Example: Configuring a Virtual Access Point for WPA Enterprise and MAC Filtering (J-Web)
This example shows how to configure virtual access point vap-2 on radio 1 for access point ap-1 with the following settings:
- SSID: employee-only
- VLAN ID: 217
- Client security: WPA2 Enterprise, with both TKIP and CCMP ciphers, and pre-authentication
- RADIUS server IP address 192.211.1.254 and RADIUS shared secret sandia#978
- MAC filtering for denied MAC addresses 00:08:C7:1B:8C:02 and 01:23:45:67:89:ab
Before you configure an access point, you must specify the MAC address of the access point being configured. See AX411 Access Point Configuration Overview.
- Select Configure>Wireless LAN>Settings.
- Under AP Name, select ap-1.
- Under Radio ID, select radio 1, then click Edit.
- In the Edit - Radio window, select the Radio tab.
- Next to Virtual Access Points, click Add.
- In the Add - Virtual Access Point window, select the Basic Settings tab.
- Next to VAP ID, select 2.
- Next to SSID, enter employee-only.
- Next to VLAN ID, enter 217.
- Unselect HTTP Redirect.
- Select the Security tab.
- Next to MAC authentication type, select Local.
- Next to Security, select WPA Enterprise.
- Next to WPA Version, select v2.
- Next to Cipher suites, select both.
- Select Pre authenticate.
- Next to Radius server, enter 192.211.1.254.
- Next to Radius key, enter sandia#978.
- Click OK to return to the Edit - Radio window.
- Click OK to return to the Wlan Settings page.
- Under AP Name, select ap-1.
- In the Edit - Access Point window, select the MAC Filtering tab.
- Click Add.
- In the Add MAC Filter window, enter 00:08:C7:1B:8C:02, and click OK.
- Click Add.
- In the Add MAC Filter window, enter 01:23:45:67:89:ab, and click OK.
- For Action, select deny.
- Click OK.
Hide Navigation Pane
Show Navigation Pane
Download
SHA1