<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MSM720 - Accessable Controller Management through Guest WLAN in M and MSM Series</title>
    <link>https://community.hpe.com/t5/m-and-msm-series/msm720-accessable-controller-management-through-guest-wlan/m-p/6310145#M3637</link>
    <description>When you go to Management -&amp;gt; Management Tool , there is an option for Active Interfaces, and a checkbox for each of the following: LAN Port, Internet Port, and VPN. You'd de-select the Internet Port if you don't want the management web interface to be available from the guest wireless network.&lt;BR /&gt;&lt;BR /&gt;Regards.&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Thu, 19 Dec 2013 21:30:33 GMT</pubDate>
    <dc:creator>JesseR</dc:creator>
    <dc:date>2013-12-19T21:30:33Z</dc:date>
    <item>
      <title>MSM720 - Accessable Controller Management through Guest WLAN</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msm720-accessable-controller-management-through-guest-wlan/m-p/6309519#M3629</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have an MSM720 WLAN Controller. Goal is two SSIDs. One for employees (VLAN 7) and one for guests (with HTML Authentication) (VLAN 8).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I configured the Controller with the "Configure initial controller settings".&amp;nbsp; The "Access network" was set to the IP 10.160.6.2/24 and is untagged in VLAN 6 on the Core Switch Port. The "Internet network" was configuried with the IP 10.160.8.2/24 with Gateway 10.160.8.1 (Internet Router/Firewall). DNS was set to 8.8.8.8 and 8.8.4.4. The "Internet network"-Port (Port 5) was untagged in VLAN 8. All Access Points are untagged in VLAN 6 and tagged in VLAN 7 and get an IP per DHCP from my "Internet Router/Firewall".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After that, i created a new "Network profile" for VLAN 7 named "employees". Then i created with the wizard an new wireless network for employess. Setup SSID and ticked the "Network Profile" "employees" at the Point "Send traffic to:" to get this traffice into VLAN 7. Except wireless Security all Settings are default. This network works just fine. I get an IP per DHCP from my Internet Router/Firewall from VLAN 7 and can access the Internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After that, i created a second wireless network for guests with the known wizard. Named SSID "guests", configured "guest authentication" for local user Accounts on the controller and setup the controller to act as a DHCP Server with the Range (192.168.1.1 - 192.168.1.254 and Mask 255.255.255.0).&lt;/P&gt;&lt;P&gt;I tried the guest WLAN and all seems to work fine. I get an 192.168.1.x IP Address, get the Login Page and can access the Internet after successfull login. On my firewall Port for VLAN 8 i see just the "Internet network" IP 10.160.8.2 as Source IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Problem now is, that i am able to ping the following IPs:&lt;/P&gt;&lt;P&gt;- 10.160.6.2 (Controller Access network IP)&lt;/P&gt;&lt;P&gt;- 10.160.8.2 (Controller Internet network IP)&lt;/P&gt;&lt;P&gt;- 10.160.8.1 (Internet Router/Firewall IP)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Much more "unfortunatelly" is, that i can access the Controller Management Site from guest WLAN if i type the controller IP in my browser.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'am not sure, if first my setup is ok and second where my misstake is hidden.&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for any tip or advice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2013 09:37:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msm720-accessable-controller-management-through-guest-wlan/m-p/6309519#M3629</guid>
      <dc:creator>Nameeert</dc:creator>
      <dc:date>2013-12-19T09:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: MSM720 - Accessable Controller Management through Guest WLAN</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msm720-accessable-controller-management-through-guest-wlan/m-p/6310079#M3635</link>
      <description>Hey Marco. Good job on the setup, I read through each step you discussed and all looks good.&lt;BR /&gt;&lt;BR /&gt;Just to verify, on the guest VSC, you have the "Always tunnel client traffic" enabled, correct?&lt;BR /&gt;&lt;BR /&gt;By default, you WILL be able to ping the IP addresses of the network controller for both the Access Port and Internet Port, even from the guest network. This is NORMAL.&lt;BR /&gt;&lt;BR /&gt;Even being able to ping the 10.160.8.1 is normal too. The bigger concern is, can you ping devices on the 10.160.6.x network or the 10.160.7.x network -- I'm guessing you can't -- when connected to the guest wireless.&lt;BR /&gt;&lt;BR /&gt;Also remember, you CAN setup ACLs on the wireless controller too via the Public Access -&amp;gt; Attributes page. Here you can put in deny statements as necessary to prevent access to your internal network. However, since (from what I can tell by your description) the Internet port of your MSM is plugged Directly into your firewall (maybe on a DMZ interface?), you're probably more than good to go.&lt;BR /&gt;&lt;BR /&gt;If you want to turn OFF the ability for guest users to get intot the MSM controllers web interface, that would be done from Management -&amp;gt; Management Tool, where you can DESELECT the interfaces of your choice!&lt;BR /&gt;&lt;BR /&gt;Hope that helps.</description>
      <pubDate>Thu, 19 Dec 2013 20:04:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msm720-accessable-controller-management-through-guest-wlan/m-p/6310079#M3635</guid>
      <dc:creator>JesseR</dc:creator>
      <dc:date>2013-12-19T20:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: MSM720 - Accessable Controller Management through Guest WLAN</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msm720-accessable-controller-management-through-guest-wlan/m-p/6310133#M3636</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for your reply.&lt;/P&gt;&lt;P&gt;Yes, "Always tunnel client traffic" is for the guest wireless network enabled. For the "employees" Network not enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I cannot ping devices from the other VLANs. I just can ping the controller IP 10.160.6.2. The Gateway in the VLAN 6 for example (10.160.6.1) is not pingable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to work with ACLs like described in a HP Guide and tried to deny access to private Networks (10.x.x.x). Unfortunatelly the guest wireless clients were still able to ping the IPs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes. I just want to turn off management for my guest users. The ability to ping the controllers IPs is not really a problem for me or my customer.&lt;/P&gt;&lt;P&gt;Unfortunatelly I am not able to set the setting you advice right now. The device is at the customers site.&lt;/P&gt;&lt;P&gt;But do i unstand right, that i can DISABLE management for specific interfaces? So i can DESELECT the "Access network port" and "Internet network port" and use a third custom port/network for management which i place in my productiv Network?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please give a short reply if i understand right.&lt;/P&gt;&lt;P&gt;Then i will try to change the setting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2013 21:06:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msm720-accessable-controller-management-through-guest-wlan/m-p/6310133#M3636</guid>
      <dc:creator>Nameeert</dc:creator>
      <dc:date>2013-12-19T21:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: MSM720 - Accessable Controller Management through Guest WLAN</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msm720-accessable-controller-management-through-guest-wlan/m-p/6310145#M3637</link>
      <description>When you go to Management -&amp;gt; Management Tool , there is an option for Active Interfaces, and a checkbox for each of the following: LAN Port, Internet Port, and VPN. You'd de-select the Internet Port if you don't want the management web interface to be available from the guest wireless network.&lt;BR /&gt;&lt;BR /&gt;Regards.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 19 Dec 2013 21:30:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msm720-accessable-controller-management-through-guest-wlan/m-p/6310145#M3637</guid>
      <dc:creator>JesseR</dc:creator>
      <dc:date>2013-12-19T21:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: MSM720 - Accessable Controller Management through Guest WLAN</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msm720-accessable-controller-management-through-guest-wlan/m-p/6357153#M3675</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i tried your suggestion and it worked like a charm.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2014 11:35:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msm720-accessable-controller-management-through-guest-wlan/m-p/6357153#M3675</guid>
      <dc:creator>Treeeman</dc:creator>
      <dc:date>2014-01-30T11:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: MSM720 - Accessable Controller Management through Guest WLAN</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msm720-accessable-controller-management-through-guest-wlan/m-p/6567506#M3950</link>
      <description>&lt;P&gt;Thank you all. This is of great help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I ask one question please? Your help is greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do I change the local hostname of the html login page for public access? The default is : &lt;A target="_blank" href="http://wireless.hp.internal:8080."&gt;http://wireless.hp.internal:8080.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance for your help.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2014 05:34:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msm720-accessable-controller-management-through-guest-wlan/m-p/6567506#M3950</guid>
      <dc:creator>JunB</dc:creator>
      <dc:date>2014-08-08T05:34:51Z</dc:date>
    </item>
  </channel>
</rss>

