Sign in to the controller
Reach the management console at 10.30.0.4 and authenticate as the administrator.
Create a guest access service
Define how visitors authenticate and what they may reach. Name it, set the post‑login behavior, and confirm the corporate network is shielded.
Restricted subnets
Traffic to these ranges is blocked for guests. Confirm the corporate range is listed.
- 10.30.0.0/16
- 10.40.7.0/24restricted
- 198.51.100.0/24restricted
Create the guest wireless LAN
Broadcast an open guest SSID, bind it to your guest access service, and isolate guest devices from one another.
LIVE TOPOLOGY
Provision a guest pass
Open the guest‑pass portal in a separate window and, as an authorized host, generate a pass for a visitor.
Visitor pass portal
Sign in as an authorized host to issue a pass.
Issue a visitor pass
Bound to service Visitor_Net.
—
Test from Foyer‑PC
On the lobby laptop, join the guest SSID and authenticate with the pass key.
Knowledge check
Three questions on the security reasoning behind what you just configured. Pick the best answer.