We have 1 802.1X SSID and 1 open web auth passthrough SSID.

Traffic on the authenticated SSID goes through our normal User VRF. Traffic on 
guest goes directly to an internet VRF which passes through our PAN. We do 
allow traffic to go out the internet and back, which we are flirting with 
disabling.

We throttle the speed of the open SSID to 1mbps up/down.

Our problem is that users find it easier to configure devices for the web auth 
so we try to time them out often, lower their speed, and maybe prevent them 
from reaching VPN (future). 

-----Original Message-----
From: The EDUCAUSE Wireless Issues Constituent Group Listserv 
[mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU] On Behalf Of Frank Sweetser
Sent: Tuesday, September 09, 2014 10:51 AM
To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU
Subject: Re: [WIRELESS-LAN] guest wireless

Our general policies are posted here:

https://urldefense.proofpoint.com/v1/url?u=http://www.wpi.edu/Academics/CCC/Netops/Wireless/Guest/&k=yYSsEqip9%2FcIjLHUhVwIqA%3D%3D%0A&r=eHsexY0U6WY24UhDK4eLQbvXOPzMySRoCq87DX3WV5M%3D%0A&m=qwzpYaLupWPZPbEbZunzdvuj06nITcEsszfpVFAAi58%3D%0A&s=c96ff8e0f964342ef759d323c7d96cf860113ed8931ca16b2e6236d6248e1dce

We avoid doing completely open wifi, as we have decided not to become a hotspot 
for any neighbors or people wandering by.  To handle the request volume and 
keep the turnaround time low, we have a larger number of contacts throughout 
campus (including the majority of administrative assistants) set up to hand out 
guest passes, typically limited to one day.

We don't set concurrent limits on logins, so we don't do anything special for 
group accounts vs individual ones.

In addition, we are also in the process of rolling out eduroam campus wide.

Frank Sweetser fs at wpi.edu    |  For every problem, there is a solution that
Manager of Network Operations   |  is simple, elegant, and wrong.
Worcester Polytechnic Institute |           - HL Mencken

On 09/09/2014 11:40 AM, Mark Reboli wrote:
> I am looking for information on what people do with guest wireless.  
> Do you have open wireless on your campus?  Do you have a password that 
> everyone knows?  Do you create special passwords for groups?  Any 
> assistance would be helpful.
>
> Thank you
>
> m
>
> Description: MU Arches
>
> Mark Reboli
>
> Network/Telcom Manager
>
> Misericordia University
>
> (570) 674-6753
>
> ********** Participation and subscription information for this 
> EDUCAUSE Constituent Group discussion list can be found at 
> https://urldefense.proofpoint.com/v1/url?u=http://www.educause.edu/groups/&k=yYSsEqip9%2FcIjLHUhVwIqA%3D%3D%0A&r=eHsexY0U6WY24UhDK4eLQbvXOPzMySRoCq87DX3WV5M%3D%0A&m=qwzpYaLupWPZPbEbZunzdvuj06nITcEsszfpVFAAi58%3D%0A&s=e5c6f89fb62653a0d95879fdd6086e0d68e9311f8aca8200b3ac774ae9621d9e.
>

**********
Participation and subscription information for this EDUCAUSE Constituent Group 
discussion list can be found at 
https://urldefense.proofpoint.com/v1/url?u=http://www.educause.edu/groups/&k=yYSsEqip9%2FcIjLHUhVwIqA%3D%3D%0A&r=eHsexY0U6WY24UhDK4eLQbvXOPzMySRoCq87DX3WV5M%3D%0A&m=qwzpYaLupWPZPbEbZunzdvuj06nITcEsszfpVFAAi58%3D%0A&s=e5c6f89fb62653a0d95879fdd6086e0d68e9311f8aca8200b3ac774ae9621d9e.

**********
Participation and subscription information for this EDUCAUSE Constituent Group 
discussion list can be found at http://www.educause.edu/groups/.

Reply via email to