Chapter 3. Design and Implement Guest Access Services

Guest networks should use the existing enterprise wired and wireless infrastructure as much as possible. It is cheaper and simpler than creating an overlay network. You need the following elements to achieve this:

• Dedicated guest WLAN/VLAN

• Method for segregating guest traffic from corporate traffic

• Appropriate guest access control

• Guest user account/credential management

Understanding Guest Access Architecture

Traditional Guest Access

It was common in wired networks to create a guest VLAN in a demilitarized zone (DMZ) network. Firewall rules at the DMZ router allowed unfettered access to the Internet but isolated the guest user from the corporate network. Early guest WLANs were created ...

Get CCNP Wireless (642-737 IAUWS) Quick Reference now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.