I have little to no experience with cisco EWC.
I want to create a 2 separate SSIDs which are Internal and Guest.
I think in EWC, Guest settings is included.
I want to use the same LAN subnet for both SSIDs.
And I don't want the Guest Wifi to access the Internal network.
In default settings for Guest and Internal SSIDs, can they ping each other if they are in the same subnet?
If I configure an ACL at Guest interface on access point to block the guest to use the Internal network, will it solve the problem?
Thank you advance for your help.
If you put all your clients under the same vlan, you can not configure an Access List blocking traffic between them. If you use two vlans, then you can configure an Access List inbound or outbound deny or permiting the traffic.
Does not make sense you separate the traffic on the Wireless interface and then, put them together on the wired interface. From the security perspective, you are wasting your time.
Technically there are multiple ways you can achieve this, however considering the security issues this will bring not recommended at all. It is always better and recommended to go with dedicated VLAN for guest and another for internal usage.
But if you want to deploy, you can consider using Flexconnect ACL's with P2P drop or Per user VLAN's by using a Radius server for your Guest SSID.
P2P feature is well explained in below link, config guide you can refer to the code you are running
You need to use Flex ACL's. noy WLAN ACL's.