01-17-2019 05:16 PM
Solved! Go to Solution.
01-17-2019 05:52 PM
01-17-2019 06:01 PM
!
! Configuration of AP6532 version 5.8.6.5-002R
!
!
version 2.5
!
!
ip access-list BROADCAST-MULTICAST-CONTROL
permit tcp any any rule-precedence 10 rule-description "permit all TCP traffic"
permit udp any eq 67 any eq dhcpc rule-precedence 11 rule-description "permit DHCP replies"
deny udp any range 137 138 any range 137 138 rule-precedence 20 rule-description "deny windows netbios"
deny ip any 224.0.0.0/4 rule-precedence 21 rule-description "deny IP multicast"
deny ip any host 255.255.255.255 rule-precedence 22 rule-description "deny IP local broadcast"
permit ip any any rule-precedence 100 rule-description "permit all IP traffic"
!
mac access-list PERMIT-ARP-AND-IPv4
permit any any type ip rule-precedence 10 rule-description "permit all IPv4 traffic"
permit any any type arp rule-precedence 20 rule-description "permit all ARP traffic"
!
ip snmp-access-list default
permit any
!
firewall-policy default
no ip dos tcp-sequence-past-window
no stateful-packet-inspection-l2
!
!
mint-policy global-default
!
meshpoint-qos-policy default
!
wlan-qos-policy default
qos trust dscp
qos trust wmm
!
radio-qos-policy default
!
aaa-policy internal-aaa
authentication server 1 host 10.0.2.21 secret 0 *******
!
captive-portal gosc
access-type no-auth
webpage internal registration field city type text enable label "City" placeholder "Enter City"
webpage internal registration field street type text enable label "Address" placeholder "123 Any Street"
webpage internal registration field name type text enable label "Full Name" placeholder "Enter First Name, Last Name"
webpage internal registration field zip type number enable label "Zip" placeholder "Zip"
webpage internal registration field via-sms type checkbox enable title "SMS Preferred"
webpage internal registration field mobile type number enable label "Mobile" placeholder "Mobile Number with Country code"
webpage internal registration field age-range type dropdown-menu enable label "Age Range" title "Age Range"
webpage internal registration field email type e-address enable mandatory label "Email" placeholder "you@domain.com"
webpage internal registration field via-email type checkbox enable title "Email Preferred"
!
wlan xxxx_Internet
ssid xxxx_Internet
vlan 6
bridging-mode local
encryption-type none
authentication-type none
use captive-portal gosc
!
wlan xxxx_test
ssid xxxx_test
vlan 1
bridging-mode local
encryption-type ccmp
authentication-type none
wpa-wpa2 psk 0 **********
!
wips-policy default
!
radius-group upwifi
policy vlan 1
policy ssid XXXXXXXXXX
!
radius-server-policy default
authentication data-source ldap
ldap-agent primary domain-name xxxxxxx domain-admin-user ISC domain-admin-password 0 *************
use radius-group upwifi
!
!
management-policy default
no telnet
no http server
https server
ssh
user admin password 1 ********************************************* role superuser access all
snmp-server community 0 public ro
snmp-server user snmptrap v3 encrypted des auth md5 0 motorola
snmp-server user snmpmanager v3 encrypted des auth md5 0 motorola
!
event-system-policy default
!
l2tpv3 policy default
!
profile ap6532 default-ap6532
ip name-server 10.0.1.50
ip name-server 10.0.1.51
ip domain-name unionparts
ip default-gateway 10.0.2.1
autoinstall configuration
autoinstall firmware
use radius-server-policy default
no load-balancing neighbor-selection-strategy use-common-clients
no load-balancing neighbor-selection-strategy use-roam-notification
no load-balancing neighbor-selection-strategy use-smart-rf
crypto ikev1 policy ikev1-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ikev2 policy ikev2-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
crypto ikev1 remote-vpn
crypto ikev2 remote-vpn
crypto auto-ipsec-secure
crypto load-management
crypto remote-vpn-client
interface radio1
wlan xxxx_Internet bss 2 primary
wlan xxxx_test bss 3 primary
interface radio2
interface ge1
switchport mode trunk
switchport trunk native vlan 1
no switchport trunk native tagged
switchport trunk allowed vlan 1-10
interface vlan1
ip address dhcp
ip address zeroconf secondary
ip dhcp client request options all
interface pppoe1
use firewall-policy default
rf-domain-manager capable
ip dns-server-forward
controller host 10.0.1.2 pool 1 level 1
service pm sys-restart
!
rf-domain default
location Xxxx_Xxxx
contact admin@xxxxxx.pl
timezone Europe/Warsaw
country-code pl
!
ap6532 B4-C7-99-23-81-8C
use profile default-ap6532
use rf-domain default
hostname ap6532-23818C
mint mlcp ip
ip default-gateway 10.0.2.1
interface ge1
switchport mode trunk
switchport trunk native vlan 1
no switchport trunk native tagged
switchport trunk allowed vlan 1-10
interface vlan1
ip address 10.0.2.23/24
ip address zeroconf secondary
!
!
end
01-17-2019 05:52 PM
01-17-2019 05:25 PM
01-17-2019 05:22 PM