What are the five required results in this case?
The fictional Northbank network needs guest internet access, staff report access and management-workstation access to AP administration. Guests must be refused access to both reports and AP administration. Write those five outcomes before choosing the settings.
Staff use individual authentication in the selected enterprise design. A guest connecting to Wi-Fi is not automatically authorised to use internal reports. An administrator’s management request also has a different target from an ordinary staff report request.
The supplied logs show guests reaching both internal targets through a broad LAN rule. The observed problem is that permitted path. Renaming the guest network would not repair it.
Does a separate SSID prove that guests are isolated?
A separate SSID identifies a wireless network name; the actual forwarding and policy configuration determines which destinations its clients can reach. Check the segment assignment and enforced boundaries, then test them.
Our lab uses a stated default-deny design. Remove the broad guest-to-LAN permit and keep narrow rules for guest web access, staff reports and the management source. The exact configuration screens and evaluation order of a real product need its own documentation.
NIST’s WLAN security guidance provides a general security-management foundation. Its 2012 publication date means it should not be used as a current list of wireless feature support or modern product defaults.
How do authentication and network boundaries work together?
Authentication establishes the accepted identity or credential evidence; boundaries and application permissions restrict the allowed destinations and actions. They solve related parts of the task.
Individual staff authentication supports accountable assignments. It does not eliminate the need for appropriate report permissions. A guest network can offer internet access while preventing an internal path, provided the actual rules enforce that design.
Trace each request from client to its destination using the network controls guide. Keep the AP’s administrative interface separate from the application service you want staff to use.
Which connection tests should I record?
Record all five required outcomes from the intended client segments. Successful guest internet access alone would leave two important prohibited paths untested. Successful management access from a staff laptop would not prove the intended restriction.
Use the permissions table to write the expected result, and the response sheet to record the fresh observed request. For an allowed result, identify the narrow rule and target that permit it. For a refusal, check that the refusal occurred at the expected control rather than through an unrelated broken connection.
How can I change the case to check my understanding?
Change one legitimate requirement, then revise the relevant path and tests. For example, a guest needs a public training portal but still no internal reports. Add the narrow intended path and verify that the two internal refusals remain intact.
Do not treat a failed TLS identity check as evidence that the segmentation rule is wrong. Use the broken-connection case to separate a boundary failure from a later secure-service failure. An effective repair addresses the failed stage and preserves the protections that are still required.

