Overview of Configuration Steps

Assign interfaces

Field Menu Value
Switch port 1 to 5 Physical Interfaces -> Ethernet Ports -> Port Configuration en1-0 to en1-4

Set up Internet access

Field Menu Value
Connector Type Assistants -> Internet Access -> Internet Connections -> New External gateway/cable modem
Physical Ethernet Port Assistants -> Internet Access -> Internet Connections -> Next ETH5
Internet Service Provider Assistants -> Internet Access -> Internet Connections -> Next - User-Specified -
IP parameters obtained dynamically Assistants -> Internet Access -> Internet Connections -> Next Disabled
Local IP Address Assistants -> Internet Access -> Internet Connections -> Next e. g. 1.2.3.4
Gateway IP address Assistants -> Internet Access -> Internet Connections -> Next e. g. 1.2.3.1
Netmask Assistants -> Internet Access -> Internet Connections -> Next 255.255.255.0
DNS Server 1 Assistants -> Internet Access -> Internet Connections -> Next e. g. 1.2.3.1

Configure interfaces

Field Menu Value
IP Address / Netmask LAN -> IP Configuration-> Interfaces -> <en1-0> 10.0.0.1 and 255.255.255.0
IP Address / Netmask LAN -> IP Configuration-> Interfaces -> <en1-1> 10.0.1.1 and 255.255.255.0
IP Address / Netmask LAN -> IP Configuration-> Interfaces -><en1-2> 10.0.2.1 and 255.255.255.0
Based on Ethernet Interface LAN -> IP Configuration-> Interfaces -> New en1-0
Address mode LAN -> IP Configuration-> Interfaces -> New Static
IP Address / Netmask LAN -> IP Configuration-> Interfaces -> New 10.0.10.1 and 255.255.255.0
Interface Mode LAN -> IP Configuration-> Interfaces -> New Tagged (VLAN)
VLAN ID LAN -> IP Configuration-> Interfaces -> New 10
Based on Ethernet Interface LAN -> IP Configuration-> Interfaces -> New en1-0
Address mode LAN -> IP Configuration-> Interfaces -> New Static
IP Address / Netmask LAN -> IP Configuration-> Interfaces -> New 10.0.20.1 and 255.255.255.0
Interface Mode LAN -> IP Configuration-> Interfaces -> New Tagged (VLAN)
VLAN ID LAN -> IP Configuration-> Interfaces -> New 20

Set up access

Field Menu Value
en1-0 System Management -> Administrative Access -> Access Telnet , SSH , HTTP , HTTPS , Ping , SNMP
en1-1 to en1-4 System Management -> Administrative Access -> Access Ping

Change password

Field Menu Value
System Admin Password System Management -> Global Settings -> Passwords e. g. test12345
Confirm Admin Password System Management -> Global Settings -> Passwords e. g. test12345

Set up firewall

Field Menu Value
Description Firewall -> Services -> Groups -> New Local services
Members Firewall -> Services -> Groups -> New e. g. echo , dns , dhcp , ntp

Define addresses

Field Menu Value
Description Firewall -> Addresses -> Address List -> New Broadcast
Address / Subnet Firewall -> Addresses -> Address List -> New 255.255.255.255 / 255.255.255.255
Description Firewall -> Addresses -> Address List -> New e. g. Employee LAN GW
Address / Subnet Firewall -> Addresses -> Address List -> New 10.0.1.1 / 255.255.255.255
Description Firewall -> Addresses -> Address List -> New Guest LAN GW
Address / Subnet Firewall -> Addresses -> Address List -> New 10.0.2.1 / 255.255.255.255
Description Firewall -> Addresses -> Address List -> New Employee WLAN GW
Address / Subnet Firewall -> Addresses -> Address List -> New 10.0.10.1 / 255.255.255.255
Description Firewall -> Addresses -> Address List -> New Guest WLAN GW
Address / Subnet Firewall -> Addresses -> Address List -> New 10.0.20.1 / 255.255.255.255

Define groups

Field Menu Value
Description Firewall -> Interfaces -> IPv4 Groups -> New Employees
Members Firewall -> Interfaces -> IPv4 Groups -> New LAN_EN1-1 , LEASED_EN1-0-1
Description Firewall -> Interfaces -> IPv4 Groups -> New Guest
Members Firewall -> Interfaces -> IPv4 Groups -> New LAN_EN1-2 , LEASED_EN1-0-2
Description Firewall -> Interfaces -> IPv4 Groups -> New Users
Members Firewall -> Interfaces -> IPv4 Groups -> New LAN_EN1-1 , LAN_EN1-2 , LEASED_EN1-0-1 , LEASED_EN1-0-2

Create policies (network areas connected by the router)

Field Menu Value
Source Firewall -> Policies -> IPv4 Filter Rules -> New LAN_EN1-0
Destination Firewall -> Policies -> IPv4 Filter Rules -> New ANY
Service Firewall -> Policies -> IPv4 Filter Rules -> New any
Action Firewall -> Policies -> IPv4 Filter Rules -> New Access
Source Firewall -> Policies -> IPv4 Filter Rules -> New Employees
Destination Firewall -> Policies -> IPv4 Filter Rules -> New Users
Service Firewall -> Policies -> IPv4 Filter Rules -> New any
Action Firewall -> Policies -> IPv4 Filter Rules -> New Access
Source Firewall -> Policies -> IPv4 Filter Rules -> New Guest
Destination Firewall -> Policies -> IPv4 Filter Rules -> New Guest
Service Firewall -> Policies -> IPv4 Filter Rules -> New any
Action Firewall -> Policies -> IPv4 Filter Rules -> New Access
Source Firewall -> Policies -> IPv4 Filter Rules -> New Users
Destination Firewall -> Policies -> IPv4 Filter Rules -> New LAN_EN1-4
Service Firewall -> Policies -> IPv4 Filter Rules -> New any
Action Firewall -> Policies -> IPv4 Filter Rules -> New Access

Create policies (IP addresses connected on the router)

Field Menu Value
Source Firewall -> Policies -> IPv4 Filter Rules -> New Users
Destination Firewall -> Policies -> IPv4 Filter Rules -> New Broadcast
Service Firewall -> Policies -> IPv4 Filter Rules -> New Local services
Action Firewall -> Policies -> IPv4 Filter Rules -> New Access
Source Firewall -> Policies -> IPv4 Filter Rules -> New LAN_EN1-1
Destination Firewall -> Policies -> IPv4 Filter Rules -> New Employee LAN GW
Service Firewall -> Policies -> IPv4 Filter Rules -> New Local services
Action Firewall -> Policies -> IPv4 Filter Rules -> New Access
Source Firewall -> Policies -> IPv4 Filter Rules -> New LAN_EN1-2
Destination Firewall -> Policies -> IPv4 Filter Rules -> New Guest LAN GW
Service Firewall -> Policies -> IPv4 Filter Rules -> New Local services
Action Firewall -> Policies -> IPv4 Filter Rules -> New Access
Source Firewall -> Policies -> IPv4 Filter Rules -> New LEASED_EN1-0-1
Destination Firewall -> Policies -> IPv4 Filter Rules -> New Employee WLAN GW
Service Firewall -> Policies -> IPv4 Filter Rules -> New Local services
Action Firewall -> Policies -> IPv4 Filter Rules -> New Access
Source Firewall -> Policies -> IPv4 Filter Rules -> New LEASED_EN1-0-2
Destination Firewall -> Policies -> IPv4 Filter Rules -> New Guest WLAN GW
Service Firewall -> Policies -> IPv4 Filter Rules -> New Local services
Action Firewall -> Policies -> IPv4 Filter Rules -> New Access

DHCP configuration

Field Menu Value
IP Pool Name Local Services -> DHCP Server -> IP Pool Configuration -> New e. g. Slave APs
IP Address Range Local Services -> DHCP Server -> IP Pool Configuration -> New 10.0.0.10 - 10.0.0.29
Interface Local Services -> DHCP Server -> DHCP Configuration -> New en1-0
IP Pool Name Local Services -> DHCP Server -> DHCP Configuration -> New e. g. Slave APs
Pool Usage Local Services -> DHCP Server -> DHCP Configuration -> New Local
Gateway Local Services -> DHCP Server -> DHCP Configuration -> New Use Router as Gateway
DHCP Options Local Services -> DHCP Server -> DHCP Configuration -> New DNS Server / 10.0.0.1 and CAPWAP Controller / 10.0.0.1
IP Pool Name Local Services -> DHCP Server -> IP Pool Configuration -> New e. g. Staff-WLAN
IP Address Range Local Services -> DHCP Server -> IP Pool Configuration -> New 10.0.10.10 - 10.0.10.254
Interface Local Services -> DHCP Server -> DHCP Configuration -> New en1-0-1
IP Pool Name Local Services -> DHCP Server -> DHCP Configuration -> New e. g. Staff-WLAN
Pool Usage Local Services -> DHCP Server -> DHCP Configuration -> New Local
Gateway Local Services -> DHCP Server -> DHCP Configuration -> New Use Router as Gateway
DHCP Options Local Services -> DHCP Server -> DHCP Configuration -> New DNS Server / 10.0.10.1
IP Pool Name Local Services -> DHCP Server -> IP Pool Configuration -> New e. g. Guest-WLAN
IP Address Range Local Services -> DHCP Server -> IP Pool Configuration -> New 10.0.20.10 - 10.0.20.254
Interface Local Services -> DHCP Server -> DHCP Configuration -> New en1-0-2
IP Pool Name Local Services -> DHCP Server -> DHCP Configuration -> New e. g. Guest-WLAN
Pool Usage Local Services -> DHCP Server -> DHCP Configuration -> New Local
Gateway Local Services -> DHCP Server -> DHCP Configuration -> New Use Router as Gateway
DHCP Options Local Services -> DHCP Server -> DHCP Configuration -> New DNS Server / 10.0.20.1
IP Pool Name Local Services -> DHCP Server -> IP Pool Configuration -> New e. g. Staff-Ethernet
IP Address Range Local Services -> DHCP Server -> IP Pool Configuration -> New 10.0.1.10 - 10.0.1.254
Interface Local Services -> DHCP Server -> DHCP Configuration -> New en1-1
IP Pool Name Local Services -> DHCP Server -> DHCP Configuration -> New e. g. Staff-Ethernet
Pool Usage Local Services -> DHCP Server -> DHCP Configuration -> New Local
Gateway Local Services -> DHCP Server -> DHCP Configuration -> New Use Router as Gateway
DHCP Options Local Services -> DHCP Server -> DHCP Configuration -> New DNS Server / 10.0.1.1
IP Pool Name Local Services -> DHCP Server -> IP Pool Configuration -> New e. g. Guest-Ethernet
IP Address Range Local Services -> DHCP Server -> IP Pool Configuration -> New 10.0.2.10 - 10.0.2.254
Interface Local Services -> DHCP Server -> DHCP Configuration -> New en1-2
IP Pool Name Local Services -> DHCP Server -> DHCP Configuration -> New e. g. Guest-Ethernet
Pool Usage Local Services -> DHCP Server -> DHCP Configuration -> New Local
Gateway Local Services -> DHCP Server -> DHCP Configuration -> New Use Router as Gateway
DHCP Options Local Services -> DHCP Server -> DHCP Configuration -> New DNS Server / 10.0.2.1

Configure WLAN controller

Field Menu Value
Region Wireless LAN Controller -> Controller Configuration -> General Germany
Interface Wireless LAN Controller -> Controller Configuration -> General LAN_EN1-0
DHCP Server Wireless LAN Controller -> Controller Configuration -> General Internal
IP Address Range Wireless LAN Controller -> Controller Configuration -> General 10.0.0.10 - 10.0.0.29
Slave AP location Wireless LAN Controller -> Controller Configuration -> General Local (LAN)

Edit wireless networks

Field Menu Value
Network Name (SSID) Wireless LAN Controller -> Slave AP Configuration->Wireless Networks (VSS)-> <vss-1> e. g. Employees
Security mode Wireless LAN Controller -> Slave AP Configuration->Wireless Networks (VSS)-> <vss-1> WPA-PSK
WPA Mode Wireless LAN Controller -> Slave AP Configuration->Wireless Networks (VSS)-> <vss-1> WPA and WPA 2
WPA Cipher Wireless LAN Controller -> Slave AP Configuration->Wireless Networks (VSS)-> <vss-1> TKIP
WPA2 Cipher Wireless LAN Controller -> Slave AP Configuration->Wireless Networks (VSS)-> <vss-1> AES
Preshared key Wireless LAN Controller -> Slave AP Configuration->Wireless Networks (VSS)-> <vss-1> Enter password
VLAN Wireless LAN Controller -> Slave AP Configuration->Wireless Networks (VSS)-> <vss-1> Enabled
VLAN ID Wireless LAN Controller -> Slave AP Configuration->Wireless Networks (VSS)-> <vss-1> 10
Network Name (SSID) Wireless LAN -> WLAN1 ->Wireless Networks (VSS)-> New e. g. Guest
Security mode Wireless LAN -> WLAN1 ->Wireless Networks (VSS)-> New WPA-PSK
WPA Mode Wireless LAN -> WLAN1 ->Wireless Networks (VSS)-> New WPA and WPA 2
WPA Cipher Wireless LAN -> WLAN1 ->Wireless Networks (VSS)-> New TKIP
WPA2 Cipher Wireless LAN -> WLAN1 ->Wireless Networks (VSS)-> New AES
Preshared key Wireless LAN -> WLAN1 ->Wireless Networks (VSS)-> New Enter password
VLAN Wireless LAN -> WLAN1 ->Wireless Networks (VSS)-> New Enabled
VLAN ID Wireless LAN -> WLAN1 ->Wireless Networks (VSS)-> New 20

Edit radio profiles

Field Menu Value
Operation Band Wireless LAN Controller -> Slave AP Configuration-> Radio Profiles-> <2.4 GHz Radio Profile> 2.4 GHz In/Outdoor
Wireless Mode Wireless LAN Controller -> Slave AP Configuration-> Radio Profiles-> <2.4 GHz Radio Profile> 802.11g/n
Burst Mode Wireless LAN Controller -> Slave AP Configuration-> Radio Profiles-> <2.4 GHz Radio Profile> Enabled
Channel plan Wireless LAN Controller ->Slave AP Configuration -> Radio Profiles-> <2.4 GHz Radio Profile> -> Advanced Settings User-defined
User-defined Channel Plan Wireless LAN Controller ->Slave AP Configuration -> Radio Profiles-> <2.4 GHz Radio Profile> -> Advanced Settings 1 , 5 , 9 , 13
Short Guard Interval Wireless LAN Controller ->Slave AP Configuration -> Radio Profiles-> <2.4 GHz Radio Profile> -> Advanced Settings Enabled

Set up slave access points

Field Menu Value
Location Wireless LAN Controller -> Slave-AP Configuration-> Slave Access Points e. g. Meeting Room
Description Wireless LAN Controller -> Slave-AP Configuration-> Slave Access Points e. g. Marketing
CAPWAP Encryption Wireless LAN Controller -> Slave-AP Configuration-> Slave Access Points Enabled
Operation Mode Wireless LAN Controller -> Slave-AP Configuration-> Slave Access Points On
Active wireless module profile Wireless LAN Controller -> Slave-AP Configuration-> Slave Access Points 2.4 GHz Radio Profile
Channel Wireless LAN Controller -> Slave-AP Configuration-> Slave Access Points Auto
Assigned wireless networks (VSS) Wireless LAN Controller -> Slave-AP Configuration-> Slave Access Points vss-1: Employee / vss-2: Guest
Location Wireless LAN Controller -> Slave-AP Configuration-> Slave Access Points e. g. Kitchen
Location Wireless LAN Controller -> Slave-AP Configuration-> Slave Access Points e. g. Terrace
Location Wireless LAN Controller -> Slave-AP Configuration-> Slave Access Points e. g. Bottom of stairs
Location Wireless LAN Controller -> Slave-AP Configuration-> Slave Access Points e. g. Bend in stairs
Location Wireless LAN Controller -> Slave-AP Configuration-> Slave Access Points e. g. End of hall

New channel setting

Field Menu Value
New channel setting Wireless LAN Controller -> Slave-AP Configuration-> Slave Access Points START