Looking to create secure wirless guest acces susing Netgear Switch/AP - Need help!

trevstonbury

Honorable
Jan 7, 2014
5
0
10,510
Good afternoon,

I am looking to configure a AP and switch in my office so that I can provide secure 'guest' access to visitors which is separate from our coporate LAN. The devices I need to configure are as follows;

1 x Netgear WNAP210 Access Point
1 x Netgear GS724TP Switch

The switch is currently running without any advanced configuration serving data to the Ethernet ports in the office and the AP is configured with an SSID on the default VLAN 1 using WPA2-PSK. The AP is patched into port 14 on the Netgear switch.

I can configure the AP with an additional profile and I have briefly carried out some config on the switch to create a VLAN with an ID of 2 and linked the 2nd profile on the AP to match this. Clients can access the WLAN on the 2nd profile but can't access the internet. I've not really configured AP's or switches in this way before and don’t have much experience with VLAN but would someone be able to point in the right direction? your help would be much appreciated!

The manuals for each device can be found from the links below;

AP - http://www.downloads.netgear.com/files/GDC/WNAP210/WNAP210_UM_1December11.pdf
Switch - http://www.downloads.netgear.com/files/GS700TP_UM_08May08_.pdf

If you need any further info please let me know


Kind regards

Trevor
 
You still are going to need a router/firewall to connect the vlans. You have to think of this as you went out and bought yourself a separate AP and switch that are not connected to the first one. You accomplished your first goal to keep them separate now the hard part is to securely give them access to what you want.

If you goal is to allow it to the internet you can put in a isolated internet router on a port assigned to vlan 2. Otherwise you are going to need a router that supports multiple lan networks. You would either use a second cable or configure it like you AP and add a taged vlan to the port. In any case the router will have 2 different subnets in it and they you would have to put in whatever security rules to prevent traffic from flowing between.