All language subtitles for 12. Cisco Wireless Architecture

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal) Download
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

In our next section we will talk about Cisco wireless infrastructure

let's start with the access point types and connecting to Cisco access point as Cisco wireless network

can consist of autonomously access points or light the way to access points that are coupled with one

or more wireless LAN controllers.

As you can see in the screen we have an autonomous API in here and we have the lightweight HP in here.

The autonomous AP is connected to a switched network wire at wrinkling and this lightweight AP is connected

to a switch lan mostly with an access link but lightweight AP is communicating with the wireless controller

also as you can see in here with cap wrap.

Okay.

After this brief information let's talk about in some more detail about these two types and autonomous

a access point is a standalone device and nothing else is needed to forward to Ethernet frames from

a wired we lend to a wireless LAN and vice versa.

In effect the AP maps each wheel then to a wireless LAN and the assess the autonomous AP has a single

wired Ethernet interface as shown in the left portion of fear and as I showed you.

Which means that multiple villains must be brought to it over at CERN Klink a lightweight AP also has

a single wide Internet interface.

However it must be paired with a wireless controller to be fully functional.

Why do we Lance that terminate at the wireless controller can be mapped to wireless local area network

that emerge at the access point even though multiple villains are being extended from the wireless controller

to the access point they are all carried over and they kept that tunnel between the two.

That means the access point needs only an access link to connect to the network infrastructure and terminate

its end of the tunnel.

As shown in the right portion of the figure.

So if you want to configure and manage Cisco access points you can connect to a serial console cable

from your P.C. to the console port of the access point once the access point is operational and has

an IP address.

You can also use 10 that or SSA to connect to it CLIA over the wired network autonomous APIs support

browser beach browser based management sessions via ETP and Asian shitty as you can manage the light

weight a piece from a browser session to the wireless controller

okay.

But how are we going to access to the Cisco wireless controller to connect to and configure Cisco wireless

controller.

You will need to open a web browser to the wireless controllers management to address with either ATP

or H2 G.P.S..

This can be done only after the wireless controller has an initial configuration and management IP address

assigned to its management interface.

The web based G UI provides an effective way to monitor configure and troubleshoot a wireless network.

You can also connect to Cisco wireless controller with an SSD each session where you can use it CLIA

to monitor configure and debug activity both the web based G U and the S.L. I require management users

to log in.

Users can be authenticated against an internal list of local user names or against an authentication

authorization and accounting through Apple a server such as tax plus or radius.

When you first open a web browser to the management address you will see the initial Logan's screen.

Once you click the logging button you can see in here once you click this button and then you enter

your credentials as you are prompted for them

when you successfully log in the wireless controller will display and monitoring dashboard similar to

the one you can see in the figure.

Guys you will not be able to make any configuration change here.

You must click on the advanced link a you can see it here to make some configuration changes.

And even here you can see some network summary and total wireless network counts how many access points

you have.

How many active clients do you have and some rogue IP information and interfere.

Is here also once you click the advanced button this will bring up the full wireless control or G you

I as shown in the figure you can select categories of functions from among in here.

You can also see that monitor wireless LAN controller wireless security management commands help and

feedback saw at the vertical list of functions at the left side of the screen and will change accordingly.

Once you select one of these options you can expand the list to entries if needed and select one to

work on the main screen area will display all of relevant fields and options.

You can edit as you make a configuration change.

So how we can connect to Cisco wireless control or let's talk in detail about this one.

So guys connecting a Cisco wireless LAN controller to the network is not quite as straight forward because

it has several different types of connections.

Control of ports are physical connections made to an external wired or switched network whereas interfaces

are logical connections made internally within the controller.

You can connect several different types of controller ports to your network.

As you can see in the screen so you can see here we have service part.

This port is used for out of pain management system recovery and initial built functions always come

next to a switch port in Access mode and we have also distribution ports in here then these ports are

used for all normal access point and management traffic and usually connect to a switch port in trying

so here is mostly trying.

And here is the access parts.

And we have also console port in here you can see that.

And this port is used for out bands of management system recovery and initial boot functions.

And we also have the redundancy port and that is used to connect to a pier controller for high availability

so let's go ahead with connecting to Cisco wireless controller through its distribution system ports.

A controller can connect to multiple villains on the switch network.

Internally the controller must somehow map those wide valence to actual and logical wireless networks

for example.

Guys.

So let's suppose that we land 10 is set aside for wireless users in the engineering division of the

company that we land must be connected to a unique wireless local area network that exists on air controller

and its associated access point the wireless local area network must then be extended to every client

that associates with the service set identifier and SS I.D. engineering.

So Cisco wireless controllers provide the necessary connectivity through internal logical interfaces

which must be configured with an IP address subnet mask default gateway and AD D.

Hey the HBP server each interface is then assigned to a physical port and we land I.D. You can't think

of an interface as Layer three termination of real long guys.

So Cisco controller support following interface types that you can see in screen also.

And the first one is the dynamic interface dynamic interface is used to connect to a villain to a violence

local area network.

You can see in here.

We also have the management interface.

You can see also in here and management the interface is used for normal management traffic such as

ready as user authentication web based and SSA sessions as an MP.

A.P. and so on the management the interface is also used to terminate kep tunnels between the controller

and it has access point.

And also we have the redundancy management interface and this is the management the IP address of a

redundant wireless controller.

That is part of our high availability pair of controllers the active wireless controller uses the management

the interface address while this thing by wireless controller uses the redundancy management address.

And we have also in here the service part interface and this interface is bound to the service port

and the used for out of bond management.

Also we also have the virtual interface and IP address facing wireless clients.

When controller is relaying climbed the H.S. peer requests performing client work authentication and

supporting client mobility and we also have the virtual interface which is the IP address facing wireless

clients when the controller is relaying client ACP requests performing client web authentication and

supporting client mobility

so let's talk about the configuring our wireless local area network and wireless local area network

controller and an access point work in concert to provide network connectivity to wireless clients from

a wireless perspective.

The AP advertises a service said identifier which is known as SSI I.D. for declined to join from a wide

perspective the controller connects to a virtual lan villain through one of its dynamic interfaces and

to complete the path between the SS I.D. and the villain as illustrated in the screen.

You must first define a wireless local area network on the controller

so let's go step by step how we can call for your local wireless local area network if your need wireless

local area network will use a security scheme that requires a radio server such as WPA WPA to enterprise

or WPA 3 enterprise you will need to define the server first guys and a unit to select.

You can see in here security triple A and the authentication and you need to click new

once you click the name you will go to the screen that you can create a new server.

And next you need to enter servers IP address firstly.

OK.

And shared scripts key and the port number if you already had two other radio servers configured the

server at two.

That 30 will be index number three as you can see in here.

Be sure to set these server status to enabled so that the controller can begin using it at the bottom

of the page.

Also guys you can see the type of user that will be authenticated with the server you can check the

network user to authenticate wireless clients or management to authenticate wireless administrators

that will access the controls management functions.

Then you need to click apply button in here to save your configuration.

The next step is creating a dynamic interface a dynamic interface is used to connect the controller

to every LAN on the wired network.

As I explained you before when you create a wireless LAN you will bind the dynamic interface to our

wireless network to create a new dynamic interface.

You navigate the controller and the interfaces and you just click the new button to define the new interface.

Then you enter and name as you can see in here the name is engineering and you just defined the villain

idea which is defined one hundred four days.

Example

next you need to enter the IP address subnet mask and Gateway address for the interface.

Okay.

You can see in here and they are all defined and also you should define primary and secondary DCP server

addresses that the controller will use when it relays the ACP requests from clients that are bound to

that interface.

And here is the DCP information defined as you can see in here.

Okay.

As a summary it is defined as an IP address with one hundred and ten and with a net mask with 255 255

255 that zero and Gateway is one hundred.

That that that that one and we have to DTP service and they are one that 17 and one that 18 once we

accomplish here we just can click apply to save our configuration.

Okay.

After creating the dynamic interface then step three is creating a new wireless local area network.

You can display a list of the currently defined wireless local area networks by selecting wireless local

area networks from the top menu bar in feed your abode.

The controller does not have any wireless local area networks defined already.

You can't create a new wireless local area network by selecting create new from the drop down menu and

then clicking the Go button.

OK next enter a descriptive name as the profile name and the SSA I.D. text string.

You can see all these definitions on the figure below and the profile name and SS I.D. are identical

and they are both set the engineering as you can see in here and this is just to keep things straight

forward.

The idea number is used as an index into the list of wireless local area networks that are defined on

the controller didn't next page will allow you to edit for categories of parameters corresponding to

the tops across the top.

As shown in the figure you can control whether the wireless local area network is enabled or disabled

with the status check box in here you can see the checkbox regarding the status.

And even though the general page shows a specific security policy word for the wireless local area network

you can make changes in a later step through these security tap and under read your policy you can see

that one here select the type of the radio that will offer the wireless local area network and by default

the wireless local area network will be offered on all radios that are joint with the controller and

next unit to select which of the controllers dynamic interfaces will be bumped to the wireless local

area network you can see in here we are binding the engineering right.

Okay.

The drop down list contains all the interfaces names that are available and a new engineering violence

local network will be bound to the engineering interface that we already created on our previous step

and finally use the broadcast to access ideas.

There is a box in here that you can check so I use the broadcast SSI the checkbox to select whether

a piece should broadcast the SSI Dean name in beacons they transmit broadcasting SSI I.D. is usually

more convenient for users because their devices can learn and displayed the SSI I.D. names automatically.

In fact most devices actually need the SS I.D. in the big beacons to understand and that the AP is still

available for that SS I.D. hiding the SS I.D. name by not broadcasting it.

I mean does not really provide any worthwhile security.

Instead it just prevents user devices from discovering an SS I.D. and trying to use it as a default

network.

And also lets go ahead with the security tab.

That is the 2nd tab and this is the place that you can configure the security sector settings as you

select a security type.

Be sure to remember which choices are types that have been deprecated or proven to be weak and avoid

them if possible further down the screen you can select which specific WPA wpa 2 and WPA 3 methods to

support on the wireless local area network.

You can select more than one if you need to support different types of wireless clients that require

several security methods and also in the screen.

WPA plus wpa 2 has been selected from the pull down menu then only wpa 2 and i e s and corruption have

been selected WPA and tiki T.K. IP have been avoided because they are legacy and deprecated methods

under the authentication key management section.

You can select the authentication methods the villain wireless local area network will use only appreciate.

Key has been selected in the figure so the wireless local area network will only WPA to personal with

the appreciate key authentication and the venue switch to the true police service tap.

You will have an option to define different radio servers for authentication will be used for W lan

authentication.

And here you can see that a 3 different ready servers are defined already and by default a controller

will contact a radio server from its management interface and you can overwrite this behavior by checking

the box next to radius so overwrite interface so that the controller sources reduce requests from the.

Dynamic interface that is associated with the W LAN and here is that option you can see.

The option in here OK.

OK.

Once you add change to the a curious a we can define some cure as parameters for our wireless local

area networks so you can simply select the cures tab to configure quality of service settings for the

wireless local area network as shown in the figure by default the controller will consider all frames

in the wireless local area network to be normal data to be handled in a best effort manner.

I mean you can't set the cure as drew up the menu to classify a classify all frames in one of the following

ways and they are platinum was gold video silver best effort and the bronze background finally you can

select the advanced tab to configure a variety of advanced wireless local area network settings as you

can see in the figure you can enable functions such as coverage hole detection peer to peer blocking

client exclusion client load limits and so on and so on.

Although most of the advanced settings are beyond the scope of the CCMA objectives you should be aware

of a few defaults that might affect your wireless clients so the first thing is here by default client

sessions with the wireless local area network are limited to one thousand and eight hundred seconds

which equals to 30 minutes.

Once the session time expires a client will be required to re authenticate this setting is controlled

by the enabled session time out checkbox and the timeout failed.

The controller maintains a set of security policies that are used to detect potentially malicious violence

clients as well.

If a client exhibits as certain behavior the controller can exclude it from the wireless local area

network for a period of time by default.

Again all clients are subject to the policies configured on their security wireless protection policies

and client exclusion block policies.

These policies include the excessive 810 to that eleven association failures eight hundred and two that

eleven authentication failures and 800 words and two that one ex authentication failures web authentication

failures and sorry and IP addresses theft or reuse or offending clients will be automatically excluded

or blocked for six seconds as a deterrent to attacks on the wireless network and finally when you are

satisfied with the settings in each of the wireless local area network configuration taps you can click

the play button in the upper right corner of the wireless local area network edit screen the wireless

local area network will be created and edit the controller configuration and in here you can see we

created any wireless local network and will an I.D. is w lan I.D. one type is wireless local area network

our profile name and they w lan SSI is set to engineering and admits that this is already enabled and

here is the security policies.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.