{"id":2400,"date":"2011-11-19T21:45:00","date_gmt":"2011-11-20T05:45:00","guid":{"rendered":"https:\/\/thebeagle.itgroove.net\/?p=63"},"modified":"2023-02-24T21:47:07","modified_gmt":"2023-02-24T21:47:07","slug":"sonicwall-wireless-primer","status":"publish","type":"post","link":"https:\/\/regroove.ca\/archive\/2011\/11\/19\/sonicwall-wireless-primer\/","title":{"rendered":"Sonicwall Wireless Primer"},"content":{"rendered":"<p>All new generation Sonicwall firewalls support \u201ccentrally controlled access\u201d wireless management via the built-in wireless in the <b><i>TZ100W, TZ200W, TZ210W, NSA220W, NSA250MW<\/i><\/b> and\/or via one or more <b><i>SonicPoints<\/i><\/b>. Both the built-in wireless and the SonicPoints allow for provisioning multiple \u201cvirtual\u201d access points or <b><i>VAP\u2019s<\/i><\/b>. A VAP is a specific wireless profile that can have settings that are totally different from other VAP\u2019s applied to the wireless or the SonicPoint. The end result can be a single physical access point (built-in wireless or SonicPoint) that provides the services of multiple access points from the point of view of wireless clients. In practice this means that a single Sonicwall wireless network can provide secured, locked-down \u201ccorporate\u201d access and less secure, \u201copen\u201d guest access all at once using VAP\u2019s. What\u2019s more, two or more SonicPoints can share all the same settings so that the controlled wireless network can be made seamless across a large physical location.<\/p>\n<p>As an example, Company A will be installing an NSA240 along with a SonicPoint (more may be added down the road) to provide both secure corporate access to authenticated users as well as open, public access to guests in their office. The one SonicPoint will appear as multiple access points (more on this in a bit). If they add another SonicPoint to extend coverage that SonicPoint will take on all the same characteristics as the first one and the SonicPoints will perform seamless hand off of client connections, one to the other.<\/p>\n<p>The trick to configuring the VAP\u2019s is to understand how networking to the VAP\u2019s needs to be configured.<\/p>\n<p>In all cases, separate networks are required to be set up in various network zones in order to provide the basics for separation of secured versus unsecured traffic (corp vs. guest) as firewall rules can be enforced on traffic that has to cross network zones. The trick to the separation is to create VLAN\u2019s on the Sonicwall pre-configured network port that supports the built-in wireless or on the port that has been assigned to the WLAN zone (or custom created zone) to which SonicPoint(s) will be connected. (Keep in mind that if you are VLAN\u2019ing for SonicPoints that you will need to either run a single cable to a single SonicPoint from the Sonicwall port OR you will need a switch that can pass VLAN\u2019d traffic.) VLAN\u2019s are added to a Sonicwall port on the Network Interface page (Add Interface option). When VLAN\u2019s are created a DHCP scope is also created for the specified network and the interface port is given a static IP (it becomes the gateway for the VLAN\u2019d network).<\/p>\n<p>Once VLAN\u2019s are added the VAP profile(s) can be created. In essence, a VAP profile is created to set all of the parameters that you want to see for a given type of access just as you would configure settings on a physical access point. Things like the SSID and the encryption type are set within the VAP profile along with the desired network (think VLAN) and the radio settings. One or more VAP profiles can then be added to a VAP Group. A VAP Group can be thought of as the \u201csuper profile\u201d that will then be applied to one or more SonicPoint radios. It is the VAP group that provisions a SonicPoint with the multiple virtual access points.<\/p>\n<p>The built-in wireless on \u201cW\u201d models can be provisioned with one VAP Group (there is one radio). The single-radio SonicPoints (SonicPoint Ni and Ne) can also be provisioned with one VAP Group. The dual-radio SonicPoint NDR can be provisioned with two VAP Groups providing there is NO overlap between the VAP groups (e.g. no overlap of VLAN\u2019s).<\/p>\n<p>Sonicwall also provides for additional configuration for \u201cguest\u201d networks with an array of predefined \u201cguest network\u201d settings. When enabled things like enforced logon to the guest wireless network can be controlled through a simple login webpage; when a client connects to the wireless they cannot actually use the network without authenticating in some fashion to the login webpage. Sonicwall also provides a mechanism whereby access to the \u201ccorporate\u201d wireless network can be more fully secured by enforcing the requirement that the client machine connect over the network using a Sonicwall VPN client.<\/p>\n<p>When a SonicPoint is attached to a TZ or NSA unit, it will download and boot the latest firmware from the host. Once the firmware is downloaded the unit will reboot and it will then load whatever appropriate profile has been assigned to it specifically OR it will download the default profile that has been created for its model type (NDR, N for the Ni or Ne, G for older SonicPoint G\u2019s). If the downloaded profile has a VAP (or VAP\u2019s) configured then the SonicPoint will provide access over one or more VAP\u2019s. This ability to use VAP\u2019s and profiles gives a SonicPoint network a great deal of flexibility. NOTE: A SonicPoint cannot be used as a standalone access point in a network that does not have an appropriate TZ or NSA host unit; SonicPoint\u2019s are totally \u201cdumb\u201d units that rely on a TZ or NSA host to provide their firmware, profile and settings.<\/p>\n<p>The built-in wireless on the \u201cW\u201d models as well as the wireless in the SonicPoint Ni and Ne is 2.4GHz b\/g\/n compliant. The dual-radio SonicPoint NDR has one 2.4GHz b\/g\/n radio and one 5 GHz a\/n radio. The 5GHz radio will work with clients that have 5GHz radios but will not talk to the 2.4GHz radios. The \u201cW\u201d models as well as the SonicPoint\u2019s Ne and NDR have external antenna\u2019s (three per radio) while the SonicPoint Ni only has a single concealed internal antenna. The external antennae tend to provide better coverage than does the internal antenna on the Ni while the 5GHz radio on the NDR provides the most powerful signal and the most bandwidth. All SonicPoints are PoE enabled; the Ni unit is PoE only while the Ne and NDR can also be powered by an external power supply.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>All new generation Sonicwall firewalls support \u201ccentrally controlled access\u201d wireless management via the built-in wireless in the TZ100W, TZ200W, TZ210W, NSA220W, NSA250MW and\/or via one or more SonicPoints. Both the built-in wireless and the SonicPoints allow for provisioning multiple \u201cvirtual\u201d access points or VAP\u2019s. A VAP is a specific wireless profile that can have settings &hellip; <a href=\"https:\/\/regroove.ca\/archive\/2011\/11\/19\/sonicwall-wireless-primer\/\"><\/a><\/p>\n","protected":false},"author":10,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[266],"tags":[473,503,573,611,625,631,637,655],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Sonicwall Wireless Primer - Archive<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/regroove.ca\/archive\/2011\/11\/19\/sonicwall-wireless-primer\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Sonicwall Wireless Primer - Archive\" \/>\n<meta property=\"og:description\" content=\"All new generation Sonicwall firewalls support \u201ccentrally controlled access\u201d wireless management via the built-in wireless in the TZ100W, TZ200W, TZ210W, NSA220W, NSA250MW and\/or via one or more SonicPoints. Both the built-in wireless and the SonicPoints allow for provisioning multiple \u201cvirtual\u201d access points or VAP\u2019s. A VAP is a specific wireless profile that can have settings &hellip;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/regroove.ca\/archive\/2011\/11\/19\/sonicwall-wireless-primer\/\" \/>\n<meta property=\"og:site_name\" content=\"Archive\" \/>\n<meta property=\"article:published_time\" content=\"2011-11-20T05:45:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-02-24T21:47:07+00:00\" \/>\n<meta name=\"author\" content=\"Sean Wallbridge\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sean Wallbridge\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/regroove.ca\/archive\/2011\/11\/19\/sonicwall-wireless-primer\/\",\"url\":\"https:\/\/regroove.ca\/archive\/2011\/11\/19\/sonicwall-wireless-primer\/\",\"name\":\"Sonicwall Wireless Primer - Archive\",\"isPartOf\":{\"@id\":\"https:\/\/regroove.ca\/archive\/#website\"},\"datePublished\":\"2011-11-20T05:45:00+00:00\",\"dateModified\":\"2023-02-24T21:47:07+00:00\",\"author\":{\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77\"},\"breadcrumb\":{\"@id\":\"https:\/\/regroove.ca\/archive\/2011\/11\/19\/sonicwall-wireless-primer\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/regroove.ca\/archive\/2011\/11\/19\/sonicwall-wireless-primer\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/regroove.ca\/archive\/2011\/11\/19\/sonicwall-wireless-primer\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog Archive\",\"item\":\"https:\/\/regroove.ca\/archive\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Sonicwall Wireless Primer\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/regroove.ca\/archive\/#website\",\"url\":\"https:\/\/regroove.ca\/archive\/\",\"name\":\"Archive\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/regroove.ca\/archive\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77\",\"name\":\"Sean Wallbridge\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g\",\"caption\":\"Sean Wallbridge\"},\"url\":\"https:\/\/regroove.ca\/archive\/author\/swallbridge\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Sonicwall Wireless Primer - Archive","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/regroove.ca\/archive\/2011\/11\/19\/sonicwall-wireless-primer\/","og_locale":"en_US","og_type":"article","og_title":"Sonicwall Wireless Primer - Archive","og_description":"All new generation Sonicwall firewalls support \u201ccentrally controlled access\u201d wireless management via the built-in wireless in the TZ100W, TZ200W, TZ210W, NSA220W, NSA250MW and\/or via one or more SonicPoints. Both the built-in wireless and the SonicPoints allow for provisioning multiple \u201cvirtual\u201d access points or VAP\u2019s. A VAP is a specific wireless profile that can have settings &hellip;","og_url":"https:\/\/regroove.ca\/archive\/2011\/11\/19\/sonicwall-wireless-primer\/","og_site_name":"Archive","article_published_time":"2011-11-20T05:45:00+00:00","article_modified_time":"2023-02-24T21:47:07+00:00","author":"Sean Wallbridge","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sean Wallbridge","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/regroove.ca\/archive\/2011\/11\/19\/sonicwall-wireless-primer\/","url":"https:\/\/regroove.ca\/archive\/2011\/11\/19\/sonicwall-wireless-primer\/","name":"Sonicwall Wireless Primer - Archive","isPartOf":{"@id":"https:\/\/regroove.ca\/archive\/#website"},"datePublished":"2011-11-20T05:45:00+00:00","dateModified":"2023-02-24T21:47:07+00:00","author":{"@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77"},"breadcrumb":{"@id":"https:\/\/regroove.ca\/archive\/2011\/11\/19\/sonicwall-wireless-primer\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/regroove.ca\/archive\/2011\/11\/19\/sonicwall-wireless-primer\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/regroove.ca\/archive\/2011\/11\/19\/sonicwall-wireless-primer\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog Archive","item":"https:\/\/regroove.ca\/archive\/"},{"@type":"ListItem","position":2,"name":"Sonicwall Wireless Primer"}]},{"@type":"WebSite","@id":"https:\/\/regroove.ca\/archive\/#website","url":"https:\/\/regroove.ca\/archive\/","name":"Archive","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/regroove.ca\/archive\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77","name":"Sean Wallbridge","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g","caption":"Sean Wallbridge"},"url":"https:\/\/regroove.ca\/archive\/author\/swallbridge\/"}]}},"_links":{"self":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/2400"}],"collection":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/comments?post=2400"}],"version-history":[{"count":1,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/2400\/revisions"}],"predecessor-version":[{"id":3084,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/2400\/revisions\/3084"}],"wp:attachment":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/media?parent=2400"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/categories?post=2400"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/tags?post=2400"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}