cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
444
Views
0
Helpful
3
Replies

guest wireless security

zli
Level 1
Level 1

My client concerns about the guest WLAN security, and the client would like the guest WLAN only access to the Internet and not its other vlans, specailly the server vlans. Could any one kindly provide the steps/methods to follow? BTW, the client uses cisco WLC 5508 and AP 3602i. Many thanks and kind regards,       

3 Replies 3

Amjad Abdullah
VIP Alumni
VIP Alumni

You have to take care of that from the core side. You need to allow routing for that VLAN to outside only.

The other option (which requires two WLCs) is to set up an anchor controller in the DMZ and tunnel guest traffic between your internal WLC and the anchor WLC in DMZ.

read this: Wireless Guest Access FAQ

Regards,

Amjad

Rating useful replies is more useful than saying "Thank you"

Rating useful replies is more useful than saying "Thank you"

Sandeep Choudhary
VIP Alumni
VIP Alumni

HI Zhi,

1. Police that vlan traffic either on the inside switch or on the ASA.

https://supportforums.cisco.com/docs/DOC-1230

2. Use websense for content scanning/filtering or use the CSC module on the ASA for http scanning/URL filtering.

http://www.cisco.com/en/US/docs/security/csc/csc6.1.1569.0/administration/guide/csc4.html

Regards

Saurav Lodh
Level 7
Level 7
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card