Guest and Internal WLAN

Hi,
Can you please suggest how to implement this set-up? Two wlan's to be created internal and guest, where guest will be directed to Internet only. WLC deployed on this set-up. Internal users must be authenticated, kindly suggest mechanism. can i do mac-address filter with WPA2 for internal? If i am to implement ACL preventing Guest to access Internal VLAN, would this work?

Hey Joseph,
Please find the steps below.
1) Create seperate VLANs for Guests and Internal staff.
2) You can use VACLs for blocking inter VLAN traffic from your L2 swithc or if ther is a router simple ACL would do the trick.
3) You can setup a local AD server which can be used for authenticating internal staff
     (No need for guests to authenticate via this AD)
There are many ways to achieve, I need the exact setup.
The one that you have posted is ambiguous as it is unclear whether there is a router/L3 swithc between the WLC and ASA or ASA itself is acting as an L3 device and serving your routing purpose.
Please rate helpful posts..
Ameya

Similar Messages

  • Internal WLAN vs Guest WLAN

    Hello
    I have a Cisco AIR-CT5508-K9 running revision 7.
    Can anyone explain to me the differences between a guest type WLAN and a WLAN type WLAN please? I have searched a fair bit but can't actually find an explanation.
    Also, can any one please let me know what the profile name is for please? I see that the SSID is removed on a guest lan so it must be important in some way.
    Thanks all in advance
    Anthony

    Hi,
    Q1>> Can anyone explain to me the differences between a guest type WLAN and a  WLAN type WLAN please? I have searched a fair bit but can't actually  find an explanation.
    ANS - Guest WLAN is mostly for the WIRED GUEST USERS and the Normal WLAN is for the Wireless users.. so If you want to create a guest LAN for wired guest users, choose Guest LAN
    The below link will explain you on the Wired Guest users..
    http://www.cisco.com/en/US/docs/wireless/controller/7.0/configuration/guide/c70users.html#wpxref20380
    Also most of the Guest WLAN will have a time stamp configured for  the client so that after that time stamp the client entry will be inactive..
    lemme know if this answered your question..
    Regards
    Surendra
    ====
    Please dont forget to rate the posts which answered your question and mark it as answered or was helpfull

  • WLCs 5508, HA enabled and Internal DHCP

    Hi:
    Designing a new project for a customer in which a pair of WLC-5508 and a bunch of AP-3602I will be deployed.
    Controllers running 7.4 image, and I'd also like to use them as internal DHCP servers for clients in different WLANs
    As for the redundancy mechanism I'd go for activating HA (AP-SSO) but I know HA and internal DHCP server can't coexist.
    So, my question is: does anyone know if Cisco is thinking of implementing both features in any new version to come? The goal would be the Active controller handing over all leases database in case of active to standby switchover.
    Thx!
    Juan.

    As you already know that HA and DHCP both cannot coexist on WLC. Till now there is no plan of cisco to implement this.

  • Security for Internal WLAN

    I'm trying to figure out the best way to set up authentication on my WLAN for my internal users. I want to use certificates but I'm not exactly sure what layer 2, layer 3 and AAA settings I need to configure for certificates. If I do certificate authentication is that enough or do I also need to use something like RADIUS authentication?
    Anyone got any good docs or recommendations on how to configure my WLAN for certificate authentication? Also, I'm curious what methods other people are using to secure their internal WLANs.
    Thanks. 

    If you're looking for WLAN authentication, I would recommend PEAP.  It requires all users to use their AD credentials and synchronizes with your AD infrastructure via RADIUS.  You can use your own RADIUS server or ACS / AD for authentication.
    I've used it in the past and it is very good.
    The first link gives you some detail on PEAP.
    http://www.cisco.com/en/US/prod/collateral/wireless/ps5678/ps430/prod_qas0900aecd801764fa.html
    The second link is a configuration guide.
    http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a0080665d18.shtml
    Ven

  • Dual setup for internet and internal access

    Goal: To set up an Xserve that is both hosting public web sites and internal websites. The server is currently connected to the internet via ethernet 1 and to our internal network via ethernet 2. It serves as a backup failover for our main web server and hosts an internal wiki. The wiki is getting more sensitive company information so we want to cut it off from outside access and guarantee that it cannot be hacked or otherwise seen. Someone mentioned a solution using partitioning of some kind to achieve this separation. I haven't been able to find information on this. Can anyone tell me more about what this may be or suggest a setup that will accomplish the same security.

    Here, you have two NICs within one security context.
    A security breach made via one NIC can generally gain access to another NIC within the context of a single operating system. Once the [security of the box is breached|http://labs.hoffmanlabs.com/node/1214] sufficiently to cause you problems (whether data exposures, deletions, defacement or otherwise), then the entire box is generally considered to be untrustworthy.
    If the breach arrives via http port 80 (and that is a typical web server breach), then (once the breach is made) the box itself is compromised. The firewall block here doesn't get you the degree of isolation provided by a DMZ; a breach via port 80 inward or one of these recent browser-based attacks on the firewall aren't necessarily blocked. (Whether the particular web environment is directly vulnerable to a breach is another and open question. Some environments can be more vulnerable to others, but there's the common assumption that all web-facing and internet-facing environments can potentially be vulnerable. That also ties back to how the box is managed and monitored, and how fast a breach can be detected and isolated and sealed and cleaned up.)
    Some operating systems feature technologies known as sandboxes or jails or such, and sandboxes (and jails) are not AFAIK officially available on Mac OS X Server. These are part-way between the default configuration and what's provided by operating as a VM guest. If you really want to learn the innards of the configuration sufficiently, you might be able to get a jail or sandbox or such going, but then tossing another Mac Mini at the problem solves it in what is usually a more supportable fashion than getting a sandbox or jail going and maintaining the configuration over Mac OS X Server patches and upgrades, and application installations and upgrades, and thus at lower cost.
    The approach using a VM tries to avoid extending the exposure by requiring the attacker to breach the underlying VM to get further from the box, and approaches based on a DMZ and on multiple boxes also try to contain or firewall a compromised system.

  • Setup Guest access to WLAN

    I have 8 Cisco 1230AP's providing access to my LAN for laptop users. The encryption is via WPA. I now need to setup unencrypted access to the internet for guests/visitors - keeping them away from my LAN and internal network. How can I do this? Do I just setup a 2nd SSID and allow access to be wide open or do I need to implement some type of VLAN? My switch is unmanaged and it is not a Cisco brand. Thanks for your help...

    I saw your other post and you can ignore that, since you have an unmanaged switch. No matter what you do, all traffic will be dumped out the ap to you lan. This is due to the fact that you can't create a trunk between the ap and the switch which will allow you to have multiple vlans. If you only need guest access in a certain location, you can just add an access point and set that up to go out to a dsl or broadband connection.

  • Guest access to WLAN.

    I have 8 Cisco 1230AP's providing access to my LAN for laptop users. The encryption is via WPA. I now need to setup unencrypted access to the internet for guests/visitors - keeping them away from my LAN and internal network. How can I do this? Thanks for your help...

    the only thing you can really do if your ap's are autonomous is to create another ssid and place that on a different vlan. Then you can use acl's to prevent guest subnet from accessing the internal network. Or you can place the guest user on that different vlan and then have a dsl connected to that subnet for guest users to use. That vlan will not have a layer 3 interface so it will be isolated from the rest of your network.

  • Excise Invoice number and Internal Number

    Hello Friends
    I have some queries ,I will be thankful to you if you could guide me, in understanding themu2026
    1) When we see the document in J1IEX ,in excise invoice tab, we see two fields :Excise invoice number and Internal Number.
    For Internal number we define the range in object J_1INTNUM, but how do we define range for Excise invoice  number
    2) Where do we maintain the relation between GRPO (Excise Transaction type) with the Excise Invoice number
    3) When do we require updating of register ,is it done on daily bases, and  how can we see the entries of RG23A part 1.
    4) We have excise invoice number  range of posted ,in process and cancel documents which is  assigned to GRPO transaction type, while running J1I7 though we select last option   part 1 posted  and part 2 not  posted, still the system shows the cancelled documents, How can I avoid  the cancel documents
    Thanks
    Siddharth

    1) When we see the document in J1IEX ,in excise invoice tab, we see two fields :Excise invoice number and Internal Number.
    For Internal number we define the range in object J_1INTNUM, but how do we define range for Excise invoice number
    -->> Ex inv nbr will be entered based on the vendor ex invoice .. this is external nbr assignment
    2) Where do we maintain the relation between GRPO (Excise Transaction type) with the Excise Invoice number
    --->> there is no relation between grpo vs. ex inv nbr
    3) When do we require updating of register ,is it done on daily bases, and how can we see the entries of RG23A part 1.
    >> u can see in J1I7 or thru table J_1IPART1
    4) We have excise invoice number range of posted ,in process and cancel documents which is assigned to GRPO transaction type, while running J1I7 though we select last option part 1 posted and part 2 not posted, still the system shows the cancelled documents, How can I avoid the cancel documents
    >> wait for others answers..

  • What is the diffrence between External postings and Internal postings in CO

    Dear all,
    Can brief me anyone about the Externa postings and Internal postings in CO,
    I suspected all postings from outside or interface postings is External postings and all FI postings is internal postings, Is it true or not still i am suspecting, anyone pls clarify the doubt.
    Thanks
    Raghu
    Moderator: This forum is not dedicated for basic questions. Please, read SAP material before posting

    Hi,
    All postings which are originated from other than CO module ( i.e from interface, FI etc ), are called External postings in CO.
    Whereas internal postings means posting which happen within CO module, example Assessment, Distribution etc within a company code.
    Njoy
    Siva

  • External and internal mikes are not automatically switching over either recording or on voice calls

    My laptop model name is HP Pavilion dv4-1100ea which is shipped with Vista Home premium 32 bits and has got service pack 1.
    Restored the laptop to factory setting since then I am having the following problems; I had the same problem when my laptop was brand new and whenever I reset the laptop to factory setting I get the following problems:
    1. External and internal mikes are not automatically switching over either in middle of the recording using sound recorder or while the call in progress on voice calls (skype):
       Using the sound recorder if I start recording the sound with external  mike  and in-between  recording if I  switchover from external mike to inbuilt mike and later on when I play back I can only hear the sound  up till where I used the external mike during recording, after the switchover to inbuilt mike I cant hear any sound.
       But if I start the recording with inbuilt mike and in between recording  if I plug in  the external mike and later on when I play back I can only hear the sound up till where I used the inbuilt mike during recording , after the switchover to external mike I cant hear any sound.
       So in brief both my external and internal mikes are working fine, only problem is that if I start recording (using sound recorder) or voice call with one specific mike, I have to continue with it till the end. I can’t switchover to another mike in between the conversation (voice call) or recording, if I do so, I have to select the mike manually in chat software but while recording I cant even select manually because in laptop, it takes the mike whichever is in current use as default mike in recording tab(sound window). The green tick automatically (in recording device tab) switches over according to the use of mike. Though the green tick in the recording tab is switching over automatically according to use of mikes, its not picking up the sound after switch over during recording.
    2. And also when I click on recording device tab in sound window and plug in external mike, though the green tick automatically switchovers from internal to external mike, while I speak both internal and external mikes volume meter respond to the sound inputs by rising and falling but if I take out external mike, green tick goes to internal mike and when I speak only internal mike volume meter respond to sound rising up and down not the external mike.
    To resolve the issue I have tried following steps with no luck:
    1.I have checked the mikes(internal and external) properties, the both mike shows to be enabled in general tab, in level tab the volume is set to 100 and in advanced tab , all options are selected.
    2. In device manager I have got only one audio driver named as “IDT High definition Audio CODEC”. I have uninstalled the audio driver and reinstalled it using scan for hardware option
    3. Uninstalled the audio driver in device manager and reinstalled the audio driver using recovery manager > advanced option> hardware driver re-installation.
    3. I have updated the BIOS(Insyde F.65, 12/02/2010).
    4. I tried to update the audio driver using below link but things went more worse so I did system restore (not factory setting though).
    http://h10025.www1.hp.com/ewfrf/wc/softwareDownloadIndex?softwareitem=ob-67051-1&lc=en&dlc=en&cc=us&...

    Sounds like you need to upgrade to the iPhone 5s
    The 5s has Touch ID
    You can unlock your phone with your finger instead of typing in a key code
    No swiping to unlock either, just touch the home button
    You can enrol multiple fingers as well
    Here is a video of it in action
    http://www.apple.com/iphone-5s/videos/#video-touch
    Or wait and see what iPhone 6 has to offer
    That being said, as desiel vdub posted if the phone is up to your face, the proximity sensor should turn the screen off
    And when you lower the phone turn it back on again
    Not sure about the phone locking when your on a call doesn't sound right

  • I tried dowloading Skype yesterday and my Safari browser crashed.  It gives the message "Safari quit while using the librooksbas.dylib plug-in.  I trashed Skype but still have the browser problem.  I also tried logging in under guest, and no Safari.

    I tried dowloading Skype yesterday and my Safari browser crashed.  It gives the message "Safari quit while using the librooksbas.dylib plug-in.  I trashed Skype but still have the browser problem.  I also tried logging in under guest, and still
    no Safari.

    Julie --
    Backing up QuickTime's advice --
    Unless your bank's website is insecure, you're fine.  Go up to the Safari "Search" bar and type in Rapport.  You'll be amazed.  It may  "work" on PCs, but definitely not Macs.  And it's not needed for Macs.

  • PO and internal order

    Hello i have a question concerning PO and Internal Orders.
    I have created some Internal Orders and i have made a PO for assets with this internal order (internalorder1)
    Now i have authorised a user with another internal order number.(internalorder2)
    Can i somehow prevent a user to release POs for internal orders according to the authorised internal order.(internalorder2)
    Maybe the authorization object k_order the field co_action???

    If you use TCode SU24 to look at the authorization object checking for the object K_ORDER you will see that this object is not checked for TCodes ME21, ME21N, ME22, ME22N, ME23, or ME23N.  This is probably why you can still use any internal order whether you have it in your profile or not.  You might be able to add the authorization object to these to the MM_E Materials Management: Purchasing class.  I think you can use TCode SU21 to maintain these objects, but you need to check with your Basis/Security personnel.
    As a test you can use SU24 to look at object M_BEST_EKO Purchasing Organization in Purchase Order.  You will find that it is checked in pretty much every PO creation or change TCode (ME21, ME21N, ME22, ME22N, ME23, ME23N, ME24, ME25, ME26, ME27, ME28, ME29N).
    Regards
    Edited by: Paul Shrewsbury on May 11, 2009 2:32 PM

  • SAP QUERY LOOPS AND INTERNAL TABLE

    Hi All, I have a query which i have made. It runs from Table EKPO which has PO details and what I want to do is now via ABAP Code pull through the total of goods receipt for the PO and Line Item into a field. Sounds Easy enough..Problem now,
    The table which contains the GR data is EKBE which agains a PO and Line Item can have many 101 movements and 102 movements so what I want is an ABAP Statent to basically sum up the total of 101 for the PO & LINE ITEMS and then minus this from the total of 102 for the PO & LINE ITEMS and post the result in to this new field I have created.
    I am pretty decent with ABAP Code in Querys I.e Select statements etc but from what I can see i need to create an internal table and do a loop and collect statement but I keep on failing due to not enough knowledge. Please can some one help me with this and provide me with the code and explanation as i would like to understand,
    POINTS WILL BE REWARDED
    Thanks
    Kind Regards
    Adeel Sarwar

    Hi,
    This is the full code i have entered but its not working. Any help would be appreciated. If you could rectify the code and internal tables that would be great.
    Thanks
    TABLES: EKBE.
    DATA: PurO LIKE EKPO-EBELN,
          POLI LIKE EKPO-EBELP.
    *New Table and Vars defined
    DATA:   BEGIN OF IT_EKBE,
              IT_EKBE LIKE EKBE,
            END OF IT_EKBE.
    DATA:  BEGIN OF IT_SUM OCCURS 0,
              EBELN TYPE EBELN,
              EBELP TYPE EBELP,
              DMBTR TYPE DMBTR,
              MENGE TYPE MENGE,
          END OF IT_SUM.
    CLEAR: QTYD.
    MOVE: EKPO-EBELN TO PurO,
          EKPO-EBELP TO POLI.
    SELECT * FROM EKBE INTO IT_EKBE
        WHERE EBELN = PurO
        AND   EBELP = POLI
        AND   BEWTP = 'E'
    LOOP AT IT_EKBE.
      MOVE CORRESPOING IT_EKBE TO IT_SUM.
      IF IT_EKBE-BWART = '102'.
        IT_SUM-DMBTR = IT_SUM-DMBTR * -1.
        IT_SUM-MENGE = IT_SUM-MENGE * -1.
      ENIDF.
      COLLECT IT_SUM.
      CLEAR IT_SUM.
    ENDLOOP.
    ENDSELECT.
    If sy-subrc = 0.
      QTYD = IT_SUM.
    ELSE.
      QTYD = 0.
    ENDIF.

  • I changed my data plan from 6g to 8g while my daughter who attends college outside of the US at Toronto Canada (and we have on a international calling and international data plan) was on spring break at her grandparents house here in the US. I made the ch

    I changed my data plan from 6g to 8g while my daughter who attends college outside of the US at Toronto Canada (and we have on a international calling and international data plan) was on spring break at her grandparents house here in the US. I made the change online since I had been waiting on the phone for over 10 minutes for a customer service rep to come available. Well when I made the change online since that seems to be the thing that Verizon wants it's customers to do and I didn't see all the different plans available and just did the upgrade to 8g. Next bill had over $900 in roaming charges on her phone line. I called the 1-800 number and waiting for a service rep and after 20 minutes of waiting and being put on hold was told it was the customers mistake and there was nothing they could do.Thanks for nothing. I called back after thinking about it and wondered why changing a data plan for the phones in the US would change a international call plan. Waiting over 10 minutes again between waiting for a service rep and hold for one to answer the call. Gave her all the information about it and she said she would call back. Well, 4 days later over the weekend she had nevered called back. So on the phone again for the third time and after 20 plus minutes again was told that when I did it online I click the plan that didn't include international call only the data plan. Explained that I never saw the difference in the plan packages so put on hold again and was told that they could credit $100 to my bill. Wow, thanks alot !!! We have been Verizon customers for probably atleast 12 years and this is how you treat your long term customers?

    Verizon Wireless Customer Support wrote:
    AHARDY454,
    We definitely want to review options on what has happened. We are now connection, so you can hover over my username and send me a Direct Meesage so we can review your account information. We look forward to reviewing.
    Thank you,
    TonyG_VZW
    Follow us on Twitter @VZWSupport
    TonyG_VZW they can't exactly hover over your username unless you actually link it in your post. The generic username for all the reps just doesn't fly.

  • Export - Import In ABAP ( for variables and internal table)

    how can we pass value for the variable and internal table using Export and Import?
    data: var type sy-uzeit.
    var = sy-uzeit.
    EXPORT var TO MEMORY ID 'TIME'.
    data: var type sy-uzeit.
    IMPORT var FROM MEMORY ID 'TIME'.
    write:/ var,sy-subrc,sy-uzeit.
    i found var value 0 while importing. 
    what is the right syntax for passing value of variable and internaltable.
    regards,
    dushyant.

    Hi,
    There are two possible solutions.
    Solution1:
    Program1.Should be run before atleast once so that TIME should be filled.
    data: var type sy-uzeit.
    var = sy-uzeit.
    EXPORT var TO MEMORY ID 'TIME'.
    Program2.IF the TIME is filled,then only it will produce the result.
    data: var type sy-uzeit.
    clear var.
    IMPORT var FROM MEMORY ID 'TIME'.
    write:/ var, sy-subrc, sy-uzeit.
    Solution2:
    Single program:
    data: var type sy-uzeit.
    var = sy-uzeit.
    EXPORT var TO MEMORY ID 'TIME'.
    clear var.
    IMPORT var FROM MEMORY ID 'TIME'.
    write:/ var, sy-subrc, sy-uzeit.
    Kindly reward points by clikcing the star on the left of reply,if it helps.

Maybe you are looking for

  • Random shutdown MacBook Pro

    I can't find this specific problem anywhere apart from on postings that are a couple of years old. I have a 2 year-old Macbook Pro that has never given me a moment's worry. Except on the 1 January when it refused to start up. It would get to the grey

  • Signature on text msg

    Can I add a signature to all of my outgoing text messages?  If so, how do I do it?

  • Select statement issue- urgent pls help

    Hi The following select statement is always  failed, even LIKP table has data. pls help me   LOOP AT LT_VBRP.     IF LV_KEEP_VGBEL <> LT_VBRP-VGBEL.       LV_KEEP_VGBEL = LT_VBRP-VGBEL.       CLEAR LIKP.       SELECT single  VBELN TRAID TRATY VERUR B

  • Moved CS6 Project to new computer, now Premiere CC won't use correct fonts

    I recently moved a CS6 project with very complex font designs to a new computer. I installed the fonts I needed on the new computer and opened the project in Premiere CC. I was prompted to create a new CC version of the project, which worked fine, bu

  • Sound on Macbook Pro Retina is faulty, plays at lower pitch than it should

    Retina, 13-inch, Late 2013 Memory  16 GB 1600 MHz DDR3 Graphics  Intel Iris Software  OS X 10.9.4 I turned on my mac this morning and the mac logo chime was a lower pitch than usual. I thought it might have just been me then I played a track on itune