To provide wireless access to teleworkers, the Cisco 881W Integrated Services Router uses an
access-point service module that runs its own image and has its own flash memory, independent
from the router. This access-point module supports IEEE 802.11n draft 2.0, thus providing a
higher capacity and better security.
Two additional interfaces exist that are used to communicate with the access-point module:

wlan-ap0, and wlan-GigabitEthernet0.
You must configure the wlan-ap0 interface with an IP address (any private IP address works;
check RFC 1918 for available private subnets) in order to allow reverse Telnet from the router
to the access-point module:

interface wlan-ap0
description Service module interface to manage the embedded AP
ip address <wlanap0-ip-address> 255.255.255.255
!
As mentioned earlier, one advantage of having the access-point module is that it can be
deployed in both modes:

autonomous (standalone), and lightweight (unified).

In lightweight mode, the access point associates with a WLAN controller and downloads its
configuration file from there. Thus you must do all the necessary configuration for secure
wireless access on the controller.
!
In autonomous mode, the configuration is entered on the access point itself, without using a
WLAN controller in the middle.

The following command is used on the router to define the mode of operation of the access point:
service-module wlan-ap 0 bootimage autonomous, for autonomous mode
service-module wlan-ap 0 bootimage unified, for lightweight mode

Configure the wlan-GigabitEthernet0 interface as a trunk in order to allow traffic from multiple
VLANs
to pass onto the access point:

interface Wlan-GigabitEthernet0
description Internal switch interface connecting to the embedded AP
switchport mode trunk
switchport trunk native vlan 10

!
!

881 Router Config :

interface FastEthernet4
ip address (PUBLIC_LAN_IP_ADDRESS)
!
interface wlan-ap0
description Service module interface to manage the embedded AP
ip unnumbered Vlan1
no ip redirects
no ip unreachables
arp timeout 0
!
interface Wlan-GigabitEthernet0
description Internal switch interface connecting to the embedded AP
!
interface Vlan1
Description LAN
ip address 192.168.1.1 255.255.255.0
!
bridge 1 protocol ieee
bridge 1 route ip

!
!

881w Integrated AP : Access-Point :

dot11 mbssid
dot11 syslog

!
dot11 ssid CommsWireless
vlan 1
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 050A130C351D1E074A560547

!
interface Dot11Radio0
no ip address
no ip route-cache

!
encryption vlan 1 mode ciphers tkip
!
encryption mode ciphers tkip
!
broadcast-key vlan 1 change 30
!
!
ssid CommsWireless
!
antenna gain 0
speed  basic-12.0 basic-18.0 basic-24.0 basic-36.0 basic-48.0 basic-54.0 m0. m1. m2. m3. m4. m5. m6.
m7. m8. m9. m10. m11. m12. m13. m14. m15.
station-role root

!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
bridge-group 1 spanning-disabled

!
interface GigabitEthernet0
description the embedded AP GigabitEthernet 0 is an internal interface connecting AP with the host router
no ip address

!
interface GigabitEthernet0.1
encapsulation dot1Q 1 native
bridge-group 1
no bridge-group 1 source-learning
bridge-group 1 spanning-disabled

!
interface BVI1
description LAN
ip address 192.168.1.2 255.255.255.0

!
ip default-gateway 192.168.1.1
!
bridge 1 protocol ieee
bridge 1 route ip

See complete Configuration for Router part as well as AP part.