Main Menu
  • COMPANY
    • Boundless Cybersecurity
    • Press Releases
    • News
    • Awards
    • Leadership
    • Press Kit
    • Careers
  • PROMOTIONS
    • Customer Loyalty Program
  • MANAGED SERVICES
    • Managed Security Services
    • Security as a Service
    • Professional Services
SonicWall
  • Products
    • Network Security
      • Next Generation FirewallNext-generation firewall for SMB, Enterprise, and Government
      • Security ServicesComprehensive security for your network security solution
      • Network Security ManagerModern Security Management for today’s security landscape
    • Advanced Threat Protection
      • Capture ATPMulti-engine advanced threat detection
      • Capture Security applianceAdvanced Threat Protection for modern threat landscape
    • Access Security
      • Cloud Edge Secure AccessDeploy Zero-Trust Security in minutes
      • Secure Mobile AccessRemote, best-in-class, secure access
      • Wireless Access PointsEasy to manage, fast and secure Wi-FI
      • SwitchesHigh-speed network switching for business connectivity
    • Email Security
      • Email SecurityProtect against today’s advanced email threats
    • Cloud Security
      • Cloud App SecurityVisibility and security for Cloud Apps
      • Cloud Firewall (NSv)Next-generation firewall capabilities in the cloud
    • Endpoint Security
      • Capture ClientStop advanced threats and rollback the damage caused by malware
      • Content Filtering ClientControl access to unwanted and unsecure web content
    • Product Widgets
      • Product Menu Right Image
      • Capture Cloud Platform
        Capture Cloud Platform

        A security ecosystem to harness the power of the cloud

    • Button Widgets
      • Products A-Z
        all products A–Z FREE TRIALS
  • Solutions
    • Industries
      • Distributed Enterprises
      • Retail & Hospitality
      • K-12 Education
      • Higher Education
      • State & Local
      • Federal
      • Healthcare
      • Financial Services
      • Carriers
    • Use Cases
      • Secure SD-Branch
      • Zero Trust Security
      • Secure SD-WAN
      • Office 365 Security
      • SaaS Security
      • Secure WiFi
    • Solutions Widgets
      • Solutions Content Widgets
        Federal

        Protect Federal Agencies and Networks with scalable, purpose-built cybersecurity solutions

      • Solutions Image Widgets
  • Partners
    • SonicWall Partners
      • Partners Overview
      • Find a Partner
      • Authorized Distributors
      • Technology Partners
    • Partner Resources
      • Become a Partner
      • SonicWall University
      • Training & Certification
    • Partner Widgets
      • Custom HTML : Partners Content WIdgets
        Partner Portal

        Access to deal registration, MDF, sales and marketing tools, training and more

      • Partners Image Widgets
  • Support
    • Support
      • Support Portal
      • Knowledge Base
      • Technical Documentation
      • Community
      • Video Tutorials
      • Product Life Cycle Tables
      • Partner Enabled Services
      • Contact Support
    • Resources
      • Resource Center
      • Free Trials
      • Blog
      • SonicWall University
      • MySonicWall
    • Capture Labs
      • Capture Labs
      • Security Center
      • Security News
      • PSIRT
      • Application Catalog
    • Support Widget
      • Custom HTML : Support Content WIdgets
        Support Portal

        Find answers to your questions by searching across our knowledge base, community, technical documentation and video tutorials

      • Support Image Widgets
  • COMPANY
    • Boundless Cybersecurity
    • Press Releases
    • News
    • Awards
    • Leadership
    • Press Kit
    • Careers
  • PROMOTIONS
    • Customer Loyalty Program
  • MANAGED SERVICES
    • Managed Security Services
    • Security as a Service
    • Professional Services
  • Contact Sales
  • English English English en
  • BLOG
  • CONTACT SALES
  • FREE TRIALS
  • English English English en
SonicWall
  • Products
    • Network Security
      • Next Generation FirewallNext-generation firewall for SMB, Enterprise, and Government
      • Security ServicesComprehensive security for your network security solution
      • Network Security ManagerModern Security Management for today’s security landscape
    • Advanced Threat Protection
      • Capture ATPMulti-engine advanced threat detection
      • Capture Security applianceAdvanced Threat Protection for modern threat landscape
    • Access Security
      • Cloud Edge Secure AccessDeploy Zero-Trust Security in minutes
      • Secure Mobile AccessRemote, best-in-class, secure access
      • Wireless Access PointsEasy to manage, fast and secure Wi-FI
      • SwitchesHigh-speed network switching for business connectivity
    • Email Security
      • Email SecurityProtect against today’s advanced email threats
    • Cloud Security
      • Cloud App SecurityVisibility and security for Cloud Apps
      • Cloud Firewall (NSv)Next-generation firewall capabilities in the cloud
    • Endpoint Security
      • Capture ClientStop advanced threats and rollback the damage caused by malware
      • Content Filtering ClientControl access to unwanted and unsecure web content
    • Product Widgets
      • Product Menu Right Image
      • Capture Cloud Platform
        Capture Cloud Platform

        A security ecosystem to harness the power of the cloud

    • Button Widgets
      • Products A-Z
        all products A–Z FREE TRIALS
  • Solutions
    • Industries
      • Distributed Enterprises
      • Retail & Hospitality
      • K-12 Education
      • Higher Education
      • State & Local
      • Federal
      • Healthcare
      • Financial Services
      • Carriers
    • Use Cases
      • Secure SD-Branch
      • Zero Trust Security
      • Secure SD-WAN
      • Office 365 Security
      • SaaS Security
      • Secure WiFi
    • Solutions Widgets
      • Solutions Content Widgets
        Federal

        Protect Federal Agencies and Networks with scalable, purpose-built cybersecurity solutions

      • Solutions Image Widgets
  • Partners
    • SonicWall Partners
      • Partners Overview
      • Find a Partner
      • Authorized Distributors
      • Technology Partners
    • Partner Resources
      • Become a Partner
      • SonicWall University
      • Training & Certification
    • Partner Widgets
      • Custom HTML : Partners Content WIdgets
        Partner Portal

        Access to deal registration, MDF, sales and marketing tools, training and more

      • Partners Image Widgets
  • Support
    • Support
      • Support Portal
      • Knowledge Base
      • Technical Documentation
      • Community
      • Video Tutorials
      • Product Life Cycle Tables
      • Partner Enabled Services
      • Contact Support
    • Resources
      • Resource Center
      • Free Trials
      • Blog
      • SonicWall University
      • MySonicWall
    • Capture Labs
      • Capture Labs
      • Security Center
      • Security News
      • PSIRT
      • Application Catalog
    • Support Widget
      • Custom HTML : Support Content WIdgets
        Support Portal

        Find answers to your questions by searching across our knowledge base, community, technical documentation and video tutorials

      • Support Image Widgets
  • COMPANY
    • Boundless Cybersecurity
    • Press Releases
    • News
    • Awards
    • Leadership
    • Press Kit
    • Careers
  • PROMOTIONS
    • Customer Loyalty Program
  • MANAGED SERVICES
    • Managed Security Services
    • Security as a Service
    • Professional Services
  • Contact Sales
  • Menu

How can I create a Guest Wi-Fi on a Wireless capable SonicWall appliance?

10/25/2021 1,247 People found this article helpful 107,497 Views

    Download
    Print
    Share
    • LinkedIn
    • Twitter
    • Facebook
    • Email
    • Copy URL The link has been copied to clipboard

    Description

    A typical wireless implementation involves creating Wireless Access Points (WAP) for both for a well regulated network used by employee (e.g., Corp) and for a less regulated network used by Guests. While it can be achieved in a few different ways, they all use Virtual Access Points (VAP). It allows one to use a single AP to support multiple (virtual) APs with different authentication and encryption. A logical way of achieving this would be as follows.

    1. Define Virtual Access Point Profiles for authentication and encryption.
    2. Define Virtual Access Points- Corp (SSID) and Guest (SSID).
    3. Group the VAPs (SSIDs) to a Radio Group, EXAMPLE: Internal Radio Group.
    4. Assign the group to the Internal Radio.
    5. Configure the network zone and wireless Interface.

      NOTE: Wireless on a SonicWall Network Appliance can be set up in 2 different ways. For models that end with a "w" e.g., TZ500W have an internal wireless radio that can provide wireless access similar to standalone devices such as a SonicPoint. This is reflected in the GUI control where one often sees two section on a Wireless capable device (Fig. 1). For the present purpose we will discuss the setup using the Internal Wireless.

           Image

      Image

    Fig. 1. GUI wireless control on a wireless capable SonicWall Network Appliance.

    Resolution


    Resolution for SonicOS 7.X

    This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.






    Network Configurations :

    1.  Add a Guest zone with security type wireless.
    2. Configure the default WLAN Interface.

      1. Create a VLAN for the Guest Wireless Zone (the IP address of the interface will be static if the firewall distributes the DHCP addresses, EXAMPLE: step C).
      2. Set the Default WLAN in Layer2 Bridges Mode by bridging to the LAN, EXAMPLE: X0
    3. Add a Dynamic DHCP Scope.


      A:      Image


      B:      Image


           B:     Image


           C:    Image
         



    Wireless Configurations

    1. Configure the Virtual Access Point.
      A1: Add the Virtual Access Point Profile

             Image

      A2: Add the Virtual Access Points:

                Image

      A3: Add GuestWifi to the Internal Address Group

          Image

    2. Configure Settings.

      Image


    • Enable Short Guard Interval : Enabling Short Guard specifies an interval of 400 Nano seconds (ns) as opposed to the standard of 800 ns. This refers to a  pause in transmission intended to avoid data loss from interference or multiple delays.
    • Enable Aggregation : This refers to 802.11n frame aggregation which combines frames to reduce overhead and increases throughput.
    • Enabling Short Guard and Aggregation may improve throughput in environments that have low interference. However, in environments with significant interferences, they are not advisable.

    Single SSID

    • As explained above, a wireless capable device (SonicWall Network Appliance or SonicPoint) may be used for supporting a single SSID or multiple SSIDs (as discussed above). For cases one would like to set up the device for a single SSID, the configurations done on the settings page can be done on the Wireless | Settings and Security page.
    • Settings for a single SSID on Wireless capable appliance (e.g., TZ500W or TZ 670W). Based on the Authentication Type (1) WPA2-AUTO-PSK (A) or WPA2-AUTO-EAP (B), one has to update a Preshared Key (2) or the RADIUS information. Please note that, the RADIUS configuration may also be used in the VAP by selecting the WPA2-AUTO-EAP. 

      Image

                    Image


    Performance Tweak

    • Implementations using the 2.4 GHz radio is often challenging as 2.4 GHz is a common frequency used by common gadgets (e.g., cordless phones, mobile phones, Microwave). In such cases, it is useful to tweak the radio settings. Fig. 7 is an example of a 2.4GHz radio settings.

      Image

    Settings for a 2.4 GHz/5 GHz implementation. Channels 1,6 and 11 are non-overlapping. In an environment with nearby radios consider experimenting with the channels.

    • Tweaking Wireless | Advanced is often useful.

            Image

    • Advanced Radio Settings:

           Image


    Resolution for SonicOS 6.5

    This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.



    Network Configurations (-Fig. 2)

    1.  Add a Guest zone with security type wireless.
    2. Configure the default WLAN Interface.

      1. Create a VLAN for the Guest Wireless Zone (the IP address of the interface will be static if the firewall distributes the DHCP addresses, EXAMPLE: step C).
      2. Set the Default WLAN in Layer2 Bridges Mode by bridging to the LAN, EXAMPLE: X0
    3. Add a Dynamic DHCP Scope.
       Image
                                                                                           
                                                                                                    Fig. 2. Network configurations for setting up a Guest Wireless.



    Wireless Configurations

    1. Configure the Virtual Access Point (Fig. 3).
    2. Configure Settings (Fig. 4).

      Image
      Fig. 3. Configure Virtual access points (VAP). A VAP enables a single device (e.g., TZ500W or a Sonic Point to support multiple SSIDs with different access profiles (e.g., encryption). Please note that we already have a corporate Wi-Fi profile.


      Image
      Fig. 4. Wireless Settings - Steps A: Access Role, B: Enable WLAN Radio, C: Select Radio Mode (2.4 or 5 GHz), D: Short Guard and Aggregation  E: SSID (if only one SSID is used), F: VAP (if a group of SSID is used).




    • Enable Short Guard Interval : Enabling Short Guard specifies an interval of 400 Nano seconds (ns) as opposed to the standard of 800 ns. This refers to a  pause in transmission intended to avoid data loss from interference or multiple delays.
    • Enable Aggregation : This refers to 802.11n frame aggregation which combines frames to reduce overhead and increases throughput.
    • Enabling Short Guard and Aggregation may improve throughput in environments that have low interference. However, in environments with significant interferences, they are not advisable.


    This should start transmitting the two SSIDs- Corporate and Guest (Fig. 5)

    Image
    Fig. 5. Results of Wireless configuration using the inbuilt Radio on a TZ500W.



    Single SSID

    • As explained above, a wireless capable device (SonicWall Network Appliance or SonicPoint) may be used for supporting a single SSID or multiple SSIDs (as discussed above). For cases one would like to set up the device for a single SSID, the configurations done on the settings page can be done on the Wireless | Security page (Fig. 6).
      Image
      Fig. 6. Settings for a single SSID on Wireless capable appliance (e.g., TZ500W). Based on the Authentication Type (1) WPA2-AUTO-PSK (A) or WPA2-AUTO-EAP (B), one has to update a Preshared Key (2) or the RADIUS information. Please note that, the RADIUS configuration may also be used in the VAP by selecting the WPA2-AUTO-EAP. 

    Performance Tweak

    • Implementations using the 2.4 GHz radio is often challenging as 2.4 GHz is a common frequency used by common gadgets (e.g., cordless phones, mobile phones, Microwave). In such cases, it is useful to tweak the radio settings. Fig. 7 is an example of a 2.4GHz radio settings.
      Image
      Fig. 7. Settings for a 2.4 GHz implementation. Channels 1,6 and 11 are non-overlapping. In an environment with nearby radios consider experimenting with the channels.

    • Tweaking Wireless | Advanced is often useful. Fig. 8 summarizes key features.
      Image
        Fig. 8. Wireless Advanced settings for performance tweaking.

    Related Articles

    • ‘Error sending one-time password’ encountered when connecting to NetExtender
    • Supported SonicWall and 3rd party SFP and SFP+ modules that can be used with SonicWall NSsp series
    • Supported SonicWall and 3rd party SFP and SFP+ modules that can be used with SonicWall NSA series

    Categories

    • Firewalls > TZ Series

    Not Finding Your Answers?

    ASK THE COMMUNITY

    Was This Article Helpful?

    YESNO

    Article Helpful Form

    Article Not Helpful Form

    Company
    • Careers
    • News
    • Leadership
    • Awards
    • Press Kit
    • Contact Us
    Popular resources
    • Communities
    • Blog
    • SonicWall Capture Labs

    Stay In Touch

    • By submitting this form, you agree to our Terms of Use and acknowledge our Privacy Statement. You can unsubscribe at any time from the Preference Center.
    • This field is for validation purposes and should be left unchanged.
    • Facebook
    • Twitter
    • Linkedin
    • Youtube
    • Instagram

    © 2022 SonicWall. All Rights Reserved.

    • Legal
    • Privacy
    • English
    Scroll to top
    Trace:957d8e7b1ca3887eccd6a78a7ba67e6e-76