14
Copyright © 2011, Juniper Networks, Inc.
APPLICATION NOTE - Configuring and deploying the AX411 Wireless Access Point
The access request message contains the following attributes, which can be used by the rAdIus server to grant or
deny access to clients (in particular, note the access point MAC, IP address, and ssId info).
User-Name = “00-12-00-00-00-00”
User-Password = “NOPASSWORD”
NAS-IP-Address = 192.168.2.3
Called-Station-Id = “00-DE-AD-10-75-00:WifiNet”
Calling-Station-Id = “00-12-00-00-00-00”
NAS-Port-Type = Wireless-802.11
Connect-Info = “CONNECT 11Mbps 802.11b”
When using rAdIus authentication, it is important to remember that the rAdIus requests, originated from the
management address of each access point, must be permitted by the firewall policies.
Creating Multiple Wireless Networks using VAps
A requirement for many organizations is to segment their networks so a more granular access control can be enforced.
In this example, we will separate the network into two different zones. The Corporate zone, with a WifiNet ssId, will
enforce encryption using Wi-fi Protected Access (WPA) and rAdIus authentication. The guest zone, with a guest
ssId, will be open but will only allow hTTP and domain Name system (dNs) traffic to the Internet.
Two VAPs will be used, each with a single ssId and each associated to a VLAN. Traffic from clients associated to the
WifiNet ssId will be tagged using VLAN tag 2, while traffic for the guest network will be tagged with VLAN tag 3.
In order to provide a better channel management, each radio will be transmitting a single ssId. radio 1 will be
transmitting in the 2.4 ghz band advertising the guestNet ssId, while radio 2 will be transmitting in the 5 ghz band
advertising the WifiNet ssId.
Please note that it is also possible to configure both radios to advertise both ssIds simultaneously, if needed (as
previously noted, each radio can advertise up to 16 ssIds simultaneously).
Figure 7: using multiple VAps
INTERNET
OFFICE
ge-0/0/7.0 (trust)
192.198.254.1/24
Radius Server
192.168.254.2
Client
AP-1
00:de:ad:10:75:00
AP-2
00:de:ad:10:76:00
AP-3
00:de:ad:10:77:00
CorpNet and GuestNet SSIDs
Clients associated to CorpNet are tagged with VLAN tag 2
Clients associated to GuestNET are tagged with VLAN tag 3
SRX
Series
ge-0/0/0.0
(untrust)
198.0.0.1/24