# cnMatrix (LAN)

## Assigning a switch to a switch group

Select the *Devices* tab, go to the *Switches* tab and select the switch. Go to the *Configuration* tab and select the group to which the switch should belong.

```{thumbnail} /_images/network-devices-configuration/cambium-networks/wired/cnmatrix-maestro/LAN_SW.png
:width: 25 %
```

## Switch group configuration

After logging in to the management panel, select the *Switch Groups* tab and create a new group or modify an existing one.

Go to the *Configuration* section, to the *Management* tab. Here we specify the SNMP, NTP, syslog and administrative access settings:

```{thumbnail} /_images/network-devices-configuration/cambium-networks/wired/cnmatrix-maestro/LAN_MGMT1.png
:width: 25 %
```
```{thumbnail} /_images/network-devices-configuration/cambium-networks/wired/cnmatrix-maestro/LAN_MGMT2.png
:width: 25 %
```

Go to the *Network* tab. Select the *DHCP Snooping* option.

```{thumbnail} /_images/network-devices-configuration/cambium-networks/wired/cnmatrix-maestro/LAN_NET.png
:width: 25 %
```

### VLAN Voice

Here you should also specify the VLANs for the VoIP service: one for the voice domain (*Voice*) and one for the data domain (*Data*).

```{thumbnail} /_images/network-devices-configuration/cambium-networks/wired/cnmatrix-maestro/LAN_VoIP1.png
:width: 25 %
```
```{thumbnail} /_images/network-devices-configuration/cambium-networks/wired/cnmatrix-maestro/LAN_VoIP2.png
:width: 25 %
```

Go to the *Security* tab. Enter the IP, keys, and RADIUS ports.

```{thumbnail} /_images/network-devices-configuration/cambium-networks/wired/cnmatrix-maestro/LAN_RADIUS.png
:width: 25 %
```

Go to the *Switch Ports* section. Select the ports to edit, then select *Edit*.

```{thumbnail} /_images/network-devices-configuration/cambium-networks/wired/cnmatrix-maestro/LAN_PORTS.png
:width: 25 %
```

Go to the *Network* tab. We set the ports as *Access*, specify the default VLAN and disable STP (or enable the *Port Fast* option.)

```{thumbnail} /_images/network-devices-configuration/cambium-networks/wired/cnmatrix-maestro/LAN_PORTS2.png
:width: 25 %
```

Go to the *Security* tab. Set *Port Control* to *Auto*, *Host Mode* to *Multi Host*, *MAC Authentication Bypass* to *Enable*. Set *DHCP Snooping* to *Untrusted*.

```{thumbnail} /_images/network-devices-configuration/cambium-networks/wired/cnmatrix-maestro/LAN_PORTS3.png
:width: 25 %
```

*Save*.

### VoIP Port (*multi-domain*)

Go to the *Network* tab. We set the ports as *Hybrid*, specify the default VLAN and disable STP (or enable the *Port Fast* option.)

```{thumbnail} /_images/network-devices-configuration/cambium-networks/wired/cnmatrix-maestro/LAN_VoIP4.png
:width: 25 %
```

If the phone supports the *LLDP-MED* functionality, it should also be enabled on the switch.

```{thumbnail} /_images/network-devices-configuration/cambium-networks/wired/cnmatrix-maestro/LAN_VoIP5.png
:width: 25 %
```

Go to the *Security* tab. Set *Port Control* to *Auto*, *Host Mode* to *Multi Host*, *MAC Authentication Bypass* to *Enable*. Set *DHCP Snooping* to *Untrusted*.

```{thumbnail} /_images/network-devices-configuration/cambium-networks/wired/cnmatrix-maestro/LAN_VoIP6.png
:width: 25 %
```

The port in VoIP mode will, regardless of the VLAN returned from NV, assign the *Voice* and *Data* VLANs as tagged and untagged VLANs, respectively. 


### Port CP

The guest access port is configured like an access port, but the authorization order should be changed to *MAB 802.1x*.

```{thumbnail} /_images/network-devices-configuration/cambium-networks/wired/cnmatrix-maestro/LAN_CP.png
:width: 25 %
```

## Reauthentication (CoA) settings

In NACVIEW, the following reauthentication settings should be set:

* port 3799
* MAC address format: MM-MM-MM-SS-SS-SS
* password identical to the RADIUS server password
* CoA format: Cisco IOS

```{thumbnail} /_images/network-devices-configuration/cambium-networks/wired/cnmatrix-maestro/COA.png
:width: 25 %
```

