SMC Networks EliteConnect SMCE21011 User Manual page 61

802.11b/g/n ap
Hide thumbs Also See for EliteConnect SMCE21011:
Table of Contents

Advertisement

The management VLAN is for managing the access point through
remote management tools, such as the web interface, SSH, SNMP, or
Telnet. The access point only accepts management traffic that is tagged
with the specified management VLAN ID.
All wireless clients associated to the access point are assigned to a
VLAN. If IEEE 802.1X is being used to authenticate wireless clients,
specific VLAN IDs can be configured on the RADIUS server to be
assigned to each client. If a client is not assigned to a specific VLAN or
if 802.1X is not used, the client is assigned to the default VLAN for the
VAP interface with which it is associated. The access point only allows
traffic tagged with assigned VLAN IDs or default VLAN IDs to access
clients associated on each VAP interface.
When VLAN support is enabled on the access point, traffic passed to the
wired network is tagged with the appropriate VLAN ID, either an
assigned client VLAN ID, default VLAN ID, or the management VLAN ID.
Traffic received from the wired network must also be tagged with one of
these known VLAN IDs. Received traffic that has an unknown VLAN ID
or no VLAN tag is dropped.
When VLAN support is disabled, the access point does not tag traffic
passed to the wired network and ignores the VLAN tags on any received
frames.
Before enabling VLAN tagging on the access point, be sure to
N
:
OTE
configure the attached network switch port to support tagged VLAN frames
from the access point's management VLAN ID, default VLAN IDs, and other
client VLAN IDs. Otherwise, connectivity to the access point will be lost
when you enable the VLAN feature.
Using IEEE 802.1X and a central RADIUS server, up to 64 VLAN IDs can be
mapped to specific wireless clients, allowing users to remain within the
same VLAN as they move around a campus site. This feature can also be
used to control access to network resources from clients, thereby
improving security.
A VLAN ID (1-4094) can be assigned to a client after successful IEEE
802.1X authentication. The client VLAN IDs must be configured on the
RADIUS server for each user authorized to access the network. If a client
does not have a configured VLAN ID on the RADIUS server, the access
point assigns the client to the configured default VLAN ID for the VAP
interface.
When using IEEE 802.1X to dynamically assign VLAN IDs, the access
N
:
OTE
point must have 802.1X authentication enabled and a RADIUS server
configured. Wireless clients must also support 802.1X client software.
– 61 –
| System Settings
C
5
HAPTER
VLAN Configuration

Advertisement

Table of Contents
loading

Table of Contents