SSIDs

The SSID application simplifies wireless network configuration with one-step provisioning, including SSID setup as well as authentication and policy configuration. When you create an SSID, relevant related default configurations (Access Role Profile, Access Policy, Authentication Strategy, Guest Access Strategy, BYOD Access Strategy, AAA Server Profile, Tunnel Profile, and Global Configuration) are automatically created and linked to the SSID using a name derived from the SSID. As you go through the creation/customization process you can customize these default SSID configurations to fit your network requirements.

The SSIDs screen displays information about all configured SSIDs. The screen displays up to 15 SSIDs at a time. Scroll to view additional SSIDs. If you have more than 15 SSIDs, you can choose which 15 SSIDs to display on the screen by customizing the display order. The screen is used to Enable/Disable SSIDs, create, edit, and delete SSIDs, and modify an SSID's AP Group Assignment and AP Availability Schedule.

Note: SSIDs can also be configured in the WLAN Service (Expert) application. Note that WLAN Name and WLAN Service Name refer to the SSID Service Name.

Creating an SSID

Click on the Add icon to create and customize a new SSID. Complete the fields on the Create SSID Screen and the Customize SSID Screen to customize the SSID configuration.

Create an SSID

Complete the fields as described below to create an SSID, then click on the Create & Customize button to customize the configuration. After completing the configuration, click on the Save and Apply to AP Group button to apply the SSID to AP Groups.

Customize an SSID

As mentioned earlier, when you create an SSID, relevant related default configurations (e.g., Access Role Profile, Access Policy, Authentication Strategy) are automatically created and linked to the SSID using a name derived from the SSID. As you go through the creation/customization process you can customize these SSID configurations to fit your network requirements.

When you create an SSID, the default configuration is displayed on the Customize SSID Screen. Complete the fields as described below to customize these defaults as well as additional SSID configurations. Note that the fields displayed depend on the Usage that you selected in the previous screen.

General

Private Group PSK

When a PSK-enabled SSID is created, you can either create a static PSK or enforce Device Specific PSK. This provides a common Passphrase key, which is suitable for networks requiring network-wide common PSK. Enabling the Private Group PSK (PPSK) allows you to create private groups of client devices based on a PPSK Entry. Each client device specifies a Passphrase when connecting to an SSID. If the passphrase matches any of the PPSK Entry, the client is placed in the specified Access Role Profile.

Configuring the Private Group PSK attribute is offered only when Device Specific PSK is Disabled or set to "Prefer Device Specific PSK". When the Device Specific PSK is set to "Force Device Specific PSK", OmniVista will not display the Private Group PSK attribute because the Passphrase specified in Company Property is used instead.

Complete the following fields to configure PPSK Entries:

Note: Each SSID can have up to 16 PPSK Entries. The total number of entries across all SSIDs that exist on an AP cannot exceed 64 on any AP.

Authentication Strategy

The following configuration options may be available, depending on the Usage you selected:

Note: The automatically generated AAA Server Profile is given the same name as the SSID. Do not make changes to this profile through the AAA Server Profile Page. For example, if you want to change the RADIUS server, edit the SSID and select a different RAIUS server. Alternatively, go to the AAA Server Profile page and select the corresponding profile row to make the edit.

Access Policy

Note: The "WLAN Name" Mapping Condition refers either to the "SSID Service Name" in the “SSIDs” application or to the "WLAN Service Name" in the WLAN Service (Expert) application.

Guest Access Strategy

The following configuration options may be available, depending on the Usage you selected:

BYOD Access Strategy

The following configuration options may be available, depending on the Usage you selected:

Default VLAN/Network

A Default Access Role Profile will be applied to clients joining this SSID if a role cannot be assigned by other role assignment methods. In this section, you can configure the Default VLAN/Network and other attributes of this Default Access Role Profile. You can either create a new Access Role Profile or use an existing Access Role Profile for this SSID.

Configure Access Role Attributes

Tunnel Guidelines

 If you create two tunnel profiles with the same Remote IP and Tunnel ID, the "Support of Entropy" status must be the same on both tunnels (both must be "enabled" or "disabled"). Choose the value based on what use case you plan to deploy. The following are the four possible use cases that are supported:

1. GRE Tunnel from AP to AOS Switch - This is the typical Guest Tunnel uses case where AOS acts as the Guest Tunnel Termination Switch. The AOS Switch expects the Tunnel ID to be non-0 and "Support of Entropy" must be "Enabled".

2. GRE Tunnel from AP to Non-AOS Switch/Server (e.g., Nokia 7750 SR/Standard Linux Tunnel Server) - This is the Guest Tunnel use case with a non-AOS switch. The Tunnel ID must be 0 and "Support of Entropy" must be "Disabled", as the Key field in L2GRE header is not expected by the Switch/Server.

3. GRE Tunnel Between AP and OV VPN Server Appliance - This is the regular Data VPN tunnel use case between Remote APs and and an OV VPN Server acting as the Data VPN Server. The Tunnel ID must be 0 and "Support of Entropy" must be "Disabled", as the Key field in L2GRE header is not expected by OV VPN Server.

4. GRE Tunnel from AP to AOS Switch, Over the Data VPN tunnel Between AP and OV VPN Server Appliance - This is a rare use case of using the Data VPN tunnel to reach from a remote site where the AP is located, to the Central Site where the AOS Switch is located. The AOS Switch expects the Tunnel ID to be non-0 and "Support of Entropy" must be "Enabled".

The following combinations of values are not supported:

Choose an Existing Access Role Profile

Advanced Access Role Configuration

Advanced WLAN Service Configuration

SSID Setting

QoS Settings

Editing an SSID

Select an SSID by clicking on the checkbox in the upper-left corner of the SSID column, then click on the Edit icon. The Customize SSID Screen appears. Edit the configuration as described above and click on the Save and Apply to AP Group button. The new configuration will be saved and applied to the AP Groups on which the SSID was previously applied.

If you edit an SSID that was created in a previous release of OmniVista Cirrus, there is an extra step in the edit process. When you click on the Edit icon, the Upgrade SSID Screen appears. Depending on the type of Security Level configured for the WLAN Service (Personal/Open), only certain Usages will be available for editing. Select a Usage and Captive Portal/BYOD configuration and click on the Upgrade & Customize button. The Customize SSID Screen appears. Edit the configuration as described above and click on the Save and Apply to AP Group button to apply the edited SSID to AP Groups.

Note: You can only edit one SSID at a time. You cannot edit the SSID Name.

Deleting an SSID

Select an SSID(s) by clicking on the checkbox in the upper-left corner of the SSID column, click on the Delete icon, then click OK at the Confirmation Prompt. Note that when you delete an SSID you delete the relevant related configurations created for the SSID (e.g., Access Role Profile, Access Policy, Authentication Strategy), unless those configurations are in use outside of this SSID.

Applying an SSID

The AP Group Assignment and Schedule Screen is used to apply SSIDs to AP Groups. You can also set an availability schedule for APs in a group. Select AP Groups as described below, set a schedule, and click on the Apply button.

Note: If you have just created an SSID, the SSID Name is displayed in the SSIDs field (as shown above). If you clicked on the AP Group Assignment and Schedule button to modify an existing SSID's AP Group assignment or AP Schedule, select an SSID from the SSID's drop-down menu.

Note: The maximum number of SSIDs per band that an AP can support is based on the AP model and whether the Extended SSID Scale option is enabled for the AP Group to which the AP belongs.

Applying an SSID to AP Groups

If you are creating a new SSID, the Default AP Group is pre-selected by default and is displayed in the AP Group area. Click on the Change Selection button to add/remove AP Groups.

Note: You do not have to apply the SSID to an AP Group when you create it. Click on the Cancel button to create the SSID without any AP Group assignment. You can apply AP Groups to the SSID at any time by selecting the SSID in the SSIDs Table and clicking on the AP Group Assignment and Schedule button.

If you are editing an SSID, all of the AP Groups to which the SSID was applied are displayed as pre-selected. Click on the Change Selection button to bring up the AP Group Selection window to add/remove AP Groups.

Scheduling AP Availability

By default, the schedule you set is applied to all selected AP Groups, however set different schedules for each selected AP Group, as described below:

Editing an SSID AP Group/Schedule

To edit an SSID's AP Group assignment or AP Schedule, select the SSID and click on the AP Group Assignment and Schedule button at the top of the SSIDs Screen. The AP Group Assignment and Schedule Screen appears with the selected SSID displayed in the SSIDs field. Edit the AP Groups and/or AP Schedule as described above and click on the Apply button.

Note that you can also just click on the AP Group Assignment and Schedule button and select the SSID you want to modify from the SSIDs drop-down menu.

Enabling/Disabling an SSID

Click on the checkbox next to an SSID(s) and select the Enable or Disable button to enable/disable an SSID. When you disable an SSID, the SSID stops broadcasting; the configuration remains on the AP. When you enable an SSID, it begins broadcasting again.

SSIDs Table

The SSIDs Screen displays information about all configured SSIDs. If a specific parameter has not been configured for an SSID, the field is blank. The screen displays up to 15 SSIDs at time. Scroll to view configured SSIDs. You can also customize the display order of the SSIDs on the screen. The screen can also be used to quickly edit relevant related SSID configurations (e.g., Access Role Profile, Access Policy, Authentication Strategy).

Customizing the Display

You can customize the order in which SSIDs are displayed on the screen, prioritizing them so that specific SSIDs are shown in the first columns. Click on the drop-down arrow at the top of a column to display a list of all configured SSIDs and select an SSID. The selected SSID will be displayed in that column.

The SSID that was previously displayed will not be "moved" to another location. To re-display that SSID, go to another column and repeat the procedure to re-display that SSID in that column.

If you have fewer than 15 SSIDs configured and create a new SSID, the new SSID will be displayed in the last column. However, if you have reached the maximum display of 15 SSIDs and create a new SSID, the SSID will not replace an existing SSID in the display. To display the SSID you must click on the drop-down at the top of one of the columns and select the new SSID.

Editing an SSID's Related Configurations

You can quickly edit relevant related SSID configurations (e.g., Access Role Profile, Access Policy, Authentication Strategy) from the SSIDs Screen. The names of these configurations are displayed as a hyperlink. Click on the link to open a configuration window. The configuration will be pre-selected with the Detailed Configuration information displayed. Click on the Edit icon on the window to edit the configuration. Click on the Apply button to apply the update, then click on the Close button to close the window and return to the SSIDs Screen.

Note: If you edit the Access Role Profile for an SSID, you must re-apply the profile to the SSID. After editing the Access Role Profile, select the SSID on the SSIDs Screen, and click on the AP Group Assignment and Schedule button. The AP Group Assignment and Schedule Screen appears. Click on the Apply button to apply the new configuration.

Note: When an SSID is created with a RADIUS Server, the auto-generated AAA Server Profile for the SSID assigns the RADIUS Server for Captive Portal and MAC authentication. If TLS was disabled for the RADIUS Server configured for the SSID, enabling TLS for the server will fail because a TLS-enabled RADIUS Server does not support Captive Portal and MAC authentication in the AAA Server Profile.