Monday, October 19, 2020

Guest Wifi VLAN behind Split Sophos RED10 box

Hi,

I've a Sophos UTM at HQ office. Setting up a remote office soon, and going to be deploying a RED10 with Split Tunneling to connect back to HQ UTM. DHCP is provided by the Sophos UTM.

At remote office, ISP provided router --> RED10 --> Layer ? switch --> Unifi APs

Here comes the problem: the guest traffic should be separate from Staff and go straight to the Internet. For Unifi APs, we'll need to have two SSIDs: Staff and Guest. If I remember correct, it's possible to do VLAN tagging on the SSIDs, or rather guest traffic.

Do I need a layer 3 or layer 2 switch? Is it possible to have the devices on Guest Wifi get DHCP from the ISP-provided router?

thanks.



No comments:

Post a Comment