Guest WiFi Help

Using a Balance 305, SD Switch and Enterprise APs…

What is the best way to allow guest wifi users access to the internet but isolate them from the other devices on the newtork? VLAN, subnet…?

We are new to larger deployments like this and would appreciate any constructive help/feedback.

Thanks in advance.

Create a new VLAN/Subnet, untick inter VLAN routing. assign the Guest Wifi SSID to it.
Then consider setting up a captive portal to restrict usage by time / data.

1 Like

Assuming these are Peplink APs, I use the Guest Protect option in the SSID. You have to click on the question mark inside the SSID setup which causes the fields to display. We have multiple LANs connected by PepVPN. For the Guest SSID I list all the LANs on the Guest Protect list, and also check “block PepVPN.”

Martin, is my method any more or less secure than using a separate VLAN?

I use Martin’s VLAN approach, which works well because I also have the wired jack in the guest room on the same VLAN as that guest SSID.

1 Like

I found that, in order to fully isolate a guest wifi network on my balance One, I need to do two things:

  1. disabling inter-vlan routing in the VLAN network setup
  2. If you use PepVPN an internal firewall rule to disallow access from the Guest vlan to the other vlan(s) on the other side of the PepPVN tunnel. Note vlans count as internal traffic for the firewall.

Barthold

1 Like