T23:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Access Secure Enough?</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-secure-enough/m-p/1042094#M12938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I personally don't like to use the ACL feature on the wlc.  Why not create acl's on the L3 interface of vlan 2 to deny guest network to internal network.  If you have a different internet connection for guest, you can use one of the available ports for the guest traffic.  This is specifed in the interface you create for guest.  If you have one internet connection, then create acl's on the l3 switch.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2008 00:39:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-secure-enough/m-p/1042094#M12938</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2008-09-24T00:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Access Secure Enough?</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-secure-enough/m-p/1042095#M12939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why/What don't you like on WCS ACL?  Is adding the ACL to the vlan as a secondary precaution create enough security (plus the web-auth)?  Also, I don't have another internet connection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2008 13:56:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-secure-enough/m-p/1042095#M12939</guid>
      <dc:creator>toddgermana</dc:creator>
      <dc:date>2008-09-24T13:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Access Secure Enough?</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-secure-enough/m-p/1042096#M12940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The reason why using like setting up acl's on the wlc is because it really doesn't work as well depending on your rules.  ACL's are better managed on the L3 interface.&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2008 18:55:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-secure-enough/m-p/1042096#M12940</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2008-09-24T18:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Access Secure Enough?</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-secure-enough/m-p/1042097#M12941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had to double check with one of Cisco's engineers and he came up with the some solution.  Thanks for your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2008 12:04:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-secure-enough/m-p/1042097#M12941</guid>
      <dc:creator>toddgermana</dc:creator>
      <dc:date>2008-09-25T12:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Access Secure Enough?</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-secure-enough/m-p/1042098#M12942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have a guest internet dmz in place, you can simply connect one of the physical distribution ports to the dmz, and have the guest wlan pointing to that interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Nov 2008 17:34:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-secure-enough/m-p/1042098#M12942</guid>
      <dc:creator>steve.gordon</dc:creator>
      <dc:date>2008-11-26T17:34:03Z</dc:date>
    </item>
  </channel>
</rss>

