Configuring VLAN Tagging between Netscreen and Netgear WNDAP360
- Netgear: Configure VLAN tagging on all Netgear Security Profiles
- Configuration -> Security -> Profile Settings
- Select each enabled profile, and choose Edit
- Assign a unique VLAN ID to each Profile
- Configuration -> IP -> IP Settings
- Select DHCP Client enable (so Netgear will be accessible after enabling VLANs on Netscreen)
- Netscreen:
- Create VLAN configuration
- unset interface vlan1 ip
- set interface ethernet0/3.1 ip 6.6.6.254/24
- set interface ethernet0/3.1 nat
- set interface ethernet0/3.2 ip 6.6.7.254/24
- set interface ethernet0/3.2 nat
- set interface ethernet0/3.1 dhcp server service
- set interface ethernet0/3.2 dhcp server service
- set interface ethernet0/3.1 dhcp server enable
- set interface ethernet0/3.2 dhcp server enable
- set interface ethernet0/3.1 dhcp server option gateway 6.6.6.254
- set interface ethernet0/3.1 dhcp server option netmask 255.255.255.0
- set interface ethernet0/3.1 dhcp server option domainname example.com
- set interface ethernet0/3.1 dhcp server option dns1 6.6.6.11
- set interface ethernet0/3.1 dhcp server option dns2 8.8.8.8
- set interface ethernet0/3.1 dhcp server option dns3 8.8.4.4
- set interface ethernet0/3.1 dhcp server option smtp 6.6.6.11
- set interface ethernet0/3.2 dhcp server option lease 60
- set interface ethernet0/3.2 dhcp server option gateway 6.6.7.254
- set interface ethernet0/3.2 dhcp server option netmask 255.255.255.0
- set interface ethernet0/3.2 dhcp server option domainname example.com
- set interface ethernet0/3.2 dhcp server option dns1 8.8.8.8
- set interface ethernet0/3.2 dhcp server option dns2 8.8.4.4
- set interface ethernet0/3.1 dhcp server ip 6.6.6.100 to 6.6.6.149
- set interface ethernet0/3.2 dhcp server ip 6.6.7.100 to 6.6.7.149
- unset interface ethernet0/3.1 dhcp server config next-server-ip
- unset interface ethernet0/3.2 dhcp server config next-server-ip
- set address "Trust" "6.6.6.0" 10.53.48.0 255.255.255.0 "Trusted Wireless"
- set address "Untrust" "6.6.7.0" 172.16.47.0 255.255.255.0 "Untrusted Wireless"
- set interface ethernet0/3.1 dhcp server ip 6.6.6.50 mac
- set interface bgroup0 dhcp server ip 6.6.5.50 mac
- Create Reasonable Policies for Untrusted and Trusted wireless segments.
Comments
Post a Comment