<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Single AP7532 - connected to leased line in ExtremeWireless (WiNG)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-wing/single-ap7532-connected-to-leased-line/m-p/63739#M5706</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;  &lt;P&gt;&amp;nbsp; I have a single AP that I want to be used to stage some devices from a public facing server we have.&lt;/P&gt;  &lt;P&gt;I want to set the AP to give the devices a when they connect an ip using the onboard dhcp server&lt;/P&gt;  &lt;P&gt;but the AP will have an IP from the range we have from ISP.&lt;/P&gt;  &lt;P&gt;So the AP will be in the same VLAN as our WAN connection via a firewall.&lt;/P&gt;  &lt;P&gt;I have tried to follow this guide: But I’m missing something as the wifi clients won’t connect&lt;/P&gt;  &lt;P&gt;so the traffic will leave via vlan 2 ( wan )&amp;nbsp; Then I need to tie it down to the IP’s of the staging servers.&lt;/P&gt;  &lt;P&gt;So the AP will be off the Corp network, then maybe do some firewall rule that would allow the AP to be manged using a port forward from our other leased line&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;The AP is running 5.9.2.1 The AP is in enterprise mode ( Virtual controller&amp;nbsp; AP )&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;Its a bit long, but someone may see what is missing&lt;/P&gt;  &lt;P&gt;Thanks in advance&lt;/P&gt;  &lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Natting and Guest WLAN setup on a virtual controller:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;  &lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;For this setup the following are used:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;  &lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Internal/Guest subnet 192.168.100.0/24&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;  &lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Internal/Guest VLAN: VLAN 100&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;  &lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Corp subnet 10.10.10.0/24&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;  &lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Corp VLAN: VLAN 1&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;  &lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Note: All settings must be configured on the VC. &lt;/SPAN&gt;&lt;/P&gt;  &lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;1 – &amp;nbsp;Create your inside (guest) and outside (corp) VLANs&lt;/SPAN&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;From System Profile, create a VLAN for Internal/Guest users, Example: VLAN 100, do not give it an IP address at this point.&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Configuration &amp;gt;&amp;gt; Devices &amp;gt;&amp;gt; System Profile &amp;gt;&amp;gt; Select the AP profile &amp;gt;&amp;gt; Interfaces &amp;gt;&amp;gt; Virtual Interfaces &amp;gt;&amp;gt; Add &amp;gt;&amp;gt; VLAN ID: 100 &amp;gt;&amp;gt; Continue &amp;gt;&amp;gt; Exit &amp;gt;&amp;gt; Commit and Save&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;Give an IP to VLAN 100 on the &lt;STRONG&gt;virtual controller&lt;/STRONG&gt; as an override:&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Configuration &amp;gt;&amp;gt; Devices &amp;gt;&amp;gt; Device Overrides &amp;gt;&amp;gt; Select the VC AP&amp;gt;&amp;gt; Interfaces &amp;gt;&amp;gt; Virtual Interfaces &amp;gt;&amp;gt; VLAN 100 &amp;gt;&amp;gt; IPv4 &amp;gt;&amp;gt; Primary IP address 192.168.100.1 &amp;gt;&amp;gt; Exit &amp;gt;&amp;gt; Commit and Save&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;Define NAT direction:&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Still in the VLAN setting, General tab, under Network Address Translation &amp;gt;&amp;gt; NAT direction: &lt;STRONG&gt;Inside&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;This AP is now the default gateway. &lt;/SPAN&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;Define NAT direction on corp VLAN 1 which is the outside VLAN:&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Configuration &amp;gt;&amp;gt; Devices &amp;gt;&amp;gt; Device Overrides &amp;gt;&amp;gt; Select the VC AP &amp;gt;&amp;gt; Interfaces &amp;gt;&amp;gt; Virtual Interfaces &amp;gt;&amp;gt; VLAN&amp;nbsp; 1 &amp;gt;&amp;gt; General &amp;gt;&amp;gt; Network Address Translation &amp;gt;&amp;gt; NAT direction: &lt;STRONG&gt;Outside&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;2 – Allow these VLANs out of the ge1 port&lt;/SPAN&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;&lt;EM&gt;&lt;EM&gt;Configuration &amp;gt;&amp;gt; Devices &amp;gt;&amp;gt; System profile &amp;gt;&amp;gt; select profile &amp;gt;&amp;gt; Interface &amp;gt;&amp;gt; Ethernet ports &amp;gt;&amp;gt; ge1 &amp;gt;&amp;gt; Switching mode &amp;gt;&amp;gt; Mode: Trunk &amp;gt;&amp;gt; Allowed VLANs: 1,100 &amp;gt;&amp;gt; Ok &amp;gt;&amp;gt; Exit &amp;gt;&amp;gt; Commit and Save&lt;/EM&gt;&lt;/EM&gt;&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;SPAN style="color:#FF0000;"&gt;IMPORTANT NOTE: Make sure that the switch port the APs are connected to are also configured to allow the same VLANs. &lt;/SPAN&gt;&lt;/P&gt;  &lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;3 - Configure the DHCP server policy&lt;/SPAN&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;&lt;EM&gt;&lt;EM&gt;Configuration &amp;gt;&amp;gt; Services &amp;gt;&amp;gt; DHCP server &amp;gt;&amp;gt; Add &amp;gt;&amp;gt; Create the policy with the required information (subnet, pool, Default router IP address which is the IP address of your AP, in this case 192.168.100.1)&lt;/EM&gt;&lt;/EM&gt;&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;  &lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;4 – Enable the DHCP server policy&lt;/SPAN&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;&lt;EM&gt;&lt;EM&gt;Configuration &amp;gt;&amp;gt; Devices &amp;gt;&amp;gt; Device Overrides &amp;gt;&amp;gt; Select VC AP &amp;gt;&amp;gt; Services &amp;gt;&amp;gt;DHCP server&amp;gt;&amp;gt;DHCP Server Policy &amp;gt;&amp;gt; Select the one you created earlier from the drop down menu &amp;gt;&amp;gt; Ok &amp;gt;&amp;gt; Commit and Save&lt;/EM&gt;&lt;/EM&gt;&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;5 - Create NAT ACL&lt;/SPAN&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;&lt;EM&gt;&lt;EM&gt;Configuration &amp;gt;&amp;gt; Security &amp;gt;&amp;gt; IP Firewall &amp;gt;&amp;gt; IPv4 ACL &amp;gt;&amp;gt; Add &amp;gt;&amp;gt; Enter IP Firewall Policy name &amp;gt;&amp;gt; Change only the following: Action: allow&amp;gt;&amp;gt; Source: Network (here we chose 192.168.100.0/24), Destination: Any &amp;gt;&amp;gt; OK &amp;gt;&amp;gt; Commit and Save&lt;/EM&gt;&lt;/EM&gt;&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;6 - Create NAT&lt;/SPAN&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;&lt;EM&gt;&lt;EM&gt;Configuration &amp;gt;&amp;gt; Devices &amp;gt;&amp;gt; Device Overrides &amp;gt;&amp;gt; Select VC AP &amp;gt;&amp;gt; Security &amp;gt;&amp;gt; NAT &amp;gt;&amp;gt; Dynamic NAT (Add) &amp;gt;&amp;gt; Select ACL created earlier from dropdown &amp;gt;&amp;gt; Network inside &amp;gt;&amp;gt; Add Row &amp;gt;&amp;gt;Interface VLAN ID: 1. &lt;/EM&gt;&lt;/EM&gt;&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;GUEST WLAN SETUP:&lt;/SPAN&gt;&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;  &lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;If the guest WLAN is going to go through corp network you will have to configure an ACL rule to prevent guest users from accessing corp resources:&lt;/SPAN&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;&lt;EM&gt;&lt;EM&gt;Configuration &amp;gt;&amp;gt; Security &amp;gt;&amp;gt; IP Firewall&amp;nbsp; &amp;gt;&amp;gt; IPv4 ACL &amp;gt;&amp;gt; Add &amp;gt;&amp;gt; Enter ACL name (example&amp;nbsp; guestacl) &amp;gt;&amp;gt; Add following rules:&lt;/EM&gt;&lt;/EM&gt;&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;1 – Precedence 1&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Action: Deny&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Source: Network (enter IP of network subnet: Example 192.168.100.0/24 in this case)&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Destination: Network (Enter IP of corp network: Example 10.10.10.0/24 in this case)&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Protocol: IP&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;&amp;nbsp;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;2 – Precedence 2&lt;/SPAN&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Action: Allow&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Source: Network (enter IP of network subnet: Example 192.168.100.0/24 in this case)&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Destination: Any&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Protocol: IP&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;&lt;EM&gt;&lt;EM&gt;Create your Guest WLAN (example: guest-wlan) then from the menu tree, go to the Firewall &amp;gt;&amp;gt; IP Firewall Rules &amp;gt;&amp;gt; Inbound IP Firewall Rules and select the ACL you created earlier from the drop down menu. &lt;/EM&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;&lt;EM&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 20 May 2020 19:46:11 GMT</pubDate>
    <dc:creator>Phil_storey</dc:creator>
    <dc:date>2020-05-20T19:46:11Z</dc:date>
    <item>
      <title>Single AP7532 - connected to leased line</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/single-ap7532-connected-to-leased-line/m-p/63739#M5706</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;  &lt;P&gt;&amp;nbsp; I have a single AP that I want to be used to stage some devices from a public facing server we have.&lt;/P&gt;  &lt;P&gt;I want to set the AP to give the devices a when they connect an ip using the onboard dhcp server&lt;/P&gt;  &lt;P&gt;but the AP will have an IP from the range we have from ISP.&lt;/P&gt;  &lt;P&gt;So the AP will be in the same VLAN as our WAN connection via a firewall.&lt;/P&gt;  &lt;P&gt;I have tried to follow this guide: But I’m missing something as the wifi clients won’t connect&lt;/P&gt;  &lt;P&gt;so the traffic will leave via vlan 2 ( wan )&amp;nbsp; Then I need to tie it down to the IP’s of the staging servers.&lt;/P&gt;  &lt;P&gt;So the AP will be off the Corp network, then maybe do some firewall rule that would allow the AP to be manged using a port forward from our other leased line&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;The AP is running 5.9.2.1 The AP is in enterprise mode ( Virtual controller&amp;nbsp; AP )&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;Its a bit long, but someone may see what is missing&lt;/P&gt;  &lt;P&gt;Thanks in advance&lt;/P&gt;  &lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Natting and Guest WLAN setup on a virtual controller:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;  &lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;For this setup the following are used:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;  &lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Internal/Guest subnet 192.168.100.0/24&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;  &lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Internal/Guest VLAN: VLAN 100&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;  &lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Corp subnet 10.10.10.0/24&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;  &lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Corp VLAN: VLAN 1&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;  &lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Note: All settings must be configured on the VC. &lt;/SPAN&gt;&lt;/P&gt;  &lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;1 – &amp;nbsp;Create your inside (guest) and outside (corp) VLANs&lt;/SPAN&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;From System Profile, create a VLAN for Internal/Guest users, Example: VLAN 100, do not give it an IP address at this point.&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Configuration &amp;gt;&amp;gt; Devices &amp;gt;&amp;gt; System Profile &amp;gt;&amp;gt; Select the AP profile &amp;gt;&amp;gt; Interfaces &amp;gt;&amp;gt; Virtual Interfaces &amp;gt;&amp;gt; Add &amp;gt;&amp;gt; VLAN ID: 100 &amp;gt;&amp;gt; Continue &amp;gt;&amp;gt; Exit &amp;gt;&amp;gt; Commit and Save&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;Give an IP to VLAN 100 on the &lt;STRONG&gt;virtual controller&lt;/STRONG&gt; as an override:&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Configuration &amp;gt;&amp;gt; Devices &amp;gt;&amp;gt; Device Overrides &amp;gt;&amp;gt; Select the VC AP&amp;gt;&amp;gt; Interfaces &amp;gt;&amp;gt; Virtual Interfaces &amp;gt;&amp;gt; VLAN 100 &amp;gt;&amp;gt; IPv4 &amp;gt;&amp;gt; Primary IP address 192.168.100.1 &amp;gt;&amp;gt; Exit &amp;gt;&amp;gt; Commit and Save&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;Define NAT direction:&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Still in the VLAN setting, General tab, under Network Address Translation &amp;gt;&amp;gt; NAT direction: &lt;STRONG&gt;Inside&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;This AP is now the default gateway. &lt;/SPAN&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;Define NAT direction on corp VLAN 1 which is the outside VLAN:&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Configuration &amp;gt;&amp;gt; Devices &amp;gt;&amp;gt; Device Overrides &amp;gt;&amp;gt; Select the VC AP &amp;gt;&amp;gt; Interfaces &amp;gt;&amp;gt; Virtual Interfaces &amp;gt;&amp;gt; VLAN&amp;nbsp; 1 &amp;gt;&amp;gt; General &amp;gt;&amp;gt; Network Address Translation &amp;gt;&amp;gt; NAT direction: &lt;STRONG&gt;Outside&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;2 – Allow these VLANs out of the ge1 port&lt;/SPAN&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;&lt;EM&gt;&lt;EM&gt;Configuration &amp;gt;&amp;gt; Devices &amp;gt;&amp;gt; System profile &amp;gt;&amp;gt; select profile &amp;gt;&amp;gt; Interface &amp;gt;&amp;gt; Ethernet ports &amp;gt;&amp;gt; ge1 &amp;gt;&amp;gt; Switching mode &amp;gt;&amp;gt; Mode: Trunk &amp;gt;&amp;gt; Allowed VLANs: 1,100 &amp;gt;&amp;gt; Ok &amp;gt;&amp;gt; Exit &amp;gt;&amp;gt; Commit and Save&lt;/EM&gt;&lt;/EM&gt;&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;SPAN style="color:#FF0000;"&gt;IMPORTANT NOTE: Make sure that the switch port the APs are connected to are also configured to allow the same VLANs. &lt;/SPAN&gt;&lt;/P&gt;  &lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;3 - Configure the DHCP server policy&lt;/SPAN&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;&lt;EM&gt;&lt;EM&gt;Configuration &amp;gt;&amp;gt; Services &amp;gt;&amp;gt; DHCP server &amp;gt;&amp;gt; Add &amp;gt;&amp;gt; Create the policy with the required information (subnet, pool, Default router IP address which is the IP address of your AP, in this case 192.168.100.1)&lt;/EM&gt;&lt;/EM&gt;&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;  &lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;4 – Enable the DHCP server policy&lt;/SPAN&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;&lt;EM&gt;&lt;EM&gt;Configuration &amp;gt;&amp;gt; Devices &amp;gt;&amp;gt; Device Overrides &amp;gt;&amp;gt; Select VC AP &amp;gt;&amp;gt; Services &amp;gt;&amp;gt;DHCP server&amp;gt;&amp;gt;DHCP Server Policy &amp;gt;&amp;gt; Select the one you created earlier from the drop down menu &amp;gt;&amp;gt; Ok &amp;gt;&amp;gt; Commit and Save&lt;/EM&gt;&lt;/EM&gt;&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;5 - Create NAT ACL&lt;/SPAN&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;&lt;EM&gt;&lt;EM&gt;Configuration &amp;gt;&amp;gt; Security &amp;gt;&amp;gt; IP Firewall &amp;gt;&amp;gt; IPv4 ACL &amp;gt;&amp;gt; Add &amp;gt;&amp;gt; Enter IP Firewall Policy name &amp;gt;&amp;gt; Change only the following: Action: allow&amp;gt;&amp;gt; Source: Network (here we chose 192.168.100.0/24), Destination: Any &amp;gt;&amp;gt; OK &amp;gt;&amp;gt; Commit and Save&lt;/EM&gt;&lt;/EM&gt;&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;6 - Create NAT&lt;/SPAN&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;&lt;EM&gt;&lt;EM&gt;Configuration &amp;gt;&amp;gt; Devices &amp;gt;&amp;gt; Device Overrides &amp;gt;&amp;gt; Select VC AP &amp;gt;&amp;gt; Security &amp;gt;&amp;gt; NAT &amp;gt;&amp;gt; Dynamic NAT (Add) &amp;gt;&amp;gt; Select ACL created earlier from dropdown &amp;gt;&amp;gt; Network inside &amp;gt;&amp;gt; Add Row &amp;gt;&amp;gt;Interface VLAN ID: 1. &lt;/EM&gt;&lt;/EM&gt;&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;GUEST WLAN SETUP:&lt;/SPAN&gt;&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;  &lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;If the guest WLAN is going to go through corp network you will have to configure an ACL rule to prevent guest users from accessing corp resources:&lt;/SPAN&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;&lt;EM&gt;&lt;EM&gt;Configuration &amp;gt;&amp;gt; Security &amp;gt;&amp;gt; IP Firewall&amp;nbsp; &amp;gt;&amp;gt; IPv4 ACL &amp;gt;&amp;gt; Add &amp;gt;&amp;gt; Enter ACL name (example&amp;nbsp; guestacl) &amp;gt;&amp;gt; Add following rules:&lt;/EM&gt;&lt;/EM&gt;&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;1 – Precedence 1&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Action: Deny&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Source: Network (enter IP of network subnet: Example 192.168.100.0/24 in this case)&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Destination: Network (Enter IP of corp network: Example 10.10.10.0/24 in this case)&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Protocol: IP&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;&amp;nbsp;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;2 – Precedence 2&lt;/SPAN&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Action: Allow&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Source: Network (enter IP of network subnet: Example 192.168.100.0/24 in this case)&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Destination: Any&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;EM&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;Protocol: IP&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;  &lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;&lt;EM&gt;&lt;EM&gt;Create your Guest WLAN (example: guest-wlan) then from the menu tree, go to the Firewall &amp;gt;&amp;gt; IP Firewall Rules &amp;gt;&amp;gt; Inbound IP Firewall Rules and select the ACL you created earlier from the drop down menu. &lt;/EM&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;&lt;EM&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;&lt;SPAN style="color:rgb(0,0,0);"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2020 19:46:11 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/single-ap7532-connected-to-leased-line/m-p/63739#M5706</guid>
      <dc:creator>Phil_storey</dc:creator>
      <dc:date>2020-05-20T19:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: Single AP7532 - connected to leased line</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/single-ap7532-connected-to-leased-line/m-p/63740#M5707</link>
      <description>&lt;P&gt;Hi Phil,&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;Quick question for clarity - they won’t connect ie. associate or no IP address is given to them on this guest VLAN? How is the WLAN configured? And is the traffic required to be NAT-ted or left in that guest VLAN?&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;Kind regards,&lt;/P&gt;  &lt;P&gt;Tomasz&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2020 05:13:32 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/single-ap7532-connected-to-leased-line/m-p/63740#M5707</guid>
      <dc:creator>Tomasz</dc:creator>
      <dc:date>2020-05-21T05:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: Single AP7532 - connected to leased line</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/single-ap7532-connected-to-leased-line/m-p/63741#M5708</link>
      <description>&lt;P&gt;Hi Tomasz&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; the laptop can see the network but will not associate so can’t get an IP.&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;The AP will be connected to a non natted leased line via a network switch in vlan2 so the ap has a public facing IP 105.xxx.xxx.42/27 ( example ) the units to be staged will scan a QR code that has the wifi network and key embedded in the QR code along with details of the server it needs to connect to and the apps it needs to pull from the server.&lt;/P&gt;  &lt;P&gt;At present the AP is on the bench, I set the wifi up and wanted to make sure the laptop would get an IP address from the AP dhcp server, so the internal 192.168.xxx.xxx traffic needs to get out on to the net, to get the apps/etc for staging&lt;/P&gt;  &lt;P&gt;best regards&lt;/P&gt;  &lt;P&gt;Phil&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2020 14:32:47 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/single-ap7532-connected-to-leased-line/m-p/63741#M5708</guid>
      <dc:creator>Phil_storey</dc:creator>
      <dc:date>2020-05-21T14:32:47Z</dc:date>
    </item>
    <item>
      <title>Re: Single AP7532 - connected to leased line</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/single-ap7532-connected-to-leased-line/m-p/63742#M5709</link>
      <description>&lt;P&gt;Hi Phil,&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;I see.&lt;/P&gt;  &lt;P&gt;When you say the laptop can see the network but won’t associate, perhaps it’s too soon to say either DHCP/NAT is well done or with errors... IMHO something on WLAN configuration might have to be checked first: encryption, authentication, any side options and improvements that can cause issues with particular client hardware/software sometimes.&lt;/P&gt;  &lt;P&gt;If it’s not an issue, please paste your WLAN config.&lt;/P&gt;  &lt;P&gt;Also try to run packet capture and wireless debug. For wireless debug I use ‘remote-debug wireless’ command for that (like ‘remote-debug wireless rf-domain default clients aa:bb:cc:dd:ee:11 max-events 10000 duration 86400 events all’), but it’s especially useful for more than one AP (and running this for an entire site). You can also check ‘service show wireless log-internal’ or ‘show event-history’ if it shows you something relevant.&lt;/P&gt;  &lt;P&gt;For packet capture, ‘remote-debug live-pktcap’ or ‘service pktcap’ commands may come in handy.&lt;/P&gt;  &lt;P&gt;Just to give you some example, I had a problem with clients not being able to authenticate over 802.1X network and it turned out it was a driver issue on Intel AC card when it saw 802.11r and 11w over the air. Under packet capture I was able to see that WPA handshake is not complete, and in logs I could find some more descriptive message (that allowed me to google for the root cause with success :D).&lt;/P&gt;  &lt;P&gt;Please see this for some reference on these debugging options in WiNG: &lt;A href="https://1drv.ms/b/s!AvxWpCsRBHSfg0xyeFuPXn_B_m_u?e=0i4bQL" target="_blank" rel="nofollow noreferrer noopener"&gt;https://1drv.ms/b/s!AvxWpCsRBHSfg0xyeFuPXn_B_m_u?e=0i4bQL&lt;/A&gt;&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;Hope that helps,&lt;/P&gt;  &lt;P&gt;Tomasz&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2020 23:22:53 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/single-ap7532-connected-to-leased-line/m-p/63742#M5709</guid>
      <dc:creator>Tomasz</dc:creator>
      <dc:date>2020-05-21T23:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: Single AP7532 - connected to leased line</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/single-ap7532-connected-to-leased-line/m-p/63743#M5710</link>
      <description>&lt;P&gt;Hi Tomasz&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&amp;nbsp; thankyou for the reply, I’m going to work through the guide I was following, did that all look OK ? or is there bits missing, I have factoryReset the AP, I’ll try and report back later today&lt;/P&gt;  &lt;P&gt;Phil&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 16:23:34 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/single-ap7532-connected-to-leased-line/m-p/63743#M5710</guid>
      <dc:creator>Phil_storey</dc:creator>
      <dc:date>2020-05-22T16:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: Single AP7532 - connected to leased line</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/single-ap7532-connected-to-leased-line/m-p/63744#M5711</link>
      <description>&lt;P&gt;Hi Phil,&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;Good luck!&lt;/P&gt;  &lt;P&gt;Should you have any questions, just let us know.&lt;/P&gt;  &lt;P&gt;Eventually, we could try with some remote session if that helps.&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;Take care,&lt;/P&gt;  &lt;P&gt;Tomasz&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 16:26:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/single-ap7532-connected-to-leased-line/m-p/63744#M5711</guid>
      <dc:creator>Tomasz</dc:creator>
      <dc:date>2020-05-22T16:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: Single AP7532 - connected to leased line</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/single-ap7532-connected-to-leased-line/m-p/63745#M5712</link>
      <description>&lt;P&gt;Hi Tomasz&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have tried again, something I’m doing wrong, If the offer stands for a remote session I would like to take you up on the offer, I have defaulted the&amp;nbsp;AP again ready to restart doing the config again&lt;/P&gt;  &lt;P&gt;Phil&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 17:33:51 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/single-ap7532-connected-to-leased-line/m-p/63745#M5712</guid>
      <dc:creator>Phil_storey</dc:creator>
      <dc:date>2020-05-26T17:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: Single AP7532 - connected to leased line</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/single-ap7532-connected-to-leased-line/m-p/63746#M5713</link>
      <description>&lt;P&gt;Hi Phil,&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;Sure, I’d love to give you another pair of eyes to look at it, not a business offer. This week mainly evenings in GMT time zone work for me. Please pm me and let me know when it’s feasible for you to connect.&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;Take care,&lt;/P&gt;  &lt;P&gt;Tomasz&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 03:55:11 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/single-ap7532-connected-to-leased-line/m-p/63746#M5713</guid>
      <dc:creator>Tomasz</dc:creator>
      <dc:date>2020-05-27T03:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: Single AP7532 - connected to leased line</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/single-ap7532-connected-to-leased-line/m-p/63747#M5714</link>
      <description>&lt;P&gt;Hi Tomasz&lt;/P&gt;  &lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;thankyou for your assistance on this, It seems to be working now, just got to tie it down a bit from the WAN side of things&lt;/P&gt;  &lt;P&gt;Phil&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2020 13:41:08 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/single-ap7532-connected-to-leased-line/m-p/63747#M5714</guid>
      <dc:creator>Phil_storey</dc:creator>
      <dc:date>2020-06-09T13:41:08Z</dc:date>
    </item>
  </channel>
</rss>

