25
What one selects under QoS depends to some extent on how the organisation otherwise supports
QoS in its network. The first QoS options are TOS (Type Of Service) values for IP tagging.
Unfortunately this tagging will apply to all clients in this WLAN and therefore in practice is not
applicable to eduroam. On the other hand, WMM depends on the relationship between the controller
(access point) and clients, and may provide measurable benefits for real-time applications, so “WMM
Policy Allowed” is recommended.
Under Advanced there are certain options to which one must give some thought, but as a rule these
are:
Allow AAA Override: Enabled – This makes it possible to let RADIUS override the VLAN
which has been assigned to the WLAN. In other words, a user of a different category is
assigned to another VLAN. Failure to override will result in the user being assigned to the
VLAN which is defined for the WLAN. In this way, it is possible to assign users to separate
VLANs depending on their class, such as employee, student or guest, without using different
wireless profiles.
Aironet IE: Enabled – Useful for those clients with this type of support.
P2P Blocking Action: Disabled – This determines whether wireless clients are able to
communicate directly with each other (via WLC) or not. For security reasons it is not
advisable to allow clients to do this, so we recommend “Disabled”, but it is up to each
organisation to consider this.
Содержание 4402 - Wireless LAN Controller
Страница 23: ...23 Security Layer 3 shall be None ...
Страница 36: ...36 A 4 Default VLAN Now go to SECURITY SSID Manager and specify the default VLAN ...
Страница 43: ...43 Create a Connection Request Policy for every connection this RADIUS server is to serve ...
Страница 60: ...More Best Practice Documents are available at www terena org campus bp campus bp announcements terena org ...