configuring xclaim waps for use with sonicwall

4
Objective: Test new wireless access points to verify they are VLAN capable and run according to spec on a SonicWALL Firewall. Setup Parameters: 1. Configure two SSIDs on WAPs (KD Test1 and KD Test2) and assign VLAN IDs as follows: 1 (Test1), 20 (Test2) 2. Setup KD Test1 SSID with connection to internal KD network (10.0.11.1 255.255.255.0 Subnet) 3. Setup KD Test2 SSID with connection to internet access only (10.0.12.1 255.255.255.0 Subnet) 4. Configure SonicWALL to accept VLAN IDs 1 and 20 (Allow VLAN 1 to have access to internal network, and VLAN 20 to have access to Internet only) Testing Parameters: 1. Connect to Test1 and ping server and Google.com 2. Connect to Test2 and ping server and Google.com Results should reflect that server is not accessible from Test2 but IS accessible from Test1. Configuration Steps for SonicWALL: 1. Configured X2 Interface on SonicWALL to add new LAN (10.0.11.1) Network > Interfaces > Configure Column for X2

Upload: colin-powell

Post on 22-Jan-2018

159 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: Configuring Xclaim WAPs for use with SonicWALL

Objective: Test new wireless access points to verify they are VLAN capable and run according to spec on a SonicWALL Firewall.

Setup Parameters:

1. Configure two SSIDs on WAPs (KD Test1 and KD Test2) and assign VLAN IDs as follows: 1 (Test1),

20 (Test2)

2. Setup KD Test1 SSID with connection to internal KD network (10.0.11.1 255.255.255.0 Subnet)

3. Setup KD Test2 SSID with connection to internet access only (10.0.12.1 255.255.255.0 Subnet)

4. Configure SonicWALL to accept VLAN IDs 1 and 20 (Allow VLAN 1 to have access to internal network, and VLAN 20 to have access to Internet only)

Testing Parameters:

1. Connect to Test1 and ping server and Google.com 2. Connect to Test2 and ping server and Google.com

Results should reflect that server is not accessible from Test2 but IS accessible from Test1.

Configuration Steps for SonicWALL:

1. Configured X2 Interface on

SonicWALL to add new LAN

(10.0.11.1) Network > Interfaces

> Configure Column for X2

Page 2: Configuring Xclaim WAPs for use with SonicWALL

2. Added VLAN for 10.0.12.1 network click Add Interface… and select your Zone as LAN, VLAN tag

as the VLAN ID you want (this one is 20) and select the Parent Interface as X2

3. Created 2 Dynamic DHCP Scopes and bound them to the X2 Subnet and the X2:V20 VLAN and

made them both start at 10.0.x.10 and end at 25 Network > DHCP Server > DHCP Server Lease

Scopes

Page 3: Configuring Xclaim WAPs for use with SonicWALL

4. Then, in order to make the VLAN not able to access internal resources, added a Firewall rule to

deny access to LAN subnets coming from X2:V20 Firewall > Matrix > (LAN > LAN)

Configuration steps for Xclaim Wireless Access Point:

Requirements: Wireless Device with iOS or Android and Xclaim Harmony App Installed

1. Unbox Xclaim Access Point and connect it using the provided PoE Injector NOTE: The Xclaim

device needs to be connected to the port you setup your two subnets on the SonicWALL (in this

example, the port X2 was used)

2. If the Xclaim has been used elsewhere (or has prior configurations on it) press and hold the

RESET button down for 15 seconds then release. (The reset process should take approximately 2

minutes to complete)

3. Use your wireless device and open your Xclaim Harmony Application (First time users of the App

should complete steps 4-7 , if you have finished setup, skip to step 8)

4. Tap Get Started

5. Create a password you can remember and tap next

6. Skip the SSID setup page (We will create the SSIDs later)

7. Tap Finish

8. Tap the WLANS tab and tap the Plus sign above it

9. Under SSID type in the first SSID you would like to setup (for this test Test1 was used)

Page 4: Configuring Xclaim WAPs for use with SonicWALL

10. Choose to broadcast the SSID (If you do not broadcast the SSID, you will need to remember it

EXACTLY as you typed it in)

11. If this is the internal network, make sure the VLAN ID is set to 1

12. Under Encryption, tap Secured

13. Type in the Enter Passphrase box, the password you want to use

14. Choose AES

15. Turn off Client Isolation (by default its turned off)

16. If you want to limit bandwidth on Uplink or Downlink (Upload or Download) then do so below

Client Isolation, if not tap the Floppy Drive icon at the top right

17. Once it is saved, tap the Plus sign again and complete steps 9-16 with the SSID, Password, and

VLAN ID for the second network (in this example Test2, Testing1!, and 20 were used)

18. Connect to the Xclaim WAP with your device (the SSID will broadcast as xclaim_setup)

19. Make sure you’re on the Access Points tab and tap Search for Access Points

20. Select the Access Point from the list

21. Name the Access Point (in this example, the name was WAP)

22. Type in a location for the WAP (this is optional)

23. You can change the settings of the radios for your wireless (in this example, the default values

were sufficient)

24. Scroll down to the bottom and choose your WLANS (tap once for both radios to broadcast or tap

more times to indicate 2.4 or 5GHz frequencies dependent on your environment. In this

example, Both Radios were chosen for both WLANS)

25. Once you have completed your configuration, tap the Floppy Disk icon on the top right to save.

NOTE: Once you save, it will kick you off the xclaim_setup WiFi and you will need to connect to

one of the SSIDs you setup on the WAP in order to configure it further

26. Give the Xclaim WAP about 5 minutes to fully configure the SSIDs and you will be good to go!

Connect up and test the internet connection to make sure it is configured properly. 27. Have some pie because this was tough! :D