Configure WAP4410N with Multiple SSIDS

I need to configure a WAP4410N for use on a small, very simple business network.  There should be a corporate WLAN and a guest WLAN.  The corporate WLAN should allow anyone connectd to it to access resources on the domain.
In front of the WAP is a cable modem/router and a basic Level 2 (web managed) switch.  What do i have to do to segregate the corporate and guest networks.
I thought I would add the corporate WLAN to VLAN1 (assuming the default VLAN in the switch is VLAN1).  Then I figured I could create the guest WLAN and assign it to VLAN2 which which will be controlled entirely by the 4410N (DHCP, DNS, etc.)  Does this sound like the right way of going about things?
If not, can you please point me in th right direction?
Thank you,

That's right.If you are going to create a guest wireless network, or any additional SSIDs for that matter, you'll also need to create an additional vlan for the guest network. I've pasted below the 4 steps from the WAP4410N manual, and then as a final step you'll also need to configure vlans on your switch so that traffic on the guest wlan will be allowed a path on your network.
STEP 1
Click Wireless > VLAN & QoS.
STEP 2
To configure VLAN settings:
NOTE You can enable this feature only if the hubs/switches on your network
support the VLAN standard.
a. To enable VLAN, click Enabled.
b. Provide the following information:
• Default VLAN ID—Enter the default VLAN ID.
• VLAN Tag—Select Tagged to determine the associated VLAN from the
VLAN tag. The default is Untagged.
• AP Management VLAN—Specify the VLAN ID used for management.
• VLAN Tag over WDS—Select Enabled or Disabled as required.
STEP 3
To configure the QoS settings, enter the following information:
• VLAN ID—Enter the ID to assign to the VLAN.
• Priority—Select a priority from the list.
• WMM—To enable WMM, check the corresponding check box.
Wi-Fi Multimedia is a QoS feature defined by WiFi Alliance before IEEE
802.11e was finalized. Now it is part of IEEE 802.11e. When it is enabled, it
provides four priority queues for different types of traffic. It automatically
maps the incoming packets to the appropriate queues based on QoS
settings (in IP or layer 2 header). WMM provides the capability to prioritize
traffic in your environment. The default is Enabled.
STEP 4
Click Save.
STEP 5
Configuration on a Switch running IOS
apply the following to the interface that the WAP4410N is connected to:
en
conf t
int
switchport mode trunk
switchport trunk encapsulation dot1q
switchport trunk native vlan 1
switchport trunk allowed vlan 1,
end
*you'll also need to configure any interfaces that packets from the guest wlan will traverse, if you intend to permit guest traffic over them.

Similar Messages

  • WAP200 and .1x/radius authentication with multiple SSIDs

    Apparently it's not possible to define more than a single radius server when using multiple SSIDs with WAP200. Unfortunately WAP200 doesn't add the name of the SSID as a radius attribute, so it's not possible to make distinction whether the user is trying to log in to SSID A or B. Does anyone have any ideas or workarounds for this limitation? Of course the best solution would be if Cisco/Linksys fixed the firmware so that the SSID of the logging in user would be sent to the radius server as an extra attribute or appended to the client mac address.

    Security option for an SSID can be unique and can be configured when you configure a SSID or under VLAN . Note that each vlan is uniquely mapped to induvidual SSID.

  • Authentication with Multiple SSIDs AP521G, using Autonomous

    I have an AP521G access point that I am trying to setup authentication for multiple SSIDs. One SSID is for domain users with WPA/TKIP authentication to a radius server and the other SSID is for guest to have access to Internet with no authentication. Is there a way to setup both SSIDs on the AP for this configuration?

    Security option for an SSID can be unique and can be configured when you configure a SSID or under VLAN . Note that each vlan is uniquely mapped to induvidual SSID.

  • Single access point with multiple ssids and single channel possible?

    Hi everybody.
    I have this silly question.
    Let say we have three vlans, vlan1,2,3  and they are mapped to wlans as follows:
    Vlan 1  ssid1
    Vlan 2 ssid2
    Vlan3 ssid 3
                      AP --------trunk------Switchted network.
    Our Ap  has mobile devices in three wlans, i.e ssid1ssid2 and ssid3
    Since AP uses half duplex mode,  mobile devices need positive ack from ap  before they can send data,  therefore once channel let say channel 3( assuming 802.11b is used) can be shared by all mobile devices in three wlans.  
    Is  my understanding correct?
    Thanks and have a great weekend.

    Hii ,
    Yes ,that is pretty much possible as suggested by other experts on board. Depending on your access point you will have 1 (2.4 GHz) or  both 2.4 & 5GHz radios.
    You can configure multiple SSIDs (up to 16 ) known as MBSSID mode in autonomous environment. In Controller based architecture you can configure up to 512 WLAN (SSID) and transmit any 16 of them per AP (using AP group feature). However , it is recommended to keep multiple SSID count below 8 as for each SSID separate beacon will be sent on air which consumes more air time.
    Hope this helps
    Thanks
    Vinay

  • Prioritize data on one SSID on an autonomous AP with multiple SSIDs

    Hello,
    I have a standalone AP(AP1261N) which is configured with 3 SSIDs.I would like to prioritize any data flow on SSID 1 for example so that users on SSID 1 are always functional independent on what is happening on the other SSIDS.
    Then have the SSID 2 with a lower priority and SSID 3 lowest priority.
    Each SSID is associated with a vlan.
    I have seen some posts describing that this can be done using QOS associated with the different vlans.
    Could someone please explain how I could configure the AP to do so?
    I am using Command line.     
    Thank you 

    Hi Kavi,
    Here are the few important points you need to understand when it comes to Autonomous AP QoS (this is extract from the link provided by Scot in above).
    The QoS implementation for wireless LANs differs from QoS  implementations on other Cisco devices. With QoS enabled, access points  perform the following:
    •They  do not classify packets; they prioritize packets based on DSCP value,  client type (such as a wireless phone), or the priority value in the  802.1q or 802.1p tag.
    •They  do not construct internal DSCP values; they only support mapping by  assigning IP DSCP, Precedence, or Protocol values to Layer 2 COS values.
    •They carry out EDCF like queuing on the radio egress port only.
    •They do only FIFO queueing on the Ethernet egress port.
    •They support only 802.1Q/P tagged packets. Access points do not support ISL.
    •They support only MQC policy-map set cos action.
    •They  prioritize the traffic from voice clients (such as Symbol phones) over  traffic from other clients when the QoS Element for Wireless Phones  feature is enabled.
    •They support Spectralink phones using the class-map IP protocol clause with the protocol value set to 119.
    Also it is important to understand what type of traffic get impacted by AAP QoS. When you configure AAP for QoS it will primarily affect downstream traffic from AP to Client (No control over traffic coming from wireless client to AP - where priority will determine by WMM UP of clients traffic)
    As you can see in the above, only FIFO available on ethernet egress (from AP to rest of your network) & then depend on how do you configure network switch ports connected to these AP (either trust DSCP or COS) it will determine how QoS maintain within your wired network.
    In unified wireless enviroment you can classify each SSID with different QoS profile (Platinum, Gold, Silver & Bronze) & control what is the max level of QoS priority packets will get in each SSID. But in autonomous world it is not straightforward like that.
    HTH
    Rasika

  • Wireless Network Management with Multiple SSIDs in one Wireless Profile

    Could anybody explain me about how Multiple SSIDs in one Wireless Network Name (Network Profile) ? Configuration will be pushed to Windows 7 Pro from Wins Server 2008 R2.
    Objective: Multiple office locations will have different SSIDs and when the laptop user travels one location to another, he/she could connect to wireless networks at any offices without any configuration change but utilizing "Automatically use my Windows
    logon name and password (and domain if any.)" setting in EAP MSCHAPv2 properties. 
    Network Name: Enterprise
    SSIDS: SFO-WIFI, LAX-WIFI,CHI-WIFI,NYC-WIFI,
    Network Type:Access Point
    Security Type: WPA2-Enterprise
    Encryption Type: AES
    Network Authentication Method: Microsoft:Protect EAP(PEAP)
    My question is: (1) Will Windows try all the SSIDs in order to get connected to the Wireless Network at the office? (Let's say, user is in NYC, but will Windows try to find SFO-WIFI SSID first, wait until time out, retry?, and moves on to LAS-WIFI SSID,
    wait until time out, retry?, and moves on to CHI-WIFI and finally tries NYC-WIFI SSID and found the SSID in the beacon from Access Point and authenticates through RADIUS?
    (2) If the answer is YES, what is the waiting time/timeout setting for one SSID before moves on to another?
    (3) If the answer is NO, what is the process to get user connected to NYC-WIFI SSID when he/she is in NYC office within the range of that SSID?

    Hello Ninjago_2224,
    About the multiple office location have different SSIDs, does the location A has the signal used in
    location D?
    Please go to Control Panel\Network and Internet\Network and Sharing Center
    , and then click Manage wireless networks.
    The windows will try to connect to these networks in the order listed.
    Please check if the four SSID pushed by Windows Server 2008 is listed as mentioned above.
    If the location A have the location D SSID and the location D SSID has higher priority, the Windows will connect to
    location D SSID.
    So about the question 1, the Windows will try the SSID in order.
    About the question 2, I can’t find the accurate time that test one SSID and move to another. But based on my test, it is very fast.
    For more information, please take a look at the following article.
    http://www.howtogeek.com/howto/27067/change-wireless-network-priority-to-make-windows-7-choose-the-right-network-first/
    Please note: Since the website is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.
    Best regards,
    Fangzhou CHEN
    Fangzhou CHEN
    TechNet Community Support

  • Prioritize date with multiple SSIDS?

    Hi,
    When running multiple SSIDs on an AP all SSIDs share the available bandwidth. Is there a way to prioritize the traffic?....ie...can I somehow give preference to traffic on SSID A over traffic on SSID B?
    ...thanks in advance.......J

    Hi,
    I was afraid of that...ie....a feature of light weight only? We are running autonomous 1100s (AIR-AP1121G-A-K9), I should have mentioned this is my first message. I presume I'm out of luck?
    ...thanks in advance......J

  • Network Locations not working with Multiple SSIDs

    I've had a MacBookPro 15 for three years.  Started with 10.5 and upgraded to 10.6.  I just received a new MacBookPro 15 with Lion 10.7.
    The Issue:
    On 10.5 and 10.6 I use multiple network locaitons.  One for work, one for Home and one for Roaming.  I have a "Work" SSID at work and at Home.  I also have a "Home" SSID at home.
    So basically, when I'm home I can select "work" to be on my hardware VPN router and connect directly to the office.  Then, when I'm not working, I can switch to the "home" location and automatically connect to my home network and not have big brother watching me surf the web.
    In 10.7 this no longer works.  All of the WIFI settings are them same in both locations.  When I'm on "home" I add the SSID for home and it connects.  I then turn off the wifi and switch locations (same as I do in 10.6).  Then I turn WIFI back on, and it connects to my home SSID.  I go to the wireless settings, and add the work SSID and delete the home SSID.  I shut off wireless, change back to home and turn it back on.  I go to wireless settings, and the only SSID is the one I added under the work location.
    Has anyone else seen this change in behavior?
    Dan

    I prefer to continue the way I've been using it for 3 years rather than switch now.  The work location has the WIFI adapter as primary so that the default gateway is the wifi network even if I have a network cable plugged in.  This allows me to use my "work" network, but I can still share content with my local home network and also print to my local printer (not on my work network).
    So, this solution really doesn't work for me.  And yes, I know you can only connect to one at a time, but  again, those are not the only settings that I change when switching locations.  Those are the only settings that are broken.
    Dan

  • Trying to setup 1131 in autonomous mode with multiple ssids and vlans

    hi there,
    I'm trying to setup an aironet 1131 in autonomous mode with a WLAN for each VLAN.
    I can connect to the SSID "BLUGstaff" but I don't pick up a DHCP address and when I set a static IP I can't anything on the vlan so I can only assume I have made an error.
    I have attached the config for the access point.
    The switch port the access point connects to has the following config...
    interface FastEthernet1/0/3
    description ## Access Point ##
    switchport trunk encapsulation dot1q
    switchport trunk native vlan 121
    switchport trunk allowed vlan 1,121-124
    switchport mode trunk
    spanning-tree portfast
    end
    Can anyone explain what I've done wrong? Thanks in advance for any help,
    Huw

    Hello Huw,
    as i see in your confirguartion.
    native VLAN is 121. so you have to correct following in your AP configuration
    1) interface Dot11Radio0.121
    encapsulation dot1Q 121 native
    bridge-group 121         ->>>>>>>>>>>>>>>> change this to brige-group 1 , native always tied to bridge group 1
    2)
    interface FastEthernet0.121
    encapsulation dot1Q 121
    add also under this sub interface
    bridge-group 1
    please let me know how it goes.
    Kind regards
    Talal
    ==========
    please rate answers that you find useful , and mark as answered - when it is :-) - so others can find it easily

  • FAQ or tutorial for configuring RV220W with multiple static external IP addresses?

    I just acquired a used RV220W and would like to use it with my Comcast business internet service (13 external IP's).
    My network currently consists of multiple linux machines.  Each machine has an internal IP and an external IP.  All firewalling is done on the machine itself (using iptables).
    I would like to configure the RV220W to be a frontline firewall so the individual machines don't need to be firewalled.  I would like each machine to maintain it's network configuration, so as to avoid major disruptions.  IOW, I don't (currently) want to use one-to-one nat mapping.
    I may consider moving to nat routing at some point in the future.
    Does anyone know of a tutorial or FAQ that outlines the configuration steps to accomplish this?
    Although I am an IT professional, I am not a networking guru.
    Thanks!
    david

    Hello, 
    I'm sorry, I'm a little bit confuse about your current setup but I can definitely explain the capabilities on our Small Business Routers.
    On the devices that support any type of connection to a modem providing multiple addresses the only way to use then is as follows:
    1- The router should be configured with a Static IP address
    2- That static IP needs to be part of the same subnet as the other IP addresses that you are planning to use on the inside of the network.
    3- The subnet mask configured on the Static IP address should reflect the amount of addresses that you have avialble, For example, if you have 13 available IP addresses your subnet mask on the WAN connection should not be 255.255.255.252.
    4- The only way to allow the other public IP addresses on the inside of the network is by configuring One to One NAT and assign them to private IP addresses on the LAN.
    5- When you enable the One to One NAT rules on the router, you will be opening either all or just one port depending on the router, and then you will have to configure restrictions on the firewall to block or allow more ports.
    Now, if you have a Router with a DMZ port like the RV320, then you can configure the public IP address on a Range on the DMZ port and use the actual public IP address on the NIC of the linux PC's.
    I hope this helps

  • Fail to configure MPxIO with multiple SAN LUNs

    Hi
    Anyone with ideas on why Solaris 10u3 x86 MPxIO operates for single lun under default 'scsi_vhci' but not for multiple LUNs seen (ref below).
    All feedback appreciated.
    # cfgadm -al -o show_SCSI_LUN c2
    Ap_Id Type Receptacle Occupant Condition
    c2 fc-private connected configured unknown
    c2::200100172a3100c2,0 disk connected configured unknown
    c2::200100172a3100c2,1 disk connected configured unknown
    c2::200100172a3100c2,2 disk connected configured unknown
    c2::200100172a3100c2,3 disk connected configured unknown
    c2::200100172a3100c2,4 disk connected configured unknown
    c2::200100172a3100c2,5 disk connected configured unknown
    c2::200100172a3100c2,6 disk connected configured unknown
    c2::200100172a3100c2,7 disk connected configured unknown
    # cfgadm -al -o show_SCSI_LUN c3
    Ap_Id Type Receptacle Occupant Condition
    c3 fc-private connected configured unknown
    c3::200300172a3100c2,0 disk connected configured unknown
    c3::200300172a3100c2,1 disk connected configured unknown
    c3::200300172a3100c2,2 disk connected configured unknown
    c3::200300172a3100c2,3 disk connected configured unknown
    c3::200300172a3100c2,4 disk connected configured unknown
    c3::200300172a3100c2,5 disk connected configured unknown
    c3::200300172a3100c2,6 disk connected configured unknown
    c3::200300172a3100c2,7 disk connected configured unknown
    #

    ssolbach wrote:
    you need to initialize the repository.
    And after that it should get mounted (not under OVS though... the path was something like /opt/ovs-repositories/mount/ID or something). Sorry can't check atm.It gets mounted in /var/ovs/mount/UUID

  • Configure RRAS with multiple public STATIC IP address

    <p>I have Server 2012 Standard edition. &nbsp;I have two network cards installed. &nbsp;I have configure my server to be my router aka NAT BOX using Server 2k12 RRAS. We recently added more servers to our internal network. We needed more
    Public Static IP address. Currently we had one and then upgrade to 5 with Time Warner. I configure my WAN NIC card on the server with the new Static IP address from TIME WARNER. How do I add the remaining ones to RRAS. THen i can use services tab to add that
    static IP address with this port to that internal ip address which happens to be another server. &nbsp;</p><p>Currently when I add to the address pool tab couple my PC or servers gets kicked off the internet especially when I add the service
    port and the public ip address from the public ip address pool and the internal ip address and the internal port.&nbsp;</p><p></p><p>Anyhow, what i am trying achieve here is NAT the remaining public IP Address to an internal ip
    address. Only a certain ports such as SMTP Port, VPN port, pop3 port, HTTP port HTTPS ports. &nbsp;Can someone help me configure this on RRAS on server 2012</p>

    how can i do port forwarding with the address pool of public static IP address.  Currently my  Server 2012 is my acting router. I have NIC cards on there. One of the NIC is connected to the Cable Modem and the other NIC card is connected to the
    switch. How can I use port forwarding with the other remaining public IP address.  The reason is I have two exchange server in my internal network. Both can't be using the same ports so I got more public IP addresses. I just want to configure my RRAS
    port forward 80, 443, 25, 110, 143 to both exchange server who have an internal ip address. In order to achieve that I need to have two public IP address. 
    Tell me if there is a solution. 

  • How to Configure iCloud with multiple iCloud accounts and one apple id

    I need some help from the icloud experts. I almost have my arms around this, but not completely.
    What I want to end up with is the following:
    One account that both my wife and I use for shared contacts, calendars, photostream and find my device.
    Separate account for my email among several devices.
    Separate account for my wife for her email among several devices.
    Now what I curently have is an apple id (*.mac.com), which is the main account used for purchases, etc. It has my mail, backups, and 25GB of space as a result from MobileMe.
    I created a separate icloud account for my wife, using her Apple ID, so that her mail stayed separate from mine. However, now we have separate photo streams, contacts, etc, which is getting confusing and cumbersome.
    I would like to keep my apple id as the main account since it already has the 25GB of space. So tell me if the following make sense.
    I setup the master account using my apple id (the one with 25GB of space) for both of us, and enable the contacts and calendar syncing for all of our devices.
    I turn the mail and Safari bookmarks syncing on for my devices; but turn it off  for my wife's devices.
    Then I use my wife's account on her devices to sync her mail, bookmarks, etc.
    Would this work or is there another combination to use? Ideally a family oriented apple id would be good for the master account, but it wouldn't have the 25GB of space unless I purchased it. I'm trying to get around that if possible. I have tried to find something like this on the discussion boards but haven't had luck yet.
    Thanks in advance for any help.

    Set up your mac.com account again on devices.  Turn off Mail and other data syncing with this account on your wife's devices for data that you want to keep separate.  Then set up a second ("secondary") iCloud account on your wife's devices to sync Mail.
    If you already set up a separate iCloud account on your wife's devices, on her devices go to Settings>iCloud, tap Delete Account, then sign back in your your mac.com ID.  Turn on the data you want to share with this account across all devices; don't turn Mail on.  Then go to Settings>Mail,Contacts,Calendars>Add Account>iCloud and enter her separate iCloud credentials and turn Mail to On.
    The only downside to this approach is that her email will be fetch, not push email.  Push email is only supported in the main ("primary") account, not a secondary account.
    The limitations to be aware of with secondary accounts are that only the primary account can be used for Photo Stream, Bookmarks, Documents, iCloud Backup and Find My Device.  Also, push mail only works for the primary account; secondary account mail is fetch.

  • WAP4410N and multiple SSIDs on different VLANs using RADIUS

                       I am trying to setup the above environment.  When I connect on my guest network it does not give me an IP address from my guest network DHCP scope that is configured on my CISCO router.
    Does anyone have any idea how to set this up???
    Any help would be appreciated...

    It is most likely (I'm not certain from the description) that
    the 'sub-buttons' are a 'child' MC of the main button? if so, the
    'on' handler for the 'main' button will override any handlers
    attached to 'child' buttons within it. the only solution is to use
    a hitTest method for either the 'parent' button or the 'child'
    buttons, OR separate the two MCs and use the 'main' button to bring
    a MC of the 'sub' buttons to the Stage.

  • Multiple vlan with multiple SSID

    I have a 1130 AP connected to a 500 series express catalyst switch. I want to have two vlans one for guest internet access only and the other that can have both internet and internal access. I want to have two SSID one for guest and the other for internal employee which should match the vlan. Can anyone guide me to a good doc. that can help me implement this solution. And is the 500 series switch is capable of doing this.
    Thanks.

    To anwser your first question Yes your 500 series switch is capable of doing vlans (See Link: "http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps6545/product_data_sheet0900aecd80322aeb.html") (first time pasting a link sorry if it doesnt work) here is another link that you can utilize on config examples. and as for you access point you can do the same as well (http://cisco.com/en/US/products/ps6087/tsd_products_support_configure.html)

Maybe you are looking for

  • Idoc to jdbc :On the basis of field WERKS, the child segments should get re

    We are working on IDOC to JDBC scenario. In my IDOC INFREC.INFRECMASS01 has one  segment E1E1NAM( parent segment), inside this parent segment we have one  child segment E1E1NEM containing two lines. On the basis of one field WERKS, the child segments

  • Data Refresh

    Hello Gurus We have a query reg the data refresh....recently we have made the the Quality CRM and R/3 data refresh, i want to know wht all the things we need to be  consider for post data refresh i mean in terms of middleware........ as per my knowle

  • Filtering Content while displaying

    I have created a news content. I need to display the top five news in my iview. Where do i set this filter criteria? Also, is there a way of displaying the news in the the locale of the logged in user?

  • Upgrade MacBook Pro 2011 Mac OS X 10.6.8 to Mountain Lion

    Can I Upgrade MacBook Pro from Mac OS X 10.6.8 to Mountain Lion?

  • When exporting document to Package in InDesign, bleeds disappear!

    I've tried to export to PDF, and the bleeds and crop marks come out just fine. But when I try to export to package, I get this: Once again, I have the document setup to bleed at 5mm on all sides and you can even see the red line in the background of