SonicOS 7.0 Objects

Configuring a Zone for Guest Access

You cannot configure guest access for an Untrusted, Encrypted, SSL VPN, or Management zone.

SonicWall user Guest Services provide an easy solution for creating wired and wireless guest passes and/or locked-down Internet-only network access for visitors or untrusted network nodes. This functionality can be extended to wireless or wired users on the WLAN, LAN, DMZ, public, or semi-public zone of your choice.

To configure Guest Services

  1. Navigate to OBJECT | Match Objects > Zones.
  2. Hover over the zone in the Zones table and click the Edit icon to add Guest Services.
  3. Click the Guest Services tab.

    By the default, all the options are disabled for Guest Services.

  4. Enable Guest Services to make the guest services options available for selection.
  5. Set the toggle keys and configuration for Guest Services as follows.

    Enable inter-guest communication Allows guests to communicate directly with other users who are connected to this zone.
    Enable External Guest Authentication

    Requires guests connecting from the device or network you select to authenticate before gaining access. Selecting this option makes Configure available.

    When Enable External Guest Authentication is selected, the following options become unavailable:

    • Enable Captive Portal Authentication
    • Enable Policy Page without authentication
    • Custom Authentication Page
    Enable Captive Portal Authentication

    This option is available only in Classic Mode. You can enable this option only when Enable External Guest Authentication option is disabled.

    Allows you to create a customized login page with RADIUS authentication. Selecting this option makes Configure available.

    For more information about configuring Enable Captive Portal Authentication, refer to the Configuring a Zone for Captive Portal Authentication with RADIUS.

    Enable Policy Page without authentication is unavailable for Enable Captive Portal Authentication.

    Enable Policy Page without authentication

    Directs users to a guest services usage policy page when they first connect to a SonicPoint or SonicWave in the WLAN zone. Guest users are authenticated by accepting the policy instead of providing a user name and password. Selecting this option makes Configure available.

    Click Configure to set up a HTML customizable policy usage page. For more information, refer to the Configuring a Zone for Customized Policy Message.

    When you Enable Policy Page without authentication option, Enable Captive Portal Authentication option gets disabled automatically.

    Custom Authentication Page

    Redirects users to a custom authentication page when they first connect to the network. Selecting this option makes Configure available.

    Click Configure to set up a custom authentication page. For more information, refer to the Configuring a Zone for Customized Login Page.

    Enable Post Authentication Page Directs users to the specified page immediately after successful authentication. Selecting this option makes Post Authentication Page field available.
    Post Authentication Page Enter a URL for the post-authentication page.
    Bypass Guest Authentication

    Allows the Guest Services feature to integrate into environments already using some form of user-level authentication. This feature automates the authentication process, allowing wireless users unrestricted wireless Guest Services without requiring authentication.

    When Bypass Guest Authentication is enabled, drop-down menu becomes available:

    • All MAC Addresses (default)
    • An Address Object
    • An Address Group
    • Create new MAC object
    • Create new MAC object group

    This feature should only be used when unrestricted Guest Service access is desired or when another device upstream is enforcing authentication.

    Redirect SMTP traffic to

    Redirects incoming SMTP traffic on this zone to a SMTP server you specify. When Redirect SMTP traffic to is enabled, drop-down menu becomes available:

    • An Address Object
    • Create new address object
    Deny Networks

    Blocks traffic to the selected networks. When Deny Networks is enabled, drop-down menu becomes available

    • An Address Object
    • An Address Object group
    • Create new address object
    • Create new address object group
    Pass Networks

    Allows traffic through the Guest Service-enabled zone to the selected networks automatically. When Pass Networks is enabled, drop-down menu becomes available:

    • An Address Object
    • An Address Object group
    • Create new address object
    • Create new address object group
    Max Guests Specifies the maximum number of guest users allowed to connect to this zone. The minimum number is 1, the maximum number is 4500, and the default number is 10.
    Wireless Zone Guest Services Options Displays only for the WLAN zone or for a custom zone with a Security Type of Wireless.
    Enable Dynamic Address Translation Grants access to non-DHCP guests.
  6. Click Save to apply these settings to this zone.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden