Design Considerations for Guest Services in Wireless Networks
Providing wireless guest services with traditional autonomous APs poses significant challenges. To maintain internal corporate network security, guest traffic must be restricted to the appropriate subnet and VLAN; these guest VLANs must extend throughout the infrastructure to reach every location where guest access is required. Reconfiguring of the access switches that serve conference rooms, offices, and cubicles to selectively adjust VLANs for guest access can involve many network staff hours.
The Cisco UWN supports simplified configuration and deployment of guest access for customers, vendors, and partners through deployment of lightweight APs. In a basic scenario, WLCs centralize the configuration and management of the APs and segregate internal user traffic from guest user traffic with VLANs. With this architecture, VLAN and subnet configuration occurs only at the wired network where the controller is connected, as shown in Figure 9-31. The result is a dramatic reduction in time to configure the network.
Figure 9-31 Supporting Basic Guest Access
DSL Router/FW
Figure 9-31 Supporting Basic Guest Access
DSL Router/FW
If the guest network SSID is the only one broadcast, unauthorized users might make fewer attempts to access the internal private WLANs. To increase security, the Cisco UWN ensures that all clients gain access within the number of attempts specified by the administrator. Should a client fail to gain access within that limit, it is automatically excluded (blocked from access) until the administrator-set timer expires.
In this scenario, however, traffic isolation is provided by VLANs, only up to the switch to which the controller is connected. For many enterprises, guest traffic isolation via a VLAN may not provide a sufficient level of security.
In such cases, the Cisco UWN can provide path isolation using a Layer 2 (EtherIP) tunnel to direct all guest traffic to a WLC dedicated to guest services (called the anchor WLC) in a demilitarized zone (DMZ), a secured network zone between the private (inside) network and a public (outside) network. EtherIP tunnels logically segment and transport the guest traffic between Edge and Anchor WLCs, whereas other traffic (for example, employee traffic) is still locally bridged on the corresponding VLAN. This scenario is illustrated in Figure 9-32.
Figure 9-32 Guest Access Path Isolation Using an EtherIP Tunnel
Ethernet in IP "Guest Tunnel"
Anchor WLC
Campus Core
Campus Core
Anchor WLC
Ethernet in IP "Guest Tunnel"
The guest VLANs do not need to be defined on the switches connected to the edge controllers; the original Ethernet frame from the guest client is maintained across the LWAPP and EtherIP tunnels to the anchor WLC. This WLC applies the appropriate policies before Internet access is granted. Corporate wireless use policies are managed by the WLCs internal to the enterprise.
NOTE EtherIP tunnels are supported across all Cisco WLCs. The 2006 WLC, however, cannot anchor the EtherIP connections.
Path isolation allows the guest traffic to be separated and differentiated from the corporate internal traffic and to be securely transported across the internal network infrastructure.

Post a comment