06-24-2011
08:29 AM
- last edited on
02-03-2015
08:04 AM
by
linksys-communi
I cannot get the Guest Network feature to work.
Even though Guest SSID is enabled, it does not show up on any devices attempting to connect. Manually connecting by entering the Guest SSID fails (not recognized). On devices with the primary 5 and 2.4 GHz configured they do see the third network but without SSID (unknown) and are also unable to connect to it manually using the SSID.
Here are my settings:
Firmware: 1.0.02
E4200 is configured in Bridge mode (WAP).
5 GHz Network
Mode Mixed
SSID Astro2-an
Width Auto
Channel Auto (DFS)
SSID Broadcast Disabled
2.4 GHz Network
Mode Mixed
SSID Astro2-bgn
Width Auto
Channel Auto
SSID Broadcast Disabled
Guest Access
Allow yes
Name Astro2-bgn-guest (cannot be changed)
Guest Password testpassword
Total Guests Allowed 5
SSID Broadcast enabled
I did not try this before 1.0.02. Have rebooted modem and verified all configs (multiple times). The network is live in an office and can't keep screwing with it or drastically changing its settings.
Peter
Solved! Go to Solution.
06-24-2011 10:40 AM - edited 06-24-2011 10:41 AM
It's not possible to use guest access in bridge mode. Guest access is only possible when the E4200 operates as router. In bridge mode any wireless network goes directly into the same LAN. Guest separation would not be possible.
Also don't disable the SSID broadcast.
06-24-2011 11:26 AM
If you look at the settings I provided, SSID is enabled for Guest mode. Are you saying that for guest mode to work and its SSID to be enabled you must have the main 2.4 GHz network SSID enabled?
Also... Following is from the release notes for latest firmware:
- Prevented devices on the guest network to access any private IP address (RFC 1918)
This would imply that the router makes private addresses non-routable for the Guest network which would make bridging a non-issue (and is why I decided to try Guest with this release of the firmware). If this works the way I expect, only Internet routable IPs should be accessible to the guest network (my LAN is all private IP).
Peter
06-25-2011 07:10 PM - edited 06-25-2011 07:14 PM
This particular E4200 was purchased with firmware 1.0.0, then upgraded to 1.0.01, and finally updated to 1.0.02. I did not hard reset after the upgrades, just let the firmware carry over the configs. Seeing other problems in the forum resolved after upgrade by hard resetting, I gave it a try. I printed off all config and status pages, did a hard reset, and then manually entered all the configs exactly as they were. But now the guest network works and all is well. For those interested, the guest network is placed on a completely different subnet (19.168.33.0/24 versus my normal LAN on 192.168.0.0/24). Additionally, the E4200 does make all private IPs non-routable while on the guest network. This means you can use the E4200 as a WAP in bridge mode anywhere on your private subnet and guest users can only access Internet routable locations. Very nice! And, to close the other question raise in this thread, you can leave the SSID disabled on the main 5 and 2.4 GHz networks and separately enable or disable it for the Guest network.
I would suggest always do a hard reset after firmware upgrade even if your settings appear to have carried over...
Peter
07-01-2011 07:54 PM
This still appears to be the case. I have my E4200 behind a Fortigate 50B and only use the E4200 as my AP. I would like to see this fixed.... not having the guest network really makes the AP less useful to me.
07-11-2011 06:42 PM
Peter,
Thanks for the detailed post about this. I bought this router because of a few reviews and then because of your post about guest access.
I can confirm that guest acess works in bridge mode when using the router as an AP on my internal LAN. Infact it has to go through two other routers to get to the internet so it works quite well! Guests have no access to my internal network. Works great.
08-09-2011 06:47 AM
08-17-2011 06:39 PM
Same issue as whsbuss, any help would be greatly appreciated.
Thanks
08-18-2011
08:31 PM
- last edited on
08-18-2011
09:59 PM
by
daikunzeon
I have now tried 3 of these routers and the problem as I see it is when you set the E4200 to bridege mode with a static IP then the client receives a .33.x address receive the E4200's default gateway and a .33.1 as the dns servers. I don't see how the clients could resolve dns with these 2 entries.
Alas, I have think I have now figured out why some people can connect using the E4200 in bridge mode as a guest and some cannot. It is my belief that Cisco needs to update the firmware to allow you to enter dns values on the staic page because if you set the E4200 to obtain an IP address automatically then it receives good DNS info. You can verify my results by looking at the staus page in staic and dynamic mode.
I hope this helps people that are having problems.......
(Mod Note: Edited due to non-compliance of forum guidelines.)
08-19-2011 05:30 AM
paul@ininc.com wrote:I have now tried 3 of these routers and the problem as I see it is when you set the E4200 to bridege mode with a static IP then the client receives a .33.x address receive the E4200's default gateway and a .33.1 as the dns servers. I don't see how the clients could resolve dns with these 2 entries.
Alas, I have think I have now figured out why some people can connect using the E4200 in bridge mode as a guest and some cannot. It is my belief that Cisco needs to update the firmware to allow you to enter dns values on the staic page because if you set the E4200 to obtain an IP address automatically then it receives good DNS info. You can verify my results by looking at the staus page in staic and dynamic mode.
I hope this helps people that are having problems.......
(Mod Note: Edited due to non-compliance of forum guidelines.)
Your findings are correct. However I don't see where adding a static DNS would work. What Cisco needs to do is provide the DNS of the connected gateway for internet access when in bridge mode for guest connections. Then restrict routing to just the gateway for internet access and no local routing.