How an Access Point or Access Switch Gets Assigned to a Unit

Units that belong to properties that are part of a network segmentation group can be assigned either an access point (AP) or access switch (also referrred to as an "edge switch") to provide network connectivity. With an AP, you also assign an ethernet port to the unit. With an access switch, you assign a port on the switch, then Cloudpath assigns a VLAN once the end user is authenticated.

Assigning an AP to a Unit

  1. To assign an AP and an ethernet port, click the magnifying glass for a unit such as unit 1a in Property Details Example After Adding Two Units.
  2. In the "Network Segmentation Information" section of the ensuing screen, click Assign Access Point.

    Using the Assign Access Point Button

  3. From the Access Point drop-down (see screen below), select the AP and a single ethernet port to assign to the Unit, then click Save.

    Access Point Selection

  4. After your selection is saved, you can check that the "Network Segmentation Information" on the screen reflects the selection, as shown in the following screen example:

    Network Segmentation Information For a Unit After Access Point Is Selected

    You can use the buttons shown as follows:

    • Change Access Point: This button allows you to change your selection from the Access Point drop-down list.
    • Remove Assignment: This button removes the access point and ethernet port assignments from the unit.
    • Assign Ports: This button invokes a popup screen that shows available ethernet ports you can select.

  5. Repeat the preceding steps to assign APs to other units in the property.
  6. If you return to the Units tab view of the property, the access points and port selections you have made now appear:

    Units Tab View of Property With AP and Port Assigned to Two Units in a Property

How an Access Switch and VLAN Get Assigned to a Unit

The port on the access switch (also called the "edge switch") that is physically connected to a specific unit is determined by the network administrator.

To complete the switch assignment, the end user must be authenticated. After authentication occurs, Cloudpath assigns a unique VLAN to the unit from a pool of VLANs configured on SmartZone for the network segmentation profile,

Therefore, the following steps must occur for the end user to be authenticated and the switch assignment to be completed.

  1. The end user plugs their device into the switch port for their unit. This invokes a captive portal - the Web Authentication page - where the user logs in.

    Web Authentication Page Example

  2. In the "PassPhrase or DPSK Prompt" field (the exact name of this field is determined by the network administrator in Setup Access Switches in the "Password Label" field,) the DPSK secret for the unit (or the Guest DPSK, if applicable) must be entered. The DPSK secret must be provided by the network administrator to the end user. To find the DPSK secret, navigate to the following location in the Cloudpath UI: Managed Access > Properties, then click the wrench icon of the desired property, click the Units tab, then click the magnifying glass of the unit whose DPSK secret you need. The Unit Information portion of the Unit screen for Unit 2a is shown below:

    Unit Information Screen Containing DPSK Secret

  3. Click the magnifying glass to reveal the DPSK secret, as shown in the example below:

    DPSK Secret Unhidden

    The key "zoawvezvovld" is the password that the unit 2a user would need to enter in the Web Auth page.

  4. As network administrator, you may want to check the "Network Segmentation Information" portion of the Unit screen for Unit 2a to make sure that the switch port and VLAN assignments are now reflected there, as shown in the example screen below:

    Unit 2a Example After Switch Port and VLAN Assignment Has Occurred

  5. The preceding steps can be followed to assign switch ports and VLANs to other units in the property.
  6. To view all VLAN assignments in the network segmentation group:
    1. In the Cloudpath UI, navigate to Managed Access > Network Segmentation.
    2. Click the wrench icon for the network segmentation group.
    3. Click the Distribution Switches tab.
    4. Click the magnifying glass icon for the distribution switch.
    5. Click the Switch VLANs tab. The Switch VLANs table is displayed, as shown in the example below:

      Switch VLANs Tab

      The table shows all VLANs that have been assigned to units in the network segmentation grouo as well as their corresponding assigned VNIs. The available VLANs and available VNIs are based on the configuration on SmartZone for this network segmentation profile.

Example of Assigned VNIs After APs and Switches Have Been Added

The following example screen shows the information that the Assigned VNIs tab provides if your network segmentation group is currently using both APs and switches. Navigate in the Cloudpath UI to Managed Access > Network Segmentation Groups, then click the wrench icon for the group, then click the Assigned VNIs tab.

Example of Assigned VNIs Tab After APs and Switches Have Been Assigned