!! Configuration of RFS4000 version R!! version 2.3!! ip access-list BROADCAST-MULTICAST-CONTROL permit tcp any any rule-precedence 10

Similar documents
FortiNAC Motorola Wireless Controllers Integration

WiNG 5.x How-To Guide

Case Study Captive Portal with QR Code authenticator assisted

CONFIGURING AND DEPLOYING THE AX411 WIRELESS ACCESS POINT

Network security session 9-2 Router Security. Network II

Cisco Virtual Office: Easy VPN Deployment Guide

BEST PRACTICE - NAC AUF ARUBA SWITCHES. Rollenbasierte Konzepte mit Aruba OS Switches in Verbindung mit ClearPass Vorstellung Mobile First Features

cnpilot Enterprise AP Release Notes

Configuring Cisco ACE for Load Balancing Cisco Identity Service Engine (ISE)

TECHNICAL NOTE UWW & CLEARPASS HOW-TO: CONFIGURE UNIFIED WIRELESS WITH CLEARPASS. Version 2

P ART 3. Configuring the Infrastructure

Switch and Wireless LAN Controller Configuration Required to Support Cisco ISE Functions

How to social login with Aruba controller. Bo Nielsen, CCIE #53075 (Sec) December 2016, V1.00

Cisco TrustSec How-To Guide: Universal Configuration for the Cisco Wireless LAN Controller

WISNETWORKS. WisOS 11ac V /3/21. Software version WisOS 11ac

Deployment Guide for Cisco Guest Access Using the Cisco Wireless LAN Controller, Release 4.1

Creating Wireless Networks

Configuring the WMIC for the First Time

Universal Wireless Controller Configuration for Cisco Identity Services Engine. Secure Access How-To Guide Series

Securing Wireless LAN Controllers (WLCs)

Configure Devices Using Converged Access Deployment Templates for Campus and Branch Networks

Payload Types At Different OSI Layers: Layer 2 - Frame Layer 3 - Packet Layer 4 - Datagram

Vendor: Aruba. Exam Code: ACMP_6.1. Exam Name: Aruba Certified Mobility Professional 6.1. Version: Demo

Configuring Hybrid REAP

RADIUS Configuration Note WINS : Wireless Interoperability & Network Solutions

Identity Services Engine Guest Portal Local Web Authentication Configuration Example

Lab 8.5.2: Troubleshooting Enterprise Networks 2

Support for policy-based routing applies to the Barracuda Web Security Gateway running version 6.x only.

Configure to Secure a Flexconnect AP Switchport with Dot1x

TECHNICAL NOTE MSM & CLEARPASS HOW TO CONFIGURE HPE MSM CONTROLLERS WITH ARUBA CLEARPASS VERSION 3, JUNE 2016

Vendor: HP. Exam Code: HP2-Z32. Exam Name: Implementing HP MSM Wireless Networks. Version: Demo

AOS-W 6.4. Quick Start Guide. Install the Switch. Initial Setup Using the WebUI Setup Wizard

exam. Number: Passing Score: 800 Time Limit: 120 min CISCO Interconnecting Cisco Networking Devices Part 1 (ICND)

Release Notes for Avaya WLAN 9100 AOS-Lite Operating System WAP9112 Release WAP9114 Release 8.1.0

ACMP_6.4

FortiNAC. Aerohive Wireless Access Point Integration. Version 8.x 8/28/2018. Rev: E

Exam HP2-Z32 Implementing HP MSM Wireless Networks Version: 7.1 [ Total Questions: 115 ]

Configuring Web-Based Authentication

NXC Series. Handbook. NXC Controllers NXC 2500/ Default Login Details. Firmware Version 5.00 Edition 19, 5/

CISCO SWITCH BEST PRACTICES GUIDE

WiNG 5.8 HOTSPOT HOW-TO. RRC Poland Auto ID 2015

Note that you can also use the password command but the secret command gives you a better encryption algorithm.

Configuring a Basic Wireless LAN Connection

CWA URL Redirect support on C891FW

CCNP Switch Questions/Answers Securing Campus Infrastructure

FortiNAC. Cisco Airespace Wireless Controller Integration. Version: 8.x. Date: 8/28/2018. Rev: B

User Guide TL-R470T+/TL-R480T REV9.0.2

UniNets CCNA Security LAB MANUAL UNiNets CCNA Cisco Certified Network Associate Security LAB MANUAL UniNets CCNA LAB MANUAL

FortiNAC. HiPath. Enterasys. Siemens. Extreme. Wireless Integration. Version: 8.x. Date: 8/28/2018. Rev: B

Configuring Network Admission Control

WISNETWORKS. WisOS 11ac V /3/21. Software version WisOS 11ac

ActualTorrent. Professional company engaging Providing Valid Actual Torrent file for qualification exams.

High Availability Synchronization PAN-OS 5.0.3

Written by Alexei Spirin Wednesday, 02 January :06 - Last Updated Wednesday, 02 January :24

Aruba ACMP. Aruba Certified Mobility Professional

Integrating Meraki Networks with

ITCertMaster. Safe, simple and fast. 100% Pass guarantee! IT Certification Guaranteed, The Easy Way!

A connected workforce is a more productive workforce

Securing Cisco Wireless Enterprise Networks ( )

Cisco Structured Wireless-Aware Network (SWAN) Implementation Guide

Aruba Central Instant Access Point Configuration

Numerics INDEX. 2.4-GHz WMIC, contrasted with 4.9-GHz WMIC g 3-6, x authentication 4-13

CCIE Wireless v3 Lab Video Series 1 Table of Contents

Wireless Client Isolation. Overview. Bridge Mode Client Isolation. Configuration

Table of Contents X Configuration 1-1

Cisco TrustSec How-To Guide: Central Web Authentication

Sample Business Ready Branch Configuration Listings

Actual4Test. Actual4test - actual test exam dumps-pass for IT exams

Interconnecting Cisco Networking Devices Part 1 (ICND1) Course Overview

Aruba Mobility. Setup Guide

M a/b/g Outdoor Layer-2 MESH AP

Wireless BYOD with Identity Services Engine

Command Guide of WGSW-28040

IEEE a/ac/n/b/g Outdoor Stand-Alone Access Point. Management Guide. ECWO Series. Software Release v1.0.1.

Document Created by Nick Schuster

MultiAP 700G. User Manual

Cisco Mobility Express User Guide for Release 8.1

Cloudpath and Aruba Instant Integration

Skills Assessment. CCNA Routing and Switching: Connecting Networks. Topology. Assessment Objectives. Scenario

Configuring the Access Point/Bridge for the First Time

Wireless LAN Controller Web Authentication Configuration Example

Cisco Mobility Express Configuration and User Guide, Cisco Wireless Release 8.3

For more information, see "Provision APs for Mesh" on page 6 6. Connect your APs to the network. See "Install the APs" on page 6

1.1 Configuring HQ Router as Remote Access Group VPN Server

Aruba Central Access Points Configuration

Ports and Interfaces. Ports. Information About Ports. Ports, page 1 Link Aggregation, page 5 Interfaces, page 10

Configuring RADIUS Servers

PASS4TEST. IT Certification Guaranteed, The Easy Way! We offer free update service for one year

Configuring Client Profiling

TestOut Routing and Switching Pro - English 6.0.x COURSE OUTLINE. Modified

Fundamentals of Network Security v1.1 Scope and Sequence

Internetwork Expert s CCNA Security Bootcamp. Mitigating Layer 2 Attacks. Layer 2 Mitigation Overview

TORNADO M100 CELLNODE USER MANUAL

User Manual. SSV Remote Access Gateway. Web ConfigTool

SSG Configuration Example

Configuring Network Admission Control

Wireless AC1200 Concurrent Dual Band PoE Access Point

DWS-4000 Series DWL-3600AP DWL-6600AP

Assignment - 1 Chap. 1 Wired LAN s

Converged Access CT 5760 AVC Deployment Guide, Cisco IOS XE Release 3.3

Transcription:

Configuration of RFS4000 version 5.5.1.0-017R version 2.3 ip access-list BROADCAST-MULTICAST-CONTROL permit tcp any any rule-precedence 10 rule-description "permit all TCP traffic" permit udp any eq 67 any eq dhcpc rule-precedence 11 rule-description "permit DHCP replies" deny udp any range 137 138 any range 137 138 rule-precedence 20 rule-description "deny windows netbios" deny ip any 224.0.0.0/4 rule-precedence 21 rule-description "deny IP multicast" deny ip any host 255.255.255.255 rule-precedence 22 rule-description "deny IP local broadcast" permit ip any any rule-precedence 100 rule-description "permit all IP traffic" ip access-list nat-rule permit ip 172.16.11.0/24 any rule-precedence 10 mac access-list PERMIT-ARP-AND-IPv4 permit any any type ip rule-precedence 10 rule-description "permit all IPv4 traffic" permit any any type arp rule-precedence 20 rule-description "permit all ARP traffic" firewall-policy default no ip dos tcp-sequence-past-window mint-policy global-default meshpoint-qos-policy default wlan-qos-policy default qos trust wmm radio-qos-policy default aaa-policy default-external authentication server 1 host 10.86.119.170 secret 0 cisco123 mac-address-format pair-colon case upper attributes all attribute cisco-vsa audit-session-id dns-whitelist ISE_whitelist permit vsantau-ise2.cisco.com

permit vsantau-ise2 permit 10.86.119.170 captive-portal ISE access-type no-auth connection-mode https server host on-boaring.com server mode centralized-controller hosting-vlan-interface 16 webpage external login https://10.86.119.170/portal/gateway?portal=5dbe4590-c486-11e4-af78-005056bf4687&action=cwa use aaa-policy default-external use dns-whitelist ISE_whitelist radius-vlan-assignment captive-portal ISE-dynamic access-type no-auth server host on-boaring.com server mode centralized-controller webpage internal login title agreement webpage internal agreement description You will be redirected to Cisco ISE portal webpage internal agreement header ISE portal use dns-whitelist ISE_whitelist captive-portal ISEWebAuth terms-agreement use aaa-policy default-external captive-portal default-external server host guest-access.net server mode centralized-controller use aaa-policy default-external wlan wlan-ise1x ssid motorolaise1x vlan 10 bridging-mode tunnel encryption-type tkip authentication-type eap radius vlan-assignment radius dynamic-authorization use aaa-policy default-external use captive-portal ISE-dynamic captive-portal-enforcement fall-back

wlan wlan1 ssid motorolaise vlan 10 bridging-mode tunnel encryption-type none authentication-type none radius vlan-assignment radius dynamic-authorization use aaa-policy default-external use captive-portal ISEWebAuth captive-portal-enforcement fall-back ap300 default-ap300 radius-server-policy ISE-CoA dhcp-server-policy DHCPPolicy dhcp-pool vlan11 network 172.16.12.0/24 address range 172.16.12.22 172.16.12.99 domain-name cisco2.com default-router 172.16.12.1 dhcp-pool main network 172.16.11.0/24 address range 172.16.11.10 172.16.11.250 domain-name cisco.com default-router 172.16.11.1 dns-server 172.16.11.1 management-policy default no http server https server ssh user admin password 1 115ed7702f6dfc585e5effcdd6d9975d1719ff406fb1ca81241762ffa6ad0632 role superuser access all snmp-server community 0 public ro snmp-server user snmptrap v3 encrypted des auth md5 0 motorola snmp-server user snmpmanager v3 encrypted des auth md5 0 motorola l2tpv3 policy default

profile rfs4000 default-rfs4000 ip default-gateway 10.86.116.1 wlan wlan-ise1x bss 2 primary wlan wlan-ise1x bss 2 primary interface up1 switchport mode access switchport access vlan 16 interface ge2 interface ge3 interface ge4 interface ge5 interface wwan1

use dhcp-server-policy DHCPPolicy use captive-portal server ISE logging on profile ap82xx default-ap82xx interface radio3 interface ge2 interface wwan1 profile ap81xx default-ap81xx

interface radio3 interface ge2 interface wwan1 profile ap71xx default-ap71xx

interface radio3 interface ge2 interface wwan1 profile ap6532 default-ap6532 crypto load-management

profile ap650 default-ap650 crypto load-management profile ap6521 default-ap6521

profile ap621 default-ap621 profile ap6511 default-ap6511 interface up1 interface fe1 interface fe2

interface fe3 interface fe4 profile ap6562 default-ap6562 crypto load-management placement outdoor placement outdoor

profile ap6522 default-ap6522 crypto load-management profile ap622 default-ap622

crypto load-management rf-domain default timezone America/New_York country-code us rfs4000 B4-C7-99-DD-F5-5E use profile default-rfs4000 use rf-domain default hostname rfs4000-ddf55e license AP DEFAULT-6AP-LICENSE license ADSEC DEFAULT-ADV-SEC-LICENSE service radius dynamic-authorization additional-port 3799 ip name-server 161.44.124.122 ip name-server 64.102.6.247 ip domain-name cisco.com use radius-server-policy ISE-CoA wlan wlan-ise1x bss 1 primary wlan wlan-ise1x bss 2 primary interface up1 switchport mode trunk switchport trunk native vlan 16 no switchport trunk native tagged

switchport trunk allowed vlan 10-11,16 ip address 192.168.0.1/24 no ip nat shutdown 0 ip address 172.16.11.1/24 no ip nat inside no dhcp-relay-incoming 1 ip address 172.16.12.1/24 ip nat inside 6 description "Virtual Interface for WAN" ip address 10.86.119.145/22 no ip nat outside no dhcp-relay-incoming use dhcp-server-policy DHCPPolicy use captive-portal server ISE-dynamic ip dns-server-forward logging on logging console warnings logging buffered warnings ip nat inside source list nat-rule precedence 10 6 overload end