13 Replies Latest reply: Jan 21, 2014 6:59 PM by banyanfinn Branched to a new discussion.
l008com Level 1 Level 1 (35 points)

I'm wondering if you can use the Guest wifi network feature on an Airport Extreme that is in bridged mode. When I say bridged mode, I do NOT mean "extending" a wireless network (like many threads with a smiliar title seem to mean). What I mean is that I have a single Airport Extreme. I want to use it as a wireless access point, while continue to use my ISP's modem/router combo as the DHCP provider. The ISP box will have no wifi enabled. The Airport will connect to that box (via a large switch) and be convfigured as a bridge, instead of "distributing IP addresses" itself.


I know that in this setup, a regular wireless network is not a problem. But I've never tried a regular and a guest network together, while in bridged mode. I'm hoping this is do-able, because I don't think the DHCP in the ISP box can be turned off. Plus we only planned for a single ethernet cable going up a floor to where this airport is going to live. If it is going to be the DHCP provider too, then there would have to be a second ethernet cable, so the airport can logically be between the ISP box and the switch.

  • Bob Timmons Level 10 Level 10 (91,840 points)

    I'm wondering if you can use the Guest wifi network feature on an Airport Extreme that is in bridged mode.

    Sorry, but no. The AIrPort Extreme will have to be in router mode providing DHCP and NAT services if you want it to create both a "main" and "guest" network.

  • l008com Level 1 Level 1 (35 points)

    So as it turns out, you can use the guest network feature while the airport is in bridged mode. I just unwrapped the one I bought for this job and tested it out by piggy backing it into my wired network and putting it in bridged mode. I was able to create a primary and a guest network.

  • Bob Timmons Level 10 Level 10 (91,840 points)

    Tried this with 3 different 3rd party routers, but no go.


    If you have another Apple router on the wired network that is set up with the Guest Network, then you can add a second AirPort and the guest network will work in Bridge Mode.


    Might that be the case?


    If not, have you tested to verify that you can get an Internet connection on the Guest Network?

  • l008com Level 1 Level 1 (35 points)

    Turns out you can connect to both networks, but you only get an IP over the private network. Public just gives you a self-assigned IP. That is particularly annoying. Even running DHCP only for the guest network would be an OK option. But we can't double-nat the primary network, and the comcst modem has a router built in that I don't think you can disable.

  • Bob Timmons Level 10 Level 10 (91,840 points)

    As I mentioned previously, the AirPort must be in a Router Mode of DHCP and NAT to enable the Guest Network feature....and have both the "main" "guest" networks operate correctly with Internet access.


    You might check with your ISP about the possibility of obtaining a simple modem.

  • l008com Level 1 Level 1 (35 points)

    Yeah that's the plan. Everything with comcast is a pain in the *** but hopefully I can just buy a modem and have then enable it over the phone. I've done things that way before but this is a business account and they like to do things differently just to mess with people with business accounts.

  • Bob Timmons Level 10 Level 10 (91,840 points)

    Please post back when you get the new modem that should get you in business.


    Most ISPs will activate a new modem over the phone if you have the MAC Address of the modem, which should be clearly marked on the back or bottom of the device.


    Good luck!

  • dennypage Level 1 Level 1 (0 points)

    Yes, you can have both private and guest in bridged mode.


    The reason that a DHCP address is not received on the guest network is because packets originating on the guest network are 802.1Q tagged as vlan 1003. In order for your firewall/dhcp server to process these packets, you will need to add a virtual interface for that vlan.

  • nrh Level 1 Level 1 (10 points)

    thanks for the pointer dennypage.

    Are you referring to Airport Express Base or do other Wi-Fi routers use VLANs like this?

  • dennypage Level 1 Level 1 (0 points)

    I was referring to the Aiport Extreme. I don't know if the Express works the same way or not.


    Wi-Fi access points that have the capability to host multiple SSIDs often have VLAN as a configuration option. But most retail access points designed for home use do not.

  • name99 Level 1 Level 1 (5 points)

    This is a valuable answer because it clarifies the one piece of the puzzle as to how this might (or might not) work.


    It is obvious that a device connecting to the base station informs the base station as to whether it is on the guest or private network through the SSID it connects to. It's obvious how one can create two overlaid networks through using two different (non-routable) IP address ranges. It's obvious how the base station --- AS DHCP and NAT HOST --- can allocate addresses in these two ranges.


    What was not obvious is how this can all propagate out to a third party DHCP server --- how would that server know to allocate IP addresses in one range rather than the other?

    But use of a VLAN tag answers that question. Very cute use of a (to home users) rather obscure part of the ethernet spec.

  • LewisO Level 1 Level 1 (0 points)

    Dennypage, you mentioned "you will need to add a virtual interface for that vlan.", where does one set this up? In Airport? or in the device supplying the DHCP, ie. the firewall device?

    Thanks - Lewis

  • banyanfinn Level 1 Level 1 (0 points)

    Oops I posted ths on the wrong thread... can't figure out how to delete my post.