<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Guest access on the 5508 WLC in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076591#M44423</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay this is getting confusing... this Is how I would do it.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Option 1:&lt;/P&gt;&lt;P&gt;I would make sure that on the guest ssid, that flexconnect local switching is disabled.&amp;nbsp; So basically all the guest traffic will tunnel back to the WLC at test site 2 and be placed in the same interface as guest in test site 1.&amp;nbsp; This is the easiest way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Option 2:&lt;/P&gt;&lt;P&gt;Is that you create AP's groups and you still keep the guest ssid the same as above... not using local switching and you define and ap group for test 1 and test 2.&amp;nbsp; In there, you map your guest ssid to the interface on the WLC.&amp;nbsp; SO in the WLC, you need to have two subnet's created for guest at test site 1 and test site 2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Feb 2013 12:59:05 GMT</pubDate>
    <dc:creator>Scott Fella</dc:creator>
    <dc:date>2013-02-06T12:59:05Z</dc:date>
    <item>
      <title>Guest access on the 5508 WLC</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076579#M44411</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm looking to implement guest WiFi access with web authentication on one of our 5508 WLC (currently deployed within a sandbox environment), but looking for some assistance. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The WLC currently has a single connection from port 1 to the 'Test Site 2' switch. This is a dot1q trunk. On the WLC, the interface (for port 1) is configured as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Name: Management&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Guest LAN: No&lt;/P&gt;&lt;P&gt;Quarantine: No&lt;/P&gt;&lt;P&gt;Enable NAT: No&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VLAN ID: 0&lt;/P&gt;&lt;P&gt;IP Address: 10.0.254.105&lt;/P&gt;&lt;P&gt;Mask: 255.255.255.0&lt;/P&gt;&lt;P&gt;Gateway: 10.0.254.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Physical Port No.: 1&lt;/P&gt;&lt;P&gt;Backup Port: 0&lt;/P&gt;&lt;P&gt;Active Port: 1&lt;/P&gt;&lt;P&gt;Enable Dynamic AP Management: Yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Primary DHCP Server: 10.0.254.10&lt;/P&gt;&lt;P&gt;ACL: None&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently, I have one WLAN configured with the profile name 'Guest Test 1', it's enabled and broadcasting the SSID. Security is L3 only with web authentication configured. The WLAN is configured to use the interface names "guest_wifi".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration for the Interface "guest_wifi" is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Name: guest_wifi&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Guest LAN: No&lt;/P&gt;&lt;P&gt;Quarantine: No&lt;/P&gt;&lt;P&gt;Enable NAT: No&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VLAN ID: 99&lt;/P&gt;&lt;P&gt;IP Address: 10.99.254.100&lt;/P&gt;&lt;P&gt;Mask: 255.255.255.0&lt;/P&gt;&lt;P&gt;Gateway: 10.99.254.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Physical Port No.: 1&lt;/P&gt;&lt;P&gt;Backup Port: 0&lt;/P&gt;&lt;P&gt;Active Port: 1&lt;/P&gt;&lt;P&gt;Enable Dynamic AP Management: No&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Primary DHCP Server: 10.0.254.105 &lt;EM&gt;(The WLC is configured to issue addresses for the guest WLAN)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;ACL: None&lt;EM&gt; (This will eventually be locked down, but for the purposes of testing, I've disabled the ACL)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;The default gateway for the Test Site 2 is 10.0.254.1, and has a sub interface configured which is in VLAN 99 with an IP address of 10.99.254.1 /24.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Diagram of the setup...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/0/2/8/127820-Test%20Network%20-%20WLC%20Setup%20-%20Cisco%20Support.jpg" alt="Test Network - WLC Setup - Cisco Support.jpg" class="jive-image-thumbnail jive-image" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue is that when a client connects to the WLAN, it receives an IP address okay (10.99.254.x address), but doesn't seem to be able to contact the WLC to get the web authentication page. Eventually, the WLC terminates the connection due to an authentication failure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know there is probably a load more questions on the configuration that I haven't listed, but I'm happy to answer any queries to help solve this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Equally - does it sound like I'm taking the correct approach here? The idea is that clients connect to the guest WLAN, which puts them on VLAN 99 and routes traffic through to the ASA and then onto the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Tony&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 06:22:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076579#M44411</guid>
      <dc:creator>tonymitchell</dc:creator>
      <dc:date>2021-07-04T06:22:00Z</dc:date>
    </item>
    <item>
      <title>Guest access on the 5508 WLC</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076580#M44412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you remove the webauth and test just with an open ssid, you can get an ip address and connect to the internet?&amp;nbsp; Just want to make sure the routing is working first? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 17:21:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076580#M44412</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-01-17T17:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: Guest access on the 5508 WLC</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076581#M44413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott,&lt;BR /&gt;&lt;BR /&gt;Thanks for the reply, sounds like a sensible move! I'm out of the office now until the 28th Jan, but will try your suggestion when I get back and let you know.&lt;BR /&gt;&lt;BR /&gt;Thanks again&lt;BR /&gt;Tony&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2013 09:42:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076581#M44413</guid>
      <dc:creator>tonymitchell</dc:creator>
      <dc:date>2013-01-18T09:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: Guest access on the 5508 WLC</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076582#M44414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No problem. The main reason WebAuth doesn't work if the network is fine is DNS. The clients homepage must be http and not an secure site for one. The WLC must be able to resolve the devices homepage before the WebAuth page is displayed to the user. If using a 3rd party certificate, the clients must be able to resolve the FQDN from the DNS server that the client obtains through DNS.&lt;BR /&gt;&lt;BR /&gt;Here is a good guide&lt;BR /&gt;&lt;BR /&gt; &lt;A href="https://supportforums.cisco.com/docs/DOC-13954" target="_blank"&gt;https://supportforums.cisco.com/docs/DOC-13954&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2013 09:58:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076582#M44414</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-01-18T09:58:41Z</dc:date>
    </item>
    <item>
      <title>Re: Guest access on the 5508 WLC</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076583#M44415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Indeed, the issue was with the routing to the internet, and so (as you said above), the WLC will not have been able to resolve the clients homepage in order to proceed with Web Authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The routing issue has been resolved, and now all is working well from this test site (Test Site 2 on the diagram)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am however now facing another issue on the same network, but from Test Site 1. I need to understand the issue a little more, but will open another discussion if I get stumped again! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help Scott.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Tony&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2013 14:24:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076583#M44415</guid>
      <dc:creator>tonymitchell</dc:creator>
      <dc:date>2013-01-31T14:24:01Z</dc:date>
    </item>
    <item>
      <title>Guest access on the 5508 WLC</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076584#M44416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No problem Tony!&amp;nbsp; Just post and one of us will answer:) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2013 15:23:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076584#M44416</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-01-31T15:23:15Z</dc:date>
    </item>
    <item>
      <title>Guest access on the 5508 WLC</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076585#M44417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi again Scott (and others!),&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm stumped again with guest access, but from a different site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've updated the diagram in my original post, showing clients accessing the guest wireless network from Test Site 1. Clients are receiving an IP address from the WLC, but have no connectivity other than to the interface IP address on the WLC. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've disabled WebAuth and ACLs for the moment. The full configuration is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Name: TS1_Int_Guest&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Guest LAN: No&lt;/P&gt;&lt;P&gt;Quarantine: No&lt;/P&gt;&lt;P&gt;Enable NAT: No&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VLAN ID: 98&lt;/P&gt;&lt;P&gt;IP Address: 10.98.253.254&lt;/P&gt;&lt;P&gt;Mask: 255.255.255.0&lt;/P&gt;&lt;P&gt;Gateway: 10.98.253.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Physical Port No.: 1&lt;/P&gt;&lt;P&gt;Backup Port: 0&lt;/P&gt;&lt;P&gt;Active Port: 1&lt;/P&gt;&lt;P&gt;Enable Dynamic AP Management: No&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Primary DHCP Server: 10.0.254.105 &lt;EM&gt;(The WLC is configured to issue addresses for the guest WLAN - 10.98.253.10 to 20/24)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;ACL: None&lt;EM&gt; (This will eventually be locked down, but for the purposes of testing, I've disabled the ACL)&lt;/EM&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt;"&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;The default gateway for the Test Site 1 is 10.0.253.1, and has a sub interface configured which is in VLAN 98 with an IP address of 10.98.253.1 /24.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once a client is connected to the WLAN on Test Site 1, it receives an IP address (e.g. 10.98.253.10), and can ping the interface for the WLAN (10.98.253.254), but not the gateway address (10.98.253.1) or beyond.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Incidentally, I can ping the VLAN 98 IP address (10.98.253.1) from the switch on Test Site 2, but not from the WLC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Routing issue from the WLC??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Tony&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 16:34:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076585#M44417</guid>
      <dc:creator>tonymitchell</dc:creator>
      <dc:date>2013-02-04T16:34:39Z</dc:date>
    </item>
    <item>
      <title>Guest access on the 5508 WLC</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076586#M44418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so really dumb question...but are you allowing VLAN 98 on the trunk to the WLC?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH, &lt;BR /&gt;Steve &lt;BR /&gt; &lt;BR /&gt;------------------------------------------------------------------------------------------------ &lt;BR /&gt;Please remember to rate useful posts, and mark questions as answered&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 16:37:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076586#M44418</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2013-02-04T16:37:38Z</dc:date>
    </item>
    <item>
      <title>Guest access on the 5508 WLC</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076587#M44419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steve - the switch port that connects the WLC is a trunk with no restrictions (ACLs) applied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Tony&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 17:09:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076587#M44419</guid>
      <dc:creator>tonymitchell</dc:creator>
      <dc:date>2013-02-04T17:09:49Z</dc:date>
    </item>
    <item>
      <title>Guest access on the 5508 WLC</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076588#M44420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you share the config of the port?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The WLC doesn't 'route', it's just going to dump the traffic onto the port in the VLAN linked to the interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH, &lt;BR /&gt;Steve &lt;BR /&gt; &lt;BR /&gt;------------------------------------------------------------------------------------------------ &lt;BR /&gt;Please remember to rate useful posts, and mark questions as answered&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 17:20:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076588#M44420</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2013-02-04T17:20:19Z</dc:date>
    </item>
    <item>
      <title>Guest access on the 5508 WLC</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076589#M44421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Switch port config (connection to WLC management interface - port 1)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; switchport trunk encapsulation dot1q&lt;/P&gt;&lt;P&gt; switchport mode trunk&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;WLC port configuration (management interface)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Interface Name................................... management&lt;/P&gt;&lt;P&gt;MAC Address...................................... d4:8c:b5:a7:05:80&lt;/P&gt;&lt;P&gt;IP Address....................................... 10.0.254.105&lt;/P&gt;&lt;P&gt;IP Netmask....................................... 255.255.255.0&lt;/P&gt;&lt;P&gt;IP Gateway....................................... 10.0.254.1&lt;/P&gt;&lt;P&gt;External NAT IP State............................ Disabled&lt;/P&gt;&lt;P&gt;External NAT IP Address.......................... 0.0.0.0&lt;/P&gt;&lt;P&gt;VLAN............................................. untagged&lt;/P&gt;&lt;P&gt;Quarantine-vlan.................................. 0&lt;/P&gt;&lt;P&gt;Active Physical Port............................. 1&lt;/P&gt;&lt;P&gt;Primary Physical Port............................ 1&lt;/P&gt;&lt;P&gt;Backup Physical Port............................. Unconfigured&lt;/P&gt;&lt;P&gt;Primary DHCP Server.............................. 10.0.254.10&lt;/P&gt;&lt;P&gt;Secondary DHCP Server............................ Unconfigured&lt;/P&gt;&lt;P&gt;DHCP Option 82................................... Disabled&lt;/P&gt;&lt;P&gt;ACL.............................................. Unconfigured&lt;/P&gt;&lt;P&gt;AP Manager....................................... Yes&lt;/P&gt;&lt;P&gt;Guest Interface.................................. No&lt;/P&gt;&lt;P&gt;L2 Multicast..................................... Disabled&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2013 11:21:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076589#M44421</guid>
      <dc:creator>tonymitchell</dc:creator>
      <dc:date>2013-02-05T11:21:03Z</dc:date>
    </item>
    <item>
      <title>Guest access on the 5508 WLC</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076590#M44422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could this be down to NOT using Interface Groups?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Test Site 1 and Test Site 2 are different subnets, though I want Guest access to function the same way for all sites. (i.e. client connects to AP on Test Site 1, receives a 10.99.254.x IP address, authenticates through WebAuth and then has internet access. A client on test site 2, will go through the same process, but get an IP from the 10.99.253.x subnet).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Tony&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Feb 2013 11:42:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076590#M44422</guid>
      <dc:creator>tonymitchell</dc:creator>
      <dc:date>2013-02-06T11:42:30Z</dc:date>
    </item>
    <item>
      <title>Guest access on the 5508 WLC</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076591#M44423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay this is getting confusing... this Is how I would do it.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Option 1:&lt;/P&gt;&lt;P&gt;I would make sure that on the guest ssid, that flexconnect local switching is disabled.&amp;nbsp; So basically all the guest traffic will tunnel back to the WLC at test site 2 and be placed in the same interface as guest in test site 1.&amp;nbsp; This is the easiest way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Option 2:&lt;/P&gt;&lt;P&gt;Is that you create AP's groups and you still keep the guest ssid the same as above... not using local switching and you define and ap group for test 1 and test 2.&amp;nbsp; In there, you map your guest ssid to the interface on the WLC.&amp;nbsp; SO in the WLC, you need to have two subnet's created for guest at test site 1 and test site 2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Feb 2013 12:59:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076591#M44423</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-02-06T12:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: Guest access on the 5508 WLC</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076592#M44424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It most certainly is confusing!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My current config is exactly as per your Option 2 (though my guest SSIDs are different)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;TS1 (Test site 1) - Clients receive DHCP IP address, but have no access other than can ping the interface IP.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Interface (Dynamic) &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; - Name: TS1_Int_Guest&lt;/P&gt;&lt;P&gt; - VLAN 98&lt;/P&gt;&lt;P&gt; - IP Address: 10.98.253.254&lt;/P&gt;&lt;P&gt; - Mask: 255.255.255.0&lt;/P&gt;&lt;P&gt; - Gateway: 10.98.253.1&lt;/P&gt;&lt;P&gt; - Dynamic AP Mgt: No&lt;/P&gt;&lt;P&gt; - DHCP Server: WLC&lt;/P&gt;&lt;P&gt; - ACL: None (disabled for testing)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;WLAN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; - Type: WLAN&lt;/P&gt;&lt;P&gt; - Name: TS1_WLAN_Guest&lt;/P&gt;&lt;P&gt; - Status: Enabled&lt;/P&gt;&lt;P&gt; - Security Policy: None (disabled Web-Auth for testing)&lt;/P&gt;&lt;P&gt; - FlexConnect: Disabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;AP Group&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;TS1_AP_Group&lt;/P&gt;&lt;P&gt; - WLANs: TS1_WLAN_Guest&lt;/P&gt;&lt;P&gt; - Interface: TS1_Int_Guest&lt;/P&gt;&lt;P&gt; - Contains 1 AP (MAC ending 4E5C)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;TS2 (Test site 2) - Currently works fine!&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Interface (Dynamic) &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; - Name: TS2_Int_Guest&lt;/P&gt;&lt;P&gt; - VLAN 99&lt;/P&gt;&lt;P&gt; - IP Address: 10.99.254.254&lt;/P&gt;&lt;P&gt; - Mask: 255.255.255.0&lt;/P&gt;&lt;P&gt; - Gateway: 10.99.254.1&lt;/P&gt;&lt;P&gt; - Dynamic AP Mgt: No&lt;/P&gt;&lt;P&gt; - DHCP Server: WLC&lt;/P&gt;&lt;P&gt; - ACL: Configured &amp;amp; working&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;WLAN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; - Type: WLAN&lt;/P&gt;&lt;P&gt; - Name: TS2_WLAN_Guest&lt;/P&gt;&lt;P&gt; - Status: Enabled&lt;/P&gt;&lt;P&gt; - Security Policy: Web-Auth&lt;/P&gt;&lt;P&gt; - FlexConnect: Disabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;AP Group&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;TS2_AP_Group&lt;/P&gt;&lt;P&gt; - WLANs: TS2_WLAN_Guest&lt;/P&gt;&lt;P&gt; - Interface: TS2_Int_Guest&lt;/P&gt;&lt;P&gt; - Contains 1 AP (MAC ending 4D22)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two DHCP scopes on the WLC (one for each subnet).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm currently in the process of ensure all router IOS versions are the same, the configs are the same, plus I've also spanned the port from the AP at Test Site 1 and run through a Wireshark capture. I can see the CAPWAP packets between the WLC and the AP, and within that I can see ping replies from the TS1 interface IP on the WLC. However, I can't see any other ICMP packets that I'm pinging from the client (i.e. pinging the gateway at TS1... 10.98.253.1).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry if this is confusing - I am trying to keep the explainations as simple as possible. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tony&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Feb 2013 13:24:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-on-the-5508-wlc/m-p/2076592#M44424</guid>
      <dc:creator>tonymitchell</dc:creator>
      <dc:date>2013-02-06T13:24:57Z</dc:date>
    </item>
  </channel>
</rss>

