<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Guest Wireless and DNS in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/guest-wireless-and-dns/m-p/1862917#M28966</link>
    <description>&lt;P&gt;During our implementation of Guest Wireless (currently ongoing), we are trying to decide where to point to for DNS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a 5508 WLC in our Internet DMZ and it acts as the Anchor WLC. This WLC is also used as the DHCP server for the Guest Wireless clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are debating whether to point the clients internally to our primary DNS servers, or externally to the public service provider DNS servers. The only DNS servers in the DMZ are external forwarders.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From a network standpoint, I think either solution would work. But from a security standpoint, which is better? Or is there another option?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone recommend a standard or best practice design when it comes to DNS for Guest Wireless?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Sun, 04 Jul 2021 04:26:57 GMT</pubDate>
    <dc:creator>Jason Wing</dc:creator>
    <dc:date>2021-07-04T04:26:57Z</dc:date>
    <item>
      <title>Guest Wireless and DNS</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-and-dns/m-p/1862917#M28966</link>
      <description>&lt;P&gt;During our implementation of Guest Wireless (currently ongoing), we are trying to decide where to point to for DNS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a 5508 WLC in our Internet DMZ and it acts as the Anchor WLC. This WLC is also used as the DHCP server for the Guest Wireless clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are debating whether to point the clients internally to our primary DNS servers, or externally to the public service provider DNS servers. The only DNS servers in the DMZ are external forwarders.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From a network standpoint, I think either solution would work. But from a security standpoint, which is better? Or is there another option?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone recommend a standard or best practice design when it comes to DNS for Guest Wireless?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 04:26:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-and-dns/m-p/1862917#M28966</guid>
      <dc:creator>Jason Wing</dc:creator>
      <dc:date>2021-07-04T04:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Wireless and DNS</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-and-dns/m-p/1862918#M28967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Use an external dns if possible. The only time I would use an internal is if I install a 3rd party certificate on the guest anchor to get rid of the certificate error page during a webauth and the client doesn't have an external dns or the isp will not add an A record to resolve the certificate CN name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott Fella&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jan 2012 03:03:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-and-dns/m-p/1862918#M28967</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-01-25T03:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Wireless and DNS</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-and-dns/m-p/1862919#M28968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are not playing around with third party certificates for webauth. Just point to external Internet servers. The only reason to use yours is if they would need access to internal resources, like a printer. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jan 2012 03:06:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-and-dns/m-p/1862919#M28968</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2012-01-25T03:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Wireless and DNS</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-and-dns/m-p/1862920#M28969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for the info - exactly what I needed. The guest access is not needed internally and I am not doing cerficicates. Therefore - external it is. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jan 2012 17:14:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-and-dns/m-p/1862920#M28969</guid>
      <dc:creator>Jason Wing</dc:creator>
      <dc:date>2012-01-25T17:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Wireless and DNS</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-and-dns/m-p/4140132#M28970</link>
      <description>&lt;P&gt;Hi Cisco community group,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having a similar issue.&lt;/P&gt;&lt;P&gt;Our setup is as follows:&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have visitor SSID on WLC which is not in DMZ. We are doing AAA for visitor SSID on WLC using the external webauth using Cisso ISE visitor portal and the redirect URL.&lt;/P&gt;&lt;P&gt;But, in the entire flow of getting the visitor credentials authenticated from ISE visitor pprtal through WLC, there is the virtual interface of 192.0.2.1 on WLC which is required with a DNS record.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now if I use External - public or ISP DNS, it cannot resolve that virtual interface DNS record and thus the authentication process seems to break and the wireless user doesn't reach the Run status, it is stuck in Webauth Required status.&lt;/P&gt;&lt;P&gt;Now, We are not pointing the visitor wireless users to the Internal DNS, as we only want the publicly facing servers to be visible to the&amp;nbsp; visitors and not the private records.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can we get around this problem.&lt;/P&gt;&lt;P&gt;Whats is the best way to implement guest or Visitor wireless in a campus environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2020 04:04:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-and-dns/m-p/4140132#M28970</guid>
      <dc:creator>parag_waghmare</dc:creator>
      <dc:date>2020-08-24T04:04:06Z</dc:date>
    </item>
  </channel>
</rss>

