06-02-2016 03:28 AM - edited 07-05-2021 05:10 AM
Hi,
I've been asked to investigate if there is a better way of providing guest wifi across all our site.
We currently have a Cisco 4404 wireless controller which controls all the cisco AP's across 4 sites. We provide a guest wifi for visitors via the Cisco AP's and with a separate ADSL line at one of the sites, the guest access is managed from the controller.
The problem is all the traffic from the other three sites goes over the WAN to get to the ADSL line which isn't the best
So one idea is to put an ADSL line into each site to provide the guest wifi for that site. My question is can we still use the one controller to manage the guest wifi access or would we need a controller on each site.
Thanks
Dave
06-02-2016 06:59 AM
Are you using AP Groups for each site, also are the AP's in FlexConnect mode or local mode?
06-02-2016 08:05 AM
Hi Mohammed,
We are not using AP groups for each site, the only group is the default group.
The AP are set in HREAP which I think is the same Flexconnect mode.
Thanks
Dave
06-02-2016 08:26 AM
Ok so it would be a good idea to utilize AP groups for each site. Gives you some organization and also more control over customizing configs on the AP's.
You can still utilize the same controller and do Central Auth/Local Switching. Create a non routed VLAN locally going out the local ADSL circuit and dump all the guest traffic on that from the clients once they pass the Authentication.
06-03-2016 06:41 AM
Hi Mohammad,
Thanks for the reply but I think I may not have explained myself very well.
We want to have a ADSL line at each site to take the guest traffic for each site but still using the controller for the management.
Thanks
Dave
06-03-2016 07:30 AM
You are welcome I understand that is what I meant.
1- you get DSL circuits at each location
2- you setup central authentication and local switching
3- at each site you can create a VLAN that goes out the DSL circuit
4- setup FlexConnect/HREAP for that VLAN.
5- Client will connect to the SSID --> Authenticate from the 4400 controller based on whatever mechanism you setup for authentication --> traffic will then go out the guest VLAN you created.
06-09-2016 05:17 AM
Hi Mohammad,
Thanks for the info I'll give that a try and let you know.
Thanks
Dave
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide