OmniAccessReferenceAOS-W System ReferenceTM
OmniAccess Reference: AOS-W System Referencex Part 031652-00 May 2005Configuring Captive Portal Authentication with Web UI . . . . . . . . . . . . . .
OmniAccess Reference: AOS-W System Reference78 Part 031652-00 May 2005FIGURE 5-13 LDAP Directory StructureAn entry at a given level in the directory’
Security Options 79Chapter 5and server is a TCP connection, there is a possibility for a third party to snoop the password from the connection. LDAP s
OmniAccess Reference: AOS-W System Reference80 Part 031652-00 May 2005Server Name – Specifies a human-readable name to reference the LDAP server.Host
Security Options 81Chapter 5authentication type, or the information may be learned from the authentication server through an attribute. Any attribute
OmniAccess Reference: AOS-W System Reference82 Part 031652-00 May 2005Internal Authentication DatabaseAOS-W supports an internal authentication databa
Security Options 83Chapter 5AccountingAOS-W supports standard RADIUS accounting for tracking user login/logout times. Accounting will track logins acc
OmniAccess Reference: AOS-W System Reference84 Part 031652-00 May 2005Once an authentication method has been enabled on the switch, it is automaticall
Security Options 85Chapter 5To configure 802.1x, navigate to Configuration > Security > Authentication Methods > 802.1x as shown in the figur
OmniAccess Reference: AOS-W System Reference86 Part 031652-00 May 2005Authentication Failure Timeout – After authentication fails, the 802.1x state ma
Security Options 87Chapter 5The equivalent CLI configuration for the example above is:aaa dot1x default-role "employee"aaa dot1x mode enable
xiDefining Roles Using Web UI. . . . . . . . . . . . . . 389Role Design . . . . . . . . . . . . . . . . . . . . . 389Configuring Roles. . . . . .
OmniAccess Reference: AOS-W System Reference88 Part 031652-00 May 2005VPN AuthenticationWhen the use of IPSec or PPTP is desired, Alcatel switches pro
Security Options 89Chapter 5aaa vpn-authentication auth-server Internalaaa vpn-authentication max-authentication-failures 0Captive Portal Authenticati
OmniAccess Reference: AOS-W System Reference90 Part 031652-00 May 2005Enable Guest Logon – When this option is selected, the captive portal page will
Security Options 91Chapter 5aaa captive-portal default-role "employee"aaa captive-portal guest-logonaaa captive-portal user-logonaaa captive
OmniAccess Reference: AOS-W System Reference92 Part 031652-00 May 2005Default Role – If a client is identified by MAC address, and the authentication
Security Options 93Chapter 5FIGURE 5-23 Stateful 802.1x ConfigurationAvailable configuration parameters are:Authentication Enabled – Enables or disab
OmniAccess Reference: AOS-W System Reference94 Part 031652-00 May 2005FIGURE 5-24 Stateful 802.1x AP/Server ConfigurationAvailable configuration para
Security Options 95Chapter 5FIGURE 5-25 SSID Role MappingAvailable configuration options are:Condition – Specifies how the value should be matched.Va
OmniAccess Reference: AOS-W System Reference96 Part 031652-00 May 2005bypassed, this method should always be combined with a firewall policy. To conf
Security Options 97Chapter 5Configuring VPN SettingsWhen the use of IPSec or PPTP is desired, Alcatel switches provide full VPN termination capabiliti
OmniAccess Reference: AOS-W System Referencexii Part 031652-00 May 2005AP Provisioning. . . . . . . . . . . . . . . . . . . . . . 428Plug and Play .
OmniAccess Reference: AOS-W System Reference98 Part 031652-00 May 2005FIGURE 5-27 IPSec ConfigurationAvailable configuration parameters are:Enable L2
Security Options 99Chapter 5Address Pools - IPSec tunnel endpoints are assigned IP addresses. The Alcatel switch endpoint will always use the switch
OmniAccess Reference: AOS-W System Reference100 Part 031652-00 May 2005crypto isakmp policy 10 authentication pre-sharePPTPPPTP provides an alternati
Security Options 101Chapter 5The equivalent CLI configuration for the example above is:vpdn group pptp client configuration dns 1.1.1.1 2.2.2.2 client
OmniAccess Reference: AOS-W System Reference102 Part 031652-00 May 2005As shown in the figure, two VPN dialers are currently configured. “Default-dia
Security Options 103Chapter 5Disable Wireless Devices when Client is Wired Allows the VPN dialer to detect when a wired network connection is in use.
OmniAccess Reference: AOS-W System Reference104 Part 031652-00 May 2005The equivalent CLI configuration for the example above is:vpn-dialer dialer2 e
Security Options 105Chapter 5The equivalent CLI configuration for the example above is:ip access-list session vpn-dst-nat any host 1.2.3.4 svc-ike ds
OmniAccess Reference: AOS-W System Reference106 Part 031652-00 May 2005To add the new condition, click Apply.SecureID Token CachingSecureID Token Cach
Security Options 107Chapter 5Adding IPSec Transform SetsTo create IPSec transform sets, click Add. The Add Transform Set screen appears.where:To add t
xiiiConfiguring IPSec Using the CLI . . . . . . . . . . . . 516Configuring PPTP Using the CLI . . . . . . . . . . . . 517Configuring the VPN Diale
OmniAccess Reference: AOS-W System Reference108 Part 031652-00 May 2005where:To apply the new firewall settings, click Apply. Parameter DescriptionMon
Security Options 109Chapter 5Advanced Security OptionsService AliasesService aliases aid in policy configuration by applying a human-readable label to
OmniAccess Reference: AOS-W System Reference110 Part 031652-00 May 2005Service Name – A human-readable name to identify the service alias. Default ser
Security Options 111Chapter 5User – When a traffic policy containing the “user” alias is applied to an authenticated user, this alias is replaced by t
OmniAccess Reference: AOS-W System Reference112 Part 031652-00 May 2005Source/destination aliases contain one or more IP addresses or ranges of IP add
Security Options 113Chapter 5Time RangeTo define a time range select Configuration > Security > Advanced > Time Range. The Time Range screen
OmniAccess Reference: AOS-W System Reference114 Part 031652-00 May 2005EncryptionEncrypting the transmitted data is only one part of the security proc
Security Options 115Chapter 5IPSec IP was originally developed within a highly restricted, secure network. Therefore, IP did not have security feature
OmniAccess Reference: AOS-W System Reference116 Part 031652-00 May 2005The PSK mode uses a pre-shared key (password) which is shared by all clients on
Security Options 117Chapter 5z CHAPz UNIX Loginz OthersRADIUS authentication is based on the exchange of shared secrets between a client and the authe
OmniAccess Reference: AOS-W System Referencexiv Part 031652-00 May 2005Wireless LAN Monitoring . . . . . . . . . . . . . . . . 576Debug Information
OmniAccess Reference: AOS-W System Reference118 Part 031652-00 May 2005z Microsoft Windows Mobile 203/CE 4.2 with built-in L2TP/IPSec VPN sup-port (PD
Security Options 119Chapter 5If you have a proxy server:z Navigate to Settings > Connections > Set up my proxy server.z Follow the on-screen ins
OmniAccess Reference: AOS-W System Reference120 Part 031652-00 May 2005
121PartSwitch Configuration3
OmniAccess Reference: AOS-W System Reference122 Part 031652-00 May 2005
Common Tasks 123CHAPTER 6Common TasksBasic Network ConfigurationVLANsVirtual Local Area Networks (VLANs) are used to divide LAN traffic into manageabl
OmniAccess Reference: AOS-W System Reference124 Part 031652-00 May 2005Provide a routing interface for the VLAN.Set the DHCP server for relaying DHCP
Common Tasks 125Chapter 6Set the port for access to the VLAN.Define whether the port is trusted (LAN) or untrusted (wireless).If connected to the trus
OmniAccess Reference: AOS-W System Reference126 Part 031652-00 May 2005z max-age <interval>Set the spanning tree maximum age interval.z priority
Common Tasks 127Chapter 6Save any current configuration changes.Determine the name of the current configuration file.In this example, default.cfg is t
xvNetwork Utilities . . . . . . . . . . . . . . . . . . . . . 627Ping . . . . . . . . . . . . . . . . . . . . . . . . . . 627Traceroute . . . . .
OmniAccess Reference: AOS-W System Reference128 Part 031652-00 May 2005For example:Here, the configuration file is downloaded to a TFTP server with IP
Common Tasks 129Chapter 6Upgrading the AOS-W SoftwareThe Alcatel AOS-W software can be upgraded as new releases become available.Obtain a valid Alcate
OmniAccess Reference: AOS-W System Reference130 Part 031652-00 May 2005Use the following command to check the memory partitions:In this example, parti
Common Tasks 131Chapter 6Verify that the new image is loaded.Use the following command to check the memory partitions:In this example, the new image c
OmniAccess Reference: AOS-W System Reference132 Part 031652-00 May 2005When the boot process is complete, verify the upgrade.In this example, Version
Common Tasks 133Chapter 6Reset Configuration to DefaultsUnder some conditions, like when reassigning a switch to a new environment, it may be helpful
OmniAccess Reference: AOS-W System Reference134 Part 031652-00 May 2005
Air Management 135CHAPTER 7Air ManagementThis chapter explains the main elements of wireless intrusion prevention.Alcatel Access Points (AP60, AP61, a
OmniAccess Reference: AOS-W System Reference136 Part 031652-00 May 2005Wireless LAN ClassificationThe WMS continually monitors wireless traffic to det
Air Management 137Chapter 7Wireless Client Station ClassificationsA wireless client station (STA) is classified as one of the following: z Valid STA (
OmniAccess Reference: AOS-W System Referencexvi Part 031652-00 May 2005aaa Commands . . . . . . . . . . . . . . . . . . . . . . 675aaa xml-api client
OmniAccess Reference: AOS-W System Reference138 Part 031652-00 May 2005Wired-Side MAC AddressesIf an AM is segregated from the LAN (by a firewall for
Air Management 139Chapter 7z Valid channel list for 802.11a channels:z Valid channel list for 802.11b channels:z SSID list:Enabling the PolicyOnce the
OmniAccess Reference: AOS-W System Reference140 Part 031652-00 May 2005Enabling the PolicyOnce the reserved channels are defined, the protection polic
Air Management 141Chapter 7Use the following commands to configure watermarks.z To set high and low watermarks for number of users per AP:z To set hig
OmniAccess Reference: AOS-W System Reference142 Part 031652-00 May 2005STA Impersonation Detection If the AM detects two stations with the same MAC ad
Air Management 143Chapter 7Global PoliciesWeak WEPIf the AM detects a station or AP encrypting 802.11 frames with weak WEP, a syslog event is generate
OmniAccess Reference: AOS-W System Reference144 Part 031652-00 May 2005generated. No new events are generated until the statistic value falls below th
Air Management 145Chapter 7z Poll intervalThis defines the interval in milliseconds for communication between the Alcatel Wireless LAN Switch and the
OmniAccess Reference: AOS-W System Reference146 Part 031652-00 May 2005z Laser beam debugWhen an AM generates a laser beam, it impersonates an AP or w
Air Management 147Chapter 7On the Alcatel Wireless LAN switch, configure the AM to send captured packets to the monitoring client station.NOTE—The Air
xviishutdown . . . . . . . . . . . . . . . . . . . . . . 774site-survey . . . . . . . . . . . . . . . . . . . . . . 774snmp-server . . . . . . .
OmniAccess Reference: AOS-W System Reference148 Part 031652-00 May 2005In the capture window, the absolute time stamps that are displayed corre-spond
Air Management 149Chapter 7Additional information TBC.
OmniAccess Reference: AOS-W System Reference150 Part 031652-00 May 2005
802.1x Client Setup 151CHAPTER 8802.1x Client SetupThis chapter describes how to configure your wireless client station for 802.1x authentication usin
OmniAccess Reference: AOS-W System Reference152 Part 031652-00 May 2005PEAP or TLS for Windows 2000Prepare the Operating SystemInstall Windows 2000 wi
802.1x Client Setup 153Chapter 8If necessary, enable the Wireless Configuration service for auto-matic startup.If the Wireless Configuration item in t
OmniAccess Reference: AOS-W System Reference154 Part 031652-00 May 2005Select the Wireless Network Connection properties.From the Windows Start menu,
802.1x Client Setup 155Chapter 8Configure the Association attributes.In the Wireless network properties window, select the Association tab and set the
OmniAccess Reference: AOS-W System Reference156 Part 031652-00 May 2005Configure the Authentication attributes.NOTE—To configure settings on the Authe
802.1x Client Setup 157Chapter 8Configure the Authentication Properties.Click on the Properties button. Depending on the authentication type selected,
OmniAccess Reference: AOS-W System Referencexviii Part 031652-00 May 2005Local Database Commands . . . . . . . . . . . . . . . 853VPN Commands . . .
OmniAccess Reference: AOS-W System Reference158 Part 031652-00 May 2005For EAP-PEAP authentication, set the following:z Enable Fast Reconnect: This en
802.1x Client Setup 159Chapter 8The wireless client station adapter should now use EAP authentication and the following type of message appears:This m
OmniAccess Reference: AOS-W System Reference160 Part 031652-00 May 2005PEAP or TLS for Windows XPNOTE—If using Cisco-PEAP with Windows XP, see the ins
802.1x Client Setup 161Chapter 8Select the Access Point for association.zIn the Network Connections window, right-click on the Wireless Network Connec
OmniAccess Reference: AOS-W System Reference162 Part 031652-00 May 2005Cisco-PEAP for Windows XPPresently, only EAP-PEAP is supported with the Cisco A
802.1x Client Setup 163Chapter 8From the Start menu, select Control Panel | Administrative Tools | Services.In the Services window, locate and double-
OmniAccess Reference: AOS-W System Reference164 Part 031652-00 May 2005On the General properties tab, set the Startup type to Auto-matic.If necessary,
802.1x Client Setup 165Chapter 8Specify the System Parameters.On the System Parameters tab, specify the following:z Client Name: Specify the name of t
OmniAccess Reference: AOS-W System Reference166 Part 031652-00 May 2005Specify the Network Security parameters.On the Network Security tab, specify th
802.1x Client Setup 167Chapter 8Configure the Wireless Network ConnectionEnable the Wireless Network Connection.From the Windows Start menu, select Co
Preface xixPrefaceThis preface includes the following information:z An overview of the sections in this manualz A list of related documentation for fu
OmniAccess Reference: AOS-W System Reference168 Part 031652-00 May 2005Select the Access Point for association.zIn the Network Connections window, rig
802.1x Client Setup 169Chapter 8Configure the Association attributes.In the Wireless network properties window, select the Association tab and set the
OmniAccess Reference: AOS-W System Reference170 Part 031652-00 May 2005Configure the Authentication attributes.NOTE—To configure settings on the Authe
802.1x Client Setup 171Chapter 8Configure the Authentication Properties.On the Authentication tab, click on the Properties button and set the followin
OmniAccess Reference: AOS-W System Reference172 Part 031652-00 May 2005z Second Phase EAP Type: Select the Generic Token Card option and click on prop
802.1x Client Setup 173Chapter 8z Static Password:z OTP:For OTP, select either the Hardware Token or Software Token option. If you select Software Tok
OmniAccess Reference: AOS-W System Reference174 Part 031652-00 May 2005In some cases, the following type of message appears:This message indicates the
Basic Switch Configuration 175CHAPTER 9Basic Switch ConfigurationThis chapter explains how to configure the Alcatel Wireless LAN switch using the AOS-
OmniAccess Reference: AOS-W System Reference176 Part 031652-00 May 2005To set the switch role from the CLI, use the command masterip from configuratio
Basic Switch Configuration 177Chapter 9 ip address 10.1.1.1Mobility ConfigurationTo enable mobility, select the Enable Mobility checkbox.FIGURE
OmniAccess Reference: AOS-W System Referenceii Part 031652-00 May 2005CopyrightCopyright © 2005 Alcatel Internetworking, Inc. All rights reserved.Spec
OmniAccess Reference: AOS-W System Referencexx Part 031652-00 May 2005Related DocumentsThe following items are part of the complete documentation for
OmniAccess Reference: AOS-W System Reference178 Part 031652-00 May 2005FIGURE 9-4 VLAN ConfigurationTo enable mux ports in the CLI, enter commands in
Basic Switch Configuration 179Chapter 9navigate to Configuration > Switch > General and specify them in the MUX VLANs section. In the example be
OmniAccess Reference: AOS-W System Reference180 Part 031652-00 May 2005Setting the 802.11d Regulatory DomainThe 802.11d regulatory domain controls whi
Basic Switch Configuration 181Chapter 9FIGURE 9-8 NTP ConfigurationThe equivalent CLI configuration for the example above is:ntp server 172.16.1.25NO
OmniAccess Reference: AOS-W System Reference182 Part 031652-00 May 2005FIGURE 9-9 Port Selection OptionsPorts may be selected based on their administ
Basic Switch Configuration 183Chapter 9To select multiple ports from the CLI, enter commands in the form:interface range FastEthernet 2/12-23This will
OmniAccess Reference: AOS-W System Reference184 Part 031652-00 May 2005Port Mode – Sets the mode of the port with respect to VLAN tagging. If the port
Basic Switch Configuration 185Chapter 9VLAN 1 is the default VLAN. All ports are part of VLAN 1 until configured otherwise. VLAN 1 cannot be deleted.V
OmniAccess Reference: AOS-W System Reference186 Part 031652-00 May 2005FIGURE 9-13 Adding a New VLANThe equivalent CLI configuration for the example
Basic Switch Configuration 187Chapter 9FIGURE 9-14 TunnelsTo create a tunnel, click Add and define the tunnel.IP Route ConfigurationAlcatel AOS-W sup
Preface xxiContacting AlcatelWeb SiteTelephone Numbers<Arguments> In the command examples, italicized text within angle brackets represents item
OmniAccess Reference: AOS-W System Reference188 Part 031652-00 May 2005VRRP ConfigurationAOS-W 2.2 supports redundant switch configurations using Virt
Basic Switch Configuration 189Chapter 9Description – An optional description of the VRRP instance that can be used for administrator convenience.IP Ad
OmniAccess Reference: AOS-W System Reference190 Part 031652-00 May 2005The figure below shows a sample VRRP configuration. In this example, the switch
Basic Switch Configuration 191Chapter 92. Follow the rules of operation below.Rules of Operating a Virtual Switch1. When a single SC is present in the
OmniAccess Reference: AOS-W System Reference192 Part 031652-00 May 2005When the reset button is pushed on a SC, it will reset the SC and only the line
Basic Switch Configuration 193Chapter 9FIGURE 9-19 VLAN Pool ConfigurationA different DHCP pool must be created for each IP subnet for which DHCP ser
OmniAccess Reference: AOS-W System Reference194 Part 031652-00 May 2005ip dhcp pool vlan26-pool default-router 10.26.1.1 dns-server 192.168.1.10 domai
802.1x Configuration 195CHAPTER 10802.1x ConfigurationIntroductionThis chapter will explain the process of configuring the server for 802.1x and using
OmniAccess Reference: AOS-W System Reference196 Part 031652-00 May 2005Definitions and Common AbbreviationsAuthentication serverAn entity that provide
802.1x Configuration 197Chapter 10PEAP(Protected EAP) is an authentication protocol that uses TLS to enhance the security of other EAP authentication
OmniAccess Reference: AOS-W System Referencexxii Part 031652-00 May 2005
OmniAccess Reference: AOS-W System Reference198 Part 031652-00 May 2005NOTE—To configure an SSID to support 802.1x, set its opmode to dynamicWep or dy
802.1x Configuration 199Chapter 10Enter Configuration commands, one per line. End with CNTL Z.NOTE—The command reference for this action may be found
OmniAccess Reference: AOS-W System Reference200 Part 031652-00 May 2005Assigning a Server to 802.1x AuthenticationEach instance of a RADIUS server, as
802.1x Configuration 201Chapter 10Assigning Default RolesA role is a broad classification of users and is associated with a specific set of permission
OmniAccess Reference: AOS-W System Reference202 Part 031652-00 May 2005Specify any for the source, destination, and port parameters and permit for the
802.1x Configuration 203Chapter 10Verify that the authorization server and default roles were correctly assigned.Ty p e show aaa dot1x <Enter>
OmniAccess Reference: AOS-W System Reference204 Part 031652-00 May 2005Configuring the 802.1x State MachineDot1x CLI CommandsThis section describes th
802.1x Configuration 205Chapter 10Dot1x serverThe dot1x server commands are used for setting the back-end authentication server configuration.dot1x se
OmniAccess Reference: AOS-W System Reference206 Part 031652-00 May 2005dot1x timeout quiet-period <quiet period>The state machine enters a quiet
802.1x Configuration 207Chapter 10802.1x Show CommandsThis sections describes the show commands applicable to 802.1x.show dot1x configThe show dot1x c
1PartOverview1
OmniAccess Reference: AOS-W System Reference208 Part 031652-00 May 2005show dot1x ap-tableThe show dot1x ap-table command and its variants display inf
802.1x Configuration 209Chapter 10z User Namez Authentication Status (yes/no)z AP MACz Encryption Keyz Authorization Modez EAP typeshow dot1x supplica
OmniAccess Reference: AOS-W System Reference210 Part 031652-00 May 2005show aaa dot1xThe show aaa dot1x commands displays which servers are configured
802.1x Configuration 211Chapter 10Debug CommandsThe commands in this section are used for debugging the authentication module. Debugging is accomplish
OmniAccess Reference: AOS-W System Reference212 Part 031652-00 May 2005RF Deauthentication DebuggingUsing Alcatel Air Management features, Alcatel APs
802.1x Configuration 213Chapter 10certificate. The client’s certificate is then verified against the CA certificate of the authority which issued it (
OmniAccess Reference: AOS-W System Reference214 Part 031652-00 May 2005Obtaining A Certification Authority (CA) CertificateCA Certificates are obtaine
802.1x Configuration 215Chapter 10Select the Retrieve the CA Certificate or certificate revocation list option, then click Next. The following screen
OmniAccess Reference: AOS-W System Reference216 Part 031652-00 May 2005You may receive one or both of the following warnings. In either case click Ye
802.1x Configuration 217Chapter 10Obtaining a Server CertificateThe following steps will guide you through the process of obtaining and installing an
OmniAccess Reference: AOS-W System Reference2 Part 031652-00 May 2005
OmniAccess Reference: AOS-W System Reference218 Part 031652-00 May 2005Select the Request a certificate option, then click Next.The web page below sho
802.1x Configuration 219Chapter 10The following web page should appear in your browser window.
OmniAccess Reference: AOS-W System Reference220 Part 031652-00 May 2005Select the Submit a certificate request to this CA using a form option, then cl
802.1x Configuration 221Chapter 10The web page form below should appear in your browser window.Enter the following information in the Identity Informa
OmniAccess Reference: AOS-W System Reference222 Part 031652-00 May 2005Select Server Authentication Server Certificate under the Intended Purpose sect
802.1x Configuration 223Chapter 10The web page shown below should appear in your browser window.Click the Install this certificate button.You may see
OmniAccess Reference: AOS-W System Reference224 Part 031652-00 May 2005Obtaining a Client CertificateThe following steps will guide you through the pr
802.1x Configuration 225Chapter 10Select the Request a certificate option, then click Next.The web page below should appear in your browser window.Sel
OmniAccess Reference: AOS-W System Reference226 Part 031652-00 May 2005The following web page should appear in your browser window.
802.1x Configuration 227Chapter 10Select the Submit a certificate request to this CA using a form option, then click Next.You may receive one of the
Overview 3CHAPTER 1OverviewThe AOS-W 2.2 Interface Reference is organized by product feature for the Alcatel Wireless LAN switches and access points.
OmniAccess Reference: AOS-W System Reference228 Part 031652-00 May 2005The web page form below should appear in your browser window.Enter the followin
802.1x Configuration 229Chapter 10Select Server Authentication Server Certificate under the Intended Purpose section.Set the following options under t
OmniAccess Reference: AOS-W System Reference230 Part 031652-00 May 2005The web page shown below should appear in your browser window.Click the Install
802.1x Configuration 231Chapter 10Configuration using Pocket PC Embedded Supplicant Export Trusted Certification Authority The first step in enabling
OmniAccess Reference: AOS-W System Reference232 Part 031652-00 May 2005To install the certificate authority, simply tap on the certificate file. The s
802.1x Configuration 233Chapter 10Configuration of the Funk Odyssey client can be performed either on the host PC or on the Pocket PC device. All perm
OmniAccess Reference: AOS-W System Reference234 Part 031652-00 May 2005The second and more secure method specifies the domain name of the authenticati
802.1x Configuration 235Chapter 10Captive Portal Certificates with Intermediate CAsTo install certificates for captive portal installations that have
OmniAccess Reference: AOS-W System Reference236 Part 031652-00 May 2005
802.1x Solution Cookbook 237CHAPTER 11802.1x Solution CookbookThis chapter describes the theory, configuration, and operation of a wireless network ba
OmniAccess Reference: AOS-W System Reference4 Part 031652-00 May 2005Enhanced Location ServicesAOS-W 2.2 adds more precise position tracking of wirele
OmniAccess Reference: AOS-W System Reference238 Part 031652-00 May 2005802.1x authentication based on PEAP is used to provide both computer and user a
802.1x Solution Cookbook 239Chapter 11a The laptop searches for the wireless ESSID “Wireless LAN-01”, chooses the AP with the best signal strength, an
OmniAccess Reference: AOS-W System Reference240 Part 031652-00 May 2005The IAS server has also been configured to transmit an RADIUS attribute called
802.1x Solution Cookbook 241Chapter 11a The laptop will transmit an EAPOL-Start message to the Alcatel switch. The Alcatel switch will then proceed wi
OmniAccess Reference: AOS-W System Reference242 Part 031652-00 May 2005authentication takes place when a user is not logged in to the laptop, the comp
802.1x Solution Cookbook 243Chapter 11netdestination district-network network 10.0.0.0 255.0.0.0 network 172.16.0.0 255.255.0.0 Student Policy The pol
OmniAccess Reference: AOS-W System Reference244 Part 031652-00 May 2005Printer Policy The following policy is used for the printer role. It restricts
802.1x Solution Cookbook 245Chapter 11user-role computer session-acl allowall ! user-role guest session-acl guest bandwidth-contract guest-1M Authenti
OmniAccess Reference: AOS-W System Reference246 Part 031652-00 May 2005802.1x Configuration The following statements enable 802.1x authentication. It
802.1x Solution Cookbook 247Chapter 11! interface vlan 60 ip address 10.1.60.1 255.255.255.0 ip helper-address 10.1.1.25 ! interface vlan 61 ip addres
Overview 5Chapter 1provides the ability to enable local probe responses for remotely connected APs. This feature may be configured under the Wireless
OmniAccess Reference: AOS-W System Reference248 Part 031652-00 May 2005staticWep deny-bcast enable virtual-ap “Guest” vlan-id 63 opmode opensystem den
802.1x Solution Cookbook 249Chapter 11Windows Group Membership Configuration The authentication policy configured in IAS depends on the group membersh
OmniAccess Reference: AOS-W System Reference250 Part 031652-00 May 2005z The encryption type is WEP z Open authentication should be used (this refers
802.1x Solution Cookbook 251Chapter 11Microsoft Internet Authentication Server Configuration Microsoft Internet Authentication Server (IAS) provides a
OmniAccess Reference: AOS-W System Reference252 Part 031652-00 May 2005z The Wireless-Student policy matches the “Student” group. z The Wireless-Facul
802.1x Solution Cookbook 253Chapter 11Advanced Attributes One of the principles in this network is that the Alcatel switch will restrict network acces
OmniAccess Reference: AOS-W System Reference254 Part 031652-00 May 2005z Specifies the EAP type as PEAP z Clients will not attempt to authenticate as
802.1x Solution Cookbook 255Chapter 11In the management console, select File > Add/Remove Snap-in. Select the Certificates snap-in. Typically, a tr
OmniAccess Reference: AOS-W System Reference256 Part 031652-00 May 2005If the appropriate ESSID is not already shown in the list, add it by selecting
Switch Management Configuration 257CHAPTER 12Switch Management ConfigurationThis Chapter discusses how to use the various management features of Alcat
OmniAccess Reference: AOS-W System Reference6 Part 031652-00 May 2005If no DNS information is available, the AP will begin using Alcatel Discovery Pro
OmniAccess Reference: AOS-W System Reference258 Part 031652-00 May 2005Navigate to the Configuration > Management > SNMP page. Add system inform
Switch Management Configuration 259Chapter 12Click Add in the Trap Receivers section of the SNMP page.The Add Host page appears on the screen.Enter th
OmniAccess Reference: AOS-W System Reference260 Part 031652-00 May 2005NOTE—The console will revert to the immediate (non-privileged mode) when you ch
Switch Management Configuration 261Chapter 12Configuring Administrative Access Using Web UIAOS-W allows different levels of access for administrative
OmniAccess Reference: AOS-W System Reference262 Part 031652-00 May 2005Navigate to the Configuration > Management > Access Control page.You can
Switch Management Configuration 263Chapter 12Adding and Editing Management UsersAdding and editing users is accomplished in the Management Users secti
OmniAccess Reference: AOS-W System Reference264 Part 031652-00 May 2005Adding and Editing Management RolesAdd or edit Management Role by clicking Add
Switch Management Configuration 265Chapter 12Adding and Changing Administrative Access Using the CLIViewing Management UsersYou may view currently con
OmniAccess Reference: AOS-W System Reference266 Part 031652-00 May 2005Viewing Management RolesYou may view currently configured management roles and
Switch Management Configuration 267Chapter 12Adding Auth ServersLoggingThe logging feature in Alcatel AOS-W allows permanent system logs to be stored
Overview 7Chapter 1 option serverip 10.1.1.10; } range 10.200.10.200 10.200.10.252;}To configure Microsoft’s DHCP server for this feature:1
OmniAccess Reference: AOS-W System Reference268 Part 031652-00 May 2005Configuring Logging Using Web UIBegin configuring logging servers by navigating
Switch Management Configuration 269Chapter 12Enter the address of a logging server and click the Add button next to the text field.Select a check box
OmniAccess Reference: AOS-W System Reference270 Part 031652-00 May 2005Configuring Logging Using The CLIAdding A Logging ServerAdd a logging server us
Switch Management Configuration 271Chapter 12Viewing Current Logging LevelsView the current logging levels using the show logging level command from t
OmniAccess Reference: AOS-W System Reference272 Part 031652-00 May 2005
Wireless LAN Configuration 273CHAPTER 13Wireless LAN ConfigurationThis chapter discussed how to configure all the standard 802.11 features of an Alcat
OmniAccess Reference: AOS-W System Reference274 Part 031652-00 May 2005FIGURE 13-1 SSID Configuration The first SSID configured is primary and can be
Wireless LAN Configuration 275Chapter 13Radio Type – SSIDs may appear on only 802.11a radios, only 802.11b/g radios or on both types of radios.SSID De
OmniAccess Reference: AOS-W System Reference276 Part 031652-00 May 2005The 802.1x framework also allows the encryption key to be rotated at specific i
Wireless LAN Configuration 277Chapter 13The equivalent CLI configuration to add the SSID shown above is:ap location 0.0.0 phy-type a virtual-ap "
iiiPreface xixAn Overview of this Manual . . . . . . . . . . . . . . . xixRelated Documents . . . . . . . . . . . . . . . . . . . . xxText Conven
OmniAccess Reference: AOS-W System Reference8 Part 031652-00 May 20052. From a command prompt, enter:c:\>netshnetsh>dhcpnetsh dhcp>server \\&
OmniAccess Reference: AOS-W System Reference278 Part 031652-00 May 2005FIGURE 13-4 TKIP Configuration If PSK TKIP is selected, fill in the pre-shared
Wireless LAN Configuration 279Chapter 13NOTE—AOS-W versions 2.4.0.0 and later support different staticWep and stat-icTkip keys per SSID. In earliers r
OmniAccess Reference: AOS-W System Reference280 Part 031652-00 May 2005FIGURE 13-7 802.11b and g Radio ParametersFIGURE 13-8 802.11a Radio Parameter
Wireless LAN Configuration 281Chapter 13NOTE—Note: These parameters affect all APs in the network, unless a more specific configuration applies. Confi
OmniAccess Reference: AOS-W System Reference282 Part 031652-00 May 2005Default Channel – Sets the default channel on which the AP will operate, unless
Wireless LAN Configuration 283Chapter 13deny Deny wireless access according to timerange argumentdeny-bcast enable to
OmniAccess Reference: AOS-W System Reference284 Part 031652-00 May 2005telnet Enable or disable telnet to the APtx-power
Wireless LAN Configuration 285Chapter 13configuration section. To view or modify location-based configuration, navigate to Configuration > Wireless
OmniAccess Reference: AOS-W System Reference286 Part 031652-00 May 2005FIGURE 13-10 Location 2.0.0 ConfigurationAssuming that the same change is made
Wireless LAN Configuration 287Chapter 13FIGURE 13-11 Advanced Wireless LAN ConfigurationClick Add to display the four categories of advanced Wireless
Management Options 9CHAPTER 2Management OptionsAOS-W provides a number of methods for managing your Alcatel Wireless LAN Switch.Command-Line Interface
OmniAccess Reference: AOS-W System Reference288 Part 031652-00 May 2005FIGURE 13-12 General Wireless LAN Settings
Radio Resource Management 289CHAPTER 14Radio Resource ManagementThis chapter discusses the process of configuring the Radio Resource Management featur
OmniAccess Reference: AOS-W System Reference290 Part 031652-00 May 2005process allows the Alcatel switch to build an RF-based map of the network topol
Radio Resource Management 291Chapter 14FIGURE 14-3 Calibration Results The equivalent CLI command to perform calibration is “site-survey calibrate”.O
OmniAccess Reference: AOS-W System Reference292 Part 031652-00 May 2005Maximum neighbors to participate in self-healing – The maximum number of neighb
Radio Resource Management 293Chapter 14FIGURE 14-5 Load Balancing Configuration Available parameters are:Enable Load Balancing – Enables or disables
OmniAccess Reference: AOS-W System Reference294 Part 031652-00 May 2005The equivalent CLI configuration for the above example is:ap-policy ap-load-bal
Radio Resource Management 295Chapter 14DoS Client Block Time – Specifies the number of seconds a client will be quarantined from the network after a d
OmniAccess Reference: AOS-W System Reference296 Part 031652-00 May 2005FIGURE 14-7 Coverage Hole Detection Other than enabling or disabling the featu
Radio Resource Management 297Chapter 14stm poor-rssi-threshold 10stm hole-detection-interval 120stm good-sta-ageout 30stm idle-sta-ageout 90Interferen
OmniAccess Reference: AOS-W System Reference10 Part 031652-00 May 2005z Configure and manage wireless intrusion prevention and performance poli-ciesz
OmniAccess Reference: AOS-W System Reference298 Part 031652-00 May 2005wms global-policy detect-interference disable global-policy interference-inc-th
Radio Resource Management 299Chapter 14FIGURE 14-9 Event Threshold ConfigurationTo disable detection for any parameter, set the value to 0. Available
OmniAccess Reference: AOS-W System Reference300 Part 031652-00 May 2005Frame Error Rate High Watermark – If the frame error rate, as a percentage of t
Radio Resource Management 301Chapter 14Frame Retry Rate Low Watermark – After a frame retry rate exceeded condition exists, the condition will persist
OmniAccess Reference: AOS-W System Reference302 Part 031652-00 May 2005FIGURE 14-10 RF Management Advanced ParametersThe advanced parameters are:AP A
Radio Resource Management 303Chapter 14Station Scan Inactivity– TBC.Enable Statistics Update in DB– TBC:auto-rra scan-interval 10auto-rra scan-time 11
OmniAccess Reference: AOS-W System Reference304 Part 031652-00 May 2005
Intrusion Detection Configuration 305CHAPTER 15Intrusion Detection ConfigurationThis chapter discusses the various kinds of intrusion and Wireless LAN
OmniAccess Reference: AOS-W System Reference306 Part 031652-00 May 2005Network discovery is a normal part of 802.11, and allows client devices to disc
Intrusion Detection Configuration 307Chapter 15Rogue APRogue APs represent perhaps the largest threat to enterprise network security because they bypa
Management Options 11Chapter 2z Page Tree–Each tool has its own information or configuration pages and sub-pages.The page tree lists all of the pages
OmniAccess Reference: AOS-W System Reference308 Part 031652-00 May 2005Mark All New APs as Valid – When installing an Alcatel switch in an environment
Intrusion Detection Configuration 309Chapter 15FIGURE 15-2 Rate Analysis Configuration Configuration is divided into two sections: Channel thresholds
OmniAccess Reference: AOS-W System Reference310 Part 031652-00 May 2005 ids-policy rate-frame-type-param assoc channel-quiet-time 900 ids-policy rate-
Intrusion Detection Configuration 311Chapter 15To configure detection of FakeAP, navigate to Configuration > Wireless LAN Intrusion Detection >
OmniAccess Reference: AOS-W System Reference312 Part 031652-00 May 2005Such an attack also enables other attacks that can learn a user’s authenticatio
Intrusion Detection Configuration 313Chapter 15FIGURE 15-5 Detect Station Disconnection Configuration parameters are:Enable Disconnect Station Analys
OmniAccess Reference: AOS-W System Reference314 Part 031652-00 May 2005FIGURE 15-7 EAP Handshake Analysis Configuration parameters are:Enable EAP Han
Intrusion Detection Configuration 315Chapter 15FIGURE 15-8 Sequence Number AnalysisConfiguration parameters are:Enable Sequence Number Discrepancy Ch
OmniAccess Reference: AOS-W System Reference316 Part 031652-00 May 2005FIGURE 15-9 AP Impersonation ProtectionConfiguration parameters are:Enable AP
Intrusion Detection Configuration 317Chapter 15FIGURE 15-10 Signature Analysis Configuration parameters are:Enable Signature Analysis – Enables and d
OmniAccess Reference: AOS-W System Reference12 Part 031652-00 May 2005z Check Boxes–Represented as small squares in front of the item text. These fiel
OmniAccess Reference: AOS-W System Reference318 Part 031652-00 May 2005Null-Probe-Response - An attack with the potential to crash or lock up the firm
Intrusion Detection Configuration 319Chapter 15Adding New SignaturesTo add new signatures, click the Add button. The Add IDS Signature screen is shown
OmniAccess Reference: AOS-W System Reference320 Part 031652-00 May 2005Wireless LAN PoliciesAd-hoc Network ProtectionAs far as network administrators
Intrusion Detection Configuration 321Chapter 15Wireless Bridge DetectionWireless bridges are normally used to connect multiple buildings together. How
OmniAccess Reference: AOS-W System Reference322 Part 031652-00 May 2005policy is useful in blocking access to that AP until the configuration can be f
Intrusion Detection Configuration 323Chapter 15Enforce WEP Encryption for all Traffic – Any valid AP not using WEP will be flagged as misconfigured.En
OmniAccess Reference: AOS-W System Reference324 Part 031652-00 May 2005configure detection of weak WEP implementations, navigate to Configuration >
Intrusion Detection Configuration 325Chapter 15FIGURE 15-16 Multi-Tenancy ConfigurationAvailable parameters are:Disable APs Violating Enterprise SSID
OmniAccess Reference: AOS-W System Reference326 Part 031652-00 May 2005FIGURE 15-17 MAC OUI CheckingAvailable parameters are:Enable MAC OUI Check – E
Authentication Server Configuration 327CHAPTER 16Authentication Server ConfigurationIntroductionStrong authentication methods use authentication serve
Command Line Basics 13CHAPTER 3Command Line BasicsThe Command Line Interface (CLI) is the most direct and comprehensive method for managing the Alcate
OmniAccess Reference: AOS-W System Reference328 Part 031652-00 May 2005You may configure 2 general parameters here, they are:Configuring RADIUS Server
Authentication Server Configuration 329Chapter 16Add a new server by clicking the Add button.The Add RADIUS Server page appears. Enter information abo
OmniAccess Reference: AOS-W System Reference330 Part 031652-00 May 2005Server RulesServer rules may be defined for each server to determine role and V
Authentication Server Configuration 331Chapter 16Add a rule by clicking the add button.The following parameters may be configured for server rules usi
OmniAccess Reference: AOS-W System Reference332 Part 031652-00 May 2005where:Attribute Name TBCAttribute ID TBCAttribute Type TBCVendor Name TBCVendor
Authentication Server Configuration 333Chapter 16Configuring LDAP Servers with Web UIAlcatel switches allow for authentication using LDAP servers. Con
OmniAccess Reference: AOS-W System Reference334 Part 031652-00 May 2005Adding a Server RuleTo add a server rule, click Add on the Add LDAP Server page
Authentication Server Configuration 335Chapter 16where:Rule type is Role Assignment or Vlan Assignment.TBCAttribute is TBCCondition is TBCValue is TBC
OmniAccess Reference: AOS-W System Reference336 Part 031652-00 May 2005Configuring the Internal Authentication Database with Web UIAlcatel AOS-W suppo
Authentication Server Configuration 337Chapter 16Configuring RADIUS Accounting with Web UIAlcatel AOS-W supports RADIUS accounting, tracking login and
OmniAccess Reference: AOS-W System Reference14 Part 031652-00 May 2005Local or Remote TelnetIf properly set up, the CLI can be accessed locally or rem
OmniAccess Reference: AOS-W System Reference338 Part 031652-00 May 2005Configuring 802.1x Authentication with Web UI802.1x authentication is designed
Authentication Server Configuration 339Chapter 16Click the Enable Authentication checkbox.Select a default role from the pull-down menuAdd an authenti
OmniAccess Reference: AOS-W System Reference340 Part 031652-00 May 2005Configuring VPN Authentication with Web UIAlcatel switches provide full VPN ter
Authentication Server Configuration 341Chapter 16Configuring Captive Portal Authentication with Web UIAlcatel switches provide the ability to allow wi
OmniAccess Reference: AOS-W System Reference342 Part 031652-00 May 2005Default Role Use this pull-down menu to select the default role for the client
Authentication Server Configuration 343Chapter 16Authentication FailureThreshold for Station BlacklistingSpecifies the number of time a station may fa
OmniAccess Reference: AOS-W System Reference344 Part 031652-00 May 2005Configuring MAC Address Role Mapping with Web UIMAC Address role mapping provid
Authentication Server Configuration 345Chapter 16Configuring Stateful 802.1x for Third Party Access PointsThis feature allows the switch to intercept
OmniAccess Reference: AOS-W System Reference346 Part 031652-00 May 2005Role MappingFrom the Web UI, you can perform role mapping based on SSID and enc
Authentication Server Configuration 347Chapter 16Adding a Role MapClick Add.Select a match condition from the Condition pull-down menu box.Enter a val
Command Line Basics 15Chapter 3Using Telnet to ConnectUse a Telnet client on your management workstation to connect to the Alcatel Wireless LAN Switch
OmniAccess Reference: AOS-W System Reference348 Part 031652-00 May 2005Adding a ConditionTBCwhere:Rule Type–specifies what rule will apply such as on
Authentication Server Configuration 349Chapter 16Configuring General AAA Settings Using the CLIConfigure the general AAA settings using the aaa timers
OmniAccess Reference: AOS-W System Reference350 Part 031652-00 May 2005The configured RADIUS server settings may be viewed using the show aaa radius-s
Authentication Server Configuration 351Chapter 16Configuring LDAP Servers Using the CLIConfigure LDAP servers using the aaa ldap-server command from t
OmniAccess Reference: AOS-W System Reference352 Part 031652-00 May 2005Enter the config-ldapserver submode by executing the aaa ldap-server command wi
Authentication Server Configuration 353Chapter 16Set the mode, enable or disable LDAP.View the LDAP server settings using the show aaa ldap-server <
OmniAccess Reference: AOS-W System Reference354 Part 031652-00 May 2005Configuring the Internal Authentication Database Using the CLIAn internal authe
Authentication Server Configuration 355Chapter 16Assign an accounting server.Configuring 802.1x Authentication Using the CLI802.1x configuration is ac
OmniAccess Reference: AOS-W System Reference356 Part 031652-00 May 2005Enable or disable re-authentication. Use the “no” form of the command to disabl
Authentication Server Configuration 357Chapter 16You may view the 802.1x configuration settings using the show aaa dot1x command from the CLI.(Alcatel
OmniAccess Reference: AOS-W System Reference16 Part 031652-00 May 2005z Privileged ModeAll configuration and management functions are available in pri
OmniAccess Reference: AOS-W System Reference358 Part 031652-00 May 2005Adding 802.1x Authentication ServersAdd an existing configured 802.1x authentic
Authentication Server Configuration 359Chapter 16Configure Captive Portal using the aaa captive-portal commands from the CLI.Set the default role. Thi
OmniAccess Reference: AOS-W System Reference360 Part 031652-00 May 2005Configuring MAC Address Role Mapping Using the CLIMAC Address Role Mapping is a
Authentication Server Configuration 361Chapter 16Specify the authentication server.AP/Server Configuration for Stateful 802.1xWhen stateful 802.1x aut
OmniAccess Reference: AOS-W System Reference362 Part 031652-00 May 2005Notes on Advanced AAA FeaturesThe Advanced AAA feature pack for AOS-W unlocks a
Authentication Server Configuration 363Chapter 16The AOS-W SolutionAll the problems outlined above are solved using the Advanced AAA feature pack for
OmniAccess Reference: AOS-W System Reference364 Part 031652-00 May 2005In an enterprise network, this capability can be used to authenticate users fro
Authentication Server Configuration 365Chapter 16number of different services to be provided. All users can connect to the network using the same met
OmniAccess Reference: AOS-W System Reference366 Part 031652-00 May 2005
IAS Server Configuration 367CHAPTER 17IAS Server ConfigurationThis chapter describes how to configure your IAS server for Extensible Authorization Pro
Command Line Basics 17Chapter 3z Show CommandsThe show commands list information about the switch configuration and performance and are invaluable for
OmniAccess Reference: AOS-W System Reference368 Part 031652-00 May 2005Starting the IAS ServerClick Start on task bar, click Settings, click Administr
IAS Server Configuration 369Chapter 17Change the Startup type to Automatic.Creating NAS Client EntriesOpen the IAS Administration Tool3
OmniAccess Reference: AOS-W System Reference370 Part 031652-00 May 2005Click Start on the task bar, click Programs, then Administrative Tools, and the
IAS Server Configuration 371Chapter 17Select New Client. The Add Client Dialog window appears.Enter a meaningful name in the Friendly name box.Use the
OmniAccess Reference: AOS-W System Reference372 Part 031652-00 May 2005Enter a word in the Shared secret text box, then re-enter the same word in the
IAS Server Configuration 373Chapter 17Remote access policies are created using the IAS Administration Tool. If the IAS Administration Tool is not alre
OmniAccess Reference: AOS-W System Reference374 Part 031652-00 May 2005Click Next. The Select Attribute dialog window appears.Click the Add button. Th
IAS Server Configuration 375Chapter 17When finished adding conditions, click the Next button on Add Remote Access Policy dialog.Select the Grant remot
OmniAccess Reference: AOS-W System Reference376 Part 031652-00 May 2005Click the Edit Profile button. The Edit Dial-In Profile window appears. Click o
IAS Server Configuration 377Chapter 17Click Start, then Run, then type mmc and press Enter. The Console window appears.Click Console and select Add/Re
OmniAccess Reference: AOS-W System Referenceiv Part 031652-00 May 2005Part 2Design and Planning . . . . . . . . . . . . 23Chapter 4RF Design . . . .
OmniAccess Reference: AOS-W System Reference18 Part 031652-00 May 2005ShortcutsCommand CompletionTo make command input easier, you can usually abbrevi
OmniAccess Reference: AOS-W System Reference378 Part 031652-00 May 2005Select the Active Directory User and Computer item in the Add Standalone Snap-i
IAS Server Configuration 379Chapter 17Type the user’s name information in the appropriate text fields., then click Next.Enter the password in the Pass
OmniAccess Reference: AOS-W System Reference380 Part 031652-00 May 2005Configuring SBRTBCConfiguring FunkTBC
Firewall Configuration 381CHAPTER 18Firewall ConfigurationSetting Policies Using Web UIAliasesAliases are a convenient way to associate a human unders
OmniAccess Reference: AOS-W System Reference382 Part 031652-00 May 2005Navigate to the Configuration > Security > Advanced > Services page.Ad
Firewall Configuration 383Chapter 18Enter a name in the Service Name text field.Check the appropriate Protocol radio button.Enter the Starting Port.En
OmniAccess Reference: AOS-W System Reference384 Part 031652-00 May 2005You may add, delete, or modify source and destination aliases on this page.Alca
Firewall Configuration 385Chapter 18Click Add to expand the page and expose the Add Rule section, near the bottom.Enter a name for the new destination
OmniAccess Reference: AOS-W System Reference386 Part 031652-00 May 2005Rules are organized in top-down lists where the first rule applied to the traff
Firewall Configuration 387Chapter 18The Source and Destination elements of a rule have the same 5 options. Those options are:The Service element of a
Command Line Basics 19Chapter 3List Matching CommandsWhen typed at the end of a possible command or abbreviation, the question mark lists the commands
OmniAccess Reference: AOS-W System Reference388 Part 031652-00 May 2005Add a policy by clicking Add, the Add New Policy page appears. The Add New Poli
Firewall Configuration 389Chapter 18Navigate to the Configuration > Switch > Port page. Select the port to which you wish to apply a policy, the
OmniAccess Reference: AOS-W System Reference390 Part 031652-00 May 2005Defining Roles Using Web UIRole DesignA role is assigned to a user when they co
Firewall Configuration 391Chapter 18Click Add to begin adding a new role to the list. The Add Role page appears.
OmniAccess Reference: AOS-W System Reference392 Part 031652-00 May 2005Adding Firewall PoliciesAdd firewall policies, begin by clicking the Add button
Firewall Configuration 393Chapter 18Specify an Existing PolicySelect the Choose from Configured Policies radio box.Specify a particular AP (if you wis
OmniAccess Reference: AOS-W System Reference394 Part 031652-00 May 2005additional options.Setting Policies Using the CLIThis portion of the chapter de
Firewall Configuration 395Chapter 18You may define a service alias by giving it a name, then choosing to specify one of three options:.Define the serv
OmniAccess Reference: AOS-W System Reference396 Part 031652-00 May 2005Defining Source and Destination AliasesDefine a source/destination alias and en
Firewall Configuration 397Chapter 18Enter rules in the order you wish them to be applied.If you wish to change the position of a rule in the list, use
OmniAccess Reference: AOS-W System Reference20 Part 031652-00 May 2005Command Line EditingThe command line editing feature allows you to make correcti
OmniAccess Reference: AOS-W System Reference398 Part 031652-00 May 2005Assign a policy to a the port used when entering the config-if mode.Defining Ro
Firewall Configuration 399Chapter 18Extended ACLsCreate extended ACLs using the extended option of the access-list command.MAC ACLsCreate MAC ACLs usi
OmniAccess Reference: AOS-W System Reference400 Part 031652-00 May 2005
Captive Portal Setup 401CHAPTER 19Captive Portal SetupOverviewThe following outline lists the steps used to configure captive portal authentication. E
OmniAccess Reference: AOS-W System Reference402 Part 031652-00 May 2005Add Users to the DatabaseAuthentication can be provided using one of the follow
Captive Portal Setup 403Chapter 19Configure RADIUS Server InformationIf using a Wireless LAN switch internal server, skip to the next section.Otherwis
OmniAccess Reference: AOS-W System Reference404 Part 031652-00 May 2005Use the no prefix to remove the server information from the database. For examp
Captive Portal Setup 405Chapter 19Customize the Logon RoleThe logon role is intended only to allow clients to access the captive portal logon page. Ty
OmniAccess Reference: AOS-W System Reference406 Part 031652-00 May 2005Modify the Captive Portal ACLA default captiveportal ACL is already configured
Captive Portal Setup 407Chapter 19Modify the Logon RoleThe logon role should have only the control and captive portal ACLs assigned. ACLs that allow o
Command Line Basics 21Chapter 3z Pipe | —denotes a two or more parameters, separated one from the other by the | symbol.For example:crypto ipsec tran
OmniAccess Reference: AOS-W System Reference408 Part 031652-00 May 2005Allow Guest AccessBy default, guest access is disabled. To allow guest access,
Captive Portal Setup 409Chapter 19In the example above, a destination alias is created that represents all IP addresses except the internal network (b
OmniAccess Reference: AOS-W System Reference410 Part 031652-00 May 2005Configuring Role DerivationThe simplest option for role derivation is to config
Captive Portal Setup 411Chapter 19For more information on how role derivation works, refer to “Setting Access Rights” on page 419.Import a Server Cert
OmniAccess Reference: AOS-W System Reference412 Part 031652-00 May 2005Log in using the admin accountWhen successful, the following page appears:FIGUR
Captive Portal Setup 413Chapter 19Customize the Login ScreenIf desired, the background image shown on the captive portal login screen can be replaced
OmniAccess Reference: AOS-W System Reference414 Part 031652-00 May 2005Sample ConfigurationListed below are the commands relevant to the captive porta
Captive Portal Setup 415Chapter 19user-role ap session-acl nonoc session-acl noilabsexitaaa captive-portal default-role nocaaa captive-portal auth-ser
OmniAccess Reference: AOS-W System Reference416 Part 031652-00 May 2005show rights <role-name>This command details the access rights associated
Captive Portal Setup 417Chapter 19show user-tableThis command shows all the users currently known to the system:The meaning for the various columns is
OmniAccess Reference: AOS-W System Reference22 Part 031652-00 May 2005
OmniAccess Reference: AOS-W System Reference418 Part 031652-00 May 2005
Setting Access Rights 419CHAPTER 20Setting Access RightsThis chapter will describe how to set access rights on the OmniAccess 6000 switch using the AO
OmniAccess Reference: AOS-W System Reference420 Part 031652-00 May 2005Defining Alias’Defining Service Alias’Alias’ are useful when creating filters,
Setting Access Rights 421Chapter 20Creating Session ACLs and RolesCreating A Session ACL for LogonA session ACL must first be created for the Logon ro
OmniAccess Reference: AOS-W System Reference422 Part 031652-00 May 2005Role DerivationThe simplest way to assign a role is to create a default role fo
Setting Access Rights 423Chapter 20The following flow illustrates how roles are derived.FIGURE 20-1 Role Derivation Flow Chart
OmniAccess Reference: AOS-W System Reference424 Part 031652-00 May 2005Show CommandsThe Show Commands associated with user rights are:z show rightsz s
Access Point Setup 425CHAPTER 21Access Point SetupThis chapter covers the following topics for the Alcatel Wireless Access Point (AP):z Overview of th
OmniAccess Reference: AOS-W System Reference426 Part 031652-00 May 2005System OverviewComponentsThe Alcatel Wireless LAN solution consists of the thre
Access Point Setup 427Chapter 21APs with a direct connection to the Wireless LAN switch can also utilize optional Serial and Power Over Ethernet (SPOE
23PartDesign and Planning2
OmniAccess Reference: AOS-W System Reference428 Part 031652-00 May 2005AP ProvisioningThere are several methods for setting up and configuring Alcatel
Access Point Setup 429Chapter 21Simplified AP ProvisioningThis is a streamlined example of the AP Programming Mode. This procedure represents the most
OmniAccess Reference: AOS-W System Reference430 Part 031652-00 May 2005Once the settings are correct, push the configuration to the APs.Disable the AP
Access Point Setup 431Chapter 21Connect the Alcatel APs that require configuration to one of the specified AP programming ports on the switch.NOTE—Alt
OmniAccess Reference: AOS-W System Reference432 Part 031652-00 May 2005z Disconnect and reconnect the AP from the switch port. If the AP list had prev
Access Point Setup 433Chapter 21My network uses direct IP addresses instead of DNS.If using direct IP addresses in your network, use the following com
OmniAccess Reference: AOS-W System Reference434 Part 031652-00 May 2005If you prefer to manually generate the location data, record the location you s
Access Point Setup 435Chapter 21Push the configuration to the APs.Depending on how specific your AP configuration must be applies, use one of the foll
OmniAccess Reference: AOS-W System Reference436 Part 031652-00 May 2005If no other APs are to be configured, disable the AP program-ming mode:This wil
Access Point Setup 437Chapter 21If desired, you can reset a deployed AP to its factory default set-tings:where AP index is the AP’s entry in the list
OmniAccess Reference: AOS-W System Reference24 Part 031652-00 May 2005
OmniAccess Reference: AOS-W System Reference438 Part 031652-00 May 2005Proceed to Step 3 on page 439.If using Telnet to connect to the AP remotely, ac
Access Point Setup 439Chapter 21Interrupt the AP boot process.Depending on how far the AP boot has booted, use one of the following lettered steps:If
OmniAccess Reference: AOS-W System Reference440 Part 031652-00 May 2005If the AP has completed booting.If no key is pressed before the autoboot timer
Access Point Setup 441Chapter 21Initial ConfigurationThe Alcatel AP requires some initial configuration before it will operate. All direct configurati
OmniAccess Reference: AOS-W System Reference442 Part 031652-00 May 2005Specify host information, if necessary.In order to provide centralized manageme
Access Point Setup 443Chapter 21NOTE—If the servername environment variable is configured in this scenario, it will be ignored.Specify an IP address,
OmniAccess Reference: AOS-W System Reference444 Part 031652-00 May 2005Advanced AP ConfigurationThe following sections cover the following:z How to ac
Access Point Setup 445Chapter 21APBoot Environment VariablesThe following environment variables can be configured using the setenv command and listed
OmniAccess Reference: AOS-W System Reference446 Part 031652-00 May 2005The following environmental variables should be kept at their default values un
Access Point Setup 447Chapter 21AP Configuration ExamplesFactory Default ValuesBy default, the environmental variables are as follows:NOTE—Variables n
RF Design 25CHAPTER 4RF DesignThe Alcatel RF Plan ToolRF Plan is a three-dimensional wireless deployment modeling tool that enables Network Administra
OmniAccess Reference: AOS-W System Reference448 Part 031652-00 May 2005z The AP location is set to -1.-1.-1 (unconfigured) and uses the default loca-t
Access Point Setup 449Chapter 21When booted normally (without entering APBoot mode), the AP will use the new settings and the AP console will display
OmniAccess Reference: AOS-W System Reference450 Part 031652-00 May 2005If DNS is not used or if you need to assign different TFTP servers for the soft
Access Point Setup 451Chapter 21Set AP with Specific LocationThe location variable can be used to specify where the AP will be permanently installed.
OmniAccess Reference: AOS-W System Reference452 Part 031652-00 May 2005GRE TunnelsRegardless of the network topology between the AP and the Wireless L
Access Point Setup 453Chapter 21The value of lms_address is the Wireless LAN switch tunnel end point in use by AP.Wireless Client IP AddressThe wirele
OmniAccess Reference: AOS-W System Reference454 Part 031652-00 May 2005Direct traffic into the tunnel.Traffic can be directed into the tunnel using st
Access Point Setup 455Chapter 21Location-Based ProfilesAP configuration profiles can be based on the unique location index (building.floor.device) ass
OmniAccess Reference: AOS-W System Reference456 Part 031652-00 May 2005Using AP Location WildcardsThe location profiles allow zero (0) to be used as a
Access Point Setup 457Chapter 21Attributes in the various profiles are treated individually. Only the attributes which are specifically configured in
OmniAccess Reference: AOS-W System Reference26 Part 031652-00 May 2005tings for each AP. Real-time calibration can be automatically programmed or manu
OmniAccess Reference: AOS-W System Reference458 Part 031652-00 May 2005The Unconfigured AP ProfileAPs are typically assigned a unique location code wh
Access Point Setup 459Chapter 21AP Attribute CommandsAP Configuration ModeThe following commands are available from the AP location or BSSID configura
OmniAccess Reference: AOS-W System Reference460 Part 031652-00 May 2005z no <command>Clear the specified command attributes in the current profi
Access Point Setup 461Chapter 21z wep-key{1|2|3|4} <key string (5 or 13 characters hexidecimal)>Used when opmode is set for staticWep. This comm
OmniAccess Reference: AOS-W System Reference462 Part 031652-00 May 2005Physical Layer Sub-modeIn addition to the regular AP attribute commands, the fo
Access Point Setup 463Chapter 21Order of Precedence for Profile AttributesChannel and Transmit PowerSettings for the AP channel and transmit power att
OmniAccess Reference: AOS-W System Reference464 Part 031652-00 May 2005Matching BSSID specific profileMatching location specific profile (exact match,
Access Point Setup 465Chapter 21CLI Configuration ExamplesThis section has typical commands for configuring AP attributes on the Wireless LAN switch.
OmniAccess Reference: AOS-W System Reference466 Part 031652-00 May 2005Set the opmode to opensystem.Resetting the Base Location ProfileThe base locati
Access Point Setup 467Chapter 21Enable Static WEP for a Specific BuildingTo select all APs in a specific building for configuration changes, the build
RF Design 27Chapter 4Launching RF PlanTo open RF Plan select: Start > All Programs > Alcatel Offline RF Plan> Alcatel RF Plan.RF Plan BasicsP
OmniAccess Reference: AOS-W System Reference468 Part 031652-00 May 2005Viewing AP Attribute SettingsShow a Location ProfileNOTE—Channel and transmit p
Access Point Setup 469Chapter 21Show a BSSID ProfileShow Encryption Keys for a LocationNOTE—For security, passwords and keys are encrypted by default.
OmniAccess Reference: AOS-W System Reference470 Part 031652-00 May 2005Show Effective Config for a Specific APThis example shows the actual configurat
Access Point Setup 471Chapter 21Viewing AP Information and StatisticsList Bootstrapped APsFor STATE, the expected value is 2 (sent tunnel response) or
OmniAccess Reference: AOS-W System Reference472 Part 031652-00 May 2005List Management Registered APsList AP Association TableList Wireless STA StateL
Access Point Setup 473Chapter 21Use the following command to view the state of the Access Point Status LED for a specific line card:(Alcatel) # show a
OmniAccess Reference: AOS-W System Reference474 Part 031652-00 May 2005List Configuration Applied on an APList Statistics for an AP or STA(Alcatel) #
Access Point Setup 475Chapter 21(Alcatel) # show ap stats 10.2.12.212 00:30:f1:70:49:65 verbose Frame rates-----------retry low-speed non-unicast recv
OmniAccess Reference: AOS-W System Reference476 Part 031652-00 May 2005List Status for an AP(OmniAccess 6000) #show ap status 10.1.1.114Station Table-
Access Point Setup 477Chapter 21List Information for Technical Support(Alcatel) # show tech-support
vAuthentication Methods . . . . . . . . . . . . . . . . . 83802.1x Authentication . . . . . . . . . . . . . . . . 84VPN Authentication. . . . . .
OmniAccess Reference: AOS-W System Reference28 Part 031652-00 May 2005Page FieldsEach tool in the RF Plan has its own unique information or configurat
OmniAccess Reference: AOS-W System Reference478 Part 031652-00 May 2005AP ReprovisioningIf the AP is already configured and you want to change the AP
Access Point Setup 479Chapter 215. Configure the location, Host IP/Name, Master IP. If the AP is going to be assigned a static IP, enter IP address, N
OmniAccess Reference: AOS-W System Reference480 Part 031652-00 May 2005FIGURE 21-6 Updated ConfigurationClick Back to go into the previous page and s
Access Point Setup 481Chapter 21
OmniAccess Reference: AOS-W System Reference482 Part 031652-00 May 2005
VPN Setup 483CHAPTER 22VPN SetupThe Alcatel Virtual Private Network (VPN) connection consists of the wireless user, the Access Point, and the Alcatel
OmniAccess Reference: AOS-W System Reference484 Part 031652-00 May 2005z Obtain a valid RADIUS server IP Address (if you are not using an internal dat
VPN Setup 485Chapter 22Configure the VLAN port using the following CLI commands.(Set the default gateway using the following CLI command.Test the conn
OmniAccess Reference: AOS-W System Reference486 Part 031652-00 May 2005Exit the RADIUS server setup.Test the RADIUS server setup using the following C
VPN Setup 487Chapter 22Test the setup using the following CLI CommandsL2TP IPSec VPN Server SetupThis section describes the steps necessary to configu
RF Design 29Chapter 4NavigationThe RF Plan tool is a wizard in that it logically guides you through the process of defining radio coverage for all the
OmniAccess Reference: AOS-W System Reference488 Part 031652-00 May 2005Turn off the default mschapv2 authentication using the following CLI command.Sp
VPN Setup 489Chapter 22Exit the vpn-dialer sub-mode.Enter the role sub-mode and create a role using the following CLI command.Assign a dialer to the r
OmniAccess Reference: AOS-W System Reference490 Part 031652-00 May 2005VPN DialerBefore You Beginz Make sure you have wireless connectivity.You can ch
VPN Setup 491Chapter 22Enter your username and password, then click the Log In button.NOTE—You might see a Security Alert Dialog appear. If this happe
OmniAccess Reference: AOS-W System Reference492 Part 031652-00 May 2005Click on the Click to download VPN Dialer link. NOTE—If you close the Alcatel L
VPN Setup 493Chapter 22The download process will begin and installation will begin automatically.
OmniAccess Reference: AOS-W System Reference494 Part 031652-00 May 2005InstallationWhen the setup file is finished downloading the Dialer Setup Wizard
VPN Setup 495Chapter 22Click on the Complete button.The Ready to Install dialog appears.Click the Install button.34
OmniAccess Reference: AOS-W System Reference496 Part 031652-00 May 2005The Installation Progress dialog appears, when the installation is finished the
VPN Setup 497Chapter 22Connecting With VPNYou are now ready to connect to the network using VPN. The Alcatel VPN icon appears in the Startup tray at t
OmniAccess Reference: AOS-W System Reference30 Part 031652-00 May 2005Opening ScreenWhen RF Plan opens, the browser window will show the default page:
OmniAccess Reference: AOS-W System Reference498 Part 031652-00 May 2005Alcatel VPN Dialer FeaturesThe Dialer has 4 features that may be selected.z Lau
VPN Setup 499Chapter 22Network InfoThis feature will display a static window showing important network information.test
OmniAccess Reference: AOS-W System Reference500 Part 031652-00 May 2005TroubleshootingCommon Dialer Error MessagesInterface is down or no route.This m
VPN Setup 501Chapter 22Common ProblemsDialer does not connect to serverIf the dialer seems to stall while attempting to connect (as indicated by a per
OmniAccess Reference: AOS-W System Reference502 Part 031652-00 May 2005Use the show crypto ipsec sa command on the switch to make sure the user is doi
VPN Setup 503Chapter 22"L2TP"=DWORD:1"DNETCLEAR"=DWORD:0"MSCHAPV2"=DWORD:0"CACHE-SECURID"=DWORD:1"IKESECS
OmniAccess Reference: AOS-W System Reference504 Part 031652-00 May 2005
VPN Configuration 505CHAPTER 23VPN ConfigurationAlcatel switches provide full support for Virtual Private Network (VPN) termination using IPSec and PP
OmniAccess Reference: AOS-W System Reference506 Part 031652-00 May 2005Configuring IPSec Using Web UIThe following parameters and options may be confi
VPN Configuration 507Chapter 23z Secondary WINS ServerSpecify the IP address of the Secondary WINS server in the text box.z Address Pools IPSec tunnel
RF Design 31Chapter 4You may add, edit, and delete buildings using this window. You may also import and export buildings using the import and export b
OmniAccess Reference: AOS-W System Reference508 Part 031652-00 May 2005Adding Address PoolsAdd Address Pools by clicking Add under the address pool se
VPN Configuration 509Chapter 23The Configuration> Security > VPN Settings > IPSec > Add IKE Secret page appears.Type the secret in the IKE
OmniAccess Reference: AOS-W System Reference510 Part 031652-00 May 2005Specify a priority.Select an encryption type from the Encryption pull-down box.
VPN Configuration 511Chapter 23Add address pools by clicking Add in the Address Pools section of the PPTP page. The PPTP > Add Address Pool page ap
OmniAccess Reference: AOS-W System Reference512 Part 031652-00 May 2005You may configure the VPN dialer by navigating to the Configuration > VPN Se
VPN Configuration 513Chapter 23z Enable PPTP Enable PPTP tunneling to the Alcatel switch.NOTE—You may check both PPTP and L2TP, however they will not
OmniAccess Reference: AOS-W System Reference514 Part 031652-00 May 2005Configuring VPN Server Emulation Using Web UIIt is sometimes common for users i
VPN Configuration 515Chapter 23VPN Server Emulation may be configured by navigating to the Configuration > VPN Settings Emulate VPN Servers page.Ad
OmniAccess Reference: AOS-W System Reference516 Part 031652-00 May 2005SecureID Token Ring Caching may be configured by navigating to the Configuratio
VPN Configuration 517Chapter 23Specify the primary and secondary WINS serversSelect authentication protocolsDefine an address pool for VPN users. This
OmniAccess Reference: AOS-W System Reference32 Part 031652-00 May 2005Planning RequirementsYou should collect the following information before beginni
OmniAccess Reference: AOS-W System Reference518 Part 031652-00 May 2005Enter the config-vpdn-pptp submode using the vpdn group pptp command from the C
VPN Configuration 519Chapter 23Set the IKE lifetime.Select an encryption type.Specify a Diffie-Hellman group.Specify a IKE hash algorithm.Specify a pr
OmniAccess Reference: AOS-W System Reference520 Part 031652-00 May 2005Define rules.Return to the config prompt.Apply a role for VPN users.Set the pos
VPN Configuration 521Chapter 23VPN Quick Start GuideRequirements From CustomerThe user must provide the following:z RADIUS server IP (if not using int
OmniAccess Reference: AOS-W System Reference522 Part 031652-00 May 20055Set up clientThe following sections explain each step in detail.1. Set up Netw
VPN Configuration 523Chapter 23z Username and/or password is wrongz Alcatel switch is not allowed to access RADIUS server (NAS IP on RADIUS)2(b). Set
OmniAccess Reference: AOS-W System Reference524 Part 031652-00 May 2005(Alcatel6000) (config-vpdn-l2tp) # ppp authentication PAP(Alcatel6000) (confi
VPN Configuration 525Chapter 23Type in username foo, password bar. You should see a page with the link to download VPN-dialer. Select that link and op
OmniAccess Reference: AOS-W System Reference526 Part 031652-00 May 2005 transform: esp-3des esp-sha-hmacIf there is an initiator IP that matches the
VPN Configuration 527Chapter 23Common Dialer Messages:Interface is down or no routeThere is a basic wireless connectivity problem.Route to destination
RF Design 33Chapter 4The Overview page shows the default values for your new building, most of which you can change in the following pages. On Buildin
OmniAccess Reference: AOS-W System Reference528 Part 031652-00 May 2005 CPU utilization threshold ... 60Auth Server List----------------Pri Name
VPN Configuration 529Chapter 23Hello timeout: 60 secondsDNS primary server: 10.1.1.2DNS secondary server: 30.0.0.0WINS primary server: 10.1.1.WINS sec
OmniAccess Reference: AOS-W System Reference530 Part 031652-00 May 2005Example VPN ConfigurationsThis section includes sample VPN clients terminating
VPN Configuration 531Chapter 23FIGURE 23-1 Emulating VPN ServersGo to Configuration > Security > Roles > Edit Role (logon) to verify tha
OmniAccess Reference: AOS-W System Reference532 Part 031652-00 May 2005FIGURE 23-2 Verifying the Logon Role ACLMake sure the IKE shared secrets match
VPN Configuration 533Chapter 23FIGURE 23-3 Matching the IKE Shared SecretThe IKE Aggressive Group Name is the same as the Cisco dialog box Authentica
OmniAccess Reference: AOS-W System Reference534 Part 031652-00 May 2005FIGURE 23-4 Matching IKE ParametersDefault ValuesThe following figures show th
VPN Configuration 535Chapter 23Default Transport ValuesFIGURE 23-5 Default Transport Tab Values
OmniAccess Reference: AOS-W System Reference536 Part 031652-00 May 2005Default Backup Servers ValuesFIGURE 23-6 Default Backup Servers Tab Values
VPN Configuration 537Chapter 23Default Dial Up ValuesFIGURE 23-7 Default Dial-Up Tab ValuesTypical Third-Party VPN ClientsThe steps required to termi
OmniAccess Reference: AOS-W System Reference34 Part 031652-00 May 2005Building Specification PageThe Building Specification Page enables you to specif
OmniAccess Reference: AOS-W System Reference538 Part 031652-00 May 2005FIGURE 23-8 Configuring a Group NameVerify the IKE policy settings by selectin
VPN Configuration 539Chapter 23FIGURE 23-9 IKE Policy SettingsVerify the basic logon role by selecting Configuration > Security > Roles >
OmniAccess Reference: AOS-W System Reference540 Part 031652-00 May 2005FIGURE 23-10 Basic Logon RoleModify the basic logon role by adding an ACL to a
VPN Configuration 541Chapter 23 FIGURE 23-11 Allowing TCP on Port 17Configuring a Third-Party VPN ClientComplete the VPN client wizard with source an
OmniAccess Reference: AOS-W System Reference542 Part 031652-00 May 2005Troubleshooting the ConnectionIf you have trouble connecting to the Alcatel Wir
Switch Maintenance 543CHAPTER 24Switch MaintenanceAlcatel switches provide full support for maintenance at the switch level, the file level, the wirel
OmniAccess Reference: AOS-W System Reference544 Part 031652-00 May 2005Image management options are.Reboot SwitchTo reboot the switch, typically after
Switch Maintenance 545Chapter 24To save any changes to the current switch configuration, click Yes. To leave the configuration file unchanged, click N
OmniAccess Reference: AOS-W System Reference546 Part 031652-00 May 2005When ready to revert to the original, factory configuration, click Continue and
Switch Maintenance 547Chapter 24The following parameters and options may be configured through Web UI.When finished, click Apply.File Maintenance The
RF Design 35Chapter 4A Word About Building DimensionsThe dimensions you specify for building width and height should be the major dimensions (maximum
OmniAccess Reference: AOS-W System Reference548 Part 031652-00 May 2005The options are.Source Selection Select Flash File System and select the name o
Switch Maintenance 549Chapter 24Copy LogsTo copy logs from the switch to another system, go to Maintenance > File > Copy Logs.You can copy the l
OmniAccess Reference: AOS-W System Reference550 Part 031652-00 May 2005You can copy the crash files using an FTP server or TFTP server. Once you have
Switch Maintenance 551Chapter 24The system must reboot before it can use the restored Flash files.Delete FilesTo keep from running out of flash file s
OmniAccess Reference: AOS-W System Reference552 Part 031652-00 May 2005z Calibrate the Radio Network—See “Calibration” on page 289.z Program Access Po
Switch Maintenance 553Chapter 24Importing a WMS DatabaseTBCRemoving Old EntriesTBC
OmniAccess Reference: AOS-W System Reference554 Part 031652-00 May 2005Re-initializing a WMS DatabaseTBC
Switch Maintenance 555Chapter 24Captive Portal MaintenanceThe captive portal is the screen users see when their wireless device connects to the networ
OmniAccess Reference: AOS-W System Reference556 Part 031652-00 May 2005Upload CertificateTo manually upload a authentication certificate for the capti
Switch Maintenance 557Chapter 24
OmniAccess Reference: AOS-W System Reference36 Part 031652-00 May 2005AP Modeling PageThe AP Modeling page allows you to specify all the information n
OmniAccess Reference: AOS-W System Reference558 Part 031652-00 May 2005
559PartMonitoring and Troubleshooting4
OmniAccess Reference: AOS-W System Reference560 Part 031652-00 May 2005
Monitoring the Wireless Environment 561CHAPTER 25Monitoring the Wireless EnvironmentThe Web UI Monitoring tab contains information on the wireless net
OmniAccess Reference: AOS-W System Reference562 Part 031652-00 May 2005Network MonitoringTo see a summary of the status of the wireless network, click
Monitoring the Wireless Environment 563Chapter 25Switch MonitoringThe Monitoring > Switch screens provide details about the Wireless LANs in the wi
OmniAccess Reference: AOS-W System Reference564 Part 031652-00 May 2005and Port ACL Hits (including ACL, ACE, New Hits, Total Hits, and Index. ACE is
Monitoring the Wireless Environment 565Chapter 25Sample Air Monitor ScreensTo display a typical screen for Air Monitors, select Monitoring > Switch
OmniAccess Reference: AOS-W System Reference566 Part 031652-00 May 2005Overview InformationClick Overview to see the following information.FIGURE 25-3
Monitoring the Wireless Environment 567Chapter 25Channel InformationClick Channel to see the following information.FIGURE 25-4 Channel Information
RF Design 37Chapter 4Radio TypeSpecify the radio type(s) of your APs using the pull-down Radio Type menu on the Modeling Parameters page.Available Rad
OmniAccess Reference: AOS-W System Reference568 Part 031652-00 May 2005The details on the selected change are shown in the figure below.FIGURE 25-5 O
Monitoring the Wireless Environment 569Chapter 25AP InformationClick APs to see the following information.FIGURE 25-6 AP InformationClient Informatio
OmniAccess Reference: AOS-W System Reference570 Part 031652-00 May 2005Packet Capture InformationClick Packet Capture to see the following information
Monitoring the Wireless Environment 571Chapter 25Diagnostics—see Figure 25-13.Port Status InformationClick Status to see the following types of inform
OmniAccess Reference: AOS-W System Reference572 Part 031652-00 May 2005Port Activity InformationClick Activity to see the following types of informati
Monitoring the Wireless Environment 573Chapter 25Status InformationClick Status to see the following types of information.FIGURE 25-14 Port Status In
OmniAccess Reference: AOS-W System Reference574 Part 031652-00 May 2005You can sort the events on any of these categories by using the Group By drop-d
Monitoring the Wireless Environment 575Chapter 25Creating Custom ReportsAdditionally, the Events tab allows you to create custom reports by going to E
OmniAccess Reference: AOS-W System Reference576 Part 031652-00 May 2005Wireless LAN MonitoringDisplays network information for each Wireless LAN based
Monitoring the Wireless Environment 577Chapter 25Creating Custom LogsUsing the information collected by the logging process, you can tailor custom log
OmniAccess Reference: AOS-W System Referencevi Part 031652-00 May 2005Enforcement Policies. . . . . . . . . . . . . . . . . . . 137AP Policies . . .
OmniAccess Reference: AOS-W System Reference38 Part 031652-00 May 2005Click Apply and the AM Modeling page displays.AM Modeling PageThe AM Modeling pa
OmniAccess Reference: AOS-W System Reference578 Part 031652-00 May 2005FIGURE 25-18 Sample ReportYou can change the status of a rogue or interfering
Monitoring the Wireless Environment 579Chapter 25AP ReportsTo see a typical AP report, select Reports > AP > Active Valid APs. The following typ
OmniAccess Reference: AOS-W System Reference580 Part 031652-00 May 2005FIGURE 25-20 Selected AP StatusUsing the Command Line InterfaceYou may use the
Monitoring the Wireless Environment 581Chapter 25asfasf
OmniAccess Reference: AOS-W System Reference582 Part 031652-00 May 2005
Firewall Logging 583CHAPTER 26Firewall LoggingThis chapter discusses firewall logging and explains the events found in those logs. Firewall logging in
OmniAccess Reference: AOS-W System Reference584 Part 031652-00 May 2005Authentication failed for User <username> : src ip <IPaddr>src port
Firewall Logging 585Chapter 26src-nat: The packet was forwarded with the source IP address modified.dst-nat: The packet was forwarded with the desti
OmniAccess Reference: AOS-W System Reference586 Part 031652-00 May 2005{TCP | UDP} srcip=<ipaddr>, srcport=<srcport>, dstip=<ipaddr>
Troubleshooting AOS-W Environments 587CHAPTER 27Troubleshooting AOS-W EnvironmentsBasic ConnectivityThe troubleshooting information in this chapter co
RF Design 39Chapter 4NOTE—The monitor rates you select for the AMs should be less than the data rates you selected for the APs. If you set the rate fo
OmniAccess Reference: AOS-W System Reference588 Part 031652-00 May 2005FIGURE 27-1 Normal Process FlowDesign your network do a wireless site surveyIn
Troubleshooting AOS-W Environments 589Chapter 27GeneralThe Wi-Fi Alliance has made great strides in testing interoperability between 802.11 devices fr
OmniAccess Reference: AOS-W System Reference590 Part 031652-00 May 2005Specific Probe Request – In this type of probe-request, the client is only inte
Troubleshooting AOS-W Environments 591Chapter 27z Ensure that the wireless network is operational and that no APs or switches have failed. If part of
OmniAccess Reference: AOS-W System Reference592 Part 031652-00 May 2005Client finds AP, but cannot associateAfter a client has located one or more APs
Troubleshooting AOS-W Environments 593Chapter 27802.11 Authentication FailsThe 802.11 authenticate exchange is a primitive form of authentication spec
OmniAccess Reference: AOS-W System Reference594 Part 031652-00 May 2005z Enable client debugging for the client device in question. From the Alcatel
Troubleshooting AOS-W Environments 595Chapter 27Client associates to AP, but higher-layer authentication failsProblems with higher-layer authenticatio
OmniAccess Reference: AOS-W System Reference596 Part 031652-00 May 2005z Once association and higher-layer authentication have succeeded, it is analog
Troubleshooting AOS-W Environments 597Chapter 27z WPA/802.11i Key Exchange Failure: In a WPA or 802.11i network, the dynamic key exchange process may
OmniAccess Reference: AOS-W System Reference40 Part 031652-00 May 2005NOTE—Importing any other file, including XML files from other applications, may
OmniAccess Reference: AOS-W System Reference598 Part 031652-00 May 2005z Reset the client NIC. If an internal error has caused the dropped associa-ti
Troubleshooting AOS-W Environments 599Chapter 27z If the above parameters are within acceptable ranges, but throughput is still low, it may indicate a
OmniAccess Reference: AOS-W System Reference600 Part 031652-00 May 2005TABLE 27-1 Access Point Duplex/Speed MatrixNIC Speed/Duplex ConfigurationSwitc
Troubleshooting AOS-W Environments 601Chapter 27100Mbps/Full-duplex1000Mbps/Full-duplexNo link No link Because the speeds do not match, no link is e
OmniAccess Reference: AOS-W System Reference602 Part 031652-00 May 2005100Mbps/Full-duplex100Mbps/Full-duplex100Mbps/Full-duplex100Mbps/Full-duplexPro
Troubleshooting AOS-W Environments 603Chapter 27AuthenticationMost enterprise wireless networks make use of some form of secure authentication. This
OmniAccess Reference: AOS-W System Reference604 Part 031652-00 May 2005Incorrect Username/password (TTLS or PEAP)A typical cause of authentication fai
Troubleshooting AOS-W Environments 605Chapter 27z Perform a wireless packet capture. If 802.1x authentication is observed to begin, and then abruptly
OmniAccess Reference: AOS-W System Reference606 Part 031652-00 May 2005RADIUS Server reports “Authentication Method Not Supported”This error message i
Troubleshooting AOS-W Environments 607Chapter 27VPN Dialer displays “No Alcatel switches detected”When this error message is displayed, it indicates t
RF Design 41Chapter 4Planning PagesPlanning Floors PageThe Planning Floors page enables you to see what the footprint of your floors look like. You ca
OmniAccess Reference: AOS-W System Reference608 Part 031652-00 May 2005z Examine the output of “show crypto ipsec sa”. Once IKE negotiation has succe
Troubleshooting AOS-W Environments 609Chapter 27FIGURE 27-5 Windows IPSec ServiceIPSec is up, but dialer does not display “Logging on” messageThis me
OmniAccess Reference: AOS-W System Reference610 Part 031652-00 May 2005Sample Packet CapturesBroadcast Probe Request FramePacket Information Flags:
Troubleshooting AOS-W Environments 611Chapter 27Supported Rates Element ID: 1 Supported Rates Length: 8 Supported Rate:
OmniAccess Reference: AOS-W System Reference612 Part 031652-00 May 2005 .0.. ... WEP Not Enabled ..0. .
Troubleshooting AOS-W Environments 613Chapter 27FCS - Frame Check Sequence FCS (Calculated): 0xCF771F24Beacon FramePacket Information Flags:
OmniAccess Reference: AOS-W System Reference614 Part 031652-00 May 2005 x... ... Reserved .x...
Troubleshooting AOS-W Environments 615Chapter 27 Supported Rate: 18.0 (Not BSS Basic Rate) Supported Rate: 24.0 (Not BSS Basic Rate)
OmniAccess Reference: AOS-W System Reference616 Part 031652-00 May 2005 Timestamp: 14:33:18.161865000 02/10/2004 Data Rate: 2
Troubleshooting AOS-W Environments 617Chapter 27 ...x ... Reserved ... 0... Channel Ag
OmniAccess Reference: AOS-W System Reference42 Part 031652-00 May 2005ZoomThe Zoom control sets the viewing size of the floor image. It is adjustable
OmniAccess Reference: AOS-W System Reference618 Part 031652-00 May 2005 Noise Level: 0% Noise dBm: 0802.11 MAC Header Version:
Troubleshooting AOS-W Environments 619Chapter 27 Signal Level: 37% Signal dBm: 0 Noise Level: 0% Noise dBm:
OmniAccess Reference: AOS-W System Reference620 Part 031652-00 May 2005 Data Rate: 2 1.0 Mbps Channel: 1 2412 MHz Signal
Troubleshooting AOS-W Environments 621Chapter 27 ... ..1... Short Preamble ... ...1... Priv
OmniAccess Reference: AOS-W System Reference622 Part 031652-00 May 2005 Auth OUI: 0x00-0x50-0xF2-01 SSNExtra bytes (Padding): ..
Troubleshooting AOS-W Environments 623Chapter 27802.11 Management—Association Response Capability Info: %0000010000110001
OmniAccess Reference: AOS-W System Reference624 Part 031652-00 May 2005z Session mirror sniffing and z Packet-capture for control path packetsPacket C
Troubleshooting AOS-W Environments 625Chapter 27z Alcatel message BPDUsz TCP cli ports (default ones)ExamplesDebugging a wireless WEP station doing VP
OmniAccess Reference: AOS-W System Reference626 Part 031652-00 May 2005Use ethereal on the target machine, in the above example, that's 1.2.3.4.
Diagnostic Tools 627CHAPTER 28Diagnostic ToolsThe Web UI Diagnostic tab contains information on tools to help you coordinate your troubleshooting of y
RF Design 43Chapter 4Coverage RateAdjusting the coverage rate will also affect the size of the coverage circles for AMs. Adjusting the rate values wil
OmniAccess Reference: AOS-W System Reference628 Part 031652-00 May 2005TracerouteTo see the path traffic is taking by using the WebUI, navigate to Dia
Diagnostic Tools 629Chapter 28Received ConfigurationTo capture AP configurations, navigate to Diagnostics > Received Configuration. Enter the AP IP
OmniAccess Reference: AOS-W System Reference630 Part 031652-00 May 2005Debug LogTo display the debug log when you have run debug tests, navigate to Di
Diagnostic Tools 631Chapter 28Web DiagnosticTo see diagnostics information from an AP’s Web Server, navigate to Diagnostics > Web Diagnostics, ente
OmniAccess Reference: AOS-W System Reference632 Part 031652-00 May 2005
633PartCommand Reference5
OmniAccess Reference: AOS-W System Reference634 Part 031652-00 May 2005
AOS-W Commands 635CHAPTER 29AOS-W CommandsUnderstanding the Command Line InterfaceThe AOS-W command line interface is designed to conform with network
OmniAccess Reference: AOS-W System Reference636 Part 031652-00 May 2005Online help is available for all commands by pressing ?. There are two levels o
AOS-W Commands 637Chapter 29Execute Mode CommandsExec mode commands allow very basic administrative access to the switch. Users who know the username
OmniAccess Reference: AOS-W System Reference44 Part 031652-00 May 2005Floor Editor PageClick Edit Floor to display the Floor Editor which allows you t
OmniAccess Reference: AOS-W System Reference638 Part 031652-00 May 2005See logout.logoutTerminates the session.Example(switch)> logout_See exit.pin
AOS-W Commands 639Chapter 29Example(switch)#traceroute 10.1.2.3Press 'q' to abort.Tracing the route to 10.1.2.3 1 10.4.21.254 0.788 msec
OmniAccess Reference: AOS-W System Reference640 Part 031652-00 May 2005boot Restarts the switch.clear Accesses clear commands.clock Sets the system cl
AOS-W Commands 641Chapter 29aaa CommandsThe Privileged mode aaa commands include:(switch) #aaa ?inservice Bring authentication server into servicestat
OmniAccess Reference: AOS-W System Reference642 Part 031652-00 May 2005user User commandsSee also the aaa commands in Configure mod
AOS-W Commands 643Chapter 29ExampleThe following example verifies that the authentication server Alcatel is enabled and working.(switch)# aaa test-ser
OmniAccess Reference: AOS-W System Reference644 Part 031652-00 May 2005Example (switch) #ads netad learn amConfigures scanning on the specified channe
AOS-W Commands 645Chapter 29backupBacks up and compresses critical files to flashbackup.tar.gz.Example(switch) #backup flashSee also restore.bootSpec
OmniAccess Reference: AOS-W System Reference646 Part 031652-00 May 2005clear ads netad anomalySets the network anomaly detection counters to zero.Exam
AOS-W Commands 647Chapter 29clear counters vrrp Clears the Virtual Router Redundancy Protocol statistics.Syntaxclear counters vrrp <id>where <
RF Design 45Chapter 4Area Editor PageThe area editor allows you to specify areas on your buildings floors where you either do not care about coverage,
OmniAccess Reference: AOS-W System Reference648 Part 031652-00 May 2005(switch) #clear loginsession 2 (switch) #clear mobile packet-counters
AOS-W Commands 649Chapter 29<cr>(switch) #clear site-survey calibration Clear Site Survey Calibration In Progresschannel-plan
OmniAccess Reference: AOS-W System Reference650 Part 031652-00 May 2005bssid BSSID for the flagged AP to clear hole(switch) #clear s
AOS-W Commands 651Chapter 29(switch) #clear wms ap Clear AP informationprobe sta Clear STA
OmniAccess Reference: AOS-W System Reference652 Part 031652-00 May 2005where <year> is the four-digit year, <month> is the name of the mon
AOS-W Commands 653Chapter 29Examples(switch) #copy flash: 9147 tftp:10.1.1.55(switch) #copy flash: 9147 flash: copy9147copy system Copies the system f
OmniAccess Reference: AOS-W System Reference654 Part 031652-00 May 2005sapm Logging for AP Manager (Master switch only)snmp
AOS-W Commands 655Chapter 29Syntax copy ftp: <filename> <flash | system partition>where:<filename> Is the name of the file to be
OmniAccess Reference: AOS-W System Reference656 Part 031652-00 May 2005crypto Debugging for VPN (IKE/IPSEC)dhcpd De
AOS-W Commands 657Chapter 29(switch) #debug aaa all(switch) #deleteRemoves the specified file name from flash. The file must exist in flash and be cor
OmniAccess Reference: AOS-W System Reference46 Part 031652-00 May 2005You may also use the drag and drop feature of the Area Editor to drag your area
OmniAccess Reference: AOS-W System Reference658 Part 031652-00 May 2005Example (switch) #halt (switch) #local-userdbManages the user database.Syntaxlo
AOS-W Commands 659Chapter 29(switch) #no crypto isakmpTo disable debugging the L2TP module, enter:(switch) #no debug l2tppacket-captureConfigures moni
OmniAccess Reference: AOS-W System Reference660 Part 031652-00 May 2005ExampleTBD(switch) #paging (switch) # panicManages files created during a sys
AOS-W Commands 661Chapter 29bssid BSSID of AM interface to start PCAP onchannel Channel to tune into to capture packetsExampleThe following example st
OmniAccess Reference: AOS-W System Reference662 Part 031652-00 May 2005(switch) #reload-peer-SCrenameChanges the specified file name to a new file nam
AOS-W Commands 663Chapter 29banner boot Display boot parametersclock configuration Sho
OmniAccess Reference: AOS-W System Reference664 Part 031652-00 May 2005provisioning-ap-list rap-wml Rogue AP Wired MAC Lookup Comma
AOS-W Commands 665Chapter 29site-survey See also the site-survey commands in Configuration mode. SyntaxExample(switch) #site-survey ?calibrate
OmniAccess Reference: AOS-W System Reference666 Part 031652-00 May 2005(switch) #site-survey calibrate 1.1.1 ?(switch) #site-survey update-channel-pla
AOS-W Commands 667Chapter 29(switch) #stm add-dos-sta ?<mac> STA to add to DoS list(switch) #stm add-dos-sta 00:00:00:01:01:ab
RF Design 47Chapter 4You may name an Access Point anything you wish. The name must be comprised of alpha-numeric characters and be 64 characters or le
OmniAccess Reference: AOS-W System Reference668 Part 031652-00 May 2005<mac> STA to remove from DoS list(switch) #stm remove-d
AOS-W Commands 669Chapter 29ExampleTBDtarCreates a file in Unix tar file format.Syntaxtar {clean | crash | flash | logs} where:clean Removes a tar fil
OmniAccess Reference: AOS-W System Reference670 Part 031652-00 May 2005(switch) #See also the traceroute command in Configuration mode and Exec mode.
AOS-W Commands 671Chapter 29(switch) #wms ap pub ?(switch) #wms ap pub ^% Invalid input detected at '^' marker.(switch) #
OmniAccess Reference: AOS-W System Reference672 Part 031652-00 May 2005(switch) #wms station ?<mac> MAC Address of station(swi
AOS-W Commands 673Chapter 29The following command allow you to configure your Wireless LAN Switch and APs.TABLE 29-3 Terminal Configuration Mode Comma
OmniAccess Reference: AOS-W System Reference674 Part 031652-00 May 2005loginsession Login Sessionmac-address-table Configure the MAC address tab
AOS-W Commands 675Chapter 29aaa CommandsThis command controls user authorization and authentication for the switch. Use the no form of this command to
OmniAccess Reference: AOS-W System Reference676 Part 031652-00 May 2005Syntaxaaa {bandwidth-contract | captive-portal | derivation-rules | dot1x | ker
AOS-W Commands 677Chapter 29Syntaxaaa captive-portal {auth-server <string> <position> <range> | default-role <string> | guest
viiOperation . . . . . . . . . . . . . . . . . . . . . 190Rules of Operating a Virtual Switch . . . . . . . . 191Hot Swapping Support. . . . . . .
OmniAccess Reference: AOS-W System Reference48 Part 031652-00 May 2005802.11 TypesThe 802.11 b/g and 802.11a Type drop down boxes allow you to choose
OmniAccess Reference: AOS-W System Reference678 Part 031652-00 May 2005aaa derivation-rules server Configures rules to derive user role or VLAN af
AOS-W Commands 679Chapter 29SyntaxnoneExample(Alcatel6000) (config) #aaa dot1x enforce-machine-authenticationaaa dot1x max-authentication-failure Conf
OmniAccess Reference: AOS-W System Reference680 Part 031652-00 May 2005aaa ldap-serverConfigures an LDAP server.Syntaxaaa ldap-server STRINGwhere STRI
AOS-W Commands 681Chapter 29Example(Alcatel6000) (config-ldapserver-paul)#allow-noencrypt (Alcatel6000) (config-ldapserver-paul)# (Alcatel6000) (confi
OmniAccess Reference: AOS-W System Reference682 Part 031652-00 May 2005Example(Alcatel6000) (config-ldapserver-paul)#filter filter (Alcatel6000) (conf
AOS-W Commands 683Chapter 29aaa ldap-server modeEnables or disables the LDAP server.SyntaxinserviceExample(Alcatel6000) (config-ldapserver-paul)#ins
OmniAccess Reference: AOS-W System Reference684 Part 031652-00 May 2005syntaxaaa mac-authentication auth-server STRING position where STRING is the na
AOS-W Commands 685Chapter 29aaa mgmt-authentication auth-server Configures administrator user authenticationsyntaxaaa mgmt-authentication auth-server
OmniAccess Reference: AOS-W System Reference686 Part 031652-00 May 2005aaa radius-accountingConfigures RADIUS accounting.Syntaxaaa radius-accountingEx
AOS-W Commands 687Chapter 29 where the options to this command are:STRING specifies the name of RADIUS server.acctport specifies the port number used
RF Design 49Chapter 4AP PlanThe AP Plan feature uses the information entered in the modeling pages to locate access points in the building(s) you desc
OmniAccess Reference: AOS-W System Reference688 Part 031652-00 May 2005Syntaxaaa stateful-authentication dot1x ap-config <name> ap-ipaddr radius
AOS-W Commands 689Chapter 29Example(Alcatel6000) (config) #aaa stateful-authentication dot1x default-role pauldefrole (Alcatel6000) (config) #aaa sta
OmniAccess Reference: AOS-W System Reference690 Part 031652-00 May 2005Example(Alcatel6000) (config) #aaa stateful-authentication kerberos enable (Al
AOS-W Commands 691Chapter 29aaa timers dead-timeConfigure authentication timers(Alcatel6000) (config) #aaa timers ?dead-time Help not d
OmniAccess Reference: AOS-W System Reference692 Part 031652-00 May 2005aaa timers idle-timeout(Alcatel6000) (config) #aaa timers ?dead-time
AOS-W Commands 693Chapter 29aaa timers logon-lifetime(Alcatel6000) (config) #aaa timers ?dead-time Help not definedidle-timeout
OmniAccess Reference: AOS-W System Reference694 Part 031652-00 May 2005aaa trusted-ap Configure trusted third party APs.Syntaxaaa trusted
AOS-W Commands 695Chapter 29aaa vpn-authentication auth-server Assigns an authentication server.Syntax(Alcatel6000) (config) #aaa vpn-authenticat
OmniAccess Reference: AOS-W System Reference696 Part 031652-00 May 2005Syntax(Alcatel6000) (config) #aaa web admin-port https port numberwhere :admin-
AOS-W Commands 697Chapter 29adp discovery Enables or disables ADP. Syntax (Alcatel6000) (config) # adp [discovery <disable | enable> | igmp-joi
OmniAccess Reference: AOS-W System Reference50 Part 031652-00 May 2005Colored circles around the AP symbols on the floor plan indicate the approximate
OmniAccess Reference: AOS-W System Reference698 Part 031652-00 May 2005(Alcatel6000) (config) #ads netad mode learn ?<cr>(Alcatel6000) (config)
AOS-W Commands 699Chapter 29ap location Accesses the AP location mode.arm CommandsConfigures the Adaptive Radio Management commands.Syntaxarm [accepta
OmniAccess Reference: AOS-W System Reference700 Part 031652-00 May 2005Where:Example(Alcatel6000) (config) #arm acceptable-coverage-index 2 arm backof
AOS-W Commands 701Chapter 29arpAdds a static Address Resolution Protocol entry to the routing table.Syntax arp <ipaddr> <mac> where:<
OmniAccess Reference: AOS-W System Reference702 Part 031652-00 May 2005(Alcatel6000) (config) #clock CommandsConfigures the Wireless LAN Switch’s cloc
AOS-W Commands 703Chapter 29 Configures the time zone in which the Switch is located.Syntaxclock summer-time <WORD> [<-23-23]
OmniAccess Reference: AOS-W System Reference704 Part 031652-00 May 2005syntax dynamic-map <dynamic-map-name> <dynamic-map-number> <no|
AOS-W Commands 705Chapter 29Syntax crypto ipsec <mtu> <size> | < transform-set> <transform-set-name> <encryption> <au
OmniAccess Reference: AOS-W System Reference706 Part 031652-00 May 2005Example(Alcatel6000) (config) #crypto isakmp ?address Configure
AOS-W Commands 707Chapter 29(Alcatel6000) (config) #(Alcatel6000) (config) #crypto isakmp ?address Configure the IP for the group keyd
RF Design 51Chapter 4The Suggested AP Table lists the coordinates, power, location, power setting, and channel for each of the APs that are shown in t
OmniAccess Reference: AOS-W System Reference708 Part 031652-00 May 2005(Alcatel6000) (config) #crypto isakmp groupname ?<name>
AOS-W Commands 709Chapter 29<peer-address> Configure the IP for the group key(Alcatel6000) (config) #crypto isakmp key 1111111111 addre
OmniAccess Reference: AOS-W System Reference710 Part 031652-00 May 2005pre-share Use Pre Shared Keys for IKE authenticationrsa-sig
AOS-W Commands 711Chapter 29(Alcatel6000) (config-isakmp)# hash md5 ?<cr>(Alcatel6000) (config-isakmp)# lifetime ?<seconds>
OmniAccess Reference: AOS-W System Reference712 Part 031652-00 May 2005Where:<global map> configures the default global map <map-number>
AOS-W Commands 713Chapter 29(Alcatel6000) (config) #destinationSyntaxdestination STRING <IP address><subnet mask> [invert | <cr>]Wh
OmniAccess Reference: AOS-W System Reference714 Part 031652-00 May 2005timeout Set 802.1X timeout valuesunicast-keyrotation Enable
AOS-W Commands 715Chapter 29dot1x key-size Set the Dynamic WEP Key Size.Syntaxdot1x key-size <128> |<40>where128 specifies
OmniAccess Reference: AOS-W System Reference716 Part 031652-00 May 2005Syntaxdot1x opp-key-caching ?Example(Alcatel6000) (config) # dot1x opp-key-cach
AOS-W Commands 717Chapter 29 Example(Alcatel6000) (config) # dot1x server server-retry 3(Alcatel6000) (config) #(Alcatel6000) (config) # dot1x server
OmniAccess Reference: AOS-W System Reference52 Part 031652-00 May 2005Viewing the ResultsViewing the results of the AM Plan feature is similar to that
OmniAccess Reference: AOS-W System Reference718 Part 031652-00 May 2005Example(Alcatel6000) (config) # dot1x timeout quiet-period 22(Alcatel6000) (co
AOS-W Commands 719Chapter 29Syntaxdot1x timeout wpa-key-timeout <period>where:<period> is the timeout in seconds for each WPA key exchange
OmniAccess Reference: AOS-W System Reference720 Part 031652-00 May 2005Syntaxdot1x wired-clients Example(Alcatel6000) (config) # dot1x wired-clients
AOS-W Commands 721Chapter 29Example(Alcatel6000) (config) # enablePassword:******Re-Type password:****** (Alcatel6000) (config) #encryptEnables encryp
OmniAccess Reference: AOS-W System Reference722 Part 031652-00 May 2005is the number of pings per second allowed. Higher number of pings per second ar
AOS-W Commands 723Chapter 29Example(Alcatel2400) (config) #firewall deny-inter-user-bridging (Alcatel2400) (config) #firewall disable-ftp-server
OmniAccess Reference: AOS-W System Reference724 Part 031652-00 May 2005firewall enable-per-packet-logging Enable per-packet logging. Default is per-se
AOS-W Commands 725Chapter 29Example(Alcatel2400) (config) #firewall prohibit-ip-spoofing (Alcatel2400) (config) #firewall prohibit-rst-replay Proh
OmniAccess Reference: AOS-W System Reference726 Part 031652-00 May 2005Syntax secure delete <spi_value> where <spi_value> is
AOS-W Commands 727Chapter 29secure-foreign deleteDeletes the home-agent-foreign-agent security association.Syntaxhome-agent delete <spi_value>
RF Design 53Chapter 4
OmniAccess Reference: AOS-W System Reference728 Part 031652-00 May 2005Syntaxhostname <hostname>where:<hostname> Specifies th
AOS-W Commands 729Chapter 29description Syntaxdescription <text>where<line> is a text lable. Lables can be up to Example(Alcatel6000) (co
OmniAccess Reference: AOS-W System Reference730 Part 031652-00 May 2005muxportConfigures Mux functionality on the port.SyntaxwhereExample (Alcatel6000
AOS-W Commands 731Chapter 29Example (Alcatel6000) (config-if)#rnet <slot/port>poe Power Over Ethernetinterface fastethernet
OmniAccess Reference: AOS-W System Reference732 Part 031652-00 May 2005interface fastethernet <slot/port>snmp Modify SNMP int
AOS-W Commands 733Chapter 29SyntaxwhereExample (Alcatel6000) (config-if)#interface fastethernet <slot/port>switchport Set the switc
OmniAccess Reference: AOS-W System Reference734 Part 031652-00 May 2005Example (Alcatel6000) (config-if)#interface fastethernet <slot/port> trus
AOS-W Commands 735Chapter 29Exampleinterface port-channelEthernet channel of interfacesSyntaxExampleinterface rangeInterface rangeinterface tunnelSynt
OmniAccess Reference: AOS-W System Reference736 Part 031652-00 May 2005<cr>(Alcatel6000) (config) #interface loopback(Alcatel6000) (config-loop)
AOS-W Commands 737Chapter 29 as switch ip.(switch) (config-loop)# ip address ?A.B.C.D A.B.C.D IP address(switc
OmniAccess Reference: AOS-W System Reference54 Part 031652-00 May 2005
OmniAccess Reference: AOS-W System Reference738 Part 031652-00 May 2005NAT which configures Network Address Translation. RADIUS which configures RADIU
AOS-W Commands 739Chapter 29Example(hostswitch) (config) #ip access-list mac 709 (hostswitch) (config) #ip access-list sessionConfigures a session acc
OmniAccess Reference: AOS-W System Reference740 Part 031652-00 May 2005Example (hostswitch) (config) #ip default-gateway 1.1.1.1 mgmt (hostswitch) (co
AOS-W Commands 741Chapter 29no Delete Commandoption Configure client specific optionsip igmpConfigure Internet G
OmniAccess Reference: AOS-W System Reference742 Part 031652-00 May 2005 ip radius dynamic-authorizationConfigures a RFC-3576 compliant RADIUS client.S
AOS-W Commands 743Chapter 29(hostswitch) (config) #ip radius source-interface vlan 3030(hostswitch) (config) #ip routeEstablishes static routes.Syntax
OmniAccess Reference: AOS-W System Reference744 Part 031652-00 May 2005(switch) (config) # key paulSyntax Error processing command(switch) (config) #l
AOS-W Commands 745Chapter 29Examplelogging levelSet Facility Logging levellogging monitorSet Terminal Line (monitor) logging level(switch) (config) #l
OmniAccess Reference: AOS-W System Reference746 Part 031652-00 May 2005gigabitethernet specifies Gigabit Ethernet per the IEEE 802.3 specification<
AOS-W Commands 747Chapter 29Example(hostswitch) (config-master-redundancy)# no master-vrrp (hostswitch) (config-master-redundancy)#(hostswitch) (confi
Security Options 55CHAPTER 5Security OptionsStrong network security is an absolute necessity in today’s enterprise network environment. There are pryi
OmniAccess Reference: AOS-W System Reference748 Part 031652-00 May 2005mgmt-roleAccess the commands that define the Management Role.Syntaxmgmt-role &l
AOS-W Commands 749Chapter 29ExampleTBDmgmt-user (Alcatel6000) (config) #mgmt-user ?<username> Name of the user.(Alcatel6000) (confi
OmniAccess Reference: AOS-W System Reference750 Part 031652-00 May 2005(Alcatel6000) (config) #no mgmt-user pauluser ?<cr>(Alcatel6000) (config)
AOS-W Commands 751Chapter 29event-thresholdSyntaxExampleignore-l2-broadcastIgnore layer 2 broadcasts for making mobility decisions. Default disabled.S
OmniAccess Reference: AOS-W System Reference752 Part 031652-00 May 2005Examplemax-dhcp-requests Maximum number of DHCP DISCOVERS/REQUESTS after
AOS-W Commands 753Chapter 29secure Configure the global security association parameters for the mobility manager.SyntaxExamplestation
OmniAccess Reference: AOS-W System Reference754 Part 031652-00 May 2005SyntaxExampleha-priority Set Home Agent priority for this VLAN Synt
AOS-W Commands 755Chapter 29mux-address(Alcatel6000) (config) #mux-address ?<mux-ip-address> A.B.C.D IP address(Alcatel6000) (config) #m
OmniAccess Reference: AOS-W System Reference756 Part 031652-00 May 2005% Incomplete command.(Alcatel6000) (config) #no mux-vlan 24(Alcatel6000) (confi
AOS-W Commands 757Chapter 29newbury(Alcatel6000) (config) # newbury ?<ip-addr> Specify IP Address of Locate Server A.B.C.D(Alcate
OmniAccess Reference: AOS-W System Reference56 Part 031652-00 May 2005Default Open PortsBy default, Alcatel Wireless LAN Switches and Access Points tr
OmniAccess Reference: AOS-W System Reference758 Part 031652-00 May 2005no clock Configure time-of-day clockSyntaxExampleno crypto
AOS-W Commands 759Chapter 29SyntaxExampleno firewall Configure global firwall policiesSyntaxExampleno interface Select an
OmniAccess Reference: AOS-W System Reference760 Part 031652-00 May 2005no loginsession Login SessionSyntaxExampleno mac-address-table
AOS-W Commands 761Chapter 29SyntaxExampleno netdestination Configure network destinationno netservice Configure a network servic
OmniAccess Reference: AOS-W System Reference762 Part 031652-00 May 2005SyntaxExampleno router Router MobileSyntaxExampleno service
AOS-W Commands 763Chapter 29no spanning-tree Spanning Tree SubsystemSyntaxExampleno telnet Enable telnet portSyntaxExamplen
OmniAccess Reference: AOS-W System Reference764 Part 031652-00 May 2005SyntaxExampleno vlan Create Switch VLAN Virtual InterfaceSyn
AOS-W Commands 765Chapter 29(Alcatel6000) (config) #ntp 10.100.101.30 ?(Alcatel6000) (config) #ntp 10.100.101.30packet-capture-defaults(Alcatel6000) (
OmniAccess Reference: AOS-W System Reference766 Part 031652-00 May 2005(Alcatel6000) (config) #packet-capture-defaults tcp ?ports Up
AOS-W Commands 767Chapter 29(Alcatel6000) (config) # ping(Alcatel6000) (config) #ping ?<ipaddr> Send ICMP echo packets to a speci
Security Options 57Chapter 568 UDP AP (and Wireless LAN Switch if DHCP server is configured)DHCP client69 UDP Wireless LAN SwitchTFTP80 TCP AP and Wir
OmniAccess Reference: AOS-W System Reference768 Part 031652-00 May 2005(Alcatel6000) (config) #no pptp ip ?local Configure local IP
AOS-W Commands 769Chapter 29(Alcatel5050) >(Alcatel5050) >enablePassword:******(Alcatel5050) #configure terminalEnter Configuration commands, on
OmniAccess Reference: AOS-W System Reference770 Part 031652-00 May 2005% Incomplete command.(Alcatel6000) (config) # show rap-wml ?cache
AOS-W Commands 771Chapter 29<server-name> Specify Name of MSSQL Servertable Specify Table Name for Lookup(Alcatel600
OmniAccess Reference: AOS-W System Reference772 Part 031652-00 May 2005(Alcatel6000) (config) #router mobile ?<A.B.C.D> IP Address
AOS-W Commands 773Chapter 29SAPM_COUNTERS_RESULT--------------------LOC SAP_IP Updates Sent ACKs Rcvd APBoots Sent APBoots Rcvd Bootstraps Rebo
OmniAccess Reference: AOS-W System Reference774 Part 031652-00 May 2005shutdown(switch) (config) # shutdown ?all All the physical
AOS-W Commands 775Chapter 29neighbor-tx-power-bump amount of increase in tx power for a neighbor for HA recoveryrra-max-comput
OmniAccess Reference: AOS-W System Reference776 Part 031652-00 May 2005(switch) (config) #site-survey neighbor-tx-power-bump ?<neighbor-tx-power-bu
AOS-W Commands 777Chapter 29snmp-server(switch) (config) #snmp-server ?community set read-only community stringenable h
OmniAccess Reference: AOS-W System Referenceviii Part 031652-00 May 2005Wireless Network Operation . . . . . . . . . . . . . . 238Wireless Laptops .
OmniAccess Reference: AOS-W System Reference58 Part 031652-00 May 2005514 UDP Wireless LAN SwitchSyslog1701 UDP Wireless LAN SwitchL2TP1723 TCP Wirele
OmniAccess Reference: AOS-W System Reference778 Part 031652-00 May 2005snmp-server host(switch) (config) #snmp-server host ?A.B.C.D IP
AOS-W Commands 779Chapter 29spanning-tree forward-time(switch) (config) #spanning-tree forward-time ?<value> Set a Spanning Tree
OmniAccess Reference: AOS-W System Reference780 Part 031652-00 May 2005(switch) (config) #show spanning-treeSpanning Tree is not currently activeThe f
AOS-W Commands 781Chapter 29 this valuesta-dos-block-time Amount of time to block a STA on with DoS is detected
OmniAccess Reference: AOS-W System Reference782 Part 031652-00 May 2005good-sta-ageout Amount of time after with STA with good RSSID to one
AOS-W Commands 783Chapter 29Examplestm coverage-hole-dectectionSyntaxExamplestm dos-prevention(switch) (config) #(switch) (config) #stm dos-prevention
OmniAccess Reference: AOS-W System Reference784 Part 031652-00 May 2005enable Enable(switch) (config) #stm dos-prevention enable fast
AOS-W Commands 785Chapter 29 this valuesta-dos-block-time Amount of time to block a STA on with DoS is detected
OmniAccess Reference: AOS-W System Reference786 Part 031652-00 May 2005coverage-hole-detecti.. Enable/Disable STM coverage hole capabilitiesdos-preven
AOS-W Commands 787Chapter 29auth-failure-block-ti.. Amount of time to block a STA if it fails repeated au thentications. In sec
Security Options 59Chapter 5AOS-W Security OptionsThe following security configuration options are supported in AOS-W:z Rolesz Policiesz AAA Serversz
OmniAccess Reference: AOS-W System Reference788 Part 031652-00 May 2005stm sta-dos-preventionstm strict-complianceSyntaxExamplesyscontact(switch) (con
AOS-W Commands 789Chapter 29(switch) (config) #syslocation Crossman main lab ^% Invalid input detected
OmniAccess Reference: AOS-W System Reference790 Part 031652-00 May 2005time-rangeInforms the Switch when a time-restricted feature, like an access lis
AOS-W Commands 791Chapter 29(switch) (config) #show time-range(switch) (config) #traceroute(switch) (config) #traceroute ?<ipaddr>
OmniAccess Reference: AOS-W System Reference792 Part 031652-00 May 2005 20 * * * 21 * * * 22 * * * 23 * * * 24 * * * 25 * * * 26 *
AOS-W Commands 793Chapter 29<cr>(switch) (config) #show user ?authentication-method Match authentication methodbssid Match B
OmniAccess Reference: AOS-W System Reference794 Part 031652-00 May 200510.4.21.102 00:00:00:00:00:00 rama ap-role 00:00:25 VPN 10.4.21.2
AOS-W Commands 795Chapter 29(switch) (config) #show user role guest ?rows Show certain rows<cr>(switch) (config) #show user r
OmniAccess Reference: AOS-W System Reference796 Part 031652-00 May 2005(switch) (config-role) #show user role visitorUsers----- IP MAC
AOS-W Commands 797Chapter 29(switch) (config-role) #version 2.4(switch) (config) #show version ?<cr>(switch) (config) #show versionAlcatel Wirel
OmniAccess Reference: AOS-W System Reference60 Part 031652-00 May 2005z Global Firewall Settingsz AdvancedThese options are described in this chapter.
OmniAccess Reference: AOS-W System Reference798 Part 031652-00 May 2005(switch) (config) #vlan(switch) (config) # vlan <id>(switch) (config) #sh
AOS-W Commands 799Chapter 29pptp Configure the PPTP group(switch) (config) #vpdn group l2tp ?<cr>(switch) (config) #vpdn grou
OmniAccess Reference: AOS-W System Reference800 Part 031652-00 May 2005(switch) (config) #show vpdn pptp ?configuration Show PPTP configurat
AOS-W Commands 801Chapter 29<cr>(switch) (config) #show vpdn tunnel pptpCommand obsolete. Please use show user-table to get a list of users. A
OmniAccess Reference: AOS-W System Reference802 Part 031652-00 May 2005STRING Configuration Name of the VPN dialer(switch) (config) #
AOS-W Commands 803Chapter 29CACHE-SECURID disabledIKESECS 28800IKEENC 3DESIKEGROUP TWOIKEHASH SH
OmniAccess Reference: AOS-W System Reference804 Part 031652-00 May 2005intra-switch Intra-switch Virtual Router Redundancy Protocol Confi
AOS-W Commands 805Chapter 29shutdown Disable VRRP intra-switch(switch) (config-vrrp)#no shutdown ?<cr>(switch) (config-vrrp)#no s
OmniAccess Reference: AOS-W System Reference806 Part 031652-00 May 2005 SSLv3 and TLSv1admin-port(switch) (config-webserver)#ad
AOS-W Commands 807Chapter 29<cr>(switch) (config-webserver)#ssl-protocol tlsv1 sslv2 ?sslv3 Use SSLv3<cr>(switch) (confi
Security Options 61Chapter 5FIGURE 5-2 Add New RoleUser role configuration parameters are described in the following sections.
OmniAccess Reference: AOS-W System Reference808 Part 031652-00 May 2005reserved-11a-channel enable/disable 80211a channel as multi tenancy protec
AOS-W Commands 809Chapter 29ap-lb-max-retries max tries to encourage STA to move to a unloaded APap-lb-user-high-wm High WM on max users th
OmniAccess Reference: AOS-W System Reference810 Part 031652-00 May 2005 balancingap-lb-util-low-wm Low WM on utilization
AOS-W Commands 811Chapter 29ids-signature configure a signature for the IDS checkno Delete Commandreserved-11a-channel
OmniAccess Reference: AOS-W System Reference812 Part 031652-00 May 2005poll-retries # of retries before it is declared downsta-ageout-inter
AOS-W Commands 813Chapter 29 ake anomlay after which the check can be resumedeap-rate-threshold Number of EAP handshake pa
OmniAccess Reference: AOS-W System Reference814 Part 031652-00 May 2005ap-flood-check IDS Fake AP Flood Detectionap-flood-inc-time Numb
AOS-W Commands 815Chapter 29wbridge-quiet-time Time to wait in seconds after detecting a wireless br idge after which the
OmniAccess Reference: AOS-W System Reference816 Part 031652-00 May 2005(switch) (wms) #reserved-11a-channel ?<reserved-11a-channel> enable/disa
AOS-W Commands 817Chapter 29NOTE—The handoff-assist option allows the switch to force a sticky client off of an AP when the RSSI drops below the defi
OmniAccess Reference: AOS-W System Reference62 Part 031652-00 May 2005CLI Configuration for User RolesSample CLI configuration follows for two differe
OmniAccess Reference: AOS-W System Reference818 Part 031652-00 May 2005(switch) (wms) #valid-11b-channel 14 ?mode enable/disable(sw
Action Commands 819CHAPTER 30Action CommandsAction Commands are available from the main Command-Line Interface (CLI) prompts in user mode and privileg
OmniAccess Reference: AOS-W System Reference820 Part 031652-00 May 2005Switch Management CommandsenableType this command to enter the privileged mode.
Action Commands 821Chapter 30Privileged Mode CommandsPrivileged mode is entered from the user mode through the enable command (see page 820). This mod
OmniAccess Reference: AOS-W System Reference822 Part 031652-00 May 2005configure terminalEnter the configuration mode. This mode provides access to sy
Action Commands 823Chapter 30delete <filename>Delete the specified file from the system. To view a list of files, use the dir command.dirList th
OmniAccess Reference: AOS-W System Reference824 Part 031652-00 May 2005reloadReboot the system after prompting the user to verify the command. If ther
Action Commands 825Chapter 30traceroute <IP Address>This command traces the route, displaying each hop, to a host specified by the IP Address ar
OmniAccess Reference: AOS-W System Reference826 Part 031652-00 May 2005WMS Commandswms ap <MAC address> [mode <type (dos |interfering| valid)
Action Commands 827Chapter 30Site Survey Commandssite-survey...Variations:z site-survey calibrate <building ID> <type (a|b|G)> [channel &l
Security Options 63Chapter 5what came before – at best, ACLs can look at the “SYN” flag in a TCP packet, treating the session as new if the flag is se
OmniAccess Reference: AOS-W System Reference828 Part 031652-00 May 2005Authentication CommandsAAA CommandsThe following immediate commands are used fo
Action Commands 829Chapter 30Local Database CommandsThe local user database is an internal Wireless LAN switch database for authenticating users. If u
OmniAccess Reference: AOS-W System Reference830 Part 031652-00 May 2005Clear Commandsclear arpThis command clears the ARP table.clear counters [fastet
Action Commands 831Chapter 30clear stm hole <BSSID>This command clears the coverage hole information for the specified BSSID.Debug Commandsdebug
OmniAccess Reference: AOS-W System Reference832 Part 031652-00 May 2005Panic Commandspanic clearThis command Clears all panic information from NVRAM.p
Show Commands 833CHAPTER 31Show CommandsThis chapter provides a summary of the show commands available on the Alcatel Wireless LAN Switch in your netw
OmniAccess Reference: AOS-W System Reference834 Part 031652-00 May 2005show image versionThis command displays version information about the software
Show Commands 835Chapter 31show loginsessionsThis command displays information about current sessions.Information returned by this command is:z ID: Se
OmniAccess Reference: AOS-W System Reference836 Part 031652-00 May 2005show station-tableThis command displays information about the stations connecte
Show Commands 837Chapter 31show inventoryThis commands shows the physical contents of the switch. It also shows the status of each power supply and fa
OmniAccess Reference: AOS-W System Reference64 Part 031652-00 May 2005To edit or delete existing policies, click the appropriate button. Note that som
OmniAccess Reference: AOS-W System Reference838 Part 031652-00 May 2005show processesThis command shows which processes are currently running and thei
Show Commands 839Chapter 31show syslocationThis command displays the physical location of the switch, if it has been specified in the configuration fi
OmniAccess Reference: AOS-W System Reference840 Part 031652-00 May 2005Layer 2/Layer 3 CommandsLayer 2 Commandsshow mac-address-tableDisplays the MAC
Show Commands 841Chapter 31show spantreeThis command display information about the status of spanning-tree ports. Execute this command with no options
OmniAccess Reference: AOS-W System Reference842 Part 031652-00 May 2005show vlan [<ID>]This command displays the name and ports for the specifie
Show Commands 843Chapter 31Layer 3 Commandsshow ip route [static]show routeridThis command displays the IP Address of the switch.(Alcatel) # show ip r
OmniAccess Reference: AOS-W System Reference844 Part 031652-00 May 2005show arp(Alcatel) # show arpProtocol Address Hardware Address
Show Commands 845Chapter 31DHCP Commandsshow ip dhcp databaseThis command displays information about DHCP pools created using the ip dhcp pool command
OmniAccess Reference: AOS-W System Reference846 Part 031652-00 May 2005Interface Commandsshow port link-eventThis command displays a count of up/down
Show Commands 847Chapter 31z POEz Tr u stedz SpanningTreez PortModeshow port trustedThis commands displays a list of trusted ports.Information returne
Security Options 65Chapter 5Network – An IP subnet, consisting of a network number and subnet mask.Alias – When Alias is selected, allows selection of
OmniAccess Reference: AOS-W System Reference848 Part 031652-00 May 2005show interface countersThis command displays the various inbound and outbound p
Show Commands 849Chapter 31show interface {fastethernet|gigabitethernet} <slot>/<port> [switchport] [allowed-vlan|native-vlan]This command
OmniAccess Reference: AOS-W System Reference850 Part 031652-00 May 2005show interface fastethernet <slot>/<port>show interface fastetherne
Show Commands 851Chapter 31show interface fastethernet <slot>/<port> switchport native-vlanshow interface gigabitethernet <slot> <
OmniAccess Reference: AOS-W System Reference852 Part 031652-00 May 2005show interface port-channel <0-7>show interface vlan <1 - 4094>(Alc
Show Commands 853Chapter 31Local Database Commandsshow local-userdb [<username>]This command displays information about local users.Information
OmniAccess Reference: AOS-W System Reference854 Part 031652-00 May 2005VPN CommandsIPSec Commandsshow crypto dpThis command displays the last few add
Show Commands 855Chapter 31show crypto ipsec transform-set [tag <transform-set-name>]This command displays the encryption and data authenticatio
OmniAccess Reference: AOS-W System Reference856 Part 031652-00 May 2005L2TP Commandsshow vpdn tunnel {l2tp|pptp|tunnel} [id <tunnel ID>]This com
Show Commands 857Chapter 31show vpdn {l2tp|pptp} configurationThis command displays information about the VPN tunnel settings.L2TP optionPPTP option(A
OmniAccess Reference: AOS-W System Reference66 Part 031652-00 May 2005Src-nat – Changes the source IP address of the packet. If no source NAT pool is
OmniAccess Reference: AOS-W System Reference858 Part 031652-00 May 2005show vpdn {l2tp|pptp} local pool [<pool name>]This command displays infor
Show Commands 859Chapter 31VPN Dialer Commandsshow vpn-dialer [<dialername>]This command displays all the attributes of the specified dialername
OmniAccess Reference: AOS-W System Reference860 Part 031652-00 May 2005PPTP Commandsshow vpdn pptp configurationThis command displays the VPN configur
Show Commands 861Chapter 31Mobility Commandsshow mobile active-user-tableThis command displays information about all currently active users.show forei
OmniAccess Reference: AOS-W System Reference862 Part 031652-00 May 2005show home-agent [configuration|{security [for-eign|mobile]}|status]This command
Show Commands 863Chapter 31show mobile client [verbose <IP>]This command will display information about mobile clients currently registered with
OmniAccess Reference: AOS-W System Reference864 Part 031652-00 May 2005show mobile configurationThis command displays information bout the mobility ma
Show Commands 865Chapter 31show mobile home-agents {global|local}This command displays the home agent tables.The following information is contained in
OmniAccess Reference: AOS-W System Reference866 Part 031652-00 May 2005show mobile messagesThe messages shown by the mobile messages command are liste
Show Commands 867Chapter 31show mobile received-packets <num (0-50)>Information returned in the table includes:z Noz Timez Opcode: manufacturing
Security Options 67Chapter 5FIGURE 5-5 Rule OrderingCLI ConfigurationAll CLI configuration for traffic/firewall policies is done under the ip access-
OmniAccess Reference: AOS-W System Reference868 Part 031652-00 May 2005show mobile registration-statistics <IP>This command displays mobile IP p
Show Commands 869Chapter 31show mobile tunnels [ mobile-ip | sap ]This command displays all the IPIP tunnels existing between M-switches.show mobile
OmniAccess Reference: AOS-W System Reference870 Part 031652-00 May 2005show mobile user-status [address <IP Address>] [mac-address <Address&g
Show Commands 871Chapter 31show mobile vlan-configurationThis command displays all the current VLANs on the switch.(Alcatel) (config) #show mobile vla
OmniAccess Reference: AOS-W System Reference872 Part 031652-00 May 2005Air Management CommandsAir Monitor Commandsshow pcap free-space <AM IP addre
Show Commands 873Chapter 31show am bssid-scan <am-ip> <channel>This command lists the ...show am channel <am-ip> <channel>Thi
OmniAccess Reference: AOS-W System Reference874 Part 031652-00 May 2005show am pot-ap-list <am-ip>This command displays the BSSIDs seen on the s
Show Commands 875Chapter 31show am stats <AM IP address> <MAC address> [verbose]TIP: You can find an AP or AM IP address and MAC by using
OmniAccess Reference: AOS-W System Reference876 Part 031652-00 May 2005(Alcatel) # show ap stats 10.2.12.212 00:30:f1:70:49:65 verbose Frame rates----
Show Commands 877Chapter 31show am association <AM IP address> <ap-bssid>This command displays information about a specific station assoc
ixChapter 14 Radio Resource Management . . . . . . 289Introduction . . . . . . . . . . . . . . . . . . . . . . 289Calibration . . . . . . . . . .
OmniAccess Reference: AOS-W System Reference68 Part 031652-00 May 2005FIGURE 5-6 Applying Traffic Policies to PortsTo add traffic policies to ports u
OmniAccess Reference: AOS-W System Reference878 Part 031652-00 May 2005show am sta-list <AM IP address>show am config <AM IP address>show
Show Commands 879Chapter 31show am version <AM IP address>show am scan-times <AM IP address>This command displays the scan times for the s
OmniAccess Reference: AOS-W System Reference880 Part 031652-00 May 2005show am counters <AM IP address>(Alcatel) # show am counters 10.1.1.162Co
Show Commands 881Chapter 31WMS CommandsWMS commands are privileged commands entered from the WMS sub-mode.Enter the privileged mode.Ty p e configure
OmniAccess Reference: AOS-W System Reference882 Part 031652-00 May 2005show wms ap <BSSID>This command displays the monitors that are listening
Show Commands 883Chapter 31show wms sta <MAC address>This command displays the monitors that are listening to the station specified in the MAC A
OmniAccess Reference: AOS-W System Reference884 Part 031652-00 May 2005show wms countersSite Survey Commandsshow site survey calibration [dst<bssid
Show Commands 885Chapter 31show site survey in-progressThis commands displays information about any site survey currently in progress.Station Manageme
OmniAccess Reference: AOS-W System Reference886 Part 031652-00 May 2005show stm dos-staThis command displays information about stations that are curre
Show Commands 887Chapter 31Access Point Management CommandsAlcatel Soft AP Commandsshow ap config location <location>This command displays the c
Security Options 69Chapter 5“Location” field on this line. See the chapter entitled “Wireless LAN Configuration – Advanced Location-Based AP Configura
OmniAccess Reference: AOS-W System Reference888 Part 031652-00 May 2005show ap configsThis command displays the configuration information for all APs.
Show Commands 889Chapter 31show ap keys <location>This command displays the keys for the AP in the specified location. If the encrypt feature ha
OmniAccess Reference: AOS-W System Reference890 Part 031652-00 May 2005show ap registered location <location>Different values for STATE are as f
Show Commands 891Chapter 31Authentication CommandsGeneral Authentication Commandsshow netservice [<name>]show destination [<name>]show use
OmniAccess Reference: AOS-W System Reference892 Part 031652-00 May 2005show userThis command displays information about users, including: roles, IP ad
Show Commands 893Chapter 31show rightsshow rights <role name>This commands shows the rights assigned to a specific role name.z mobile This optio
OmniAccess Reference: AOS-W System Reference894 Part 031652-00 May 2005IEEE 802.1x Commandsshow dot1x configThe show dot1x config command displays the
Show Commands 895Chapter 31z MAC Address of the supplicantz User Namez Authentication Status (yes/no)z AP MACz Encryption Keyz Authorization Modez EAP
OmniAccess Reference: AOS-W System Reference896 Part 031652-00 May 2005Accounting, Authentication, Authorizationshow aaa derivation-rulesThis command
Show Commands 897Chapter 31show aaa server-rules <server name>This command displays the User Rule Table for the named authentication server. You
OmniAccess Reference: AOS-W System Reference70 Part 031652-00 May 2005Role VLAN ID –This parameter allows the user to be mapped to a particular VLAN b
OmniAccess Reference: AOS-W System Reference898 Part 031652-00 May 2005show aaa timersshow aaa bandwidth-contractsThis command displays the name of ea
Show Commands 899Chapter 31show aaa state messages(Alcatel) # show aaa state messagesPAPI Messages-------------Msg ID Name Since last Read
OmniAccess Reference: AOS-W System Reference900 Part 031652-00 May 2005show aaa state user <IP address>show aaa state configurationshow aaa radi
Show Commands 901Chapter 31show aaa localdb-server [server-name <name>] show aaa dot1xThe show aaa dot1x commands displays which servers are con
OmniAccess Reference: AOS-W System Reference902 Part 031652-00 May 2005show aaa auth-server [server-name <name>] [server-type {radius|ldap|local
Show Commands 903Chapter 31Access Lists Commandsshow access-list [<name>|<number>]Display a list of the configured ACLs, or a specific ACL
OmniAccess Reference: AOS-W System Reference904 Part 031652-00 May 2005show ip access-list [<name>|<number>]Preferred from of the show acc
Show Commands 905Chapter 31show time-rangeThis command displays currently configured time ranges.MUX Commandsshow muxThis command displays information
OmniAccess Reference: AOS-W System Reference906 Part 031652-00 May 2005Enhanced Show CommandsDepending on the target of the show command, the output i
Show Commands 907Chapter 31z Detail ListsThe show commands that display information for a specific device, protocol, or event present detailed informa
Security Options 71Chapter 5physical port basis, MAC address ACLs and Ethertype ACLs are both available. All ACL configuration is done through the CLI
OmniAccess Reference: AOS-W System Reference908 Part 031652-00 May 2005
909PartAppendices6
OmniAccess Reference: AOS-W System Reference910 Part 031652-00 May 2005
Glossary 911Glossary10BaseT*An IEEE standard (802.3) for operating 10 Mbps Ethernet networks (LANs) with twisted pair cabling and a wiring hub.802.11
OmniAccess Reference: AOS-W System Reference912 Part 031652-00 May 2005802.11b*International standard for wireless networking that operates in the 2.4
Glossary 913Authentication serverAn entity that provides an authentication service to an authenticator. This service determines, from the credentials
OmniAccess Reference: AOS-W System Reference914 Part 031652-00 May 2005Bus adapter*A special adapter card that installs in a PC's PCI or ISA slot
Glossary 915Crossover cable*A special cable used for networking two computers without the use of a hub. Crossover cables may also be required for conn
OmniAccess Reference: AOS-W System Reference916 Part 031652-00 May 2005DHCP*A utility that enables a server to dynamically assign IP addresses from a
Glossary 917Encryption key*An alphanumeric (letters and/or numbers) series that enables data to be encrypted and then decrypted so it can be safely sh
OmniAccess Reference: AOS-W System Reference72 Part 031652-00 May 2005permit icmp 1.1.1.0 0.0.0.255 any echo-replyThe example above permits TCP traffi
OmniAccess Reference: AOS-W System Reference918 Part 031652-00 May 2005transmits packets it receives to all the connected ports. A small wired hub may
Glossary 919IP address*A 32-bit number that identifies each sender or receiver of information that is sent across the Internet. An IP address has two
OmniAccess Reference: AOS-W System Reference920 Part 031652-00 May 2005L2TPLayer 2 Tunnelling Protocol. L2TP is an extension of Point-to-Point Protoco
Glossary 921Network name*Identifies the wireless network for all the shared components. During the installation process for most wireless networks, yo
OmniAccess Reference: AOS-W System Reference922 Part 031652-00 May 2005Plug and Play*A computer system feature that provides for automatic configurati
Glossary 923Router*A device that forwards data packets from one local area network (LAN) or wide area network (WAN) to another. Based on routing table
OmniAccess Reference: AOS-W System Reference924 Part 031652-00 May 2005SSL*Commonly used encryption scheme used by many online retail and banking site
Glossary 925on a network. Every computer in a TCP/IP network has its own IP address that is either dynamically assigned at startup or permanently assi
OmniAccess Reference: AOS-W System Reference926 Part 031652-00 May 2005Wi-Fi*An interoperability certification for wireless local area network (LAN) p
Glossary 927
Security Options 73Chapter 5To configure general authentication server settings, navigate to Configuration > Security > AAA Servers > General
OmniAccess Reference: AOS-W System Reference928 Part 031652-00 May 2005
OmniAccess Reference: AOS-W System Reference74 Part 031652-00 May 2005FIGURE 5-10 RADIUS Server ConfigurationA list of currently configured RADIUS se
Security Options 75Chapter 5Shared Secret – Each RADIUS client-server pair must use a shared secret. Treat this shared secret as a password, and ensur
OmniAccess Reference: AOS-W System Reference76 Part 031652-00 May 2005FIGURE 5-12 Add RADIUS Server RuleAvailable configuration parameters are:Rule T
Security Options 77Chapter 5LDAPLDAP (Lightweight Directory Access Protocol) is a lightweight protocol for accessing directory services. A directory i
Komentarze do niniejszej Instrukcji