Tinkerloft, a community makerspace, is hosting a weekend BYOD workshop. Visitors will bring their own phones, tablets, and laptops and need internet access — but they must stay walled off from the staff network and shop equipment on 10.50.0.0/16, and from each other. Stand up a dedicated guest WLAN on the AirLoom controller, secure it, and segment it. Then answer the review questions, enter a callsign, and submit.
Profile and SSID should read Tinkerloft-Guest. Tag it to the guest VLAN, pick the strongest encryption, turn off WPS, and switch on the captive portal and client isolation.
The guest VLAN needs its own scope. Build it on 172.22.80.0/24: gateway .1, hand out .50–.200, DNS 9.9.9.9, 8-hour lease.
Keep guests off the internal network. Add a rule that denies the guest VLAN to 10.50.0.0/16. Internet stays permitted by the default rule.
| # | Source | Destination | Action | |
|---|---|---|---|---|
| 0 | VLAN 80 (Guest) | 0.0.0.0/0 | Permit | default |