For each profile group, the Edit Profile (Group-X, in which X is the group number) screen lets you create and configure up to 8 security profiles per wireless radio (8 profiles for a single-band access point; 16 profiles for a dual-band access point). Separate profiles are applied to 802.11b/bg/ng-mode and 802.11a/na-mode radios.
To add a security profile to an advanced profile group and configure the security profile:
- Open a web browser. In the browser's address field, type the http:// followed by the IP address that you assigned to the wireless controller.
By default, the IP address is 192.168.0.250. If you have not yet assigned another IP address to the wireless controller, type http://192.168.0.250.
The wireless controller's login screen displays. - Enter your user name and password.
If you have not yet personalized your user name and password, enter admin for the user name and password for the password, both in lowercase letters. - Click the Login button.
The wireless controller's web management interface opens and displays the Summary screen. - Select Configuration > Profile > Advanced > Radio.
The Profile Groups screen displays. - Click the Edit button.
The Edit Profile (Group-X) screen displays. - Click the tab for the radio that for which you want to add a profile.
- Click the + button to add the profile to the selected advanced profile group.
The Add Profiles pop-up screen displays:

- (Optional) Clone an existing profile:
a. Select the Clone an existing Profile check box.
b. Select a profile from the Profiles menu. - Click the Add button.
The newly created profile displays onscreen, and the tab for the new profile is automatically selected to let you configure the new profile.
Note: The authentication server settings that you specify on the Authentication Server screen affect the selections that are available from the Network Authentication menu.

- Configure the settings as described in the following table:
Setting Description Profile Definition section Name Enter a unique name to identify the profile.
This value can be up to 32 alphanumeric characters. Use meaningful profile names instead of the default names. The default profile names are Profile1, Profile2, and so on, through Profile8.Wireless Network Name (SSID) Enter a unique name for the wireless network associated with this profile. Broadcast Wireless Network Name Select the Yes radio button to enable broadcast of the SSID.
This is the default setting.
Select the No radio button to disable broadcast of the SSID, in which case only devices that have the correct SSID can connect to the access point.Client Authentication section
Note: The options that display onscreen depend on your selection from Network Authentication menu.Network Authentication From the menu, select the authentication type to be used.
The table in "What are the network authentication and data encryption options for my ProSAFE Wireless Controller WC7600?Data Encryption From the menu, select the data encryption type to be used.
The options available for data encryption as well as other requirements such as entering a key or passphrase depend on the network authentication settings.
The table in "What are the network authentication and data encryption options for my ProSAFE Wireless Controller WC7600?Wireless Client Security Separation From the menu, select Disable to prevent associated wireless clients from communicating with each other, or select Enable to allow such communication. Wireless client separation is intended for hotspots and other public access situations. VLAN Enter the VLAN ID to be associated with this security profile.
This VLAN ID must match the VLAN ID that other network devices use.Authentication Settings section
Note: The options that display onscreen depend on the selection from Network Authentication menu.Note: The MAC ACL
buttons displays only when
you select Open System,
Shared Key, WPA-PSK,
WPA2-PSK, or
WPA-PSK & WPA2-PSK
from the Network
Authentication menu.MAC ACL Select one of the following radio buttons:
• Local. Use local MAC authentication.
The Local MAC ACL Group menu displays so you can
select a group. For more information, see "How do I manage mac authentication and mac authentication groups on my ProSAFE Wireless Controller WC7600?".
• External. Use external MAC authentication.
The External Radius Server menu displays so you can
select a server. You can select either the basic-Auth
RADIUS server or a RADIUS server of an advanced
authentication group. You cannot use the external LDAP
server.
For information about setting up and enabling internal and
external authentication servers.
Note: The MAC ACL radio buttons do not display onscreen if
the network authentication uses an external RADIUS server.
The reason for this is that you can configure either MAC
authentication with an external RADIUS server or network
authentication with an external RADIUS server, but not both.
That is, if you configure an external RADIUS server with WPA,
WPA2, or WPA & WPA2 (or you use Legacy 802.1X), you
cannot use external MAC authentication, and the MAC ACL
radio buttons do not display on screen. You can still use internal
MAC authentication.Note: The Captive
Portal check box displays
only when you select
Open System, Shared
Key, WPA-PSK,
WPA2-PSK, or
WPA-PSK & WPA2-PSK
from the Network
Authentication menu.Captive Portal Select the Captive Portal if you want to enable the captive portal.
For more information, see "How do I manage guest network access on my ProSAFE Wireless Controller WC7600?".
Note: If the network authentication uses a RADIUS server,
whether it is a local server or an external server, you cannot
configure captive portal authentication. That is, if you configure
a RADIUS server with WPA, WPA2, or WPA & WPA2 (or if you
use legacy 802.1X), the Captive Portal check box is not shown
onscreen.Note: The
Authentication Server
buttons and menu display
only when you select WPA
with Radius, WPA2 with
Radius, or WPA & WPA2
with Radius from the
Network Authentication
menu.Authentication Server Select one of the following radio buttons:
• Local. Use the local authentication server.
• External. Use an external authentication server.
Select an external authentication server from the
Authentication Server menu.
Note: For information about setting up and enabling internal
and external authentication servers, see "How do I specify the type of authentication server and what are the authentication server concepts for my ProSAFE Wireless Controller WC7600?Wireless QoS section Wi-Fi Multimedia (WMM) To enable Wi-Fi Multimedia (WMM), select the Enable radio button, which is the default setting.
Select the Disable button to disable the feature. For more information, see "How do I manage the Quality of Service (Qos) for an advanced profile group for my ProSAFE Wireless Controller WC7600?WMM Powersave The WMM Powersave feature saves power for battery-powered equipment by increasing the efficiency and flexibility of data transmission.
To enable this feature, select the Enable radio button, which is the default setting.
Select the Disable button to disable the feature. - Click the Apply button.