Configuration Roadmap - Colubris Networks CN3000 Administrator's Manual

Table of Contents

Advertisement

Chapter 4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Scenarios - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Chapter 4
All CN300s have identical configurations as follows:
• Downstream port mapped to VLAN 60. This means that all traffic with no VLAN
• Two SSIDs are defined:
Configuration
Install the CN3000
roadmap
1. Install the CN3000 as described in
2. Connect the Internet port to the broadband modem and then restart it.
3. Start the management tool.
Configure the wireless network
Wireless > Neighborhood
Open this page to see if there are other access points operating in your area and make
a note of their operating frequencies.
Wireless > Wi-Fi
1. Set the Operating frequency to a channel that does not overlap an existing access
2. Use the default settings for all other parameters.
Configure the Internet port
Network > Ports > Internet port
1. Select the addressing option supported by your ISP and click Configure.
2. Define all settings as required.
Enable the firewall
Security > Firewall
Select the Preset firewall with Security level set to High.
Create a RADIUS profile
Security > RADIUS
1. Click Add New Profile.
2. In the Profile name box, assign RADIUS Profile 1 to the new profile.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 91 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
assigned will be sent on VLAN 60 by default. Note that all management traffic from the
CN300s will use this VLAN and therefore be sent to the CN3000.
• Public: This SSID is used by guests who login with their web browsers via the
CN3000's public access interface. Guest accounts are stored on the corporate
RADIUS server. No VLAN is assigned to this SSID so all traffic is assigned to VLAN
60 and is directed to the CN3000.
• Private: This SSID is used by employees to securely access the corporate intranet.
WPA is enabled on this SSID and it is mapped to VLAN 70. This permits employees
to reach the corporate RADIUS server for their logins to be validated. Once
authenticated, the RADIUS server assigns the employee with a new VLAN based on
settings in the employees RADIUS account. This enables employees to be assigned
to VLAN 51, 52, or 53 according to their needs.
(page 214)
point. See
"Configuring overlapping wireless cells" on page 31
(page 253)
(page
Chapter 3.
(page 225)
(page 228)
250
and 251)
for details.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents