Author: Michael Chileshe
A multi-floor enterprise wireless network with VLAN-segmented corporate and guest SSIDs, DHCP, ACL-based guest isolation, and subnet sizing designed for 500+ concurrent users. Built in Cisco Packet Tracer.
- Deploy access points across 3 floors, each broadcasting a corporate SSID (VLAN 20) and a guest SSID (VLAN 30)
- Size the corporate subnet to handle 500+ simultaneous wireless users (/22 = 1,022 hosts)
- Provide centralized DHCP from the core router for all wireless clients
- Isolate guest wireless traffic from the corporate network and server VLAN using ACLs — guests get internet-only access
- Prove connectivity: corporate clients reach the server, guest clients are blocked from internal resources
Packet Tracer simulates wireless at a functional level — APs associate clients, SSIDs work, WPA2-PSK works — but it doesn't simulate RF planning, channel management, or roaming. This lab proves the network architecture (VLAN segmentation, DHCP scoping, ACL isolation) that sits behind a real wireless deployment. The 500+ user scale is reflected in the IP/VLAN design rather than in actually placing 500 devices in PT.
In PT, each Access Point supports one SSID per radio. To simulate two SSIDs (CORP + GUEST) per floor, each floor uses two APs — one for each SSID. A real enterprise would use a single multi-SSID AP or a WLC-managed lightweight AP; the two-AP-per-floor approach achieves the same VLAN separation in PT's simulator.
enterprise-wireless/
├── README.md
├── .gitignore
├── docs/
│ ├── ip-addressing.md
├── configs/
│ ├── CORE-RTR.txt
│ └── DIST-SW.txt
└── topology/
└── (.pkt file)
- All APs visible and associated with wireless clients
- Corporate laptops receive DHCP in the 10.10.20.0/22 range
- Guest laptops receive DHCP in the 10.10.30.0/23 range
- Corporate laptop can ping the server (10.10.40.10)
- Guest laptop is BLOCKED from pinging the server (ACL deny)
- Guest laptop CAN ping the core router's own address (proves connectivity exists, just restricted)
- Corporate laptop can ping a guest laptop (cross-VLAN routing works, ACL only restricts guest-initiated traffic to server VLAN)