HP Advanced Services zl Module with Microsoft® Windows Server® 2008 R2 Planning and Design Guide

3-8
Solution 2: Survivable Wireless Networking
Solution Implementation
Internal interface 1—In this solution, the Mobility Controller’s Inter-
net interface bridges wireless users’ traffic into the LAN (the APs
could alternatively bridge the traffic themselves). This interface is
assigned untagged to VLAN 294. It is also tagged for the user-based
VLAN.
The IP address will be 10.29.4.20/24 on the untagged VLAN. The tagged
VLAN will not have IP addresses.
Internal interface 2—The Mobility Controller’s LAN interface con-
nects to the APs. It is assigned to a new VLAN reserved for the APs,
VLAN 192. The IP address will be 192.168.4.1/24.
Port Authentication
In this example, the HP zl switch at the branch enforces 802.1X authentication
on edge ports. To ensure that users can authenticate during WAN failure, add
the IP address of the server that runs on the Advanced Services zl Module as
a secondary RADIUS server.
Switch Clock
The HP zl Services Modules take their time from the switch clock. If that clock
is not accurate, the services might fail; for example, the Windows Server 2008
R2 running on the module cannot join the domain. Therefore, it is recom-
mended that the HP zl switch use SNTP to synchronize its clock to the same
server used by the domain controller.
Example Configuration
The configuration below indicates the time, VLAN, IP, and 802.1X configura-
tion on the HP zl switch in this example solution. Your switch might be
configured with other features as well. In this example:
The switch connects to a WAN router with an Internet connection on port
A1
The switch connects to APs on ports B1 to B17
The E-MSM765 zl Mobility Controller is installed in slot C
The Advanced Services zl Module with Microsoft Windows Server 2008
R2 is installed in slot E
Note The configuration includes the VLAN assignment for the HP Services zl
Modules’ internal ports. However, you will not be able to configure these
assignments until you install the modules.