Configuring a Zone for Guest Access

SonicWall User Guest Services provides you with an easy solution for creating wired and wireless guest passes and/or locked-down Internet-only network access for visitors or untrusted network nodes. This functionality can be extended to either wired or wireless users on the LAN, WLAN, and DMZ zones, or a public/semi-public zone of your choice.

To configure the User Guest Services feature:
1
An existing zone, navigate to the Network > Zones page in the SonicOS management interface.
2
Under the Configure column, click the Edit icon for the zone where you wish to add Guest Services. The Edit Zone menu displays.
NOTE: Depending on the zone, there may be tabs available for General, Guest Services, or Wireless.
3
Click the Guest Services tab. Guest Services allows access to the Internet only.

4
To grant access to guests and visitors, select Enable Guest Services. Guest services may be wired or wireless. This option must be selected to activate the other options.
5
6
7
8
Optionally, to require guests connecting from the Guest Services Zone to authenticate before gaining access, select Enable External Guest Authentication. This feature, based on Lightweight Hotspot Messaging (LHM) is used for authenticating Hotspot users and providing them parametrically bound network access.

To configure external guest authentication, go to Configuring External Guest Authentication.

NOTE: Selecting Enable External Guest Authentication disables (dims) these options: Enable Policy Page without authentication, Custom Authentication Page, and Post Authentication Page.
9
a
Click Configure to display the Customize Policy Message window.

b
c
Click OK.
10
a
Click Configure to set up the custom authentication page. The Customize Policy Message dialog displays.

b
For the Custom Header Content Type and Custom Footer Content Type, select either URL or Text.
c
In the Content fields, enter either:
A URL to an authentication page if you selected URL. The URL must be in the format http://www.domainname.com.
d
11
Optionally, to redirect users to a custom authentication page immediately after successful authentication when they first connect to the Guest Services Zone, select Post Authentication Page. Enter a URL for the post-authentication page in the field. The URL must be in the format http://www.domainname.com.
12
Optionally, to grant unrestricted Wireless Guest Services access, select Bypass Guest Authentication. This option allows the Guest Services feature to integrate into environments already using some form of user-level authentication. This feature automates the Guest Services authentication process, allowing wireless users to reach Guest Services resources without requiring authentication.
From the drop-down menu, select All MAC Addresses, Create new MAC Object…, or an existing Address Group.
13
14
15
16
Special Guest Services Features for Wireless Zones
17
Optionally, to grant access to non_DHCP guests, select Enable Dynamic Address Translation (DAT). DAT allows the SonicPoint to support any IP addressing scheme for Guest Services users.

Guest Services provides spur-of-the-moment, Hotspot access to wireless-capable guests and visitors. For easy connectivity, Guest Services allows wireless users to authenticate and associate, obtain IP settings, and authenticate using any Web-browser. Without DAT, if a guest user is not a DHCP client, but instead has static IP settings incompatible with the Wireless WLAN network settings, network connectivity is prevented until the user’s settings change to compatible values.

If this option is disabled (unchecked), wireless guest users must either have DHCP enabled, or an IP addressing scheme compatible with the SonicPoint’s network settings.

Dynamic Address Translation (DAT) is a form of Network Address Translation (NAT) that allows the system to support any IP addressing scheme for guest users. For example, the Wireless WLAN interface is configured with its default address of 172.16.31.1, and one guest client has a static IP address of 192.168.0.10 and a default gateway of 192.168.0.1, while another has a static IP address of 10.1.1.10 and a gateway of 10.1.1.1, and DAT enables network communication for both of these clients.

18
Click OK to apply these settings to this zone.