Management and Configuration Guide Supplement 4.4.0.50
5
Support for VLANs and Subnets
that was configured for the Access Controller under 4.1.3.93. This untagged
subnet provides the functionality available under 4.1.3.93, and is used for
communication between the Access Controller and the Access Control Server.
Under the Interfaces tab, the Subnet sub-tab (where subnets could be config-
ured for downlink ports) is no longer available.
See the ProCurve Secure Access 700wl Series Software Version 4.4 Update
Guide for a more detailed discussion, including an example, of how to
configure the Access Controller for upstream VLANs. If you have been using
the downlink port subnet feature, the Update Guide describes how to migrate
your settings to the new method.
The following provides a brief overview of the tasks required to use subnets
and VLANs with software release 4.4.0.50:
■ For each upstream subnet you want clients to be able to access, create
a VLAN for the subnet. You can do this either directly under the Local
Networks page for the Access Controller, or you can do it under the
Global Network page. Creating subnets globally through the Global
Network page will save time if you need to configure multiple Access
Controllers with the same set of VLANs/subnets—you will be able to
select the subnet to go with the VLAN ID, rather than re-entering all
the subnet information for each Access Controller.
If you create the subnets on the Local Networks page, a Global Subnet
Group is created automatically. If an appropriately configured DHCP
server is available on the subnet, the DHCP, DNS and other information
in the Global Subnet Group can be obtained from the DHCP server.
■ For each VLAN you define, create an Access Policy that specifies the
appropriate VLAN ID. The VLAN tag value can be set under the
Settings tab in the New or Edit Access Policy page.
Traffic from clients who get their rights through this Access Policy will
be tagged with the correct VLAN ID, and that traffic will be sent to the
correct upstream subnet. If these clients are to receive Real IP addresses,
this mechanism will ensure that they receive an IP address from the DHCP
server in the correct subnet.
■ Revise your Rights Table configuration so that clients are associated
with the appropriate Access Policy (and thus the appropriate VLAN/
subnet) based on their Identity and/or how they connect to the
system.