Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Controller based AP Training

CK
April 28, 2016

Controller based AP Training

Introduce how to control the light AP ECW7220-L by Controller EWS4502/4606

CK

April 28, 2016
Tweet

More Decks by CK

Other Decks in Technology

Transcript

  1. Agenda • AC/AP Basic Setup • Switch Configuration • 802.1x/MAC

    Authentication • Captive Portal • Mitigate Wireless Interference and Improve Performance • AC Cluster
  2. Controller-based Product List Model EWS4502 EWS4606 Product Type Wireless Access

    Controller Wireless Access Controller Description - 2 x GE, manage 500 pcs AP - Support 3+1 clustering backup - 6 x GE with 2 x USB, manage 2000pcs AP - Support 3+1 clustering backup Wireless Access Controller Model ECW7220-L Product Type Indoor AP Description 11ac, dual band 3x3 MIMO Controller-based AP
  3. Scenario ECS2100-10P 192.168.1.10 EWS4502 WiFi Controller 192.168.1.1 192.168.1.2 ECW7220L 11ac

    AP 192.168.1.11 Internet Laptop HQ_Staff Vlan 10 Smart Phone HQ_Guest Vlan 20 PVID =1 Vid=10,20 tagged PVID =1 Vid=10,20 tagged PVID =1 Vid=1 untagged DHCP Server 192.168.1.200 PVID =1 Vid=1 untagged PVID =1 Vid=1,10,20 tagged ECS4620-28P/52P GE L3 PoE Switch 192.168.2.1 ECW7220L 11ac AP 192.168.1.11 Laptop HQ_Staff Vlan 30 Smart Phone HQ_Guest Vlan 40 PVID =1 Vid=30,40 tagged PVID =1 Vid=30,40 tagged HQ Branch Office ECS4620-28F GE L3 Fiber Switch 192.168.2.1
  4. HQ Topology ECS2100-10P 192.168.1.10 EWS4502 WiFi Controller 192.168.1.1 192.168.1.2 ECW7220L

    11ac AP 192.168.1.11 Internet Laptop HQ_Staff Vlan 10 Smart Phone HQ_Guest Vlan 20 PVID =1 Vid=10,20 tagged PVID =1 Vid=10,20 tagged PVID =1 Vid=1 untagged DHCP Server 192.168.1.200 PVID =1 Vid=1 untagged PVID =1 Vid=1,10,20 tagged HQ ECS4620-28F GE L3 Fiber Switch 192.168.2.1
  5. Modify Band_plan & Country_code for AP • From AP Console,

    check band plan and country code ECW7220-L-ff68c0# nvram show : band_plan=ETSI : country_code=TR : • Change Band plan & Country code ECW7220-L-ff68c0# nvram set band_plan=FCC ECW7220-L-ff68c0# nvram set country_code=US ECW7220-L-ff68c0# nvram commit ECW7220-L-ff68c0# factory-reset Are you sure you want to reset the system to factory defaults (y/n)? y
  6. L3 Switch Play DHCP Server Role ECS2100-10P 192.168.1.10 EWS4502 WiFi

    Controller 192.168.1.1 192.168.1.2 ECW7220L 11ac AP 192.168.1.11 Internet Laptop HQ_Staff Vlan 10 Smart Phone HQ_Guest Vlan 20 PVID =1 Vid=10,20 tagged PVID =1 Vid=10,20 tagged PVID =1 Vid=1 untagged PVID =1 Vid=1 untagged PVID =1 Vid=1,10,20 tagged HQ ECS4620-28F GE L3 Fiber Switch 192.168.2.1
  7. Configuration of Switch • Create HQ_Staff VLAN & HQ_Guest VLAN

    • Add Port 7 connected to AP VLAN 10, 20 Tagged port • Default VLAN 1 for communication between AP & AC
  8. Configure HQ_Staff VLAN member port • Configure Port 1 VLAN

    10 member port, Wireless client associated to SSID HQ_Staff can communicate with device connected to port 1
  9. Configure HQ_Guest VLAN member port • Configure Port 1 VLAN

    20 member port, Wireless client associated to SSID HQ_Guest can communicate with device connected to port 2
  10. Configure IP Interfaces on L3 Switch • Set IP address

    (default gateway) for 3 VLANs (Subnets), so traffic can be routed from one subnet to the other
  11. Create DHCP Server IP Pool for Management VLAN • Create

    DHCP server IP pool for management VLAN • Exclude the IP range for static IP such as IP of the AC and Switches • AP will be assigned IP address dynamically after configuration auto- provision from AC
  12. Managed AP Obtained IP • AP obtained IP address from

    DHCP Server so will not have IP address conflict with default IP (192.168.1.10)
  13. Create DHCP Server IP Pool for HQ_Staff VLAN • Create

    DHCP Server IP Pool for HQ_Staff VLAN so wireless clients associated to HQ_Staff SSID will obtain IP from corresponding subnet dynamically
  14. Create DHCP Server IP Pool for HQ_Guest VLAN • Create

    DHCP Server IP Pool for HQ_Guest VLAN so wireless clients associated to HQ_Guest SSID will obtain IP from corresponding subnet dynamically
  15. L3 Switch Play DHCP Relay Role ECS2100-10P 192.168.1.10 EWS4502 WiFi

    Controller 192.168.1.1 192.168.1.2 ECW7220L 11ac AP 192.168.1.11 Internet Laptop HQ_Staff Vlan 10 Smart Phone HQ_Guest Vlan 20 PVID =1 Vid=10,20 tagged PVID =1 Vid=10,20 tagged PVID =1 Vid=1 untagged DHCP Server 192.168.1.200 PVID =1 Vid=1 untagged PVID =1 Vid=1,10,20 tagged HQ ECS4620-28F GE L3 Fiber Switch 192.168.2.1
  16. DHCP Relay • If there is a DHCP Server in

    the network, configure L3 for DHCP relay, so clients for all subnet will get IP address from DHCP Server
  17. Branch Office Topology Internet ECS4620-28P/52P GE L3 PoE Switch 192.168.2.1

    ECW7220L 11ac AP 192.168.1.11 Laptop HQ_Staff Vlan 30 Smart Phone HQ_Guest Vlan 40 PVID =1 Vid=30,40 tagged PVID =1 Vid=30,40 tagged Branch Office
  18. Remote Fit AP Configuration • AP default IP mode is

    DHCP, default IP is 192.168.1.10 • Need specify AC IP address if they not at the same network • Remember save configuration
  19. Set Static IP on Remote AP • Disable DHCP mode

    and set static IP and default gateway on AP • Ping default GW and Remote AC to make sure it can be reachable
  20. Captive Portal Topology ECS2100-10P 192.168.1.10 EWS4502 WiFi Controller 192.168.1.1 ECW7220-L

    11ac AP 192.168.1.11 Internet Smart Phone HQ_Guest Vlan 1 PVID =1 Vid=1 untagged PVID =1 Vid=1 untagged PVID =1 Vid=1 untagged DHCP Server 192.168.1.200
  21. WPA/WPA2 Enterprise with 802.1x Authentication AC: • 1. Add RADIUS

    server and Accounting Server • 2. Go to AP profiles, enabled Security with WPA/WPA2 Enterprise
  22. Remote RADIUS MAC Authentication Radius Server: • 1. Create account

    username with client MAC address, password with NOPASSWORD AC: • 1. At WLAN Configuration>Global, set MAC Authentication Mode to white-list • 2. Go to AP Profiles, set MAC Authentication as RADIUS at the VAP
  23. Local MAC Authentication • 1. At WLAN Configuration>Global, set MAC

    Authentication Mode to white-list • 2. At WLAN Configuration>Known Client, add client MAC address and select Authentication Action as Global Action • 3. Go to AP Profiles, set MAC Authentication as Local at VAP
  24. AP Load Balance and Maximum Clients AP 1 AP 2

    AP 3 Full !! Full !! Wireless Clients
  25. VAP Bandwidth Limitation & Equal Share Bandwidth 51200kbps/2 51200kbps/3 New

    User VAP Bandwidth Limitation 51200kbps 51200kbps/3
  26. AC Cluster • The switch with highest priority in a

    cluster becomes the Cluster Controller. If the priority is the same then the switch with lowest IP address becomes the Cluster Controller. • The highest cluster priority is 255. • The Cluster Controller collects status and statistics from all the other AC in the cluster, including information about the APs peer switches manage and the clients associated to those APs
  27. EWS4502-2 192.168.1.31 EWS4502-1 192.168.1.30 Cluster Controller Peer Group ID :

    1 Cluster Priority : 225 Slave AC Peer Group ID : 1 Cluster Priority : 1 AP managed by Cluster Controller.
  28. Slave AC Peer Group ID : 1 Cluster Priority :

    1 Cluster Controller Peer Group ID : 1 Cluster Priority : 225 EWS4502-2 192.168.1.31 EWS4502-1 192.168.1.30 AP managed by slave AC.