I am asked to design a Guest Wifi architecture for spokes with some basic requirements:
- Guest Wifi user should have access to Internet only
- A single Guest Wifi subnet should be used for all 600+ sites
However, the splash page should be stored in an internal server which is located in the Data Center / hub. This splash page will not be reachable via Internet.
From my understanding, if the splash page is only reachable from AutoVPN tunnel, I guess that the Guest Wifi VLAN / subnet of each spoke should be advertise to the hub => so we cannot use single Guest Wifi subnet but we should have 1 subnet per spoke and things get more complicated.
Am I correct? Is there any way to meet the requirement? Thanks for your advice.