Chapter 3. Design and Implement Guest Access Services

Guest networks should use the existing enterprise wired and wireless infrastructure as much as possible. It is cheaper and simpler than creating an overlay network. The following is a list of elements needed to achieve this:

• Dedicated guest WLAN or LAN

• Method for segregating guest traffic from corporate traffic

• Appropriate guest access control

• Guest user account/credential management

Understanding Guest Access Architecture

Traditional guest access

It was common in wired networks to create a guest VLAN in a demilitarized zone (DMZ) network. Firewall rules at the DMZ router allowed unfettered access to the Internet but isolated the guest user from the corporate network. Early guest ...

Get CCNP Wireless IAUWS Quick Reference now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.