Set up your essensys SSID at a single site to ensure your Occupier's receive the best possible Digital experience and get the most out of your essensys Intelligence. Follow this process at more than 1 site & you will enhance your Intelligence & create your network of connected spaces.
Please note the process below is for Meraki WAPs only.
Configure the correct SSID on your Access Points
Log into your Meraki Dashboard (Meraki cloud portal)
Navigate to 'Wireless', go to the 'Configure' column & select 'SSIDs'.
A new SSID should be created to be configured to essensys specifications & creating this separately will allow for testing. This maybe all or some of your WAPs within a building, ensure the correct WAPs have been selected where you want to broadast essensys services.
SSID name: "Wi-Fi Secure" (no quotes)
The specific naming of this SSID is important to allow your customers to roam between buildings. Without consistent SSID naming, a user will need to re-login to WiFi every time they visit a new site.
When the SSID is built, click 'edit settings' next to Access Control row.
Configure the SSID with the following Access Control:
SSID status - Enabled
Security - Enterprise with my RADIUS server
WiFi personal network (WPN) - Disabled
WPA encryption - WPA2 only
802.11r - Disabled
802.11w - Disabled
Mandatory DHCP - Disabled
Splash page - None (direct access)
Add a RADIUS server;
Host IP - [To be shared by essensys]
Auth Port - [To be shared by essensys]
Secret - [To be shared by essensys]
RADSec - [To be shared by essensys]
Add a RADIUS accounting server;
Host IP - [To be shared by essensys]
Acct Port - [To be shared by essensys]
Secret - [To be shared by essensys]
RadSec - [To be shared by essensys]
Radius testing - Disabled
RADIUS CoA support - Disabled
Dashboard RADIUS proxy - Disabled
RADIUS attribute specifying group policy name - Reply-Message
Advanced RADIUS settings:
NAS ID - Custom (from excel sheet) *
keep the rest of the settings as default
Client IP and VLAN - External DHCP server assigned - Bridged
Layer 3 roaming - Disabled
RADIUS override - Ignore VLAN attribute
RADIUS guest VLAN - Disabled
Bonjour forwarding - Disabled
VLAN tagging - VLAN ID (Default - use own internal VLAN ID)
Assign group policies by device type - Disabled
Configure Location Analytics for new SSID
Go to 'Network-wide', 'General' and scroll down to Location & scanning
Double check you have Wi-Fi Secure selected as the network on the left hand side.
Analytics - Analytics enabled
Scanning API - Scanning API enabled
Validator: (this will be automatically generated, please share with essensys)
Add a Post URL;
Post URL - [To be shared by essensys]
Secret - [To be shared by essensys]
API Version - V3
Radio Type - WiFi
Click "Validate" to ensure changes are saved.
Tag your WiFi Access points for your new SSID;
Go to 'Wireless', 'Access points' and ensure you are on the 'List View'
Double check you have Wi-Fi Secure selected as the network.
You should be presented with a list of WiFi access points which are now broadcasting this new SSID
Select all via the check box
A 'tag' option will become available
Create a new tag 'EXTERNAL' & Save
Lastly,
Go to 'Wireless', 'Firewall & traffic shaping' and ensure you are on the 'List View'
Double check you have Wi-Fi Secure selected as the network
Set 'Layer 2 LAN isolation' - Enabled.
Save
To ensure the configuration is correct, we advise a test is carried out. The process for this can be found here.