In my opinion the best deployment model is to create an individual Hotspot at each broadcast domain barrier, and use central authentication (RADIUS) as well as central login pages (allow that server in walled garden, use meta refresh redirects in the HTML on the router itself to point to the external server). Creating larger broadcast domains is bad practice, and Hotspots work best at the broadcast domain barrier.
Thanks fewi,
I believe my plan is as sort of inline with your layout, without making it too complex. So, I guess I may have confused the issue by thinking one needs to create one big subnet. Not really, to my understanding what needs to be done per your suggestion.
To connect each individual hotspot to the central authentication (radius) via EoIP, one would avoid making this one large subnet. Simply interconnect the IP's with EoIP? or?
So, creating large broadcast domains bad practice? Unnecessary traffic? Unsecure? Less manageable?
And, so is there any real need to create a secure tunnel between the Hotspots and Central Radius?
You recommend "https" on each hotspot?
Thanks