3Com OfficeConnect WX1200 Release Note Download Page 12

12

W

IRELESS

 LAN S

WITCH

 

AND

 C

ONTROLLER

 MSS V

ERSION

 3.0 R

ELEASE

 N

OTES

Access to 3WXM. To secure access, configure user 
accounts within 3WXM. 

Access to the 3WXM monitoring service. To secure 
access, configure user accounts within the moni-
toring service. 

Do not use passwords that are easy to guess, such 
as vehicle registration plates, family birthdays and 
names, or common words. Use combinations of 
uppercase and lowercase letters as well as num-
bers in all passwords. 

SNMP

SNMP is disabled by default. 3Com recommends that 
you leave SNMP disabled unless you are using 3Com 
Network Director or a similar product to manage your 
wired network. If you do need to use SNMP, do not 
use the well-known community strings 

public

 (com-

monly used for read-only access) or 

private

 (com-

monly used for read-write access.) By default, no 
SNMP community strings are configured. Use SNMP 
on an isolated management VLAN so that the clear 
text community strings are not visible on the public 
network. 

The 3.0 manuals state that MSS has default commu-
nity strings 

public

 and 

private

. This is incorrect. No 

community strings are set by default in MSS Version 
3.0. 

To disable SNMP (if not already disabled), use the 

set 

ip snmp server disable

 command. 

To change the community strings, use the 

set snmp 

community

 command.

CLI Access

MSS allows CLI access through the console, through 
Telnet, and through SSH. Console and SSH access are 
enabled by default. Telnet is disabled by default. 

Configure a username and password, so that MSS 
requires login even for console access. Usernames 
and their passwords are not specific to the type of 
management access. You can use the same username 
and password for access through the console, Telnet, 
or SSH.

Leave Telnet disabled unless you need it. Use SSH 
instead. 

Even though the SSH service is enabled by default, 
you need to generate a key pair before you can use 
SSH. Use the 

crypto generate key ssh

 command.

Web Access

Web Manager uses HTTPS for encrypted communica-
tions and certificate-based server authentication, and 
requires use of the enable password.

Web Manager access through HTTPS is enabled by 
default. Unless you need to use Web Manager, dis-
able the HTTPS server on the WX switch. (Even 
though 3WXM also uses HTTPS, disabling the HTTPS 
server does not disable access by 3WXM.) To disable 
the HTTPS server, use the 

set ip ssh server disable

 

command.

If you do need to use Web Manager, use the follow-
ing best practices to preserve or increase the security 
level related to Web access:

Summary of Contents for OfficeConnect WX1200

Page 1: ...cting exe that you have downloaded from the 3Com Web site Points to Note when using the WX1200 and WX4400 Follow these best practice recommendations during configuration and implementation to avoid or...

Page 2: ...le below lists the NICs that have been used successfully with MSS The majority were tested using recently available drivers using the Microsoft native 802 1X client and a Microsoft IAS RADIUS server 3...

Page 3: ...ds that you set up a sepa rate service profile for WPA CCMP with a different SSID for compatibility If you are migrating from Dynamic WEP to WPA TKIP 3Com recommends creat ing separate service profile...

Page 4: ...e to the client through the MAP for the duration of the 802 1X quiet period timer which defaults to 60 seconds An error mes sage indicating that a client has failed authorization appears in the WX swi...

Page 5: ...Some drivers install this automatically if you run the setup exe utility to install the driver 3Com strongly recommends that you update the driver manually using the driver properties in the Network c...

Page 6: ...ble WEP encryption When using dynamic WEP in Windows 2000 select static WEP 128bit and enter any static WEP key as a placeholder This temporary key configures the driver to use WEP to encrypt packets...

Page 7: ...the current Panther client If you need to run both WPA TKIP and Dynamic WEP at the same time you must configured separate service profiles for each encryption type in order to maintain compatibility w...

Page 8: ...KB826942 or Hotfix KB822596 Windows 2000 requires hotfix KB822596 Using PEAP MS CHAP V2 with computer authenti cation will allow users who have never logged on to a PC authenticate wirelessly without...

Page 9: ...LDAP with specific protocols as noted in the table The tests were initially performed using Dynamic WEP though subsequent testing has revealed no noticeable differ ences in RADIUS compatibility when...

Page 10: ...pe in this case Dynamic WEP Additionally compatibility with wireless NICs is reduced Downloading the latest drivers for your wireless NIC is strongly recommended See 802 1X Cli ents for specific infor...

Page 11: ...rmation Security Best Practices MSS and 3WXM provide robust options for securing management access to WX switches and to the 3WXM client and 3WXM monitoring service To opti mize security for managemen...

Page 12: ...SNMP if not already disabled use the set ip snmp server disable command To change the community strings use the set snmp community command CLI Access MSS allows CLI access through the console through...

Page 13: ...the one where you installed the certificate signed by the CA Communication between the WX Switch and 3WXM or Web Manager Administration certificate requirement 11974 Before the WX switch can communica...

Page 14: ...atedly disables and reenables the link caus ing STP to repeatedly stop the other device s port from forwarding traffic As a result the boot attempt is never successful To allow a MAP to boot over a li...

Page 15: ...c For a user ACL to take effect you must explicitly set both the source and destina tion addresses in the ACL Add Authentication Rules for Last Resort Access to Any SSID Last resort authentication is...

Page 16: ...o use these strings you will need to con figure them manually To configure an SNMP commu nity string use the set snmp community command The quickstart command prompts for time and date parameters 1817...

Page 17: ...ng on the license WX1200 20 configured 12 active Includes directly attached MAPs and Distributed MAPs Inactive configurations are backups Minimum link speed within a Mobility Domain 128 Kbps Network P...

Page 18: ...t 18367 MSS can tunnel traffic for a VLAN through a WX switch that does not have that VLAN statically config ured If you attempt to add a static VLAN to a switch that is already tunneling traffic for...

Page 19: ...ed Below is an example of the error message This applies to both MX1200 and MX4400 Example Starting supervisor 3 0 3 0_110304_WX1200 SPAN Nov 05 07 01 44 073135 ERROR SPAN_VLAN_ERR span_port_change po...

Page 20: ...port group before you add the groups ports to the VLAN then add the port group to the VLAN MAP Issues WX1200 allows configuration of ports 7 and 8 as MAP access ports 18280 Ports 7 and 8 on the WX120...

Page 21: ...e to the additional messages sent by 802 11b g radios When the radio enters protection mode a message such as the following appears in the WX switch s log buffer MAP Jul 09 21 01 36 845822 WARNING Por...

Page 22: ...tem IP address from 3WXM causes the switch to be unmanageable from 3WXM 18414 If you use 3WXM to change a managed switch s system name or system IP address other changes to the switch are not received...

Page 23: ...conds with the following command set arp agingtime 1200 Logging in to SSH requires hitting Enter twice 15613 When you start an SSH session with a WX switch the switch does not display the login prompt...

Page 24: ...rt become congested and another instance of the RADIUS server on the same machine is configured to use a different UDP port number MSS does not allow you to specify the UDP port number of a RADIUS ser...

Page 25: ...s However the commands that con figure MAC Web and last resort network access rules accept the value This is an invalid configuration and can provide unexpected results The command for configuring 802...

Page 26: ...tatistics output The display radius command is not documented and has no output 18233 Web AAA Issues Web AAA users receive page not found error if RADIUS is the authentication method 17752 If you use...

Page 27: ...he ACE name that starts with abc which is not a CLI keyword is accepted WX1200 set security acl ip port_abc deny 0 0 0 0 255 255 255 255 error Wrong ACL name input port_abc WX1200 set security acl ip...

Page 28: ...tream through a MAP stop receiving the stream if one of the clients leaves the group Do not disable IGMP snooping The feature is enabled by default Invalid IP multicast forwarded 12784 IGMP multicast...

Reviews: