Got it

Guest WiFi

Created: Aug 8, 2018 14:51:01Latest reply: Aug 10, 2018 15:53:33 12874 15 0 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hi, all!


This post is about guest WiFi. Please see below.


ISSUE DESCRIPTION


How do I set up a guest SSID (I have done that already), but it can not access the main SSID (as it's part of the internal network)?


Thanks,


Eric

Featured Answers

Hello Eric!


The below commands are used to apply the ACL to  the traffic-filter. The filter will take effect on the vap-profile of the guest SSID or the SSID where you applied it on.

Please check the example below:

<Huawei> system-view
[Huawei] wlan
[Huawei-wlan-view] traffic-profile name default
[Huawei-wlan-traffic-prof-default] traffic-filter inbound ipv4 acl 3003


<Huawei> system-view
[Huawei] wlan
[Huawei-wlan-view] vap-profile name Guests
[Huawei-wlan-vap-prof-Guests] traffic-profile default


Can you please clarify the current issue - the guest users cannot access the internal servers plus they cannot access the internet either?

If so, just make another permit rule allowing the guest subnet to reach the gateway like below:
 
(in the below example 192.168.1.1 is the gateway to the internet)

<Huawei>sys
[Huawei]acl 3003
[Huawei-acl-adv-3003] rule 5 permit ip source 192.168.1.0 0.0.0.255 destination 192.168.1.35 0
[Huawei-acl-adv-3003] rule 10 permit ip source 192.168.2.0 0.0.0.255 destination 192.168.1.1 0
[Huawei-acl-adv-3003] rule 15 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.1.35 0
[Huawei-acl-adv-3003] quit


If my answer helped solve your problem, I would appreciate if you could give me the best answer tag.

Have a nice evening!
View more
  • x
  • convention:

All Answers
Hello Eric,

on what device are you trying to configure this?
View more
  • x
  • convention:

1. Could you please share your configuration?
2. You can use this command to check the reason of user online failed: display station online-fail-record sta-mac xxx
View more
  • x
  • convention:

can u share screenshot?
View more
  • x
  • convention:

Hi,

Sorry I mean I want to setup 2 SSID, one is for guest the other one is for internal network and I want to set it up so that the guest SSID can not access anything within the interal network SSID, hope this make sense?
View more
  • x
  • convention:

The device is AP4030DN

Software is V200R007C20SPC700.

I have the 2 SSID setup already, but when I am connected to the guest SSID, I can still access the server within the internal network which I don't want.


Thanks.
View more
  • x
  • convention:

Posted by Jackofalltrades at 2018-08-08 14:53 Hello Eric,on what device are you trying to configure this?
The device is AP4030DN

Software is V200R007C20SPC700.

I have the 2 SSID setup already, but when I am connected to the guest SSID, I can still access the server within the internal network which I don't want.


Thanks.
View more
  • x
  • convention:

Hello Eric,

You will first have to create two subnets one for the guests and one for the internal network, after that a traffic filter will help you with this issue. We can asume that 192.168.1.35 is the server and 192.168.1.0 is the subnet used on your internal network, and you use 192.168.2.0 for guests services

For more details regarding this please check the following guide:

[Huawei-acl-adv-3003] rule 5 permit ip source 192.168.1.0 0.0.0.255 destination 192.168.1.35 0
[Huawei-acl-adv-3003] rule 10 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.1.35 0
[Huawei-acl-adv-3003] quit

[Huawei] wlan
[Huawei-wlan-view] traffic-profile name default
[Huawei-wlan-traffic-prof-default] traffic-filter inbound ipv4 acl 3003

Please let me know after doing the above if you still have issues.
View more
  • x
  • convention:

Posted by Luke_WiFi_Walker at 2018-08-08 15:51 Hello Eric,You will first have to create two subnets one for the guests and one for the internal net ...
Hi,

Thanks for your reply, I have created 2 SSID, so therefore I have 2 subnet created already.

I am not fimilar with the command line but how can I do that with the web interface? Do I go to ACL(that I have created already) to create the permit and deny rules on the subnet I want to block?

Hope this make sense?


Thanks,
Eric
View more
  • x
  • convention:

This post was last edited by reylon at 2018-08-08 17:51. here the link to make the ACL http://support.huawei.com/hedex/hdx.do?docid=EDOC1000153689&id=dc_wlan_webhelp_acl_0003&text=Advanced ACL Settings&lang=en
View more
  • x
  • convention:

12
Back to list

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.