Quantcast
Channel: All Ethernet Switching posts
Viewing all articles
Browse latest Browse all 10307

Re: Allow guest to acess employee resource

$
0
0

Assuming your guest wifi is 10.2.2.0/24 and the specific address is 10.1.1.100/24

 

set interfaces vlan unit 999 description "guest wifi"
set interfaces vlan unit 999 family inet filter input guest-outbound-filter
set interfaces vlan unit 999 family inet filter output guest-inbound-filter
set interfaces vlan unit 999 family inet address 10.2.2.1/24

set firewall family inet filter guest-inbound-filter term empvlan from source-address 10.1.1.100/32
set firewall family inet filter guest-inbound-filter term empvlan then accept
set firewall family inet filter guest-inbound-filter term deny-everything-else then discard

set firewall family inet filter guest-outbound-filter term empvlan from destination-address 10.1.1.100/32
set firewall family inet filter guest-outbound-filter term empvlan then accept
set firewall family inet filter guest-outbound-filter term deny-everything-else then discard

Assuming you want guest wifi to also have internet access:

 

set interfaces vlan unit 999 description "guest wifi"
set interfaces vlan unit 999 family inet filter input guest-outbound-filter
set interfaces vlan unit 999 family inet filter output guest-inbound-filter
set interfaces vlan unit 999 family inet address 10.2.2.1/24

set firewall family inet filter guest-inbound-filter term empvlan from source-address 10.1.1.100/32
set firewall family inet filter guest-inbound-filter term empvlan then accept
set firewall family inet filter guest-inbound-filter term no-rfc1918 from source-address 10.0.0.0/8
set firewall family inet filter guest-inbound-filter term no-rfc1918 from source-address 172.16.0.0/12
set firewall family inet filter guest-inbound-filter term no-rfc1918 from source-address 192.168.0.0/16
set firewall family inet filter guest-inbound-filter term no-rfc1918 from source-address 169.254.0.0/16
set firewall family inet filter guest-inbound-filter term no-rfc1918 from source-address 127.0.0.0/8
set firewall family inet filter guest-inbound-filter term no-rfc1918 from source-address 224.0.0.0/3
set firewall family inet filter guest-inbound-filter term no-rfc1918 then discard
set firewall family inet filter guest-inbound-filter term allow-internet then accept

set firewall family inet filter guest-outbound-filter term empvlan from destination-address 10.1.1.100/32
set firewall family inet filter guest-outbound-filter term empvlan then accept
set firewall family inet filter guest-outbound-filter term no-rfc1918 from destination-address 10.0.0.0/8
set firewall family inet filter guest-outbound-filter term no-rfc1918 from destination-address 172.16.0.0/12
set firewall family inet filter guest-outbound-filter term no-rfc1918 from destination-address 192.168.0.0/16
set firewall family inet filter guest-outbound-filter term no-rfc1918 from destination-address 169.254.0.0/16
set firewall family inet filter guest-outbound-filter term no-rfc1918 from destination-address 127.0.0.0/8
set firewall family inet filter guest-outbound-filter term no-rfc1918 from destination-address 224.0.0.0/3
set firewall family inet filter guest-outbound-filter term no-rfc1918 then discard
set firewall family inet filter guest-outbound-filter term allow-internet then accept

 


Viewing all articles
Browse latest Browse all 10307

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>