In our office we decided to create another wifi ssid, "guest" one, so our visitors can use Internet but have no access to LAN. Simple idea, so to say, and no problem to add another ssid and vlan and nat rule.
The problem is, how can I limit usage of that guest network to fair level, what's the best approach? I can devote (better to say - share) some WAN bandwidth to this network, but I don't want to see, say, torrents running over this gust network (while some visitors can have torrent client running on their notebooks), and I don't want to see any illegal activity from/to this guest network.
I can limit traffic only to 80/443 ports (weird approach), or I can implement transparent http/https proxy (not that good, too), or I can even analyze netflow to check what kind of traffic client used to use.
Any better idea? How did [b]you[/b] implemented guest network?