Jump to content

Recommended Posts

Posted

Hello All,

 

I am wanting to configure a guest WiFi network so that when visitors come in they can easily connect to the Internet without seeing any of our internal network.

 

I figure this is going to involve VLANS to segregate traffic, this is not something I have ever done so treat me as a lay man :)

 

So far I have created a guest network with open security, enabled the guest portal with no authentication. I can see it being broadcast and I can connect with the landing page appearing. I cannot navigate any links as we use a proxy and this is not set in any way. I will need some idea as to how I can work with this so that guests do not need to enter the proxy settings on their device. When connected to the guest network I cannot see any of our internal hardware via the Network in My Computer... Does this mean I won't have to do anymore to ensure that our internal network is not visible to guests?

 

Many thanks in advance and should any more info help please let me know :) TomHD

Posted

It all depends on your proxy setup etc.

 

The usual way is to create a 2nd VLAN, have the Guest Wifi on that VLAN. Then make everything on that VLAN get the same level of filtering through whichever method you choose. Most filters will do it with Ident by IP or everything on theat VLAN treated as something. That's the very basics of what you need to do, obviously it is a little more complicated in reality.

  • Thanks 1
  • 1 month later...
Posted

Hi there TomHD,

 

We currently have a guest network set up on our Unifi controller. We use a separate VLAN and we have it set up as a Hotspot and have the Voucher enabled as authorisation.

In the means of restricting the guest users from browsing our internal system we use the Access Control which is found under the guest control, we have then just added restricted subnets.

Posted

I am interested on setting this up but I do not have a controller on site. I use a proxy from a council which provides our internet, could this be setup quote easily

 

My Access points are unifi AC Pro with PoE

 

Can anyone help ?

Posted

When you say the controller, you mean the Unifi software right?

 

If so then it should still all work fine, as long as you have access tot he controller you can setup the 2nd VLAN on the wifi points, then setup the same VLAN on the network switches etc. The bit that might be more complicated is the Guest Portal, as you would need the VLAN to be able to access the controller to get the default guest portal.

Posted

Which part, the controller is just software it can install anywhere.

 

You could in theory you could have two Wifi networks with no VLAN and one as a Guest network that would be open, but you are then allowing people to connect and leaving yourself much more open to malicious outsiders. I don't think it would be a very good idea though, I think you need to accept that VLANs are necessary for a Guest Wireless network.

 

Depending on the managed switch depends on how simple it will be, but if shouldn't be very hard to setup a 2nd VLAN.

Posted

Well I have already mentioned this to be honest and my boss is not interested.

 

I know how to create scope, but create a vlan on a managed switch are my thing. Not to sure how it can be done via telnet but im sure its easy doing it via web based software

Posted

I'm trying to think of a way of getting round the issue for you, and to be honest I really can't think of an easy one.

 

Most decent switches will allow it to be done via both telnet and web based, HPs, Cisco, Netgears all do from experience. Ciscos can be a bit funny about it, but ours are now very old so it might just be the firmware we have.

 

If you had a 2nd Wifi Network but no seperate VLAN, the guests would access the same range as your normal flat network as your DHCP server couldn't tell the difference between a guest and a normal client. If you use all fixed IPs you could make it so you knew which IP addresses were on the Guest Wifi and then use the Access Control built into Unifi to restrict them to accessing on certain IP addresses. Maybe you could use that to control access anyway without everything else on fixed but it might be a long winded way.

 

You would definitely need your Guest Wifi to have a password as well though, well I would personally. The real issue is how you get those on the Guest Wifi to authenicate against any filtering to gain any form of Internet access, because you couldn't identify by IP easily unless the above bit is true, so the only thing you could offer would be a login page for your filter, which is far from ideal.

Posted
Maybe its too complex but if you are stuck with the one VLAN, could you make use of an IPsec policy whereby only domain joined PC's can communicate with each other? A guest device wouldn't get that policy and so wouldn't be able to get at your servers etc?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...