Home
Siemens
Wireless Access Point
SCALANCE W1750D UI
Siemens SCALANCE W1750D UI User Manual
4
of 1
of 1 rating
570 pages
Give review
Manual
Specs
To Next Page
To Next Page
To Previous Page
To Previous Page
Loading...
AP
-
VPN Dep
loyment Scen
arios
35.1
Scen
ario 1
-
IPsec: S
ingle Dat
acent
er Deploym
ent wi
th No Re
dundancy
SCALANCE W1750D UI
Configuration M
anual
,
02/2018, C79000
-
G8976
-
C451
-
02
531
Topology
The following f
igure shows the topo
logy and the IP addres
sing schem
e used
in this
scenario.
Figure
35
-1
Scenario 1
-
IPsec: S
ingle d
atacen
ter Deplo
yment wit
h No R
edundanc
y
530
532
Table of Contents
Default Chapter
2
C79000-G8976-C451
2
Table of Contents
5
1 About this Guide
19
Table 1- 1 Typographical Conventions
19
2 Security Recommendations
21
3 About SCALANCE W
25
Overview
25
Scalance W Ui
26
Scalance W Cli
27
4 Setting up an AP
29
Setting up an SCALANCE W Network
29
Connecting an AP
29
Assigning an IP Address to the AP
30
Provisioning an AP
31
Zero Touch Provisioning of Aps
31
Provisioning Aps through Airwave
33
Logging in to the SCALANCE W UI
34
Figure 4-1 Login Screen
34
Accessing the SCALANCE W CLI
36
5 Automatic Retrieval of Configuration
41
Managed Mode Operations
41
Configuration Managed Mode Parameters
42
Table 5- 1 Managed Mode Commands
42
Verifying the Configuration
44
6 SCALANCE W User Interface
45
Login Screen
45
Figure 6-1 Connectivity Summary
45
Main Window
47
Figure 6-2 SCALANCE W Main Window
47
Configuration
47
Tabs
49
Network Tab
49
Access Points Tab
50
Clients Tab
51
Links
52
New Version Available
52
System
53
Security
54
Maintenance
55
More
56
Figure 6-3 VPN Window for Ipsec Configuration
56
Figure 6-4 IDS Window: Intrusion Detection
57
Figure 6-5 IDS Window: Intrusion Protection
57
Figure 6-6 Wired Window
58
Figure 6-7 Services Window: Default View
59
Figure 6-8 DHCP Servers Window
60
Help
61
Logout
61
Monitoring
61
Figure 6-9 RF Dashboard in the Monitoring Pane
64
Figure 6-10 RF Trends for Access Point
66
Figure 6-11 RF Trends for Clients
66
Monitoring
67
Figure 6-12 Usage Trends Graphs in the Default View
68
Client Match
72
Figure 6-13 Client Distribution on AP Radio
72
Figure 6-14 Channel Availability Map for Clients
72
Apprf
73
Spectrum
73
Alerts
74
Figure 6-15 Alerts Link
74
Table 6- 1 Types of Alerts
75
Figure 6-16 Client Alerts
75
Table 6- 2 Types of Alerts
76
Ids
78
Airgroup
79
Configuration
79
Airwave Setup
80
Pause/Resume
80
Views
80
7 Initial Configuration Tasks
81
Configuring System Parameters
81
Table 7- 1 System Parameters
81
Changing Password
87
8 Customizing AP Settings
89
Modifying the AP Host Name
89
Configuring Zone Settings on an AP
90
Specifying a Method for Obtaining IP Address
91
Configuring Radio Profiles for an AP
92
Configuring Uplink VLAN for an AP
94
Changing USB Port Status
95
Master Election and Virtual Controller
96
Adding an AP to the Network
98
Removing an AP from the Network
99
9 VLAN Configuration
101
VLAN Pooling
101
Uplink VLAN Monitoring and Detection on Upstream Devices
101
10 Ipv6 Support
103
Ipv6 Notation
103
Enabling Ipv6 Support for AP Configuration
104
Firewall Support for Ipv6
106
Debugging Commands
107
11 Wireless Network Profiles
109
Configuring Wireless Network Profiles
109
Configuring WLAN Settings for an SSID Profile
110
Configuring VLAN Settings for a WLAN SSID Profile
117
Configuring Security Settings for a WLAN SSID Profile
120
Configuring Access Rules for a WLAN SSID Profile
131
Configuring Per-AP SSID and Per-AP-VLAN Settings on a Wireless Profile
134
Configuring Fast Roaming for Wireless Clients
135
Opportunistic Key Caching
135
Fast BSS Transition (802.11R Roaming)
137
Radio Resource Management (802.11K)
138
BSS Transition Management (802.11V)
141
Configuring Modulation Rates on a WLAN SSID
142
Multi-User-MIMO
143
Management Frame Protection
144
Disabling Short Preamble for Wireless Client
144
Editing Status of a WLAN SSID Profile
145
Deleting a WLAN SSID Profile
145
12 Wired Profiles
147
Configuring a Wired Profile
147
Configuring Wired Settings
147
Configuring VLAN for a Wired Profile
149
Configuring Security Settings for a Wired Profile
151
Authentication and User
151
Configuring Access Rules for a Wired Profile
153
Assigning a Profile to Ethernet Ports
155
Editing a Wired Profile
156
Deleting a Wired Profile
156
Link Aggregation Control Protocol
156
Enabling Port-Channel on a Switch
157
Enabling Static LACP Configuration
158
Understanding Hierarchical Deployment
159
13 Captive Portal for Guest Access
161
Understanding Captive Portal
161
Types of Captive Portal
161
Walled Garden
162
Configuring a WLAN SSID for Guest Access
163
Configuring Wired Profile for Guest Access
170
Configuring Internal Captive Portal for Guest Network
172
Configuring External Captive Portal for Guest Network
176
External Captive Portal Profiles
176
Creating a Captive Portal Profile
176
Configuring an SSID or Wired Profile to Use External Captive Portal Authentication
178
External Captive Portal Redirect Parameters
181
Configuring External Captive Portal Authentication Using Clearpass Guest
181
Table 13- 1 External Captive Portal Redirect Parameters
181
Configuring Facebook Login
184
Setting up a Facebook Page
184
Configuring an SSID
184
Configuring the Facebook Portal Page
185
Accessing the Portal Page
186
Configuring Guest Logon Role and Access Rules for Guest Users
187
Configuring Captive Portal Roles for an SSID
190
Configuring Walled Garden Access
194
Disabling Captive Portal Authentication
195
14 Authentication and User Management
197
Managing AP Users
197
Table 14- 1 User Privileges
197
Configuring AP Users
198
Configuring Authentication Parameters for Management Users
200
Adding Guest Users through the Guest Management Interface
202
Supported Authentication Methods
203
Supported EAP Authentication Frameworks
205
Configuring Authentication Servers
206
Supported Authentication Servers
206
TACACS Servers
208
Configuring an External Server for Authentication
209
Enabling RADIUS Communication over TLS
214
Configuring Dynamic RADIUS Proxy Parameters
216
Associate Server Profiles to a Network Profile
218
Understanding Encryption Types
220
Table 14- 2 WPA and WPA-2 Features
220
Table 14- 3 Recommended Authentication and Encryption Combinations
221
Configuring Authentication Survivability
222
Configuring 802.1X Authentication for a Network Profile
224
Enabling 802.1X Supplicant Support
227
Configuring MAC Authentication for a Network Profile
229
Configuring MAC Authentication with Captive Portal Authentication
231
Configuring Wispr Authentication
233
Blacklisting Clients
235
Uploading Certificate
238
15 Roles and Policies
243
Firewall Policies
243
Access Control List Rules
243
Configuring ACL Rules for Network Services
244
Configuring Network Address Translation Rules
247
Configuring ALG Protocols
250
Configuring Firewall Settings for Protection from ARP Attacks
251
Configuring Firewall Settings to Disable Auto Topology Rules
253
Managing Inbound Traffic
254
Content Filtering
260
Configuring User Roles
266
Configuring Derivation Rules
270
Understanding Role Assignment Rule
270
Creating a Role Derivation Rule
271
Understanding VLAN Assignment
273
Configuring VLAN Derivation Rules
275
Using Advanced Expressions in Role and VLAN Derivation Rules
277
Table 15- 1 Regular Expressions
277
Configuring a User Role for VLAN Derivation
279
16 DHCP Configuration
281
Configuring DHCP Scopes
281
Configuring Local DHCP Scopes
281
Configuring Distributed DHCP Scopes
284
Configuring Centralized DHCP Scopes
288
Table 16- 1 DHCP Relay and Option 82
289
Configuring the Default DHCP Scope for Client IP Assignment
291
17 Configuring Time-Based Services
295
Time Range Profiles
295
Configuring a Time Range Profile
296
Applying a Time Range Profile to a WLAN SSID
297
Verifying the Configuration
298
18 Dynamic DNS Registration
299
Enabling Dynamic DNS
299
Configuring Dynamic DNS Updates for Clients
301
Verifying the Configuration
302
19 VPN Configuration
303
Understanding VPN Features
303
Table 19- 1 VPN Protocols
304
Configuring a Tunnel from an AP to a Mobility Controller
305
Configuring an Ipsec Tunnel
305
Configuring an L2-GRE Tunnel
308
Configuring an L2Tpv3 Tunnel
313
Configuring Routing Profiles
323
20 AP-VPN Deployment
327
Understanding AP-VPN Architecture
327
Table 20- 1 AP-VPN Scalability
327
Table 20- 2 DHCP Scope and VPN Forwarding Modes Matrix
330
Configuring AP and Controller for AP-VPN Operations
331
Configuring an AP Network for AP-VPN Operations
331
Configuring a Controller for AP-VPN Operations
334
Table 20- 3 Branch Details
339
21 Adaptive Radio Management
341
ARM Overview
341
Configuring ARM Features on an AP
343
Band Steering
343
Airtime Fairness Mode
343
Client Match
344
Access Point Control
347
Verifying ARM Configuration
348
Configuring Radio Settings
351
22 Deep Packet Inspection and Application Visibility
357
Deep Packet Inspection
357
Enabling Application Visibility
358
Application Visibility
359
Enabling URL Visibility
366
Configuring ACL Rules for Application and Application Categories
367
Configuring Web Policy Enforcement Service
371
23 Voice and Video
375
Wi-Fi Multimedia Traffic Management
376
Table 23- 1 WMM AC to 802.1P Priority Mapping
376
Table 23- 2 WMM AC-DSCP Mapping
377
Media Classification for Voice and Video Calls
380
Enabling Enhanced Voice Call Tracking
382
Table 23- 3 SNMP Trap Details for Voip Calls
382
24 Services
383
Configuring Airgroup
383
Multicast DNS and Bonjour® Services
384
DLNA Upnp Support
385
Airgroup Features
386
Airgroup Components
388
Table 24- 1 SCALANCE W, Clearpass Policy Manager, and Clearpass Guest Requirements
388
Configuring Airgroup and Airgroup Services on an AP
389
Table 24- 2 Airgroup Filtering Options
389
Configuring Airgroup and Clearpass Policy Manager Interface in SCALANCE W
393
Configuring an AP for RTLS Support
395
Configuring an AP for Analytics and Location Engine Support
397
Managing BLE Beacons
400
Configuring Opendns Credentials
402
Integrating an AP with Palo Alto Networks Firewall
403
Integrating an AP with an XML API Interface
406
Table 24- 3 XML API Command
407
Table 24- 4 XML API Command Options
408
CALEA Integration and Lawful Intercept Compliance
409
25 AP Management and Monitoring
417
Managing an AP from Airwave
417
Configuring Organization String
421
Alternate Method for Defining Vendor Specific DHCP Options
424
26 Uplink Configuration
425
Uplink Interfaces
425
Ethernet Uplink
426
Cellular Uplink
429
Wi-Fi Uplink
431
Uplink Preferences and Switching
434
Enforcing Uplinks
434
Setting an Uplink Priority
435
Enabling Uplink Preemption
435
Switching Uplinks Based on VPN and Internet Availability
436
Viewing Uplink Status and Configuration
438
27 Intrusion Detection
441
Detecting and Classifying Rouge Aps
441
OS Fingerprinting
442
Configuring Wireless Intrusion Protection and Detection Levels
443
Configuring IDS
448
28 Mesh AP Configuration
451
Mesh Network Overview
451
Setting up SCALANCE W Mesh Network
453
Configuring Wired Bridging on Ethernet 0 for Mesh Point
454
29 Mobility and Client Management
455
Layer-3 Mobility Overview
455
Configuring L3-Mobility
457
30 Spectrum Monitor
461
Understanding Spectrum Data
461
Configuring Spectrum Monitors and Hybrid Aps
467
31 AP Maintenance
471
Upgrading an AP
471
Backing up and Restoring AP Configuration Data
473
Converting an AP to a Remote AP and Campus AP
474
Resetting a Remote AP or Campus AP to an AP
478
Rebooting the AP
479
32 Monitoring Devices and Logs
481
Configuring SNMP
481
Configuring a Syslog Server
486
Configuring TFTP Dump Server
489
Running Debug Commands
490
Uplink Bandwidth Monitoring
495
33 Hotspot Profiles
497
Understanding Hotspot Profiles
497
Configuring Hotspot Profiles
500
Creating Advertisement Profiles for Hotspot Configuration
500
Creating a Hotspot Profile
509
Associating an Advertisement Profile to a Hotspot Profile
511
Creating a WLAN SSID and Associating Hotspot Profile
512
Sample Configuration
514
34 Clearpass Guest Setup
519
Configuring Clearpass Guest
519
Verifying Clearpass Guest Setup
526
Troubleshooting
527
35 AP-VPN Deployment Scenarios
529
Scenario 1 - Ipsec: Single Datacenter Deployment with no Redundancy
530
Scenario 2 - Ipsec: Single Datacenter with Multiple Controllers for Redundancy
535
Scenario 3 - Ipsec: Multiple Datacenter Deployment with Primary and Backup Controllers for Redundancy
541
Scenario 4 - GRE: Single Datacenter Deployment with no Redundancy
547
Appendix
553
Terms
553
Acronyms and Abbreviations
556
Glossary
566
4
Based on 1 rating
Ask a question
Give review
Questions and Answers:
Need help?
Do you have a question about the Siemens SCALANCE W1750D UI and is the answer not in the manual?
Ask a question
Siemens SCALANCE W1750D UI Specifications
General
Brand
Siemens
Model
SCALANCE W1750D UI
Category
Wireless Access Point
Language
English
Related product manuals
Siemens SCALANCE W1780
368 pages
Siemens SCALANCE W700
92 pages
Siemens SCALANCE W774-1
64 pages
Siemens SCALANCE W788-1
54 pages
Siemens SCALANCE W734-1
64 pages
Siemens SCALANCE W788-2PRO
274 pages
Siemens SCALANCE W788-2 M12
456 pages
Siemens SCALANCE W786-2 SFP
456 pages
Siemens SCALANCE W738-1 M12
77 pages
Siemens SCALANCE W734-1 RJ-45
78 pages
Siemens SCALANCE W748-1 RJ-45
456 pages
Siemens SCALANCE W786-1 RJ-45
456 pages