How to set Access Control to create guest SSID on Omada Controller/EAP

EAP225-Wall , OC200 , EAP225-Outdoor , EAP245 , EAP320 , EAP110 , EAP220 , EAP330 , EAP120 , EAP235-Wall , EAP115 , EAP225 , EAP110-Outdoor , EAP115-Wall
Recent updates may have expanded access to feature(s) discussed in this FAQ. Visit your product's support page, select the correct hardware version for your device, and check either the Datasheet or the firmware section for the latest improvements added to your product. Please note that product availability varies by region, and certain models may not be available in your region.
Suitable for Omada Controller/OC200/EAP
In some scenario, customers may want to provide Wi-Fi access to the Internet for visitors. But they don’t want the visitor to access the local wired network or other wireless clients for security consideration.
For Omada Controller, there are two ways to achieve this goal by using access control function or guest network. This article aims to give you some instructions about how to configure access control or guest network on Omada Controller.
Method 1: How to configure Access Control to create guest SSID on Omada Controller
Below is a sample topology. In this sample the mobile phone which connect to Guest SSID can access Internet but cannot access the wired devices.
1. Add an Access Control Rule at Wireless Control->Access Control->Add Access Control Rule, then click Apply. For example, if the wireless clients and wired clients belong to same subnet (192.168.1.x). We can set Block Subnets as 192.168.1.0/24, Block Exclude Subnets as 192.168.1.1(Gateway), 192.168.1.7(IP address of Omada Controller). (If guest clients need to connect to some special devices, you can add the IP address of these devices to Exclude Subnets list. Please note, you must not block the gateway, DHCP Server, DNS Server, or you will not connect to the Internet!)
2. Add a Guest SSID at Wireless Settings->Basic Wireless Setting
3. Edit this SSID, and add the corresponding access control rule to this SSID, click Apply. (Note: Access Control function can’t take effect to wireless clients which connected with the same SSID of same AP.)
4. If you want to Block the communication between wireless clients which connected with same SSID of same AP, please enable SSID Isolation function (block the communication between wireless clients which are connected to a same SSID of a same AP) at Wireless Settings->Basic Wireless Setting->Edit SSID
Notes:
1) There are two Rule Modes including Allow and Block. Allow is a white list and Block is a black list.
2) The IP address in “Subnets” list comply with the rule mode you choose, except the IP address in “Except Subnets” list. For example, if you configure a Block rule with subnets: 192.168.1.0/24 and except subnets: 192.168.1.2/32. Then clients connect with this SSID will only access 192.168.1.2 of 192.168.1.x subnet. But clients are able to access other subnets.
3) You may not see SSID isolation settings on your controller. Because this function has been upgraded to Guest Network function since controller 3.1.4 version. You can continue reading below to see how the Guest Network function works.
Method 2: How to configure Guest Network on Omada Controller
We have added Guest Network in Omada Controller and EAP. With Guest Network enabled,
- All wireless devices connected to the SSID cannot communicate with each other;
- All wireless devices connected to the SSID will be blocked from reaching any private IP subnet (10.0.0.0 -- 10.255.255.255; 172.16.0.0 -- 172.31.255.555; 192.168.0.0 -- 192.168.255.255 ).
When we configure the Guest SSID, just enable guest network, then guest network will block clients from reaching any private IP subnet.
Note:
1. Guest Network is only available on Omada Controller 3.1.4 or higher version.
2. Guest Network can only be used after upgraded your EAP to corresponding firmware.
A fost util acest FAQ?
Părerea ta ne ajută să îmbunătățim acest site.
Ce probleme ai avut cu acest articol?
- Nemulțumit de produs
- Prea complicat
- Titlu confuz
- Nu se aplică pentru mine
- Prea vag
- Alt motiv
Mulțumim
Apreciem părerea ta.
Acest site web folosește cookie-uri pentru a îmbunătăți experiența navigării web, a analiza activitățile online și a oferi utilizatorilor cea mai bună experiență pe site-ul nostru. Te poți opune utilizării cookie-urilor în orice moment. Poți afla mai multe informații în politica de confidențialitate .
Acest site web folosește cookie-uri pentru a îmbunătăți experiența navigării web, a analiza activitățile online și a oferi utilizatorilor cea mai bună experiență pe site-ul nostru. Te poți opune utilizării cookie-urilor în orice moment. Poți afla mai multe informații în politica de confidențialitate .
Cookie-uri de bază
Aceste cookie-uri sunt necesare pentru funcționarea site-ului web și nu pot fi dezactivate în sistemele tale
TP-Link
SESSION, JSESSIONID, accepted_local_switcher, tp_privacy_base, tp_privacy_marketing, tp_smb-select-product_scence, tp_smb-select-product_scenceSimple, tp_smb-select-product_userChoice, tp_smb-select-product_userChoiceSimple, tp_smb-select-product_userInfo, tp_smb-select-product_userInfoSimple, tp_top-banner, tp_popup-bottom, tp_popup-center, tp_popup-right-middle, tp_popup-right-bottom, tp_productCategoryType
Youtube
id, VISITOR_INFO1_LIVE, LOGIN_INFO, SIDCC, SAPISID, APISID, SSID, SID, YSC, __Secure-1PSID, __Secure-1PAPISID, __Secure-1PSIDCC, __Secure-3PSID, __Secure-3PAPISID, __Secure-3PSIDCC, 1P_JAR, AEC, NID, OTZ
Zendesk
OptanonConsent, __cf_bm, __cfruid, _cfuvid, _help_center_session, _pendo___sg__.<container-id>, _pendo_meta.<container-id>, _pendo_visitorId.<container-id>, _zendesk_authenticated, _zendesk_cookie, _zendesk_session, _zendesk_shared_session, ajs_anonymous_id, cf_clearance
Cookie-uri de analiză și marketing
Cookie-urile de analiză ne permit să analizăm activitățile tale de pe site-ul nostru web a îmbunătăți și ajusta funcționalitatea site-ului.
Cookie-urile de marketing pot fi setate prin intermediul site-ului nostru web de către partenerii noștri publicitari pentru a crea un profilul intereselor tale și a-ți afișeze reclame relevante pe alte site-uri web.
Google Analytics, Google Tag Manager
_gid, _ga_<container-id>, _ga, _gat_gtag_<container-id>
Google Ads și DoubleClick
test_cookie, _gcl_au