Wireless guest access
Wireless guest access is a network security feature that
-
provides internet access to guests in a secure and accountable manner
-
uses the enterprise's existing wireless and wired infrastructure to the maximum extent, and
-
reduces the cost and complexity of building a physical overlay network.
Wireless guest access architecture and components
The Wireless Guest Access solution comprises of two controllers - a Guest Foreign and a Guest Anchor. An administrator can limit bandwidth and shape the guest traffic to avoid impacting the performance of the internal network.
![]() Note |
|
Wireless Guest Access feature comprises these functions:
-
Guest Anchor controller is the point of presence for a client.
-
Guest Anchor Controller provides internal security by forwarding the traffic from a guest client to a Cisco Wireless Controller in the demilitarized zone (DMZ) network through the anchor controller.
-
Guest Foreign controller is the point of attachment of the client.
-
Guest Foreign Controller is a dedicated guest WLAN or SSID and is implemented throughout the campus wireless network wherever guest access is required. A WLAN with mobility anchor (guest controller) configured on it identifies the guest WLAN.
-
Guest traffic segregation implements Layer 2 or Layer 3 techniques across the campus network to restrict the locations where guests are allowed.
-
Guest user-level QoS is used for rate limiting and shaping, although it is widely implemented to restrict the bandwidth usage for a guest user.
-
Access control involves using embedded access control functionality within the campus network, or implementing an external platform to control guest access to the Internet from the enterprise network.
-
Authentication and authorization of guests that are based on variables, including date, duration, and bandwidth.
-
An audit mechanism to track who is currently using, or has used, the network.
-
A wider coverage is provided by including areas such as lobbies and other common areas that are otherwise not wired for network connectivity.
-
The need for designated guest access areas or rooms is removed.
![]() Note |
To use IRCM with AireOS in your network, contact Cisco TAC for assistance. |
This table shows controller support for guest access functions.
|
Controller Name |
Supported as Guest Anchor |
Supported as Guest Foreign |
|---|---|---|
|
Cisco Catalyst 9800-40 Wireless Controller |
Yes |
Yes |
|
Cisco Catalyst 9800-80 Wireless Controller |
Yes |
Yes |
|
Cisco Catalyst 9800-CL Wireless Controller |
Yes |
Yes |
|
Cisco Catalyst 9800-L Wireless Controller |
Yes |
Yes |
|
Cisco Catalyst 9800 Embedded Wireless Controller for Switch |
No |
No |
|
Cisco Catalyst 9800 Embedded Wireless Controller on Cisco Catalyst 9100 Series APs |
No |
No |
This is a list of features supported by Cisco Guest Access:
-
Sleeping Clients
-
FQDN
-
AVC (AP upstream and downstream)
-
Native Profiling
-
Open Authentication
-
OpenDNS
-
Supported Security Methods:
-
MAB Central Web Authentication (CWA)
-
Local Web Authentication (LWA)
-
LWA on MAB Failure
-
802.1x + CWA
-
802.1x
-
PSK
-
802.1x + LWA
-
PSK + CWA
-
PSK + LWA
-
iPSK + CWA
-
MAB Failure + PSK
-
MAB Failure + OWE
-
MAB Failure + SAE
-
-
SSID QoS Upstream and Downstream (Foreign)
-
AP/ Client SSO
-
Static IP Roaming
-
Client IPv6
-
Roaming across controllers
-
RADIUS Accounting

Note
In a guest access scenario, accounting is always performed at the foreign controller for all authentication methods.
-
QoS: Client-Level Rate Limiting
-
Guest Anchor Load Balancing
-
Workgroup Bridges (WGB)
![]() Note |
To enable the controller to support multiple VLANs from a WGB, use wgb vlan command. |
Foreign map
A foreign map is a guest access feature that
-
supports guest access using Policy Profile and WLAN Profile configuration models in the controller
-
is achieved with policy profile and WLAN profile config model, and
-
configures two different WLAN profiles on two Guest Foreigns where seamless roaming is not allowed between them.
Foreign map configuration
Foreign Map support in Cisco Catalyst 9800 Series Wireless Controller is achieved with the policy profile and WLAN profile configuration model.
Foreign map commands
-
Guest Foreign commands:
-
Foreign1: wlanProf1 PolicyProf1
-
Foreign2: wlanProf2 PolicyProf2
-
-
Guest Anchor commands:
-
wlanProf1, wlanProf2
-
PolicyProf1: Vlan100 - subnet1
-
PolicyProf2: Vlan200 - subnet2
-
Foreign map roaming
Configure two different WLAN profiles on the two Guest Foreigns and seamless roaming is not allowed between them. This is expected configuration. However, seamless roaming is allowed if the same WLAN profile is configured on two Guest Foreigns, but it prevents Foreign Map feature from working.
Wireless Guest Access: Use Cases
The wireless guest access feature can be used to meet different requirements. Some of the possibilities are shared here.
Scenario One: Providing Secured Network Access During Company Merger
This feature can be configured to provide employees of company A who are visiting company B to access company A resources on company B network securely.
Scenario Two: Shared Services over Existing Setup
Using this feature, you can provide multiple services using multiple vendors piggy backing on the existing network. A company can provide services on an SSID which is anchored on the existing controller. This is while the existing service continues to serve over the same controller and network.
Guidelines for wireless guest access
Match the security profiles under WLAN on both Guest Foreign, and Guest Anchor.
-
Match the policy profile attributes such as NAC and AAA Override on both Guest Foreign, and Guest Anchor controllers.
-
On Export Anchor, the WLAN profile name and Policy profile name is chosen when a client joins at runtime and the same should match with the Guest Foreign controller.
Recommendation: troubleshooting IPv6
When a guest export client cannot get a routable IPv6 address through SLAAC or cannot pass traffic when the IPv6 address is learned through DHCPv6, you can use these workarounds:
-
On IPv6 Routers: You can work around the RA multicast to unicast conversion by modifying behavior on the IPv6 gateway. Depending on the product, this may be the default behavior or may require configuration.
-
On Cisco IPv6 Routers: Configure unicast RA depending on your platform.
-
On non-Cisco IPv6 Routers: If non-Cisco network devices do not support configuration command to enable solicited unicast RA then a work around does not exist.
For Cisco IPv6 Routers:
-
Cisco Nexus platform: Has solicited unicast RA enabled by default to help with wireless deployment.
-
Cisco IOS-XE platform: Use the following configuration command to turn on unicast RA to help with wireless deployment:
ipv6 nd ra solicited unicast
Load balancing among multiple guest controllers
Load balancing among multiple guest controllers is a network configuration feature that
-
distributes large guest client volumes across up to 72 controllers for a single export foreign guest WLAN configuration
-
supports priority-based anchor configuration with primary anchors (priority 1,3) and backup anchors for failure scenarios, and
-
automatically handles failover by disconnecting clients from failed primary anchors and redirecting them to secondary anchors.
Configuration and failover behavior
To configure mobility guest controllers, use mobility anchor ip address .
You can specify primary anchors with priority (1,3) and choose another anchor as backup in case of failure.
In a multi-anchor scenario, when the primary anchor goes down, the clients get disconnected from the primary anchor and joins the secondary anchor.
When the highest priority anchor goes down before the keep-alive timeout completes, the export anchor request for new clients fails, and Foreign selects the next highest priority Anchor in the list to export the clients.
Configure mobility tunnel for guest access (GUI)
Enable secure guest network access by establishing a mobility tunnel that allows traffic to traverse between network segments while maintaining security policies.
Use this procedure when setting up guest network access that requires mobility tunneling to route guest traffic through designated mobility anchors in your wireless infrastructure.
Procedure
|
Step 1 |
Choose . |
|
Step 2 |
In the Wireless Networks area, click the relevant WLAN or RLAN and click Mobility Anchor. |
|
Step 3 |
In the Wireless Network Details section, choose a device from the Switch IP Address drop-down list. |
|
Step 4 |
Click Apply. |
The mobility tunnel for guest access is configured and the selected switch is designated as the mobility anchor for the wireless network.
Configure mobility tunnel for guest access (CLI)
Procedure
|
Step 1 |
Configure a mobility group. Example:
Example:
|
|
Step 2 |
Configure a mobility MAC address. Example:
Example:
|
|
Step 3 |
Configure a mobility peer. Example:
Example:
|
Configure guest access policy (GUI)
Configure guest access policies to manage how guest users connect to and use your wireless network.
Guest access policies define the network access parameters and security settings for temporary users who need network connectivity without full user credentials.
Procedure
|
Step 1 |
Choose . |
|
Step 2 |
Click Add. |
|
Step 3 |
In the General tab, enter the Name and enable the Central Switching toggle button. |
|
Step 4 |
In the Access Policies tab, under the VLAN settings, choose the vlans from the VLAN/VLAN Group drop-down list. |
|
Step 5 |
In the Mobility tab, under the Mobility Anchors settings, check the Export Anchor check box. |
|
Step 6 |
In the Advanced tab, under the WLAN Timeout settings, enter the Idle Timeout (sec). |
|
Step 7 |
Click Apply to Device. |
The guest access policy is configured and applied to the device, allowing guest users to access the network according to the defined parameters.
Configure guest access policy (CLI)
Follow the procedure given below to create and configure the guest access profile policy. Alternately, you may use the existing default policy profile after configuring the mobility anchor to that policy.
You can only configure anchors which are peers. Ensure that the IP address that is used is a mobility peer and is included in the mobility group. The system shows an invalid anchor IP address error message when any other IP address is used.
To delete the mobility group, ensure that the mobility peer which is also a mobility anchor is removed from the policy profile.
![]() Note |
|
Procedure
|
Step 1 |
Enter global configuration mode. Example:
|
||
|
Step 2 |
Configure the policy profile and enter wireless profile configuration mode. Example:
Example:
|
||
|
Step 3 |
Shut down the policy if it exists before configuring the anchor. Example:
|
||
|
Step 4 |
(Optional) Enable central switching. Example:
|
||
|
Step 5 |
Configure Guest Foreign or Guest Anchor.
Example:For Guest Foreign:
For Guest Anchor:
Example:For Guest Foreign:
For Guest Anchor:
|
||
|
Step 6 |
(Optional) Configure duration of idle timeout, in seconds. Example:
Example:
|
||
|
Step 7 |
Configure VLAN name or VLAN ID. Example:
Example:
|
||
|
Step 8 |
Enable policy profile. Example:
|
||
|
Step 9 |
Exit the configuration mode and return to privileged EXEC mode. Example:
|
||
|
Step 10 |
(Optional) Display the configured profiles. Example:
|
||
|
Step 11 |
(Optional) Display detailed information of a policy profile. Example:
Example:
|
View guest access debug information (CLI)
View guest access debug information using commands.
-
To display client level detailed information about mobility state and the anchor IP address, use this command:
show wireless client mac-add mac-address detail
-
To display the client mobility statistics, use this command:
show wireless client mac-address mac-address mobility statistics
-
To display client level roam history for an active client in sub-domain, use this command:
show wireless client mac-address mac-address mobility history
-
To display detailed parameters of a given profile policy, use this command:
show wireless profile policy detailed policy-name
-
To display the global level summary for all mobility messages, use this command:
show wireless mobility summary
-
To display the statistics for the Mobility manager, use this command:
show wireless stats mobility
Verify wireless guest access enablement
To check if wireless guest access is enabled, run this command.
Device# show platform hardware chassis active qfp feature sw client vlan all
-------------------------------------------------------------
Vlan : 666
Learning Enabled : true
DHCPSN Enabled : true
Non IP Multicast Enabled : false
Broadcast Enabled : false
Wireless Passive Client Enabled : false
Guest-Lan Enabled : true
MTU : 65535
Input UIDB : 65503
Output UIDB : 65497
Flood List : 0XB8658A0
Feedback