cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
9471
Views
0
Helpful
9
Replies

WAP121 Guest Access

f1techinc
Level 1
Level 1

Hello.

I'm trying to configure the WAP121 for Guest Internet Access.

It seems no matter what I do, the guests have free access to the rest of the network. I'd just like them to be able to browse the Internet. I tried playing around with ACLs etc, but with no success.

The router is just a generic 5 port router, which handles the DHCP.

What am I doing wrong?

Thanks.

9 Replies 9

lariasqu
Level 1
Level 1

Hi Paul, thank you for using our forum, my name is Luis I am part of the Small business Support community. Did you try to isolate the VLANs?

Please follow these instructions: Wireless > Networks.

Then modify the SSID that you want to exclude from the access and check the Isolate option, then save the changes.

You could find more information in admin guide, Page 74

http://www.cisco.com/en/US/docs/wireless/access_point/csbap/wap121/administration/guide/WAP121_321_AG_en.pdf

I hope you find this answer useful

Greetings,

Luis Arias.

Cisco Network Support Engineer.

Thanks for the reply.

On page 76, it says the following:

When enabled, the WAP device blocks communication between wireless clients on the same VAP. The WAP device still allows data traffic between its wireless clients and wired devices on the network, across a WDS link, and with other wireless clients associated with a different VAP, but not among wireless clients.

I'd like an option to not allow traffic to wired devices - servers, printers etc.

Thanks.

In order to accomplish what you are describing, you need to have a router that can disable inter-vlan routing. You can then put the guest network on one vlan and have your internal network on a different network. That way when inter vlan routing is disabled the two vlans can not talk to each other.

Thanks

Eric Moyers    .:|:.:|:.

Cisco Small Business US STAC Advanced Support Engineer

CCNA, CCNA-Wireless

866-606-1866

Mon - Fri 09:00 - 18:00 (UTC - 05:00)

*Please rate the Post so other will know when an answer has been found.

Thanks Eric.

Is there a device that Cisco has - a Router/AP - that would accomplish what I need? I'd like an all ine one solution if possible.

Thanks.

For exactly this purpose I use a RV042. Simple and not too expensive.

It can provide Internet access to different VLANs (port based) that can not communicate between each other. All you need inbetween is a VLAN capabale Switch, e.g. one from the SG200 series and you configure two VLANs, one for the internal network and one for guests.

Hi. I am trying to do this same thing.

I have multiple cisco WAP121 access points and a SG200 switch. I plan to get a RV042 but just want to make sure I'm correct on the end result.

From the switch I have a single network cable to the access points. I would like to configure the setup so that from these APs I can have both wireless networks (main network and guest network). If I select a particular VLAN to be active on that port on the switch, am I right in thinking that I will only be able to wirelessly broadcast that VLAN?

Can anyone suggest the best way to achieve what I need or advice on how to configure these products to achieve what I need.

Many thanks for your help.

M

Hi. I am trying to do this same thing.

I have multiple cisco WAP121 access points and a SG200 switch. I plan to get a RV042 but just want to make sure I'm correct on the end result.

From the switch I have a single network cable to the access points. I would like to configure the setup so that from these APs I can have both wireless networks (main network and guest network). If I select a particular VLAN to be active on that port on the switch, am I right in thinking that I will only be able to wirelessly broadcast that VLAN?

Can anyone suggest the best way to achieve what I need or advice on how to configure these products to achieve what I need.

Many thanks for your help.

M

Hi Luis ..... I too am trying to setup a basic Wireless Guest network that will allow general public to connect to Internet only and not any other resources on network. I was sold this product stating that it was possible.

Can you advise what the configuration should be? I find if I use Channel Isolation then I don;t get an assigned DHCP IP Address.

Basically what you will need to do is put each SSID on different VLANs. In order for that to work, you will also need a router that can do vlans and be able to disable inter-vlan routing.

Eric Moyers
.:|:.:|:. CISCO | Cisco Presales Technical Support | Wireless Subject Matter Expert

Please rate helpful Posts and Let others know when your Question has been answered.