Note
Ports on the Universal APs are labeled ETH0, ETH1. Other AP models label the ports GE1, GE2 or LAN1, LAN2. In all cases, the user interface field labels display "ETH0" and "ETH1" which are equivalent to GE1 and GE2, and LAN1 and LAN2, respectively.Untagged traffic from an access port to a single VLAN on ExtremeCloud IQ Controller. (The wired port is associated with a single network.)
Tagged traffic using a Transparent Bridge that supports a trunk port to multiple VLANs.
For more information, see Configure Transparent Bridge.
The Client Bridge deployment includes one or more infrastructure APs. After provisioning, the Client AP connects to normal infrastructure services. The infrastructure AP is essentially any AP deployed for standard service offering. The infrastructure APs communicate with the ExtremeCloud IQ Controller supporting the usual traffic flow. The Client Bridge AP roams like a wireless client, supporting background scanning to determine available infrastructure APs. The Client Bridge AP associates on the infrastructure AP SSID (using network credentials) establishing a Client Bridge link with the infrastructure.
When the Client Bridge AP is in Client mode, the wired clients connected to it are controlled by the same policies as the wireless clients that are connected to any other AP.
When the Client Bridge AP is in Transparent Bridge mode, the Client Bridge AP transparently forwards all traffic without monitoring individual sessions.
Configure the Client Bridge settings on ExtremeCloud IQ Controller from the configuration Profile. The Client Bridge AP is a member of a device group that references a Profile configured for Client Bridge.
Configure the Client Bridge AP mode in the Profile Advanced dialog, as follows:
To support Client mode, set the ETH1 port function to Client.
To support Transparent Bridge mode, set the ETH1 Port Function to Bridge in the dialog for the device or device profile.
Define Client Bridge from the Radios tab within the configuration Profile. Only one radio can be configured as a Client Bridge. This can be either radio. Regardless of which radio is configured as the Client Bridge, both radios will continue to provide service.
Note
The Bridge port is not supported on access points with a single Ethernet port.Note
For ExtremeCloud IQ Controller deployments with network policy assignment for proper end-system visibility, the Client Bridge AP must be in a Centralized Site (Campus mode) and must be managed by ExtremeCloud IQ Controller.Note
Network policy is applied to both wired and wireless clients in the same way. The network policy is enforced on the Client Bridge AP before the network traffic is forwarded. All configuration updates are pushed to the Client Bridge AP before being applied to the infrastructure AP.
Note
For a Client Bridge path, policy enforcement for clients is handled at the Client Bridged AP, including any adjustments to topology assignment (VLAN Tagging). The infrastructure AP operates purely as a transparent bridge for the traffic that is received from the Client Bridge AP. The same applies to management network access. If the infrastructure is configured to require management traffic on a specific VLAN, and is tagged by the infrastructure AP, the same configuration needs to be applied to each Client Bridge AP, ensuring that the VLAN tags match the infrastructure requirement. It behaves essentially as if the Client Bridge access point was directly connected to the same infrastructure switch port as the infrastructure AP that provides the path for wireless connectivity.