Netgear WC7520 WC7520 Reference Manual - Page 24

DHCP Server, Client Authentication and Data Encryption, Client VLANs - radius

Page 24 highlights

ProSafe 20-AP Wireless Controller WC7520 Reference Manual Client VLANs Each authenticated wireless user is placed into a VLAN that determines the user's DHCP server, IP address, and layer 2 connection. Although you could place all authenticated wireless users into the single VLAN that is specified in the basic security profile, the wireless controller allows you to group wireless users into separate VLANs based on the wireless SSID to differentiate access to network resources. For example, you might place authorized employee users into one VLAN and itinerant users, such as contractors or guests, into a separate VLAN. To use different VLANs, you must create different security profiles. For information about how to configure regular VLANs, see Managing Wireless Security Profiles on page 83. DHCP Server The wireless controller can function as a DHCP server and assign IP addresses to both wireless and wired devices that are connected to it. You can add up to 64 DHCP server pools, each assigned to a different VLAN. Client Authentication and Data Encryption A user must authenticate to the WLAN to be able to access WLAN resources. The wireless controller supports several types of security methods, including those that require an external RADIUS or LDAP authentication server. The encryption option that you can select depends upon the authentication method that you have selected. The following table lists the authentication methods available, with their corresponding encryption options. Table 2. Authentication and Encryption Options Authentication Method Open system Shared Key Legacy 802.1x WPA-PSK WPA2-PSK WPA-PSK and WPA2-PSK WPA WPA2 WPA and WPA2 Encryption Option 64-bit, 128-bit, or 152-bit WEP 64-bit, 128-bit, or 152-bit WEP WEP TKIP or TKIP+AES AES or TKIP+AES TKIP+AES TKIP or TKIP+AES AES or TKIP+AES TKIP+AES Authentication Server None None Internal authentication server or external RADIUS server None None None Internal authentication server, external RADIUS server, or external AD server Internal authentication server, external RADIUS server, or external AD server Internal authentication server, external RADIUS server, or external AD server For information about how to configure client authentication and data encryption, see Managing Wireless Security Profiles on page 83. Chapter 2: System Planning and Deployment Scenarios | 24

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162

Chapter 2:
System Planning and Deployment Scenarios
|
24
ProSafe 20-AP Wireless Controller WC7520 Reference Manual
Client VLANs
Each authenticated wireless user is placed into a VLAN that determines the user’s DHCP
server, IP address, and layer 2 connection. Although you could place all authenticated
wireless users into the single VLAN that is specified in the basic security profile, the wireless
controller allows you to group wireless users into separate VLANs based on the wireless
SSID to differentiate access to network resources. For example, you might place authorized
employee users into one VLAN and itinerant users, such as contractors or guests, into a
separate VLAN. To use different VLANs, you must create different security profiles.
For information about how to configure regular VLANs, see
Managing Wireless Security
Profiles
on page 83.
DHCP Server
The wireless controller can function as a DHCP server and assign IP addresses to both
wireless and wired devices that are connected to it. You can add up to 64 DHCP server
pools, each assigned to a different VLAN.
Client Authentication and Data Encryption
A user must authenticate to the WLAN to be able to access WLAN resources. The wireless
controller supports several types of security methods, including those that require an external
RADIUS or LDAP authentication server.
The encryption option that you can select depends upon the authentication method that you
have selected. The following table lists the authentication methods available, with their
corresponding encryption options.
For information about how to configure client authentication and data encryption, see
Managing Wireless Security Profiles
on page 83.
Table 2.
Authentication and Encryption Options
Authentication Method
Encryption Option
Authentication Server
Open system
64-bit, 128-bit, or 152-bit WEP
None
Shared Key
64-bit, 128-bit, or 152-bit WEP
None
Legacy 802.1x
WEP
Internal authentication server or
external RADIUS server
WPA-PSK
TKIP or TKIP+AES
None
WPA2-PSK
AES or TKIP+AES
None
WPA-PSK and WPA2-PSK
TKIP+AES
None
WPA
TKIP or TKIP+AES
Internal authentication server, external
RADIUS server, or external AD server
WPA2
AES or TKIP+AES
Internal authentication server, external
RADIUS server, or external AD server
WPA and WPA2
TKIP+AES
Internal authentication server, external
RADIUS server, or external AD server