Ejercicio: Red Inalámbrica
Quinta parte de la serie. La red cableada del edificio ya es redundante y segura. Ahora añade acceso inalámbrico: una WLAN corporativa para los equipos de Sistemas y una WLAN para invitados aislada en su propia VLAN.
graph LR
L[Laptop] -.->|"Oficina-WiFi (VLAN 20)"| AP
G[Cliente invitado] -.->|"Invitados (VLAN 30)"| AP
AP[AP1] ---|trunk| SW1[SW1]
SW1 --- R1[R1 / R2]
Requisitos
Section titled “Requisitos”- Red del ejercicio anterior: VLANs 10, 20 y 99, switches redundantes y HSRP.
- Un AP autónomo conectado por un puerto trunk de SW1.
- Nuevo segmento VLAN 30 - Invitados (192.168.30.0/24), sin acceso a la red interna.
Objetivos
Section titled “Objetivos”- Crear la VLAN 30 (Invitados) y extenderla al router.
- Configurar dos SSIDs:
Oficina-WiFi(VLAN 20) yInvitados(VLAN 30). - Proteger las WLANs con WPA2/WPA3.
- Verificar la asociación de un cliente y su segmentación.
1. VLAN de invitados en los switches y el router
Section titled “1. VLAN de invitados en los switches y el router”SW1(config)# vlan 30SW1(config-vlan)# name InvitadosSW1(config-vlan)# exitSW1(config)# interface GigabitEthernet0/24SW1(config-if)# switchport mode trunkSW1(config-if)# switchport trunk allowed vlan 10,20,30,99En el router, crea la subinterfaz y el grupo HSRP de la VLAN 30 (en R1 y R2, con el mismo procedimiento que viste en el Módulo 6):
R1(config)# interface GigabitEthernet0/0.30R1(config-subif)# encapsulation dot1q 30R1(config-subif)# ip address 192.168.30.1 255.255.255.0R1(config-subif)# standby 30 ip 192.168.30.254R1(config-subif)# standby 30 priority 150R1(config-subif)# standby 30 preempt2. SSIDs en el AP autónomo
Section titled “2. SSIDs en el AP autónomo”AP1(config)# dot11 ssid Oficina-WiFiAP1(config-ssid)# authentication openAP1(config-ssid)# mbssid guest-modeAP1(config-ssid)# exit
AP1(config)# dot11 ssid InvitadosAP1(config-ssid)# authentication openAP1(config-ssid)# mbssid guest-modeAP1(config-ssid)# exit
AP1(config)# interface Dot11Radio0AP1(config-if)# ssid Oficina-WiFiAP1(config-if)# ssid InvitadosAP1(config-if)# station-role root3. Seguridad WPA2/WPA3 (PSK)
Section titled “3. Seguridad WPA2/WPA3 (PSK)”En los WLC o en el AP por GUI, cada SSID lleva su clave:
| SSID | Seguridad | VLAN | Clave (ejemplo) |
|---|---|---|---|
| Oficina-WiFi | WPA2/WPA3 (AES) | 20 | ClaveOficina! |
| Invitados | WPA2 (AES) | 30 | ClaveGuest! |
En la CLI del WLC sería, por ejemplo:
config wlan security wpa akm psk set-key ascii ClaveOficina! 1yconfig wlan interface 1 vlan-20.
4. Aislamiento de invitados
Section titled “4. Aislamiento de invitados”Para que los invitados no alcancen la red interna, restringe en el router el tráfico entre la VLAN 30 y las VLANs 10/20. Eso se hace con ACLs, que verás en detalle en el Módulo 8; aquí lo dejas anotado para aplicarlo al final:
R1(config)# access-list 101 deny ip 192.168.30.0 0.0.0.255 192.168.0.0 0.0.255.255R1(config)# access-list 101 permit ip any anyR1(config)# interface GigabitEthernet0/0.30R1(config-subif)# ip access-group 101 inVerificación
Section titled “Verificación”En el WLC (o show dot11 associations en el AP autónomo):
(Cisco Controller) > show wlan summaryWLAN ID WLAN Profile Name / SSID Status------- ------------------------------ -------1 Oficina-WiFi / Oficina-WiFi ENABLED2 Invitados / Invitados ENABLED
(Cisco Controller) > show client summaryMAC Address AP Name WLAN State IP Address----------- ------------------- ---- ----- ------------aaaa.bbbb.cccc AP-CORREDOR-01 1 Assoc 192.168.20.42Prueba desde un cliente de Oficina-WiFi:
Laptop# ping 192.168.10.10 # hacia Ventas (VLAN 10): debe responderLaptop# ping 192.168.30.50 # hacia un invitado: queda bloqueado por ACLComprobación final
Section titled “Comprobación final”| Pregunta | Respuesta esperada |
|---|---|
| ¿El AP emite los dos SSIDs? | Sí, Oficina-WiFi y Invitados |
| ¿Cliente corporativo en VLAN 20? | Sí, con IP 192.168.20.x |
| ¿Cliente invitado en VLAN 30? | Sí, con IP 192.168.30.x |
| ¿Invitados acceden a la red interna? | No (bloqueado por ACL) |
Resumen
Section titled “Resumen”- Se añadió el acceso inalámbrico con dos SSIDs: corporativo (VLAN 20) e invitados (VLAN 30).
- Cada WLAN usa WPA2/WPA3 y queda mapeada a su VLAN.
- Los invitados quedan aislados de la red interna mediante una ACL.
En el Módulo 8 terminarás el edificio con los servicios IP: DHCP automático, salida a internet con NAT/PAT y las ACLs.