AP-VPN Deployment Scenarios
35.1 Scenario 1 - IPsec: Single Datacenter Deployment with No Redundancy
SCALANCE W1750D UI
Configuration Manual, 02/2018, C79000-G8976-C451-02
533
5. Create authentication servers for
user authentication. The example in
the next column assumes 802.1X
SSID.
(scalance)(config)# wlan auth-server serv-
er1
(scalance)(Auth Server "server1")# ip
10.2.2.1
(scalance)(Auth Server "server1")# port
1812
(scalance)(Auth Server "server1")# acctport
1813
(scalance)(Auth Server "server1")# key
"presharedkey"
(scalance)(Auth Server "server1")# exit
(scalance)(config)# wlan auth-server serv-
er2
(scalance)(Auth Server "server2")# ip
10.2.2.2
(scalance)(Auth Server "server2")# port
1812
(scalance)(Auth Server "server2")# acctport
1813
(scalance)(Auth Server "server2")# key
"presharedkey"
See Configuring an Exter-
nal Server for Authentica-
tion
6. Configure wired port and wireless
SSIDs using the authentication serv-
ers.
Configure wired ports to operate in L2 mode and
associate Centralized, L2 mode VLAN 20 to the
wired port profile.
(scalance)(config) # wired-port-profile
wired-port (scalance)(wired-port-profile
"wired-port")# switchport-mode access
(scalance)(wired-port-profile "wired-
port")# allowed-vlan all
(scalance)(wired-port-profile "wired-
port")# native-vlan 20
(scalance)(wired-port-profile "wired-
port")# no shutdown
(scalance)(wired-port-profile "wired-
port")# access-rule-name wired-port
(scalance)(wired-port-profile "wired-
port")# type employee
(scalance)(wired-port-profile "wired-
port")# auth- server server1
(scalance)(wired-port-profile "wired-
port")# auth- server server2
(scalance)(wired-port-profile "wired-
port")# dot1x (scalance)(wired-port-profile
"wired-port")# exit (scalance)(config)#
enet1-port-profile wired-port
Configure a wireless SSID to operate in L3 mode
and associate Distributed, L3 mode VLAN 30 to the
WLAN SSID profile.
(scalance)(config) # wlan ssid-profile
wireless- ssid
(scalance)(SSID Profile "wireless-ssid")#
enable (scalance)(SSID Profile "wireless-
ssid")# type employee
(scalance)(SSID Profile "wireless-ssid")#
essid wireless-ssid
(scalance)(SSID Profile "wireless-ssid")#
opmode wpa2-aes
(scalance)(SSID Profile "wireless-ssid")#
vlan 30 (scalance)(SSID Profile "wireless-
ssid")# auth- server server1
(scalance)(SSID Profile "wireless-ssid")#
auth- server server2
(scalance)(SSID Profile "wireless-ssid")#
See Configuring a Wired
Profile and Wireless Net-
work Profiles