04-03-2012 01:17 AM - edited 07-03-2021 09:56 PM
Hi there,
Could someone point me in the right direction with regards to the following?
I have a requirement to set up a guest SSID for contractor so that they can use the internet while in the office.
Security say that all traffic on this SSID should be isolated and directed straight to the firewall, with no chance of contamination into the company network infrastructure.
With the 5508, my understanding is using the setting up a guest account functionality built in will achieve this, but all traffic would end up at the wireless controller. How do I then put a direct forward for all traffic to the firewall which will only affect the guest traffic?
Any help would be welcomed with delight and joy!!!
Andy
Solved! Go to Solution.
04-03-2012 07:28 PM
1. Drop the traffic at the WLC apply ACl
2. Anchor the traffic to the DMZ
3. Take one of the ports from the WLC and plug it into the FW
DONE...
04-03-2012 01:20 AM
Configure an ACL on the router of the ACL for that Guest VLAN so that, the Guest VLAN can only go out directly to the internet and not to communicate with any other VLAN..
Regards
Surendra
04-03-2012 07:17 PM
The best way to accomplish this would be to have your internal controller anchor to another controller located in you DMZ. This would allow you to choose whatever SSID you want and have its traffic virtually terminate outside of your trusted network. If clients attached to this SSID needed access to internal resources they could use a VPN to come back in.
Sent from Cisco Technical Support iPad App
04-03-2012 07:28 PM
1. Drop the traffic at the WLC apply ACl
2. Anchor the traffic to the DMZ
3. Take one of the ports from the WLC and plug it into the FW
DONE...
04-03-2012 08:54 PM
Could you provide url of documentation how to implement third solution -
Take one of the ports from the WLC and plug it into the FW,
especialy configuration of WLC.
04-03-2012 09:02 PM
There is no documentation for that, most don't do it and I've seen it not recommended before.
Anyways, all you do is setup a dynamic interface and select port 8 for example and plug that into your DMZ network or FW interface directly. This will only work if you are not doing LAG on the 5508.
04-03-2012 09:06 PM
As Blake pointed out its not supported, but it works. I have a customer set up like this and they are running fine.
04-04-2012 04:41 AM
I too have customers setup this way with no issues. I don't know why it wouldn't be supported... It was supported on the 4400's and even on the 2504's. Oh well... It works fine.
Thanks,
Scott Fella
Sent from my iPhone
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide