+ Post New Thread
Results 1 to 3 of 3
Wireless Networks Thread, How secure is Ruckus Guest Access with the AP's on our normal IP scope? in Technical; Hi, We're pretty new to a managed wireless solution but are moving forward nicely. We use Ruckus for managed wireless ...
  1. #1

    Join Date
    Nov 2009
    North Walsham
    Thank Post
    Thanked 9 Times in 9 Posts
    Rep Power

    How secure is Ruckus Guest Access with the AP's on our normal IP scope?


    We're pretty new to a managed wireless solution but are moving forward nicely.

    We use Ruckus for managed wireless and Smoothwall for proxy/web filtering. Smoothwall is also the default Gateway.

    We have 10 Ruckus points, all with fixed IP addresses from our usual scope. We have created a Guest WLAN which uses full isolation so clients are unable to communicate with each other or access any of the restricted subnets. We have set a restricted subnet so that they can only talk to the proxy.

    We use transparent proxy on port 80 with SSL login. If a guest brings a device in, they can connect to the Guest WLAN and providing they have no browser settings defined, it will automatically take them to the Ruckus AUP page. They agree and are then challenged for a Smoothwall SSL login. We have locked down some AD accounts and issued these to regular guests, such as Adult Education, Connections, etc. It all works great.

    If students brought in their own devices, they are able to connect and use the Internet which is fine but without having some type of VLAN or having the Ruckus on a different scope, how secure is it?

    If someone was a hacker, could they potential reach areas of the network we wouldn't them to as these AP's are on our normal scope range?

    The reason we have it all on our normal IP scope is because we also have a corporate WLAN for staff to use. If we made the Ruckus AP's on a different range, i.e., etc...how would the staff be able to access their Resources, etc?

    Would we better of setting up the Guest WLAN on a VLAN and the corporate WLAN on another VLAN? If so, what is the process involved here?

    Any help would be much appreciated.

    Last edited by ronnoco; 10th February 2012 at 02:24 PM.

  2. #2
    smithson83's Avatar
    Join Date
    Nov 2007
    Thank Post
    Thanked 46 Times in 38 Posts
    Rep Power
    Sorry to HiJack the thread, but I'm going to be getting Ruckus in our new school, and was wondering similar things re the Guest WLAN.

    As far as my limited understanding of the situation as far as the VLANing goes. Would it be as simple as putting the port the Smoothwall(or ANother default gateway) on both the default VLAN and a second VLAN and then add the Wireless Controller to both and set the Guest WLAN to use VLAN2. Possibley requiring a DHCP service etc running somewhere on the second VLAN to keep everything nice and seperate. Could use the same scope on both DHCPs but limiting the range so as not to confuse the Gateway eg for GuestDHCP and for Corporate Network.

  3. #3
    White_Fi's Avatar
    Join Date
    Sep 2008
    Thank Post
    Thanked 34 Times in 32 Posts
    Rep Power
    Gary, I'd stick the Ruckus kit in a VLAN used for server/management then throw each WLAN into its own VLAN, relevant to network access.

    The security is tight with VLANs, the only risk being any known issues with your switches, rare. And your configuration.

    You can disable the spare ports on the back of the APs or make them access ports to particular VLANs to stop unwanted access.

+ Post New Thread

Similar Threads

  1. Ruckus Guest Access
    By Quackers in forum Wireless Networks
    Replies: 5
    Last Post: 6th February 2012, 11:59 AM
  2. Replies: 5
    Last Post: 13th March 2011, 06:01 PM
  3. How to block 3g phones access to the internet ?
    By niko007 in forum Internet Related/Filtering/Firewall
    Replies: 6
    Last Post: 10th February 2011, 11:22 PM
    By mattx in forum General Chat
    Replies: 9
    Last Post: 31st January 2011, 09:44 AM
  5. How secure is a VLAN?
    By Ben_Stanton in forum Wireless Networks
    Replies: 5
    Last Post: 26th July 2007, 10:15 AM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts