Guest Network Won't Serve IP Addresses

I have enabled the guest network feature on an AirPort Express. I have the AE in bridge mode so that any connecting devices receive their IP addresses from our Windows Server (functioning as a DHCP server). Devices have no trouble connecting and receiving IPs when they connect to the main (password-protected) network, but when a device connects to the Guest network (no password) they do not receive an IP address and generally end up "self-assigning" themselves an IP.
I am creating a roaming network of Apple AirPort Extremes and Expresses at our K-8 school. I can't find any similar situations mentioned online. Any ideas? Is there perhaps an issue between the Windows Server 2003 and the Airport?

Hi!
thanks everyone for the brainstorm.
I managed to get it working.
Airport Extreeme base station with 2,4 and 5ghz modes working,
Guest network too, and the AE is set into bridge mode!
I have another router, that does the routing and dhcp. That is a mikrotik RB450 router with 5ports.
The trick is to have AE connected with 2 wires to the main router!
The main wire goes from AE Wan port to the main router lan port, and the second wire goes from AE lan port to the routers other internal lan port. The AE is set to get external ip from my router and that chain works alright.
Now the second wire is connected to an isolated port on the router. That way we make sure we serve the whole purpose of GuestNetwork. That isolated port is also set as a master port to host VLAN port with ID=1003.
The last thing to do is to make a separate dhcp service running on the VLAN port alone. (not the phisical port).
It doesn't matter what ip range you give out by your second dhcp service, as long as it plays well in your subnet scheme. You can simply put both your main and the guest networks close like 192.168.1.0/24 and 192.168.2.0/24. The dns enries stay the same for both networks.
It should work with any router capable of VLAN and with at lease two lan ports avail.
Forget about sniffing ip ranges out of your AE device. It's useless! Along with the vlan tag 1003 any dhcp service met on the vlan path will respong to your guest request.
Good luck!

Similar Messages

  • TS4505 Unable to connect to internet over Guest Network  (Airport)

    I have changed the guest network's DNS server IPv4 addresses to 75.75.75.75 and 75.75.76.76 and rebooted base station.  These are the values for Comcast.
    Still not able to connect to internet over this guest network.
    Do I need to do anything else?  Help!

    Bob - thank you for your quick reply.  My setup is as shown in the attached image:
    My guest network is on the Apple Airport TIme Capsule (v7.7.2).  Router mode for this time capsule shows "Off (Bridge Mode)" but grayed out.  No edits possible as shown below:
    Northbound of the Time Capsule is my Apple Airport Extreme (v7.6.4) that is in turn connected to a Comcast uBee DDM3513 Docsis 3.0 Cable Modem.  I believe it is this one.

  • Guest network...can't get it to stick

    I'm trying to add a Guest Network to my existing airport network (using the current model Airport Extreme base station) and can't get it to work.
    Scoured the entire Airport Utility settings looking for it, nowhere to be found. Finally decided to reset the base station to factory default, and then the Guest Network tab finally appeared.
    Created a new wireless network with suitable settings & security, turned on Guest Network, updated the base station. After uploading the configuration, eventually got the green light and everything was working.
    Went to try to connect to the guest network on my Mac. Clicked the airport icon in the menu bar, where I saw my main network and the new guest network listed. But only for a moment...then the guest network disappeared from the list. Went back to the airport utility, the guest network tab had disappeared there, too.
    Repeated this entire process 3 more times with the same results. I have no idea why the guest network won't stick. So I'm desperately hoping someone here does.
    FWIW, my Airport Extreme is connected to a FIOS modem/wireless router, and I've never hand any issues with my airport network. I have two Airport Expresses on the network as well, one for printing and one for music streaming to the stereo. Everything works fine except I can't get the guest network established. I'm totally perplexed.
    thanks in advance,
    -Nelson

    +FWIW, my Airport Extreme is connected to a FIOS modem/wireless router, and I've never hand any issues with my airport network. I have two Airport Expresses on the network as well, one for printing and one for music streaming to the stereo. Everything works fine except I can't get the guest network established. I'm totally perplexed.+
    When you had the AirPort Extreme configured and could not locate the Guest Network tab, it was configured in Bridge Mode.
    AirPort Utility > Manual Setup > Internet icon > Connection Sharing = Off (Bridge Mode)
    This is the correct setting for your setup since your FIOS modem/router is the "main" router for your network. To work correctly on your network, the AirPort Exptrem must be configured in Bridge Mode to allow the FIOS router to control the network.
    In order for the Guest Network feature to function correctly, your Airport Extreme must be connected directly to a simple modem (only one ethernet port). Unfortunately, you won't be able to utilize the Guest Network feature as long as your FIOS router remains on the network.

  • Need DHCP ending address to set up Guest network on Airport expressk

    I have a 2wire modem router that I attached an Airport express to to resolve the issue of constant droppin gof the internet. The wireless and outing are turned off the 2 wire so it acts as a simple modem. I then was able to access the the section in Airport Utility to set up the Guest Network. When I change the net work from Bridged to Shared, I had errors for the beginning and ending DHCP #s. I have the beging number but have no idea what the ending number is or how where to look.

    The error message is the DHCP range conflicts with the WAN IP address. The default range that was entered by the utility was 192.168.1.2 to 192.168.1.200. It does not like the begining or the ending address. i entered 192.168.1.254 (DNS server and router) and it accepts that s the starting  address.

  • Setup Guest Network with OS X Server and Airport Extreme - NEED HELP!

    Hi All,
    So I have a small business with a Mac Mini Server (10.6.5) and an Airport Extreme. The Airport is handling the routing and DHCP duties, while the Server is handling the DNS. The Airport is pointed to pull DNS from the Server. All internal systems work great accessing the internet and folders on the Server.
    I need to setup a Guest network for internet access, so I turned this function on in the Airport Extreme. It sets up fine, but if you connect to that new Guest Network the system hangs trying to open a web page. My thinking is since the Server is the one handling the DNS it is not working for Guest computers since they are not part of our internal network. At least that is my theory, I could be wrong.
    With this type of setup what do I need to modify to get this working? Anyone have any ideas?

    After trying for days to figure this out I was finally able to get a working solution and I now have my APE providing a guest and main network while using my lion server as the Dsn server for the main network.
    The setup is a bit of a hack and does require you to have at least two devices with staticly assigned ip information on the main network but it does allow you to serve dhcp for both networks from the server and make some services available to the guest network such as iTunes remote for parties.
    1) delete your custom Dns entries from the Internet settings in the APE and set two dhcp reservations for .2 and .3 (in this case my Mac mini server and my airport express)
    2) reduce the dhcp range to only have 2 available IPs (10.0.1.2-10.0.1.3) and save settings
    3) on a computer connected to the main network install wireshark and begin sniffing for packets. Connect at least one device to your guest network and look for any packets that have an ip from your guest network (usually 172.16.42.x) once you capture one of these packets expand the vlan information. This should list a vlan ID ( in my case this was 1003. I would suspect this is universal but do not know)
    4) on your server open network preferences, click the gear at the bottom and click "manage virtual interfaces", add a vlan that matches the vlan ID from above. Click ok and apply your settings. The vlan interface should get an ip in the guest network range from your APE.
    * if you are running lion you will need to install server admin tools before proceeding*
    5) open server admin and add the dhcp service. Create an entry for your primary network (ex: 10.0.1.x) make the dhcp range one higher than the settings in step 2 ( ie: 10.0.1.4 to 10.0.1.253) assign this to the physical interface. Make sure this entry has your internal DNA servers
    6) add another entry for the guest networks ip range (ex: 172.16.42.x) again set it one ip higher than step 2 ( 172.16.42.4 to 172.16.42.253) save and activate both ranges. Assign this range to the vlan interface. Make sure this entry either contains your isps dns servers or another public dns server. Turn on dhcp.
    Because you have now assigned the only two addresses in the APEs pool for your primary network to static entries there will not be any addresses to assign and the APE will not respond to requests. This will allow your server to pick up the work of assigning IPs. As for your guest network, the APE will assign IPs for two host and then stop. Your clients may either get an IP from the APE or the osx server so both should have the same info. Just make sure the two static clients on your main network have the local DNA servers entered manually.

  • Guest network feature of Time Capsule/Airport Extreme in conflict with DNS on OS X Server?

    Hi, I want use the guest network feature of Time Capsule/Airport Extreme which requires an external DNS server but my OS X Server is the dns server...Can I configure server and airport with an external dns without messing up my OS server?
    Thx Ron

    If you want to use the guest network while also using your server for DNS - you will need to do the following:  It's a bit painful - but it works.
    On your Airport Device (Airport Extreme or Time Capsule) - in the Internet tab you will need to do one of the following:
    1)  Leave the DNS Servers Blank - which they will default to the DNS servers provided by your ISP.
    2)  Actually enter your ISP's DNS servers.
    3)  Enter Open DNS servers (I use 208.67.222.222 / 208.67.220.220).
    The DNS servers specified in the airport device must be internet routable addresses (if you are going to use the guest network functionality) - and cannot refer to private ip address (e.g. 10.x.x.x, 192.168.x.x, etc).
    Here is the painful part...on all of the devices (Macs, PCs, phones, ipads - that will be used on your "private" network 10.0.1.x - you will need to provide static DNS setting (but still allow DHCP to assign the devices IP address).  You will specify 10.0.1.13 as primary DNS and 208.267.222.222 (or your ISP's primary DNS IP).
    One you do this - your devices that you permanently use on your local network - will still use your server for DNS - and the external DNS - should your DNS server happen to be down.
    Anyone visiting your house - will connect to your guest network - and automatically be DHCP assigned a guest IP address - and the external DNS servers that you specified in the Airport Extreme device.
    This has been working great for me.  I suspect that the guest network functionality is flawed in the Airport Extreme/Express and Time Capsule.  Since I do not have another router that provides a guest network - I cannot say whether this issues is limited to the Airport devices - or whether this workaround would need to be done - regardless of which brand of router is providing the guest network.
    In a nutshell - your household permanent devices will have to specify static DNS servers - but your guests will connect seamlessly without having to change and risk messing up any of their device settings.
    If this solution works for you - Please be sure to click either "This solved my problem" or "This helped me".

  • How to setup the guest network just access internet only (not touch in internal server)

    I had setup the AirPort Extreme in basic and guest network, but observed the guest can access to our server currently, for the security issue, we can setup the guest network to access internet only? pleae advice and thanks

    By default, a properly configured Guest network on the AirPort Extreme only allows network clients to access the Internet. No access to the "main" network's resources should be available.
    This is assuming that the AirPort Extreme is the only or "main" router in your current network configuration.

  • How can I use Guest network when my internal server provides the DNS?

    How can I use guest network when my internal server provides the DNS? The help article TS4505 tells me to enter an external DNS server, but I believe I can not configure my network that way...

    Apple assumes that you will be connecting the Time Capsule to a simple modem....and.....that the Time Capsule is configured as a router to provide DHCP and NAT services for the network.
    The Guest Network cannot be enabled correctly unless the Time Capsule is in charge of DHCP and NAT services on the network.
    Another way of saying the same thing is that the Guest Network will not operate correctly if the  Time Capsule is configured in Bridge Mode or DHCP Only.

  • 5760 guest network not receiving IP address

    I'm testing a pair of 5760s for a near-term production rollout.  I have the dot1x employee wlan working, but am having trouble with the guest web-auth wlan.  We have a foreign controller with connected APs and an anchor controller in the DMZ.  We're using an external redirect to the ISE guest portal.  ISE is working with our production equipment and hasn't been changed.  However, I'm not able to get an IP address assignment to test the ISE redirect.  When I remove all of the web-auth configuration, I'm getting an IP address without issues.  My configuration is attached below, and would appreciate an extra set of eyes.
    !! Anchor controller
    aaa group server radius ISE
     server name iseservername
    aaa authentication login ISE-MethodList group ISE
    parameter-map type webauth global
     type webauth
     virtual-ip ipv4 x.x.127.1 virtual-host guest-redirect.domain.com
    parameter-map type webauth Guest-param-map
     type webauth
     redirect for-login https://guestportal.domain.com:8443/guestportal/portal.jsp
     redirect portal ipv4 x.x.164.35
    ip access-list extended Guest-preauth
     permit udp any any eq domain
     permit udp any eq domain any
     permit udp any any range bootps bootpc
     permit tcp any any eq 8443
     permit tcp any any established
    ip access-list extended Guest-redirect-acl
     permit tcp any any eq www
    radius server iseservername
     address ipv4 x.x.164.35 auth-port 1812 acct-port 1813
     key [verysecretkey]
    wlan Guest 1 Guest
     client vlan 330
     ip access-group web Guest-preauth
     mobility anchor
     no security wpa
     no security wpa akm dot1x
     no security wpa wpa2
     no security wpa wpa2 ciphers aes
     security web-auth
     security web-auth authentication-list ISE-MethodList
     security web-auth parameter-map Guest-param-map
     no shutdown
    !! Foreign Controller
    wireless management interface Vlan60
    wlan Guest 1 Guest 1
     client vlan 60
     mobility anchor x.x.60.160
     no security wpa
     no security wpa akm dot1x
     no security wpa wpa2
     no security wpa wpa2 ciphers aes
     security web-auth
     no shutdown

    Have you tried this by enabling DHCP snooping for the vlan 330 on your 5760  & trust 5760 uplink ? In the below I have assume 10G port of 5760 is map to a etherchannel (Po1). Otherwise trust the physical interface.
    ip dhcp snooping
    ip dhcp snooping vlan 330
    interface Port-channel x
     switchport trunk native vlan x
     switchport trunk allowed vlan x,y,z
     switchport mode trunk
     ip dhcp snooping trust
    HTH
    Rasika
    **** Pls rate all useful responses ****

  • HT3477 I am attempting to set up a guest network. When I change the Network settings to DHCP NAT I get a message that tells me that the service has a private IP address and so I must connect using off bridge mode. In this mode I can not connect to the int

    I am attempting to set up a guest network on the Airport Extreme Base Station. The Base Station is connected to a DSL Modem. The network is also extended using an Airport Express. When I have attempted to set up the Base Station using DHCP NAT in the netword feature I get a message that because the service has a private IP address the only way that I can connect is in Off Bridge Mode. In this mode I do not seem to be able to connect to the internet using the guest network. Any suggestions would be helpful.

    Ok, your Speedport is actually a combination DSL modem and wireless router. In this case you would typically configure a downstream router, like your AirPort Extreme in Bridge mode. Unfortunately, when in Bridge mode, the AirPort does NOT support providing a guest network.
    The only possible option is to reconfigure the Speedport as a bridge and use the Extreme as your Internet router. You would still need the DSL modem provided by the Speedport for Internet connectivity.

  • Mac Lion won't accept IP address sent from DHCP server

    Upgraded to Lion a few days ago.  Everything worked for a couple days.  Plug in the ethernet cable today and I never get an ip address with DHCP from my router.  I have 2 other devices plugged into the router and they get ip addresses normally.  Captured the DHCP communication to see if I was getting a valid DHCP offer and I am...it is included.  The Lion firewall is disabled.  For some reason Lion isn't accepting the DHCP offer.  Could this be a bug or maybe something in a cache needs to cleaned out.  I connect to several different networks daily and they all work except for this one.
    The line in Bold type shows the ip address being offered that never gets accepted by lion.
    No.     Time        Source                Destination           Protocol Info
         26 21.993141   10.19.39.97           255.255.255.255       DHCP     DHCP Offer    - Transaction ID 0x4e299603
    Frame 26 (353 bytes on wire, 353 bytes captured)
        Arrival Time: Aug  5, 2011 19:30:01.105566000
        [Time delta from previous captured frame: 0.001086000 seconds]
        [Time delta from previous displayed frame: 0.001086000 seconds]
        [Time since reference or first frame: 21.993141000 seconds]
        Frame Number: 26
        Frame Length: 353 bytes
        Capture Length: 353 bytes
        [Frame is marked: False]
        [Protocols in frame: eth:ip:udp:bootp]
        [Coloring Rule Name: UDP]
        [Coloring Rule String: udp]
    Ethernet II, Src: e8:b7:48:e6:ab:5c (e8:b7:48:e6:ab:5c), Dst: Broadcast (ff:ff:ff:ff:ff:ff)
        Destination: Broadcast (ff:ff:ff:ff:ff:ff)
            Address: Broadcast (ff:ff:ff:ff:ff:ff)
            .... ...1 .... .... .... .... = IG bit: Group address (multicast/broadcast)
            .... ..1. .... .... .... .... = LG bit: Locally administered address (this is NOT the factory default)
        Source: e8:b7:48:e6:ab:5c (e8:b7:48:e6:ab:5c)
            Address: e8:b7:48:e6:ab:5c (e8:b7:48:e6:ab:5c)
            .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
            .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
        Type: IP (0x0800)
    Internet Protocol, Src: 10.19.39.97 (10.19.39.97), Dst: 255.255.255.255 (255.255.255.255)
        Version: 4
        Header length: 20 bytes
        Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
            0000 00.. = Differentiated Services Codepoint: Default (0x00)
            .... ..0. = ECN-Capable Transport (ECT): 0
            .... ...0 = ECN-CE: 0
        Total Length: 339
        Identification: 0x00fa (250)
        Flags: 0x00
            0.. = Reserved bit: Not Set
            .0. = Don't fragment: Not Set
            ..0 = More fragments: Not Set
        Fragment offset: 0
        Time to live: 255
        Protocol: UDP (0x11)
        Header checksum: 0x882c [correct]
            [Good: True]
            [Bad : False]
        Source: 10.19.39.97 (10.19.39.97)
        Destination: 255.255.255.255 (255.255.255.255)
    User Datagram Protocol, Src Port: bootps (67), Dst Port: bootpc (68)
        Source port: bootps (67)
        Destination port: bootpc (68)
        Length: 319
        Checksum: 0x038d [validation disabled]
            [Good Checksum: False]
            [Bad Checksum: False]
    Bootstrap Protocol
        Message type: Boot Reply (2)
        Hardware type: Ethernet
        Hardware address length: 6
        Hops: 0
        Transaction ID: 0x4e299603
        Seconds elapsed: 0
        Bootp flags: 0x8000 (Broadcast)
            1... .... .... .... = Broadcast flag: Broadcast
            .000 0000 0000 0000 = Reserved flags: 0x0000
        Client IP address: 0.0.0.0 (0.0.0.0)
        Your (client) IP address: 10.19.39.98 (10.19.39.98)
        Next server IP address: 0.0.0.0 (0.0.0.0)
        Relay agent IP address: 0.0.0.0 (0.0.0.0)
        Client MAC address: Apple_17:fd:5d (c4:2c:03:17:fd:5d)
        Client hardware address padding: 00000000000000000000
        Server host name not given
        Boot file name not given
        Magic cookie: (OK)
        Option: (t=53,l=1) DHCP Message Type = DHCP Offer
            Option: (53) DHCP Message Type
            Length: 1
            Value: 02
        Option: (t=54,l=4) DHCP Server Identifier = 10.19.39.97
            Option: (54) DHCP Server Identifier
            Length: 4
            Value: 0A132761
        Option: (t=51,l=4) IP Address Lease Time = 1 day, 23 hours, 39 minutes, 50 seconds
            Option: (51) IP Address Lease Time
            Length: 4
            Value: 00029E46
        Option: (t=58,l=4) Renewal Time Value = 23 hours, 49 minutes, 55 seconds
            Option: (58) Renewal Time Value
            Length: 4
            Value: 00014F23
        Option: (t=59,l=4) Rebinding Time Value = 1 day, 17 hours, 42 minutes, 16 seconds
            Option: (59) Rebinding Time Value
            Length: 4
            Value: 00024A78
        Option: (t=1,l=4) Subnet Mask = 255.255.255.240
            Option: (1) Subnet Mask
            Length: 4
            Value: FFFFFFF0
        Option: (t=6,l=8) Domain Name Server
            Option: (6) Domain Name Server
            Length: 8
            Value: AB44E278AB46A8B7
            IP Address: 171.68.226.120
            IP Address: 171.70.168.183
        Option: (t=44,l=8) NetBIOS over TCP/IP Name Server
            Option: (44) NetBIOS over TCP/IP Name Server
            Length: 8
            Value: AB443935AD2573BF
            IP Address: 171.68.57.53
            IP Address: 173.37.115.191
        Option: (t=3,l=4) Router = 10.19.39.97
            Option: (3) Router
            Length: 4
            Value: 0A132761
        End Option

    I have seen the same issue with my iOS and Mac OS devices (iPhone and MacBook Pro). I have written my own DHCP server (http://notebook.kulchenko.com/embedded/dhcp-and-dns-servers-with-arduino) and have had troubles getting my devices to connect (Windows Vista and Ubuntu devices connect fine). I suspect that this problem happens because the DHCP Offer message is sent to a broadcast address, even though (at least in my case) the broadcast flag is off in the DHCP Discover message I see.
    Unfortunately you didn't include the Discover message, so I can't tell for sure, but if it indeed has the broadcast flag set to 0, then the server should send the response message using unicast as per DHCP spec (http://www.ietf.org/rfc/rfc2131.txt, section 4.1):
      If the broadcast bit is not set and 'giaddr' is zero and
       'ciaddr' is zero, then the server unicasts DHCPOFFER and DHCPACK
       messages to the client's hardware address and 'yiaddr' address.
    So, it seems like in this case the server may be at fault, even though it would be nice for Mac OS to accept broadcast responses (and would solve my problem too).
    Can someone confirm that Mac OS does not accept broadcast responses to DHCP Discover and DHCP Request messages? Thanks.
    Paul.

  • Airport utility 6 won't let me set up a guest network

    Hi I want to set up a guest network.
    In previous versions of Airport utility I could simply use the manual config option to do this. In version 6 I no longer have the option. The Wireless panel doesn't have the 'Create Guest Network' option anywhere on it.
    So how do I set up a guest network?

    Please download and install AirPort Utility 5.6 for Mac OS X Lion , which provides much more functionality than AirPort Utility 6.0.
    If you still don't see the Guest Network tab, your AirPort is likely set up in Bridge Mode. It needs to be set up to Share a public IP address in order for the Guest Network option to appear.
    Click the Internet icon, then click the Internet Connection tab
    Check the setting for Connection Sharing
    You can keep both versions of AirPort Utility on your Mac, as it is not possible to remove AirPort Utility 6.0.

  • EA6500 - using other DNS server only applies to Guest network?

    I have an EA6500. I use OpenDNS.org as my DNS server to provide additonal filtering. I have added the Guest network option to separate my network access.
    When I change DNS server settings on the EA6500 to those for OpenDNS, I've found they only apply to the Guest network. For the 'regular' network, the DNS server provided by Comcast (my cable provider) is used. I have verified this by connecting various devices to both the regular and Guest networks and checking which DNS server is in use.
    I assume this is a bug in the firmware? Or am I doing something wrong? Please advise.

    You're welcome
    Since we're into really in getting this possibly resolve, I suggest you try rolling back the firmware to the classic version then let's see.
    Rolling back the Cisco Connect Cloud firmware to the Classic EA Series router web interface
    http://homekb.cisco.com/Cisco2/ukp.aspx?vw=1&articleid=25856

  • Guest Network access

    Hello,
    Im trying to setup access for our guests to go out a specific interface/ISP
    We have our main connection to our datacenter.
    We also have a little SAT Receiver that we get internet from (10MB).
    I want a specific vlan to go out ONLY to that SAT Receiver connection. Here is my setup:
    Guest Network
    vlan 216
    name WIFI-Guests
    SAT Receiver
    interface Vlan70
    ip address 192.168.151.2 255.255.255.0
    interface Vlan216
    description Guest WIFI
    ip address 10.2.16.1 255.255.255.0
    ip helper-address 10.2.1.26
    Can this be done via vrf, and how? Or is there an easier way?
    Thanks...

    Just noticed that you are using an ip helper-address which means you won't be able to use a VRF effectively as your guest network needs access to the vlan with the DHCP server in it.
    Assuming you want to keep DHCP for this network on the DHCP server then probably PBR is better ie.
    access-list 101 permit udp any any eq bootps log
    access-list 102 permit ip 10.2.16.0 0.0.0.255 any
    route-map PBR permit 10
    match ip address 101
    route-map PBR permit 20
    match ip address 102
    set ip next-hop
    int vlan 216
    ip policy route-map PBR
    note that with the above the first acl has to allow DHCP to get through to the DHCP server. Normally with PBR you would simply use just the one acl eg.
    access-list 101 deny udp any any eq bootps
    access-list 101 permit ip 10.2.16.0 0.0.0.255 any
    but with the 3750 (and some other switches) if you use deny lines in the acl this can cause CPU issues on the switch. So a different acl is used for each PBR entry. The first PBR permit entry uses acl 101 and simply matches DHCP traffic and does nothing so it is routed normally. The second PBR permit statement uses acl 102 and matches all other traffic ie. internet and sends it to the SAT device.
    Also worth saying that all traffic is sent to the SAT device but you should also apply an acl on the SVI for vlan 216 to stop traffic from vlan 216 clients to other vlans. The PBR would send this to the SAT device anyway but the SAT device might then route it back to the switch which you don't want. So your acl would look like -
    access-list 103 permit udp any any eq bootps
    access-list 103 deny ip 10.2.16.0 0.0.0.255
    etc. for each internal subnet
    access-list 103 permit ip 10.2.16.0 0.0.0.255 any
    int vlan 216
    ip access-group 103 in
    Hope all that makes sense. If not please come back with any questions you have.
    Jon

  • Airport express and guest network

    My operatign system is OS X 10.9.1
    Airport Express Time capsule 1 TB
    I have had my airport express time capsule for 2 years (1 TB)and it worked pretty near flawlessly since then.  It started with the time capsule being too full and that got me messsing with it.
    I could not fugure out how to delete files and it was not writing over old ones.  I have seen the same problem on here already. (In the end I bought an external drive and now that seems to have solved it, even though I deleted a bunch of old files and my compute is now hovering around 830 MB it still won't back up on the time capsule.  I am not too worried about this though.  If you can help me on this part that is great.   )
    Then I tried to reset my AE device.  WIth that I had to reset my guest network.  this is where the problems began. 
    Previously my AE had a steady green light and hosted two wifi names (mine and for guests). 
    Now if I click not bridged (?) then I can not get Internet access on the guest network.  If I click DHC and Nat it constantly blinks amber but the guest network is not there (even though I set it up).  I have gone back and forth with this and it is consistently behaving like I described above. 
    I have done a reset.  I have done a reset and unplugged the machine (though I admit I did not wait two minutes, closer to 45 seconds)
    I want to go back to the steady green light and the two wifis established.
    Can you please help me?

    Also one  more thing to add.  My Server name has disappeared too.  I get an error message that says
    There was a problem connecting to the server "name"
    The server may not exist or it is unavailable at this time.  Check the server name or IP address, check your network connection, then try again.
    Seems I did a great job messing with this today.
    Merry Christmas!

Maybe you are looking for

  • Problem with Screen EXITS.

    Hi, I need to to some enhancements to my std screen for T.code IE03. I found screen exits and Function exits for that . I  create the subscreen in screen exit and linking to the functional exit, Whem i am activiting it raises the error "Incorrect nes

  • Settings SLD and JCO connection for Java Web Dynpro

    Hi BI Gurus, I'm a Business Intelligence newbye and I'm a bit confused about Web Dynpro configurations. I try to execute, through Netweaver Developer Studio 7, a simple java Web Dynpro who call the standard Flight List BAPI. My configuration is: NW 2

  • Saving a Contact Sheet...

    In iView I can make a contact sheet that I can save as a jpg. How can I do this in LR? Jeff

  • SQL Ports For SCCM 2012 (Stand alone Server)

    Is there any reason to open port 1433 and 4022 if the SCCM server is a stand alone? It keeps displaying the error in the monitoring tab if i don't open the ports. The SQL  and SCCM  are on the same server.

  • Change of nokia account

    I bought nokia lumia520 from my uncle but was unable to change his first registered microsoft and nokia account to mine.. How it can be done..