Here is my configuration :
version 6.1.3.0-3.1.0
virtual-controller-country SG
virtual-controller-key 9c8888d30122e0e9e42ef5391dc6dc2f48251501eddee678e6
name ACP11-1
virtual-controller-ip 10.10.50.82
terminal-access
ntp-server 10.10.0.51
clock timezone Jakarta 07 00
rf-band 2.4
allow-new-aps
allowed-ap d8:c7:c8:c8:8b:04
allowed-ap d8:c7:c8:c8:8b:20
allowed-ap d8:c7:c8:c8:8b:0c
arm
wide-bands 24ghz
g-channels 6
min-tx-power 3
max-tx-power 127
band-steering-mode disable
air-time-fairness-mode fair-access
client-aware
scanning
syslog-level warn ap-debug
syslog-level warn network
syslog-level warn security
syslog-level warn system
syslog-level warn user
syslog-level warn user-debug
syslog-level warn wireless
user 1c659da23bd8 2c5b3ae2921fe0f4c51ab169fb722cfa0156f600d623a59b radius
user 0017c41a1998 e90ba7f0e792071e4e37b94fca7f414fa7009ca32c0e42b1 radius
user 001f3b0b06dd 99d69afb8124fa2b185ee79820a107a64679f4ebfb378815 radius
user 889ffa0b70e0 86c2cdd20d75a401c99e502490b8397adafcb54724ace334 radius
mgmt-user admin bc3be3a28338276bb378a9c7432ef042b8a1f1c0494e6520
wlan access-rule default_wired_port_profile
rule any any match any any any permit
wlan access-rule SIM-AN
rule any any match any any any permit
wlan access-rule default_dev_rule
rule any any match any any any permit
wlan ssid-profile SIM-AN
index 0
type employee
essid SIM-AN
wpa-passphrase 3a92121734a5de57c49f828926c7daa6561b72fefa2b1845
opmode wpa-psk-tkip,wpa2-psk-aes
max-authentication-failures 0
vlan 1
rf-band 2.4
captive-portal disable
dtim-period 1
inactivity-timeout 1000
broadcast-filter none
blacklist
dmo-channel-utilization-threshold 90
enet-vlan guest
wlan captive-portal
background-color 16777215
banner-color 16777215
banner-text "Welcome to the Guest Network."
terms-of-use "Please read and accept terms and conditions and then login."
use-policy "This network is not secure and use it at your own risk."
authenticated
wlan external-captive-portal
server localhost
port 80
url "/"
auth-text "Authenticated"
blacklist-time 60
auth-failure-blacklist-time 60
blacklist-client e0:91:53:39:ea:b9
blacklist-client 18:20:32:72:eb:d6
blacklist-client 10:78:d2:e2:15:fe
ids
wireless-containment none
wired-port-profile default_wired_port_profile
switchport-mode trunk
allowed-vlan all
native-vlan 1
shutdown
access-rule-name default_wired_port_profile
speed auto
duplex full
no poe
type employee
captive-portal disable
enet0-port-profile default_wired_port_profile
enet1-port-profile default_wired_port_profile
enet2-port-profile default_wired_port_profile
uplink
preemption
enforce none
l3-mobility