The following sample scenario consists of an advanced network with one wireless controller, one redundant wireless controller, one core switch, two PoE switches in different buildings, access points, and several VLANs and SSIDs. These are the components in the wireless controller system:
- One wireless controller
- 50 access points (managed by the wireless controller through management VLAN 1)
- One redundant wireless controller
- Four VLANs: VLAN 10, VLAN 20, VLAN 30, and VLAN 40
- Three SSIDs: SSID 1, SSID 2, and SSID 3
In this scenario, the VLANs and SSIDs are used to accommodate traffic for different user groups in a school that is spread out over two buildings.
- Building 1:
-SSID 1 in VLAN 10 for staff traffic
-SSID 2 in VLAN 20 for middle school students
-SSID 3 in VLAN 30 for guests - Building 2:
-SSID 1 in VLAN 10 for staff traffic
-SSID 2 in VLAN 40 for high school students
-SSID 3 in VLAN 30 for guests

The access points and wireless controllers are connected in the same subnet and same VLAN and use the same IP address range that is assigned for that subnet. The core switch is located between the wireless controllers and the PoE switches, to which the access points are connected. The core switch provides Internet access.
This network configuration has the following prerequisites:
- VLAN 1 is configured on the wireless controllers, core switch, and PoE switches. This VLAN is untagged.
- VLANs 10, 20, and 30 are configured on the wireless controllers, core switch, and the PoE switch in Building 1. These VLANs are tagged.
- VLANs 1, 10, 20, 30, and 40 are configured on the wireless controllers, core switch, and PoE switches. Except for VLAN 1, these VLANs are tagged.
To provision the wireless controller:
Access Point > Discovery Wizard| Step | Configuration | Web management interface path |
| 1. | Configure the basic system settings: | |
| 1. Configure the country code of operation. | Configuration > System > General | |
| 2. Configure the time settings. | Configuration > System > Time | |
| 3. Configure the IP address of wireless controller. | Configuration > System > IP/VLAN | |
| 4. Verify that VLAN 1 is set as the management VLAN and is marked as untagged. By default, VLAN 1 an untagged management VLAN. |
||
| 2. | Configure the following profiles, and configure network authentication and data encryption for these profiles: |
|
| 1. A profile with SSID 1 and VLAN 10. | Configuration > Profile > Basic | |
| 2. A profile with SSID 2 and VLAN 20. | ||
| 3. A profile with SSID 2 and VLAN 30. | ||
| 4. A profile with SSID 3 and VLAN 40. | ||
| 5. If necessary for the selected network authentication options, configure one or more authentication servers. | Configuration > Security > Basic > Authentication Server |
|
| 3. | Configure the following profile groups: | |
| 1. A profile group with the name Building 1, to which you add the following profiles: - The profile with SSID 1 and VLAN 10 - The profile with SSID 2 and VLAN 20 - The profile with SSID 2 and VLAN 30 |
Configuration > Profile > Advanced | |
| 2. A profile group with the name Building 2, to which you add the following profiles: - The profile with SSID 1 and VLAN 10 - The profile with SSID 2 and VLAN 30 - The profile with SSID 3 and VLAN 40 |
||
| 4. | Deploy the access points and connect them to PoE switches. | |
| 5. | When the access points are operating, open the Discovery Wizard to do the following: |
|
| 1. Specify the state of the access points, which is factory default in a Layer 2 network. | ||
| 2. Run the Discovery Wizard. | ||
| 3. Select and add the access points that you want to be managed by the wireless controller to the managed list. Note: By default, all access points are added to the basic group. |
||
| 6. | Assign the access points to the access point profile groups (also referred to as WLAN groups) Building 1 and Building 2. | Configuration > WLAN Network |