northeast_technician Posted July 10, 2019 Posted July 10, 2019 Is it possible to have 2 dhcp ranges running at the same time on the same server? I am having an issue with filtering and need the byod devices to be on a separate range so they apply the correct filtering policy. This is because my domain machines require a security certificate to filter correctly. Of course this isnt possible to give to byod devices. Any help appreciated
northeast_technician Posted July 10, 2019 Author Posted July 10, 2019 possibly, basically we have switched via our ISP to a new filtering which requires a user agent on the machine and to install a security certificate. Which is fine when connected as a domain user. The BYOD for obvious reasons wouldnt get either
CHiLL Posted July 10, 2019 Posted July 10, 2019 possibly, basically we have switched via our ISP to a new filtering which requires a user agent on the machine and to install a security certificate. Which is fine when connected as a domain user. The BYOD for obvious reasons wouldnt get either We have 12 VLANS at the moment, each one has it's own DHCP range, so 10.22.10.2 to 10.22.10.254, or 10.22.100.2 to 10.22.103.254. This allows us to segregate our network. We do have a VLAN specifically for BYOD, so clients connecting to the BYOD SSID only receive an IP address from the BYOD DHCP/VLAN. 1
bald_pig Posted July 10, 2019 Posted July 10, 2019 It's possible, yes, but setting it up to get the correct ip address is going to take some work. Separate VLANS is one option, you can also set up filters on dhcp but that would be fiddly and unreliable. 1
Davit2005 Posted July 10, 2019 Posted July 10, 2019 Is it possible to have 2 dhcp ranges running at the same time on the same server? I am having an issue with filtering and need the byod devices to be on a separate range so they apply the correct filtering policy. This is because my domain machines require a security certificate to filter correctly. Of course this isnt possible to give to byod devices. Any help appreciated If you have layer 3 switches then you could setup different vlans for BOYD but I'd personally use a firewall and put the BOYD gateway there and then you will have easier control over the traffic you may want to allow to your internal network. Your Firewall or WiFi solution may give you option for captive portal where users could download a certificate for BOYD devices, this is how I did this before.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now