The wireless controller can discover remote access points over a site-to-site VPN connection or behind a remote NAT router without a VPN connection. Before attempting to autodiscover remote access points the following guidelines should be met:
• Enable SNMP and SSH on all standalone access points.
• Enable DHCP option 43 (vendor-specific information) on the DHCP server. Specify the wireless controller’s IP address to allow the access points to receive the wireless controller’s IP address and the DHCP server to assign IP addresses to the access points.
The DHCP server on the wireless controller automatically enables DHCP option 43 with its own IP address.
Please see the following guides for configuring DHCP option 43 on a Netgear switchand Windows Server.
• Access points which will operate behind a NAT router should first be converted to managed access points and then install behind the NAT router.
• Assign each access point an IP address. All access points that are the same model ship with the same default IP address. Except for access points in the factory default state that are in the same Layer 2 network at the remote site, if two or more access points are assigned the same IP address, then only one of them is discovered at a time. You must add the access point to the managed list, change its IP address, and then run discovery again to discover the next access point with that IP address.
• An access point must run at least its initial firmware release or a newer version. No other firmware requirements exist for the access point to function with the wireless controller.
• Unblock the following ports in the firewall at the site where the wireless controller is located so that the remote access points can communicate with the wireless controller:
- For models WC7600 and WC9500:
• TCP port 22. Used by Secure Shell (SSH) and Secure Copy (SCP) for the transfer of software images and large configuration files and for the transfer over a tunnel.
• UDP port 69. Used by TFTP for software image upgrades of standalone access points.
• UDP port 123. Used by Network Time Protocol (NTP).
• UDP port 138. Used by NetBIOS to resolve names.
• UDP port 161. Used by the SNMP discovery process.
• UDP port 6650. Used by the control channel between the wireless controller and the remote access point.
• UDP port 7890. Used by the multicast discovery process. This port does not need to be unblocked in a configuration in which remote access points are located behind a NAT router.
- For models WC7500 and WC7600v2:
• TCP port 22. Used by Secure Shell (SSH) and Secure Copy (SCP) for the transfer of software images and large configuration files and for the transfer over a tunnel.
• TCP port 6670. Used for communication and backward compatibility with access points that run an older firmware release.
• TCP port 6680. Used for communication and backward compatibility with access points that run an older firmware release.
• UDP port 69. Used by TFTP for software image upgrades of standalone access points.
• UDP port 123. Used by Network Time Protocol (NTP).
• UDP port 138. Used by NetBIOS datagram service.
• UDP port 161. Used by the SNMP discovery process.
• UDP port 6650. Used by the control channel between the wireless controller and the remote access point.
• UDP port 7000. Used for Layer 3 roaming support.
• UDP port 7890. Used by the multicast discovery process. This port does not need to be unblocked in a configuration in which remote access points are located behind a NAT router.
• UDP port 7892. Used for access point registration with the wireless controller after discovery.
• UDP port 7893. Used for access point registration with the wireless controller during multicast discovery.
Limitations after Discovery
The following limitations apply after remote access points have been discovered:
• Seamless Layer 2 roaming is supported for the clients of a remote access points, but seamless Layer 3 roaming is not supported for the clients across remote access points. When clients move from one IP subnet to another at the remote site, they are disconnected from their access point and need to reconnect to another access point.
• If a remote access point is disconnected from the wireless controller, for example, because the VPN connection goes down, the following occurs:
- The remote access point uses its last known configuration and functions as a standalone access point while continuously attempting to reconnect to the wireless controller.
- If the access point uses WPA-PSK, WPA2-PSK, or WPA-PSK & WPA2-PSK authentication, it can continue to accept new clients. If the access point uses RADIUS Access Point Discovery and Management authentication with the local RADIUS server of the wireless controller instead of an external RADIUS server, the access point can no longer accept new clients.
- If the access point is rebooted, it loses its configuration. After the connection with the wireless controller is reestablished, the remote access point functions once again as a managed access point.
It is important to first convert the remote AP to a managed AP before trying to add it as a remote access point. This requires joining the AP to the controller locally so the controller firmware is pushed onto the access point converting it to a managed access point.
Discovering remote access points
1. Select Access Point - Discovery Wizard.
There is three options to specify the state of the access points you wish to discover
- Out of Factory and L2 Subnet Ap's. The access point(s) have not been configured or deployed.
- Installed and working in Standalone Mode. The access points have been configured or deployed as standalone access point.
- I am not sure. Displays link to product documentation.
Click Next to proceed to the discovery wizard.
2 (b) Select Installed and working in Standalone Mode. (remote access points should already be installed and have an IP address assigned)
Click Next, you need to Specify IP range your remote access points are operating in. You may specify up to 3 IP ranges, click Next.
The controller will find your standalone access points in the specified subnet ranges. For each access point you wish to add to the controller, select the check box to the right of the access point and click ADD.
Note: this option is used when discovering access points across Layer 3 networks.
3. Enter access point password. If the access point password is the default password leave the password field blank, otherwise enter the current access point password and click ADD to proceed.
4. Once the access point is added it is shown in the Access Point - Discovery - Managed AP List.