Overview
The Primary WLAN
In addition to the LAN and DMZ networks, you can define a wireless internal network
called the primary WLAN (wireless LAN) network. The primary WLAN is the main
wireless network, and it controls all other wireless network's statuses: wireless networks
can be enabled only if the primary WLAN is enabled, and disabling the primary WLAN
automatically disables all other wireless network. In addition, all wireless networks inherit
certain settings from the primary WLAN.
You can configure the primary WLAN in either of the following ways:
•
Wireless Configuration Wizard. Guides you through the primary WLAN setup,
step by step.
See Using the Wireless Configuration Wizard on page 273.
•
Manual configuration. Offers advanced setup options for the primary WLAN.
See Manually Configuring a WLAN on page 280.
Virtual Access Points
The UTM-1 appliance enables you to partition the primary WLAN into virtual access
points (VAPs). A VAP is a logical wireless network behind the UTM-1 appliance and is a
type of VLAN (see Configuring VLANs on page 179). Like other types of VLANs, VAPs
are isolated from each other and can have separate security policies, IP network segments,
and Traffic Shaper settings. This enables you to configure separate policies for different
groups of wireless users.
For example, you could assign different permissions to employees and guests using your
company's wireless network, by defining two VAPs called "Guest" and "Employee". The
Guest VAP would use simple WPA-Personal encryption, and the security policy would
mandate that stations connected to this network can access the Internet, but not sensitive
company resources. You could configure Traffic Shaper bandwidth management to give
stations in the Guest network a low priority, and by enabling Secure HotSpot on this
network, you could define terms of use that the guest users must accept before accessing
the Internet. In contrast, the Employee VAP would use the more secure WPA2-Enterprise
266
Check Point UTM-1 Edge User Guide
Need help?
Do you have a question about the UTM-1 Edge and is the answer not in the manual?