<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Wing 5.8, RFS7000, AP7532. Users disconnect and are asked to login again. in ExtremeWireless (WiNG)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-5-8-rfs7000-ap7532-users-disconnect-and-are-asked-to-login/m-p/54812#M3530</link>
    <description>I will do it and post the result. Thank you!&lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Wed, 23 Aug 2017 22:44:00 GMT</pubDate>
    <dc:creator>Vankman</dc:creator>
    <dc:date>2017-08-23T22:44:00Z</dc:date>
    <item>
      <title>Wing 5.8, RFS7000, AP7532. Users disconnect and are asked to login again.</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-5-8-rfs7000-ap7532-users-disconnect-and-are-asked-to-login/m-p/54808#M3526</link>
      <description>Hello,&lt;BR /&gt;
&lt;BR /&gt;
I'm learning   about as much wireless network as zebra equipments and I configured one   network with 2 ssid. After a long time I finally made it. The users   connect on both SSID, they go to internet and so on, but sometimes,   during not only roaming, they are disconnected and the system ask for   another authentication via Captive Portal.&lt;BR /&gt;
&lt;BR /&gt;
What could be wrong? &lt;BR /&gt;
Thanks a lot.&lt;BR /&gt;
&lt;BR /&gt;
!&lt;BR /&gt;
! Configuration of RFS7000 version 5.8.4.0-034R&lt;BR /&gt;
!&lt;BR /&gt;
!&lt;BR /&gt;
version 2.5&lt;BR /&gt;
!&lt;BR /&gt;
!&lt;BR /&gt;
client-identity-group default&lt;BR /&gt;
 load default-fingerprints&lt;BR /&gt;
!&lt;BR /&gt;
ip access-list BROADCAST-MULTICAST-CONTROL&lt;BR /&gt;
 permit tcp any any rule-precedence 10 rule-description "permit all TCP traffic"&lt;BR /&gt;
 permit udp any eq 67 any eq dhcpc rule-precedence 11 rule-description "permit DHCP replies"&lt;BR /&gt;
 deny udp any range 137 138 any range 137 138 rule-precedence 20 rule-description "deny windows netbios"&lt;BR /&gt;
 deny ip any 224.0.0.0/4 rule-precedence 21 rule-description "deny IP multicast"&lt;BR /&gt;
 deny ip any host 255.255.255.255 rule-precedence 22 rule-description "deny IP local broadcast"&lt;BR /&gt;
 permit ip any any rule-precedence 100 rule-description "permit all IP traffic"&lt;BR /&gt;
!&lt;BR /&gt;
mac access-list PERMIT-ARP-AND-IPv4&lt;BR /&gt;
 permit any any type ip rule-precedence 10 rule-description "permit all IPv4 traffic"&lt;BR /&gt;
 permit any any type arp rule-precedence 20 rule-description "permit all ARP traffic"&lt;BR /&gt;
!&lt;BR /&gt;
ip snmp-access-list default&lt;BR /&gt;
 permit any&lt;BR /&gt;
!&lt;BR /&gt;
firewall-policy default&lt;BR /&gt;
 no ip dos tcp-sequence-past-window&lt;BR /&gt;
!&lt;BR /&gt;
!&lt;BR /&gt;
mint-policy global-default&lt;BR /&gt;
!&lt;BR /&gt;
meshpoint-qos-policy default&lt;BR /&gt;
!&lt;BR /&gt;
wlan-qos-policy default&lt;BR /&gt;
 qos trust dscp&lt;BR /&gt;
 qos trust wmm&lt;BR /&gt;
!&lt;BR /&gt;
radio-qos-policy default&lt;BR /&gt;
!&lt;BR /&gt;
aaa-policy esaf01_AAA&lt;BR /&gt;
 authentication server 1 onboard controller&lt;BR /&gt;
 authentication server 1 proxy-mode through-controller&lt;BR /&gt;
 authentication server 1 dscp 46&lt;BR /&gt;
 accounting server 1 onboard controller&lt;BR /&gt;
!&lt;BR /&gt;
aaa-policy esaffuncionarios&lt;BR /&gt;
 authentication server 1 host 10.10.10.40 secret 0 XXXXXXXXXXX&lt;BR /&gt;
 authentication server 1 proxy-mode through-controller&lt;BR /&gt;
 accounting server 1 host 10.10.10.40 secret 0 XXXXXXXXXXX&lt;BR /&gt;
 accounting server 1 proxy-mode through-controller&lt;BR /&gt;
!&lt;BR /&gt;
dns-whitelist dns_listabranca&lt;BR /&gt;
 permit XXXXXXXXXXX.gov.br suffix&lt;BR /&gt;
!&lt;BR /&gt;
captive-portal Portal&lt;BR /&gt;
 access-time 720&lt;BR /&gt;
 inactivity-timeout 21600&lt;BR /&gt;
 server host 10.195.40.10&lt;BR /&gt;
 server mode centralized&lt;BR /&gt;
 simultaneous-users 2000&lt;BR /&gt;
 webpage internal org-name ESAF&lt;BR /&gt;
 webpage internal org-signature ESAF&lt;BR /&gt;
 webpage internal login footer Entre em contato com o administrador caso encontre algum problema.&lt;BR /&gt;
 webpage internal login main-logo XXXXXXXXXXX.br/imagens/logoesafidg.jpg&lt;BR /&gt;
 webpage internal login org-background-color #ffffff&lt;BR /&gt;
 webpage internal login org-font-color #003300&lt;BR /&gt;
 webpage internal login body-background-color #ffffff&lt;BR /&gt;
 webpage internal welcome main-logo XXXXXXXXXXXXX.br/imagens/logoesafidg.jpg&lt;BR /&gt;
 webpage internal welcome title Seja bem vindo&lt;BR /&gt;
 webpage internal fail header O acesso foi negado.&lt;BR /&gt;
 webpage internal fail main-logo XXXXXXXXXXXXX.br/imagens/logoesafidg.jpg&lt;BR /&gt;
 webpage internal fail title Falha&lt;BR /&gt;
 webpage internal agreement header Seja bem vindo&lt;BR /&gt;
 webpage internal agreement main-logo XXXXXXXXXXXXX.br/imagens/logoesafidg.jpg&lt;BR /&gt;
 webpage internal agreement title ESAF&lt;BR /&gt;
 webpage internal acknowledgement main-logo XXXXXXXXXXXXX.br/imagens/logoesafidg.jpg&lt;BR /&gt;
 webpage internal registration description Por favor encontre um momento para registrar-se.&lt;BR /&gt;
 webpage internal registration header Bem vindo&lt;BR /&gt;
 webpage internal registration main-logo XXXXXXXXXXXXX.br/imagens/logoesafidg.jpg&lt;BR /&gt;
 webpage internal no-service main-logo XXXXXXXXXXXXX.br/imagens/logoesafidg.jpg&lt;BR /&gt;
 accounting radius&lt;BR /&gt;
 use aaa-policy esaf01_AAA&lt;BR /&gt;
 use dns-whitelist dns_listabranca&lt;BR /&gt;
 webpage internal registration field city type text enable label "City" placeholder "Enter City"&lt;BR /&gt;
 webpage internal registration field street type text enable label "Address" placeholder "123 Any Street"&lt;BR /&gt;
 webpage internal registration field name type text enable label "Full Name" placeholder "Enter First Name, Last Name"&lt;BR /&gt;
 webpage internal registration field zip type number enable label "Zip" placeholder "Zip"&lt;BR /&gt;
 webpage internal registration field via-sms type checkbox enable title "SMS Preferred"&lt;BR /&gt;
 webpage internal registration field mobile type number enable label "Mobile" placeholder "Mobile Number with Country code"&lt;BR /&gt;
 webpage internal registration field age-range type dropdown-menu enable label "Age Range" title "Age Range"&lt;BR /&gt;
 webpage internal registration field email type e-address enable mandatory label "Email" placeholder &lt;BR /&gt;
 webpage internal registration field via-email type checkbox enable title "Email Preferred"&lt;BR /&gt;
!&lt;BR /&gt;
captive-portal PortalFuncionario&lt;BR /&gt;
 access-time 720&lt;BR /&gt;
 inactivity-timeout 21600&lt;BR /&gt;
 server host 10.195.37.2&lt;BR /&gt;
 server mode centralized&lt;BR /&gt;
 simultaneous-users 200&lt;BR /&gt;
 webpage internal org-name ESAF&lt;BR /&gt;
 webpage internal org-signature ESAF&lt;BR /&gt;
 webpage internal login description Conecte-se com nome e senha&lt;BR /&gt;
 webpage internal login footer Conecte-se com nome e senha&lt;BR /&gt;
 webpage internal login header Conecte-se com nome e senha&lt;BR /&gt;
 webpage internal login main-logo XXXXXXXXXXXXX.br/imagens/logoesafidg.jpg&lt;BR /&gt;
 webpage internal login main-logo use-as-banner&lt;BR /&gt;
 accounting radius&lt;BR /&gt;
 use aaa-policy esaffuncionarios&lt;BR /&gt;
 use dns-whitelist dns_listabranca&lt;BR /&gt;
 webpage internal registration field city type text enable label "City" placeholder "Enter City"&lt;BR /&gt;
 webpage internal registration field street type text enable label "Address" placeholder "123 Any Street"&lt;BR /&gt;
 webpage internal registration field name type text enable label "Full Name" placeholder "Enter First Name, Last Name"&lt;BR /&gt;
 webpage internal registration field zip type number enable label "Zip" placeholder "Zip"&lt;BR /&gt;
 webpage internal registration field via-sms type checkbox enable title "SMS Preferred"&lt;BR /&gt;
 webpage internal registration field mobile type number enable label "Mobile" placeholder "Mobile Number with Country code"&lt;BR /&gt;
 webpage internal registration field age-range type dropdown-menu enable label "Age Range" title "Age Range"&lt;BR /&gt;
 webpage internal registration field email type e-address enable mandatory label "Email" placeholder &lt;BR /&gt;
 webpage internal registration field via-email type checkbox enable title "Email Preferred"&lt;BR /&gt;
!&lt;BR /&gt;
wlan ESAF-01&lt;BR /&gt;
 description ESAF-Visitantes&lt;BR /&gt;
 shutdown&lt;BR /&gt;
 ssid ESAF-Visitantes&lt;BR /&gt;
 vlan 2074&lt;BR /&gt;
 bridging-mode local&lt;BR /&gt;
 encryption-type none&lt;BR /&gt;
 authentication-type none&lt;BR /&gt;
 no fast-bss-transition over-ds&lt;BR /&gt;
 use captive-portal Portal&lt;BR /&gt;
 captive-portal-enforcement&lt;BR /&gt;
 ip dhcp trust&lt;BR /&gt;
!&lt;BR /&gt;
wlan ESAFFuncionarios&lt;BR /&gt;
 description ESAF-Servidores&lt;BR /&gt;
 ssid ESAF-Funcionarios&lt;BR /&gt;
 vlan 2075&lt;BR /&gt;
 bridging-mode local&lt;BR /&gt;
 encryption-type none&lt;BR /&gt;
 authentication-type none&lt;BR /&gt;
 wireless-client inactivity-timeout 21600&lt;BR /&gt;
 wireless-client cred-cache-ageout 43200&lt;BR /&gt;
 wireless-client vlan-cache-ageout 43200&lt;BR /&gt;
 use aaa-policy esaffuncionarios&lt;BR /&gt;
 use captive-portal PortalFuncionario&lt;BR /&gt;
 captive-portal-enforcement&lt;BR /&gt;
 relay-agent dhcp-option82&lt;BR /&gt;
!&lt;BR /&gt;
wlan ESAFVISITANTES&lt;BR /&gt;
 ssid ESAF-Visitantes&lt;BR /&gt;
 vlan 2074&lt;BR /&gt;
 bridging-mode tunnel&lt;BR /&gt;
 encryption-type none&lt;BR /&gt;
 authentication-type none&lt;BR /&gt;
 wireless-client inactivity-timeout 21600&lt;BR /&gt;
 wireless-client cred-cache-ageout 43200&lt;BR /&gt;
 wireless-client vlan-cache-ageout 43200&lt;BR /&gt;
 wing-extensions move-command&lt;BR /&gt;
 wing-extensions scan-assist&lt;BR /&gt;
 wing-extensions ft-over-ds-aggregate&lt;BR /&gt;
 use aaa-policy esaf01_AAA&lt;BR /&gt;
 use captive-portal Portal&lt;BR /&gt;
 captive-portal-enforcement&lt;BR /&gt;
!&lt;BR /&gt;
smart-rf-policy smartrfbasico&lt;BR /&gt;
 group-by area&lt;BR /&gt;
!&lt;BR /&gt;
         auto-provisioning-policy aps-7532&lt;BR /&gt;
 adopt ap7532 precedence 1 profile AP-7532 rf-domain RF-SERPRO any  &lt;BR /&gt;
!&lt;BR /&gt;
radius-group Esaf01&lt;BR /&gt;
 guest&lt;BR /&gt;
 policy vlan 2074&lt;BR /&gt;
 policy ssid ESAF-Visitantes&lt;BR /&gt;
 policy day mo&lt;BR /&gt;
 policy day tu&lt;BR /&gt;
 policy day we&lt;BR /&gt;
 policy day th&lt;BR /&gt;
 policy day fr&lt;BR /&gt;
 policy day sa&lt;BR /&gt;
 policy day su&lt;BR /&gt;
!&lt;BR /&gt;
radius-group Esaf02&lt;BR /&gt;
 policy vlan 2074&lt;BR /&gt;
!&lt;BR /&gt;
radius-group helpdesk&lt;BR /&gt;
 policy access web&lt;BR /&gt;
 policy role helpdesk&lt;BR /&gt;
!&lt;BR /&gt;
radius-user-pool-policy visitante&lt;BR /&gt;
 user Esaf password 0 esaf group Esaf02&lt;BR /&gt;
 user helpdesk password 0 helpdesk group helpdesk&lt;BR /&gt;
 user esaf password 0 esaf group Esaf02&lt;BR /&gt;
!&lt;BR /&gt;
radius-server-policy radius-esaf&lt;BR /&gt;
 use radius-user-pool-policy visitante&lt;BR /&gt;
 use radius-group Esaf01&lt;BR /&gt;
!&lt;BR /&gt;
dhcp-server-policy DHCP-ESAF&lt;BR /&gt;
 dhcp-pool ESAF-VISITANTES&lt;BR /&gt;
  network 10.195.40.0/22&lt;BR /&gt;
  address range 10.195.40.50 10.195.43.254 &lt;BR /&gt;
  lease 0 14 26 40&lt;BR /&gt;
  default-router 10.195.40.1&lt;BR /&gt;
  dns-server  200.198.205.242 161.48.25.38&lt;BR /&gt;
 dhcp-pool ge&lt;BR /&gt;
  network 192.168.0.0/24&lt;BR /&gt;
  address range 192.168.0.100 192.168.0.120 &lt;BR /&gt;
 dhcp-pool ESAF&lt;BR /&gt;
  network 10.195.37.0/24&lt;BR /&gt;
  address range 10.195.37.10 10.195.37.254 &lt;BR /&gt;
  lease 0 14 26 40&lt;BR /&gt;
  default-router 10.195.37.1&lt;BR /&gt;
  dns-server  200.198.205.242 161.48.25.38&lt;BR /&gt;
 dhcp-pool APS&lt;BR /&gt;
  network 10.195.11.0/24&lt;BR /&gt;
  address range 10.195.11.111 10.195.11.130 &lt;BR /&gt;
  default-router 10.195.11.1&lt;BR /&gt;
  dns-server  10.12.1.16&lt;BR /&gt;
!&lt;BR /&gt;
!&lt;BR /&gt;
management-policy default&lt;BR /&gt;
 telnet&lt;BR /&gt;
 no http server&lt;BR /&gt;
 https server&lt;BR /&gt;
 ssh&lt;BR /&gt;
 user admin password 1 XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXx role superuser access all&lt;BR /&gt;
 user teste password 1 XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXx role web-user-admin &lt;BR /&gt;
 user helpdesk password 1 XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXx role helpdesk access web&lt;BR /&gt;
 snmp-server community 0 private rw&lt;BR /&gt;
 snmp-server community 0 public ro&lt;BR /&gt;
 snmp-server user snmptrap v3 encrypted des auth md5 0 senha00&lt;BR /&gt;
 snmp-server user snmpmanager v3 encrypted des auth md5 0 senha00&lt;BR /&gt;
 t5 snmp-server community public ro 192.168.0.1&lt;BR /&gt;
 t5 snmp-server community private rw 192.168.0.1&lt;BR /&gt;
 idle-session-timeout 300&lt;BR /&gt;
!&lt;BR /&gt;
ex3500-management-policy default&lt;BR /&gt;
 snmp-server community public ro&lt;BR /&gt;
 snmp-server community private rw&lt;BR /&gt;
 snmp-server notify-filter 1 remote 127.0.0.1&lt;BR /&gt;
 snmp-server view defaultview 1 included&lt;BR /&gt;
!&lt;BR /&gt;
ex3500-qos-class-map-policy default&lt;BR /&gt;
!&lt;BR /&gt;
ex3500-qos-policy-map default&lt;BR /&gt;
!&lt;BR /&gt;
l2tpv3 policy default&lt;BR /&gt;
!&lt;BR /&gt;
profile rfs7000 default-rfs7000&lt;BR /&gt;
 bridge vlan 100&lt;BR /&gt;
  ip igmp snooping&lt;BR /&gt;
  ip igmp snooping querier&lt;BR /&gt;
  ipv6 mld snooping&lt;BR /&gt;
  ipv6 mld snooping querier&lt;BR /&gt;
 ip default-gateway 10.195.40.1&lt;BR /&gt;
 autoinstall configuration&lt;BR /&gt;
 autoinstall firmware&lt;BR /&gt;
 use radius-server-policy radius-esaf&lt;BR /&gt;
 crypto ikev1 policy ikev1-default &lt;BR /&gt;
  isakmp-proposal default encryption aes-256 group 2 hash sha &lt;BR /&gt;
 crypto ikev2 policy ikev2-default &lt;BR /&gt;
  isakmp-proposal default encryption aes-256 group 2 hash sha &lt;BR /&gt;
 crypto ipsec transform-set default esp-aes-256 esp-sha-hmac&lt;BR /&gt;
 crypto ikev1 remote-vpn&lt;BR /&gt;
 crypto ikev2 remote-vpn&lt;BR /&gt;
 crypto auto-ipsec-secure&lt;BR /&gt;
 crypto remote-vpn-client&lt;BR /&gt;
 interface me1&lt;BR /&gt;
 interface ge1&lt;BR /&gt;
  switchport mode trunk&lt;BR /&gt;
  switchport trunk native vlan 1&lt;BR /&gt;
  switchport trunk native tagged&lt;BR /&gt;
  switchport trunk allowed vlan 1,100&lt;BR /&gt;
 interface ge2&lt;BR /&gt;
  switchport mode access&lt;BR /&gt;
  switchport access vlan 100&lt;BR /&gt;
 interface ge3&lt;BR /&gt;
 interface ge4&lt;BR /&gt;
 interface vlan1&lt;BR /&gt;
  description Esaf01&lt;BR /&gt;
 interface pppoe1&lt;BR /&gt;
 use dhcp-server-policy DHCP-ESAF&lt;BR /&gt;
 use firewall-policy default&lt;BR /&gt;
 use auto-provisioning-policy aps-7532&lt;BR /&gt;
 use captive-portal server Portal&lt;BR /&gt;
 logging on&lt;BR /&gt;
 service pm sys-restart&lt;BR /&gt;
 router ospf&lt;BR /&gt;
!&lt;BR /&gt;
profile ap8533 default-ap8533&lt;BR /&gt;
 autoinstall configuration&lt;BR /&gt;
 autoinstall firmware&lt;BR /&gt;
 crypto ikev1 policy ikev1-default &lt;BR /&gt;
  isakmp-proposal default encryption aes-256 group 2 hash sha &lt;BR /&gt;
 crypto ikev2 policy ikev2-default &lt;BR /&gt;
  isakmp-proposal default encryption aes-256 group 2 hash sha &lt;BR /&gt;
 crypto ipsec transform-set default esp-aes-256 esp-sha-hmac&lt;BR /&gt;
 crypto ikev1 remote-vpn&lt;BR /&gt;
 crypto ikev2 remote-vpn&lt;BR /&gt;
 crypto auto-ipsec-secure&lt;BR /&gt;
 crypto load-management&lt;BR /&gt;
 crypto remote-vpn-client&lt;BR /&gt;
 interface radio1&lt;BR /&gt;
 interface radio2&lt;BR /&gt;
 interface radio3&lt;BR /&gt;
 interface bluetooth1&lt;BR /&gt;
  shutdown&lt;BR /&gt;
 interface ge1&lt;BR /&gt;
 interface ge2&lt;BR /&gt;
 interface vlan1&lt;BR /&gt;
  ip address dhcp&lt;BR /&gt;
  ip address zeroconf secondary&lt;BR /&gt;
  ip dhcp client request options all&lt;BR /&gt;
 interface pppoe1&lt;BR /&gt;
 use firewall-policy default&lt;BR /&gt;
 use client-identity-group default&lt;BR /&gt;
 logging on&lt;BR /&gt;
 service pm sys-restart&lt;BR /&gt;
 router ospf&lt;BR /&gt;
!&lt;BR /&gt;
profile ap82xx default-ap82xx&lt;BR /&gt;
 autoinstall configuration&lt;BR /&gt;
 autoinstall firmware&lt;BR /&gt;
 crypto ikev1 policy ikev1-default &lt;BR /&gt;
  isakmp-proposal default encryption aes-256 group 2 hash sha &lt;BR /&gt;
 crypto ikev2 policy ikev2-default &lt;BR /&gt;
  isakmp-proposal default encryption aes-256 group 2 hash sha &lt;BR /&gt;
 crypto ipsec transform-set default esp-aes-256 esp-sha-hmac&lt;BR /&gt;
 crypto ikev1 remote-vpn&lt;BR /&gt;
 crypto ikev2 remote-vpn&lt;BR /&gt;
 crypto auto-ipsec-secure&lt;BR /&gt;
 crypto remote-vpn-client&lt;BR /&gt;
 interface radio1&lt;BR /&gt;
 interface radio2&lt;BR /&gt;
 interface radio3&lt;BR /&gt;
 interface ge1&lt;BR /&gt;
 interface ge2&lt;BR /&gt;
 interface vlan1&lt;BR /&gt;
  ip address dhcp&lt;BR /&gt;
  ip address zeroconf secondary&lt;BR /&gt;
  ip dhcp client request options all&lt;BR /&gt;
 interface wwan1&lt;BR /&gt;
 interface pppoe1&lt;BR /&gt;
 use firewall-policy default&lt;BR /&gt;
 use client-identity-group default&lt;BR /&gt;
 logging on&lt;BR /&gt;
 service pm sys-restart&lt;BR /&gt;
 router ospf&lt;BR /&gt;
!&lt;BR /&gt;
profile ap81xx default-ap81xx&lt;BR /&gt;
 autoinstall configuration&lt;BR /&gt;
 autoinstall firmware&lt;BR /&gt;
 crypto ikev1 policy ikev1-default &lt;BR /&gt;
  isakmp-proposal default encryption aes-256 group 2 hash sha &lt;BR /&gt;
 crypto ikev2 policy ikev2-default &lt;BR /&gt;
  isakmp-proposal default encryption aes-256 group 2 hash sha &lt;BR /&gt;
 crypto ipsec transform-set default esp-aes-256 esp-sha-hmac&lt;BR /&gt;
 crypto ikev1 remote-vpn&lt;BR /&gt;
 crypto ikev2 remote-vpn&lt;BR /&gt;
 crypto auto-ipsec-secure&lt;BR /&gt;
 crypto remote-vpn-client&lt;BR /&gt;
 interface radio1&lt;BR /&gt;
 interface radio2&lt;BR /&gt;
 interface radio3&lt;BR /&gt;
 interface bluetooth1&lt;BR /&gt;
  shutdown&lt;BR /&gt;
 interface ge1&lt;BR /&gt;
 interface ge2&lt;BR /&gt;
 interface vlan1&lt;BR /&gt;
  ip address dhcp&lt;BR /&gt;
  ip address zeroconf secondary&lt;BR /&gt;
  ip dhcp client request options all&lt;BR /&gt;
 interface wwan1&lt;BR /&gt;
 interface pppoe1&lt;BR /&gt;
 use firewall-policy default&lt;BR /&gt;
 use client-identity-group default&lt;BR /&gt;
 logging on&lt;BR /&gt;
 service pm sys-restart&lt;BR /&gt;
 router ospf&lt;BR /&gt;
!&lt;BR /&gt;
profile ap7532 AP-7532&lt;BR /&gt;
 bridge vlan 1&lt;BR /&gt;
  ip igmp snooping&lt;BR /&gt;
  ip igmp snooping querier&lt;BR /&gt;
  ipv6 mld snooping&lt;BR /&gt;
  ipv6 mld snooping querier&lt;BR /&gt;
 bridge vlan 10&lt;BR /&gt;
  ip igmp snooping&lt;BR /&gt;
  ip igmp snooping querier&lt;BR /&gt;
  ipv6 mld snooping&lt;BR /&gt;
  ipv6 mld snooping querier&lt;BR /&gt;
 bridge vlan 100&lt;BR /&gt;
  use captive-portal Portal&lt;BR /&gt;
  ip igmp snooping&lt;BR /&gt;
  ip igmp snooping querier&lt;BR /&gt;
  ipv6 mld snooping&lt;BR /&gt;
  ipv6 mld snooping querier&lt;BR /&gt;
 ip name-server 10.12.1.16&lt;BR /&gt;
 ip name-server 8.8.8.8&lt;BR /&gt;
 ip name-server 4.2.2.2&lt;BR /&gt;
 ip default-gateway 10.195.40.1&lt;BR /&gt;
 no autoinstall configuration&lt;BR /&gt;
 no autoinstall firmware&lt;BR /&gt;
 use radius-server-policy radius-esaf&lt;BR /&gt;
 crypto ikev1 policy ikev1-default &lt;BR /&gt;
  isakmp-proposal default encryption aes-256 group 2 hash sha &lt;BR /&gt;
 crypto ikev2 policy ikev2-default &lt;BR /&gt;
  isakmp-proposal default encryption aes-256 group 2 hash sha &lt;BR /&gt;
 crypto ipsec transform-set default esp-aes-256 esp-sha-hmac&lt;BR /&gt;
 crypto ikev1 remote-vpn&lt;BR /&gt;
 crypto ikev2 remote-vpn&lt;BR /&gt;
 crypto auto-ipsec-secure&lt;BR /&gt;
 crypto load-management&lt;BR /&gt;
 crypto remote-vpn-client&lt;BR /&gt;
 interface radio1&lt;BR /&gt;
  wlan ESAF-01 bss 1 primary&lt;BR /&gt;
  wlan ESAFVISITANTES bss 2 primary&lt;BR /&gt;
  wlan ESAFFuncionarios bss 3 primary&lt;BR /&gt;
 interface radio2&lt;BR /&gt;
  wlan ESAF-01 bss 1 primary&lt;BR /&gt;
  wlan ESAFVISITANTES bss 2 primary&lt;BR /&gt;
  wlan ESAFFuncionarios bss 3 primary&lt;BR /&gt;
 interface ge1&lt;BR /&gt;
  switchport mode trunk&lt;BR /&gt;
  switchport trunk native vlan 1&lt;BR /&gt;
  switchport trunk native tagged&lt;BR /&gt;
  switchport trunk allowed vlan 1,11,2074-2075&lt;BR /&gt;
 interface vlan1&lt;BR /&gt;
 interface vlan11&lt;BR /&gt;
  description Gerencia&lt;BR /&gt;
  ip address dhcp&lt;BR /&gt;
 interface vlan2074&lt;BR /&gt;
  description Vlan_rede_visitantes&lt;BR /&gt;
 interface vlan2075&lt;BR /&gt;
  description Vlan_rede_funcionarios&lt;BR /&gt;
 interface pppoe1&lt;BR /&gt;
 use dhcp-server-policy DHCP-ESAF&lt;BR /&gt;
 use firewall-policy default&lt;BR /&gt;
 use captive-portal server Portal&lt;BR /&gt;
 use captive-portal server PortalFuncionario&lt;BR /&gt;
 logging on&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
 service pm sys-restart&lt;BR /&gt;
 router ospf&lt;BR /&gt;
!&lt;BR /&gt;
profile ap7532 PROFILE-AP7532&lt;BR /&gt;
 no autoinstall configuration&lt;BR /&gt;
 no autoinstall firmware&lt;BR /&gt;
 crypto ikev1 policy ikev1-default &lt;BR /&gt;
  isakmp-proposal default encryption aes-256 group 2 hash sha &lt;BR /&gt;
 crypto ikev2 policy ikev2-default &lt;BR /&gt;
  isakmp-proposal default encryption aes-256 group 2 hash sha &lt;BR /&gt;
 crypto ipsec transform-set default esp-aes-256 esp-sha-hmac&lt;BR /&gt;
 crypto ikev1 remote-vpn&lt;BR /&gt;
 crypto ikev2 remote-vpn&lt;BR /&gt;
 crypto auto-ipsec-secure&lt;BR /&gt;
 crypto load-management&lt;BR /&gt;
 crypto remote-vpn-client&lt;BR /&gt;
 interface radio1&lt;BR /&gt;
 interface radio2&lt;BR /&gt;
 interface ge1&lt;BR /&gt;
 interface vlan11&lt;BR /&gt;
  ip address dhcp&lt;BR /&gt;
 interface pppoe1&lt;BR /&gt;
 use firewall-policy default&lt;BR /&gt;
 controller host 10.195.11.100&lt;BR /&gt;
 service pm sys-restart&lt;BR /&gt;
 router ospf&lt;BR /&gt;
!&lt;BR /&gt;
&lt;BR /&gt;
rf-domain RF-SERPRO&lt;BR /&gt;
 location ESAF&lt;BR /&gt;
 contact Serpro&lt;BR /&gt;
 timezone America/Sao_Paulo&lt;BR /&gt;
 country-code br&lt;BR /&gt;
 use smart-rf-policy smartrfbasico&lt;BR /&gt;
 controller-managed&lt;BR /&gt;
!&lt;BR /&gt;
rfs7000 5C-0E-8B-1A-45-26&lt;BR /&gt;
 use profile default-rfs7000&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname rfs7000-1A4526&lt;BR /&gt;
 layout-coordinates 3.0 2.5&lt;BR /&gt;
 license AP 65b47071ef2b3f0237c8f5ff63b4589f1cff782846631007ef3878466f287e8a4745e462a14cae5d&lt;BR /&gt;
 ip default-gateway 10.195.11.1&lt;BR /&gt;
 interface me1&lt;BR /&gt;
  ip address dhcp&lt;BR /&gt;
 interface ge1&lt;BR /&gt;
  switchport mode trunk&lt;BR /&gt;
  switchport trunk native vlan 1&lt;BR /&gt;
  switchport trunk native tagged&lt;BR /&gt;
  switchport trunk allowed vlan 1,10-11,2074-2075&lt;BR /&gt;
 interface ge2&lt;BR /&gt;
  switchport mode access&lt;BR /&gt;
  switchport access vlan 11&lt;BR /&gt;
 interface vlan1&lt;BR /&gt;
  ip address 192.168.10.1/24&lt;BR /&gt;
 interface vlan11&lt;BR /&gt;
  description Gerencia&lt;BR /&gt;
  ip address 10.195.11.100/24&lt;BR /&gt;
 interface vlan2074&lt;BR /&gt;
  description wifi_visitantes&lt;BR /&gt;
  ip address 10.195.40.10/22&lt;BR /&gt;
 interface vlan2075&lt;BR /&gt;
  description wifi_funcionarios&lt;BR /&gt;
  ip address 10.195.37.2/24&lt;BR /&gt;
 logging syslog debugging&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-26-44&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-032644&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-26-48&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-032648&lt;BR /&gt;
 interface ge1&lt;BR /&gt;
  switchport mode trunk&lt;BR /&gt;
  switchport trunk native vlan 1&lt;BR /&gt;
  switchport trunk native tagged&lt;BR /&gt;
  switchport trunk allowed vlan 1,11,2074-2075&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
 controller vlan 11&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-26-9C&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-03269C&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-26-A4&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-0326A4&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-26-B4&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-0326B4&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-28-78&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-032878&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-28-B0&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-0328B0&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-28-D8&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-0328D8&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-37-18&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-033718&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-37-1C&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-03371C&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-37-20&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-033720&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-37-C0&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-0337C0&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-37-E0&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-0337E0&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-37-E8&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-0337E8&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-38-08&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-033808&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-38-34&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-033834&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-38-54&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-033854&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-38-80&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-033880&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-3D-BC&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-033DBC&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
!&lt;BR /&gt;
ap7532 74-67-F7-03-3E-F0&lt;BR /&gt;
 use profile AP-7532&lt;BR /&gt;
 use rf-domain RF-SERPRO&lt;BR /&gt;
 hostname ap7532-033EF0&lt;BR /&gt;
 interface vlan11&lt;BR /&gt;
  ip address 10.195.11.110/24&lt;BR /&gt;
 controller host 10.195.11.100 pool 1 level 1&lt;BR /&gt;
!&lt;BR /&gt;
!&lt;BR /&gt;
end&lt;BR /&gt;
&lt;BR /&gt;
AP7532&lt;BR /&gt;
&lt;BR /&gt;
!&lt;BR /&gt;
! Configuration of AP7532 version 5.8.4.0-034R&lt;BR /&gt;
!&lt;BR /&gt;
!&lt;BR /&gt;
version 2.5&lt;BR /&gt;
!&lt;BR /&gt;
!&lt;BR /&gt;
ip snmp-access-list default&lt;BR /&gt;
 permit any&lt;BR /&gt;
!&lt;BR /&gt;
firewall-policy default&lt;BR /&gt;
 no ip dos tcp-sequence-past-window&lt;BR /&gt;
!&lt;BR /&gt;
!&lt;BR /&gt;
mint-policy global-default&lt;BR /&gt;
!&lt;BR /&gt;
wlan-qos-policy default&lt;BR /&gt;
 qos trust dscp&lt;BR /&gt;
 qos trust wmm&lt;BR /&gt;
!&lt;BR /&gt;
radio-qos-policy default&lt;BR /&gt;
!&lt;BR /&gt;
aaa-policy esaf01_AAA&lt;BR /&gt;
 authentication server 1 onboard controller&lt;BR /&gt;
 authentication server 1 proxy-mode through-controller&lt;BR /&gt;
 authentication server 1 dscp 46&lt;BR /&gt;
 accounting server 1 onboard controller&lt;BR /&gt;
!&lt;BR /&gt;
aaa-policy esaffuncionarios&lt;BR /&gt;
 authentication server 1 host 10.10.10.40 secret 0 XXXXXXXXXXXXXXXXXX&lt;BR /&gt;
 authentication server 1 proxy-mode through-controller&lt;BR /&gt;
 accounting server 1 host 10.10.10.40 secret 0 XXXXXXXXXXXXXXXXX&lt;BR /&gt;
 accounting server 1 proxy-mode through-controller&lt;BR /&gt;
!&lt;BR /&gt;
dns-whitelist dns_listabranca&lt;BR /&gt;
 permit XXXXXXXXXXXXX suffix&lt;BR /&gt;
!&lt;BR /&gt;
captive-portal Portal&lt;BR /&gt;
 access-time 720&lt;BR /&gt;
 inactivity-timeout 21600&lt;BR /&gt;
 server host 10.195.40.10&lt;BR /&gt;
 server mode centralized&lt;BR /&gt;
 simultaneous-users 2000&lt;BR /&gt;
 webpage internal org-name ESAF&lt;BR /&gt;
 webpage internal org-signature ESAF&lt;BR /&gt;
 webpage internal login footer Entre em contato com o administrador caso encontre algum problema.&lt;BR /&gt;
 webpage internal login main-logo XXXXXXXXXXXXX.br/imagens/logoesafidg.jpg&lt;BR /&gt;
 webpage internal login org-background-color #ffffff&lt;BR /&gt;
 webpage internal login org-font-color #003300&lt;BR /&gt;
 webpage internal login body-background-color #ffffff&lt;BR /&gt;
 webpage internal welcome main-logo XXXXXXXXXXXXX.br/imagens/logoesafidg.jpg&lt;BR /&gt;
 webpage internal welcome title Seja bem vindo&lt;BR /&gt;
 webpage internal fail header O acesso foi negado.&lt;BR /&gt;
 webpage internal fail main-logo XXXXXXXXXXXXX.br/imagens/logoesafidg.jpg&lt;BR /&gt;
 webpage internal fail title Falha&lt;BR /&gt;
 webpage internal agreement header Seja bem vindo&lt;BR /&gt;
 webpage internal agreement main-logo XXXXXXXXXXXXX.br/imagens/logoesafidg.jpg&lt;BR /&gt;
 webpage internal agreement title ESAF&lt;BR /&gt;
 webpage internal acknowledgement main-logo XXXXXXXXXXXXX.br/imagens/logoesafidg.jpg&lt;BR /&gt;
 webpage internal registration description Por favor encontre um momento para registrar-se.&lt;BR /&gt;
 webpage internal registration header Bem vindo&lt;BR /&gt;
 webpage internal registration main-logo XXXXXXXXXXXXX.br/imagens/logoesafidg.jpg&lt;BR /&gt;
 webpage internal no-service main-logo XXXXXXXXXXXXX.br/imagens/logoesafidg.jpg&lt;BR /&gt;
 accounting radius&lt;BR /&gt;
 use aaa-policy esaf01_AAA&lt;BR /&gt;
 use dns-whitelist dns_listabranca&lt;BR /&gt;
 webpage internal registration field city type text enable label "City" placeholder "Enter City"&lt;BR /&gt;
 webpage internal registration field street type text enable label "Address" placeholder "123 Any Street"&lt;BR /&gt;
 webpage internal registration field name type text enable label "Full Name" placeholder "Enter First Name, Last Name"&lt;BR /&gt;
 webpage internal registration field zip type number enable label "Zip" placeholder "Zip"&lt;BR /&gt;
 webpage internal registration field via-sms type checkbox enable title "SMS Preferred"&lt;BR /&gt;
 webpage internal registration field mobile type number enable label "Mobile" placeholder "Mobile Number with Country code"&lt;BR /&gt;
 webpage internal registration field age-range type dropdown-menu enable label "Age Range" title "Age Range"&lt;BR /&gt;
 webpage internal registration field email type e-address enable mandatory label "Email" placeholder "youdomain.com"&lt;BR /&gt;
 webpage internal registration field via-email type checkbox enable title "Email Preferred"&lt;BR /&gt;
!&lt;BR /&gt;
captive-portal PortalFuncionario&lt;BR /&gt;
 access-time 720&lt;BR /&gt;
 inactivity-timeout 21600&lt;BR /&gt;
 server host 10.195.37.2&lt;BR /&gt;
 server mode centralized&lt;BR /&gt;
 simultaneous-users 200&lt;BR /&gt;
 webpage internal org-name ESAF&lt;BR /&gt;
 webpage internal org-signature ESAF&lt;BR /&gt;
 webpage internal login description Conecte-se com nome e senha&lt;BR /&gt;
 webpage internal login footer Conecte-se com nome e senha&lt;BR /&gt;
 webpage internal login header Conecte-se com nome e senha&lt;BR /&gt;
 webpage internal login main-logo XXXXXXXXXXXXX.br/imagens/logoesafidg.jpg&lt;BR /&gt;
 webpage internal login main-logo use-as-banner&lt;BR /&gt;
 accounting radius&lt;BR /&gt;
 use aaa-policy esaffuncionarios&lt;BR /&gt;
 use dns-whitelist dns_listabranca&lt;BR /&gt;
 webpage internal registration field city type text enable label "City" placeholder "Enter City"&lt;BR /&gt;
 webpage internal registration field street type text enable label "Address" placeholder "123 Any Street"&lt;BR /&gt;
 webpage internal registration field name type text enable label "Full Name" placeholder "Enter First Name, Last Name"&lt;BR /&gt;
 webpage internal registration field zip type number enable label "Zip" placeholder "Zip"&lt;BR /&gt;
 webpage internal registration field via-sms type checkbox enable title "SMS Preferred"&lt;BR /&gt;
 webpage internal registration field mobile type number enable label "Mobile" placeholder "Mobile Number with Country code"&lt;BR /&gt;
 webpage internal registration field age-range type dropdown-menu enable label "Age Range" title "Age Range"&lt;BR /&gt;
 webpage internal registration field email type e-address enable mandatory label "Email" placeholder "youdomain.com"&lt;BR /&gt;
 webpage internal registration field via-email type checkbox enable title "Email Preferred"&lt;BR /&gt;
!&lt;BR /&gt;
wlan ESAF-01&lt;BR /&gt;
 description ESAF-Visitantes&lt;BR /&gt;
 shutdown&lt;BR /&gt;
 ssid ESAF-Visitantes&lt;BR /&gt;
 vlan 2074&lt;BR /&gt;
 bridging-mode local&lt;BR /&gt;
 encryption-type none&lt;BR /&gt;
 authentication-type none&lt;BR /&gt;
 no fast-bss-transition over-ds&lt;BR /&gt;
 use captive-portal Portal&lt;BR /&gt;
 captive-portal-enforcement&lt;BR /&gt;
 ip dhcp trust&lt;BR /&gt;
!&lt;BR /&gt;
wlan ESAFFuncionarios&lt;BR /&gt;
 description ESAF-Servidores&lt;BR /&gt;
 ssid ESAF-Funcionarios&lt;BR /&gt;
 vlan 2075&lt;BR /&gt;
 bridging-mode local&lt;BR /&gt;
 encryption-type none&lt;BR /&gt;
 authentication-type none&lt;BR /&gt;
 wireless-client inactivity-timeout 21600&lt;BR /&gt;
 wireless-client cred-cache-ageout 43200&lt;BR /&gt;
 wireless-client vlan-cache-ageout 43200&lt;BR /&gt;
 use aaa-policy esaffuncionarios&lt;BR /&gt;
 use captive-portal PortalFuncionario&lt;BR /&gt;
 captive-portal-enforcement&lt;BR /&gt;
 relay-agent dhcp-option82&lt;BR /&gt;
!&lt;BR /&gt;
wlan ESAFVISITANTES&lt;BR /&gt;
 ssid ESAF-Visitantes&lt;BR /&gt;
 vlan 2074&lt;BR /&gt;
 bridging-mode tunnel&lt;BR /&gt;
 encryption-type none&lt;BR /&gt;
 authentication-type none&lt;BR /&gt;
 wireless-client inactivity-timeout 21600&lt;BR /&gt;
 wireless-client cred-cache-ageout 43200&lt;BR /&gt;
 wireless-client vlan-cache-ageout 43200&lt;BR /&gt;
 wing-extensions move-command&lt;BR /&gt;
 wing-extensions scan-assist&lt;BR /&gt;
 wing-extensions ft-over-ds-aggregate&lt;BR /&gt;
 use aaa-policy esaf01_AAA&lt;BR /&gt;
 use captive-portal Portal&lt;BR /&gt;
 captive-portal-enforcement&lt;BR /&gt;
!&lt;BR /&gt;
smart-rf-policy smartrfbasico&lt;BR /&gt;
 group-by area&lt;BR /&gt;
!&lt;BR /&gt;
radius-group Esaf01&lt;BR /&gt;
 guest&lt;BR /&gt;
 policy vlan 2074&lt;BR /&gt;
 policy ssid ESAF-Visitantes&lt;BR /&gt;
 policy day mo&lt;BR /&gt;
 policy day tu&lt;BR /&gt;
 policy day we&lt;BR /&gt;
 policy day th&lt;BR /&gt;
 policy day fr&lt;BR /&gt;
 policy day sa&lt;BR /&gt;
 policy day su&lt;BR /&gt;
!&lt;BR /&gt;
radius-group Esaf02&lt;BR /&gt;
 policy vlan 2074&lt;BR /&gt;
!&lt;BR /&gt;
radius-group helpdesk&lt;BR /&gt;
 policy access web&lt;BR /&gt;
 policy role helpdesk&lt;BR /&gt;
!&lt;BR /&gt;
radius-user-pool-policy visitante&lt;BR /&gt;
 user Esaf password 0 esaf group Esaf02&lt;BR /&gt;
 user helpdesk password 0 helpdesk group helpdesk&lt;BR /&gt;
 user esaf password 0 esaf group Esaf02&lt;BR /&gt;
!&lt;BR /&gt;
radius-server-policy radius-esaf&lt;BR /&gt;
 use radius-user-pool-policy visitante&lt;BR /&gt;
 use radius-group Esaf01&lt;BR /&gt;
!&lt;BR /&gt;
dhcp-server-policy DHCP-ESAF&lt;BR /&gt;
 dhcp-pool APS&lt;BR /&gt;
  network 10.195.11.0/24&lt;BR /&gt;
  address range 10.195.11.111 10.195.11.130 &lt;BR /&gt;
  default-router 10.195.11.1&lt;BR /&gt;
  dns-server  10.12.1.16&lt;BR /&gt;
 dhcp-pool ge&lt;BR /&gt;
  network 192.168.0.0/24&lt;BR /&gt;
  address range 192.168.0.100 192.168.0.120 &lt;BR /&gt;
 dhcp-pool ESAF&lt;BR /&gt;
  network 10.195.37.0/24&lt;BR /&gt;
  address range 10.195.37.10 10.195.37.254 &lt;BR /&gt;
  lease 0 14 26 40&lt;BR /&gt;
  default-router 10.195.37.1&lt;BR /&gt;
  dns-server  200.198.205.242 161.48.25.38&lt;BR /&gt;
 dhcp-pool ESAF-VISITANTES&lt;BR /&gt;
  network 10.195.40.0/22&lt;BR /&gt;
  address range 10.195.40.50 10.195.43.254 &lt;BR /&gt;
  lease 0 14 26 40&lt;BR /&gt;
  default-router 10.195.40.1&lt;BR /&gt;
  dns-server  200.198.205.242 161.48.25.38&lt;BR /&gt;
!&lt;BR /&gt;
!&lt;BR /&gt;
management-policy default&lt;BR /&gt;
 telnet&lt;BR /&gt;
 no http server&lt;BR /&gt;
 https server&lt;BR /&gt;
 no ftp&lt;BR /&gt;
 ssh&lt;BR /&gt;
 user admin password 1 XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX role superuser access all&lt;BR /&gt;
 user teste password 1 XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX r</description>
      <pubDate>Wed, 23 Aug 2017 21:25:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-5-8-rfs7000-ap7532-users-disconnect-and-are-asked-to-login/m-p/54808#M3526</guid>
      <dc:creator>Vankman</dc:creator>
      <dc:date>2017-08-23T21:25:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wing 5.8, RFS7000, AP7532. Users disconnect and are asked to login again.</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-5-8-rfs7000-ap7532-users-disconnect-and-are-asked-to-login/m-p/54809#M3527</link>
      <description>You have defined vlan 2074 both as local and tunneled - that's not supported. You are creating loops. Local VLANs - bridged at the AP. Tunnel VLANs are going to the controller and switched there.</description>
      <pubDate>Wed, 23 Aug 2017 22:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-5-8-rfs7000-ap7532-users-disconnect-and-are-asked-to-login/m-p/54809#M3527</guid>
      <dc:creator>Alona</dc:creator>
      <dc:date>2017-08-23T22:44:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wing 5.8, RFS7000, AP7532. Users disconnect and are asked to login again.</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-5-8-rfs7000-ap7532-users-disconnect-and-are-asked-to-login/m-p/54810#M3528</link>
      <description>Hello Alona,&lt;BR /&gt;
This is a problem, even if the first wlan is set to SHUTDOWN?&lt;BR /&gt;
Thank you for the answer. &lt;BR /&gt;</description>
      <pubDate>Wed, 23 Aug 2017 22:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-5-8-rfs7000-ap7532-users-disconnect-and-are-asked-to-login/m-p/54810#M3528</guid>
      <dc:creator>Vankman</dc:creator>
      <dc:date>2017-08-23T22:44:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wing 5.8, RFS7000, AP7532. Users disconnect and are asked to login again.</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-5-8-rfs7000-ap7532-users-disconnect-and-are-asked-to-login/m-p/54811#M3529</link>
      <description>You need to make the following change on the guest WLAN to match the inactivity-timeout on the captive portal:&lt;BR /&gt;
&lt;BR /&gt;
Current Captive Portal config&amp;gt; inactivity-timeout 21600 (in seconds)&lt;BR /&gt;
What the WLAN requires&amp;gt; wireless-client hold-time 21600 (in seconds)&lt;BR /&gt;
&lt;BR /&gt;
This should resolve your current issue.</description>
      <pubDate>Wed, 23 Aug 2017 22:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-5-8-rfs7000-ap7532-users-disconnect-and-are-asked-to-login/m-p/54811#M3529</guid>
      <dc:creator>Christopher_Fra</dc:creator>
      <dc:date>2017-08-23T22:44:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wing 5.8, RFS7000, AP7532. Users disconnect and are asked to login again.</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-5-8-rfs7000-ap7532-users-disconnect-and-are-asked-to-login/m-p/54812#M3530</link>
      <description>I will do it and post the result. Thank you!&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Wed, 23 Aug 2017 22:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-5-8-rfs7000-ap7532-users-disconnect-and-are-asked-to-login/m-p/54812#M3530</guid>
      <dc:creator>Vankman</dc:creator>
      <dc:date>2017-08-23T22:44:00Z</dc:date>
    </item>
  </channel>
</rss>

