ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    ubnt guest wireless or separate VLAN?

    IT Discussion
    vlan security networking ubnt ubiquiti
    7
    23
    3.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller @dafyre
      last edited by

      @dafyre said in ubnt guest wireless or separate VLAN?:

      and 2) It's more secure. the Guest mode on the UBNT would still have to pass across the MetroE connection, and your systems at the other end would still need to know how to deal with it.

      So.... exactly like a VLAN? You just described a VLAN, in fact.

      JaredBuschJ 1 Reply Last reply Reply Quote 0
      • JaredBuschJ
        JaredBusch @scottalanmiller
        last edited by

        @scottalanmiller said in ubnt guest wireless or separate VLAN?:

        @dafyre said in ubnt guest wireless or separate VLAN?:

        and 2) It's more secure. the Guest mode on the UBNT would still have to pass across the MetroE connection, and your systems at the other end would still need to know how to deal with it.

        So.... exactly like a VLAN? You just described a VLAN, in fact.

        No. Completely not like a VLAN. Even if @dafyre doesn't know how to phrase it correctly.

        scottalanmillerS 1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller @JaredBusch
          last edited by

          @JaredBusch said in ubnt guest wireless or separate VLAN?:

          @scottalanmiller said in ubnt guest wireless or separate VLAN?:

          @dafyre said in ubnt guest wireless or separate VLAN?:

          and 2) It's more secure. the Guest mode on the UBNT would still have to pass across the MetroE connection, and your systems at the other end would still need to know how to deal with it.

          So.... exactly like a VLAN? You just described a VLAN, in fact.

          No. Completely not like a VLAN. Even if @dafyre doesn't know how to phrase it correctly.

          I meant the description was exactly the same... that it has to transit the metroE and if the equipment on the other end doesn't honour it the security evaporates.

          dafyreD 1 Reply Last reply Reply Quote 1
          • dafyreD
            dafyre @scottalanmiller
            last edited by

            @scottalanmiller said in ubnt guest wireless or separate VLAN?:

            @JaredBusch said in ubnt guest wireless or separate VLAN?:

            @scottalanmiller said in ubnt guest wireless or separate VLAN?:

            @dafyre said in ubnt guest wireless or separate VLAN?:

            and 2) It's more secure. the Guest mode on the UBNT would still have to pass across the MetroE connection, and your systems at the other end would still need to know how to deal with it.

            So.... exactly like a VLAN? You just described a VLAN, in fact.

            No. Completely not like a VLAN. Even if @dafyre doesn't know how to phrase it correctly.

            I meant the description was exactly the same... that it has to transit the metroE and if the equipment on the other end doesn't honour it the security evaporates.

            That was my point.

            scottalanmillerS 1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @dafyre
              last edited by

              @dafyre said in ubnt guest wireless or separate VLAN?:

              @scottalanmiller said in ubnt guest wireless or separate VLAN?:

              @JaredBusch said in ubnt guest wireless or separate VLAN?:

              @scottalanmiller said in ubnt guest wireless or separate VLAN?:

              @dafyre said in ubnt guest wireless or separate VLAN?:

              and 2) It's more secure. the Guest mode on the UBNT would still have to pass across the MetroE connection, and your systems at the other end would still need to know how to deal with it.

              So.... exactly like a VLAN? You just described a VLAN, in fact.

              No. Completely not like a VLAN. Even if @dafyre doesn't know how to phrase it correctly.

              I meant the description was exactly the same... that it has to transit the metroE and if the equipment on the other end doesn't honour it the security evaporates.

              That was my point.

              But you said that you would keep VLANs because .... and it seemed like you were saying that VLANs were more secure in this case.

              dafyreD 1 Reply Last reply Reply Quote 0
              • dafyreD
                dafyre @scottalanmiller
                last edited by

                @scottalanmiller said in ubnt guest wireless or separate VLAN?:

                @dafyre said in ubnt guest wireless or separate VLAN?:

                @scottalanmiller said in ubnt guest wireless or separate VLAN?:

                @JaredBusch said in ubnt guest wireless or separate VLAN?:

                @scottalanmiller said in ubnt guest wireless or separate VLAN?:

                @dafyre said in ubnt guest wireless or separate VLAN?:

                and 2) It's more secure. the Guest mode on the UBNT would still have to pass across the MetroE connection, and your systems at the other end would still need to know how to deal with it.

                So.... exactly like a VLAN? You just described a VLAN, in fact.

                No. Completely not like a VLAN. Even if @dafyre doesn't know how to phrase it correctly.

                I meant the description was exactly the same... that it has to transit the metroE and if the equipment on the other end doesn't honour it the security evaporates.

                That was my point.

                But you said that you would keep VLANs because .... and it seemed like you were saying that VLANs were more secure in this case.

                I would. What happens when the Guest traffic gets to the other end of the Metro E connection? Does it drop it? Does it send it on to the internet? Or what?

                With VLANs (and good documentation), you know exactly what it does.

                scottalanmillerS 1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @dafyre
                  last edited by

                  @dafyre said in ubnt guest wireless or separate VLAN?:

                  @scottalanmiller said in ubnt guest wireless or separate VLAN?:

                  @dafyre said in ubnt guest wireless or separate VLAN?:

                  @scottalanmiller said in ubnt guest wireless or separate VLAN?:

                  @JaredBusch said in ubnt guest wireless or separate VLAN?:

                  @scottalanmiller said in ubnt guest wireless or separate VLAN?:

                  @dafyre said in ubnt guest wireless or separate VLAN?:

                  and 2) It's more secure. the Guest mode on the UBNT would still have to pass across the MetroE connection, and your systems at the other end would still need to know how to deal with it.

                  So.... exactly like a VLAN? You just described a VLAN, in fact.

                  No. Completely not like a VLAN. Even if @dafyre doesn't know how to phrase it correctly.

                  I meant the description was exactly the same... that it has to transit the metroE and if the equipment on the other end doesn't honour it the security evaporates.

                  That was my point.

                  But you said that you would keep VLANs because .... and it seemed like you were saying that VLANs were more secure in this case.

                  I would. What happens when the Guest traffic gets to the other end of the Metro E connection? Does it drop it? Does it send it on to the internet? Or what?

                  With VLANs (and good documentation), you know exactly what it does.

                  My point was that that's the same in both cases. Both of your posts describe the same situation for both approaches. VLAN only works because you handle it on both ends. Guest works too in the same situation.

                  1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller
                    last edited by

                    The VLAN concept depends on end to end network support and planning. Identical to how the UBNT guest system works.

                    1 Reply Last reply Reply Quote 0
                    • dafyreD
                      dafyre
                      last edited by

                      Or does it... That'd be a good question for a UBNT person...

                      There's a number of ways they could achieve this without relying on the "other end" of the connection supporting their guest mode stuff.

                      scottalanmillerS 1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller @dafyre
                        last edited by

                        @dafyre said in ubnt guest wireless or separate VLAN?:

                        Or does it... That'd be a good question for a UBNT person...

                        There's a number of ways they could achieve this without relying on the "other end" of the connection supporting their guest mode stuff.

                        That would make it better than VLAN then 🙂

                        1 Reply Last reply Reply Quote 1
                        • Deleted74295D
                          Deleted74295 Banned @JaredBusch
                          last edited by

                          @JaredBusch said

                          It is not as easy as that to make it a secure guest network.

                          Yes but it depends what you mean by "secure"

                          Not having the ability for the client machines to talk to each other without layer-3 switches needed is a big boon.

                          1 Reply Last reply Reply Quote 0
                          • Mike DavisM
                            Mike Davis
                            last edited by

                            My understanding of how Ubiquiti handles guest mode is that it drops packets destined for internal networks. What I don't know is like I think some others were getting at - what if the user tries to go to another local subnet outside the subnet their on. I guess I'll just keep the VLAN thing.

                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller @Mike Davis
                              last edited by

                              @Mike-Davis said in ubnt guest wireless or separate VLAN?:

                              My understanding of how Ubiquiti handles guest mode is that it drops packets destined for internal networks. What I don't know is like I think some others were getting at - what if the user tries to go to another local subnet outside the subnet their on. I guess I'll just keep the VLAN thing.

                              My understanding is that it totally drops those packets too. In some ways, that makes it more secure than a VLAN because just hijacking a physical switch is not enough to grab the packets.

                              1 Reply Last reply Reply Quote 1
                              • 1
                              • 2
                              • 1 / 2
                              • First post
                                Last post