<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Guest SSID in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870952#M145698</link>
    <description>&lt;P&gt;Hello &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i want to configure a guest SSID on WLC 4400 series &lt;/P&gt;&lt;P&gt;but i want it to go direct to the internet i mean it can not use the corporate network (server and other applications)&lt;/P&gt;&lt;P&gt;and i want layer 2 security on it WPA2&lt;/P&gt;&lt;P&gt;as i know i need to configure a internal DHCP pool on the controller it self for the guest users vlan right?&lt;/P&gt;&lt;P&gt;and map that to guest ssid.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it is not web authentication so shall i need to configure any access list for this subnet or no need?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any seggustion please&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks in advance&lt;/P&gt;</description>
    <pubDate>Sun, 04 Jul 2021 04:17:50 GMT</pubDate>
    <dc:creator>john smith</dc:creator>
    <dc:date>2021-07-04T04:17:50Z</dc:date>
    <item>
      <title>Guest SSID</title>
      <link>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870952#M145698</link>
      <description>&lt;P&gt;Hello &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i want to configure a guest SSID on WLC 4400 series &lt;/P&gt;&lt;P&gt;but i want it to go direct to the internet i mean it can not use the corporate network (server and other applications)&lt;/P&gt;&lt;P&gt;and i want layer 2 security on it WPA2&lt;/P&gt;&lt;P&gt;as i know i need to configure a internal DHCP pool on the controller it self for the guest users vlan right?&lt;/P&gt;&lt;P&gt;and map that to guest ssid.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it is not web authentication so shall i need to configure any access list for this subnet or no need?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any seggustion please&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks in advance&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 04:17:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870952#M145698</guid>
      <dc:creator>john smith</dc:creator>
      <dc:date>2021-07-04T04:17:50Z</dc:date>
    </item>
    <item>
      <title>Guest SSID</title>
      <link>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870953#M145699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you try can something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WLC -- L2/L3 switch (with l2 vlan for guest traffic) -- firewall (Cisco ASA) -- Internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;once you create the guest ssid on the wlc and map it to a dynamic interface (say vlan 100). create a vlan 100 on the switches along the path between WLC and firewall. Make sure that vlan 100 is purely layer 2 along the path i.e there is not SVI interface on any of the switches. You can define the gateway for vlan 100 on the firewall and configure the firewall to route traffic for vlan 100 directly to the internet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Dec 2011 13:43:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870953#M145699</guid>
      <dc:creator>Viten Patel</dc:creator>
      <dc:date>2011-12-26T13:43:52Z</dc:date>
    </item>
    <item>
      <title>Guest SSID</title>
      <link>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870954#M145700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what about if i configure a local DHCP pool for the guest users vlan and it will not go through virtual interface and will be isolated from he corporate network?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Dec 2011 19:18:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870954#M145700</guid>
      <dc:creator>john smith</dc:creator>
      <dc:date>2011-12-26T19:18:42Z</dc:date>
    </item>
    <item>
      <title>Guest SSID</title>
      <link>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870955#M145701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; even if you create a local dhcp scope, you will still need to create a dynamic interface on the wlc to which you will tie/map the guest ssid&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Dec 2011 20:08:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870955#M145701</guid>
      <dc:creator>Viten Patel</dc:creator>
      <dc:date>2011-12-26T20:08:40Z</dc:date>
    </item>
    <item>
      <title>Guest SSID</title>
      <link>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870956#M145702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yeah i am agree with you on this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you please explain that how the guest users will go to the internet through virtual interface i mean how does this works and how guest users are not coming to corporate network like applications and printers etc etc?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Dec 2011 16:54:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870956#M145702</guid>
      <dc:creator>john smith</dc:creator>
      <dc:date>2011-12-27T16:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Guest SSID</title>
      <link>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870957#M145703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To add to Viten post, Viten explains that the guest SSID will be played on the dynamic interface you use for guest. Hen using the wlc as a dhcp server for guest users, the users will see the virtual ip as the dhcp sever. So this has really nothing to do with connectivity to the Internet. To prevent guest users from accessing your internal network, Viten explains that you need a L2 connection to your FW. This means no L3 interface for that guest subnet.  With no L3 interface, guest gets pushed to the FW and not able to route internally. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Dec 2011 17:50:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870957#M145703</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2011-12-27T17:50:39Z</dc:date>
    </item>
    <item>
      <title>Guest SSID</title>
      <link>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870958#M145704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks guys for your reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but i have not any firewall in my network and i want to configure wlc as a dhcp server for guest users and to avoid them to access to the internal netwrok aplication and all our other servers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what you say if i hit my local DNS server ip addresses in DHCP pool or it is not really necessary?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i already configured it without firewall local DHCP for guest users vlan on wlc but my guest users can access to the application how i can avoid them?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also i can see virtual interface ip address as a DHCP ip address on client side which connected to guest ssid so what should i do any one has any idea?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 Dec 2011 08:21:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870958#M145704</guid>
      <dc:creator>john smith</dc:creator>
      <dc:date>2011-12-31T08:21:19Z</dc:date>
    </item>
    <item>
      <title>Guest SSID</title>
      <link>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870959#M145705</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what you say if i hit my local DNS server ip addresses in DHCP pool or it is not really necessary?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are going to use the wlc for dhcp for the guest users, you still need to create a dynamic interface to place the guest users on.&amp;nbsp; You also need to use the wlc managment ip address as your dhcp server ip address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i already configured it without firewall local DHCP for guest users vlan on wlc but my guest users can access to the application how i can avoid them?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configured what.... if you have created another subnet on your layer 3 switch and also created a layer 3 interface, then you are routing between the guest network and all your other netowrks.&amp;nbsp; You would need to create an access list (ACL) to prevent this.&amp;nbsp; You do have a layer 3 switch correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also i can see virtual interface ip address as a DHCP ip address on client side which connected to guest ssid so what should i do any one has any idea?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't worry about this... it is because you have dhcp proxy enabled.&amp;nbsp;&amp;nbsp; If you diable dhcp proxy then users will see the ip of the dhcp server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So basically what equipment do you have.... a 4400WLC that connects to a layer 3 switch then to a router for internet?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 Dec 2011 15:54:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870959#M145705</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2011-12-31T15:54:56Z</dc:date>
    </item>
    <item>
      <title>Guest SSID</title>
      <link>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870960#M145706</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for your reply Fella &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes i have wism card in 6500 series switch and i have configured the same guest user vlans on that switch too but also i configured the same vlans on WLC locally too and DHCP as well and configured controllers mgmt ip in dhcp server ip address place&amp;nbsp; in wlan advance tab&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but as i guess ACL we creat to give access to applications to our guest vlan users if we configure local DHCP for them what you say about this ? or can we configure ACL to avoide them to go to applications ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So basically what equipment do you have.... a 4400WLC that connects to a layer 3 switch then to a router for internet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ans: &lt;/P&gt;&lt;P&gt;i have wism in 6500 series switch and switch is conected to core switch and core is connected to our main office via layer 3 link OSPF.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any idea please?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 Dec 2011 16:51:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870960#M145706</guid>
      <dc:creator>john smith</dc:creator>
      <dc:date>2011-12-31T16:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Guest SSID</title>
      <link>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870961#M145707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay so you need to create an acl on the guest layer 3 interface to deny traffic to your internal networks. You can still use the wlc for dhcp for the guest.  This doesn't matter if you do the dhcp in the wlc, switch or internal dhcp server. You still need to create an acl.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott Fella&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 Dec 2011 17:05:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870961#M145707</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2011-12-31T17:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: Guest SSID</title>
      <link>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870962#M145708</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want to create an ACL on the WLC, here is a link.&amp;nbsp; I suggest doing ti on the L3... works better:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_tech_note09186a00807ce372.shtml"&gt;http://www.cisco.com/en/US/tech/tk722/tk809/technologies_tech_note09186a00807ce372.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 Dec 2011 23:18:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870962#M145708</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2011-12-31T23:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: Guest SSID</title>
      <link>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870963#M145709</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for your replyy fella&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i configured acl with but i donot know may be i configured wrong i can still acces other server from guest ssid&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i want to configure it to use only our external local&amp;nbsp; DNS server for internet only whil all the other accesses i want to block them &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DHCP will be at controller the sane i want to use that&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please tell me how i can deny these all accesses and only alow acces to DNS ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Jan 2012 20:18:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870963#M145709</guid>
      <dc:creator>john smith</dc:creator>
      <dc:date>2012-01-01T20:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: Guest SSID</title>
      <link>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870964#M145710</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Waseem,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think its time for a TAC case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Jan 2012 20:34:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870964#M145710</guid>
      <dc:creator>Viten Patel</dc:creator>
      <dc:date>2012-01-01T20:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: Guest SSID</title>
      <link>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870965#M145711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your all reply scott&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but unfortunately still i did not solve this issue please help me on this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have one vlan subnet 10.135.104.0/24 for guest users&lt;/P&gt;&lt;P&gt;External DHCP for this vlan 10.5.2.22&lt;/P&gt;&lt;P&gt;External local DNS server 10.5.2.23&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i want to allow them to use only internet like HTTP only &lt;/P&gt;&lt;P&gt;but they will get ip from external DHCP&amp;nbsp;&amp;nbsp; *** here please advise me what is good to use external or local DHCP server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for DNS this is only external i have they should use that one&lt;/P&gt;&lt;P&gt;i have not any firewall in my network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i know the solution is only to configure ACL on WLC&lt;/P&gt;&lt;P&gt;but i don't know how to configure it, i followed one doc. but failed to configure it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i mentioned my vlan ip above please tell me how i can configure ACL for that in order to give only internet access to that WLAN's users step by step.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jan 2012 20:33:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870965#M145711</guid>
      <dc:creator>john smith</dc:creator>
      <dc:date>2012-01-09T20:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: Guest SSID</title>
      <link>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870966#M145712</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can configure a typical ACL on the SVI interface of GUEST. Thus allowing you to manage what goes where. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jan 2012 05:54:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-ssid/m-p/1870966#M145712</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2012-01-10T05:54:01Z</dc:date>
    </item>
  </channel>
</rss>

