cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1366
Views
0
Helpful
4
Replies

Trusted and Untrusted VLANs in WLAN

paneer.r
Level 1
Level 1

Can anyone help me to find out how to configure guest mode VLAN & one secure VLAN. I want guest mode VLAN to be configured without any authentication and trusted VLAN association only with MAC & LEAP authentication.

Regards,

4 Replies 4

Not applicable

I don't think the concept of guest VLAN is there in WLAN.

jafrazie
Cisco Employee
Cisco Employee

True, but a WLAN Guest Access Network can be a WLAN VLAN configuration, so you have alternatives for WLAN Guest access:

*Create a Guest WLAN VLAN with no encryption, open authentication, and a broadcast SSID (or tell Guests what it is).

*Same as above with Authentication Options (like BBSM/IOS-Authentication-Proxy and/or specialized clients like 802.1x.

*Add application filters, time of day controls, and/or IDS schemes as needed/required.

Hope this helps.

I have a trusted and untrusted VLAN in my WLAN. Just setup the VLANs and create LEAP accounts on the ACS server for both VLANs

ex. VLAN 100 Trusted

VLAN 101 Untrusted

Setup username VLAN100

password xxxxxxx

Do you have your devices in ACS setup in groups?

Hi ,

I could resolve the issue by doing the following.

1) I have created 2 SSID and assigned different VLANs to the same. Guest SSID configured with open/shared access and Secure SSID configured with EAP/MAC Authentication. VLAN restriction configured in the MSFC.I could find if we are selecting shared access , clients are able to join AP even without SSID. So it resolved my problem.

Thanks for all your responses.

Regards,

Shibu

Review Cisco Networking for a $25 gift card