Transient traffic connecting to Guest WiFi
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-27-2016 11:59 AM
Hello,
I have an Unleashed R600 AP [200.1.9.12.55], and set a WLAN Guest WiFi. Authentication is set to use guest pass authentication. Subnet restrictions are set to only allow traffic to local DHCP server and the WAN firewall gateway (for internet only access). Wireless client isolation is set to restrict access to other clients on the same AP.
The SSID shows publicly as open, and I am seeing transient devices auto-join/connect. Devices are receiving a DHCP address assignment. I see the devices trying to contact internet resources, such as the public DNS servers DHCP provides with it's lease. The firewall happens to be blocking the traffic, but I would expect the AP to control usage *until* device is properly authenticated.
My question, is this as expected? Can transient devices be prevented from attaching the guest WiFi? Did I miss a setting? Thank you.
I have an Unleashed R600 AP [200.1.9.12.55], and set a WLAN Guest WiFi. Authentication is set to use guest pass authentication. Subnet restrictions are set to only allow traffic to local DHCP server and the WAN firewall gateway (for internet only access). Wireless client isolation is set to restrict access to other clients on the same AP.
The SSID shows publicly as open, and I am seeing transient devices auto-join/connect. Devices are receiving a DHCP address assignment. I see the devices trying to contact internet resources, such as the public DNS servers DHCP provides with it's lease. The firewall happens to be blocking the traffic, but I would expect the AP to control usage *until* device is properly authenticated.
My question, is this as expected? Can transient devices be prevented from attaching the guest WiFi? Did I miss a setting? Thank you.
3 REPLIES 3
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-27-2016 03:22 PM
A Guest Access WLAN permits client DHCP / DNS / ARP (only), prior to Authenticated state, when network access is permitted.
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-27-2016 03:53 PM
In my opinion this is the correct behavior too. A lot of clients will cache either bogus DNS responses or negative DNS responses even after you clear the captive portal, which leads to more mysterious network issues for customers.
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-28-2016 07:49 AM
Thank you very much for the clarification.

