Cisco 4402 Configuration Guide - Page 25

Allow AAA Override: Enabled - supported access points

Page 25 highlights

What one selects under QoS depends to some extent on how the organisation otherwise supports QoS in its network. The first QoS options are TOS (Type Of Service) values for IP tagging. Unfortunately this tagging will apply to all clients in this WLAN and therefore in practice is not applicable to eduroam. On the other hand, WMM depends on the relationship between the controller (access point) and clients, and may provide measurable benefits for real-time applications, so "WMM Policy Allowed" is recommended. Under Advanced there are certain options to which one must give some thought, but as a rule these are: Allow AAA Override: Enabled - This makes it possible to let RADIUS override the VLAN which has been assigned to the WLAN. In other words, a user of a different category is assigned to another VLAN. Failure to override will result in the user being assigned to the VLAN which is defined for the WLAN. In this way, it is possible to assign users to separate VLANs depending on their class, such as employee, student or guest, without using different wireless profiles. Aironet IE: Enabled - Useful for those clients with this type of support. P2P Blocking Action: Disabled - This determines whether wireless clients are able to communicate directly with each other (via WLC) or not. For security reasons it is not advisable to allow clients to do this, so we recommend "Disabled", but it is up to each organisation to consider this. 25

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60

25
What one selects under QoS depends to some extent on how the organisation otherwise supports
QoS in its network. The first QoS options are TOS (Type Of Service) values for IP tagging.
Unfortunately this tagging will apply to
all
clients in this WLAN and therefore in practice is not
applicable to eduroam. On the other hand, WMM depends on the relationship between the controller
(access point) and clients, and may provide measurable benefits for real-time applications, so “WMM
Policy Allowed” is recommended.
Under
Advanced
there are certain options to which one must give some thought, but as a rule these
are:
Allow AAA Override: Enabled
– This makes it possible to let RADIUS
override the VLAN
which has been assigned to the WLAN.
In other words, a user of a different category is
assigned to another VLAN. Failure to override will result in the user being assigned to the
VLAN which is defined for the WLAN. In this way, it is possible to assign users to separate
VLANs depending on their class, such as employee, student or guest, without using different
wireless profiles.
Aironet IE: Enabled
– Useful for those clients with this type of support.
P2P Blocking Action: Disabled – This determines whether wireless clients are able to
communicate directly with each other (via WLC) or not.
For security reasons it is not
advisable to allow clients to do this, so we recommend “Disabled”, but it is up to each
organisation to consider this.