SSCP Systems Security Certified PractitionerNetwork and Communications SecurityMedium
A company is setting up a guest wireless network. Policy dictates that guest users should only have internet access and be strictly isolated from the internal corporate network resources. Which of the following network configurations would effectively achieve this isolation?
- APlacing guest APs on the same VLAN as internal users but with a different SSID.
- BUsing a separate VLAN for guest traffic and routing it directly to the internet via a firewall.
- CConfiguring a separate SSID for guests with no password, relying on the firewall for protection.
- DImplementing MAC address filtering on the guest APs to restrict access.
Show answer & explanationAnswer & explanation
Correct answer: B. Using a separate VLAN for guest traffic and routing it directly to the internet via a firewall.
Using a separate VLAN for guest traffic provides logical isolation from the internal network. Routing this VLAN directly to the internet through a dedicated firewall rule ensures guests only have internet access and cannot reach internal resources.
Why the other options are wrong
- A. Placing guest APs on the same VLAN as internal users, even with a different SSID, does not provide logical isolation. Guests would still be on the same broadcast domain and could potentially access internal resources.
- C. Configuring a separate SSID with no password creates an open network, which is insecure and does not inherently provide isolation from internal resources; it only makes the network easily accessible.
- D. MAC address filtering is easily bypassed and does not provide logical network isolation or control over what resources a connected device can access beyond the AP.
Guest Network Isolation
The practice of creating a separate, logically isolated network segment for guest users to prevent their access to internal corporate resources.
- Typically uses VLANs for logical separation.
- Traffic is routed through a firewall to restrict access.
- Ensures guests only have internet access.
Memory trick: Isolation is Key: VLANs Separate, Firewalls Filter, SSIDs Don't Isolate.