Netgear WC7500-Wireless User Manual - Page 122

Large WLAN Networks, Profile Naming Conventions, Considerations Before You Con Profiles

Page 122 highlights

ProSAFE Wireless Controller Large WLAN Networks For large network deployments that consist of different sets of WLAN networks, consider using the advanced configuration to create multiple profile groups. The access points that belong to the same profile group use the same WiFi, security, and QoS configurations. The wireless controller supports up to eight profile groups. Each profile group can provide its own WiFi, security, and QoS configurations. Each profile group can contain up to 16 profiles for a dual-band access point, or 8 profiles for a single-band access point. Using dual-band access points, the wireless controller could support a total of 128 profiles. Each profile provides its own SSID and can provide its own VLAN to allow the profile to establish its own tunnel. Profiles can also share the same VLAN. Also, in larger network deployments, you would assign guests to a separate VLAN because guests typically access only the Internet, not the business network, and are not allowed peer-to-peer access. Profile Naming Conventions You can use profile naming conventions that are based on user groups such as Marketing, or based on VLANs such as VLAN40, or you can use other naming conventions such as CompanyName15. Note: In the advanced configuration, you cannot change the names of profile groups. However, you can change the group names of MAC ACLs and external RADIUS servers. Considerations Before You Configure Profiles Before you create and configure profiles for the basic profile group or an advanced profile group, consider the following: • Authentication servers. If you want to use external LDAP or RADIUS authentication, or both, first configure the authentication server settings: - Configure basic server settings on the basic Authentication Server page (see Configure Basic Authentication Server Settings on page 142). - For more complex networks, configure additional RADIUS servers on the advanced Authentication Server page (see Configure a RADIUS Authentication Server Group on page 144). After you configure authentication server settings, you can then assign any authentication server to a security profile in a basic profile group or advanced profile group. Manage Security Profiles and Profile Groups 122

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398

Manage Security Profiles and Profile Groups
122
ProSAFE Wireless Controller
Large WLAN Networks
For large network deployments that consist of different sets of WLAN networks, consider
using the advanced configuration to create multiple profile groups. The access points that
belong to the same profile group use the same WiFi, security, and QoS configurations.
The wireless controller supports up to eight profile groups. Each profile group can provide its
own WiFi, security, and QoS configurations. Each profile group can contain up to 16 profiles
for a dual-band access point, or 8 profiles for a single-band access point. Using dual-band
access points, the wireless controller could support a total of 128 profiles. Each profile
provides its own SSID and can provide its own VLAN to allow the profile to establish its own
tunnel. Profiles can also share the same VLAN.
Also, in larger network deployments, you would assign guests to a separate VLAN because
guests typically access only the Internet, not the business network, and are not allowed
peer-to-peer access.
Profile Naming Conventions
You can use profile naming conventions that are based on user groups such as Marketing, or
based on VLANs such as VLAN40, or you can use other naming conventions such as
CompanyName15.
Note:
In the advanced configuration, you cannot change the names of
profile groups. However, you can change the group names of MAC
ACLs and external RADIUS servers.
Considerations Before You Configure Profiles
Before you create and configure profiles for the basic profile group or an advanced profile
group, consider the following:
Authentication servers
. If you want to use external LDAP or RADIUS authentication, or
both, first configure the authentication server settings:
-
Configure basic server settings on the basic Authentication Server page (see
Configure Basic Authentication Server Settings
on page 142).
-
For more complex networks, configure additional RADIUS servers on the advanced
Authentication Server page (see
Configure a RADIUS Authentication Server Group
on page 144).
After you configure authentication server settings, you can then assign any authentication
server to a security profile in a basic profile group or advanced profile group.