cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
188
Views
2
Helpful
2
Replies

Cisco recommended architecture for guest access to internet

neil_titchener
Level 1
Level 1

Hi All,

We're about to upgrade our WiFi network architecture.  Currently we have a Foreign/Anchor setup for direct internet access.  Is this the current Cisco recommended architecture?  A colleague has suggest a new architecture removing the Anchor and running a GRE tunnel from the Foreign controller to the external firewall.  Is this a recommended design in an Enterprise network?

Any URLs you know of regarding WiFi architecture would be greatly appreciated.

Thanks in advance for taking the time to reply

2 Replies 2

Scott Fella
Hall of Fame
Hall of Fame

I wouldn't say there are recommendations except for "how you want to delivery the guest traffic withouth touching any other part of your network." Guest anchors work fine and are pretty easy to deploy if you have the budget for them.  GRE, VRF, etc. being able to tunnel guest traffic from a site to another location for internet egress is another option.  At time, if the site has a local egress, you don't need either and can just send traffic out the foreign controller to a vlan that is dedicated to that local internet egress.  You design it the best way that you can afford and your team can support.

-Scott
*** Please rate helpful posts ***

Rich R
VIP
VIP

This is the official Cisco Design Guide:
https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Campus/cisco-campus-lan-wlan-design-guide.html#Guestwireless

It suggests the anchor design or local direct internet access - as Scott has also suggested - so it's really down to your own requirements/preferences.  Sometimes it just comes down to company policy about how guest traffic is handled where insistence on anchor design seems to be much less prevalent these days as the security folks have started to trust/accept that VLANs really do keep traffic effectively separated.

ps: If you decide you want to go for an EoGRE solution (or just want to understand it) then refer to:
https://www.cisco.com/c/dam/en/us/td/docs/wireless/controller/9800/17-2/deployment-guide/c9800-eogre-deployment-guide-rel-17-2.pdf
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-12/config-guide/b_wl_17_12_cg/m_wl_eogre.html

Review Cisco Networking for a $25 gift card