Securing the port of an outdoor AP

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Securing the port of an outdoor AP

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Securing the port of an outdoor AP
Securing the port of an outdoor AP
2023-04-26 13:25:26
Model: TL-SG2008  
Hardware Version: V3
Firmware Version: 3.0.7

I have a full Omada network with an ER605 gateway, TL-SG2008 and TL-SG2008P switches, some EAP650 APs, and an EAP225-outdoor (soon to be replaced with the EAP650-outdoor).  My controller is running in Docker on a Synology NAS.

 

Generally speaking, I want to keep my network relatively simple.  Everything is currently running on default VLAN 1 and I generally want to keep it that way.  What I really want to try to do is secure the switch port that the outdoor AP is connected to such that if someone were to disconnect the AP and plug in a PC, they couldn't get on the main network.  Essentially, I'd like to keep using VLAN 1 for clients connecting to the outdoor AP but have the physical connection be protected such that if you plugged a laptop to it, it would NOT land on VLAN 1.  I DO NOT want to have to put my controller (in Docker on my NAS) on a VLAN other than VLAN 1.

 

Is this possible?  I've read over the guide about configuring a management VLAN but it's rather unclear what exactly that does or does not do and it sounds as though the controller would have to be on that VLAN which isn't going to work for me.

  0      
  0      
#1
Options
1 Reply
Re:Securing the port of an outdoor AP
2023-04-26 20:58:54

  @SingletrackMind The only secure way is to use 802.1X authentication.

Other alternatives that will deter prying eyes is adding the devices to the managment vlan and adding firewall rules to block trafic from user's network.

things that will not deter people with basic know-how: mac based authorization.

 

 

  0  
  0  
#2
Options