Public kiosk tablets at the clerk’s office will use a guest-style SSID. Why must that SSID avoid the staff RADIUS realm?
Select an answer to reveal the explanation.
Short Explanation
Don’t let lobby kiosks check in at the employee RADIUS desk. Separate guest/kiosk auth so staff passwords and policies don’t leak into public devices—and never ‘fixnet the enable secret’ as Wi-Fi auth.
Full Explanation
Public kiosk and guest SSIDs should use authentication domains separate from staff Enterprise RADIUS realms. Mixing them risks credential phishing, unintended authorization, and policy bleed. Controller enable passwords and Telnet are unrelated and unsafe substitutes for proper guest AAA separation.