Recommend poe access point with guest settings

Recommend poe access point with guest settings

Author
Discussion

Olds124

Original Poster:

102 posts

66 months

Tuesday 21st February 2023
quotequote all
As title suggests, I am trying to source an access point that will allow a secure guest network that won’t be able to give access to the rest of the LAN. I thought I had it worked out with a tp-link using captive portal but it doesn’t block the wider access. Also needs to have poe. Any suggestions?

Thanks.

adsk

92 posts

165 months

Tuesday 21st February 2023
quotequote all
Aruba Instant On AP22 has a guest mode and isolates guest users from the rest of the network. POE capable too.

I've had mine for 18 months - easy to set up and has been very reliable.

Edited by adsk on Tuesday 21st February 23:20

Olds124

Original Poster:

102 posts

66 months

Wednesday 22nd February 2023
quotequote all
Thank you. I will have a look.

jan8p

1,739 posts

234 months

Wednesday 22nd February 2023
quotequote all
Which TP-Link are you using? I use Omada stuff and you have the option to enable Guest on each SSID which stops devices seeing other devices on the subnet:


Olds124

Original Poster:

102 posts

66 months

Wednesday 22nd February 2023
quotequote all
For this purpose I have been using a wa-1201. Tp-link helpline said they couldn’t recommend an AP that offered a truly isolated guest network, and there are a number of posts on other forums where tp-link users are expressing their frustration that they set up the guest network but can still see other devices on the network. These seemed to be deco, however, and I haven’t specifically searched against Omada. The test I’ve been using is to set up the separate ssids or captive portal and then enter the standard BT hub address and see if the supposedly isolated network can see it, and it can. On a previous thread there was a discussion about using a vlan switch but it is unclear whether this will work easily or at all with a bt smarthub 2 (non-business) as they don’t support vlans.

jan8p

1,739 posts

234 months

Wednesday 22nd February 2023
quotequote all
The difference here is you're using consumer hardware, and it's generally more business grade stuff that does proper guest isolation, i.e. Omada. Aruba, Meraki, Ubiquiti etc.



Edited by jan8p on Wednesday 22 February 11:02

somouk

1,425 posts

204 months

Wednesday 22nd February 2023
quotequote all
I use TP Link Omada stuff which does guest access, works great and would recommend it without issues.

Baldchap

8,239 posts

98 months

Wednesday 22nd February 2023
quotequote all
Unifi kit does it, but you do pay a little bit for the fancy packaging and interface. It is brilliant quality kit though and once you have a little bit it definitely spreads...

Bikerjon

2,211 posts

167 months

Wednesday 22nd February 2023
quotequote all
There's loads of options out there for isolated guest Wi-Fi, but for simplicity I think the Aruba instant-on range is a good choice for this particular feature.

Olds124

Original Poster:

102 posts

66 months

Wednesday 22nd February 2023
quotequote all
I agree there are lots of options but each time I dig into it I seem to find that what is being created is not really very secure, e.g., Omada eaps. I will have a look more closely at some of the recommendations, thank you.

ColinGreaves

72 posts

20 months

Wednesday 22nd February 2023
quotequote all
You could do what I do, being a geek, and that is --

Have no friends.

I find that pinches the problem at source.

Olds124

Original Poster:

102 posts

66 months

Sunday 12th March 2023
quotequote all
Aruba instant on has done the trick. Proper guest settings, not just a separate ssid. Very fast, too, with good coverage. Easy to manage with the app but I guess, as has been observed elsewhere, this will build in obsolescence when they stop supporting the app (there doesn’t seem to be any way of just logging in through an ip address as with standard routers/access points). Just have one for now bought used for £40 on ebay, but considering switching the whole network over. For info, it works with a standard bt smarthub connected by ethernet, directly or through a dumb switch, without the need for any other aruba network hardware.

Captain_Morgan

1,243 posts

65 months

Sunday 12th March 2023
quotequote all
Olds124 said:
Aruba instant on has done the trick. Proper guest settings, not just a separate ssid. Very fast, too, with good coverage. Easy to manage with the app but I guess, as has been observed elsewhere, this will build in obsolescence when they stop supporting the app (there doesn’t seem to be any way of just logging in through an ip address as with standard routers/access points). Just have one for now bought used for £40 on ebay, but considering switching the whole network over. For info, it works with a standard bt smarthub connected by ethernet, directly or through a dumb switch, without the need for any other aruba network hardware.
Happy that you’ve found a solution with Aruba, I suspect that it’s unlikely the Aruba cloud management will be discontinued during the working lifetime of the devices your considering.

However if it’s a serious concern then take a look at the tp-link Omada line & eap accesspoints, you can host your own on prem controller, easy vlan setup to firewall off guest &/or IoT traffic from your trusted network.

They now do a all in one fw/router/poe switch/controller now for ~£180 & lots of choice new & s/h of Omada compatible accesspoints.


FunkyGibbon

3,793 posts

270 months

Sunday 12th March 2023
quotequote all
Another vote here for TP-Link Omada - dead east to setup guest networks and VLANs for IOT stuff.

Captain_Morgan said:
They now do a all in one fw/router/poe switch/controller now for ~£180 & lots of choice new & s/h of Omada compatible accesspoints.
Oooh, do they - do you have the model number, as one box may be more wife/aesthetically pleasing than the 3 I have at the moment.

Captain_Morgan

1,243 posts

65 months

Sunday 12th March 2023
quotequote all
FunkyGibbon said:
Another vote here for TP-Link Omada - dead east to setup guest networks and VLANs for IOT stuff.

Captain_Morgan said:
They now do a all in one fw/router/poe switch/controller now for ~£180 & lots of choice new & s/h of Omada compatible accesspoints.
Oooh, do they - do you have the model number, as one box may be more wife/aesthetically pleasing than the 3 I have at the moment.
https://www.broadbandbuyer.com/products/47184-tp-link-er7212pc/

FunkyGibbon

3,793 posts

270 months

Sunday 12th March 2023
quotequote all
Captain_Morgan said:
Excellent thanks

somouk

1,425 posts

204 months

Monday 13th March 2023
quotequote all
Captain_Morgan said:
That's a great bit of kit. Wish they had that out when I was speccing my kit.