
Configure Tab
67
NXA-WAPZD1000 ZoneDirector Smart WLAN Controller
Assigning a WLAN Group to an AP
To assign a WLAN group to an Access Point:
1.
Go to Configure > Access Points.
2.
In the list of access points, find the MAC address of the AP that you want to assign to a WLAN group,
and then click Edit.
3.
In WLAN Group, select the WLAN group to which you want to assign the AP. You can only assign an AP
to a single WLAN group.
4.
Click OK to save your changes.
Deploying NXA-WAPZD1000 WLANs in a VLAN Environment
You can set up an NXA-WAPZD1000 wireless LAN as an extension of a VLAN network environment by
tagging wireless client and management traffic to specific VLANs. Qualifications include the following:
Verifying that the VLAN switch supports native VLANs. A native VLAN is a VLAN that allows
the user to designate untagged frames going in/out of a port to a specific VLAN.
For example, if an 802.1Q port has VLANs 2, 3, and 4 assigned to it with VLAN 2 being the Native
VLAN, frames on VLAN 2 that egress (exit) the port are not given an 802.1Q header (i.e., they are
plain Ethernet frames). Frames which ingress (enter) this port and have no 802.1Q header are put
into VLAN 2. Behavior of traffic relating to VLANs 3 and 4 is intuitive.
Connecting the NXA-WAPZD1000 and any Access Points (APs) to VLAN trunk ports in the
VLAN switch.
Verifying that those trunk ports are on the same native VLAN.
Tagging Management Traffic to a VLAN
Assigning management traffic to a specific management VLAN can provide benefits to the overall
performance and security of a network. If your network is designed to segment management traffic to a
specific VLAN, and you want to include the NXA-WAPZD1000’s AP management traffic in this VLAN, you
can set the parameters in the NXA-WAPZD1000 system configuration.
To assign ZD - AP management traffic to a management VLAN:
1.
Go to Configure > System.
2.
In Device IP Settings, enter the VLAN ID in the VLAN field.
3.
If you are using an additional management interface for the NXA-WAPZD1000, enter the same ID in the
VLAN field for the additional management interface.
4.
Click Apply to save your settings.
5.
Go to Configure > Access Points.
6.
In Access Point Policies, click the Enable with VLAN ID option next to Management VLAN, and enter the
VLAN ID in the field provided.
7.
Click Apply to save your settings.
All DNS, DHCP, ARP, and HTTP traffic from an unauthenticated wireless client will be
passed onto the NXA-WAPZD1000 from the AP via the management VLAN. If the
client belongs to a particular VLAN, the NXA-WAPZD1000 will add the corresponding
VLAN tag before passing traffic to the corresponding wired network. After client
authentication is performed, client traffic will directly go to the wired network from the
AP, which will add the corresponding VLAN tag. This explains why it is necessary to
configure tagged VLANs for all VLAN switch ports connecting to the NXA-
WAPZD1000 and APs.
Assigning management traffic to a VLAN makes automatic AP provisioning more
complicated, and should not be undertaken without a thorough understanding of your
own network configuration as well as the wireless deployment. You must also
configure any switches to pass VLAN traffic with the proper VLAN tags on the
relevant physical ports.
Summary of Contents for NXA-WAPZD1000
Page 4: ......
Page 12: ...viii NXA WAPZD1000 ZoneDirector Smart WLAN Controller Table of Contents ...
Page 16: ...Introduction 12 NXA WAPZD1000 ZoneDirector Smart WLAN Controller ...
Page 130: ...Blocking Client Devices 126 NXA WAPZD1000 ZoneDirector Smart WLAN Controller ...
Page 146: ...Smart Mesh Networking Best Practices 142 NXA WAPZD1000 ZoneDirector Smart WLAN Controller ...
Page 153: ...Troubleshooting 149 NXA WAPZD1000 ZoneDirector Smart WLAN Controller ...