Introduzione e demo di configurazione dello schema di autenticazione Fabebook WiFi per le Aziende. Esempio con utilizzo della funzionalità di ENSEMBLE per la gestione centralizzata sino a 10 AP.
Webinar NETGEAR - AP ProSafe WAC720 e WAC730 configurati con autenticazione Facebook Business WiFi
1. Access Point ProSAFE
WAC720 e WAC730
Configurazione dell’autenticazione
Facebook Business Wi-Fi
Formazione Online
2. Introducing
High performance Business Grade Dual Band 802.11ac Wireless Access Point for Small and Medium Enterprise
with aggregated throughput up to 1.7 Gbps
WAC730 - 450 Mbps for 2.4 GHz and 1.3 Gbps 802.11ac for 5 GHz
WAC720 - 300 Mbps for 2.4 GHz and 867 Mbps 802.11ac for 5 GHz
Designed for;
• Small and Medium Enterprises
• K-12 schools requiring gigabit throughput for multimedia applications
• Hospitalities requiring high capacity and superior wireless performance
• Manufacturing and retail stores requiring complete wireless coverage
WAC720/WAC730 are WC7500/WC7600/WC9500 and Business Central Wireless
Cloud Manager manageable.
WAC730 3x3 and WAC720 2x2 Dual Band
802.11ac Access Points
WAC730 WAC720
3. Optional power supply is available to be purchased
separately.
(12 VDC, 1.5A)
PAV12V-100NAS (for North America)
PAV12V-100AUS (for Australia)
PAV12V-100EUS (for Europe, except UK)
PAV12V-100UKS (for UK)
PAV12V-100PRS (for China)
The intended main power source is PoE 802.3af (<13W.)
Kensington lock (theft
prevention)
Console access.
WAC730 3 antenna takeoffs
External (2.4/5GHz) antenna takeoffs
WAC720 2 antenna takeoffs
4. WAC720 & WAC730 features
11ac Support
+ WAC720 supports 2x2 on 802.11AC
+ WAC730 supports 3x3 on 802.11AC
+ Beam forming is enabled on both 2.4GHz and 5 GHz radios
+ Bandsteering : Effectively utilizes 5GHz by steering dual-band clients
from 2.4GHz to 5GHz band
5. Captive Portal
+ The Standalone AP captive portal feature is supported
+ Verification can be configured to allow access for both guest and
authenticated users.
+ Authenticated users must be validated against a database of authorized
Captive Portal users before access is granted. Supports both IPV4 and
IPv6
WAC720 & WAC730 features
6. Load Balancing
+ The AP allow associations of authenticated clients while the wireless
network utilization is below configured threshold. Once the threshold is
reached, no new associations are allowed.
+ The AP starts load balancing when the configured network utilization
threshold is exceeded. Clients are denied associations once this occurs,
Load balancing continues until the network utilization drops below the
configured threshold.
WAC720 & WAC730 features
7. Ensemble, Ensemble firmware upgrade
+ Ensemble mode provides a centralized ensemble firmware upgrade
feature that allow all the APs in the cluster to be updated from the
dominant AP. The upgrade can be performed only from dominant AP.
+ The dominant AP downloads the firmware from an external filter using
TFTP mechanism, and stores it locally on the flash of the dominant AP.
WAC720 & WAC730 features
11. Facebook Business WiFi
To configure Facebook's Wi-Fi for your business, you must be an Administrator
of a Business Page that has a valid address
12. Facebook Business WiFi
AP1-Facebook
Only valid positions pages can use Facebook's Wi-Fi, so you'll have to create
a different page for each store or site of your business.
15. Chamber
StopStart
Basic
General
Time
Advanced
Ensemble General ApplyCancel
Configuration Monitoring Maintenance Support
System IP Wireless Bridge Security Ensemble Captive Portal
?
ApplyCancel
Ensemble Name
AP Name
Priority (0 – 255)
Ensemble Mode
default
ensemble1
0
Chamber
255
AP1-Facebook
default
255
Basic
Ensemble General
Management
Secured Ensemble
Advanced
192.168.0.2
AP #1 (Dominant AP)
“Ensemble” works by matching a unique identifier which
must be common to all of the access points that you
want sharing in the configuration.
In this case I will call this Ensemble group “default”
The access points that get configured with the same
Ensemble identifier will commence an election process for
dominance, all things being equal a dominant AP will be
determined by the lowest MAC address.
However we have the option to make this AP the dominant
agent by entering a high priority value.
In a case where the “next-standing” dominant AP fails we
could give other access points “graded” values to assign an
order for assuming dominance over the group.
NOTE:
The dominant AP will distribute its configuration to all
standing members of the Ensemble.
In the event that the “Dominant” AP fails, this duty will go to
the next ranking priority member, as stipulated by its MAC
address in combination with the value entered in the priority
field.
This value serves as a tie-breaker and pretty much guarantees
predictable priority ranking among the Ensemble members.
After entering a value click on “Start” and then
“Apply.”
192.168.0.2 192.168.0.3
AP1-Facebook
16. Chamber
Basic
Ensemble General
Management
Secured Ensemble
Advanced
Configuration
Basic
Monitoring Maintenance Support
System IP Wireless Bridge Security Ensemble
Ensemble General
ApplyCancel
Management
Secured Ensemble
Captive Portal
Started
Ensemble General
IP Address to manage Ensemble (IPv4)
ApplyCancel
Ensemble Status
192.168.0.9
Advanced
192.168.0.2
AP #1 (Dominant AP)
One of the most convenient aspects of “Ensemble” is the fact that it is
possible to “address” the group (regardless of which AP is currently
dominant) by using a single additional IP address.
Simply assign an available IP address from the LAN on this field.
You only need to do this on the “dominant” AP.
Click on “Secure Ensemble.”
NOTE:
The AP’s own IP address will remain unchanged.
This AP will, in fact, respond to two different IP
addresses.
If you were to “arp –a” you will get two IP addresses
from this AP’s MAC address.
192.168.0.2 192.168.0.3
192.168.0.9
In the case where the standing dominant AP fails this “Ensemble-address 172.31.99.60” will be used by the “next-standing-dominant-AP.”
AP1-Facebook
17. Chamber
Secured Ensemble
Secure Mode
Passphrase (8-63
characters)
DisabledEnabled
Re-authentication Timeout (300-8600 secs)
Ensemble Status Started
Basic
Ensemble General
Management
Secured Ensemble
Advanced
Basic
Ensemble General
Management
Secured Ensemble
Advanced
Configuration Monitoring Maintenance Support
System IP Wireless Bridge Security Ensemble
ApplyCancel
Captive Portal
ApplyCancel
300
facebook
192.168.0.2
AP #1 (Dominant AP)
The configuration for the remaining APs consists only of the name of
the “Ensemble” and the “Secure Ensemble” Passphrase.
192.168.0.2
AP1-Facebook
192.168.0.9
192.168.0.3
18. ChamberChamber
StopStart
Basic
General
Time
Advanced
Ensemble General ApplyCancel
Configuration Monitoring Maintenance Support
System IP Wireless Bridge Security Ensemble Captive Portal
?
ApplyCancel
Ensemble Name
AP Name
Priority (0 – 255)
Ensemble Mode
default
ensemble2
0
Chamber
200
AP2-Facebook
default
200
Basic
Ensemble General
Management
Secured Ensemble
Advanced
192.168.0.3
AP #1 (Dominant AP)
We are joining this AP to our Ensemble-group “default”
We gave our previous AP the highest possible priority value of 255 to make sure it is elected dominant by
the ensemble.
I want this AP to be the “next dominant” access point in this group. Which is to say that if “AP1-Facebook”
fails “AP2-Facebook” will take on the roll. I will give it the value of 200
After entering our value click on “Start” and then “Apply.”
We don’t need to go into management since we already have a dominant AP in the “Ensemble.”
We can go directly to “Secured Ensemble” to set our passphrase.
192.168.0.2 192.168.0.3
192.168.0.9
AP1-Facebook AP2-Facebook
19. ChamberChamber
Secured Ensemble
Secure Mode
Passphrase (8-63
characters)
DisabledEnabled
Re-authentication Timeout (300-8600 secs)
Ensemble Status Started
Basic
Ensemble General
Management
Secured Ensemble
Advanced
Configuration Monitoring Maintenance Support
System IP Wireless Bridge Security Ensemble
ApplyCancel
Captive Portal
ApplyCancel
default
300
facebook
Basic
Ensemble General
Management
Secured Ensemble
Advanced
192.168.0.3
Once the passphrase is set the AP will be able to interpret
the “Ensemble data” that our dominant AP is broadcasting
and will learn the name of the other members of the
ensemble…. Until then, the APs would be on separate
Ensembles.. Even if they had the same name.
AP #2 (non-dominant )
192.168.0.2 192.168.0.3
192.168.0.9
AP1-Facebook AP2-Facebook
20. 20
Ensemble Shared Data Data NOT shared
SSID IP local address
Wireless Security Access Point Names
Guest Access Settings Channel Information
NTP Settings Advanced Wireless Settings
Radio Settings VLAN
Network Security Settings Packet Capture
Quality of Service Settings
Access Lists
Username and Password
Shared DATA:
The APs will synchronize a great deal of data, but not all..
When you think about the fact that all the members of an Ensemble must be on the same layer 2 environment it makes sense why things
like VLANs are not shared.
The advanced wireless settings are such, that you want to configure that on a per AP basis anyway, like the beacons and RTS thresholds..
ChamberChamber
192.168.0.2 192.168.0.3
192.168.0.9
AP1-Facebook AP2-Facebook
21. Basic
Configuration Monitoring Maintenance Support
Channel Assignment
Advanced
ApplyCancel
Channel Assignment
Channel Assignment
System IP Wireless Bridge Security Ensemble Captive Portal
Auto Assign Channels
Ensemble Status
Settings
192.168.0.9
Started
IP Address
192.168.0.2
192.168.0.2
192.168.0.3
192.168.0.3
Radio
50:6A:03:80:5C:F0
50:6A:03:80:5C:F0
50:6A:03:80:34:B0
50:6A:03:80:34:B0
Band
11a-na-ac
11bgn
11a-na-ac
11bgn
Channel
100
1
36
6
Status
up
up
up
up
Proposed Channel Assignments
IP Address Radio Proposed Channel
StopStart Refresh
Ensemble “default”
While in Ensemble mode, every menu
will have an “Ensemble” link.
Let’s start with Configuration /
Advanced / Ensemble and under
“Channel Assignment” we can see if the
system currently allocated channels and
if it has any proposals to change
channels.
ChamberChamber
192.168.0.2 192.168.0.3
192.168.0.9
AP1-Facebook AP2-Facebook
22. Configuration
Basic
Monitoring Maintenance Support
System IP Wireless Bridge Security Ensemble
Channel Assignment
Advanced
ApplyCancel
Channel Assignment
Channel Assignment
Captive Portal
Channel interference
ApplyCancel
Ensemble Status
Settings
192.168.0.9
Started
Channel Selection Interval (minutes)
75% 1 Day
Ensemble “default”
Related to the channel assignment
under the settings we can
determine how much interference is
acceptable before changing the
channels.. we can also determine
how often these changes can be
made.
Simple and effective.
Ensemble assigns different radio channels to be used by the ensemble APs to reduce mutual interference or interference with neighboring AP’s outside of the group It maps
APs to a radio channel and measures any interference levels in the continuously.
If RF interference is detected, Ensemble automatically re-assigns some (or all) of the APs to new channels as per an efficiency algorithm.
The frequency of these channel re-assignments is user configurable with a default value of once a day.
Ensemble uses the signal strength and operating channel of any detected AP as a means to find the optimal channel to use with the goal to reduce the aggregate interference
in the wireless neighborhood.
The previous channel assignment is stored for use in case the interference reduction using the new algorithm is higher than a particular threshold. Channel re-assignment must
be evaluated between dynamic channel change and frequency of channel change.
ChamberChamber
192.168.0.2 192.168.0.3
192.168.0.9
AP1-Facebook AP2-Facebook
24. Configuration Step-by-Step
1. Disable Business Central management (automatic reboot)
2. Configure WiFi geographic area (automatic reboot)
3. Configure static IP address for management
4. Configure the Host Name
5. Configure System Clock
6. Enable Facebook WiFi login
7. Enable Ensemble management mode
24
A) For each AP
25. Configuration Step-by-Step
1. Setup SSIDs
2. Setup Authentication profile
25
B) Ensemble Master AP
C) For each AP
1. Associate the Facebook page