
l Access — Select this mode to allow the port to carry a single VLAN specified as the native VLAN.
l Trunk — Select this mode to allow the port to carry packets for multiple VLANs specified as allowed
VLANs.
b. Specify any of the following values for Client IP Assignment:
l Virtual Controller Assigned: Select this option to allow the Virtual Controller to assign IP addresses to
the wired clients. When the Virtual Controller assignment is used, the source IP address is translated for
all client traffic that goes through this interface. The Virtual Controller can also assign a guest VLAN to a
wired client.
l Network Assigned: Select this option to allow the clients to receive an IP address from the network to
which the Virtual Controller is connected. On selecting this option, the New button to create a VLAN is
displayed. Create a new VLAN if required.
c. If the Trunk mode is selected:
l Specify the Allowed VLAN, enter a list of comma separated digits or ranges 1,2,5 or 1-4, or all. The
Allowed VLAN refers to the VLANs carried by the port in Access mode.
l If Client IP Assignment is set the Network Assigned, specify a value for Native VLAN. A VLAN that
does not have a VLAN ID tag in the frames is referred to as Native VLAN. You can specify a value within
the range of 1-4093.
d. If the Access mode is selected:
l If the Client IP Assignment is set to Virtual Controller Assigned, proceed to step 2.
l If the Client IP Assignment is set the Network Assigned, specify a value for Access VLAN to indicate
the VLAN carried by the port in the Access mode.
2. Click Next. The Security tab details are displayed.
3. Configure security settings for the wired profile. For more information, see Configuring Security Settings for a
Wired Profile on page 104.
In the CLI
To configure VLAN settings for a wired profile:
(Instant Access Point)(config)# wired-port-profile <name>
(Instant Access Point)(wired ap profile <name>)# switchport-mode {<trunk> | <access>}
(Instant Access Point)(wired ap profile <name>)# allowed-vlan <vlan>
(Instant Access Point)(wired ap profile <name>)# native-vlan {<guest|1…4095>}
(Instant Access Point)(wired ap profile <name>)# end
(Instant Access Point)# commit apply
To configure a new VLAN assignment rule:
(Instant Access Point)(config)# wired-port-profile <name>
(Instant Access Point)(wired ap profile <name>)# set-vlan <attribute>{equals| not-equals| star
ts-with| ends-with| contains| matches-regular-expression} <operator> <VLAN-ID>| value-of}
(Instant Access Point)(wired ap profile <name>)# end
(Instant Access Point)# commit apply
Configuring Security Settings for a Wired Profile
If you are creating a new wired profile, complete the Wired Settings and VLAN procedures before specifying security
settings. For more information, see Configuring Wired Settings on page 102 and Configuring VLAN Settings for a
WLAN SSID Profile on page 89.
Configuring Security Settings for a Wired Employee Network
You can configure security parameters for an employee network by using the AOS-W Instant UI or CLI.
AOS-W Instant 6.3.1.1-4.0 | User Guide Wired Profiles | 104
Kommentare zu diesen Handbüchern