Jump to content

Recommended Posts

Posted

I have the guest portal working fine with codes with our Unifi setup, it is in its own VLAN with up to 62 addresses. The APs all take an address leaving about 25 addresses for clients. This is a rarely used thing, but the issue is the hundreds of phones in the building join the open network that the portal is on and just sit there taking up an IP address and therefore a legitimate user is unable to even get to the portal page :mad: . Now I only have so many IP addresses to play with in order for the filter to be able to identify traffic from clients by the county assigned ranges, otherwise I would give it a much larger private IP range.

 

What am I missing here, the lease duration is already set to a short time which only really helps between days.

 

Is there a setting on the Unifi controller or something I can do with IAS/Radius and the DHCP server to temporarily ban from the DHCP server unless authorised etc or a much simpler solution?

 

Thanks

 

Chris

Posted

1) Extend the VLAN and move the APs to statics (beyond your county identification range), leaving more room for actual users.

 

2) Add a static password to the guest network (the SSID) before they hit the actual guest portal, so that passers-by aren't occupying IPs.

 

3) I don't know about this but I suspect you can kick clients off that haven't authenticated in x amount of time.

  • Thanks 1
Posted

1) The APs occupy an additional IP address in the guest range as well as their main management IP so I'm not sure if I can do this.

2) Probably going to be the answer for now at least

3) This was the kind of solution I was hoping for

 

Thanks for all the suggestions.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...