Tuesday, 15 December 2009

Cisco Wireless Guest Access

I f you have Cisco Access Points you can deploy Wireless Guest Access and you need:

A WLC (Wireless LAN Controller), at this very moment the best options is the Cisco 5508 WLAN Controller because it's optimized for 802.11n support. It can be licensed for 12, 25, 50, 100 or 250 Access Points. With the controller you will have Wireless Guest Access based on a secure captive portal (HTTPS). You'll define users locally or in a radius server and a lifetime. At the same time of authentication you can enforce the users to accept a disclaimer or enterprise policy.

The Guest Access SSID must be configured to a Guest VLAN with only access to Internet (HTTP, HTTPS and DNS). Don't allow SMTP in this VLAN because if your ISP detects they are sending SPAM from that IP they will close that port and your organization couldn't send email.

The controller has some advantages like:

- Peer-to-peer blocking (protect wlan users from communication between other wlan users)
- The option to use the same system for wired guest access
- QoS for every class of traffic or users
- Rogue access point detection

If you have budget is better to have WCS (Wireless Control System) software too. With WCS, you add some advanced features like:

- Advanced authentication and authorizacion. Which days and hours and where each user can connect.
- Advanced report and logging. And historical data
- Management of several WLC
- Security alarm and monitoring

The main problem of all that is the prize!

No comments:

Post a Comment