Hello,
I'm wondering if the following is possible :
Would like to allow guest laptops Internet access while isolating it's traffic from corporate lan. Currently in place ASA5510 with HP Procurv switch that supports VLAN and a couple Windows servers. The Windows servers do DHCP and DNS. How would I allow Internet access to guest laptops. Is it possible to enable DHCP on one of the interfaces of the ASA5510? If that would work, I can connect a laptop directly to that port and supply Internet Access. A switch would be added if more than 1 guest.
Now let's say those guest laptops would have to be connected to the main switch, I'm wondering if it's possible to make the switch recognize a guest laptop from a trusted laptop. I believe that's where VLAN and MAC security would be involved. If the switch recognizes a trusted MAC address, it would have to tell it to go the the Windows server DHCP but if the MAC is unrecognized, it would send it to the DHCP of the ASA...
In other setups, I would allow Guest Internet access by putting a switch after the ISP modem. I would then connect the ASA to the switch and a cheap Linksys router to the switch. The rest of the corporate network would be under the ASA and the guests would connect to the Linksys router however, it has happened before that some employees would allow guests laptops to be connected into ports that were for trusted devices. I know part is employee education but I want to completly avoid the possibilty of a guest laptop accidently connecting to corporate side of the network and I don't want adding a switch + linksys router.
Thanks,
fs483
I'm wondering if the following is possible :
Would like to allow guest laptops Internet access while isolating it's traffic from corporate lan. Currently in place ASA5510 with HP Procurv switch that supports VLAN and a couple Windows servers. The Windows servers do DHCP and DNS. How would I allow Internet access to guest laptops. Is it possible to enable DHCP on one of the interfaces of the ASA5510? If that would work, I can connect a laptop directly to that port and supply Internet Access. A switch would be added if more than 1 guest.
Now let's say those guest laptops would have to be connected to the main switch, I'm wondering if it's possible to make the switch recognize a guest laptop from a trusted laptop. I believe that's where VLAN and MAC security would be involved. If the switch recognizes a trusted MAC address, it would have to tell it to go the the Windows server DHCP but if the MAC is unrecognized, it would send it to the DHCP of the ASA...
In other setups, I would allow Guest Internet access by putting a switch after the ISP modem. I would then connect the ASA to the switch and a cheap Linksys router to the switch. The rest of the corporate network would be under the ASA and the guests would connect to the Linksys router however, it has happened before that some employees would allow guests laptops to be connected into ports that were for trusted devices. I know part is employee education but I want to completly avoid the possibilty of a guest laptop accidently connecting to corporate side of the network and I don't want adding a switch + linksys router.
Thanks,
fs483