Description:

This article describes how to set up LEPS-U with dynamic VLAN on an access point with LCOS LX.


LANCOM Enhanced Passphrase Security User (LEPS-U) allows different users to be created, each with their own separate passphrase. This avoids having one global passphrase for an SSID. Instead, there are several passphrases, which can then be distributed individually.

This can be used for onboarding devices to the network, for example when a network operator wants to onboard multiple Wi-Fi devices to different areas of their network, but does not want to configure the devices since the users of the devices should do it themselves. In this case, users are given their own individual pre-shared key for the company Wi-Fi to use with their own devices.

The pre-shared key is used to map each user to a VLAN, which automatically assigns them to a specific network. The configuration of LEPS-U takes place on the infrastructure side only, so assuring full compatibility to third-party products.

The security issue presented by global passphrases is remedied by LEPS- U. Each user gets their own individual passphrase. If a passphrase assigned to a user should get lost or an employee with knowledge of their passphrase leaves the company, then only the passphrase of that user needs to be changed or deleted. All other passphrases remain valid and confidential.

LEPS on LANCOM access points with LCOS LX is only compatible with WPA2.


Requirements:

Procedure:

1) Connect to the access point via LANconfig, switch to the menu Wireless-LAN → WLAN-Networks and choose the Country where the access point is operated.

2) Open the menu Wireless-LAN → WLAN-Networks → Network.

3) Adjust the following parameters:

4) Go to the menu Wireless-LAN → Stations/LEPS and set LEPS active to the option Yes.

5) Open the menu Wireless-LAN → Stations/LEPS → Profiles.

6) Create a new profile and adjust the following parameters:

7) Open the menu Wireless-LAN → Stations/LEPS → Users.

8) Create a new entry to add a default user. This user should have access to the default network (VLAN ID is entered into the LEPS-U profile).

Adjust the following parameters:

9) Create another new entry to add a special user. This user should have access to a special network (VLAN ID is entered into the LEPS-U user)

Adjust the following parameters:

10) This concludes the configuration of LEPS-U with dynamic VLAN. You can now write the configuration back to the device.