User's Manual

8 Configuring Guest Access
172 Installation and User Guide: Airgo Access Point
Open Subnet
In an optional open subnet arrangement, shown in Figure 122, unauthenticated guest users are
permitted limited access to an open enterprise subnet specified in the Airgo AP. The enterprise
open subnet must be part of the Guest VLAN. Extended access requires authentication through an
internal or external landing page.
Figure 122: Guest Access - Open Subnet
Guest Access Persistence
If a guest user is temporarily disconnected from the Airgo AP due to loss of association, it may not
be necessary for the user to reauthenticate if the client reassociates to the same AP within one
minute. This is particularly beneficial when using a virtual private network (VPN) with guest
access, wherein the user signs on as a guest and then launches a VPN session to a remote VPN
server. Since the VPN session is tunneled over the guest session, a temporary loss of connectivity
does not require tearing down the VPN session. If loss of association extends beyond one minute, it
is necessary for the guest user to reauthenticate.
Internet
VLAN Switch
Open Subnet
Open Subnet
Address Range
No Direct Internet Access
Until Authenticated
GUEST-VLAN
A0035B
Open Access
Server
User Group = "GUEST"