Netgear WC7600 Reference Manual - Page 84

Large WLAN Networks, Profile Naming Conventions, Considerations Before You Con Profiles

Page 84 highlights

ProSAFE Wireless Controller WC7600 Large WLAN Networks For large network deployments that consist of different sets of WLAN networks, consider using the advanced configuration to create multiple profile groups. The access points that belong to the same profile group use the same wireless, security, and QoS configurations. The wireless controller supports up to eight profile groups. Each profile group can have its own wireless, security, and QoS configurations. Each profile group can contain up to 16 profiles for a dual-band access point, or eight profiles for a single-band access point. Using dual-band access points, the wireless controller could support a total of 128 profiles. Each profile has its own SSID and can have its own VLAN to allow the profile to establish its own tunnel. Profiles can also share the same VLAN. In larger network deployments also, you would assign guests to a separate VLAN because guests typically access only the Internet, not the business network, and do not have peer-to-peer access. Profile Naming Conventions You can use profile naming conventions that are based on user groups such as Marketing, or based on VLANs such as VLAN40, or you can use other naming conventions such as CompanyName15. Note: In the advanced configuration, you cannot change the names of profile groups. However, you can change the group names of MAC ACLs and external RADIUS servers. Considerations Before You Configure Profiles Before you create and configure profiles for the basic profile group or an advanced profile group, consider the following: • Authentication servers. If you want to use external LDAP or RADIUS authentication, or both, first configure the authentication server settings: - Configure basic server settings on the basic Authentication Server screen (see Configure Basic Authentication Server Settings on page 105). - For more complex networks, configure additional RADIUS servers on the advanced Authentication Server screen (see Configure a RADIUS Authentication Server Group on page 107). After you have configured authentication server settings, you can then assign any authentication server to a security profile in a basic profile group or advanced profile group. Manage Security Profiles and Profile Groups 84

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307

Manage Security Profiles and Profile Groups
84
ProSAFE Wireless Controller WC7600
Large WLAN Networks
For large network deployments that consist of different sets of WLAN networks, consider
using the advanced configuration to create multiple profile groups. The access points that
belong to the same profile group use the same wireless, security, and QoS configurations.
The wireless controller supports up to eight profile groups. Each profile group can have its
own wireless, security, and QoS configurations. Each profile group can contain up to
16
profiles for a dual-band access point, or eight profiles for a single-band access point.
Using dual-band access points, the wireless controller could support a total of 128 profiles.
Each profile has its own SSID and can have its own VLAN to allow the profile to establish its
own tunnel. Profiles can also share the same VLAN.
In larger network deployments also, you would assign guests to a separate VLAN because
guests typically access only the Internet, not the business network, and do not have
peer-to-peer access.
Profile Naming Conventions
You can use profile naming conventions that are based on user groups such as Marketing, or
based on VLANs such as VLAN40, or you can use other naming conventions such as
CompanyName15.
Note:
In the advanced configuration, you cannot change the names of
profile groups. However, you can change the group names of MAC
ACLs and external RADIUS servers.
Considerations Before You Configure Profiles
Before you create and configure profiles for the basic profile group or an advanced profile
group, consider the following:
Authentication servers
. If you want to use external LDAP or RADIUS authentication, or
both, first configure the authentication server settings:
-
Configure basic server settings on the basic Authentication Server screen (see
Configure Basic Authentication Server Settings
on page
105).
-
For more complex networks, configure additional RADIUS servers on the advanced
Authentication Server screen (see
Configure a RADIUS Authentication Server Group
on page
107).
After you have configured authentication server settings, you can then assign any
authentication server to a security profile in a basic profile group or advanced profile
group.