
UNSOLVED
R
rocknwatch
1 Rookie
•
9 Posts
0
159
February 6th, 2024 16:24
Securing ports servicing Wireless Access Points
Our organization uses Ruckus wireless access points connected to a Ruckus wireless controller. They use a native VLAN and broadcast multiple SSIDs which correlate to appropriate VLANs. So for example, the ports on our N3248PXE-ON switches have the following configuration:
switchport mode trunk
switchport trunk native vlan [VLAN ID]
(This configuration is the only way the port will work with our WAPs)
We would like to secure the Ethernet ports to which these WAPs connect. That is, we would like to prevent other devices from being connected to those ports and gaining DHCP IP address leases in the WAP scope. I tried using port-security and limiting one MAC address to the port using sticky, but that ended up preventing the clients from having connectivity. We are trying to implement a FortiNAC solution too, but are running into issues with that as well (i.e. it sees the MAC addresses of the WAP clients and then classifies it to be rogue and puts the whole port in the isolation VLAN). Essentially, we want people to be able to use the WiFi provided via the WAPs, but we do not want the APs to be removed and the port used for other devices and if the WAP is disconnected, we would like for the port to be configured to send traffic to a dead-end VLAN or prevent the offending device from getting an IP address. Anyone have any ideas?
Thanks in advance!
(edited)
Responses (0)
Solutions (0)
