Enterprise AV Home WiFi Mobile Wifi Support Shop Deals

The wireless controller can discover remote access points over a site-to-site VPN connection or behind a remote NAT router without a VPN connection. Before attempting to autodiscover remote access points the following guidelines should be met:

• All standalone access points need to have SNMP and SSH enabled.
• The following ports need to be unblocked in the firewall at the site where the wireless controller is located in order for the remote access points to communicate with the wireless controller:
- TCP port 22. Used by Secure Shell (SSH) and Secure Copy (SCP) for the transfer of software images and large configuration files and for the transfer over a tunnel.
- UDP port 69. Used by TFTP for software image upgrades of standalone access points.
- UDP port 123. Used by Network Time Protocol (NTP).
- UDP port 138. Used by NetBIOS to resolve names.
- UDP port 161. Used by the SNMP discovery process.
- UDP port 6650. Used by the control channel between the wireless controller and the remote access point.
- UDP port 7890. Used by the multicast discovery process. This port does not need to be unblocked in a configuration in which remote access points are located behind a NAT router.

• Enable DHCP option 43 (vendor-specific information) on the DHCP server. Specify the wireless controller’s IP address to allow the access points to receive the wireless controller’s IP address and the DHCP server to assign IP addresses to the access points. The DHCP server on the wireless controller automatically enables DHCP option 43 with its own IP address.
Please see the following guides for configuring DHCP option 43 on a Netgear switch

• Access points behind a NAT router first need to be converted to managed access points and then be installed behind the NAT router.

• Each access point needs to have an IP address. All access points that are the same model ship with the same default IP address. With the exception of access points in factory default state that are in the same Layer 2 network at the remote site, if more than one access point has the same IP address, then only one of them is discovered at a time. You have to add the access point to the managed list, change its IP address, and then run discovery again to discover the next access point with that IP address.

• An access point needs to run at least its initial firmware release or a newer version.

 

Limitations after Discovery
The following limitations apply after remote access points have been discovered:
• Seamless Layer 2 roaming is supported for the clients of a remote access points, but seamless Layer 3 roaming is not supported for the clients across remote access points. When clients move from one IP subnet to another at the remote site, they are disconnected from their access point and need to reconnect to another access point.
• If a remote access point is disconnected from the wireless controller, for example, because the VPN connection goes down, the following occurs:
- The remote access point uses its last known configuration and functions as a standalone access point while continuously attempting to reconnect to the wireless controller.
- If the access point uses WPA-PSK, WPA2-PSK, or WPA-PSK & WPA2-PSK authentication, it can continue to accept new clients. If the access point uses RADIUS Access Point Discovery and Management authentication with the local RADIUS server of the wireless controller instead of an external RADIUS server, the access point can no longer accept new clients.
- If the access point is rebooted, it loses its configuration. After the connection with the wireless controller is reestablished, the remote access point functions once again as a managed access point.

 

It is important to first convert the remote AP to a managed AP before trying to add it as a remote access point. This requires joining the AP to the controller locally so the controller firmware is pushed onto the access point converting it to a managed access point.

Discovering Remote access points
1. Select Access Point - Discovery Wizard.
Select the radio button to specify the state of the access points you want to discover
Installed and working in Standalone Mode. The access points have been configured or deployed as standalone access point in remote location.
Click Next to proceed to the discovery wizard.

2. Specify IP Range. Enter the start IP and End IP of the IP subnet where the access point(s) are installed.
It is possible to specify only a single class C subnet range, if you have access points in different IP subnet ranges, use the ADD function to specify more IP subnet ranges.

3. A list of discovered access points is displayed. Select the radio button to the left of an access point and click ADD to join it to the Managed AP List.
It is possible to add more than one AP at a time, however the controller will process one access point at a time, before moving onto the next access point.

4. Enter access point password. If the access point password is the default password leave the password field blank, otherwise enter the current access point password and click ADD to proceed.

5. Once the access point is added it is shown in the Access Point - Discovery - Managed AP List.

Last Updated:07/07/2025 | Article ID: 31444

This article applies to:

Recently Viewed Articles

    Our team is here to help!

    Phone
    Chat
    Email