zsero
Occasional Visitor
I'd like to set up wireless guest networks, and I'm not yet understanding how it works properly.
What I know is that the EdgeRouter Lite what I'm using has the 2 LAN + 1 WAN Wizard which sets things up perfectly for 2 hardware separated independent networks.
One port is 192.168.1.1/24 other is 192.168.2.1/24.
Both have DHCP server with independent settings, both have NAT, etc. There is no way to see one network from the other. Perfect! So far everything is clear for me in this case.
Now my confusion comes from having to make this work with APs, which broadcast both the internal network and the guest network. Naively, I'd guess that what I need is either two cables for the APs (from the 2 LAN ports on the EdgeRouter) or to make a full managed network and use VLAN tagging, which I have never done before.
What confuses me even more is that the Ruckus APs we might end up using will be installed and managed by a professional company who say that the AP can itself make the guest network, even from a single wire of unmanaged ethernet. What they recommended was to use "restrict user access to subnets" and "client isolation".
Can you explain me how is this possible, as I thought that guest isolation can only happen on the router either with physical cabling or with VLANs?
What I know is that the EdgeRouter Lite what I'm using has the 2 LAN + 1 WAN Wizard which sets things up perfectly for 2 hardware separated independent networks.
One port is 192.168.1.1/24 other is 192.168.2.1/24.
Both have DHCP server with independent settings, both have NAT, etc. There is no way to see one network from the other. Perfect! So far everything is clear for me in this case.
Now my confusion comes from having to make this work with APs, which broadcast both the internal network and the guest network. Naively, I'd guess that what I need is either two cables for the APs (from the 2 LAN ports on the EdgeRouter) or to make a full managed network and use VLAN tagging, which I have never done before.
What confuses me even more is that the Ruckus APs we might end up using will be installed and managed by a professional company who say that the AP can itself make the guest network, even from a single wire of unmanaged ethernet. What they recommended was to use "restrict user access to subnets" and "client isolation".
Can you explain me how is this possible, as I thought that guest isolation can only happen on the router either with physical cabling or with VLANs?