cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
572
Views
0
Helpful
3
Replies

Guest Access with WLC interface in DMZ

techno.it
Level 1
Level 1

Dear Experts Community,

I need you advice on the design

We have 2 x 9800 WLCs working in SSO mode with 400 WAPs and all SSIDs are configured with centrally switched mode.

We have 1 LAG connected to Core Switches on trunk port for corporate data and voice traffic

We have Cisco ISE positioned in internal data center network.

Our intention is to connect the second interface of the WLCs in the DMZ for Guest Access traffic

Is this a feasible design, and what is the recommendation from a security perspective?

 

Appreciate your insights.

 

3 Replies 3

docjb0221
Level 1
Level 1
This is definitely feasible and a good idea.

Your biggest questions will be how to handle DNS, DHCP, and reachability on port 8443 to ISE. Bear in mind that ISE has to be resolvable also, so whatever DNS server you use needs to have your ISE servers as host records. You could setup a DNS server in the DMZ and have a subset of your internal DNS records in it.

LC.IT
Level 1
Level 1

It’s a good design, make sure that you follow the @docjb0221 tips.

@LC.IT why are you telling @techno.it to follow their own tips? 
He/she is the one asking the question!

Review Cisco Networking for a $25 gift card