Guest and BYOD Wireless: Isolation, Onboarding and Per-User Keys
Guest and personal-device wireless is where network design meets the fact that you do not control the endpoint. The question is not how to secure those devices — you cannot — but how to give them the access they need while ensuring a compromised one reaches nothing that matters. Guest networks A guest network should provide internet access and nothing else. Getting that right means three things. Segmentation. Guest traffic goes into its own VLAN with no route to internal networks, enforced by access control lists rather than by the absence of a route — routes appear. Give it its own DHCP scope and DNS, and do not let guest clients resolve internal names. Client isolation. Guests should not reach each other either. Without it, one infected laptop scans and attacks every other device on the guest network, which in a hotel or conference setting is a substantial population. Wireless client isolation is a single setting on most controllers and is frequently left off....