ā03-03-2020 03:11 PM
Current Guest Network requires a passphrase to access the internet, but for new security measure, we want to move the Guest network off the 172.16.x.x address and onto a 192.168.x.x subnet. And channel it out to another ethernet port on our Content/Firewall. I read we can create the Firewall Rule for this new SSID, but should we also create a separate VLAN (Taged or Untagged). to channel the traffic and prevent it from accessing our subnet?
ā03-03-2020 05:57 PM
As always, thanks again.
ā03-03-2020 03:57 PM
I would recommend creating another VLAN, which would need to be tagged as it isn't going to be your native VLAN. This also means you'll want to set up trunk ports on your switch to pass multiple VLANs.