Wireless segmentation

Give visitors internet access without internal or management access. Staff need individual authentication and report access; only the management workstation may administer the AP.

WORKED REASONING
Remove the broad guest-to-LAN permit in the stated default-deny model. Use separate guest and staff segments with enforced boundary rules. Keep staff individual authentication supported by the selected enterprise wireless design. Restrict AP administration to the management source. Test all five required outcomes. A different SSID alone does not prove isolation; test the actual boundary.

These records and settings are fictional. The rule model is stated for teaching; actual product documentation governs real configurations.
