Using ACLs to control guests paths to the internet

Out global network consist of many sites world wide where 75% of the sites having their own internet connection.
To streamline the wireless setup in our WLC's I have considered to run the LAP's in H-REAP mode and on the guest SSID use access control lists to prevent guest users to access internal IP's.
The guest's shall still be authenticated by our NAC guest server.
The guest traffic would then flow to the default gateway which is the nearest internet connection.
I know that the guest might be able to craft an ethernet packet with spoofed source address and there might fool the ACL, but besides of that is there any major security risk I am missing here?
In a perfect world I would isolate the guest traffic, but our network structure makes it hard to streamline that.
The idea was to use 3-4 centralized controllers each with the same configuration and the H-REAP LAP's could then connect the one with lowest delay time via the "Enable Least Latency Controller Join" under the officeExtent AP settings (?).
What am i missing here?

Yep -- USB works well too.  The advantage of Bluetooth over Wifi, incidentally, is power consumption.  If you cannot cable the phone (e.g. to a charger or to the PC) then the difference will be material in terms of battery consumption if you choose Bluetooth over Wifi.  Wifi, however, works with pretty-much anything where Bluetooth obviously requires that capable for the other device.
Market Information? Come read The Market Ticker!

Similar Messages

  • HT4410 I have just installed Windows 7 64-bit full version Home Premium using Bootcamp and cannot get access to the internet. I installed on a Macbook Air Mid 2012 with Mountain Lion. Are there some drivers that are missing from the Windows 7

    Dear Apple. I have just installed Windows 7 64-bit full version Home Premium using Bootcamp and cannot get access to the internet. I installed on a Macbook Air Mid 2012 with Mountain Lion. Are there some drivers that are missing from the Windows 7 bootcamp install download from Apple

    It is a Total Misconception that the Support files are installed when you are installing Windows, even if the USB drive that holds them is inserted in the system when doing the Windows install.
    You must always Run the Setup.exe files from the support files or run the drivers individually once Windows has finished installing and booted to the desktop.
    Also you really need to run the Boot Camp Control Panel Applet and check for updates as not all the newest drivers for full function of all the hardware is included with the original support download. That download is basically a generic version to get the system working and without doing the updates not everything will work properly.

  • Guest access to the Internet with Guest Anchor Controller

    Hi;
    We are doing our initial implementation of an enterprise wireless system.  I deployed a WLC 5508 connected to our data center core switch using LAG.  The 5508 is configured in FlexConnect mode since it is serving APs deployed to a handful of remote offices.  Employee wireless access has been rolled out and is working well.
    I am designing guest access.  As is typical, I want to enforce a policy that guest wireless traffic is forwarded to the Internet Edge in our DMZ and directed out to the Internet.  We do not plan to deploy a Guest Anchor controller in the first phase of the roll out.
    What is the best way to enforce forwarding of guest traffic towards the Internet Edge once the guest traffic arrives at the 5508?  A guest VLAN between the core switch and the Internet Edge isn't feasible since there is a firewall between the core and DMZ that is configured in Routed mode.
    Thanks for the assistance!  Glenn Morrison

    you'd have to do a VLAN between the core and the firewall for the guest traffic until you get the anchor installed.
    HTH,
    Steve

  • I made an iMovie, 6.0.3 using music from iTunes and photos from the Internet. It looked fine on iMovie, but when I uploaded it to youtube,some of the photo near the beginning was corrupted.What steps should I take to export iMovie for youtube?

    I made an iMovie, 6.0.3 using music from iTunes and photos from the Internet. It looked fine on iMovie, but when I uploaded it to youtube, some of the photo near the beginning were corrupted on youtube. I tried a different photo, and the corruption took place at the same moment of the video. How do I prepare the video for export to get it ready for youtube? I wasn't sure whether to clik web or web streaming. Am I supposed to clik Quick Time after I clik Share?

    I unfortunately cannot remember where I got the 'trrndlines' plugin... I assume that it must have been from CFX (as it is located under /Users/Dom/Library/iMovie/Plug-ins/cfx/XXXtrrndlines.bundle).
    As for what it does, I also do not know, as I do not think I ever used it in my previous video projects.
    At this stage, I think I just need to uninstall it so that iMovie doesnt try to use it.
    Do you know how to uninstall a CFX plugin in iMovie?
    NOTE: I have re-installed iMovie 6.0.4 (instead of iMovie 6.0.3), but still encounter the same issue.

  • I can not get my phone to sign in to my wi fi. I used to, then I lost power to the internet and now it won't. Al other devices will.

    I can not get my phone to sign in to my wi fi. I used to, then I lost power to the internet and now it won't. All other devices will.

    Try forgetting the Wi-Fi network and then joining it again, just tap Settings >  Wi-Fi > the arrow next to your network > Forget this Network, then join the network again.
    If that doesn't do it, take a look at this Apple doc -> iOS: Troubleshooting Wi-Fi networks and connections

  • Grey  color cover the screen and can't use touch screen  when trying to open the internet.

    Pleas help, yesterday when I tried to open an website on my I pad 2 and there was a grey color cover the screen and I can't use touch screen, i still can see the internet is working in the back ground of the screen and the webpage was opend but I just can't make the grey color screen disappear. Thanks million.

    Go to Settings>Safari>Clear History, Cookies and Cache. Restart the iPad. Restart the iPad by holding down on the sleep button until the red slider appears and then slide to shut off. To power up hold the sleep button until the Apple logo appears and let go of the button.
    If that doesn't work, reset the iPad. Reset the iPad by holding down on the sleep and home buttons at the same time for about 10-15 seconds until the Apple Logo appears - ignore the red slider - let go of the buttons.
    Last thing to try is quit the app and restart the iPad. Go to the home screen first by tapping the home button. Quit Safari by double tapping the home button and the task bar will appear with all of you recent/open apps displayed at the bottom. Tap and hold down on the Safari icon until it begins to wiggle. Tap the minus sign in the upper left corner to close the apps. Restart the iPad. Restart the iPad by holding down on the sleep button until the red slider appears and then slide to shut off. To power up hold the sleep button until the Apple logo appears and let go of the button.

  • Can Shuffle be used on a computer not connected to the Internet

    Can Shuffle be used on a computer not connected to the Internet. I have access to an Internet connected computer to register but I would like to manipulate and recharge on a machine that is not connected. Thanks for any help you can provide.

    As long as you aren't trying to update/restore it the Shuffle will work on a computer with no Internet access.

  • Use iphone to coneect a laptop to the internet

    Is it possible to use iphone to connect a laptop to the internet?
    In other words is it possible to use the iphone as an access point?

    Just an update about cost (really triggered by another interrelated post “Transfer files to iphone over usb (no wifi) then mail them...”)
    In Greece Vodafone allows data exchange from tethering as part of the main data package which you get if you want with a subscription. There are various packages, currently one for 500MB extended to 1GB for the 1st year costs around 5€. That's actually added to the main phone package, so for about 40-50€ / month you have about 3 hours talk time + the 500MB/1GB data.
    Don’t know whether you consider that as expensive or not.
    Actually, before discovering tethering I never went beyond the 200MB in a month without considering the extent of internet usage. Tethering won’t really make any difference in the data exchange volume since my intention is to use it in emergency situations anyway.
    V.

  • I am using my iPhone 4s personal hotspot as the internet router for my notebook. However, I am gtting the WEB SITE IS BLOCKED BY NETGEAR FIREWALL. I've deleted some other wifi connections I had before, had system restores, clear cahes and cookie. FAILED.

    I am using my iPhone 4s personal hotspot as the internet router for my notebook. However, I am gtting the WEB SITE IS BLOCKED BY NETGEAR FIREWALL. I've deleted some other wifi connections I had before, had system restores, clear caches and cookie. Still, I failed. Whenever I tried to access FACEBOOK, it's still blocked so I still had to use https:// or tl-gp. please help asap.

    Well, aren't you all that and a bag of chips!!!!
    Oh what a relief!  What a RELIEF!  
    That just cleaned up my life.  And Cranky Boy is actually smiling!!!
    Houston, we've got dots AND BARS!!!
    P.S.  All my firware and software are always current.  If I spent as much time looking for a reset button as I spend checking for software updates, I mighta not needed to work at this!!!!
    P.P.S.  Airport Utility shows Cranky Boy's iPad as the Airport Express' Wireless Client!!!   Who knew?
    Thank you so much, m'Lord.  I am in your debt.  What would you have me do?
    Patti in Tucson AZ

  • How do I use cookies to control which part of the timeline to play from?

    Hi there,
    I have created an animation with Adobe Edge. My site uses Concrete5 and I am pulling in the Edge content into an IFRAME on my home page (there my be a better way to do this and I'm open to suggestions). I want the animation to play from the start when someone first visits the site, but if during their browser session they navigate back to the home page, I want the animation to only play a shorter segment of frames near the end.
    My question is, how do I use cookies to acheive this? I'm new to javascript/jquery.
    I've included the following code on compositionReady, (found in another post on this forum) but don't have a clue how to continue...
    // insert code to be run when the composition is fully loaded here yepnope(   {     nope:[       '/js/jquery.cookie.js'     ],   complete: init   } ); function init() { //create your cookie's initial values here } 
    My temp site is here - http://79.170.40.43/nutcrackerdesign.co.uk/
    On revisting the homepage, I only want to play from when the green 'How can we help?' button drops in.
    Many thanks!
    Russ

    Hi, Russ-
    I found this article, which seemed really helpful in describing how cookies work in JavaScript:
    http://www.quirksmode.org/js/cookies.html
    Remember that JS works just fine within Animate, so on your compositionReady, you can read your cookie and then set the play based on that.  You should probably uncheck the autoplay for your Stage and control the play of your Stage from the compositionReady.
    Good luck!
    -Elaine

  • Is it possible to use airtunes to play music streamed via the internet?

    I have recently set up my Mac so I can play music from iTunes through my stereo in my lounge using Airtunes.
    I would like to be able to play music via Airtunes when streaming it over the internet (eg BBC iPlayer or an internet radio station).
    Is there a way this can be done?

    I don't have airtunes so I am speaking from a theory perspective. It looks like airtunes works with itunes and I know many streaming stations can also be played through itunes so I would think it could be done at least to some extent. You might have to save a link to the stream and then open the link file in itunes to get it to add it to your list (I have done this with a streaming station).
    For other stations I don't know if you could select airtunes as a sound output option for general computer sound output in the sound control panel.

  • Control home appliance over the internet

    Hi .
    I am doing a project using Java & C on linux to control a home appliance attached to my system.. it needs a little cheap electronic ckts ..and i have developed a small gui to control it ovwer the network. it works fine till there.. now i want to extend its functionality over the internet. The issues are
    -> how do i identify the (ipadd) machine thats running my app if i use a dial up conxn where the ip add changes every session
    ( In short how do i control the machine @ my home from somewhere else like an internet cafe) ???
    I use a datagram based socket & packet for implementing this.. any suggestions?

    how do i identify the (ipadd) machine thats running my app if i use a dial up conxn where the ip add changes every session ?
    "(ipadd) machine thats running my app" - Which machine are you talking about? You have 2 to 3 systems. One is your machine in Internet cafe and another is the home appliance. And/Or you can have a middleware machine in your home. Either way you should know the IP Address or URL address. Else you will not be able to connect.
    how do i control the machine @ my home from somewhere else like an internet cafe) ???
    You can have 3 systems. One in Internet cafe, second, a middleware machine in your home and third is your home appliance. The middleware has a application enabled by wired or bluetoothed to talk to the home appliance. The middleware can have a URL or IPAddress. Connect to this machine from your cafe and do the neccessary.
    Good wishes,
    Rajesh

  • Not able to use software-update but still connected to the internet

    Hi there , I am currently on 10.5.6 but did this upgrade manually. When I tried to use Software-Update it gave me : Cannot contact the update server. I am connected through Airport Extreme with my Macbook. My IMac is also on this Airport Express and is working fine (Included SoftwareUpdate).
    However I can work on the internet and use Email with my Macbook.
    Itunes is also not able to conect and my widgets are also not working.
    Like I said: On my Imac everything works fine.
    Can anyone help?? please

    There are several things to try.
    First check what is installed. Go to Safari's Help menu and select Installed Plug-Ins. If you see this
    application/x-java-applet;version=1.3.1
    then it is installed and the banking website is not interpreting it correctly.
    Next, go to Safari Preferences, click Advanced, and select "show develop menu in menu bar". Go to the website and then, from Safari's newly enabled Develop menu, select User Agent > some other version of Safari. You can actually select whatever you want - perhaps the banking website is checking your browswer for compatibility.
    If this doesn't work, download and install another browser such as Firefox or Chrome. Try the banking website with one of them. If it works then either continue to use it, or tell the bank to fix its problem with Safari.

  • Using iPhone to connect my MacBook to the internet.

    Any ideas on how I can use my iPhone to connect my MacBook to the internet?

    Hi RonAnnArbor,
    Why not just tell people the truth and let them be responsible for their own actions. You cannot seriously expect us to believe that you are this ridiculously naive. Let's suppose that you are in a geographic/physical location that does not have free, or pay WiFi. But, to get the customer up and running you need a real machine with real apps to do some work. This, opposed to just playing on the net with the iPhone. Real work, not reading emails and showing your technically challenged friend how your blog looks on the phone... Instead of that, you are looking at stuff that is technical, contains a great deal of information, or contains a great deal of formatting. Could you not see that it would be easier to work with this type information not just from a readability standpoint, but a usability standpoint on something with a larger display?
    I digress. Anyway there is no way to connect your MacBook Pro to the net because there is no connection available and you are in the middle of no where, but your iPhone is in your holster and has a freakin' marvelously strong signal. So, you have this iPhone in your pocket right next to your xxxx and it is doing nothing but playing your favorite music.
    Hmm, interesting "You have an Unlimited Data Plan with AT&T" why not use it to create your own WiFi hotspot with your iPhone and allow your MacBook Pro, Windows PC, whatever to share the phone's data connection so that these and other devices can connect to the net via the iPhone? So you still don't see the advantage?
    That is an awesome feature and makes it so you can connect with anything, anywhere using your iPhone. Talk about a new marketing angle. Your iPhone is now your ISP. The iPhone would be acting as, well, a modem if that helps you bring the aforementioned post full circle.
    <post edited by moderator>
    Hope this helps and was not too strong.
    Allen

  • Help plzzzzzz..can my blackberry be used as a modem to connect to the internet???

    can any1 help me plz??? im moving to a new house and there's no phone there. the thing is i desparately want to use to the internet on the computer so i was wondering if my phone can be used as a modem too..thank you in advance )
    Solved!
    Go to Solution.

    resolution: http://www.blackberry.com/btsc/KB05196
    Click on KUDOS to appreciate our efforts and mark the thread RESOLVED if your issue is resolved.

Maybe you are looking for

  • 2010 mac pro will not sleep

    2010 Mac Pro 10.6.8 recently will not go to sleep. Will awaken without reason when it is put to sleep with menue command. Tried resetting system management controller and PRAM to no avail. Any suggestions?

  • Ipod wont turn on or off

    I have an ipod touch on which the power button will not respond. Nothing will happen if i press it. If i sync it, it goes to the unlock screen and the power slider popes up. If i turn it off i cannot turn it on unless i connect it to a charger. i res

  • How to see planned orders for P3 mrp type products in APO?

    Dear experts, I have materials with P3 MRP type (not planned in APO but in R/3 using MRP) I have active integration models with P3 and X0 mrp type products for planned orders however I can not see in APO product view the planned orders for P3 materia

  • Need to create a 1-sided matrix in Virsa CC5.2 for (132) sensitive actions

    Hello I need to set up sensitive transactions in Virsa Compliance Calibrator 5.2 , in addition to the out of the box global rule set. Our company tracks 132 sensitive transactions in SAP like PA40 for example. I need to be able to have CC 5.2 give me

  • Transaction iView opening in a separate window in SAP NW 7.3 portal

    Hi Experts     I have created a transaction iView for LSO transaction.The iView is a SAP GUI for HTML type.When I am trying to open the iView from the portal , it opens in a separate tab instead of as a pop-up window.   The Launch in a New window pro