OK. So..in the AP group for the rap in the configuration options, you have a header labeled "AP". Expand it. You will see ethernet port configurations. Enet0 is the WAN port and you cannot change it. Enet 1-4 correspond to the LAN ports on the RAP5. Within each port, you will create the following profiles
1. Ethernet port configuration profile. Call this something meaningful about that port and ALL ports with this title will be applied to ALL RAPs in this group. So, if you modify port 1, all port 1s on the other RAPs within this group will inherit this config.
Under the Ethernet port config profile, there are two others to be concerned with. They are applied to and carried with the port config profile. This brings us to....(scroll down)
...our second profile of concern
2. Wired AP profile. Here you must create a new profile (DO NOT edit the default one or you may break other wired ports elsewhere). In this profile, a few things
- uncheck "trusted"
- set mode to split-tunnel
- Choose VLAN id
3. Our last profile is the aaa profile. Since the wired port is "untrusted" there MUST be a AAA profile applied since setting to untrusted means that the endpoint must go through some sort of authentication. Since it's wired, and you may not was to authenticate, we can set the initial role to the same split tunnel role on the wired side.
So, go ahead and create a new aaa profile and set the initial role to the split-tunnel role and apply it here.