Documente Academic
Documente Profesional
Documente Cultură
It is a common security practice to setup a wireless guest network on a separate VLAN. This allows
for complete isolation of traffic between your private and guest networks. This guide will only be
covering how to implement this particular setup on MikroTik routers with built-in WiFi, such as the
RB951, RB962, etc. Before going forward, I’m assuming that a private wireless network already exists
and is fully functional. In addition, all screenshots and instructions in this guide are done using
MikroTik’s WinBox software.
Afterwards, navigate to the WiFi Interfaces tab and click the + (plus) button and select “Virtual” from
the menu. Under the General tab, set the Name for the Virtual AP, something descriptive, such as
WiFi-Guest. Afterwards, navigate to the Wireless tab and set the SSID, Security Profile, VLAN Mode,
and VLAN ID. The VLAN ID will match the VLAN interface that we will be creating in the next step.
See screenshots for further details:
CREATE THE VLAN INTERFACE
In Winbox, select Interfaces on the left-hand side and navigate to the VLAN tab. Click the + (plus)
button to create a new VLAN interface. The VLAN ID is “10” and the Interface is “WiFi-Guest”,
which are values that were set in the previous step, when creating the Virtual AP. See screenshot for
details:
NOTE: The MikroTik may be using “Interface Lists” (Winbox: Interface > Interface List tab) in some
of the firewall filter rules. If this is the case, you will want to either not use Interface Lists and use just
interfaces, or make sure to add the new VLAN interface for the guest network to the existing LAN
Interface List. If the MikroTik is using Interface Lists and you do not add the VLAN inteface for the
guest network to the existing LAN interface list, then guests will be able to connect to the network, but
will have no internet access. To be specific, the default MikroTik rule that requires the VLAN for the
guest network to be added to the LAN Interface List is the following:
NOTE: The MikroTik may be using “Interface Lists” (Winbox: Interface > Interface List tab) in some
of the firewall filter rules. If this is the case, you will want to either not use Interface Lists (requires
firewall filter rule modifications) and use just interfaces, or make sure to add the new VLAN interface
for the guest network to the existing LAN Interface List (no firewall filter rule modifications needed).
If the MikroTik is using Interface Lists and you do not add the VLAN inteface for the guest network
to the existing LAN interface list, then guests will be able to connect to the network, but will have no
internet access. To be specific, the default MikroTik rule that requires the VLAN for the guest network
to be added to the LAN Interface List is the following: