forward-mode bridge
wired-ap-enable
Optionally, you can configure the following wired AP profile settings:
(host)(config) #ap wired-ap-profile <profile>
switchport mode {access | trunk}
switchport access vlan <vlan>
switchport trunk native vlan <vlan>
switchport trunk allowed vlan <vlan>
trusted
Configuring Ethernet Ports for Secure Jack Operation
You can configure the Ethernet port(s) on mesh nodes to operate in tunnel mode. Known as secure jack
operation for mesh, this configuration allows Ethernet frames coming into the specified wired interface to be
generic routing encapsulation (GRE) tunneled to the switch. Likewise, Ethernet frames coming from the tunnel
are bridged to the corresponding wired interface. This allows an Ethernet port on the mesh node to appear as
an Ethernet port on the switch separated by one or more Layer-3 domains. You can also enable VLAN tagging.
Unlike secure jack on non-mesh APs, any mesh node configured for secure jack uses the mesh link, rather than
enet0, to tunnel the frame to the switch.
When configuring mesh Ethernet ports for secure jack operation, note the following guidelines:
n Mesh points support secure jack on enet0 and enet1.
n Mesh portals only support secure jack on enet1. This function is only applicable to Alcatel-Lucent APs that
support a second Ethernet port and mesh, such as the OAW-AP130 Series.
You configure secure jack operation in the wired AP profile.
The parameters in the wired AP profile only apply to the wired AP interface to which they are applied. Two wired
interfaces can have different parameter values.
In the WebUI
Use the following procedure to configure secure jack operation using the WebUI.
1. Navigate to the Configuration > Wireless > AP Configuration > AP Group window.
2. Click the AP group with the wired AP profile you want to edit.
3. Under the Profiles list, expand the AP menu, then select Wired AP profile. The settings for the currently
selected wired AP profile appear.
You can use a different wired AP profile by selecting a profile from the Wired AP profile drop-down list.
4. In the Profile Details window pane, do the following:
a. Select the Wired AP enable check box. This option is not selected by default.
b. From the Forward mode drop-down list, select tunnel.
c. Optionally, select Trusted to configure this as a trusted port.
5. Click Apply.
In the CLI
To configure secure jack operation using the command-line interface, access the CLI in config mode and issue
the following commands:
(host)(config) #ap wired-ap-profile <profile>
forward-mode tunnel
wired-ap-enable
Optionally, you can configure the following wired AP profile settings:
AOS-W 6.5.3.x | User Guide Secure Enterprise Mesh | 625