TomHD Posted April 15, 2016 Posted April 15, 2016 Hello All, I am wanting to configure a guest WiFi network so that when visitors come in they can easily connect to the Internet without seeing any of our internal network. I figure this is going to involve VLANS to segregate traffic, this is not something I have ever done so treat me as a lay man So far I have created a guest network with open security, enabled the guest portal with no authentication. I can see it being broadcast and I can connect with the landing page appearing. I cannot navigate any links as we use a proxy and this is not set in any way. I will need some idea as to how I can work with this so that guests do not need to enter the proxy settings on their device. When connected to the guest network I cannot see any of our internal hardware via the Network in My Computer... Does this mean I won't have to do anymore to ensure that our internal network is not visible to guests? Many thanks in advance and should any more info help please let me know TomHD
Achandler Posted April 15, 2016 Posted April 15, 2016 It all depends on your proxy setup etc. The usual way is to create a 2nd VLAN, have the Guest Wifi on that VLAN. Then make everything on that VLAN get the same level of filtering through whichever method you choose. Most filters will do it with Ident by IP or everything on theat VLAN treated as something. That's the very basics of what you need to do, obviously it is a little more complicated in reality. 1
DanArkless Posted June 14, 2016 Posted June 14, 2016 Hi there TomHD, We currently have a guest network set up on our Unifi controller. We use a separate VLAN and we have it set up as a Hotspot and have the Voucher enabled as authorisation. In the means of restricting the guest users from browsing our internal system we use the Access Control which is found under the guest control, we have then just added restricted subnets.
ITJS2015 Posted June 21, 2016 Posted June 21, 2016 I am interested on setting this up but I do not have a controller on site. I use a proxy from a council which provides our internet, could this be setup quote easily My Access points are unifi AC Pro with PoE Can anyone help ?
Achandler Posted June 21, 2016 Posted June 21, 2016 When you say the controller, you mean the Unifi software right? If so then it should still all work fine, as long as you have access tot he controller you can setup the 2nd VLAN on the wifi points, then setup the same VLAN on the network switches etc. The bit that might be more complicated is the Guest Portal, as you would need the VLAN to be able to access the controller to get the default guest portal.
ITJS2015 Posted June 21, 2016 Posted June 21, 2016 Sadly I don't use Vlans, I wish I could but its down to the boss. Can it be easily setup being on a managed switch ?
Achandler Posted June 21, 2016 Posted June 21, 2016 Which part, the controller is just software it can install anywhere. You could in theory you could have two Wifi networks with no VLAN and one as a Guest network that would be open, but you are then allowing people to connect and leaving yourself much more open to malicious outsiders. I don't think it would be a very good idea though, I think you need to accept that VLANs are necessary for a Guest Wireless network. Depending on the managed switch depends on how simple it will be, but if shouldn't be very hard to setup a 2nd VLAN.
ITJS2015 Posted June 21, 2016 Posted June 21, 2016 Well I have already mentioned this to be honest and my boss is not interested. I know how to create scope, but create a vlan on a managed switch are my thing. Not to sure how it can be done via telnet but im sure its easy doing it via web based software
DanArkless Posted June 21, 2016 Posted June 21, 2016 We don't use a VLAN for our Guest Network, I'm not sure if this is possible on other networks that you set up with security.
Achandler Posted June 21, 2016 Posted June 21, 2016 I'm trying to think of a way of getting round the issue for you, and to be honest I really can't think of an easy one. Most decent switches will allow it to be done via both telnet and web based, HPs, Cisco, Netgears all do from experience. Ciscos can be a bit funny about it, but ours are now very old so it might just be the firmware we have. If you had a 2nd Wifi Network but no seperate VLAN, the guests would access the same range as your normal flat network as your DHCP server couldn't tell the difference between a guest and a normal client. If you use all fixed IPs you could make it so you knew which IP addresses were on the Guest Wifi and then use the Access Control built into Unifi to restrict them to accessing on certain IP addresses. Maybe you could use that to control access anyway without everything else on fixed but it might be a long winded way. You would definitely need your Guest Wifi to have a password as well though, well I would personally. The real issue is how you get those on the Guest Wifi to authenicate against any filtering to gain any form of Internet access, because you couldn't identify by IP easily unless the above bit is true, so the only thing you could offer would be a login page for your filter, which is far from ideal.
themightymrp Posted June 21, 2016 Posted June 21, 2016 Maybe its too complex but if you are stuck with the one VLAN, could you make use of an IPsec policy whereby only domain joined PC's can communicate with each other? A guest device wouldn't get that policy and so wouldn't be able to get at your servers etc?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now