cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
497
Views
1
Helpful
3
Replies

guest anchor traffic flow isolation

habdelmageed
Level 1
Level 1

Hi everyone

 

I have a guest SSID anchored to DMZ WLC and everything working fine with a customize guest solution, yet my client have his security concerns regarding the guest traffic that incase of any cyber attack our local network might be exposed or face a VLAN leaking, am looking for any documentation to confirm that the IP tunneling is secured and isolated from our local DC network, the traffic flow from the client to AP to foreign controller to DMZ controller is isolated and secured,

 

Many thanks for support in advance.

3 Replies 3

marce1000
VIP
VIP

 

 - This is secure , as long as  the guest WLAN/VLAN is isolated from the Intranet as you are confirming , 

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

Hi marce

Really appreciate your feedback

The issue that my client have a highly secured network with an air gaped guest environment and our CS team need a cisco documentation confirmation is there any document created by cisco to explain the anchor tunnel concept and isolation + port mapping for firewall rules for the traffic between DC zone & DMZ zone? 

 

Thanks in advance.

Depend on the controller model you used (AireOS - traditional vs IOS-XE/9800 - modern) tunnel traffic port numbers may change. Otherwise same concept applicable for Guest Anchoring.  You can refer following deployment guide & FAQ

9800-Guest Anchoring
https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213912-configure-mobility-anchor-on-catalyst-98.html 

AireOS Guest Anchor config guide
https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/configuring_auto_anchor_mobility.html 
Guest Wi-Fi FAQ
https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/107458-wga-faq.html 

HTH
Rasika
*** Pls rate all useful responses ***

Review Cisco Networking products for a $25 gift card