26
Client Exclusion: Disabled – This is also a security feature. If, for example, a client fails to
authenticate itself a certain number of times, there will be a compulsory ban before the client
can try again. This can be more irritating than useful, so we recommend “Disabled”.
DHCP Server: No Override – Here it is possible to override the DHCP server which has been
configured for the virtual interface.
DHCP Addr. Assignment: Required – One can set a condition that clients must obtain an IP
address from a DHCP server: that is, a client is not permitted to define its own IP address
statically. Ideally this should be set to required, but experience has shown that this setting can
cause problems for some clients. In case of a temporary loss of connectivity, the controller will
require a renewal of DHCP address and some clients has problems with handling this situation.
Management Frame Protection (MFP) – Attempts to protect against DoS, man-in-the-
middle and dictionary attacks on the wireless network. To enable Client Protection, the clients
must support CCX (Cisco Compatible eXtension program).
After pressing “Apply”, this WLAN will be activated.
Содержание 4402 - Wireless LAN Controller
Страница 23: ...23 Security Layer 3 shall be None ...
Страница 36: ...36 A 4 Default VLAN Now go to SECURITY SSID Manager and specify the default VLAN ...
Страница 43: ...43 Create a Connection Request Policy for every connection this RADIUS server is to serve ...
Страница 60: ...More Best Practice Documents are available at www terena org campus bp campus bp announcements terena org ...