good practice for setting up a wifi AP to access LAN ressource
hi
in office, we only use wired LAN
we have Wifi AP only for guests and employee's personnal devices. thi Wifi is on a specific ISP modem and no link with office's lan
i want to add a wifi AP for coworker when they are many in meeting room, because add a switch on the meeting desk is messy and laptop has no rj45 connection
what is the best pratice for ? create a specific SSID with only mac filtering (so the SSID is set top open ?)
i really don't know what is the best for…
Accepted Solution
-
Hi @Asgatlat
Please reference the items that Barry mentioned.
Key point:
- The SSID need to assign a VLAN ID.
- This SSID need to enable Layer 2 Isolation & Intra-BSS Traffic Blocking.
- Firewall need set security policy to block this VLAN access other interface/LAN/VLAN/Subnet.
Zyxel Melen0
All Replies
-
Hi @Asgatlat,
To address your requirement for providing Wi-Fi access to coworkers in a meeting room for their laptops to access LAN resources, while maintaining security, here's a recommended approach:
Initial Solution
The best practice involves creating a dedicated SSID for your coworkers and implementing robust security measures beyond just MAC filtering, as MAC addresses can be spoofed. Integrating VLANs with your SSID will provide better network segregation.
- Create a Dedicated SSID:
- Set up a new SSID specifically for "Coworker Meeting Room" or similar.
- Implement Strong Security:
- WPA3-Personal or WPA2/WPA3-Mixed Mode: For robust security, use WPA3-Personal. If you have older devices that may not support WPA3, use WPA2/WPA3-Mixed mode. Avoid "Open" SSIDs, as they offer no encryption.
- (Optional) MAC-based Authentication (Whitelist): While not foolproof on its own, MAC-based authentication can add an additional layer of control. Configure a whitelist of MAC addresses for the devices your coworkers will use. This ensures only "known" devices can connect to this specific SSID.
- In Zyxel Nebula, you can often find this under MAC-based Authentication or Client Policy (MAC filter) features.
- For Zyxel firewalls with an AP Controller, you can use local MAC authentication.
- VLAN Segregation: This is crucial for isolating traffic.
- Assign this new SSID to a specific VLAN that is separate from your main corporate LAN.
- Configure your firewall or router to control access between this VLAN and your corporate LAN, allowing only necessary traffic (e.g., access to specific internal resources like printers or shared drives).
- This prevents unauthorized access to sensitive LAN resources from the Wi-Fi network.
- Enable Layer 2 Isolation & Intra-BSS Traffic Blocking: This feature prevents connected wireless clients on the same SSID from communicating directly with each other, enhancing security.
- Firewall Rules:
- On your firewall, create rules that specifically allow the necessary traffic from the coworker Wi-Fi VLAN to the specific LAN resources they need. Explicitly deny all other traffic from the Wi-Fi VLAN to the corporate LAN.
Information Collection Guide
To provide more tailored advice, please provide the following information:
- Zyxel Access Point Model(s): (e.g., NWA1123-ACv2, WAX610D, etc.)
- Firmware Version of the AP(s):
- Management Platform: Are your APs managed by Zyxel Nebula Cloud, a Zyxel Security Gateway (e.g., USG FLEX), or standalone?
- Network Topology (Diagram or Description): How is the new AP intended to connect to your existing network infrastructure?
- Specific LAN Resources: What exact LAN resources (e.g., file servers, internal websites, specific applications) do your coworkers need to access from this Wi-Fi?
- Nebula Specific Information (if applicable):
- Please enable Zyxel Support Access via
Help > Support Requestin your Nebula console. This allows our support team to view your cloud environment directly. - Provide your Organization Name and Site Name.
- Please enable Zyxel Support Access via
This AI response aims to provide initial troubleshooting steps and identify information needed for further diagnosis. Feel free to share additional details based on the suggestions above — this will help community members offer more targeted assistance.
If you have feedback or idea about this AI assistant, share them in Community Feedback.0 - Create a Dedicated SSID:
-
Hi @Asgatlat
Please reference the items that Barry mentioned.
Key point:
- The SSID need to assign a VLAN ID.
- This SSID need to enable Layer 2 Isolation & Intra-BSS Traffic Blocking.
- Firewall need set security policy to block this VLAN access other interface/LAN/VLAN/Subnet.
Zyxel Melen0
Categories
- All Categories
- 442 Beta Program
- 2.9K Nebula
- 219 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.5K Security
- 588 USG FLEX H Series
- 344 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.4K Wireless
- 52 Wireless Ideas
- 7K Consumer Product
- 298 Service & License
- 477 News and Release
- 91 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.8K FAQ
- 34 Documents
- 87 About Community
- 105 Security Highlight
Ally Member
Zyxel Employee