Alcatel OmniAccess AP61 Dokumentacja

Przeglądaj online lub pobierz Dokumentacja dla Switche sieciowe Alcatel OmniAccess AP61. Alcatel OmniAccess AP61 Specifications Instrukcja obsługi

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
Przeglądanie stron 0
OmniAccess
Reference
AOS-W System Reference
T
M
Przeglądanie stron 0
1 2 3 4 5 6 ... 949 950

Podsumowanie treści

Strona 1 - Reference

OmniAccessReferenceAOS-W System ReferenceTM

Strona 2 - Legal Notice

OmniAccess Reference: AOS-W System Referencex Part 031652-00 May 2005Configuring Captive Portal Authentication with Web UI . . . . . . . . . . . . . .

Strona 3

OmniAccess Reference: AOS-W System Reference78 Part 031652-00 May 2005FIGURE 5-13 LDAP Directory StructureAn entry at a given level in the directory’

Strona 4 - Design and Planning

Security Options 79Chapter 5and server is a TCP connection, there is a possibility for a third party to snoop the password from the connection. LDAP s

Strona 5

OmniAccess Reference: AOS-W System Reference80 Part 031652-00 May 2005Server Name – Specifies a human-readable name to reference the LDAP server.Host

Strona 6

Security Options 81Chapter 5authentication type, or the information may be learned from the authentication server through an attribute. Any attribute

Strona 7

OmniAccess Reference: AOS-W System Reference82 Part 031652-00 May 2005Internal Authentication DatabaseAOS-W supports an internal authentication databa

Strona 8

Security Options 83Chapter 5AccountingAOS-W supports standard RADIUS accounting for tracking user login/logout times. Accounting will track logins acc

Strona 9

OmniAccess Reference: AOS-W System Reference84 Part 031652-00 May 2005Once an authentication method has been enabled on the switch, it is automaticall

Strona 10

Security Options 85Chapter 5To configure 802.1x, navigate to Configuration > Security > Authentication Methods > 802.1x as shown in the figur

Strona 11

OmniAccess Reference: AOS-W System Reference86 Part 031652-00 May 2005Authentication Failure Timeout – After authentication fails, the 802.1x state ma

Strona 12

Security Options 87Chapter 5The equivalent CLI configuration for the example above is:aaa dot1x default-role "employee"aaa dot1x mode enable

Strona 13 - Chapter 25

xiDefining Roles Using Web UI. . . . . . . . . . . . . . 389Role Design . . . . . . . . . . . . . . . . . . . . . 389Configuring Roles. . . . . .

Strona 14

OmniAccess Reference: AOS-W System Reference88 Part 031652-00 May 2005VPN AuthenticationWhen the use of IPSec or PPTP is desired, Alcatel switches pro

Strona 15 - Command Reference

Security Options 89Chapter 5aaa vpn-authentication auth-server Internalaaa vpn-authentication max-authentication-failures 0Captive Portal Authenticati

Strona 16

OmniAccess Reference: AOS-W System Reference90 Part 031652-00 May 2005Enable Guest Logon – When this option is selected, the captive portal page will

Strona 17

Security Options 91Chapter 5aaa captive-portal default-role "employee"aaa captive-portal guest-logonaaa captive-portal user-logonaaa captive

Strona 18 - Appendices

OmniAccess Reference: AOS-W System Reference92 Part 031652-00 May 2005Default Role – If a client is identified by MAC address, and the authentication

Strona 19 - An Overview of this Manual

Security Options 93Chapter 5FIGURE 5-23 Stateful 802.1x ConfigurationAvailable configuration parameters are:Authentication Enabled – Enables or disab

Strona 20 - Text Conventions

OmniAccess Reference: AOS-W System Reference94 Part 031652-00 May 2005FIGURE 5-24 Stateful 802.1x AP/Server ConfigurationAvailable configuration para

Strona 21 - Contacting Alcatel

Security Options 95Chapter 5FIGURE 5-25 SSID Role MappingAvailable configuration options are:Condition – Specifies how the value should be matched.Va

Strona 22

OmniAccess Reference: AOS-W System Reference96 Part 031652-00 May 2005bypassed, this method should always be combined with a firewall policy. To conf

Strona 23 - Overview

Security Options 97Chapter 5Configuring VPN SettingsWhen the use of IPSec or PPTP is desired, Alcatel switches provide full VPN termination capabiliti

Strona 24 - 2 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Referencexii Part 031652-00 May 2005AP Provisioning. . . . . . . . . . . . . . . . . . . . . . 428Plug and Play .

Strona 25 - CHAPTER 1

OmniAccess Reference: AOS-W System Reference98 Part 031652-00 May 2005FIGURE 5-27 IPSec ConfigurationAvailable configuration parameters are:Enable L2

Strona 26 - Remote Thin AP

Security Options 99Chapter 5Address Pools - IPSec tunnel endpoints are assigned IP addresses. The Alcatel switch endpoint will always use the switch

Strona 27 - Protocol

OmniAccess Reference: AOS-W System Reference100 Part 031652-00 May 2005crypto isakmp policy 10 authentication pre-sharePPTPPPTP provides an alternati

Strona 28 - DHCP Configuration

Security Options 101Chapter 5The equivalent CLI configuration for the example above is:vpdn group pptp client configuration dns 1.1.1.1 2.2.2.2 client

Strona 29 - Overview 7

OmniAccess Reference: AOS-W System Reference102 Part 031652-00 May 2005As shown in the figure, two VPN dialers are currently configured. “Default-dia

Strona 30 - Multicast Configuration

Security Options 103Chapter 5Disable Wireless Devices when Client is Wired Allows the VPN dialer to detect when a wired network connection is in use.

Strona 31 - Management Options

OmniAccess Reference: AOS-W System Reference104 Part 031652-00 May 2005The equivalent CLI configuration for the example above is:vpn-dialer dialer2 e

Strona 32 - General Screen Elements

Security Options 105Chapter 5The equivalent CLI configuration for the example above is:ip access-list session vpn-dst-nat any host 1.2.3.4 svc-ike ds

Strona 33 - Page Elements

OmniAccess Reference: AOS-W System Reference106 Part 031652-00 May 2005To add the new condition, click Apply.SecureID Token CachingSecureID Token Cach

Strona 34 - 12 Part 031652-00 May 2005

Security Options 107Chapter 5Adding IPSec Transform SetsTo create IPSec transform sets, click Add. The Add Transform Set screen appears.where:To add t

Strona 35 - Command Line Basics

xiiiConfiguring IPSec Using the CLI . . . . . . . . . . . . 516Configuring PPTP Using the CLI . . . . . . . . . . . . 517Configuring the VPN Diale

Strona 36 - Local or Remote Telnet

OmniAccess Reference: AOS-W System Reference108 Part 031652-00 May 2005where:To apply the new firewall settings, click Apply. Parameter DescriptionMon

Strona 37 - Access Modes

Security Options 109Chapter 5Advanced Security OptionsService AliasesService aliases aid in policy configuration by applying a human-readable label to

Strona 38 - (Alcatel) #

OmniAccess Reference: AOS-W System Reference110 Part 031652-00 May 2005Service Name – A human-readable name to identify the service alias. Default ser

Strona 39 - Saved Configuration

Security Options 111Chapter 5User – When a traffic policy containing the “user” alias is applied to an authenticated user, this alias is replaced by t

Strona 40 - Shortcuts

OmniAccess Reference: AOS-W System Reference112 Part 031652-00 May 2005Source/destination aliases contain one or more IP addresses or ranges of IP add

Strona 41 - Command History

Security Options 113Chapter 5Time RangeTo define a time range select Configuration > Security > Advanced > Time Range. The Time Range screen

Strona 42 - Command Syntax

OmniAccess Reference: AOS-W System Reference114 Part 031652-00 May 2005EncryptionEncrypting the transmitted data is only one part of the security proc

Strona 43 - For example:

Security Options 115Chapter 5IPSec IP was originally developed within a highly restricted, secure network. Therefore, IP did not have security feature

Strona 44 - 22 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference116 Part 031652-00 May 2005The PSK mode uses a pre-shared key (password) which is shared by all clients on

Strona 45 - Planning

Security Options 117Chapter 5z CHAPz UNIX Loginz OthersRADIUS authentication is based on the exchange of shared secrets between a client and the authe

Strona 46 - 24 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Referencexiv Part 031652-00 May 2005Wireless LAN Monitoring . . . . . . . . . . . . . . . . 576Debug Information

Strona 47 - RF Design

OmniAccess Reference: AOS-W System Reference118 Part 031652-00 May 2005z Microsoft Windows Mobile 203/CE 4.2 with built-in L2TP/IPSec VPN sup-port (PD

Strona 48 - Getting Started

Security Options 119Chapter 5If you have a proxy server:z Navigate to Settings > Connections > Set up my proxy server.z Follow the on-screen ins

Strona 49 - RF Plan Basics

OmniAccess Reference: AOS-W System Reference120 Part 031652-00 May 2005

Strona 50 - Page Fields

121PartSwitch Configuration3

Strona 51 - Next Step Button

OmniAccess Reference: AOS-W System Reference122 Part 031652-00 May 2005

Strona 52 - Opening Screen

Common Tasks 123CHAPTER 6Common TasksBasic Network ConfigurationVLANsVirtual Local Area Networks (VLANs) are used to divide LAN traffic into manageabl

Strona 53 - Using RF Plan

OmniAccess Reference: AOS-W System Reference124 Part 031652-00 May 2005Provide a routing interface for the VLAN.Set the DHCP server for relaying DHCP

Strona 54 - Planning Requirements

Common Tasks 125Chapter 6Set the port for access to the VLAN.Define whether the port is trusted (LAN) or untrusted (wireless).If connected to the trus

Strona 55 - RF Design 33

OmniAccess Reference: AOS-W System Reference126 Part 031652-00 May 2005z max-age <interval>Set the spanning tree maximum age interval.z priority

Strona 56 - Building Specification Page

Common Tasks 127Chapter 6Save any current configuration changes.Determine the name of the current configuration file.In this example, default.cfg is t

Strona 57 - Maximum Height

xvNetwork Utilities . . . . . . . . . . . . . . . . . . . . . 627Ping . . . . . . . . . . . . . . . . . . . . . . . . . . 627Traceroute . . . . .

Strona 58 - 36 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference128 Part 031652-00 May 2005For example:Here, the configuration file is downloaded to a TFTP server with IP

Strona 59 - Available Radio Type Choices:

Common Tasks 129Chapter 6Upgrading the AOS-W SoftwareThe Alcatel AOS-W software can be upgraded as new releases become available.Obtain a valid Alcate

Strona 60 - 38 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference130 Part 031652-00 May 2005Use the following command to check the memory partitions:In this example, parti

Strona 61 - Import Buildings

Common Tasks 131Chapter 6Verify that the new image is loaded.Use the following command to check the memory partitions:In this example, the new image c

Strona 62 - Export Buildings

OmniAccess Reference: AOS-W System Reference132 Part 031652-00 May 2005When the boot process is complete, verify the upgrade.In this example, Version

Strona 63 - Planning Pages

Common Tasks 133Chapter 6Reset Configuration to DefaultsUnder some conditions, like when reassigning a switch to a new environment, it may be helpful

Strona 64 - Coverage

OmniAccess Reference: AOS-W System Reference134 Part 031652-00 May 2005

Strona 65 - Per Floor Recap

Air Management 135CHAPTER 7Air ManagementThis chapter explains the main elements of wireless intrusion prevention.Alcatel Access Points (AP60, AP61, a

Strona 66 - Background Images

OmniAccess Reference: AOS-W System Reference136 Part 031652-00 May 2005Wireless LAN ClassificationThe WMS continually monitors wireless traffic to det

Strona 67 - Locating and Sizing

Air Management 137Chapter 7Wireless Client Station ClassificationsA wireless client station (STA) is classified as one of the following: z Valid STA (

Strona 68 - Access Editor Page

OmniAccess Reference: AOS-W System Referencexvi Part 031652-00 May 2005aaa Commands . . . . . . . . . . . . . . . . . . . . . . 675aaa xml-api client

Strona 69 - PHY Types

OmniAccess Reference: AOS-W System Reference138 Part 031652-00 May 2005Wired-Side MAC AddressesIf an AM is segregated from the LAN (by a firewall for

Strona 70 - 802.11 Power Levels

Air Management 139Chapter 7z Valid channel list for 802.11a channels:z Valid channel list for 802.11b channels:z SSID list:Enabling the PolicyOnce the

Strona 71 - Initialize

OmniAccess Reference: AOS-W System Reference140 Part 031652-00 May 2005Enabling the PolicyOnce the reserved channels are defined, the protection polic

Strona 72 - Viewing the Results

Air Management 141Chapter 7Use the following commands to configure watermarks.z To set high and low watermarks for number of users per AP:z To set hig

Strona 73

OmniAccess Reference: AOS-W System Reference142 Part 031652-00 May 2005STA Impersonation Detection If the AM detects two stations with the same MAC ad

Strona 74 - Locating Devices

Air Management 143Chapter 7Global PoliciesWeak WEPIf the AM detects a station or AP encrypting 802.11 frames with weak WEP, a syslog event is generate

Strona 75 - Chapter 4

OmniAccess Reference: AOS-W System Reference144 Part 031652-00 May 2005generated. No new events are generated until the statistic value falls below th

Strona 76 - 54 Part 031652-00 May 2005

Air Management 145Chapter 7z Poll intervalThis defines the interval in milliseconds for communication between the Alcatel Wireless LAN Switch and the

Strona 77 - Security Options

OmniAccess Reference: AOS-W System Reference146 Part 031652-00 May 2005z Laser beam debugWhen an AM generates a laser beam, it impersonates an AP or w

Strona 78 - Default Open Ports

Air Management 147Chapter 7On the Alcatel Wireless LAN switch, configure the AM to send captured packets to the monitoring client station.NOTE—The Air

Strona 79 - Security Options 57

xviishutdown . . . . . . . . . . . . . . . . . . . . . . 774site-survey . . . . . . . . . . . . . . . . . . . . . . 774snmp-server . . . . . . .

Strona 80 - 58 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference148 Part 031652-00 May 2005In the capture window, the absolute time stamps that are displayed corre-spond

Strona 81 - AOS-W Security Options

Air Management 149Chapter 7Additional information TBC.

Strona 82 - User Roles

OmniAccess Reference: AOS-W System Reference150 Part 031652-00 May 2005

Strona 83 - FIGURE 5-2 Add New Role

802.1x Client Setup 151CHAPTER 8802.1x Client SetupThis chapter describes how to configure your wireless client station for 802.1x authentication usin

Strona 84 - Firewall and Traffic Policies

OmniAccess Reference: AOS-W System Reference152 Part 031652-00 May 2005PEAP or TLS for Windows 2000Prepare the Operating SystemInstall Windows 2000 wi

Strona 85 - Configuring Traffic Policies

802.1x Client Setup 153Chapter 8If necessary, enable the Wireless Configuration service for auto-matic startup.If the Wireless Configuration item in t

Strona 86 - Source/Destination

OmniAccess Reference: AOS-W System Reference154 Part 031652-00 May 2005Select the Wireless Network Connection properties.From the Windows Start menu,

Strona 87 - Security Options 65

802.1x Client Setup 155Chapter 8Configure the Association attributes.In the Wireless network properties window, select the Association tab and set the

Strona 88 - Rule Ordering

OmniAccess Reference: AOS-W System Reference156 Part 031652-00 May 2005Configure the Authentication attributes.NOTE—To configure settings on the Authe

Strona 89 - CLI Configuration

802.1x Client Setup 157Chapter 8Configure the Authentication Properties.Click on the Properties button. Depending on the authentication type selected,

Strona 90

OmniAccess Reference: AOS-W System Referencexviii Part 031652-00 May 2005Local Database Commands . . . . . . . . . . . . . . . 853VPN Commands . . .

Strona 91 - Other Role Parameters

OmniAccess Reference: AOS-W System Reference158 Part 031652-00 May 2005For EAP-PEAP authentication, set the following:z Enable Fast Reconnect: This en

Strona 92 - Access Control Lists

802.1x Client Setup 159Chapter 8The wireless client station adapter should now use EAP authentication and the following type of message appears:This m

Strona 93 - Standard ACLs

OmniAccess Reference: AOS-W System Reference160 Part 031652-00 May 2005PEAP or TLS for Windows XPNOTE—If using Cisco-PEAP with Windows XP, see the ins

Strona 94

802.1x Client Setup 161Chapter 8Select the Access Point for association.zIn the Network Connections window, right-click on the Wireless Network Connec

Strona 95

OmniAccess Reference: AOS-W System Reference162 Part 031652-00 May 2005Cisco-PEAP for Windows XPPresently, only EAP-PEAP is supported with the Cisco A

Strona 96 - IGURE 5-11 Add RADIUS Server

802.1x Client Setup 163Chapter 8From the Start menu, select Control Panel | Administrative Tools | Services.In the Services window, locate and double-

Strona 97

OmniAccess Reference: AOS-W System Reference164 Part 031652-00 May 2005On the General properties tab, set the Startup type to Auto-matic.If necessary,

Strona 98 - 76 Part 031652-00 May 2005

802.1x Client Setup 165Chapter 8Specify the System Parameters.On the System Parameters tab, specify the following:z Client Name: Specify the name of t

Strona 99 - LDAP Background

OmniAccess Reference: AOS-W System Reference166 Part 031652-00 May 2005Specify the Network Security parameters.On the Network Security tab, specify th

Strona 100 - 78 Part 031652-00 May 2005

802.1x Client Setup 167Chapter 8Configure the Wireless Network ConnectionEnable the Wireless Network Connection.From the Windows Start menu, select Co

Strona 101 - Configuring LDAP Servers

Preface xixPrefaceThis preface includes the following information:z An overview of the sections in this manualz A list of related documentation for fu

Strona 102 - Server Rules

OmniAccess Reference: AOS-W System Reference168 Part 031652-00 May 2005Select the Access Point for association.zIn the Network Connections window, rig

Strona 103 - "role" value-of

802.1x Client Setup 169Chapter 8Configure the Association attributes.In the Wireless network properties window, select the Association tab and set the

Strona 104 - employee

OmniAccess Reference: AOS-W System Reference170 Part 031652-00 May 2005Configure the Authentication attributes.NOTE—To configure settings on the Authe

Strona 105 - Authentication Methods

802.1x Client Setup 171Chapter 8Configure the Authentication Properties.On the Authentication tab, click on the Properties button and set the followin

Strona 106 - 802.1x Authentication

OmniAccess Reference: AOS-W System Reference172 Part 031652-00 May 2005z Second Phase EAP Type: Select the Generic Token Card option and click on prop

Strona 107 - Methods > 802.1x

802.1x Client Setup 173Chapter 8z Static Password:z OTP:For OTP, select either the Hardware Token or Software Token option. If you select Software Tok

Strona 108 - 86 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference174 Part 031652-00 May 2005In some cases, the following type of message appears:This message indicates the

Strona 109 - 802.1x Authentication Server

Basic Switch Configuration 175CHAPTER 9Basic Switch ConfigurationThis chapter explains how to configure the Alcatel Wireless LAN switch using the AOS-

Strona 110 - VPN Authentication

OmniAccess Reference: AOS-W System Reference176 Part 031652-00 May 2005To set the switch role from the CLI, use the command masterip from configuratio

Strona 111 - Captive Portal Authentication

Basic Switch Configuration 177Chapter 9 ip address 10.1.1.1Mobility ConfigurationTo enable mobility, select the Enable Mobility checkbox.FIGURE

Strona 112 - 90 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Referenceii Part 031652-00 May 2005CopyrightCopyright © 2005 Alcatel Internetworking, Inc. All rights reserved.Spec

Strona 113 - MAC Address Role Mapping

OmniAccess Reference: AOS-W System Referencexx Part 031652-00 May 2005Related DocumentsThe following items are part of the complete documentation for

Strona 114 - Stateful 802.1x

OmniAccess Reference: AOS-W System Reference178 Part 031652-00 May 2005FIGURE 9-4 VLAN ConfigurationTo enable mux ports in the CLI, enter commands in

Strona 115 - AP/Server Configuration

Basic Switch Configuration 179Chapter 9navigate to Configuration > Switch > General and specify them in the MUX VLANs section. In the example be

Strona 116 - SSID Role Mapping

OmniAccess Reference: AOS-W System Reference180 Part 031652-00 May 2005Setting the 802.11d Regulatory DomainThe 802.11d regulatory domain controls whi

Strona 117 - value "guest"

Basic Switch Configuration 181Chapter 9FIGURE 9-8 NTP ConfigurationThe equivalent CLI configuration for the example above is:ntp server 172.16.1.25NO

Strona 118

OmniAccess Reference: AOS-W System Reference182 Part 031652-00 May 2005FIGURE 9-9 Port Selection OptionsPorts may be selected based on their administ

Strona 119 - Configuring VPN Settings

Basic Switch Configuration 183Chapter 9To select multiple ports from the CLI, enter commands in the form:interface range FastEthernet 2/12-23This will

Strona 120 - 98 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference184 Part 031652-00 May 2005Port Mode – Sets the mode of the port with respect to VLAN tagging. If the port

Strona 121 - Security Options 99

Basic Switch Configuration 185Chapter 9VLAN 1 is the default VLAN. All ports are part of VLAN 1 until configured otherwise. VLAN 1 cannot be deleted.V

Strona 122 - authentication pre-share

OmniAccess Reference: AOS-W System Reference186 Part 031652-00 May 2005FIGURE 9-13 Adding a New VLANThe equivalent CLI configuration for the example

Strona 123 - VPN Dialer Configuration

Basic Switch Configuration 187Chapter 9FIGURE 9-14 TunnelsTo create a tunnel, click Add and define the tunnel.IP Route ConfigurationAlcatel AOS-W sup

Strona 124 - 102 Part 031652-00 May 2005

Preface xxiContacting AlcatelWeb SiteTelephone Numbers<Arguments> In the command examples, italicized text within angle brackets represents item

Strona 125 - Security Options 103

OmniAccess Reference: AOS-W System Reference188 Part 031652-00 May 2005VRRP ConfigurationAOS-W 2.2 supports redundant switch configurations using Virt

Strona 126 - VPN Server Emulation

Basic Switch Configuration 189Chapter 9Description – An optional description of the VRRP instance that can be used for administrator convenience.IP Ad

Strona 127 - Advanced Authentication

OmniAccess Reference: AOS-W System Reference190 Part 031652-00 May 2005The figure below shows a sample VRRP configuration. In this example, the switch

Strona 128 - SecureID Token Caching

Basic Switch Configuration 191Chapter 92. Follow the rules of operation below.Rules of Operating a Virtual Switch1. When a single SC is present in the

Strona 129 - Firewall Settings

OmniAccess Reference: AOS-W System Reference192 Part 031652-00 May 2005When the reset button is pushed on a SC, it will reset the SC and only the line

Strona 130 - Parameter Description

Basic Switch Configuration 193Chapter 9FIGURE 9-19 VLAN Pool ConfigurationA different DHCP pool must be created for each IP subnet for which DHCP ser

Strona 131 - Advanced Security Options

OmniAccess Reference: AOS-W System Reference194 Part 031652-00 May 2005ip dhcp pool vlan26-pool default-router 10.26.1.1 dns-server 192.168.1.10 domai

Strona 132 - Source/Destination Aliases

802.1x Configuration 195CHAPTER 10802.1x ConfigurationIntroductionThis chapter will explain the process of configuring the server for 802.1x and using

Strona 133 - Security Options 111

OmniAccess Reference: AOS-W System Reference196 Part 031652-00 May 2005Definitions and Common AbbreviationsAuthentication serverAn entity that provide

Strona 134 - NAT Pools

802.1x Configuration 197Chapter 10PEAP(Protected EAP) is an authentication protocol that uses TLS to enhance the security of other EAP authentication

Strona 135 - Additional Information

OmniAccess Reference: AOS-W System Referencexxii Part 031652-00 May 2005

Strona 136 - Encryption

OmniAccess Reference: AOS-W System Reference198 Part 031652-00 May 2005NOTE—To configure an SSID to support 802.1x, set its opmode to dynamicWep or dy

Strona 137 - The Problem With WEP

802.1x Configuration 199Chapter 10Enter Configuration commands, one per line. End with CNTL Z.NOTE—The command reference for this action may be found

Strona 138 - Authentication

OmniAccess Reference: AOS-W System Reference200 Part 031652-00 May 2005Assigning a Server to 802.1x AuthenticationEach instance of a RADIUS server, as

Strona 139 - Supported VPN Clients

802.1x Configuration 201Chapter 10Assigning Default RolesA role is a broad classification of users and is associated with a specific set of permission

Strona 140 - Configuring L2TP and IPSec

OmniAccess Reference: AOS-W System Reference202 Part 031652-00 May 2005Specify any for the source, destination, and port parameters and permit for the

Strona 141 - Security Options 119

802.1x Configuration 203Chapter 10Verify that the authorization server and default roles were correctly assigned.Ty p e show aaa dot1x <Enter>

Strona 142 - 120 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference204 Part 031652-00 May 2005Configuring the 802.1x State MachineDot1x CLI CommandsThis section describes th

Strona 143 - Switch Configuration

802.1x Configuration 205Chapter 10Dot1x serverThe dot1x server commands are used for setting the back-end authentication server configuration.dot1x se

Strona 144 - 122 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference206 Part 031652-00 May 2005dot1x timeout quiet-period <quiet period>The state machine enters a quiet

Strona 145 - (Alcatel) (config) # vlan 2

802.1x Configuration 207Chapter 10802.1x Show CommandsThis sections describes the show commands applicable to 802.1x.show dot1x configThe show dot1x c

Strona 147 - Spanning Tree

OmniAccess Reference: AOS-W System Reference208 Part 031652-00 May 2005show dot1x ap-tableThe show dot1x ap-table command and its variants display inf

Strona 148 - Making Configuration Backups

802.1x Configuration 209Chapter 10z User Namez Authentication Status (yes/no)z AP MACz Encryption Keyz Authorization Modez EAP typeshow dot1x supplica

Strona 149 - Saving to a New Location

OmniAccess Reference: AOS-W System Reference210 Part 031652-00 May 2005show aaa dot1xThe show aaa dot1x commands displays which servers are configured

Strona 150 - <original filename>

802.1x Configuration 211Chapter 10Debug CommandsThe commands in this section are used for debugging the authentication module. Debugging is accomplish

Strona 151 - (Alcatel) # ping 10.1.1.234

OmniAccess Reference: AOS-W System Reference212 Part 031652-00 May 2005RF Deauthentication DebuggingUsing Alcatel Air Management features, Alcatel APs

Strona 152 - 130 Part 031652-00 May 2005

802.1x Configuration 213Chapter 10certificate. The client’s certificate is then verified against the CA certificate of the authority which issued it (

Strona 153 - Reboot the switch

OmniAccess Reference: AOS-W System Reference214 Part 031652-00 May 2005Obtaining A Certification Authority (CA) CertificateCA Certificates are obtaine

Strona 154 - 132 Part 031652-00 May 2005

802.1x Configuration 215Chapter 10Select the Retrieve the CA Certificate or certificate revocation list option, then click Next. The following screen

Strona 155 - (Alcatel) # reload

OmniAccess Reference: AOS-W System Reference216 Part 031652-00 May 2005You may receive one or both of the following warnings. In either case click Ye

Strona 156 - 134 Part 031652-00 May 2005

802.1x Configuration 217Chapter 10Obtaining a Server CertificateThe following steps will guide you through the process of obtaining and installing an

Strona 157 - Air Management

OmniAccess Reference: AOS-W System Reference2 Part 031652-00 May 2005

Strona 158 - Wireless LAN Classification

OmniAccess Reference: AOS-W System Reference218 Part 031652-00 May 2005Select the Request a certificate option, then click Next.The web page below sho

Strona 159 - Enforcement Policies

802.1x Configuration 219Chapter 10The following web page should appear in your browser window.

Strona 160 - Attributes Description

OmniAccess Reference: AOS-W System Reference220 Part 031652-00 May 2005Select the Submit a certificate request to this CA using a form option, then cl

Strona 161 - 00:0b:86:ff:ff:ff

802.1x Configuration 221Chapter 10The web page form below should appear in your browser window.Enter the following information in the Identity Informa

Strona 162 - 140 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference222 Part 031652-00 May 2005Select Server Authentication Server Certificate under the Intended Purpose sect

Strona 163 - Air Management 141

802.1x Configuration 223Chapter 10The web page shown below should appear in your browser window.Click the Install this certificate button.You may see

Strona 164 - STA Impersonation Detection

OmniAccess Reference: AOS-W System Reference224 Part 031652-00 May 2005Obtaining a Client CertificateThe following steps will guide you through the pr

Strona 165 - Statistics Events

802.1x Configuration 225Chapter 10Select the Request a certificate option, then click Next.The web page below should appear in your browser window.Sel

Strona 166 - General WMS Attributes

OmniAccess Reference: AOS-W System Reference226 Part 031652-00 May 2005The following web page should appear in your browser window.

Strona 167 - Laser beam

802.1x Configuration 227Chapter 10Select the Submit a certificate request to this CA using a form option, then click Next.You may receive one of the

Strona 168 - Starting Packet Capture

Overview 3CHAPTER 1OverviewThe AOS-W 2.2 Interface Reference is organized by product feature for the Alcatel Wireless LAN switches and access points.

Strona 169 - The AiroPeek Application

OmniAccess Reference: AOS-W System Reference228 Part 031652-00 May 2005The web page form below should appear in your browser window.Enter the followin

Strona 170 - Remediation with Sygate

802.1x Configuration 229Chapter 10Select Server Authentication Server Certificate under the Intended Purpose section.Set the following options under t

Strona 171 - Additional information TBC

OmniAccess Reference: AOS-W System Reference230 Part 031652-00 May 2005The web page shown below should appear in your browser window.Click the Install

Strona 172 - 150 Part 031652-00 May 2005

802.1x Configuration 231Chapter 10Configuration using Pocket PC Embedded Supplicant Export Trusted Certification Authority The first step in enabling

Strona 173 - 802.1x Client Setup

OmniAccess Reference: AOS-W System Reference232 Part 031652-00 May 2005To install the certificate authority, simply tap on the certificate file. The s

Strona 174 - PEAP or TLS for Windows 2000

802.1x Configuration 233Chapter 10Configuration of the Funk Odyssey client can be performed either on the host PC or on the Pocket PC device. All perm

Strona 175 - 802.1x Client Setup 153

OmniAccess Reference: AOS-W System Reference234 Part 031652-00 May 2005The second and more secure method specifies the domain name of the authenticati

Strona 176 - 154 Part 031652-00 May 2005

802.1x Configuration 235Chapter 10Captive Portal Certificates with Intermediate CAsTo install certificates for captive portal installations that have

Strona 177 - 802.1x Client Setup 155

OmniAccess Reference: AOS-W System Reference236 Part 031652-00 May 2005

Strona 178 - 156 Part 031652-00 May 2005

802.1x Solution Cookbook 237CHAPTER 11802.1x Solution CookbookThis chapter describes the theory, configuration, and operation of a wireless network ba

Strona 179 - 802.1x Client Setup 157

OmniAccess Reference: AOS-W System Reference4 Part 031652-00 May 2005Enhanced Location ServicesAOS-W 2.2 adds more precise position tracking of wirele

Strona 180 - Validate the User Credentials

OmniAccess Reference: AOS-W System Reference238 Part 031652-00 May 2005802.1x authentication based on PEAP is used to provide both computer and user a

Strona 181 - 802.1x Client Setup 159

802.1x Solution Cookbook 239Chapter 11a The laptop searches for the wireless ESSID “Wireless LAN-01”, chooses the AP with the best signal strength, an

Strona 182 - PEAP or TLS for Windows XP

OmniAccess Reference: AOS-W System Reference240 Part 031652-00 May 2005The IAS server has also been configured to transmit an RADIUS attribute called

Strona 183 - 802.1x Client Setup 161

802.1x Solution Cookbook 241Chapter 11a The laptop will transmit an EAPOL-Start message to the Alcatel switch. The Alcatel switch will then proceed wi

Strona 184 - Cisco-PEAP for Windows XP

OmniAccess Reference: AOS-W System Reference242 Part 031652-00 May 2005authentication takes place when a user is not logged in to the laptop, the comp

Strona 185 - Zero Configuration item

802.1x Solution Cookbook 243Chapter 11netdestination district-network network 10.0.0.0 255.0.0.0 network 172.16.0.0 255.255.0.0 Student Policy The pol

Strona 186 - Configure the Cisco ACU

OmniAccess Reference: AOS-W System Reference244 Part 031652-00 May 2005Printer Policy The following policy is used for the printer role. It restricts

Strona 187 - 802.1x Client Setup 165

802.1x Solution Cookbook 245Chapter 11user-role computer session-acl allowall ! user-role guest session-acl guest bandwidth-contract guest-1M Authenti

Strona 188 - 166 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference246 Part 031652-00 May 2005802.1x Configuration The following statements enable 802.1x authentication. It

Strona 189 - Chapter 8

802.1x Solution Cookbook 247Chapter 11! interface vlan 60 ip address 10.1.60.1 255.255.255.0 ip helper-address 10.1.1.25 ! interface vlan 61 ip addres

Strona 190 - 168 Part 031652-00 May 2005

Overview 5Chapter 1provides the ability to enable local probe responses for remotely connected APs. This feature may be configured under the Wireless

Strona 191 - 802.1x Client Setup 169

OmniAccess Reference: AOS-W System Reference248 Part 031652-00 May 2005staticWep deny-bcast enable virtual-ap “Guest” vlan-id 63 opmode opensystem den

Strona 192 - 170 Part 031652-00 May 2005

802.1x Solution Cookbook 249Chapter 11Windows Group Membership Configuration The authentication policy configured in IAS depends on the group membersh

Strona 193 - 802.1x Client Setup 171

OmniAccess Reference: AOS-W System Reference250 Part 031652-00 May 2005z The encryption type is WEP z Open authentication should be used (this refers

Strona 194

802.1x Solution Cookbook 251Chapter 11Microsoft Internet Authentication Server Configuration Microsoft Internet Authentication Server (IAS) provides a

Strona 195 - 802.1x Client Setup 173

OmniAccess Reference: AOS-W System Reference252 Part 031652-00 May 2005z The Wireless-Student policy matches the “Student” group. z The Wireless-Facul

Strona 196 - 174 Part 031652-00 May 2005

802.1x Solution Cookbook 253Chapter 11Advanced Attributes One of the principles in this network is that the Alcatel switch will restrict network acces

Strona 197 - Basic Switch Configuration

OmniAccess Reference: AOS-W System Reference254 Part 031652-00 May 2005z Specifies the EAP type as PEAP z Clients will not attempt to authenticate as

Strona 198 - Switch > General

802.1x Solution Cookbook 255Chapter 11In the management console, select File > Add/Remove Snap-in. Select the Certificates snap-in. Typically, a tr

Strona 199 - ip address 10.1.1.1

OmniAccess Reference: AOS-W System Reference256 Part 031652-00 May 2005If the appropriate ESSID is not already shown in the list, add it by selecting

Strona 200 - muxport

Switch Management Configuration 257CHAPTER 12Switch Management ConfigurationThis Chapter discusses how to use the various management features of Alcat

Strona 201 - MUX Server CLI Commands

OmniAccess Reference: AOS-W System Reference6 Part 031652-00 May 2005If no DNS information is available, the AP will begin using Alcatel Discovery Pro

Strona 202 - Configuring NTP Servers

OmniAccess Reference: AOS-W System Reference258 Part 031652-00 May 2005Navigate to the Configuration > Management > SNMP page. Add system inform

Strona 203 - Port Configuration

Switch Management Configuration 259Chapter 12Click Add in the Trap Receivers section of the SNMP page.The Add Host page appears on the screen.Enter th

Strona 204 - Port Selection

OmniAccess Reference: AOS-W System Reference260 Part 031652-00 May 2005NOTE—The console will revert to the immediate (non-privileged mode) when you ch

Strona 205 - Port Configuration Options

Switch Management Configuration 261Chapter 12Configuring Administrative Access Using Web UIAOS-W allows different levels of access for administrative

Strona 206 - poe cisco

OmniAccess Reference: AOS-W System Reference262 Part 031652-00 May 2005Navigate to the Configuration > Management > Access Control page.You can

Strona 207 - Add New VLAN

Switch Management Configuration 263Chapter 12Adding and Editing Management UsersAdding and editing users is accomplished in the Management Users secti

Strona 208 - IGURE 9-13 Adding a New VLAN

OmniAccess Reference: AOS-W System Reference264 Part 031652-00 May 2005Adding and Editing Management RolesAdd or edit Management Role by clicking Add

Strona 209 - IP Route Configuration

Switch Management Configuration 265Chapter 12Adding and Changing Administrative Access Using the CLIViewing Management UsersYou may view currently con

Strona 210 - VRRP Configuration

OmniAccess Reference: AOS-W System Reference266 Part 031652-00 May 2005Viewing Management RolesYou may view currently configured management roles and

Strona 211

Switch Management Configuration 267Chapter 12Adding Auth ServersLoggingThe logging feature in Alcatel AOS-W allows permanent system logs to be stored

Strona 212 - 190 Part 031652-00 May 2005

Overview 7Chapter 1 option serverip 10.1.1.10; } range 10.200.10.200 10.200.10.252;}To configure Microsoft’s DHCP server for this feature:1

Strona 213 - Resetting the Other SC

OmniAccess Reference: AOS-W System Reference268 Part 031652-00 May 2005Configuring Logging Using Web UIBegin configuring logging servers by navigating

Strona 214 - DHCP Pool Configuration

Switch Management Configuration 269Chapter 12Enter the address of a logging server and click the Add button next to the text field.Select a check box

Strona 215 - FIGURE 9-20 DHCP Server

OmniAccess Reference: AOS-W System Reference270 Part 031652-00 May 2005Configuring Logging Using The CLIAdding A Logging ServerAdd a logging server us

Strona 216 - 194 Part 031652-00 May 2005

Switch Management Configuration 271Chapter 12Viewing Current Logging LevelsView the current logging levels using the show logging level command from t

Strona 217 - 802.1x Configuration

OmniAccess Reference: AOS-W System Reference272 Part 031652-00 May 2005

Strona 218

Wireless LAN Configuration 273CHAPTER 13Wireless LAN ConfigurationThis chapter discussed how to configure all the standard 802.11 features of an Alcat

Strona 219 - Supplicant

OmniAccess Reference: AOS-W System Reference274 Part 031652-00 May 2005FIGURE 13-1 SSID Configuration The first SSID configured is primary and can be

Strona 220 - 198 Part 031652-00 May 2005

Wireless LAN Configuration 275Chapter 13Radio Type – SSIDs may appear on only 802.11a radios, only 802.11b/g radios or on both types of radios.SSID De

Strona 221 - 802.1x Configuration 199

OmniAccess Reference: AOS-W System Reference276 Part 031652-00 May 2005The 802.1x framework also allows the encryption key to be rotated at specific i

Strona 222 - 200 Part 031652-00 May 2005

Wireless LAN Configuration 277Chapter 13The equivalent CLI configuration to add the SSID shown above is:ap location 0.0.0 phy-type a virtual-ap "

Strona 223 - (Alcatel) (config) #

iiiPreface xixAn Overview of this Manual . . . . . . . . . . . . . . . xixRelated Documents . . . . . . . . . . . . . . . . . . . . xxText Conven

Strona 224 - Create a User Role

OmniAccess Reference: AOS-W System Reference8 Part 031652-00 May 20052. From a command prompt, enter:c:\>netshnetsh>dhcpnetsh dhcp>server \\&

Strona 225 - Chapter 10

OmniAccess Reference: AOS-W System Reference278 Part 031652-00 May 2005FIGURE 13-4 TKIP Configuration If PSK TKIP is selected, fill in the pre-shared

Strona 226 - Dot1x CLI Commands

Wireless LAN Configuration 279Chapter 13NOTE—AOS-W versions 2.4.0.0 and later support different staticWep and stat-icTkip keys per SSID. In earliers r

Strona 227

OmniAccess Reference: AOS-W System Reference280 Part 031652-00 May 2005FIGURE 13-7 802.11b and g Radio ParametersFIGURE 13-8 802.11a Radio Parameter

Strona 228 - 206 Part 031652-00 May 2005

Wireless LAN Configuration 281Chapter 13NOTE—Note: These parameters affect all APs in the network, unless a more specific configuration applies. Confi

Strona 229 - 802.1x Show Commands

OmniAccess Reference: AOS-W System Reference282 Part 031652-00 May 2005Default Channel – Sets the default channel on which the AP will operate, unless

Strona 230 - [static-wep

Wireless LAN Configuration 283Chapter 13deny Deny wireless access according to timerange argumentdeny-bcast enable to

Strona 231 - 802.1x Configuration 209

OmniAccess Reference: AOS-W System Reference284 Part 031652-00 May 2005telnet Enable or disable telnet to the APtx-power

Strona 232 - 210 Part 031652-00 May 2005

Wireless LAN Configuration 285Chapter 13configuration section. To view or modify location-based configuration, navigate to Configuration > Wireless

Strona 233

OmniAccess Reference: AOS-W System Reference286 Part 031652-00 May 2005FIGURE 13-10 Location 2.0.0 ConfigurationAssuming that the same change is made

Strona 234 - Certificates

Wireless LAN Configuration 287Chapter 13FIGURE 13-11 Advanced Wireless LAN ConfigurationClick Add to display the four categories of advanced Wireless

Strona 235 - 802.1x Configuration 213

Management Options 9CHAPTER 2Management OptionsAOS-W provides a number of methods for managing your Alcatel Wireless LAN Switch.Command-Line Interface

Strona 236 - 214 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference288 Part 031652-00 May 2005FIGURE 13-12 General Wireless LAN Settings

Strona 237 - 802.1x Configuration 215

Radio Resource Management 289CHAPTER 14Radio Resource ManagementThis chapter discusses the process of configuring the Radio Resource Management featur

Strona 238 - 216 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference290 Part 031652-00 May 2005process allows the Alcatel switch to build an RF-based map of the network topol

Strona 239 - /crtserv)

Radio Resource Management 291Chapter 14FIGURE 14-3 Calibration Results The equivalent CLI command to perform calibration is “site-survey calibrate”.O

Strona 240 - 218 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference292 Part 031652-00 May 2005Maximum neighbors to participate in self-healing – The maximum number of neighb

Strona 241

Radio Resource Management 293Chapter 14FIGURE 14-5 Load Balancing Configuration Available parameters are:Enable Load Balancing – Enables or disables

Strona 242 - 220 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference294 Part 031652-00 May 2005The equivalent CLI configuration for the above example is:ap-policy ap-load-bal

Strona 243 - 802.1x Configuration 221

Radio Resource Management 295Chapter 14DoS Client Block Time – Specifies the number of seconds a client will be quarantined from the network after a d

Strona 244 - 222 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference296 Part 031652-00 May 2005FIGURE 14-7 Coverage Hole Detection Other than enabling or disabling the featu

Strona 245 - 802.1x Configuration 223

Radio Resource Management 297Chapter 14stm poor-rssi-threshold 10stm hole-detection-interval 120stm good-sta-ageout 30stm idle-sta-ageout 90Interferen

Strona 246

OmniAccess Reference: AOS-W System Reference10 Part 031652-00 May 2005z Configure and manage wireless intrusion prevention and performance poli-ciesz

Strona 247 - 802.1x Configuration 225

OmniAccess Reference: AOS-W System Reference298 Part 031652-00 May 2005wms global-policy detect-interference disable global-policy interference-inc-th

Strona 248 - 226 Part 031652-00 May 2005

Radio Resource Management 299Chapter 14FIGURE 14-9 Event Threshold ConfigurationTo disable detection for any parameter, set the value to 0. Available

Strona 249 - 802.1x Configuration 227

OmniAccess Reference: AOS-W System Reference300 Part 031652-00 May 2005Frame Error Rate High Watermark – If the frame error rate, as a percentage of t

Strona 250 - 228 Part 031652-00 May 2005

Radio Resource Management 301Chapter 14Frame Retry Rate Low Watermark – After a frame retry rate exceeded condition exists, the condition will persist

Strona 251 - 802.1x Configuration 229

OmniAccess Reference: AOS-W System Reference302 Part 031652-00 May 2005FIGURE 14-10 RF Management Advanced ParametersThe advanced parameters are:AP A

Strona 252 - 230 Part 031652-00 May 2005

Radio Resource Management 303Chapter 14Station Scan Inactivity– TBC.Enable Statistics Update in DB– TBC:auto-rra scan-interval 10auto-rra scan-time 11

Strona 253

OmniAccess Reference: AOS-W System Reference304 Part 031652-00 May 2005

Strona 254 - Login to Wireless Network

Intrusion Detection Configuration 305CHAPTER 15Intrusion Detection ConfigurationThis chapter discusses the various kinds of intrusion and Wireless LAN

Strona 255 - Odyssey Client Configuration

OmniAccess Reference: AOS-W System Reference306 Part 031652-00 May 2005Network discovery is a normal part of 802.11, and allows client devices to disc

Strona 256 - Push to Device

Intrusion Detection Configuration 307Chapter 15Rogue APRogue APs represent perhaps the largest threat to enterprise network security because they bypa

Strona 257 - 802.1x Configuration 235

Management Options 11Chapter 2z Page Tree–Each tool has its own information or configuration pages and sub-pages.The page tree lists all of the pages

Strona 258 - 236 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference308 Part 031652-00 May 2005Mark All New APs as Valid – When installing an Alcatel switch in an environment

Strona 259 - 802.1x Solution Cookbook

Intrusion Detection Configuration 309Chapter 15FIGURE 15-2 Rate Analysis Configuration Configuration is divided into two sections: Channel thresholds

Strona 260 - Wireless Network Operation

OmniAccess Reference: AOS-W System Reference310 Part 031652-00 May 2005 ids-policy rate-frame-type-param assoc channel-quiet-time 900 ids-policy rate-

Strona 261 - Chapter 11

Intrusion Detection Configuration 311Chapter 15To configure detection of FakeAP, navigate to Configuration > Wireless LAN Intrusion Detection >

Strona 262

OmniAccess Reference: AOS-W System Reference312 Part 031652-00 May 2005Such an attack also enables other attacks that can learn a user’s authenticatio

Strona 263

Intrusion Detection Configuration 313Chapter 15FIGURE 15-5 Detect Station Disconnection Configuration parameters are:Enable Disconnect Station Analys

Strona 264 - Firewall Policies

OmniAccess Reference: AOS-W System Reference314 Part 031652-00 May 2005FIGURE 15-7 EAP Handshake Analysis Configuration parameters are:Enable EAP Han

Strona 265 - Allow All Policy

Intrusion Detection Configuration 315Chapter 15FIGURE 15-8 Sequence Number AnalysisConfiguration parameters are:Enable Sequence Number Discrepancy Ch

Strona 266 - User Role Configuration

OmniAccess Reference: AOS-W System Reference316 Part 031652-00 May 2005FIGURE 15-9 AP Impersonation ProtectionConfiguration parameters are:Enable AP

Strona 267 - Authentication Parameters

Intrusion Detection Configuration 317Chapter 15FIGURE 15-10 Signature Analysis Configuration parameters are:Enable Signature Analysis – Enables and d

Strona 268

OmniAccess Reference: AOS-W System Reference12 Part 031652-00 May 2005z Check Boxes–Represented as small squares in front of the item text. These fiel

Strona 269 - Wireless Configuration

OmniAccess Reference: AOS-W System Reference318 Part 031652-00 May 2005Null-Probe-Response - An attack with the potential to crash or lock up the firm

Strona 270 - Remote Access Permission

Intrusion Detection Configuration 319Chapter 15Adding New SignaturesTo add new signatures, click the Add button. The Add IDS Signature screen is shown

Strona 271 - Group Policy Configuration

OmniAccess Reference: AOS-W System Reference320 Part 031652-00 May 2005Wireless LAN PoliciesAd-hoc Network ProtectionAs far as network administrators

Strona 272 - 250 Part 031652-00 May 2005

Intrusion Detection Configuration 321Chapter 15Wireless Bridge DetectionWireless bridges are normally used to connect multiple buildings together. How

Strona 273 - Configuration

OmniAccess Reference: AOS-W System Reference322 Part 031652-00 May 2005policy is useful in blocking access to that AP until the configuration can be f

Strona 274

Intrusion Detection Configuration 323Chapter 15Enforce WEP Encryption for all Traffic – Any valid AP not using WEP will be flagged as misconfigured.En

Strona 275 - 802.1x Solution Cookbook 253

OmniAccess Reference: AOS-W System Reference324 Part 031652-00 May 2005configure detection of weak WEP implementations, navigate to Configuration >

Strona 276 - Start > Run

Intrusion Detection Configuration 325Chapter 15FIGURE 15-16 Multi-Tenancy ConfigurationAvailable parameters are:Disable APs Violating Enterprise SSID

Strona 277

OmniAccess Reference: AOS-W System Reference326 Part 031652-00 May 2005FIGURE 15-17 MAC OUI CheckingAvailable parameters are:Enable MAC OUI Check – E

Strona 278 - Microsoft Requirement

Authentication Server Configuration 327CHAPTER 16Authentication Server ConfigurationIntroductionStrong authentication methods use authentication serve

Strona 279 - CHAPTER 12

Command Line Basics 13CHAPTER 3Command Line BasicsThe Command Line Interface (CLI) is the most direct and comprehensive method for managing the Alcate

Strona 280 - Configuring Trap Receivers

OmniAccess Reference: AOS-W System Reference328 Part 031652-00 May 2005You may configure 2 general parameters here, they are:Configuring RADIUS Server

Strona 281 - (UrsaMinor) >

Authentication Server Configuration 329Chapter 16Add a new server by clicking the Add button.The Add RADIUS Server page appears. Enter information abo

Strona 282 - Configuring SNMPv3 Users

OmniAccess Reference: AOS-W System Reference330 Part 031652-00 May 2005Server RulesServer rules may be defined for each server to determine role and V

Strona 283 - Chapter 12

Authentication Server Configuration 331Chapter 16Add a rule by clicking the add button.The following parameters may be configured for server rules usi

Strona 284 - 262 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference332 Part 031652-00 May 2005where:Attribute Name TBCAttribute ID TBCAttribute Type TBCVendor Name TBCVendor

Strona 285 - Add User page appears

Authentication Server Configuration 333Chapter 16Configuring LDAP Servers with Web UIAlcatel switches allow for authentication using LDAP servers. Con

Strona 286 - Add in the Management Roles

OmniAccess Reference: AOS-W System Reference334 Part 031652-00 May 2005Adding a Server RuleTo add a server rule, click Add on the Add LDAP Server page

Strona 287 - Viewing Management Users

Authentication Server Configuration 335Chapter 16where:Rule type is Role Assignment or Vlan Assignment.TBCAttribute is TBCCondition is TBCValue is TBC

Strona 288 - Viewing Management Roles

OmniAccess Reference: AOS-W System Reference336 Part 031652-00 May 2005Configuring the Internal Authentication Database with Web UIAlcatel AOS-W suppo

Strona 289 - Adding Auth Servers

Authentication Server Configuration 337Chapter 16Configuring RADIUS Accounting with Web UIAlcatel AOS-W supports RADIUS accounting, tracking login and

Strona 290 - Management > Logging

OmniAccess Reference: AOS-W System Reference14 Part 031652-00 May 2005Local or Remote TelnetIf properly set up, the CLI can be accessed locally or rem

Strona 291

OmniAccess Reference: AOS-W System Reference338 Part 031652-00 May 2005Configuring 802.1x Authentication with Web UI802.1x authentication is designed

Strona 292

Authentication Server Configuration 339Chapter 16Click the Enable Authentication checkbox.Select a default role from the pull-down menuAdd an authenti

Strona 293

OmniAccess Reference: AOS-W System Reference340 Part 031652-00 May 2005Configuring VPN Authentication with Web UIAlcatel switches provide full VPN ter

Strona 294 - 272 Part 031652-00 May 2005

Authentication Server Configuration 341Chapter 16Configuring Captive Portal Authentication with Web UIAlcatel switches provide the ability to allow wi

Strona 295 - Wireless LAN Configuration

OmniAccess Reference: AOS-W System Reference342 Part 031652-00 May 2005Default Role Use this pull-down menu to select the default role for the client

Strona 296 - Adding a New SSID

Authentication Server Configuration 343Chapter 16Authentication FailureThreshold for Station BlacklistingSpecifies the number of time a station may fa

Strona 297 - VLAN Mapping

OmniAccess Reference: AOS-W System Reference344 Part 031652-00 May 2005Configuring MAC Address Role Mapping with Web UIMAC Address role mapping provid

Strona 298 - IGURE 13-3 WEP Configuration

Authentication Server Configuration 345Chapter 16Configuring Stateful 802.1x for Third Party Access PointsThis feature allows the switch to intercept

Strona 299 - WPA,TKIP, and AES Encryption

OmniAccess Reference: AOS-W System Reference346 Part 031652-00 May 2005Role MappingFrom the Web UI, you can perform role mapping based on SSID and enc

Strona 300 - 278 Part 031652-00 May 2005

Authentication Server Configuration 347Chapter 16Adding a Role MapClick Add.Select a match condition from the Condition pull-down menu box.Enter a val

Strona 301 - Adjusting Radio Parameters

Command Line Basics 15Chapter 3Using Telnet to ConnectUse a Telnet client on your management workstation to connect to the Alcatel Wireless LAN Switch

Strona 302 - 280 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference348 Part 031652-00 May 2005Adding a ConditionTBCwhere:Rule Type–specifies what rule will apply such as on

Strona 303

Authentication Server Configuration 349Chapter 16Configuring General AAA Settings Using the CLIConfigure the general AAA settings using the aaa timers

Strona 304 - 282 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference350 Part 031652-00 May 2005The configured RADIUS server settings may be viewed using the show aaa radius-s

Strona 305 - Chapter 13

Authentication Server Configuration 351Chapter 16Configuring LDAP Servers Using the CLIConfigure LDAP servers using the aaa ldap-server command from t

Strona 306 - Using ARM

OmniAccess Reference: AOS-W System Reference352 Part 031652-00 May 2005Enter the config-ldapserver submode by executing the aaa ldap-server command wi

Strona 307

Authentication Server Configuration 353Chapter 16Set the mode, enable or disable LDAP.View the LDAP server settings using the show aaa ldap-server <

Strona 308 - 286 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference354 Part 031652-00 May 2005Configuring the Internal Authentication Database Using the CLIAn internal authe

Strona 309 - General Wireless LAN Settings

Authentication Server Configuration 355Chapter 16Assign an accounting server.Configuring 802.1x Authentication Using the CLI802.1x configuration is ac

Strona 310 - 288 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference356 Part 031652-00 May 2005Enable or disable re-authentication. Use the “no” form of the command to disabl

Strona 311 - Management

Authentication Server Configuration 357Chapter 16You may view the 802.1x configuration settings using the show aaa dot1x command from the CLI.(Alcatel

Strona 312 - Maintenance > Calibrate.)

OmniAccess Reference: AOS-W System Reference16 Part 031652-00 May 2005z Privileged ModeAll configuration and management functions are available in pri

Strona 313 - Optimization

OmniAccess Reference: AOS-W System Reference358 Part 031652-00 May 2005Adding 802.1x Authentication ServersAdd an existing configured 802.1x authentic

Strona 314 - Load Balancing

Authentication Server Configuration 359Chapter 16Configure Captive Portal using the aaa captive-portal commands from the CLI.Set the default role. Thi

Strona 315 - Radio Resource Management 293

OmniAccess Reference: AOS-W System Reference360 Part 031652-00 May 2005Configuring MAC Address Role Mapping Using the CLIMAC Address Role Mapping is a

Strona 316 - Client and AP DoS Protection

Authentication Server Configuration 361Chapter 16Specify the authentication server.AP/Server Configuration for Stateful 802.1xWhen stateful 802.1x aut

Strona 317 - Coverage Hole Detection

OmniAccess Reference: AOS-W System Reference362 Part 031652-00 May 2005Notes on Advanced AAA FeaturesThe Advanced AAA feature pack for AOS-W unlocks a

Strona 318 - 296 Part 031652-00 May 2005

Authentication Server Configuration 363Chapter 16The AOS-W SolutionAll the problems outlined above are solved using the Advanced AAA feature pack for

Strona 319 - Interference Detection

OmniAccess Reference: AOS-W System Reference364 Part 031652-00 May 2005In an enterprise network, this capability can be used to authenticate users fro

Strona 320 - Event Threshold Configuration

Authentication Server Configuration 365Chapter 16number of different services to be provided. All users can connect to the network using the same met

Strona 321 - Radio Resource Management 299

OmniAccess Reference: AOS-W System Reference366 Part 031652-00 May 2005

Strona 322 - 300 Part 031652-00 May 2005

IAS Server Configuration 367CHAPTER 17IAS Server ConfigurationThis chapter describes how to configure your IAS server for Extensible Authorization Pro

Strona 323 - Advanced Parameters

Command Line Basics 17Chapter 3z Show CommandsThe show commands list information about the switch configuration and performance and are invaluable for

Strona 324 - 302 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference368 Part 031652-00 May 2005Starting the IAS ServerClick Start on task bar, click Settings, click Administr

Strona 325 - Station Scan Inactivity– TBC

IAS Server Configuration 369Chapter 17Change the Startup type to Automatic.Creating NAS Client EntriesOpen the IAS Administration Tool3

Strona 326 - 304 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference370 Part 031652-00 May 2005Click Start on the task bar, click Programs, then Administrative Tools, and the

Strona 327 - CHAPTER 15

IAS Server Configuration 371Chapter 17Select New Client. The Add Client Dialog window appears.Enter a meaningful name in the Friendly name box.Use the

Strona 328 - 306 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference372 Part 031652-00 May 2005Enter a word in the Shared secret text box, then re-enter the same word in the

Strona 329 - Rogue AP

IAS Server Configuration 373Chapter 17Remote access policies are created using the IAS Administration Tool. If the IAS Administration Tool is not alre

Strona 330 - Denial of Service

OmniAccess Reference: AOS-W System Reference374 Part 031652-00 May 2005Click Next. The Select Attribute dialog window appears.Click the Add button. Th

Strona 331

IAS Server Configuration 375Chapter 17When finished adding conditions, click the Next button on Add Remote Access Policy dialog.Select the Grant remot

Strona 332 - FakeAP Detection

OmniAccess Reference: AOS-W System Reference376 Part 031652-00 May 2005Click the Edit Profile button. The Edit Dial-In Profile window appears. Click o

Strona 333 - Man-in-the-Middle

IAS Server Configuration 377Chapter 17Click Start, then Run, then type mmc and press Enter. The Console window appears.Click Console and select Add/Re

Strona 334 - MAC Spoofing

OmniAccess Reference: AOS-W System Referenceiv Part 031652-00 May 2005Part 2Design and Planning . . . . . . . . . . . . 23Chapter 4RF Design . . . .

Strona 335 - ids-policy dsta-check enable

OmniAccess Reference: AOS-W System Reference18 Part 031652-00 May 2005ShortcutsCommand CompletionTo make command input easier, you can usually abbrevi

Strona 336 - ids-policy eap-check enable

OmniAccess Reference: AOS-W System Reference378 Part 031652-00 May 2005Select the Active Directory User and Computer item in the Add Standalone Snap-i

Strona 337 - ids-policy sequence-diff 100

IAS Server Configuration 379Chapter 17Type the user’s name information in the appropriate text fields., then click Next.Enter the password in the Pass

Strona 338 - Signature Detection

OmniAccess Reference: AOS-W System Reference380 Part 031652-00 May 2005Configuring SBRTBCConfiguring FunkTBC

Strona 339 - Pre-Defined Signatures

Firewall Configuration 381CHAPTER 18Firewall ConfigurationSetting Policies Using Web UIAliasesAliases are a convenient way to associate a human unders

Strona 340 - 318 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference382 Part 031652-00 May 2005Navigate to the Configuration > Security > Advanced > Services page.Ad

Strona 341 - Adding New Signatures

Firewall Configuration 383Chapter 18Enter a name in the Service Name text field.Check the appropriate Protocol radio button.Enter the Starting Port.En

Strona 342 - Wireless LAN Policies

OmniAccess Reference: AOS-W System Reference384 Part 031652-00 May 2005You may add, delete, or modify source and destination aliases on this page.Alca

Strona 343 - Misconfigured AP Protection

Firewall Configuration 385Chapter 18Click Add to expand the page and expose the Add Rule section, near the bottom.Enter a name for the new destination

Strona 344

OmniAccess Reference: AOS-W System Reference386 Part 031652-00 May 2005Rules are organized in top-down lists where the first rule applied to the traff

Strona 345 - Weak WEP Detection

Firewall Configuration 387Chapter 18The Source and Destination elements of a rule have the same 5 options. Those options are:The Service element of a

Strona 346

Command Line Basics 19Chapter 3List Matching CommandsWhen typed at the end of a possible command or abbreviation, the question mark lists the commands

Strona 347 - MAC OUI Checking

OmniAccess Reference: AOS-W System Reference388 Part 031652-00 May 2005Add a policy by clicking Add, the Add New Policy page appears. The Add New Poli

Strona 348 - Available parameters are:

Firewall Configuration 389Chapter 18Navigate to the Configuration > Switch > Port page. Select the port to which you wish to apply a policy, the

Strona 349 - CHAPTER 16

OmniAccess Reference: AOS-W System Reference390 Part 031652-00 May 2005Defining Roles Using Web UIRole DesignA role is assigned to a user when they co

Strona 350

Firewall Configuration 391Chapter 18Click Add to begin adding a new role to the list. The Add Role page appears.

Strona 351

OmniAccess Reference: AOS-W System Reference392 Part 031652-00 May 2005Adding Firewall PoliciesAdd firewall policies, begin by clicking the Add button

Strona 352

Firewall Configuration 393Chapter 18Specify an Existing PolicySelect the Choose from Configured Policies radio box.Specify a particular AP (if you wis

Strona 353 - Configuring Attributes

OmniAccess Reference: AOS-W System Reference394 Part 031652-00 May 2005additional options.Setting Policies Using the CLIThis portion of the chapter de

Strona 354 - 332 Part 031652-00 May 2005

Firewall Configuration 395Chapter 18You may define a service alias by giving it a name, then choosing to specify one of three options:.Define the serv

Strona 355

OmniAccess Reference: AOS-W System Reference396 Part 031652-00 May 2005Defining Source and Destination AliasesDefine a source/destination alias and en

Strona 356 - Adding a Server Rule

Firewall Configuration 397Chapter 18Enter rules in the order you wish them to be applied.If you wish to change the position of a rule in the list, use

Strona 357

OmniAccess Reference: AOS-W System Reference20 Part 031652-00 May 2005Command Line EditingThe command line editing feature allows you to make correcti

Strona 358 - Database with Web UI

OmniAccess Reference: AOS-W System Reference398 Part 031652-00 May 2005Assign a policy to a the port used when entering the config-if mode.Defining Ro

Strona 359

Firewall Configuration 399Chapter 18Extended ACLsCreate extended ACLs using the extended option of the access-list command.MAC ACLsCreate MAC ACLs usi

Strona 360

OmniAccess Reference: AOS-W System Reference400 Part 031652-00 May 2005

Strona 361

Captive Portal Setup 401CHAPTER 19Captive Portal SetupOverviewThe following outline lists the steps used to configure captive portal authentication. E

Strona 362 - 340 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference402 Part 031652-00 May 2005Add Users to the DatabaseAuthentication can be provided using one of the follow

Strona 363 - Configuration >

Captive Portal Setup 403Chapter 19Configure RADIUS Server InformationIf using a Wireless LAN switch internal server, skip to the next section.Otherwis

Strona 364 - 342 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference404 Part 031652-00 May 2005Use the no prefix to remove the server information from the database. For examp

Strona 365

Captive Portal Setup 405Chapter 19Customize the Logon RoleThe logon role is intended only to allow clients to access the captive portal logon page. Ty

Strona 366

OmniAccess Reference: AOS-W System Reference406 Part 031652-00 May 2005Modify the Captive Portal ACLA default captiveportal ACL is already configured

Strona 367 - Access Points

Captive Portal Setup 407Chapter 19Modify the Logon RoleThe logon role should have only the control and captive portal ACLs assigned. ACLs that allow o

Strona 368 - Role Mapping

Command Line Basics 21Chapter 3z Pipe | —denotes a two or more parameters, separated one from the other by the | symbol.For example:crypto ipsec tran

Strona 369 - Encryption Type Role Mapping

OmniAccess Reference: AOS-W System Reference408 Part 031652-00 May 2005Allow Guest AccessBy default, guest access is disabled. To allow guest access,

Strona 370 - Adding a Condition

Captive Portal Setup 409Chapter 19In the example above, a destination alias is created that represents all IP addresses except the internal network (b

Strona 371 - Chapter 16

OmniAccess Reference: AOS-W System Reference410 Part 031652-00 May 2005Configuring Role DerivationThe simplest option for role derivation is to config

Strona 372

Captive Portal Setup 411Chapter 19For more information on how role derivation works, refer to “Setting Access Rights” on page 419.Import a Server Cert

Strona 373

OmniAccess Reference: AOS-W System Reference412 Part 031652-00 May 2005Log in using the admin accountWhen successful, the following page appears:FIGUR

Strona 374 - 352 Part 031652-00 May 2005

Captive Portal Setup 413Chapter 19Customize the Login ScreenIf desired, the background image shown on the captive portal login screen can be replaced

Strona 375

OmniAccess Reference: AOS-W System Reference414 Part 031652-00 May 2005Sample ConfigurationListed below are the commands relevant to the captive porta

Strona 376 - Database Using the CLI

Captive Portal Setup 415Chapter 19user-role ap session-acl nonoc session-acl noilabsexitaaa captive-portal default-role nocaaa captive-portal auth-ser

Strona 377

OmniAccess Reference: AOS-W System Reference416 Part 031652-00 May 2005show rights <role-name>This command details the access rights associated

Strona 378 - 356 Part 031652-00 May 2005

Captive Portal Setup 417Chapter 19show user-tableThis command shows all the users currently known to the system:The meaning for the various columns is

Strona 379

OmniAccess Reference: AOS-W System Reference22 Part 031652-00 May 2005

Strona 380 - 358 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference418 Part 031652-00 May 2005

Strona 381

Setting Access Rights 419CHAPTER 20Setting Access RightsThis chapter will describe how to set access rights on the OmniAccess 6000 switch using the AO

Strona 382 - 360 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference420 Part 031652-00 May 2005Defining Alias’Defining Service Alias’Alias’ are useful when creating filters,

Strona 383

Setting Access Rights 421Chapter 20Creating Session ACLs and RolesCreating A Session ACL for LogonA session ACL must first be created for the Logon ro

Strona 384 - The Problem

OmniAccess Reference: AOS-W System Reference422 Part 031652-00 May 2005Role DerivationThe simplest way to assign a role is to create a default role fo

Strona 385 - The AOS-W Solution

Setting Access Rights 423Chapter 20The following flow illustrates how roles are derived.FIGURE 20-1 Role Derivation Flow Chart

Strona 386 - 364 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference424 Part 031652-00 May 2005Show CommandsThe Show Commands associated with user rights are:z show rightsz s

Strona 387

Access Point Setup 425CHAPTER 21Access Point SetupThis chapter covers the following topics for the Alcatel Wireless Access Point (AP):z Overview of th

Strona 388 - 366 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference426 Part 031652-00 May 2005System OverviewComponentsThe Alcatel Wireless LAN solution consists of the thre

Strona 389 - IAS Server Configuration

Access Point Setup 427Chapter 21APs with a direct connection to the Wireless LAN switch can also utilize optional Serial and Power Over Ethernet (SPOE

Strona 390 - Starting the IAS Server

23PartDesign and Planning2

Strona 391 - Creating NAS Client Entries

OmniAccess Reference: AOS-W System Reference428 Part 031652-00 May 2005AP ProvisioningThere are several methods for setting up and configuring Alcatel

Strona 392 - 370 Part 031652-00 May 2005

Access Point Setup 429Chapter 21Simplified AP ProvisioningThis is a streamlined example of the AP Programming Mode. This procedure represents the most

Strona 393 - IAS Server Configuration 371

OmniAccess Reference: AOS-W System Reference430 Part 031652-00 May 2005Once the settings are correct, push the configuration to the APs.Disable the AP

Strona 394 - 372 Part 031652-00 May 2005

Access Point Setup 431Chapter 21Connect the Alcatel APs that require configuration to one of the specified AP programming ports on the switch.NOTE—Alt

Strona 395 - IAS Server Configuration 373

OmniAccess Reference: AOS-W System Reference432 Part 031652-00 May 2005z Disconnect and reconnect the AP from the switch port. If the AP list had prev

Strona 396 - 374 Part 031652-00 May 2005

Access Point Setup 433Chapter 21My network uses direct IP addresses instead of DNS.If using direct IP addresses in your network, use the following com

Strona 397 - IAS Server Configuration 375

OmniAccess Reference: AOS-W System Reference434 Part 031652-00 May 2005If you prefer to manually generate the location data, record the location you s

Strona 398 - Adding a User

Access Point Setup 435Chapter 21Push the configuration to the APs.Depending on how specific your AP configuration must be applies, use one of the foll

Strona 399 - IAS Server Configuration 377

OmniAccess Reference: AOS-W System Reference436 Part 031652-00 May 2005If no other APs are to be configured, disable the AP program-ming mode:This wil

Strona 400 - 378 Part 031652-00 May 2005

Access Point Setup 437Chapter 21If desired, you can reset a deployed AP to its factory default set-tings:where AP index is the AP’s entry in the list

Strona 401 - Configuring ACS

OmniAccess Reference: AOS-W System Reference24 Part 031652-00 May 2005

Strona 402 - Configuring Funk

OmniAccess Reference: AOS-W System Reference438 Part 031652-00 May 2005Proceed to Step 3 on page 439.If using Telnet to connect to the AP remotely, ac

Strona 403 - Firewall Configuration

Access Point Setup 439Chapter 21Interrupt the AP boot process.Depending on how far the AP boot has booted, use one of the following lettered steps:If

Strona 404 - 382 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference440 Part 031652-00 May 2005If the AP has completed booting.If no key is pressed before the autoboot timer

Strona 405 - Firewall Configuration 383

Access Point Setup 441Chapter 21Initial ConfigurationThe Alcatel AP requires some initial configuration before it will operate. All direct configurati

Strona 406 - 384 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference442 Part 031652-00 May 2005Specify host information, if necessary.In order to provide centralized manageme

Strona 407

Access Point Setup 443Chapter 21NOTE—If the servername environment variable is configured in this scenario, it will be ignored.Specify an IP address,

Strona 408 - Rules in Firewall Policies

OmniAccess Reference: AOS-W System Reference444 Part 031652-00 May 2005Advanced AP ConfigurationThe following sections cover the following:z How to ac

Strona 409 - Firewall Configuration 387

Access Point Setup 445Chapter 21APBoot Environment VariablesThe following environment variables can be configured using the setenv command and listed

Strona 410 - Save Configuration

OmniAccess Reference: AOS-W System Reference446 Part 031652-00 May 2005The following environmental variables should be kept at their default values un

Strona 411 - Apply and Save Configuration

Access Point Setup 447Chapter 21AP Configuration ExamplesFactory Default ValuesBy default, the environmental variables are as follows:NOTE—Variables n

Strona 412 - Defining Roles Using Web UI

RF Design 25CHAPTER 4RF DesignThe Alcatel RF Plan ToolRF Plan is a three-dimensional wireless deployment modeling tool that enables Network Administra

Strona 413 - Chapter 18

OmniAccess Reference: AOS-W System Reference448 Part 031652-00 May 2005z The AP location is set to -1.-1.-1 (unconfigured) and uses the default loca-t

Strona 414 - Adding Firewall Policies

Access Point Setup 449Chapter 21When booted normally (without entering APBoot mode), the AP will use the new settings and the AP console will display

Strona 415 - Firewall Configuration 393

OmniAccess Reference: AOS-W System Reference450 Part 031652-00 May 2005If DNS is not used or if you need to assign different TFTP servers for the soft

Strona 416 - Defining Service Aliases

Access Point Setup 451Chapter 21Set AP with Specific LocationThe location variable can be used to specify where the AP will be permanently installed.

Strona 417 - Define the service alias

OmniAccess Reference: AOS-W System Reference452 Part 031652-00 May 2005GRE TunnelsRegardless of the network topology between the AP and the Wireless L

Strona 418

Access Point Setup 453Chapter 21The value of lms_address is the Wireless LAN switch tunnel end point in use by AP.Wireless Client IP AddressThe wirele

Strona 419 - Firewall Configuration 397

OmniAccess Reference: AOS-W System Reference454 Part 031652-00 May 2005Direct traffic into the tunnel.Traffic can be directed into the tunnel using st

Strona 420 - Defining Roles Using the CLI

Access Point Setup 455Chapter 21Location-Based ProfilesAP configuration profiles can be based on the unique location index (building.floor.device) ass

Strona 421 - Ethertype ACLs

OmniAccess Reference: AOS-W System Reference456 Part 031652-00 May 2005Using AP Location WildcardsThe location profiles allow zero (0) to be used as a

Strona 422 - 400 Part 031652-00 May 2005

Access Point Setup 457Chapter 21Attributes in the various profiles are treated individually. Only the attributes which are specifically configured in

Strona 423 - Captive Portal Setup

OmniAccess Reference: AOS-W System Reference26 Part 031652-00 May 2005tings for each AP. Real-time calibration can be automatically programmed or manu

Strona 424 - Add Users to the Database

OmniAccess Reference: AOS-W System Reference458 Part 031652-00 May 2005The Unconfigured AP ProfileAPs are typically assigned a unique location code wh

Strona 425 - Captive Portal Setup 403

Access Point Setup 459Chapter 21AP Attribute CommandsAP Configuration ModeThe following commands are available from the AP location or BSSID configura

Strona 426 - <server name>

OmniAccess Reference: AOS-W System Reference460 Part 031652-00 May 2005z no <command>Clear the specified command attributes in the current profi

Strona 427 - Customize the Logon Role

Access Point Setup 461Chapter 21z wep-key{1|2|3|4} <key string (5 or 13 characters hexidecimal)>Used when opmode is set for staticWep. This comm

Strona 428 - Modify the Captive Portal ACL

OmniAccess Reference: AOS-W System Reference462 Part 031652-00 May 2005Physical Layer Sub-modeIn addition to the regular AP attribute commands, the fo

Strona 429 - Modify the Logon Role

Access Point Setup 463Chapter 21Order of Precedence for Profile AttributesChannel and Transmit PowerSettings for the AP channel and transmit power att

Strona 430 - Allow Guest Access

OmniAccess Reference: AOS-W System Reference464 Part 031652-00 May 2005Matching BSSID specific profileMatching location specific profile (exact match,

Strona 431 - Configure Other User Roles

Access Point Setup 465Chapter 21CLI Configuration ExamplesThis section has typical commands for configuring AP attributes on the Wireless LAN switch.

Strona 432 - (config)# aaa server-rule IAS

OmniAccess Reference: AOS-W System Reference466 Part 031652-00 May 2005Set the opmode to opensystem.Resetting the Base Location ProfileThe base locati

Strona 433 - Import a Server Certificate

Access Point Setup 467Chapter 21Enable Static WEP for a Specific BuildingTo select all APs in a specific building for configuration changes, the build

Strona 434 - 412 Part 031652-00 May 2005

RF Design 27Chapter 4Launching RF PlanTo open RF Plan select: Start > All Programs > Alcatel Offline RF Plan> Alcatel RF Plan.RF Plan BasicsP

Strona 435 - Customize the Login Screen

OmniAccess Reference: AOS-W System Reference468 Part 031652-00 May 2005Viewing AP Attribute SettingsShow a Location ProfileNOTE—Channel and transmit p

Strona 436 - Sample Configuration

Access Point Setup 469Chapter 21Show a BSSID ProfileShow Encryption Keys for a LocationNOTE—For security, passwords and keys are encrypted by default.

Strona 437 - Show Commands

OmniAccess Reference: AOS-W System Reference470 Part 031652-00 May 2005Show Effective Config for a Specific APThis example shows the actual configurat

Strona 438 - 416 Part 031652-00 May 2005

Access Point Setup 471Chapter 21Viewing AP Information and StatisticsList Bootstrapped APsFor STATE, the expected value is 2 (sent tunnel response) or

Strona 439 - Captive Portal Setup 417

OmniAccess Reference: AOS-W System Reference472 Part 031652-00 May 2005List Management Registered APsList AP Association TableList Wireless STA StateL

Strona 440 - 418 Part 031652-00 May 2005

Access Point Setup 473Chapter 21Use the following command to view the state of the Access Point Status LED for a specific line card:(Alcatel) # show a

Strona 441 - Setting Access Rights

OmniAccess Reference: AOS-W System Reference474 Part 031652-00 May 2005List Configuration Applied on an APList Statistics for an AP or STA(Alcatel) #

Strona 442

Access Point Setup 475Chapter 21(Alcatel) # show ap stats 10.2.12.212 00:30:f1:70:49:65 verbose Frame rates-----------retry low-speed non-unicast recv

Strona 443 - Predefined ACLs

OmniAccess Reference: AOS-W System Reference476 Part 031652-00 May 2005List Status for an AP(OmniAccess 6000) #show ap status 10.1.1.114Station Table-

Strona 444 - Role Derivation

Access Point Setup 477Chapter 21List Information for Technical Support(Alcatel) # show tech-support

Strona 445 - Chapter 20

vAuthentication Methods . . . . . . . . . . . . . . . . . 83802.1x Authentication . . . . . . . . . . . . . . . . 84VPN Authentication. . . . . .

Strona 446

OmniAccess Reference: AOS-W System Reference28 Part 031652-00 May 2005Page FieldsEach tool in the RF Plan has its own unique information or configurat

Strona 447 - Access Point Setup

OmniAccess Reference: AOS-W System Reference478 Part 031652-00 May 2005AP ReprovisioningIf the AP is already configured and you want to change the AP

Strona 448 - System Overview

Access Point Setup 479Chapter 215. Configure the location, Host IP/Name, Master IP. If the AP is going to be assigned a static IP, enter IP address, N

Strona 449

OmniAccess Reference: AOS-W System Reference480 Part 031652-00 May 2005FIGURE 21-6 Updated ConfigurationClick Back to go into the previous page and s

Strona 450 - AP Provisioning

Access Point Setup 481Chapter 21

Strona 451 - Simplified AP Provisioning

OmniAccess Reference: AOS-W System Reference482 Part 031652-00 May 2005

Strona 452 - AP Programming Mode

VPN Setup 483CHAPTER 22VPN SetupThe Alcatel Virtual Private Network (VPN) connection consists of the wireless user, the Access Point, and the Alcatel

Strona 453 - Access Point Setup 431

OmniAccess Reference: AOS-W System Reference484 Part 031652-00 May 2005z Obtain a valid RADIUS server IP Address (if you are not using an internal dat

Strona 454 - (Alcatel) (program-ap) #

VPN Setup 485Chapter 22Configure the VLAN port using the following CLI commands.(Set the default gateway using the following CLI command.Test the conn

Strona 455

OmniAccess Reference: AOS-W System Reference486 Part 031652-00 May 2005Exit the RADIUS server setup.Test the RADIUS server setup using the following C

Strona 456

VPN Setup 487Chapter 22Test the setup using the following CLI CommandsL2TP IPSec VPN Server SetupThis section describes the steps necessary to configu

Strona 457 - Access Point Setup 435

RF Design 29Chapter 4NavigationThe RF Plan tool is a wizard in that it logically guides you through the process of defining radio coverage for all the

Strona 458 - <AP IP address>

OmniAccess Reference: AOS-W System Reference488 Part 031652-00 May 2005Turn off the default mschapv2 authentication using the following CLI command.Sp

Strona 459 - <AP index>

VPN Setup 489Chapter 22Exit the vpn-dialer sub-mode.Enter the role sub-mode and create a role using the following CLI command.Assign a dialer to the r

Strona 460 - 438 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference490 Part 031652-00 May 2005VPN DialerBefore You Beginz Make sure you have wireless connectivity.You can ch

Strona 461 - Chapter 21

VPN Setup 491Chapter 22Enter your username and password, then click the Log In button.NOTE—You might see a Security Alert Dialog appear. If this happe

Strona 462 - 440 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference492 Part 031652-00 May 2005Click on the Click to download VPN Dialer link. NOTE—If you close the Alcatel L

Strona 463 - Initial Configuration

VPN Setup 493Chapter 22The download process will begin and installation will begin automatically.

Strona 464

OmniAccess Reference: AOS-W System Reference494 Part 031652-00 May 2005InstallationWhen the setup file is finished downloading the Dialer Setup Wizard

Strona 465 - Access Point Setup 443

VPN Setup 495Chapter 22Click on the Complete button.The Ready to Install dialog appears.Click the Install button.34

Strona 466 - Advanced AP Configuration

OmniAccess Reference: AOS-W System Reference496 Part 031652-00 May 2005The Installation Progress dialog appears, when the installation is finished the

Strona 467 - APBoot Environment Variables

VPN Setup 497Chapter 22Connecting With VPNYou are now ready to connect to the network using VPN. The Alcatel VPN icon appears in the Startup tray at t

Strona 468 - Variable Description

OmniAccess Reference: AOS-W System Reference30 Part 031652-00 May 2005Opening ScreenWhen RF Plan opens, the browser window will show the default page:

Strona 469 - Factory Default Values

OmniAccess Reference: AOS-W System Reference498 Part 031652-00 May 2005Alcatel VPN Dialer FeaturesThe Dialer has 4 features that may be selected.z Lau

Strona 470 - 448 Part 031652-00 May 2005

VPN Setup 499Chapter 22Network InfoThis feature will display a static window showing important network information.test

Strona 471

OmniAccess Reference: AOS-W System Reference500 Part 031652-00 May 2005TroubleshootingCommon Dialer Error MessagesInterface is down or no route.This m

Strona 472 - Set AP with Static IP Address

VPN Setup 501Chapter 22Common ProblemsDialer does not connect to serverIf the dialer seems to stall while attempting to connect (as indicated by a per

Strona 473 - Access Point Setup 451

OmniAccess Reference: AOS-W System Reference502 Part 031652-00 May 2005Use the show crypto ipsec sa command on the switch to make sure the user is doi

Strona 474 - 452 Part 031652-00 May 2005

VPN Setup 503Chapter 22"L2TP"=DWORD:1"DNETCLEAR"=DWORD:0"MSCHAPV2"=DWORD:0"CACHE-SECURID"=DWORD:1"IKESECS

Strona 475 - GRE Tunnel Configuration

OmniAccess Reference: AOS-W System Reference504 Part 031652-00 May 2005

Strona 476 - Configuration Profiles

VPN Configuration 505CHAPTER 23VPN ConfigurationAlcatel switches provide full support for Virtual Private Network (VPN) termination using IPSec and PP

Strona 477 - Location-Based Profiles

OmniAccess Reference: AOS-W System Reference506 Part 031652-00 May 2005Configuring IPSec Using Web UIThe following parameters and options may be confi

Strona 478 - Using AP Location Wildcards

VPN Configuration 507Chapter 23z Secondary WINS ServerSpecify the IP address of the Secondary WINS server in the text box.z Address Pools IPSec tunnel

Strona 479 - Access Point Setup 457

RF Design 31Chapter 4You may add, edit, and delete buildings using this window. You may also import and export buildings using the import and export b

Strona 480 - <BSSID>

OmniAccess Reference: AOS-W System Reference508 Part 031652-00 May 2005Adding Address PoolsAdd Address Pools by clicking Add under the address pool se

Strona 481 - AP Attribute Commands

VPN Configuration 509Chapter 23The Configuration> Security > VPN Settings > IPSec > Add IKE Secret page appears.Type the secret in the IKE

Strona 482 - 460 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference510 Part 031652-00 May 2005Specify a priority.Select an encryption type from the Encryption pull-down box.

Strona 483

VPN Configuration 511Chapter 23Add address pools by clicking Add in the Address Pools section of the PPTP page. The PPTP > Add Address Pool page ap

Strona 484 - (Alcatel) (config) # stm ?

OmniAccess Reference: AOS-W System Reference512 Part 031652-00 May 2005You may configure the VPN dialer by navigating to the Configuration > VPN Se

Strona 485 - Access Point Setup 463

VPN Configuration 513Chapter 23z Enable PPTP Enable PPTP tunneling to the Alcatel switch.NOTE—You may check both PPTP and L2TP, however they will not

Strona 486 - 464 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference514 Part 031652-00 May 2005Configuring VPN Server Emulation Using Web UIIt is sometimes common for users i

Strona 487 - CLI Configuration Examples

VPN Configuration 515Chapter 23VPN Server Emulation may be configured by navigating to the Configuration > VPN Settings Emulate VPN Servers page.Ad

Strona 488 - Set the opmode to opensystem

OmniAccess Reference: AOS-W System Reference516 Part 031652-00 May 2005SecureID Token Ring Caching may be configured by navigating to the Configuratio

Strona 489 - Access Point Setup 467

VPN Configuration 517Chapter 23Specify the primary and secondary WINS serversSelect authentication protocolsDefine an address pool for VPN users. This

Strona 490 - Viewing AP Attribute Settings

OmniAccess Reference: AOS-W System Reference32 Part 031652-00 May 2005Planning RequirementsYou should collect the following information before beginni

Strona 491 - Show a BSSID Profile

OmniAccess Reference: AOS-W System Reference518 Part 031652-00 May 2005Enter the config-vpdn-pptp submode using the vpdn group pptp command from the C

Strona 492 - 470 Part 031652-00 May 2005

VPN Configuration 519Chapter 23Set the IKE lifetime.Select an encryption type.Specify a Diffie-Hellman group.Specify a IKE hash algorithm.Specify a pr

Strona 493 - List Bootstrapped APs

OmniAccess Reference: AOS-W System Reference520 Part 031652-00 May 2005Define rules.Return to the config prompt.Apply a role for VPN users.Set the pos

Strona 494 - List AP Status LED State

VPN Configuration 521Chapter 23VPN Quick Start GuideRequirements From CustomerThe user must provide the following:z RADIUS server IP (if not using int

Strona 495

OmniAccess Reference: AOS-W System Reference522 Part 031652-00 May 20055Set up clientThe following sections explain each step in detail.1. Set up Netw

Strona 496

VPN Configuration 523Chapter 23z Username and/or password is wrongz Alcatel switch is not allowed to access RADIUS server (NAS IP on RADIUS)2(b). Set

Strona 497

OmniAccess Reference: AOS-W System Reference524 Part 031652-00 May 2005(Alcatel6000) (config-vpdn-l2tp) # ppp authentication PAP(Alcatel6000) (confi

Strona 498 - List Status for an AP

VPN Configuration 525Chapter 23Type in username foo, password bar. You should see a page with the link to download VPN-dialer. Select that link and op

Strona 499

OmniAccess Reference: AOS-W System Reference526 Part 031652-00 May 2005 transform: esp-3des esp-sha-hmacIf there is an initiator IP that matches the

Strona 500 - AP Reprovisioning

VPN Configuration 527Chapter 23Common Dialer Messages:Interface is down or no routeThere is a basic wireless connectivity problem.Route to destination

Strona 501 - The State shows In Progress

RF Design 33Chapter 4The Overview page shows the default values for your new building, most of which you can change in the following pages. On Buildin

Strona 502 - 480 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference528 Part 031652-00 May 2005 CPU utilization threshold ... 60Auth Server List----------------Pri Name

Strona 503

VPN Configuration 529Chapter 23Hello timeout: 60 secondsDNS primary server: 10.1.1.2DNS secondary server: 30.0.0.0WINS primary server: 10.1.1.WINS sec

Strona 504 - 482 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference530 Part 031652-00 May 2005Example VPN ConfigurationsThis section includes sample VPN clients terminating

Strona 505 - VPN Setup

VPN Configuration 531Chapter 23FIGURE 23-1 Emulating VPN ServersGo to Configuration > Security > Roles > Edit Role (logon) to verify tha

Strona 506 - Network Setup

OmniAccess Reference: AOS-W System Reference532 Part 031652-00 May 2005FIGURE 23-2 Verifying the Logon Role ACLMake sure the IKE shared secrets match

Strona 507 - RADIUS Server Setup

VPN Configuration 533Chapter 23FIGURE 23-3 Matching the IKE Shared SecretThe IKE Aggressive Group Name is the same as the Cisco dialog box Authentica

Strona 508 - Internal Database Setup

OmniAccess Reference: AOS-W System Reference534 Part 031652-00 May 2005FIGURE 23-4 Matching IKE ParametersDefault ValuesThe following figures show th

Strona 509 - L2TP IPSec VPN Server Setup

VPN Configuration 535Chapter 23Default Transport ValuesFIGURE 23-5 Default Transport Tab Values

Strona 510 - 488 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference536 Part 031652-00 May 2005Default Backup Servers ValuesFIGURE 23-6 Default Backup Servers Tab Values

Strona 511 - VPN Setup 489

VPN Configuration 537Chapter 23Default Dial Up ValuesFIGURE 23-7 Default Dial-Up Tab ValuesTypical Third-Party VPN ClientsThe steps required to termi

Strona 512 - VPN Dialer

OmniAccess Reference: AOS-W System Reference34 Part 031652-00 May 2005Building Specification PageThe Building Specification Page enables you to specif

Strona 513 - VPN Setup 491

OmniAccess Reference: AOS-W System Reference538 Part 031652-00 May 2005FIGURE 23-8 Configuring a Group NameVerify the IKE policy settings by selectin

Strona 514 - 492 Part 031652-00 May 2005

VPN Configuration 539Chapter 23FIGURE 23-9 IKE Policy SettingsVerify the basic logon role by selecting Configuration > Security > Roles >

Strona 515 - Chapter 22

OmniAccess Reference: AOS-W System Reference540 Part 031652-00 May 2005FIGURE 23-10 Basic Logon RoleModify the basic logon role by adding an ACL to a

Strona 516 - Installation

VPN Configuration 541Chapter 23 FIGURE 23-11 Allowing TCP on Port 17Configuring a Third-Party VPN ClientComplete the VPN client wizard with source an

Strona 517 - VPN Setup 495

OmniAccess Reference: AOS-W System Reference542 Part 031652-00 May 2005Troubleshooting the ConnectionIf you have trouble connecting to the Alcatel Wir

Strona 518 - Click the Finish button

Switch Maintenance 543CHAPTER 24Switch MaintenanceAlcatel switches provide full support for maintenance at the switch level, the file level, the wirel

Strona 519 - Connecting With VPN

OmniAccess Reference: AOS-W System Reference544 Part 031652-00 May 2005Image management options are.Reboot SwitchTo reboot the switch, typically after

Strona 520 - Alcatel VPN Dialer Features

Switch Maintenance 545Chapter 24To save any changes to the current switch configuration, click Yes. To leave the configuration file unchanged, click N

Strona 521 - Network Info

OmniAccess Reference: AOS-W System Reference546 Part 031652-00 May 2005When ready to revert to the original, factory configuration, click Continue and

Strona 522 - Troubleshooting

Switch Maintenance 547Chapter 24The following parameters and options may be configured through Web UI.When finished, click Apply.File Maintenance The

Strona 523 - Common Problems

RF Design 35Chapter 4A Word About Building DimensionsThe dimensions you specify for building width and height should be the major dimensions (maximum

Strona 524 - "PPTP"=DWORD:0

OmniAccess Reference: AOS-W System Reference548 Part 031652-00 May 2005The options are.Source Selection Select Flash File System and select the name o

Strona 525 - VPN Setup 503

Switch Maintenance 549Chapter 24Copy LogsTo copy logs from the switch to another system, go to Maintenance > File > Copy Logs.You can copy the l

Strona 526 - 504 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference550 Part 031652-00 May 2005You can copy the crash files using an FTP server or TFTP server. Once you have

Strona 527 - VPN Configuration

Switch Maintenance 551Chapter 24The system must reboot before it can use the restored Flash files.Delete FilesTo keep from running out of flash file s

Strona 528 - 506 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference552 Part 031652-00 May 2005z Calibrate the Radio Network—See “Calibration” on page 289.z Program Access Po

Strona 529 - VPN Configuration 507

Switch Maintenance 553Chapter 24Importing a WMS DatabaseTBCRemoving Old EntriesTBC

Strona 530 - Adding IKE Shared Secrets

OmniAccess Reference: AOS-W System Reference554 Part 031652-00 May 2005Re-initializing a WMS DatabaseTBC

Strona 531 - Adding IKE Policies

Switch Maintenance 555Chapter 24Captive Portal MaintenanceThe captive portal is the screen users see when their wireless device connects to the networ

Strona 532 - Configuring PPTP Using Web UI

OmniAccess Reference: AOS-W System Reference556 Part 031652-00 May 2005Upload CertificateTo manually upload a authentication certificate for the capti

Strona 533 - VPN Configuration 511

Switch Maintenance 557Chapter 24

Strona 534 - Settings > Dialers

OmniAccess Reference: AOS-W System Reference36 Part 031652-00 May 2005AP Modeling PageThe AP Modeling page allows you to specify all the information n

Strona 535 - VPN Configuration 513

OmniAccess Reference: AOS-W System Reference558 Part 031652-00 May 2005

Strona 536 - 514 Part 031652-00 May 2005

559PartMonitoring and Troubleshooting4

Strona 537 - Click the Add button again

OmniAccess Reference: AOS-W System Reference560 Part 031652-00 May 2005

Strona 538 - 192.168.29.2

Monitoring the Wireless Environment 561CHAPTER 25Monitoring the Wireless EnvironmentThe Web UI Monitoring tab contains information on the wireless net

Strona 539 - VPN Configuration 517

OmniAccess Reference: AOS-W System Reference562 Part 031652-00 May 2005Network MonitoringTo see a summary of the status of the wireless network, click

Strona 540 - 518 Part 031652-00 May 2005

Monitoring the Wireless Environment 563Chapter 25Switch MonitoringThe Monitoring > Switch screens provide details about the Wireless LANs in the wi

Strona 541 - VPN Configuration 519

OmniAccess Reference: AOS-W System Reference564 Part 031652-00 May 2005and Port ACL Hits (including ACL, ACE, New Hits, Total Hits, and Index. ACE is

Strona 542 - 520 Part 031652-00 May 2005

Monitoring the Wireless Environment 565Chapter 25Sample Air Monitor ScreensTo display a typical screen for Air Monitors, select Monitoring > Switch

Strona 543 - VPN Quick Start Guide

OmniAccess Reference: AOS-W System Reference566 Part 031652-00 May 2005Overview InformationClick Overview to see the following information.FIGURE 25-3

Strona 544 - 1. Set up Network

Monitoring the Wireless Environment 567Chapter 25Channel InformationClick Channel to see the following information.FIGURE 25-4 Channel Information

Strona 545 - VPN Configuration 523

RF Design 37Chapter 4Radio TypeSpecify the radio type(s) of your APs using the pull-down Radio Type menu on the Modeling Parameters page.Available Rad

Strona 546 - 524 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference568 Part 031652-00 May 2005The details on the selected change are shown in the figure below.FIGURE 25-5 O

Strona 547 - Life secs 7200

Monitoring the Wireless Environment 569Chapter 25AP InformationClick APs to see the following information.FIGURE 25-6 AP InformationClient Informatio

Strona 548 - 526 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference570 Part 031652-00 May 2005Packet Capture InformationClick Packet Capture to see the following information

Strona 549 - Verifications:

Monitoring the Wireless Environment 571Chapter 25Diagnostics—see Figure 25-13.Port Status InformationClick Status to see the following types of inform

Strona 550 - IMPORTANT

OmniAccess Reference: AOS-W System Reference572 Part 031652-00 May 2005Port Activity InformationClick Activity to see the following types of informati

Strona 551 - Chapter 23

Monitoring the Wireless Environment 573Chapter 25Status InformationClick Status to see the following types of information.FIGURE 25-14 Port Status In

Strona 552 - Example VPN Configurations

OmniAccess Reference: AOS-W System Reference574 Part 031652-00 May 2005You can sort the events on any of these categories by using the Group By drop-d

Strona 553

Monitoring the Wireless Environment 575Chapter 25Creating Custom ReportsAdditionally, the Events tab allows you to create custom reports by going to E

Strona 554 - VPN Settings > IPSec

OmniAccess Reference: AOS-W System Reference576 Part 031652-00 May 2005Wireless LAN MonitoringDisplays network information for each Wireless LAN based

Strona 555 - Password

Monitoring the Wireless Environment 577Chapter 25Creating Custom LogsUsing the information collected by the logging process, you can tailor custom log

Strona 556 - Default Values

OmniAccess Reference: AOS-W System Referencevi Part 031652-00 May 2005Enforcement Policies. . . . . . . . . . . . . . . . . . . 137AP Policies . . .

Strona 557 - Default Transport Values

OmniAccess Reference: AOS-W System Reference38 Part 031652-00 May 2005Click Apply and the AM Modeling page displays.AM Modeling PageThe AM Modeling pa

Strona 558 - Default Backup Servers Values

OmniAccess Reference: AOS-W System Reference578 Part 031652-00 May 2005FIGURE 25-18 Sample ReportYou can change the status of a rogue or interfering

Strona 559 - Basic Alcatel Configuration

Monitoring the Wireless Environment 579Chapter 25AP ReportsTo see a typical AP report, select Reports > AP > Active Valid APs. The following typ

Strona 560 - > IPSec > Edit

OmniAccess Reference: AOS-W System Reference580 Part 031652-00 May 2005FIGURE 25-20 Selected AP StatusUsing the Command Line InterfaceYou may use the

Strona 561 - (logon)

Monitoring the Wireless Environment 581Chapter 25asfasf

Strona 562 - (Control)

OmniAccess Reference: AOS-W System Reference582 Part 031652-00 May 2005

Strona 563

Firewall Logging 583CHAPTER 26Firewall LoggingThis chapter discusses firewall logging and explains the events found in those logs. Firewall logging in

Strona 564 - 542 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference584 Part 031652-00 May 2005Authentication failed for User <username> : src ip <IPaddr>src port

Strona 565 - Switch Maintenance

Firewall Logging 585Chapter 26src-nat: The packet was forwarded with the source IP address modified.dst-nat: The packet was forwarded with the desti

Strona 566 - Reboot Switch

OmniAccess Reference: AOS-W System Reference586 Part 031652-00 May 2005{TCP | UDP} srcip=<ipaddr>, srcport=<srcport>, dstip=<ipaddr>

Strona 567 - Clear Config

Troubleshooting AOS-W Environments 587CHAPTER 27Troubleshooting AOS-W EnvironmentsBasic ConnectivityThe troubleshooting information in this chapter co

Strona 568 - Boot Parameters

RF Design 39Chapter 4NOTE—The monitor rates you select for the AMs should be less than the data rates you selected for the APs. If you set the rate fo

Strona 569 - File Maintenance

OmniAccess Reference: AOS-W System Reference588 Part 031652-00 May 2005FIGURE 27-1 Normal Process FlowDesign your network do a wireless site surveyIn

Strona 570 - FTP and

Troubleshooting AOS-W Environments 589Chapter 27GeneralThe Wi-Fi Alliance has made great strides in testing interoperability between 802.11 devices fr

Strona 571 - Copy Crash Files

OmniAccess Reference: AOS-W System Reference590 Part 031652-00 May 2005Specific Probe Request – In this type of probe-request, the client is only inte

Strona 572 - Restore Flash

Troubleshooting AOS-W Environments 591Chapter 27z Ensure that the wireless network is operational and that no APs or switches have failed. If part of

Strona 573 - Wireless LAN Maintenance

OmniAccess Reference: AOS-W System Reference592 Part 031652-00 May 2005Client finds AP, but cannot associateAfter a client has located one or more APs

Strona 574 - Managing the WMS Database

Troubleshooting AOS-W Environments 593Chapter 27802.11 Authentication FailsThe 802.11 authenticate exchange is a primitive form of authentication spec

Strona 575 - Removing Old Entries

OmniAccess Reference: AOS-W System Reference594 Part 031652-00 May 2005z Enable client debugging for the client device in question. From the Alcatel

Strona 576 - 554 Part 031652-00 May 2005

Troubleshooting AOS-W Environments 595Chapter 27Client associates to AP, but higher-layer authentication failsProblems with higher-layer authenticatio

Strona 577 - Captive Portal Maintenance

OmniAccess Reference: AOS-W System Reference596 Part 031652-00 May 2005z Once association and higher-layer authentication have succeeded, it is analog

Strona 578 - Upload Custom Login Pages

Troubleshooting AOS-W Environments 597Chapter 27z WPA/802.11i Key Exchange Failure: In a WPA or 802.11i network, the dynamic key exchange process may

Strona 579 - Chapter 24

OmniAccess Reference: AOS-W System Reference40 Part 031652-00 May 2005NOTE—Importing any other file, including XML files from other applications, may

Strona 580 - 558 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference598 Part 031652-00 May 2005z Reset the client NIC. If an internal error has caused the dropped associa-ti

Strona 581 - Monitoring and

Troubleshooting AOS-W Environments 599Chapter 27z If the above parameters are within acceptable ranges, but throughput is still low, it may indicate a

Strona 582 - 560 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference600 Part 031652-00 May 2005TABLE 27-1 Access Point Duplex/Speed MatrixNIC Speed/Duplex ConfigurationSwitc

Strona 583 - CHAPTER 25

Troubleshooting AOS-W Environments 601Chapter 27100Mbps/Full-duplex1000Mbps/Full-duplexNo link No link Because the speeds do not match, no link is e

Strona 584 - Network Monitoring

OmniAccess Reference: AOS-W System Reference602 Part 031652-00 May 2005100Mbps/Full-duplex100Mbps/Full-duplex100Mbps/Full-duplex100Mbps/Full-duplexPro

Strona 585 - Switch Monitoring

Troubleshooting AOS-W Environments 603Chapter 27AuthenticationMost enterprise wireless networks make use of some form of secure authentication. This

Strona 586 - Sample Monitoring Information

OmniAccess Reference: AOS-W System Reference604 Part 031652-00 May 2005Incorrect Username/password (TTLS or PEAP)A typical cause of authentication fai

Strona 587

Troubleshooting AOS-W Environments 605Chapter 27z Perform a wireless packet capture. If 802.1x authentication is observed to begin, and then abruptly

Strona 588 - Overview Information

OmniAccess Reference: AOS-W System Reference606 Part 031652-00 May 2005RADIUS Server reports “Authentication Method Not Supported”This error message i

Strona 589 - Channel Information

Troubleshooting AOS-W Environments 607Chapter 27VPN Dialer displays “No Alcatel switches detected”When this error message is displayed, it indicates t

Strona 590 - 568 Part 031652-00 May 2005

RF Design 41Chapter 4Planning PagesPlanning Floors PageThe Planning Floors page enables you to see what the footprint of your floors look like. You ca

Strona 591 - Client Information

OmniAccess Reference: AOS-W System Reference608 Part 031652-00 May 2005z Examine the output of “show crypto ipsec sa”. Once IKE negotiation has succe

Strona 592 - Example Port Information

Troubleshooting AOS-W Environments 609Chapter 27FIGURE 27-5 Windows IPSec ServiceIPSec is up, but dialer does not display “Logging on” messageThis me

Strona 593 - Port Profile Information

OmniAccess Reference: AOS-W System Reference610 Part 031652-00 May 2005Sample Packet CapturesBroadcast Probe Request FramePacket Information Flags:

Strona 594 - Port Diagnostic Information

Troubleshooting AOS-W Environments 611Chapter 27Supported Rates Element ID: 1 Supported Rates Length: 8 Supported Rate:

Strona 595 - Status Information

OmniAccess Reference: AOS-W System Reference612 Part 031652-00 May 2005 .0.. ... WEP Not Enabled ..0. .

Strona 596 - Delete Selected Events

Troubleshooting AOS-W Environments 613Chapter 27FCS - Frame Check Sequence FCS (Calculated): 0xCF771F24Beacon FramePacket Information Flags:

Strona 597 - Creating Custom Reports

OmniAccess Reference: AOS-W System Reference614 Part 031652-00 May 2005 x... ... Reserved .x...

Strona 598 - Debug Information

Troubleshooting AOS-W Environments 615Chapter 27 Supported Rate: 18.0 (Not BSS Basic Rate) Supported Rate: 24.0 (Not BSS Basic Rate)

Strona 599 - Creating Custom Logs

OmniAccess Reference: AOS-W System Reference616 Part 031652-00 May 2005 Timestamp: 14:33:18.161865000 02/10/2004 Data Rate: 2

Strona 600 - Example Report: Rogue APs

Troubleshooting AOS-W Environments 617Chapter 27 ...x ... Reserved ... 0... Channel Ag

Strona 601 - AP Reports

OmniAccess Reference: AOS-W System Reference42 Part 031652-00 May 2005ZoomThe Zoom control sets the viewing size of the floor image. It is adjustable

Strona 602 - Custom Reports

OmniAccess Reference: AOS-W System Reference618 Part 031652-00 May 2005 Noise Level: 0% Noise dBm: 0802.11 MAC Header Version:

Strona 603

Troubleshooting AOS-W Environments 619Chapter 27 Signal Level: 37% Signal dBm: 0 Noise Level: 0% Noise dBm:

Strona 604 - 582 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference620 Part 031652-00 May 2005 Data Rate: 2 1.0 Mbps Channel: 1 2412 MHz Signal

Strona 605 - Firewall Logging

Troubleshooting AOS-W Environments 621Chapter 27 ... ..1... Short Preamble ... ...1... Priv

Strona 606 - 584 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference622 Part 031652-00 May 2005 Auth OUI: 0x00-0x50-0xF2-01 SSNExtra bytes (Padding): ..

Strona 607 - Firewall Logging 585

Troubleshooting AOS-W Environments 623Chapter 27802.11 Management—Association Response Capability Info: %0000010000110001

Strona 608 - 586 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference624 Part 031652-00 May 2005z Session mirror sniffing and z Packet-capture for control path packetsPacket C

Strona 609 - CHAPTER 27

Troubleshooting AOS-W Environments 625Chapter 27z Alcatel message BPDUsz TCP cli ports (default ones)ExamplesDebugging a wireless WEP station doing VP

Strona 610 - 588 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference626 Part 031652-00 May 2005Use ethereal on the target machine, in the above example, that's 1.2.3.4.

Strona 611 - Client cannot find AP

Diagnostic Tools 627CHAPTER 28Diagnostic ToolsThe Web UI Diagnostic tab contains information on tools to help you coordinate your troubleshooting of y

Strona 612 - Ala Net: 80:A6:00

RF Design 43Chapter 4Coverage RateAdjusting the coverage rate will also affect the size of the coverage circles for AMs. Adjusting the rate values wil

Strona 613

OmniAccess Reference: AOS-W System Reference628 Part 031652-00 May 2005TracerouteTo see the path traffic is taking by using the WebUI, navigate to Dia

Strona 614 - Associate Response

Diagnostic Tools 629Chapter 28Received ConfigurationTo capture AP configurations, navigate to Diagnostics > Received Configuration. Enter the AP IP

Strona 615

OmniAccess Reference: AOS-W System Reference630 Part 031652-00 May 2005Debug LogTo display the debug log when you have run debug tests, navigate to Di

Strona 616 - 594 Part 031652-00 May 2005

Diagnostic Tools 631Chapter 28Web DiagnosticTo see diagnostics information from an AP’s Web Server, navigate to Diagnostics > Web Diagnostics, ente

Strona 617

OmniAccess Reference: AOS-W System Reference632 Part 031652-00 May 2005

Strona 619

OmniAccess Reference: AOS-W System Reference634 Part 031652-00 May 2005

Strona 620 - 598 Part 031652-00 May 2005

AOS-W Commands 635CHAPTER 29AOS-W CommandsUnderstanding the Command Line InterfaceThe AOS-W command line interface is designed to conform with network

Strona 621

OmniAccess Reference: AOS-W System Reference636 Part 031652-00 May 2005Online help is available for all commands by pressing ?. There are two levels o

Strona 622 - 600 Part 031652-00 May 2005

AOS-W Commands 637Chapter 29Execute Mode CommandsExec mode commands allow very basic administrative access to the switch. Users who know the username

Strona 623

OmniAccess Reference: AOS-W System Reference44 Part 031652-00 May 2005Floor Editor PageClick Edit Floor to display the Floor Editor which allows you t

Strona 624 - 602 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference638 Part 031652-00 May 2005See logout.logoutTerminates the session.Example(switch)> logout_See exit.pin

Strona 625

AOS-W Commands 639Chapter 29Example(switch)#traceroute 10.1.2.3Press 'q' to abort.Tracing the route to 10.1.2.3 1 10.4.21.254 0.788 msec

Strona 626 - 604 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference640 Part 031652-00 May 2005boot Restarts the switch.clear Accesses clear commands.clock Sets the system cl

Strona 627

AOS-W Commands 641Chapter 29aaa CommandsThe Privileged mode aaa commands include:(switch) #aaa ?inservice Bring authentication server into servicestat

Strona 628 - 606 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference642 Part 031652-00 May 2005user User commandsSee also the aaa commands in Configure mod

Strona 629

AOS-W Commands 643Chapter 29ExampleThe following example verifies that the authentication server Alcatel is enabled and working.(switch)# aaa test-ser

Strona 630 - 608 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference644 Part 031652-00 May 2005Example (switch) #ads netad learn amConfigures scanning on the specified channe

Strona 631

AOS-W Commands 645Chapter 29backupBacks up and compresses critical files to flashbackup.tar.gz.Example(switch) #backup flashSee also restore.bootSpec

Strona 632 - Sample Packet Captures

OmniAccess Reference: AOS-W System Reference646 Part 031652-00 May 2005clear ads netad anomalySets the network anomaly detection counters to zero.Exam

Strona 633 - FCS - Frame Check Sequence

AOS-W Commands 647Chapter 29clear counters vrrp Clears the Virtual Router Redundancy Protocol statistics.Syntaxclear counters vrrp <id>where <

Strona 634 - 612 Part 031652-00 May 2005

RF Design 45Chapter 4Area Editor PageThe area editor allows you to specify areas on your buildings floors where you either do not care about coverage,

Strona 635 - Beacon Frame

OmniAccess Reference: AOS-W System Reference648 Part 031652-00 May 2005(switch) #clear loginsession 2 (switch) #clear mobile packet-counters

Strona 636 - Extended Supported Rates

AOS-W Commands 649Chapter 29<cr>(switch) #clear site-survey calibration Clear Site Survey Calibration In Progresschannel-plan

Strona 637 - Probe Response Frame

OmniAccess Reference: AOS-W System Reference650 Part 031652-00 May 2005bssid BSSID for the flagged AP to clear hole(switch) #clear s

Strona 638 - 802.11 MAC Header

AOS-W Commands 651Chapter 29(switch) #clear wms ap Clear AP informationprobe sta Clear STA

Strona 639 - 802.11 Authenticate Frame

OmniAccess Reference: AOS-W System Reference652 Part 031652-00 May 2005where <year> is the four-digit year, <month> is the name of the mon

Strona 640 - Packet Information

AOS-W Commands 653Chapter 29Examples(switch) #copy flash: 9147 tftp:10.1.1.55(switch) #copy flash: 9147 flash: copy9147copy system Copies the system f

Strona 641

OmniAccess Reference: AOS-W System Reference654 Part 031652-00 May 2005sapm Logging for AP Manager (Master switch only)snmp

Strona 642

AOS-W Commands 655Chapter 29Syntax copy ftp: <filename> <flash | system partition>where:<filename> Is the name of the file to be

Strona 643

OmniAccess Reference: AOS-W System Reference656 Part 031652-00 May 2005crypto Debugging for VPN (IKE/IPSEC)dhcpd De

Strona 644 - Association Response

AOS-W Commands 657Chapter 29(switch) #debug aaa all(switch) #deleteRemoves the specified file name from flash. The file must exist in flash and be cor

Strona 645 - Packet Sniffing

OmniAccess Reference: AOS-W System Reference46 Part 031652-00 May 2005You may also use the drag and drop feature of the Area Editor to drag your area

Strona 646 - Packet Capture

OmniAccess Reference: AOS-W System Reference658 Part 031652-00 May 2005Example (switch) #halt (switch) #local-userdbManages the user database.Syntaxlo

Strona 647 - SESSION MIRRORING

AOS-W Commands 659Chapter 29(switch) #no crypto isakmpTo disable debugging the L2TP module, enter:(switch) #no debug l2tppacket-captureConfigures moni

Strona 648 - 626 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference660 Part 031652-00 May 2005ExampleTBD(switch) #paging (switch) # panicManages files created during a sys

Strona 649 - Diagnostic Tools

AOS-W Commands 661Chapter 29bssid BSSID of AM interface to start PCAP onchannel Channel to tune into to capture packetsExampleThe following example st

Strona 650 - Access Point Diagnostics

OmniAccess Reference: AOS-W System Reference662 Part 031652-00 May 2005(switch) #reload-peer-SCrenameChanges the specified file name to a new file nam

Strona 651 - Software Status

AOS-W Commands 663Chapter 29banner boot Display boot parametersclock configuration Sho

Strona 652 - Detailed Statistics

OmniAccess Reference: AOS-W System Reference664 Part 031652-00 May 2005provisioning-ap-list rap-wml Rogue AP Wired MAC Lookup Comma

Strona 653 - Web Diagnostic

AOS-W Commands 665Chapter 29site-survey See also the site-survey commands in Configuration mode. SyntaxExample(switch) #site-survey ?calibrate

Strona 654 - 632 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference666 Part 031652-00 May 2005(switch) #site-survey calibrate 1.1.1 ?(switch) #site-survey update-channel-pla

Strona 655 - Command

AOS-W Commands 667Chapter 29(switch) #stm add-dos-sta ?<mac> STA to add to DoS list(switch) #stm add-dos-sta 00:00:00:01:01:ab

Strona 656 - 634 Part 031652-00 May 2005

RF Design 47Chapter 4You may name an Access Point anything you wish. The name must be comprised of alpha-numeric characters and be 64 characters or le

Strona 657 - Getting Help

OmniAccess Reference: AOS-W System Reference668 Part 031652-00 May 2005<mac> STA to remove from DoS list(switch) #stm remove-d

Strona 658 - 636 Part 031652-00 May 2005

AOS-W Commands 669Chapter 29ExampleTBDtarCreates a file in Unix tar file format.Syntaxtar {clean | crash | flash | logs} where:clean Removes a tar fil

Strona 659 - (switch)> exit

OmniAccess Reference: AOS-W System Reference670 Part 031652-00 May 2005(switch) #See also the traceroute command in Configuration mode and Exec mode.

Strona 660 - 638 Part 031652-00 May 2005

AOS-W Commands 671Chapter 29(switch) #wms ap pub ?(switch) #wms ap pub ^% Invalid input detected at '^' marker.(switch) #

Strona 661 - Privileged Mode Commands

OmniAccess Reference: AOS-W System Reference672 Part 031652-00 May 2005(switch) #wms station ?<mac> MAC Address of station(swi

Strona 662 - Prompt Commands Description

AOS-W Commands 673Chapter 29The following command allow you to configure your Wireless LAN Switch and APs.TABLE 29-3 Terminal Configuration Mode Comma

Strona 663 - (switch) #aaa ?

OmniAccess Reference: AOS-W System Reference674 Part 031652-00 May 2005loginsession Login Sessionmac-address-table Configure the MAC address tab

Strona 664 - (switch) #aaa test-server

AOS-W Commands 675Chapter 29aaa CommandsThis command controls user authorization and authentication for the switch. Use the no form of this command to

Strona 665 - Examples

OmniAccess Reference: AOS-W System Reference676 Part 031652-00 May 2005Syntaxaaa {bandwidth-contract | captive-portal | derivation-rules | dot1x | ker

Strona 666 - 644 Part 031652-00 May 2005

AOS-W Commands 677Chapter 29Syntaxaaa captive-portal {auth-server <string> <position> <range> | default-role <string> | guest

Strona 667

viiOperation . . . . . . . . . . . . . . . . . . . . . 190Rules of Operating a Virtual Switch . . . . . . . . 191Hot Swapping Support. . . . . . .

Strona 668 - 646 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference48 Part 031652-00 May 2005802.11 TypesThe 802.11 b/g and 802.11a Type drop down boxes allow you to choose

Strona 669 - clear loginsession

OmniAccess Reference: AOS-W System Reference678 Part 031652-00 May 2005aaa derivation-rules server Configures rules to derive user role or VLAN af

Strona 670 - (switch) #clear rap-wml

AOS-W Commands 679Chapter 29SyntaxnoneExample(Alcatel6000) (config) #aaa dot1x enforce-machine-authenticationaaa dot1x max-authentication-failure Conf

Strona 671 - (switch) #clear stm

OmniAccess Reference: AOS-W System Reference680 Part 031652-00 May 2005aaa ldap-serverConfigures an LDAP server.Syntaxaaa ldap-server STRINGwhere STRI

Strona 672 - (switch) #clear vpdn

AOS-W Commands 681Chapter 29Example(Alcatel6000) (config-ldapserver-paul)#allow-noencrypt (Alcatel6000) (config-ldapserver-paul)# (Alcatel6000) (confi

Strona 673 - (switch) #clear wms

OmniAccess Reference: AOS-W System Reference682 Part 031652-00 May 2005Example(Alcatel6000) (config-ldapserver-paul)#filter filter (Alcatel6000) (conf

Strona 674 - Duplicates files

AOS-W Commands 683Chapter 29aaa ldap-server modeEnables or disables the LDAP server.SyntaxinserviceExample(Alcatel6000) (config-ldapserver-paul)#ins

Strona 675

OmniAccess Reference: AOS-W System Reference684 Part 031652-00 May 2005syntaxaaa mac-authentication auth-server STRING position where STRING is the na

Strona 676 - 1 using TFTP

AOS-W Commands 685Chapter 29aaa mgmt-authentication auth-server Configures administrator user authenticationsyntaxaaa mgmt-authentication auth-server

Strona 677 - (switch) #crypto isakmp

OmniAccess Reference: AOS-W System Reference686 Part 031652-00 May 2005aaa radius-accountingConfigures RADIUS accounting.Syntaxaaa radius-accountingEx

Strona 678 - 656 Part 031652-00 May 2005

AOS-W Commands 687Chapter 29 where the options to this command are:STRING specifies the name of RADIUS server.acctport specifies the port number used

Strona 679 - Chapter 29

RF Design 49Chapter 4AP PlanThe AP Plan feature uses the information entered in the modeling pages to locate access points in the building(s) you desc

Strona 680 - To disable IKE, enter:

OmniAccess Reference: AOS-W System Reference688 Part 031652-00 May 2005Syntaxaaa stateful-authentication dot1x ap-config <name> ap-ipaddr radius

Strona 681

AOS-W Commands 689Chapter 29Example(Alcatel6000) (config) #aaa stateful-authentication dot1x default-role pauldefrole (Alcatel6000) (config) #aaa sta

Strona 682 - 660 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference690 Part 031652-00 May 2005Example(Alcatel6000) (config) #aaa stateful-authentication kerberos enable (Al

Strona 683

AOS-W Commands 691Chapter 29aaa timers dead-timeConfigure authentication timers(Alcatel6000) (config) #aaa timers ?dead-time Help not d

Strona 684 - See also backup

OmniAccess Reference: AOS-W System Reference692 Part 031652-00 May 2005aaa timers idle-timeout(Alcatel6000) (config) #aaa timers ?dead-time

Strona 685

AOS-W Commands 693Chapter 29aaa timers logon-lifetime(Alcatel6000) (config) #aaa timers ?dead-time Help not definedidle-timeout

Strona 686 - 664 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference694 Part 031652-00 May 2005aaa trusted-ap Configure trusted third party APs.Syntaxaaa trusted

Strona 687 - AOS-W Commands 665

AOS-W Commands 695Chapter 29aaa vpn-authentication auth-server Assigns an authentication server.Syntax(Alcatel6000) (config) #aaa vpn-authenticat

Strona 688 - 666 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference696 Part 031652-00 May 2005Syntax(Alcatel6000) (config) #aaa web admin-port https port numberwhere :admin-

Strona 689 - AOS-W Commands 667

AOS-W Commands 697Chapter 29adp discovery Enables or disables ADP. Syntax (Alcatel6000) (config) # adp [discovery <disable | enable> | igmp-joi

Strona 690 - 668 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference50 Part 031652-00 May 2005Colored circles around the AP symbols on the floor plan indicate the approximate

Strona 691

OmniAccess Reference: AOS-W System Reference698 Part 031652-00 May 2005(Alcatel6000) (config) #ads netad mode learn ?<cr>(Alcatel6000) (config)

Strona 692 - (switch) #whoami

AOS-W Commands 699Chapter 29ap location Accesses the AP location mode.arm CommandsConfigures the Adaptive Radio Management commands.Syntaxarm [accepta

Strona 693 - AOS-W Commands 671

OmniAccess Reference: AOS-W System Reference700 Part 031652-00 May 2005Where:Example(Alcatel6000) (config) #arm acceptable-coverage-index 2 arm backof

Strona 694 - (switch) #write memory

AOS-W Commands 701Chapter 29arpAdds a static Address Resolution Protocol entry to the routing table.Syntax arp <ipaddr> <mac> where:<

Strona 695

OmniAccess Reference: AOS-W System Reference702 Part 031652-00 May 2005(Alcatel6000) (config) #clock CommandsConfigures the Wireless LAN Switch’s cloc

Strona 696

AOS-W Commands 703Chapter 29 Configures the time zone in which the Switch is located.Syntaxclock summer-time <WORD> [<-23-23]

Strona 697

OmniAccess Reference: AOS-W System Reference704 Part 031652-00 May 2005syntax dynamic-map <dynamic-map-name> <dynamic-map-number> <no|

Strona 698 - 676 Part 031652-00 May 2005

AOS-W Commands 705Chapter 29Syntax crypto ipsec <mtu> <size> | < transform-set> <transform-set-name> <encryption> <au

Strona 699 - Example

OmniAccess Reference: AOS-W System Reference706 Part 031652-00 May 2005Example(Alcatel6000) (config) #crypto isakmp ?address Configure

Strona 700 - 678 Part 031652-00 May 2005

AOS-W Commands 707Chapter 29(Alcatel6000) (config) #(Alcatel6000) (config) #crypto isakmp ?address Configure the IP for the group keyd

Strona 701

RF Design 51Chapter 4The Suggested AP Table lists the coordinates, power, location, power setting, and channel for each of the APs that are shown in t

Strona 702 - 680 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference708 Part 031652-00 May 2005(Alcatel6000) (config) #crypto isakmp groupname ?<name>

Strona 703

AOS-W Commands 709Chapter 29<peer-address> Configure the IP for the group key(Alcatel6000) (config) #crypto isakmp key 1111111111 addre

Strona 704 - 682 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference710 Part 031652-00 May 2005pre-share Use Pre Shared Keys for IKE authenticationrsa-sig

Strona 705

AOS-W Commands 711Chapter 29(Alcatel6000) (config-isakmp)# hash md5 ?<cr>(Alcatel6000) (config-isakmp)# lifetime ?<seconds>

Strona 706 - 684 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference712 Part 031652-00 May 2005Where:<global map> configures the default global map <map-number>

Strona 707

AOS-W Commands 713Chapter 29(Alcatel6000) (config) #destinationSyntaxdestination STRING <IP address><subnet mask> [invert | <cr>]Wh

Strona 708 - 686 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference714 Part 031652-00 May 2005timeout Set 802.1X timeout valuesunicast-keyrotation Enable

Strona 709

AOS-W Commands 715Chapter 29dot1x key-size Set the Dynamic WEP Key Size.Syntaxdot1x key-size <128> |<40>where128 specifies

Strona 710 - Example

OmniAccess Reference: AOS-W System Reference716 Part 031652-00 May 2005Syntaxdot1x opp-key-caching ?Example(Alcatel6000) (config) # dot1x opp-key-cach

Strona 711

AOS-W Commands 717Chapter 29 Example(Alcatel6000) (config) # dot1x server server-retry 3(Alcatel6000) (config) #(Alcatel6000) (config) # dot1x server

Strona 712 - (Alcatel6000) (config) #

OmniAccess Reference: AOS-W System Reference52 Part 031652-00 May 2005Viewing the ResultsViewing the results of the AM Plan feature is similar to that

Strona 713

OmniAccess Reference: AOS-W System Reference718 Part 031652-00 May 2005Example(Alcatel6000) (config) # dot1x timeout quiet-period 22(Alcatel6000) (co

Strona 714 - 692 Part 031652-00 May 2005

AOS-W Commands 719Chapter 29Syntaxdot1x timeout wpa-key-timeout <period>where:<period> is the timeout in seconds for each WPA key exchange

Strona 715

OmniAccess Reference: AOS-W System Reference720 Part 031652-00 May 2005Syntaxdot1x wired-clients Example(Alcatel6000) (config) # dot1x wired-clients

Strona 716 - 694 Part 031652-00 May 2005

AOS-W Commands 721Chapter 29Example(Alcatel6000) (config) # enablePassword:******Re-Type password:****** (Alcatel6000) (config) #encryptEnables encryp

Strona 717

OmniAccess Reference: AOS-W System Reference722 Part 031652-00 May 2005is the number of pings per second allowed. Higher number of pings per second ar

Strona 718 - 696 Part 031652-00 May 2005

AOS-W Commands 723Chapter 29Example(Alcatel2400) (config) #firewall deny-inter-user-bridging (Alcatel2400) (config) #firewall disable-ftp-server

Strona 719

OmniAccess Reference: AOS-W System Reference724 Part 031652-00 May 2005firewall enable-per-packet-logging Enable per-packet logging. Default is per-se

Strona 720 - 698 Part 031652-00 May 2005

AOS-W Commands 725Chapter 29Example(Alcatel2400) (config) #firewall prohibit-ip-spoofing (Alcatel2400) (config) #firewall prohibit-rst-replay Proh

Strona 721 - AOS-W Commands 699

OmniAccess Reference: AOS-W System Reference726 Part 031652-00 May 2005Syntax secure delete <spi_value> where <spi_value> is

Strona 722 - Option Description

AOS-W Commands 727Chapter 29secure-foreign deleteDeletes the home-agent-foreign-agent security association.Syntaxhome-agent delete <spi_value>

Strona 723 - Hello TuesdayE

RF Design 53Chapter 4

Strona 724 - clock timezone

OmniAccess Reference: AOS-W System Reference728 Part 031652-00 May 2005Syntaxhostname <hostname>where:<hostname> Specifies th

Strona 725

AOS-W Commands 729Chapter 29description Syntaxdescription <text>where<line> is a text lable. Lables can be up to Example(Alcatel6000) (co

Strona 726

OmniAccess Reference: AOS-W System Reference730 Part 031652-00 May 2005muxportConfigures Mux functionality on the port.SyntaxwhereExample (Alcatel6000

Strona 727

AOS-W Commands 731Chapter 29Example (Alcatel6000) (config-if)#rnet <slot/port>poe Power Over Ethernetinterface fastethernet

Strona 728 - 706 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference732 Part 031652-00 May 2005interface fastethernet <slot/port>snmp Modify SNMP int

Strona 729

AOS-W Commands 733Chapter 29SyntaxwhereExample (Alcatel6000) (config-if)#interface fastethernet <slot/port>switchport Set the switc

Strona 730 - 708 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference734 Part 031652-00 May 2005Example (Alcatel6000) (config-if)#interface fastethernet <slot/port> trus

Strona 731

AOS-W Commands 735Chapter 29Exampleinterface port-channelEthernet channel of interfacesSyntaxExampleinterface rangeInterface rangeinterface tunnelSynt

Strona 732 - 710 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference736 Part 031652-00 May 2005<cr>(Alcatel6000) (config) #interface loopback(Alcatel6000) (config-loop)

Strona 733 - <dynamic-map-name>

AOS-W Commands 737Chapter 29 as switch ip.(switch) (config-loop)# ip address ?A.B.C.D A.B.C.D IP address(switc

Strona 734 - Paulmap

OmniAccess Reference: AOS-W System Reference54 Part 031652-00 May 2005

Strona 735 - AOS-W Commands 713

OmniAccess Reference: AOS-W System Reference738 Part 031652-00 May 2005NAT which configures Network Address Translation. RADIUS which configures RADIU

Strona 736 - 714 Part 031652-00 May 2005

AOS-W Commands 739Chapter 29Example(hostswitch) (config) #ip access-list mac 709 (hostswitch) (config) #ip access-list sessionConfigures a session acc

Strona 737

OmniAccess Reference: AOS-W System Reference740 Part 031652-00 May 2005Example (hostswitch) (config) #ip default-gateway 1.1.1.1 mgmt (hostswitch) (co

Strona 738 - 716 Part 031652-00 May 2005

AOS-W Commands 741Chapter 29no Delete Commandoption Configure client specific optionsip igmpConfigure Internet G

Strona 739

OmniAccess Reference: AOS-W System Reference742 Part 031652-00 May 2005 ip radius dynamic-authorizationConfigures a RFC-3576 compliant RADIUS client.S

Strona 740

AOS-W Commands 743Chapter 29(hostswitch) (config) #ip radius source-interface vlan 3030(hostswitch) (config) #ip routeEstablishes static routes.Syntax

Strona 741

OmniAccess Reference: AOS-W System Reference744 Part 031652-00 May 2005(switch) (config) # key paulSyntax Error processing command(switch) (config) #l

Strona 742 - 720 Part 031652-00 May 2005

AOS-W Commands 745Chapter 29Examplelogging levelSet Facility Logging levellogging monitorSet Terminal Line (monitor) logging level(switch) (config) #l

Strona 743 - To turn on encryption, enter:

OmniAccess Reference: AOS-W System Reference746 Part 031652-00 May 2005gigabitethernet specifies Gigabit Ethernet per the IEEE 802.3 specification<

Strona 744 - 722 Part 031652-00 May 2005

AOS-W Commands 747Chapter 29Example(hostswitch) (config-master-redundancy)# no master-vrrp (hostswitch) (config-master-redundancy)#(hostswitch) (confi

Strona 745 - (firewall disable-ftp-server

Security Options 55CHAPTER 5Security OptionsStrong network security is an absolute necessity in today’s enterprise network environment. There are pryi

Strona 746 - 724 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference748 Part 031652-00 May 2005mgmt-roleAccess the commands that define the Management Role.Syntaxmgmt-role &l

Strona 747 - 1.1.1.1

AOS-W Commands 749Chapter 29ExampleTBDmgmt-user (Alcatel6000) (config) #mgmt-user ?<username> Name of the user.(Alcatel6000) (confi

Strona 748

OmniAccess Reference: AOS-W System Reference750 Part 031652-00 May 2005(Alcatel6000) (config) #no mgmt-user pauluser ?<cr>(Alcatel6000) (config)

Strona 749 - (Alcatel6000) (config)#

AOS-W Commands 751Chapter 29event-thresholdSyntaxExampleignore-l2-broadcastIgnore layer 2 broadcasts for making mobility decisions. Default disabled.S

Strona 750 - (switch) (config-if) #

OmniAccess Reference: AOS-W System Reference752 Part 031652-00 May 2005Examplemax-dhcp-requests Maximum number of DHCP DISCOVERS/REQUESTS after

Strona 751 - (Alcatel6000) (config-if)#

AOS-W Commands 753Chapter 29secure Configure the global security association parameters for the mobility manager.SyntaxExamplestation

Strona 752 - 730 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference754 Part 031652-00 May 2005SyntaxExampleha-priority Set Home Agent priority for this VLAN Synt

Strona 753 - AOS-W Commands 731

AOS-W Commands 755Chapter 29mux-address(Alcatel6000) (config) #mux-address ?<mux-ip-address> A.B.C.D IP address(Alcatel6000) (config) #m

Strona 754 - 732 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference756 Part 031652-00 May 2005% Incomplete command.(Alcatel6000) (config) #no mux-vlan 24(Alcatel6000) (confi

Strona 755 - AOS-W Commands 733

AOS-W Commands 757Chapter 29newbury(Alcatel6000) (config) # newbury ?<ip-addr> Specify IP Address of Locate Server A.B.C.D(Alcate

Strona 756

OmniAccess Reference: AOS-W System Reference56 Part 031652-00 May 2005Default Open PortsBy default, Alcatel Wireless LAN Switches and Access Points tr

Strona 757 - Switch VLAN Virtual Interface

OmniAccess Reference: AOS-W System Reference758 Part 031652-00 May 2005no clock Configure time-of-day clockSyntaxExampleno crypto

Strona 758 - 736 Part 031652-00 May 2005

AOS-W Commands 759Chapter 29SyntaxExampleno firewall Configure global firwall policiesSyntaxExampleno interface Select an

Strona 759 - IP Commands

OmniAccess Reference: AOS-W System Reference760 Part 031652-00 May 2005no loginsession Login SessionSyntaxExampleno mac-address-table

Strona 760 - 738 Part 031652-00 May 2005

AOS-W Commands 761Chapter 29SyntaxExampleno netdestination Configure network destinationno netservice Configure a network servic

Strona 761

OmniAccess Reference: AOS-W System Reference762 Part 031652-00 May 2005SyntaxExampleno router Router MobileSyntaxExampleno service

Strona 762 - 740 Part 031652-00 May 2005

AOS-W Commands 763Chapter 29no spanning-tree Spanning Tree SubsystemSyntaxExampleno telnet Enable telnet portSyntaxExamplen

Strona 763

OmniAccess Reference: AOS-W System Reference764 Part 031652-00 May 2005SyntaxExampleno vlan Create Switch VLAN Virtual InterfaceSyn

Strona 764 - 742 Part 031652-00 May 2005

AOS-W Commands 765Chapter 29(Alcatel6000) (config) #ntp 10.100.101.30 ?(Alcatel6000) (config) #ntp 10.100.101.30packet-capture-defaults(Alcatel6000) (

Strona 765 - <cr>

OmniAccess Reference: AOS-W System Reference766 Part 031652-00 May 2005(Alcatel6000) (config) #packet-capture-defaults tcp ?ports Up

Strona 766 - (switch) (config) # logging ?

AOS-W Commands 767Chapter 29(Alcatel6000) (config) # ping(Alcatel6000) (config) #ping ?<ipaddr> Send ICMP echo packets to a speci

Strona 767 - Example:

Security Options 57Chapter 568 UDP AP (and Wireless LAN Switch if DHCP server is configured)DHCP client69 UDP Wireless LAN SwitchTFTP80 TCP AP and Wir

Strona 768 - 746 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference768 Part 031652-00 May 2005(Alcatel6000) (config) #no pptp ip ?local Configure local IP

Strona 769 - AOS-W Commands 747

AOS-W Commands 769Chapter 29(Alcatel5050) >(Alcatel5050) >enablePassword:******(Alcatel5050) #configure terminalEnter Configuration commands, on

Strona 770 - Description

OmniAccess Reference: AOS-W System Reference770 Part 031652-00 May 2005% Incomplete command.(Alcatel6000) (config) # show rap-wml ?cache

Strona 771 - AOS-W Commands 749

AOS-W Commands 771Chapter 29<server-name> Specify Name of MSSQL Servertable Specify Table Name for Lookup(Alcatel600

Strona 772 - mobagent

OmniAccess Reference: AOS-W System Reference772 Part 031652-00 May 2005(Alcatel6000) (config) #router mobile ?<A.B.C.D> IP Address

Strona 773

AOS-W Commands 773Chapter 29SAPM_COUNTERS_RESULT--------------------LOC SAP_IP Updates Sent ACKs Rcvd APBoots Sent APBoots Rcvd Bootstraps Rebo

Strona 774 - 752 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference774 Part 031652-00 May 2005shutdown(switch) (config) # shutdown ?all All the physical

Strona 775 - (Alcatel6000) (config-mob) #

AOS-W Commands 775Chapter 29neighbor-tx-power-bump amount of increase in tx power for a neighbor for HA recoveryrra-max-comput

Strona 776 - Delete Command

OmniAccess Reference: AOS-W System Reference776 Part 031652-00 May 2005(switch) (config) #site-survey neighbor-tx-power-bump ?<neighbor-tx-power-bu

Strona 777 - AOS-W Commands 755

AOS-W Commands 777Chapter 29snmp-server(switch) (config) #snmp-server ?community set read-only community stringenable h

Strona 778 - 756 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Referenceviii Part 031652-00 May 2005Wireless Network Operation . . . . . . . . . . . . . . 238Wireless Laptops .

Strona 779 - Cisco Access point

OmniAccess Reference: AOS-W System Reference58 Part 031652-00 May 2005514 UDP Wireless LAN SwitchSyslog1701 UDP Wireless LAN SwitchL2TP1723 TCP Wirele

Strona 780 - 758 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference778 Part 031652-00 May 2005snmp-server host(switch) (config) #snmp-server host ?A.B.C.D IP

Strona 781

AOS-W Commands 779Chapter 29spanning-tree forward-time(switch) (config) #spanning-tree forward-time ?<value> Set a Spanning Tree

Strona 782 - 760 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference780 Part 031652-00 May 2005(switch) (config) #show spanning-treeSpanning Tree is not currently activeThe f

Strona 783

AOS-W Commands 781Chapter 29 this valuesta-dos-block-time Amount of time to block a STA on with DoS is detected

Strona 784 - Shut down interface

OmniAccess Reference: AOS-W System Reference782 Part 031652-00 May 2005good-sta-ageout Amount of time after with STA with good RSSID to one

Strona 785

AOS-W Commands 783Chapter 29Examplestm coverage-hole-dectectionSyntaxExamplestm dos-prevention(switch) (config) #(switch) (config) #stm dos-prevention

Strona 786 - Configure the VPN dialer

OmniAccess Reference: AOS-W System Reference784 Part 031652-00 May 2005enable Enable(switch) (config) #stm dos-prevention enable fast

Strona 787

AOS-W Commands 785Chapter 29 this valuesta-dos-block-time Amount of time to block a STA on with DoS is detected

Strona 788 - 766 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference786 Part 031652-00 May 2005coverage-hole-detecti.. Enable/Disable STM coverage hole capabilitiesdos-preven

Strona 789

AOS-W Commands 787Chapter 29auth-failure-block-ti.. Amount of time to block a STA if it fails repeated au thentications. In sec

Strona 790 - 768 Part 031652-00 May 2005

Security Options 59Chapter 5AOS-W Security OptionsThe following security configuration options are supported in AOS-W:z Rolesz Policiesz AAA Serversz

Strona 791 - AOS-W Commands 769

OmniAccess Reference: AOS-W System Reference788 Part 031652-00 May 2005stm sta-dos-preventionstm strict-complianceSyntaxExamplesyscontact(switch) (con

Strona 792 - 770 Part 031652-00 May 2005

AOS-W Commands 789Chapter 29(switch) (config) #syslocation Crossman main lab ^% Invalid input detected

Strona 793 - AOS-W Commands 771

OmniAccess Reference: AOS-W System Reference790 Part 031652-00 May 2005time-rangeInforms the Switch when a time-restricted feature, like an access lis

Strona 794 - 772 Part 031652-00 May 2005

AOS-W Commands 791Chapter 29(switch) (config) #show time-range(switch) (config) #traceroute(switch) (config) #traceroute ?<ipaddr>

Strona 795 - Enable disable DHCP

OmniAccess Reference: AOS-W System Reference792 Part 031652-00 May 2005 20 * * * 21 * * * 22 * * * 23 * * * 24 * * * 25 * * * 26 *

Strona 796 - 774 Part 031652-00 May 2005

AOS-W Commands 793Chapter 29<cr>(switch) (config) #show user ?authentication-method Match authentication methodbssid Match B

Strona 797

OmniAccess Reference: AOS-W System Reference794 Part 031652-00 May 200510.4.21.102 00:00:00:00:00:00 rama ap-role 00:00:25 VPN 10.4.21.2

Strona 798 - 776 Part 031652-00 May 2005

AOS-W Commands 795Chapter 29(switch) (config) #show user role guest ?rows Show certain rows<cr>(switch) (config) #show user r

Strona 799

OmniAccess Reference: AOS-W System Reference796 Part 031652-00 May 2005(switch) (config-role) #show user role visitorUsers----- IP MAC

Strona 800 - 778 Part 031652-00 May 2005

AOS-W Commands 797Chapter 29(switch) (config-role) #version 2.4(switch) (config) #show version ?<cr>(switch) (config) #show versionAlcatel Wirel

Strona 801

OmniAccess Reference: AOS-W System Reference60 Part 031652-00 May 2005z Global Firewall Settingsz AdvancedThese options are described in this chapter.

Strona 802 - 780 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference798 Part 031652-00 May 2005(switch) (config) #vlan(switch) (config) # vlan <id>(switch) (config) #sh

Strona 803

AOS-W Commands 799Chapter 29pptp Configure the PPTP group(switch) (config) #vpdn group l2tp ?<cr>(switch) (config) #vpdn grou

Strona 804 - 782 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference800 Part 031652-00 May 2005(switch) (config) #show vpdn pptp ?configuration Show PPTP configurat

Strona 805

AOS-W Commands 801Chapter 29<cr>(switch) (config) #show vpdn tunnel pptpCommand obsolete. Please use show user-table to get a list of users. A

Strona 806 - 784 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference802 Part 031652-00 May 2005STRING Configuration Name of the VPN dialer(switch) (config) #

Strona 807

AOS-W Commands 803Chapter 29CACHE-SECURID disabledIKESECS 28800IKEENC 3DESIKEGROUP TWOIKEHASH SH

Strona 808 - 786 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference804 Part 031652-00 May 2005intra-switch Intra-switch Virtual Router Redundancy Protocol Confi

Strona 809

AOS-W Commands 805Chapter 29shutdown Disable VRRP intra-switch(switch) (config-vrrp)#no shutdown ?<cr>(switch) (config-vrrp)#no s

Strona 810 - 788 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference806 Part 031652-00 May 2005 SSLv3 and TLSv1admin-port(switch) (config-webserver)#ad

Strona 811

AOS-W Commands 807Chapter 29<cr>(switch) (config-webserver)#ssl-protocol tlsv1 sslv2 ?sslv3 Use SSLv3<cr>(switch) (confi

Strona 812 - 790 Part 031652-00 May 2005

Security Options 61Chapter 5FIGURE 5-2 Add New RoleUser role configuration parameters are described in the following sections.

Strona 813

OmniAccess Reference: AOS-W System Reference808 Part 031652-00 May 2005reserved-11a-channel enable/disable 80211a channel as multi tenancy protec

Strona 814 - (switch) (config) # user ?

AOS-W Commands 809Chapter 29ap-lb-max-retries max tries to encourage STA to move to a unloaded APap-lb-user-high-wm High WM on max users th

Strona 815

OmniAccess Reference: AOS-W System Reference810 Part 031652-00 May 2005 balancingap-lb-util-low-wm Low WM on utilization

Strona 816 - 794 Part 031652-00 May 2005

AOS-W Commands 811Chapter 29ids-signature configure a signature for the IDS checkno Delete Commandreserved-11a-channel

Strona 817

OmniAccess Reference: AOS-W System Reference812 Part 031652-00 May 2005poll-retries # of retries before it is declared downsta-ageout-inter

Strona 818 - 796 Part 031652-00 May 2005

AOS-W Commands 813Chapter 29 ake anomlay after which the check can be resumedeap-rate-threshold Number of EAP handshake pa

Strona 819 - AOS-W Commands 797

OmniAccess Reference: AOS-W System Reference814 Part 031652-00 May 2005ap-flood-check IDS Fake AP Flood Detectionap-flood-inc-time Numb

Strona 820 - (switch) (config) #

AOS-W Commands 815Chapter 29wbridge-quiet-time Time to wait in seconds after detecting a wireless br idge after which the

Strona 821

OmniAccess Reference: AOS-W System Reference816 Part 031652-00 May 2005(switch) (wms) #reserved-11a-channel ?<reserved-11a-channel> enable/disa

Strona 822 - 800 Part 031652-00 May 2005

AOS-W Commands 817Chapter 29NOTE—The handoff-assist option allows the switch to force a sticky client off of an AP when the RSSI drops below the defi

Strona 823

OmniAccess Reference: AOS-W System Reference62 Part 031652-00 May 2005CLI Configuration for User RolesSample CLI configuration follows for two differe

Strona 824 - 802 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference818 Part 031652-00 May 2005(switch) (wms) #valid-11b-channel 14 ?mode enable/disable(sw

Strona 825

Action Commands 819CHAPTER 30Action CommandsAction Commands are available from the main Command-Line Interface (CLI) prompts in user mode and privileg

Strona 826 - 804 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference820 Part 031652-00 May 2005Switch Management CommandsenableType this command to enter the privileged mode.

Strona 827

Action Commands 821Chapter 30Privileged Mode CommandsPrivileged mode is entered from the user mode through the enable command (see page 820). This mod

Strona 828 - 806 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference822 Part 031652-00 May 2005configure terminalEnter the configuration mode. This mode provides access to sy

Strona 829

Action Commands 823Chapter 30delete <filename>Delete the specified file from the system. To view a list of files, use the dir command.dirList th

Strona 830 - 808 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference824 Part 031652-00 May 2005reloadReboot the system after prompting the user to verify the command. If ther

Strona 831

Action Commands 825Chapter 30traceroute <IP Address>This command traces the route, displaying each hop, to a host specified by the IP Address ar

Strona 832 - 810 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference826 Part 031652-00 May 2005WMS Commandswms ap <MAC address> [mode <type (dos |interfering| valid)

Strona 833

Action Commands 827Chapter 30Site Survey Commandssite-survey...Variations:z site-survey calibrate <building ID> <type (a|b|G)> [channel &l

Strona 834 - 812 Part 031652-00 May 2005

Security Options 63Chapter 5what came before – at best, ACLs can look at the “SYN” flag in a TCP packet, treating the session as new if the flag is se

Strona 835

OmniAccess Reference: AOS-W System Reference828 Part 031652-00 May 2005Authentication CommandsAAA CommandsThe following immediate commands are used fo

Strona 836 - 814 Part 031652-00 May 2005

Action Commands 829Chapter 30Local Database CommandsThe local user database is an internal Wireless LAN switch database for authenticating users. If u

Strona 837

OmniAccess Reference: AOS-W System Reference830 Part 031652-00 May 2005Clear Commandsclear arpThis command clears the ARP table.clear counters [fastet

Strona 838 - 816 Part 031652-00 May 2005

Action Commands 831Chapter 30clear stm hole <BSSID>This command clears the coverage hole information for the specified BSSID.Debug Commandsdebug

Strona 839

OmniAccess Reference: AOS-W System Reference832 Part 031652-00 May 2005Panic Commandspanic clearThis command Clears all panic information from NVRAM.p

Strona 840 - 818 Part 031652-00 May 2005

Show Commands 833CHAPTER 31Show CommandsThis chapter provides a summary of the show commands available on the Alcatel Wireless LAN Switch in your netw

Strona 841 - Action Commands

OmniAccess Reference: AOS-W System Reference834 Part 031652-00 May 2005show image versionThis command displays version information about the software

Strona 842 - Password:***********

Show Commands 835Chapter 31show loginsessionsThis command displays information about current sessions.Information returned by this command is:z ID: Se

Strona 843

OmniAccess Reference: AOS-W System Reference836 Part 031652-00 May 2005show station-tableThis command displays information about the stations connecte

Strona 844

Show Commands 837Chapter 31show inventoryThis commands shows the physical contents of the switch. It also shows the status of each power supply and fa

Strona 845 - Action Commands 823

OmniAccess Reference: AOS-W System Reference64 Part 031652-00 May 2005To edit or delete existing policies, click the appropriate button. Note that som

Strona 846 - Layer 2/Layer 3 Commands

OmniAccess Reference: AOS-W System Reference838 Part 031652-00 May 2005show processesThis command shows which processes are currently running and thei

Strona 847 - Air Management Commands

Show Commands 839Chapter 31show syslocationThis command displays the physical location of the switch, if it has been specified in the configuration fi

Strona 848 - WMS Commands

OmniAccess Reference: AOS-W System Reference840 Part 031652-00 May 2005Layer 2/Layer 3 CommandsLayer 2 Commandsshow mac-address-tableDisplays the MAC

Strona 849 - Site Survey Commands

Show Commands 841Chapter 31show spantreeThis command display information about the status of spanning-tree ports. Execute this command with no options

Strona 850 - Authentication Commands

OmniAccess Reference: AOS-W System Reference842 Part 031652-00 May 2005show vlan [<ID>]This command displays the name and ports for the specifie

Strona 851 - Local Database Commands

Show Commands 843Chapter 31Layer 3 Commandsshow ip route [static]show routeridThis command displays the IP Address of the switch.(Alcatel) # show ip r

Strona 852 - Clear Commands

OmniAccess Reference: AOS-W System Reference844 Part 031652-00 May 2005show arp(Alcatel) # show arpProtocol Address Hardware Address

Strona 853 - Debug Commands

Show Commands 845Chapter 31DHCP Commandsshow ip dhcp databaseThis command displays information about DHCP pools created using the ip dhcp pool command

Strona 854

OmniAccess Reference: AOS-W System Reference846 Part 031652-00 May 2005Interface Commandsshow port link-eventThis command displays a count of up/down

Strona 855 - CHAPTER 31

Show Commands 847Chapter 31z POEz Tr u stedz SpanningTreez PortModeshow port trustedThis commands displays a list of trusted ports.Information returne

Strona 856 - 834 Part 031652-00 May 2005

Security Options 65Chapter 5Network – An IP subnet, consisting of a network number and subnet mask.Alias – When Alias is selected, allows selection of

Strona 857 - Show Commands 835

OmniAccess Reference: AOS-W System Reference848 Part 031652-00 May 2005show interface countersThis command displays the various inbound and outbound p

Strona 858 - 836 Part 031652-00 May 2005

Show Commands 849Chapter 31show interface {fastethernet|gigabitethernet} <slot>/<port> [switchport] [allowed-vlan|native-vlan]This command

Strona 859 - Chapter 31

OmniAccess Reference: AOS-W System Reference850 Part 031652-00 May 2005show interface fastethernet <slot>/<port>show interface fastetherne

Strona 860 - 838 Part 031652-00 May 2005

Show Commands 851Chapter 31show interface fastethernet <slot>/<port> switchport native-vlanshow interface gigabitethernet <slot> <

Strona 861

OmniAccess Reference: AOS-W System Reference852 Part 031652-00 May 2005show interface port-channel <0-7>show interface vlan <1 - 4094>(Alc

Strona 862

Show Commands 853Chapter 31Local Database Commandsshow local-userdb [<username>]This command displays information about local users.Information

Strona 863

OmniAccess Reference: AOS-W System Reference854 Part 031652-00 May 2005VPN CommandsIPSec Commandsshow crypto dpThis command displays the last few add

Strona 864 - 842 Part 031652-00 May 2005

Show Commands 855Chapter 31show crypto ipsec transform-set [tag <transform-set-name>]This command displays the encryption and data authenticatio

Strona 865 - Layer 3 Commands

OmniAccess Reference: AOS-W System Reference856 Part 031652-00 May 2005L2TP Commandsshow vpdn tunnel {l2tp|pptp|tunnel} [id <tunnel ID>]This com

Strona 866 - 844 Part 031652-00 May 2005

Show Commands 857Chapter 31show vpdn {l2tp|pptp} configurationThis command displays information about the VPN tunnel settings.L2TP optionPPTP option(A

Strona 867 - DHCP Commands

OmniAccess Reference: AOS-W System Reference66 Part 031652-00 May 2005Src-nat – Changes the source IP address of the packet. If no source NAT pool is

Strona 868 - Interface Commands

OmniAccess Reference: AOS-W System Reference858 Part 031652-00 May 2005show vpdn {l2tp|pptp} local pool [<pool name>]This command displays infor

Strona 869 - (Alcatel) # show port trusted

Show Commands 859Chapter 31VPN Dialer Commandsshow vpn-dialer [<dialername>]This command displays all the attributes of the specified dialername

Strona 870 - 848 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference860 Part 031652-00 May 2005PPTP Commandsshow vpdn pptp configurationThis command displays the VPN configur

Strona 871

Show Commands 861Chapter 31Mobility Commandsshow mobile active-user-tableThis command displays information about all currently active users.show forei

Strona 872 - 850 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference862 Part 031652-00 May 2005show home-agent [configuration|{security [for-eign|mobile]}|status]This command

Strona 873 - 1 (Default)

Show Commands 863Chapter 31show mobile client [verbose <IP>]This command will display information about mobile clients currently registered with

Strona 874 - 852 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference864 Part 031652-00 May 2005show mobile configurationThis command displays information bout the mobility ma

Strona 875

Show Commands 865Chapter 31show mobile home-agents {global|local}This command displays the home agent tables.The following information is contained in

Strona 876 - VPN Commands

OmniAccess Reference: AOS-W System Reference866 Part 031652-00 May 2005show mobile messagesThe messages shown by the mobile messages command are liste

Strona 877

Show Commands 867Chapter 31show mobile received-packets <num (0-50)>Information returned in the table includes:z Noz Timez Opcode: manufacturing

Strona 878 - L2TP Commands

Security Options 67Chapter 5FIGURE 5-5 Rule OrderingCLI ConfigurationAll CLI configuration for traffic/firewall policies is done under the ip access-

Strona 879

OmniAccess Reference: AOS-W System Reference868 Part 031652-00 May 2005show mobile registration-statistics <IP>This command displays mobile IP p

Strona 880 - 1 IPs used - 25498 IPs free

Show Commands 869Chapter 31show mobile tunnels [ mobile-ip | sap ]This command displays all the IPIP tunnels existing between M-switches.show mobile

Strona 881 - VPN Dialer Commands

OmniAccess Reference: AOS-W System Reference870 Part 031652-00 May 2005show mobile user-status [address <IP Address>] [mac-address <Address&g

Strona 882 - PPTP Commands

Show Commands 871Chapter 31show mobile vlan-configurationThis command displays all the current VLANs on the switch.(Alcatel) (config) #show mobile vla

Strona 883 - Mobility Commands

OmniAccess Reference: AOS-W System Reference872 Part 031652-00 May 2005Air Management CommandsAir Monitor Commandsshow pcap free-space <AM IP addre

Strona 884 - 862 Part 031652-00 May 2005

Show Commands 873Chapter 31show am bssid-scan <am-ip> <channel>This command lists the ...show am channel <am-ip> <channel>Thi

Strona 885

OmniAccess Reference: AOS-W System Reference874 Part 031652-00 May 2005show am pot-ap-list <am-ip>This command displays the BSSIDs seen on the s

Strona 886 - 864 Part 031652-00 May 2005

Show Commands 875Chapter 31show am stats <AM IP address> <MAC address> [verbose]TIP: You can find an AP or AM IP address and MAC by using

Strona 887 - Show Commands 865

OmniAccess Reference: AOS-W System Reference876 Part 031652-00 May 2005(Alcatel) # show ap stats 10.2.12.212 00:30:f1:70:49:65 verbose Frame rates----

Strona 888 - Control Messages

Show Commands 877Chapter 31show am association <AM IP address> <ap-bssid>This command displays information about a specific station assoc

Strona 889 - Show Commands 867

ixChapter 14 Radio Resource Management . . . . . . 289Introduction . . . . . . . . . . . . . . . . . . . . . . 289Calibration . . . . . . . . . .

Strona 890 - 868 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference68 Part 031652-00 May 2005FIGURE 5-6 Applying Traffic Policies to PortsTo add traffic policies to ports u

Strona 891 - <MACaddr>}

OmniAccess Reference: AOS-W System Reference878 Part 031652-00 May 2005show am sta-list <AM IP address>show am config <AM IP address>show

Strona 892 - 870 Part 031652-00 May 2005

Show Commands 879Chapter 31show am version <AM IP address>show am scan-times <AM IP address>This command displays the scan times for the s

Strona 893

OmniAccess Reference: AOS-W System Reference880 Part 031652-00 May 2005show am counters <AM IP address>(Alcatel) # show am counters 10.1.1.162Co

Strona 894

Show Commands 881Chapter 31WMS CommandsWMS commands are privileged commands entered from the WMS sub-mode.Enter the privileged mode.Ty p e configure

Strona 895

OmniAccess Reference: AOS-W System Reference882 Part 031652-00 May 2005show wms ap <BSSID>This command displays the monitors that are listening

Strona 896 - 874 Part 031652-00 May 2005

Show Commands 883Chapter 31show wms sta <MAC address>This command displays the monitors that are listening to the station specified in the MAC A

Strona 897

OmniAccess Reference: AOS-W System Reference884 Part 031652-00 May 2005show wms countersSite Survey Commandsshow site survey calibration [dst<bssid

Strona 898

Show Commands 885Chapter 31show site survey in-progressThis commands displays information about any site survey currently in progress.Station Manageme

Strona 899

OmniAccess Reference: AOS-W System Reference886 Part 031652-00 May 2005show stm dos-staThis command displays information about stations that are curre

Strona 900

Show Commands 887Chapter 31Access Point Management CommandsAlcatel Soft AP Commandsshow ap config location <location>This command displays the c

Strona 901

Security Options 69Chapter 5“Location” field on this line. See the chapter entitled “Wireless LAN Configuration – Advanced Location-Based AP Configura

Strona 902 - 880 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference888 Part 031652-00 May 2005show ap configsThis command displays the configuration information for all APs.

Strona 903

Show Commands 889Chapter 31show ap keys <location>This command displays the keys for the AP in the specified location. If the encrypt feature ha

Strona 904 - 882 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference890 Part 031652-00 May 2005show ap registered location <location>Different values for STATE are as f

Strona 905

Show Commands 891Chapter 31Authentication CommandsGeneral Authentication Commandsshow netservice [<name>]show destination [<name>]show use

Strona 906

OmniAccess Reference: AOS-W System Reference892 Part 031652-00 May 2005show userThis command displays information about users, including: roles, IP ad

Strona 907 - Station Management Commands

Show Commands 893Chapter 31show rightsshow rights <role name>This commands shows the rights assigned to a specific role name.z mobile This optio

Strona 908 - 886 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference894 Part 031652-00 May 2005IEEE 802.1x Commandsshow dot1x configThe show dot1x config command displays the

Strona 909 - Alcatel Soft AP Commands

Show Commands 895Chapter 31z MAC Address of the supplicantz User Namez Authentication Status (yes/no)z AP MACz Encryption Keyz Authorization Modez EAP

Strona 910 - 888 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference896 Part 031652-00 May 2005Accounting, Authentication, Authorizationshow aaa derivation-rulesThis command

Strona 911 - Number Condition

Show Commands 897Chapter 31show aaa server-rules <server name>This command displays the User Rule Table for the named authentication server. You

Strona 912

OmniAccess Reference: AOS-W System Reference70 Part 031652-00 May 2005Role VLAN ID –This parameter allows the user to be mapped to a particular VLAN b

Strona 913

OmniAccess Reference: AOS-W System Reference898 Part 031652-00 May 2005show aaa timersshow aaa bandwidth-contractsThis command displays the name of ea

Strona 914 - Options:

Show Commands 899Chapter 31show aaa state messages(Alcatel) # show aaa state messagesPAPI Messages-------------Msg ID Name Since last Read

Strona 915 - Show Commands 893

OmniAccess Reference: AOS-W System Reference900 Part 031652-00 May 2005show aaa state user <IP address>show aaa state configurationshow aaa radi

Strona 916 - IEEE 802.1x Commands

Show Commands 901Chapter 31show aaa localdb-server [server-name <name>] show aaa dot1xThe show aaa dot1x commands displays which servers are con

Strona 917 - Show Commands 895

OmniAccess Reference: AOS-W System Reference902 Part 031652-00 May 2005show aaa auth-server [server-name <name>] [server-type {radius|ldap|local

Strona 918 - 896 Part 031652-00 May 2005

Show Commands 903Chapter 31Access Lists Commandsshow access-list [<name>|<number>]Display a list of the configured ACLs, or a specific ACL

Strona 919

OmniAccess Reference: AOS-W System Reference904 Part 031652-00 May 2005show ip access-list [<name>|<number>]Preferred from of the show acc

Strona 920 - User idle timeout = 1 minutes

Show Commands 905Chapter 31show time-rangeThis command displays currently configured time ranges.MUX Commandsshow muxThis command displays information

Strona 921

OmniAccess Reference: AOS-W System Reference906 Part 031652-00 May 2005Enhanced Show CommandsDepending on the target of the show command, the output i

Strona 922 - 900 Part 031652-00 May 2005

Show Commands 907Chapter 31z Detail ListsThe show commands that display information for a specific device, protocol, or event present detailed informa

Strona 923 - Show Commands 901

Security Options 71Chapter 5physical port basis, MAC address ACLs and Ethertype ACLs are both available. All ACL configuration is done through the CLI

Strona 924 - Dialer Commands

OmniAccess Reference: AOS-W System Reference908 Part 031652-00 May 2005

Strona 926 - 904 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference910 Part 031652-00 May 2005

Strona 927 - MUX Commands

Glossary 911Glossary10BaseT*An IEEE standard (802.3) for operating 10 Mbps Ethernet networks (LANs) with twisted pair cabling and a wiring hub.802.11

Strona 928 - Enhanced Show Commands

OmniAccess Reference: AOS-W System Reference912 Part 031652-00 May 2005802.11b*International standard for wireless networking that operates in the 2.4

Strona 929 - Detail Lists

Glossary 913Authentication serverAn entity that provides an authentication service to an authenticator. This service determines, from the credentials

Strona 930 - 908 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference914 Part 031652-00 May 2005Bus adapter*A special adapter card that installs in a PC's PCI or ISA slot

Strona 931

Glossary 915Crossover cable*A special cable used for networking two computers without the use of a hub. Crossover cables may also be required for conn

Strona 932 - 910 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference916 Part 031652-00 May 2005DHCP*A utility that enables a server to dynamically assign IP addresses from a

Strona 933 - Glossary

Glossary 917Encryption key*An alphanumeric (letters and/or numbers) series that enables data to be encrypted and then decrypted so it can be safely sh

Strona 934 - Application software*

OmniAccess Reference: AOS-W System Reference72 Part 031652-00 May 2005permit icmp 1.1.1.0 0.0.0.255 any echo-replyThe example above permits TCP traffi

Strona 935 - Glossary 913

OmniAccess Reference: AOS-W System Reference918 Part 031652-00 May 2005transmits packets it receives to all the connected ports. A small wired hub may

Strona 936 - 914 Part 031652-00 May 2005

Glossary 919IP address*A 32-bit number that identifies each sender or receiver of information that is sent across the Internet. An IP address has two

Strona 937 - DC power module*

OmniAccess Reference: AOS-W System Reference920 Part 031652-00 May 2005L2TPLayer 2 Tunnelling Protocol. L2TP is an extension of Point-to-Point Protoco

Strona 938 - 916 Part 031652-00 May 2005

Glossary 921Network name*Identifies the wireless network for all the shared components. During the installation process for most wireless networks, yo

Strona 939 - Glossary 917

OmniAccess Reference: AOS-W System Reference922 Part 031652-00 May 2005Plug and Play*A computer system feature that provides for automatic configurati

Strona 940 - 918 Part 031652-00 May 2005

Glossary 923Router*A device that forwards data packets from one local area network (LAN) or wide area network (WAN) to another. Based on routing table

Strona 941 - Glossary 919

OmniAccess Reference: AOS-W System Reference924 Part 031652-00 May 2005SSL*Commonly used encryption scheme used by many online retail and banking site

Strona 942 - 920 Part 031652-00 May 2005

Glossary 925on a network. Every computer in a TCP/IP network has its own IP address that is either dynamically assigned at startup or permanently assi

Strona 943 - Glossary 921

OmniAccess Reference: AOS-W System Reference926 Part 031652-00 May 2005Wi-Fi*An interoperability certification for wireless local area network (LAN) p

Strona 945 - Site survey*

Security Options 73Chapter 5To configure general authentication server settings, navigate to Configuration > Security > AAA Servers > General

Strona 946 - 924 Part 031652-00 May 2005

OmniAccess Reference: AOS-W System Reference928 Part 031652-00 May 2005

Strona 947 - Glossary 925

OmniAccess Reference: AOS-W System Reference74 Part 031652-00 May 2005FIGURE 5-10 RADIUS Server ConfigurationA list of currently configured RADIUS se

Strona 948 - WPA WPA/2

Security Options 75Chapter 5Shared Secret – Each RADIUS client-server pair must use a shared secret. Treat this shared secret as a password, and ensur

Strona 949 - Glossary 927

OmniAccess Reference: AOS-W System Reference76 Part 031652-00 May 2005FIGURE 5-12 Add RADIUS Server RuleAvailable configuration parameters are:Rule T

Strona 950 - 928 Part 031652-00 May 2005

Security Options 77Chapter 5LDAPLDAP (Lightweight Directory Access Protocol) is a lightweight protocol for accessing directory services. A directory i

Komentarze do niniejszej Instrukcji

Brak uwag