Enterprise Wireless Security Lab — 802.1X + FortiGate + Cisco WLC

PROJECT #03  |  Wireless & Network Security

Enterprise Wireless Security Lab — 802.1X + FortiGate NGFW + Cisco WLC

Full enterprise wireless security simulation built in EVE-NG featuring 802.1X RADIUS authentication via Windows NPS, dual-SSID Cisco WLC deployment (Employees WPA2 + Guests Web-Auth), FortiGate NGFW zone-based policies with AV/IPS/Web filtering, DHCP Snooping, and Dynamic ARP Inspection. Guest traffic is fully isolated from the employee LAN.

EVE-NG FortiOS 7.x Cisco WLC 802.1X / RADIUS Windows NPS Active Directory DHCP Snooping Dynamic ARP Inspection WPA2-Enterprise Web-Auth (Guest)
🗺️
Lab Topology
Enterprise Wireless Security Lab Topology — EVE-NG
FW-01 (FortiGate) → SW-CORE (Cisco) → WLC-01 + AD-NPS-01 + CLIENT-01  |  VLANs: 10 (Employees) · 20 (Guests) · 99 (Mgmt)
🎯
Lab Objectives
🔒
802.1X RADIUS Authentication
Authenticate wireless employees via Windows NPS as RADIUS server integrated with Active Directory — WPA2-Enterprise.
📶
Dual-SSID Wireless Deployment
Cisco WLC with two SSIDs: Employees (WPA2 + 802.1X) and Guests (Web-Auth Captive Portal) on separate VLANs.
🔥
FortiGate Zone-Based Policies
Guest Zone isolated from LAN-TRUNK, Captive Portal for guests, AV + IPS + Web Filtering on employee traffic.
🛡️
Layer 2 Security Hardening
DHCP Snooping + Dynamic ARP Inspection on VLANs 10, 20, 99 at the core switch to prevent ARP spoofing attacks.
📸
Lab Screenshots
Cisco WLC — Dual SSID: Employees WPA2 + Guests Web-Auth
Cisco WLC — Dual SSID ConfigurationEmployees (WPA2-Enterprise) & Guests (Web-Auth) · Both Enabled
Windows NPS — 802.1X Network Policy for Employees
Windows NPS — 802.1X Network PolicyEmployees-802.1x policy · Grant Access · RADIUS authentication
Active Directory — testuser account in lab4.local domain
Active Directory — User Accounttestuser@lab4.local · Domain: LAB4 · Password never expires
FortiGate Firewall Policies — Guest Zone isolation + Employee to WAN
FortiGate — Zone-Based Firewall PoliciesDENY-GUEST-TO-EMP · GUEST-TO-WAN (NAT+AV) · EMP-TO-WAN (AV+IPS)
SW-CORE — DHCP Snooping + ARP Inspection on VLANs 10, 20, 99
SW-CORE — Layer 2 Security ConfigDHCP Snooping + Dynamic ARP Inspection · VLANs 10, 20, 99
Client ping verification — successful connectivity test
Client Connectivity VerificationSuccessful ping to 10.99.99.1 · TTL=255 · avg 4-5ms · Zero packet loss
🧠
Skills Demonstrated
802.1X / EAP Authentication Cisco WLC Configuration WPA2-Enterprise Deployment Web-Auth Captive Portal Windows NPS (RADIUS) Active Directory Integration FortiGate Zone Policies Guest Network Isolation DHCP Snooping Dynamic ARP Inspection VLAN Segmentation AV + IPS + Web Filtering EVE-NG Simulation UTM Security Profiles