manick Posted February 1, 2011 Posted February 1, 2011 Hi all, OK, following on from my original request for help http://www.edugeek.net/forums/networks/69311-aruba-meru-ruckus.html, I am now starting to get myself bogged down in what exactly I need on the back end with regard to security. As I said in my oiriginal question, I am looking at ensuring that any guests connecting to an AP (using a different SSID) would only be able to get out onto the internet and would not be able to touch the network at all. As far as I could see Aruba did this without the need for setting up Radius or anything else of that nature, Am I correct with this? Is it the case that with Ruckus and Meru (don't know anything about Xirrus yet) there is the need to set up either Radius or VLANS? I realise that it could be the case that I'm getting confused, but I just need a little clear guidance here. Any help much appreciated. Cheers Nick
cpjitservices Posted February 1, 2011 Posted February 1, 2011 VLAN it all the way, be the easiest solution. 1
CISCODISCO Posted February 1, 2011 Posted February 1, 2011 (edited) VLAN sounds good. Don't forget the ACL's to block the VLAN from being routed to the rest of the network/VLAN's :-) I haven't read the other thread but they probably set the RADIUS up for authentication. Edited February 1, 2011 by CISCODISCO
MicrodigitUK Posted February 2, 2011 Posted February 2, 2011 I believe all 3 systems (Ruckus and Aruba do as I have worked with both systems)have captive portal functionality that can authenticate to an internal database of users/ gest passes or Active Directory for existing users.
manick Posted February 2, 2011 Author Posted February 2, 2011 Do you mean an internal database within the controller for those users not on active directory? (thanks for the help guys!)
Lazzaman123 Posted February 2, 2011 Posted February 2, 2011 2 VLANs is the answer. Trunk the 2 VLANs down to you AP, manage it in your private network and present the public as another SSID. You will need to route a different subnet for your public network and use ACL's or a firewall to separate the two networks. What hardware are you using for switching/routing?
manick Posted February 2, 2011 Author Posted February 2, 2011 At present we have a load of old D-link kit DES 1024Rs, a DES-6000 and a Cisco 2800, but were looking at upgrading a fair few of the switches, we are looking at the Cisco Small Business SG 200-26P 26-port Gigabit PoE Smart Switches, just to get the backbone up to 1gb and also have PoE ports for wireless APs. But if Aruba et al can zone off guests (Aruba's controller has a built in firewall which does this apparently) why do I need to go down the VLAN route?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now