Jump to content

Recommended Posts

Posted

Is it possible to have 2 dhcp ranges running at the same time on the same server? I am having an issue with filtering and need the byod devices to be on a separate range so they apply the correct filtering policy. This is because my domain machines require a security certificate to filter correctly. Of course this isnt possible to give to byod devices.

 

Any help appreciated

Posted
possibly, basically we have switched via our ISP to a new filtering which requires a user agent on the machine and to install a security certificate. Which is fine when connected as a domain user. The BYOD for obvious reasons wouldnt get either
Posted
possibly, basically we have switched via our ISP to a new filtering which requires a user agent on the machine and to install a security certificate. Which is fine when connected as a domain user. The BYOD for obvious reasons wouldnt get either

We have 12 VLANS at the moment, each one has it's own DHCP range, so 10.22.10.2 to 10.22.10.254, or 10.22.100.2 to 10.22.103.254. This allows us to segregate our network. We do have a VLAN specifically for BYOD, so clients connecting to the BYOD SSID only receive an IP address from the BYOD DHCP/VLAN.

  • Thanks 1
Posted
It's possible, yes, but setting it up to get the correct ip address is going to take some work. Separate VLANS is one option, you can also set up filters on dhcp but that would be fiddly and unreliable.
  • Thanks 1
Posted
Is it possible to have 2 dhcp ranges running at the same time on the same server? I am having an issue with filtering and need the byod devices to be on a separate range so they apply the correct filtering policy. This is because my domain machines require a security certificate to filter correctly. Of course this isnt possible to give to byod devices.

 

Any help appreciated

 

If you have layer 3 switches then you could setup different vlans for BOYD but I'd personally use a firewall and put the BOYD gateway there and then you will have easier control over the traffic you may want to allow to your internal network.

 

Your Firewall or WiFi solution may give you option for captive portal where users could download a certificate for BOYD devices, this is how I did this before.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...