Skip to content

Separate operator and IoT wireless access

Test separate operator and Thing WPA2 admission, DHCP and an IoT Registration Server account as distinct access layers.

Packet Pete, your practice guide

Packet Pete
Predict the reading, then compare it with the measurement.

Cisco Packet Tracer

Desktop lab

Test separate operator and Thing WPA2 admission, DHCP and an IoT Registration Server account as distinct access layers.

Tier 3 · Install required · Cisco account required

Version tested: Cisco Packet Tracer 9.0.1 on Ubuntu 22.04 (Apptainer/Xvfb); byte-identical saved project reopened and exercised 2026-10-09. Date: 2026-10-09.

Install the tool; build from the steps. No file yet.

Download the Packet Tracer file

Need the app? Get Packet Tracer free from Cisco Networking Academy (free NetAcad login required).

Steps

Screens captured against Cisco Packet Tracer Cisco Packet Tracer 9.0.1 on Ubuntu 22.04 (Apptainer/Xvfb); byte-identical saved project reopened and exercised 2026-10-09 on 2026-10-09; the tool may have moved on — the text steps are the contract.

  1. 1 Step 1

    Do
    Open lab.pkt in the Packet Tracer Logical workspace. Locate Home Gateway0, Operator-AP and the 2960 switch. Trace Fan-Actuator to the Home Gateway dotted link. Trace Operator-Laptop to the separate AP dotted link.
    You will see
    Home Gateway0 and Operator-AP have separate device icons. The Home Gateway has a dotted link to Fan-Actuator. Operator-AP has a dotted link to Operator-Laptop. Both access devices have green wired links to SW-Remote.
    Why it matters
    The two wireless entry points represent distinct roles. A dotted line establishes current simulated radio association. The wired switch provides the shared service-side path. The topology alone does not establish traffic isolation.
    Real Packet Tracer topology showing the Home Gateway and separate Operator-AP with their wireless clients.
    Step 1 · Cisco Packet Tracer; numbered callout added to a real capture. Enlarge screenshot (new tab)
  2. 2 Step 2

    Do
    Open Operator-AP Config tab, then Port 1 panel. Read the SSID and selected authentication mode. Check that Port Status is On and encryption is AES. Compare its role with the Home Gateway in the next step.
    You will see
    Port 1 is On and the SSID field reads OperatorNet. WPA2-PSK is selected in the authentication group. The PSK Pass Phrase field contains an exercise key. Encryption Type reads AES.
    Why it matters
    This access point admits the operator laptop by one credential. WPA2-PSK here is a shared-key teaching configuration. A correct key is a radio admission check, not a service permit. The IoT Thing uses a different network identity.
    Real Operator-AP Port 1 panel showing OperatorNet, WPA2-PSK, and AES.
    Step 2 · Cisco Packet Tracer; numbered callout added to a real capture. Enlarge screenshot (new tab)
  3. 3 Step 3

    Do
    Open Home Gateway0, then Config and Wireless. Read its SSID and selected authentication mode. Check the PSK field and encryption mode. Compare these settings with Operator-AP Port 1.
    You will see
    The gateway Wireless SSID reads HomeGateway. WPA2-PSK is selected for authentication. The PSK Pass Phrase is different from Operator-AP. Encryption Type reads AES.
    Why it matters
    The Thing and operator use separate wireless credentials. A stolen operator key should not be the Thing key in this model. The two SSIDs still bridge into the same exercise LAN. Later service checks must not be mistaken for a VLAN boundary.
    Real Home Gateway Wireless panel showing HomeGateway, WPA2-PSK, and AES.
    Step 3 · Cisco Packet Tracer; numbered callout added to a real capture. Enlarge screenshot (new tab)
  4. 4 Step 4

    Do
    Open Fan-Actuator, then Config and Wireless0. Temporarily enter WrongPass2026 as its WPA2-PSK key. Keep the SSID as HomeGateway and Port Status On. Inspect the fan and gateway on the visible canvas.
    You will see
    Wireless0 still names HomeGateway and WPA2-PSK. The PSK field shows WrongPass2026. No dotted association appears between gateway and fan. The other wired devices remain visible on the canvas.
    Why it matters
    The wrong radio credential prevents the shown association. An old grey DHCP field does not prove current reachability. This is admission failure, before an application request. Restore the saved key to return to the intended state.
    Real Fan-Actuator Wireless0 panel with a wrong PSK and no gateway-to-fan dotted link.
    Step 4 · Cisco Packet Tracer; numbered callout added to a real capture. Enlarge screenshot (new tab)
  5. 5 Step 5

    Do
    Replace the fan key in the Wireless0 panel with DevicePass2026. If necessary, toggle Wireless0 Port Status Off and On. Check that the fan-to-gateway dotted association returns. Leave Wireless0 On before continuing.
    You will see
    Wireless0 shows the restored exercise key. The Port Status checkbox is On. A dotted line joins Home Gateway0 and Fan-Actuator. The wired gateway-to-switch path remains up.
    Why it matters
    Restoring the credential restores simulated radio admission. The port reset triggers a fresh association in this PT run. The dotted link is visible evidence of the radio path. The service test still needs IP and account checks.
    Real Fan-Actuator Wireless0 panel with the correct PSK and restored dotted association.
    Step 5 · Cisco Packet Tracer; numbered callout added to a real capture. Enlarge screenshot (new tab)
  6. 6 Step 6

    Do
    Open Operator-Laptop Desktop tab and PC Wireless monitor. Choose Link Information, then More Information. Read the network name, security and current address. Check that the adapter reports an active wireless link.
    You will see
    Wireless Network Name reads OperatorNet. Security reads WPA2-Personal. This run shows IPv4 address 192.168.25.102. The monitor shows signal bars and Adapter is Active.
    Why it matters
    The laptop joined the operator SSID rather than HomeGateway. The monitor supplies an independent association check. Its address shows the client also reached an IP configuration. Lease suffixes can change after reopening the saved file.
    Real Packet Tracer Wireless Network Monitor showing OperatorNet, WPA2-Personal, and a client address.
    Step 6 · Cisco Packet Tracer; numbered callout added to a real capture. Enlarge screenshot (new tab)
  7. 7 Step 7

    Do
    Reopen the byte-identical learner project. Open Operator-Laptop Desktop and IP Configuration. Wait for DHCP request successful on Wireless0. Record the address, mask, gateway and DNS shown now.
    You will see
    The Wireless0 selector and DHCP radio are visible. The status reads DHCP request successful. This reopened run assigned 192.168.25.101/24. Gateway is 192.168.25.1 and DNS is 192.168.25.10.
    Why it matters
    Radio admission and IP configuration are separate checks. The reopened address differs from the prior screenshot. The server path requires a valid local address and DNS. Use current fields, not a remembered suffix, when diagnosing.
    Real reopened Operator-Laptop IP Configuration showing successful DHCP and its current IPv4 fields.
    Step 7 · Cisco Packet Tracer; numbered callout added to a real capture. Enlarge screenshot (new tab)
  8. 8 Step 8

    Do
    In the laptop Web Browser URL field, open http://iot.lab.local. At the Registration Server Login, try a made-up account. Observe the response from the service page. Leave the approved exercise account for the next step.
    You will see
    The PT browser URL ends in /index.php. The page still says Registration Server Login. Red text reads Wrong username or password. The sign-in fields remain available for another attempt.
    Why it matters
    The laptop reached the application over the admitted network. The made-up account did not enter the IoT dashboard. This is a service login rejection, not a packet-drop ACL. A valid wireless key does not grant an IoT Server account.
    Real Packet Tracer browser showing Registration Server rejection of an unapproved account.
    Step 8 · Cisco Packet Tracer; numbered callout added to a real capture. Enlarge screenshot (new tab)
  9. 9 Step 9

    Do
    Use the disposable lab8-demo exercise account. Sign in from Operator-Laptop at iot.lab.local. Find Fan-Actuator in the IoT Server device list. Leave the saved project with both wireless paths restored.
    You will see
    The PT browser URL is http://iot.lab.local/home.html. The page heading reads IoT Server Devices. Fan-Actuator appears with a green status dot. The row identifies it as a Ceiling Fan.
    Why it matters
    The admitted operator can reach the named IoT service. The approved account opens a device list after login. The fan was registered through its distinct wireless path. The lesson proves access layers, not VLAN containment.
    Real reopened Packet Tracer IoT Server page listing Fan-Actuator after approved sign-in.
    Step 9 · Cisco Packet Tracer; numbered callout added to a real capture. Enlarge screenshot (new tab)

Chapter checks

These questions refer to the chapter’s examples. Use the return links to review their answers.

  1. A team wants every deployed sensor to share one Wi-Fi password because it is easy to install. What is the strongest review response?

    Return to the chapter’s knowledge check
  2. A sensor authenticates to Wi-Fi but can contact every internal server. What should the release review require?

    Return to the chapter’s knowledge check

Caution

The disposable PT keys and account are not production credentials. Both SSIDs bridge into one 192.168.25.0/24 LAN; this lab does not enforce VLAN or ACL isolation. The wrong server account proves application rejection, not a network drop. DHCP lease suffixes can change after reopen; wait for a fresh successful lease.

Return to Wi-Fi Security: Access and Segmentation Controls · Browse Labs