cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7396
Views
0
Helpful
1
Replies

WAP4410N - SSID isolation

wei.leng
Level 1
Level 1

Hi all,

A query here with regards to Wireless isolation between SSID and wireless isolation within SSID.

If we have 2 SSID, eg. InternalSSID, GuestSSID on AP1

Both SSID are set to Enabled for isolation between SSID, and within SSID, that would mean all machines connected thro' this AP1, would be isolated from one another.

1) If there's 1 laptop that connects to another AP, lets call it AP2, (doesn't have isolation function) on ssid01. Would this laptop still be isolated from those that connects to the first AP?

2) If there are wired PCs connected to the router. And the 2 APs are connected to the same router. Would the machines connected thro' the AP1 on either InternalSSID, GuestSSID be able to access those wired PCs? (My assumption is yes.)

3) Is there a quick and efficient way to setup on WRVS4400N to isolate GuestSSID totally from InternalSSID, and wired PCs. InternalSSID and wired PCs should be allowed to 'see' one another.

The challenge here is that, the network points are all installed already. Both AP are connecting thro' 2 separate unmanaged switch together with a couple of other PCs. 1 Port on the unmanaged switch, each,connects to the router.

1 Reply 1

David Carr
Level 6
Level 6

Wei,


What you describing with the isolation between and within ssids you have the understanding of how it operates.  If someone was to connect from another access point that did not have these features setup, they would only see the connections to that access point.  Everyone connected to the wap4410n with those settings setup would have the restrictions applied to them. 


If both rules are enabled they will not be able to see guest to private networks and neither will they be able to see resources on the network.  Pretty much they would have internet access only


With the Wrvs4400n, I would create two vlans and put the ssids in two separate vlans, then turn off inter-vlan routing to not allow them to communicate to each other.  Then you can do the isolation within the ssid on the guest so they get internet only.


Hope this helps.