Fork this blog on GitHub Fork this blog on GitHub

Aerohive How To: Create a Firewalled and NATed Separate Network

Suppose you want to create a separate wireless network for guests or so that employees may access the Internet with their personal devices. Devices on this separate network should only be able to access the Internet and not be able to access any internal resources. I have not seen this documented anywhere, so I am going to share. There are several steps, but the process is relatively painless.

Start by creating a New VLAN under Configuration > Advanced > Network Objects > VLANs. Choose a VLAN numeral that is not being used. I chose 42.

Now let’s create a New DHCP server for the new guest network under Configuration > Advanced > Network Objects > DHCP Server & Relay. Make sure you add public DNS servers to the DHCP server options.

New DHCP Server

Next create a New User Profile:

New User Profile

Fill in the following:

  • Attribute Number must be a unique number.
  • Select your new VLAN in the Default VLAN field.
  • Under firewalls add a new IP Firewall policy

The New Firewall Policy should look something like this:

New Firewall Policy

Now create a New SSID and reference the new User Profile.

The last step is a bit awkward because it must be individually performed for each access point. Unfortunately a bulk edit is not possible. Edit each AP and navigate to Optional Settings > Service Settings > DHCP Server & Relay. Add the DHCP server to each AP.

There you go! You now have a separate SSID that provides guest access (or whatever kind of access you want) to the Internet. Furthermore, this network does not leak any information about your internal private network since it uses its own IP addressing scheme, is firewalled off, and is configured to use public DNS servers.

If anyone has comments or if you find this information to be helpful, please let me know and/or follow me on Twitter.

Next entry

Previous entry

Related entries

Similar entries


  1. Fab

    Fab on 01/11/2013 4:43 p.m.

    Thanks a lot Charles for your Help concerning setting up an Access Ppoint as DHCP server for separate Guest access!

  2. Terrance

    Terrance on 01/25/2013 12:16 a.m.

    Hi Charles,

    Does the gateway still need to be terminated at the firewall/coreswitch ?

  3. Karl

    Karl on 06/03/2013 8:10 a.m.

    Brilliant guide, I've spent ages looking for exactly this.

  4. craig

    craig on 06/14/2013 1:13 p.m.

    Now let us know how to make this work with CWP.

  5. Daniel

    Daniel on 12/06/2013 5:42 p.m.

    Hi. I just got our first Aerohives. They are running 6.1r2 and I cannot find where to create a VLAN. Have you used your technique with recent firmware? Am I just being dense?


  6. вулкан играть на деньги

    вулкан играть на деньги on 04/09/2020 6:53 p.m.

    It's an remarkable post for aall the web viewers

  7. adultfriendfimder

    adultfriendfimder on 05/10/2020 2:58 p.m.

    Very good information. Lucky me I ran across your blog by chance (stumbleupon).

    I have saved as a favorite for later!

  8. face and neck exercises

    face and neck exercises on 05/10/2020 11:13 p.m.

    Now let's check out numerous things you're able to do to help increase your power so you can live an even more satisfying life.
    Dr Gerba studies how diseases are transferred through
    the environment, looking to measure what number of bacteria and
    what sort each household item develops. No doubt you are able
    to get these efas from fish at the same time, but doctors suggest that you reduce the quantity of fish you take in when you
    find yourself pregnant due to fears of mercury poisoning.

  9. 34 happy consulting

    34 happy consulting on 05/13/2020 8:46 a.m.

    Türkiye'de çalışmak için oturma ve çalışma iznine ihtiyaç duyarsınız.
    34 happy consulting sizin için tüm süreçleri
    gerçekleştirmektedir. Çalışma izni, oturma izni,
    yabancı sağlık sigortası ve daha birçok şey.

    Hemen oturma ve çalışma izinleri için bizimle iletişime geçin.

  10. казино вулкан ставка 10 копеек

    казино вулкан ставка 10 копеек on 05/14/2020 2:26 a.m.

    Самое лучшее время для составления планов на будущее, и пришел час быть
    счастливым. Я с радостью прочитал этот пост и, по возможности, хочу предложить вам несколько интересных вещей или
    предложений. Возможно, вы могли бы
    написать следующие статьи, ссылаясь на мои материалы?
    Я хочу прочитать больше
    об этом!

Post your comment


Pingbacks are closed.