Good guest policy as implemented by the stateful firewall should only allow the guest to access the local resources that are required for IP connectivity. These include DHCP and possibly DNS if an outside DNS server is not available. All other internal resources should be off limits for the guest. This is usually achieved by denying any internal address space to the guest user.
| No access |
Access controlled | after hours |
|
Additional policies should be put in place to limit the use of the network for guests. The first policy is a
Mobility
controller
Data | Controlled |
| data |
A rate limit can be put on each guest user to keep the user from using up the limited wireless bandwidth. Employee users should always have first priority to the wireless medium for conducting company business. Remember to leave enough bandwidth to keep the system usable by guests. Aruba recommends a minimum of 10%. Guests can always burst when the medium is idle.
Create a time range:
Create a bandwidth contract and apply it to an AP group:
wlan
Campus Wireless Networks Validated Reference Design Version 3.3 Design Guide | Mobility Controller Configuration 47 |