PROJECT #03 | Wireless & Network Security
Enterprise Wireless Security Lab — 802.1X + FortiGate NGFW + Cisco WLC
Full enterprise wireless security simulation built in EVE-NG featuring 802.1X RADIUS authentication via Windows NPS, dual-SSID Cisco WLC deployment (Employees WPA2 + Guests Web-Auth), FortiGate NGFW zone-based policies with AV/IPS/Web filtering, DHCP Snooping, and Dynamic ARP Inspection. Guest traffic is fully isolated from the employee LAN.
EVE-NG
FortiOS 7.x
Cisco WLC
802.1X / RADIUS
Windows NPS
Active Directory
DHCP Snooping
Dynamic ARP Inspection
WPA2-Enterprise
Web-Auth (Guest)
Lab Topology
FW-01 (FortiGate) → SW-CORE (Cisco) → WLC-01 + AD-NPS-01 + CLIENT-01 | VLANs: 10 (Employees) · 20 (Guests) · 99 (Mgmt)
Lab Objectives
802.1X RADIUS Authentication
Authenticate wireless employees via Windows NPS as RADIUS server integrated with Active Directory — WPA2-Enterprise.
Dual-SSID Wireless Deployment
Cisco WLC with two SSIDs: Employees (WPA2 + 802.1X) and Guests (Web-Auth Captive Portal) on separate VLANs.
FortiGate Zone-Based Policies
Guest Zone isolated from LAN-TRUNK, Captive Portal for guests, AV + IPS + Web Filtering on employee traffic.
Layer 2 Security Hardening
DHCP Snooping + Dynamic ARP Inspection on VLANs 10, 20, 99 at the core switch to prevent ARP spoofing attacks.
Lab Screenshots
Cisco WLC — Dual SSID ConfigurationEmployees (WPA2-Enterprise) & Guests (Web-Auth) · Both Enabled
Windows NPS — 802.1X Network PolicyEmployees-802.1x policy · Grant Access · RADIUS authentication
Active Directory — User Accounttestuser@lab4.local · Domain: LAB4 · Password never expires
FortiGate — Zone-Based Firewall PoliciesDENY-GUEST-TO-EMP · GUEST-TO-WAN (NAT+AV) · EMP-TO-WAN (AV+IPS)
SW-CORE — Layer 2 Security ConfigDHCP Snooping + Dynamic ARP Inspection · VLANs 10, 20, 99
Client Connectivity VerificationSuccessful ping to 10.99.99.1 · TTL=255 · avg 4-5ms · Zero packet loss
Skills Demonstrated
802.1X / EAP Authentication
Cisco WLC Configuration
WPA2-Enterprise Deployment
Web-Auth Captive Portal
Windows NPS (RADIUS)
Active Directory Integration
FortiGate Zone Policies
Guest Network Isolation
DHCP Snooping
Dynamic ARP Inspection
VLAN Segmentation
AV + IPS + Web Filtering
EVE-NG Simulation
UTM Security Profiles