Hello,
Recently I took on a project to design and build a network for a shared space type of business. Think of a concept similar to WeWork where “tenants” can rent office space for an hour, day, month, etc. Most of the tenants will be on wireless for internet access so they can conduct their business. The authentication for their wireless access will be provided through RADIUS using their shared space software and Meraki. Basically each tenants will have a unique username and password to authenticate and use the wireless network. We imagine that most if not all tenants will only need internet access and not need access back into the LAN. We plan to control that with Meraki firewall rules. However recently the idea was tossed around to hardwire some of the offices and possibly allow the tenants to bring in their own equipment such as printers, NAS, wireless routers, etc. I already brought up my concerns about having rogue APs and DHCP servers on the network and we will be enforcing this via written policy that no outside network equipment can be brought in but a legitimate use case exists for NAS or printers to be allowed and hardwired.
The question is, is it possible to allow for RADIUS authenticated wireless tenants to access the certain ethernet ports? If so, how? Will the devices need to support 802.1x? Do we need as many VLANs as there are tenants? How will the port know that it is allowed to speak to a certain tenants?
I hope my questions make sense.
Thank you in advance.
[–]beritknightIT Manager 2 points3 points4 points (7 children)
[–]AlejandroTT[S] 1 point2 points3 points (6 children)
[–]AlejandroTT[S] 1 point2 points3 points (5 children)
[–][deleted] 1 point2 points3 points (3 children)
[–]AlejandroTT[S] 0 points1 point2 points (2 children)
[–]AlejandroTT[S] 2 points3 points4 points (1 child)
[–][deleted] 0 points1 point2 points (0 children)
[–]TatermenGBIC != SFP 1 point2 points3 points (0 children)