CISCO 887VA-W Integrated Access-Point – DUAL SSID’s
CISCO 887VA-W WIRELESS + INTERGATED ACCESS-POINT
Cisco Router Configuration :
interface Wlan-GigabitEthernet0
description Internal switch interface connecting to the embedded AP
switchport mode trunk
no ip address
!
interface wlan-ap0
description Embedded Service module interface to manage the embedded AP
ip unnumbered Vlan1
no ip redirects
no ip unreachables
!
!
Create 2 VLANS :
interface Vlan1
description DODDS-WIFI
ip address 10.10.66.200 255.255.255.0
ip access-group CLIENT_LAN in
ip nat inside
ip inspect myfw in
ip virtual-reassembly in
ip tcp adjust-mss 1400
!
interface Vlan2
description DODDS-GUEST
ip address 192.168.66.200 255.255.255.0
ip access-group GUEST_LAN in
ip nat inside
ip inspect myfw in
ip virtual-reassembly in
ip tcp adjust-mss 1400
To ensure VLAN 2 is created, we suggest you configure one of the router’s FastEthernet interfaces
so that it is assigned to VLAN 2. This will force the router to create VLAN 2 in its VLAN database:
int fastethernet0/0
switchport access vlan 2
!
!
Create 2 VLAN ACCESS-LISTS
VLAN 1 :
ip access-list extended CLIENT_LAN
remark DHCP
permit udp any eq bootpc any eq bootps
remark SPOOFED
deny ip any host 10.10.66.255
deny ip any host 10.10.66.0
deny ip host 0.0.0.0 any
remark PERMIT_ALL
permit ip 10.10.66.0 0.0.0.255 any
remark DENY_ALL
deny ip any any log
!
VLAN2 :
ip access-list extended GUEST_LAN
remark DHCP
permit udp any eq bootpc any eq bootps
remark SPOOFED
deny ip any host 192.168.66.255
deny ip any host 192.168.66.0
deny ip host 0.0.0.0 any
remark DENY_GUESTLAN_TO_LAN
deny ip 192.168.66.0 0.0.0.255 10.10.66.0 0.0.0.255
remark PERMIT_GUESTLAN
permit ip 192.168.66.0 0.0.0.255 any
remark DENY_ALL
deny ip any any log
!
!
Create 2 DHCP Scopes for both Networks :
ip dhcp pool CLIENT
import all
network 10.10.66.0 255.255.255.0
default-router 10.10.66.200
dns-server 10.10.1.11 10.10.1.2 10.10.66.200
lease 0 12
update arp
ip dhcp pool GUEST
import all
network 192.168.66.0 255.255.255.0
default-router 192.168.66.200
dns-server 192.168.66.200
lease 0 12
update arp
!
!
Default Config in place :
bridge 1 protocol ieee
bridge 1 route ip
!
!
Cisco ACCESS-POINT Configuration :
CREATE 2 SSID’s for the 2 VLAN’s
dot11 ssid DODDS-WIFI
vlan 1
authentication open
mbssid guest-mode
!
dot11 ssid DODDS-GUEST
vlan 2
authentication open
authentication key-management wpa
mbssid guest-mode
wpa-psk ascii 7 00564302545F0F1528341F1B1D4855
!
!
Wireless Radio Interface Configuration :
interface Dot11Radio0
no ip address
no ip route-cache
!
encryption vlan 1 key 1 size 128bit 7 B4FC3CB4C9F77341AC86BD5936B9 transmit-key
encryption vlan 1 mode wep mandatory
!
encryption vlan 2 mode ciphers tkip
!
ssid DODDS-GUEST
!
ssid DODDS-WIFI
!
antenna gain 0
speed basic-12.0 basic-18.0 basic-24.0 basic-36.0 basic-48.0 basic-54.0 m0. m1. m2. m3. m4. m5. m6. m7. m8. m9. m10. m11. m12. m13. m14. m15.
channel 2412
station-role root
!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
bridge-group 1 spanning-disabled
!
interface Dot11Radio0.2
encapsulation dot1Q 2
no ip route-cache
no cdp enable
bridge-group 2
bridge-group 2 subscriber-loop-control
bridge-group 2 block-unknown-source
no bridge-group 2 source-learning
no bridge-group 2 unicast-flooding
bridge-group 2 spanning-disabled
!
!
INTERVLAN Routing Interface :
interface GigabitEthernet0
description the embedded AP GigabitEthernet 0 is an internal interface connecting
AP with the host router
no ip address
no ip route-cache
!
interface GigabitEthernet0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
no bridge-group 1 source-learning
bridge-group 1 spanning-disabled
!
interface GigabitEthernet0.2
encapsulation dot1Q 2
no ip route-cache
bridge-group 2
no bridge-group 2 source-learning
bridge-group 2 spanning-disabled
!
!
CREATE 2 Bridge Interfaces :
interface BVI1
description CLIENTLAN
ip address 10.10.66.201 255.255.255.0
no ip route-cache
!
interface BVI2
description GUESTLAN
ip address 192.168.66.201 255.255.255.0
ip helper-address 10.10.66.200
no ip route-cache
!
!
Default bridge group is 1, Create bridge 2 for Bridge interface BV2 &
interface GigabitEthernet0.2
bridge 1 protocol ieee
bridge 1 route ip
bridge 2 protocol ieee
Create a Default Route over to Cisco Router VLAN 1 :
ip default-gateway 10.10.66.200
Complete Router Configs :