3Com OfficeConnect WX1200 Release Note Download Page 20

20

W

IRELESS

 LAN S

WITCH

 

AND

 C

ONTROLLER

 MSS V

ERSION

 3.0 R

ELEASE

 N

OTES

Domain can interfere with communication 
among the switches. (16910)

If the Mobility Domain contains intermediary switches 
or routers that use a router redundancy protocol, WX 
switches that communicate through those intermedi-
ary devices might lose communication with one other 
due to the way some router redundancy protocols 
handle MAC addresses. If this issue occurs, log mes-
sages appear periodically on the seed WX switch indi-
cating that member WX switches are entering or 
leaving the Mobility Domain.

Set the FDB timer (default 300 seconds) and the ARP 
timer (default 1200 seconds) to the same values on 
the WX switches. 3Com recommends using 300 sec-
onds as the value for both timers. To set the FDB 
timer, use the 

set fdb agingtime

 command. To set 

the ARP timer, use the 

set arp agingtime

 command.

Port group in a VLAN running STP can cause 
Layer 2 loop when the WX switch is not the root 
bridge. (18171)

If you configure a port group containing ports that 
are already in a VLAN that is running STP, and you 
then add the port group to the VLAN, a Layer 2 loop 
can occur in the VLAN. This can occur when the WX 
switch is not the root bridge.

Instead of adding the port group’s ports to the VLAN 
individually, configure the port group before you add 
the groups ports to the VLAN, then add the port 
group to the VLAN.

MAP Issues

WX1200 allows configuration of ports 7 and 8 as 
MAP access ports. (18280)

Ports 7 and 8 on the WX1200 are uplink ports and do 
not support PoE. However, the CLI allows you to con-
figure these ports as MAP access ports, for directly 
connected MAPs, with an external PoE source to 
power the MAPs. Even though the MAPs boot, clients 
associated with the MAPs might not receive network 
access. This issue does not occur if the MAPs con-
nected to ports 7 and 8 are configured as Distributed 
MAPs.

To use a MAP that is directly connected to port 7 or 8 
on a WX1200, configure the MAP as a Distributed 
MAP (

set dap

 command), not as a directly connected 

MAP (

set port type ap

 command).

Distributed MAP can change IP addresses during 
boot sequence in environments with multiple 
DHCP servers. (16499)

To become fully active, a Distributed MAP does a full 
restart after downloading its software image. The first 
time the MAP is powered up, it sends a DHCP dis-
cover for an IP address, uses DNS to find its config-
ured WX switch, then downloads its software image 
from that WX. After downloading the image, the 
MAP restarts itself with the downloaded image and 
sends a second DHCP discover to again obtain its IP 
address. In a network containing more than one 
DHCP server, it is possible for the MAP to use one IP 
address when downloading the image, but end up 
with a second IP address after rebooting the second 

Summary of Contents for OfficeConnect WX1200

Page 1: ...cting exe that you have downloaded from the 3Com Web site Points to Note when using the WX1200 and WX4400 Follow these best practice recommendations during configuration and implementation to avoid or...

Page 2: ...le below lists the NICs that have been used successfully with MSS The majority were tested using recently available drivers using the Microsoft native 802 1X client and a Microsoft IAS RADIUS server 3...

Page 3: ...ds that you set up a sepa rate service profile for WPA CCMP with a different SSID for compatibility If you are migrating from Dynamic WEP to WPA TKIP 3Com recommends creat ing separate service profile...

Page 4: ...e to the client through the MAP for the duration of the 802 1X quiet period timer which defaults to 60 seconds An error mes sage indicating that a client has failed authorization appears in the WX swi...

Page 5: ...Some drivers install this automatically if you run the setup exe utility to install the driver 3Com strongly recommends that you update the driver manually using the driver properties in the Network c...

Page 6: ...ble WEP encryption When using dynamic WEP in Windows 2000 select static WEP 128bit and enter any static WEP key as a placeholder This temporary key configures the driver to use WEP to encrypt packets...

Page 7: ...the current Panther client If you need to run both WPA TKIP and Dynamic WEP at the same time you must configured separate service profiles for each encryption type in order to maintain compatibility w...

Page 8: ...KB826942 or Hotfix KB822596 Windows 2000 requires hotfix KB822596 Using PEAP MS CHAP V2 with computer authenti cation will allow users who have never logged on to a PC authenticate wirelessly without...

Page 9: ...LDAP with specific protocols as noted in the table The tests were initially performed using Dynamic WEP though subsequent testing has revealed no noticeable differ ences in RADIUS compatibility when...

Page 10: ...pe in this case Dynamic WEP Additionally compatibility with wireless NICs is reduced Downloading the latest drivers for your wireless NIC is strongly recommended See 802 1X Cli ents for specific infor...

Page 11: ...rmation Security Best Practices MSS and 3WXM provide robust options for securing management access to WX switches and to the 3WXM client and 3WXM monitoring service To opti mize security for managemen...

Page 12: ...SNMP if not already disabled use the set ip snmp server disable command To change the community strings use the set snmp community command CLI Access MSS allows CLI access through the console through...

Page 13: ...the one where you installed the certificate signed by the CA Communication between the WX Switch and 3WXM or Web Manager Administration certificate requirement 11974 Before the WX switch can communica...

Page 14: ...atedly disables and reenables the link caus ing STP to repeatedly stop the other device s port from forwarding traffic As a result the boot attempt is never successful To allow a MAP to boot over a li...

Page 15: ...c For a user ACL to take effect you must explicitly set both the source and destina tion addresses in the ACL Add Authentication Rules for Last Resort Access to Any SSID Last resort authentication is...

Page 16: ...o use these strings you will need to con figure them manually To configure an SNMP commu nity string use the set snmp community command The quickstart command prompts for time and date parameters 1817...

Page 17: ...ng on the license WX1200 20 configured 12 active Includes directly attached MAPs and Distributed MAPs Inactive configurations are backups Minimum link speed within a Mobility Domain 128 Kbps Network P...

Page 18: ...t 18367 MSS can tunnel traffic for a VLAN through a WX switch that does not have that VLAN statically config ured If you attempt to add a static VLAN to a switch that is already tunneling traffic for...

Page 19: ...ed Below is an example of the error message This applies to both MX1200 and MX4400 Example Starting supervisor 3 0 3 0_110304_WX1200 SPAN Nov 05 07 01 44 073135 ERROR SPAN_VLAN_ERR span_port_change po...

Page 20: ...port group before you add the groups ports to the VLAN then add the port group to the VLAN MAP Issues WX1200 allows configuration of ports 7 and 8 as MAP access ports 18280 Ports 7 and 8 on the WX120...

Page 21: ...e to the additional messages sent by 802 11b g radios When the radio enters protection mode a message such as the following appears in the WX switch s log buffer MAP Jul 09 21 01 36 845822 WARNING Por...

Page 22: ...tem IP address from 3WXM causes the switch to be unmanageable from 3WXM 18414 If you use 3WXM to change a managed switch s system name or system IP address other changes to the switch are not received...

Page 23: ...conds with the following command set arp agingtime 1200 Logging in to SSH requires hitting Enter twice 15613 When you start an SSH session with a WX switch the switch does not display the login prompt...

Page 24: ...rt become congested and another instance of the RADIUS server on the same machine is configured to use a different UDP port number MSS does not allow you to specify the UDP port number of a RADIUS ser...

Page 25: ...s However the commands that con figure MAC Web and last resort network access rules accept the value This is an invalid configuration and can provide unexpected results The command for configuring 802...

Page 26: ...tatistics output The display radius command is not documented and has no output 18233 Web AAA Issues Web AAA users receive page not found error if RADIUS is the authentication method 17752 If you use...

Page 27: ...he ACE name that starts with abc which is not a CLI keyword is accepted WX1200 set security acl ip port_abc deny 0 0 0 0 255 255 255 255 error Wrong ACL name input port_abc WX1200 set security acl ip...

Page 28: ...tream through a MAP stop receiving the stream if one of the clients leaves the group Do not disable IGMP snooping The feature is enabled by default Invalid IP multicast forwarded 12784 IGMP multicast...

Reviews: