Guide to configuring eduroam using a Cisco wireless controller Best ...
Guide to configuring eduroam using a Cisco wireless controller Best ...
Guide to configuring eduroam using a Cisco wireless controller Best ...
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
Figure 1 provides a summary. Each network cloud represents an IP subnet with the exception of the<br />
<strong>eduroam</strong> hierarchy which for the sake of simplicity is given its own network cloud. The arrows between<br />
the clouds indicate the necessary traffic pattern and form the basis for deciding which ports must be<br />
opened in package filters (if the units are located in different subnets). One must select a configuration<br />
in which, for example, the operating network and services are in the same subnet. In any event it is<br />
recommended that the access points be located in a dedicated subnet, since these network points are<br />
exposed in open premises and risk being tapped. The <strong>controller</strong>(s) (WLC(s)) should also be separated<br />
from the service or server network, but may for example be located in a general management network<br />
for switches.<br />
8<br />
Figure 1: Proposed subnets and necessary traffic pattern<br />
1.3 The <strong>wireless</strong> <strong>controller</strong> (WLC)<br />
The 5500 <strong>controller</strong> has one administrative IP address (Management), while the 4400 <strong>controller</strong><br />
requires two administrative IP addresses (Management and AP Manager). A WiSM module consists of<br />
two 4400 <strong>controller</strong>s and consequently requires four administrative IP addresses. The Management IP<br />
address is the one which is used for general administration of the <strong>controller</strong> and is the contact address<br />
<strong>to</strong> and from other systems such as WCS and RADIUS server. The Management address is also used<br />
for communication with the access points, but here the 4400 <strong>controller</strong> also has the AP Manager<br />
address which is used in communication with the access points after the initial contact has been