Configuring A Network To Use Wpa2-Enterprise And Dynamic Vlans; Figure 438: Wpa2-Enterprise And Dynamic Vlan Assignment; Table 388: Vap Summary - D-Link DWL-8600AP User Manual

Dws-4000 series access points
Hide thumbs Also See for DWL-8600AP:
Table of Contents

Advertisement

D-Link UWS User Manual
Configuring a Network to Use WPA2-Enterprise and Dynamic
VLANs
This configuration example shows a company deploying a wireless network that uses WPA2-Enterprise
encryption and dynamic VLANs. To keep financial information separate from other corporate data, the
network administrator has configured a separate VLAN for Accounting Department employees. Because some
individuals may be granted access to the Accounting VLAN for a short period, the administrator decides to use
user-based granular control over VLAN assignments. The administrator controls access to the accounting VLAN
by using a RADIUS server and Dynamic VLAN assignment.
This example includes two wireless networks (VAPs):
• The Visitor network provides Internet access to guests. Guests who connect to the the Visitor network are
assigned to VLAN 10, which provides limited access to network resources.
• The Corporate network is for employees. An employee who connects to this network must be
authenticated by a network RADIUS server. By default, users on this network are assigned to VLAN 20.
However, when an Accounting Department user authenticates to the Corporate network, the user is
assigned to VLAN 30. The VLAN assignment in the RADIUS profile for an Accounting Department
employee takes precedence over the default VLAN of the VAP.
Table 388
shows a summary of the VAP configuration in this example.
Network (SSID)
Visitor
Corporate
In
Figure
438, when Client_1 initiates a connection to the Corporate network, the authentication information
is passed from the client to the AP, and from the AP to the switch. Then, the switch forwards the information
to the RADIUS server. If the authentication is successful, the RADIUS server response includes the VLAN
assignment information This example includes only one AP, but the configuration is easily scalable to multiple
APs.
Client_1
48:60:BC:76:79:3E

Figure 438: WPA2-Enterprise and Dynamic VLAN Assignment

This example requires configuring settings on the RADIUS server and on the switch.
D-Link
Oct. 2015

Table 388: VAP Summary

VLAN
Security
10
None
20
WPA Enterprise
AP_1
10.27.65.178
1C:AF:F7:1F:27:40
Configuring a Network to Use WPA2-Enterprise and Dynamic
Redirect
http://www.dlink.com/tw
None
Switch_1
10.27.65.79
Unified Wired and Wireless Access System
VLANs
Radius_1
10.27.65.120
Page 706

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents