cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
235
Views
1
Helpful
1
Replies

Guest LAN authentication - WLC9800

eeebbunee
Level 1
Level 1

Hello Professional,

I would like to control Guest users who connects Guest network over the wired using WLC 9800.

VLAN 500 is Guest VLAN and currently it is matched with SSID/Policy 'Guest'.
All wireless guests are required to pass L3 authentication (Web) which controller provided.

Goal: When guest connects to wired connection (L2 switch) and port configured guest VLAN (500), then they needs to pass authentication.

eeebbunee_0-1733170956194.png

In this case, can I use VLAN500 for wireless and wired both?
Between controller and L2 switch, there are two connections. One is trunk except VLAN500 and the other is VLAN500.

Should I also make the port to be 'Trunk except VLAN500' to L2's uplink port? 
(* Uplink port = L2-Core switch connection)

Thank you for your time.

 

1 Reply 1

Firstly without an anchored WLC you will need to determine how you are going to restrict users from accessing the corporate network.
the deployment guide for this is here https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/16-12/config-guide/b_wl_16_12_cg/wired-guest.html 
You authentication methods are basically going to be open or LWA
other option for this is to use NAC and have ISE provide the portal and access

 

*****Help out other by using the rating system and marking answered questions as "Answered"*****
*** Please rate helpful posts ***
Review Cisco Networking for a $25 gift card