background image

HP MSM313/MSM323 Deployment Guide

3

    Contents

Contents

Chapter 1
Introduction

7

About this guide................................................................................8

Products covered........................................................................8
Important terms..........................................................................8
Conventions ................................................................................8
Contacting support .....................................................................9
Online documentation .................................................................9

Chapter 2
Public/guest networks

11

Introduction ....................................................................................12

Scenario 1a: Hotspot in a box .........................................................13

How it works.............................................................................13
Configuration road map ............................................................13

A. Install the service controller............................................13
B. Configure the wireless network ......................................14
C. Configure the Internet connection ..................................14
D. Define the list of users....................................................14
E. Test the public access interface ......................................14

Scenario 1b: Hotspot with custom interface ...................................16

How it works.............................................................................16
Configuration road map ............................................................16

A. Configure the Internet port .............................................16

Examples ..................................................................................17

A. Customize the login page and logo .................................17
B. Test the public access interface ......................................18

Scenario 1c: Hotspot with satellites and roaming ...........................19

How it works.............................................................................19
Configuration road map ............................................................19

A. Install the APs.................................................................19
B. Switch the APs to autonomous mode.............................20
C. Configure the wireless network ......................................20
D. Set the shared secret on the service controller...............20
E. Configure the connection to the service controller on the
APs .....................................................................................20

Scenario 1d: Hotspot with layer 2 encryption .................................21

How it works.............................................................................21
Configuration road map ............................................................21

A. Create VSCs on the APs..................................................21
B. Create VSCs on the service controller.............................22

Scenario 2a: Hotspot with RADIUS authentication..........................24

How it works.............................................................................24
Configuration road map ............................................................24

A. On the RADIUS server ....................................................24
B. Install the service controller............................................24
C. Configure the wireless network ......................................25
D. Configure the Internet port .............................................25
E. Create a RADIUS profile..................................................25
F. Enable RADIUS authentication of users...........................25
G. Test the public access interface ......................................25

Scenario 2b: Hotspot with custom interface (via RADIUS server) ..27

How it works.............................................................................27
Configuration road map ............................................................27

A. Customize the login page and logo .................................27
B. Define attributes on the RADIUS server..........................28
C. Configure the service controller to retrieve attributes from
the RADIUS server..............................................................28
D. Test the public access interface ......................................29

Scenario 2c: Hotspot with satellites and roaming (via RADIUS server)
30

How it works.............................................................................30
Configuration road map ............................................................30

A. Install the APs.................................................................30
B. Switch the APs to autonomous mode.............................30
C. Configure the wireless network ......................................31
D. Set the shared secret on the service controller...............31
E. Configure the connection to the service controller on the
APs .....................................................................................31

Scenario 2d: Hotspot with layer 2 security (AAA server) ................32

How it works.............................................................................32
Configuration road map ............................................................32

A. Create VSCs on the APs..................................................32
B. Create VSCs on the service controller.............................33

Scenario 2e: Using two radios to support A+B+G traffic .................35

How it works.............................................................................35

Network topology................................................................35

Configuration road map ............................................................35

A. Configure radio 2............................................................35
B. Configure VSC profiles ...................................................35

Scenario 3: Shared hotspot for public and private traffic ................36

How it works.............................................................................36
Configuration road map ............................................................37

A. Define settings on the RADIUS servers ..........................37
B. Install the service controller and AP ...............................37
C. Switch the AP to autonomous mode ..............................37
Configure the service controller ..........................................37
A. Configure the Internet port .............................................37
B. Create two RADIUS profiles............................................37
C. Create VLANs..................................................................38
D. Create VSCs....................................................................38
E. Set the shared secret ......................................................39
Configure the AP.................................................................39
A. Create VSCs....................................................................39
B. Configure the connection to the service controller .........40

Scenario 4: Delivering custom HTML pages using VLANs ..............41

 How it works............................................................................41
Configuration road map ............................................................42

A. On the RADIUS server ....................................................42
B. Install the service controller and the APs........................42
C. Switch the APs to autonomous mode.............................42
D. Configure the wireless network ......................................42
Configure the service controller ..........................................42
A. Configure the Internet port .............................................42
B. Create a RADIUS profile..................................................43
C. Configure the service controller to retrieve attributes from
the RADIUS server..............................................................43
D. Create VLANs .................................................................43
E. Create VSCs ....................................................................44
F. Set the shared secret.......................................................45
Configure the APs ...............................................................45
A. Set static addressing and management VLAN ................45
B. Configure management VLAN.........................................45
C. Configure a VSC .............................................................46
D. Configure the connection to the service controller .........46

Scenario 5: Custom HTML pages on each AP.................................47

How it works.............................................................................47
Configuration road map ............................................................48

A. Install the service controller and the APs........................48
B. Switch the APs to autonomous mode.............................48
C. Create the custom web pages on the web server............48
Configure the APs ...............................................................49

Summary of Contents for MSM313

Page 1: ...ProCurve 5400zl Switches Installation and Getting Started Guide HP MSM313 MSM323 Integrated Services Access Points Deployment Guide HP MSM313 MSM323 Integrated Services Access Points Deployment Guide ...

Page 2: ......

Page 3: ...HP MSM313 MSM323 Integrated Services Access Points Deployment Guide ...

Page 4: ...re set forth in the express warranty statements accompanying such products and services Nothing herein should be construed as constituting an additional warranty Hewlett Packard shall not be liable for technical or editorial errors or omissions contained herein Hewlett Packard assumes no responsibility for the use or reliability of its software on equipment that is not furnished by Hewlett Packard...

Page 5: ... with satellites and roaming via RADIUS server 30 How it works 30 Configuration road map 30 A Install the APs 30 B Switch the APs to autonomous mode 30 C Configure the wireless network 31 D Set the shared secret on the service controller 31 E Configure the connection to the service controller on the APs 31 Scenario 2d Hotspot with layer 2 security AAA server 32 How it works 32 Configuration road m...

Page 6: ...r 3 Local mesh deployment 59 Scenario 1a Dynamic local mesh 60 How it works 60 Configuration road map 61 A Install the APs and the service controller 61 B Switch the APs to autonomous mode 61 AP configuration 61 A Configure addressing 61 B Configure the radios 62 C Configure the local mesh links 62 D Configure the connection to the service controller on the APs 63 E Create VSCs on the APs 63 Servi...

Page 7: ...Chapter 1 Introduction 1 Introduction Contents About this guide 6 Contacting support 7 Online documentation 7 ...

Page 8: ...ed This guide covers the following products MSM313 MSM313 R MSM323 MSM323 R MSM335 MSM310 MSM310 R MSM320 MSM320 R Important terms The following terms are used in this guide Conventions Management tool This guide uses specific syntax when directing you to interact with the management tool user interface Refer to this image for identification of key user interface elements and then the table below ...

Page 9: ...tions in this guide What to do in the user interface Select Security RADIUS profiles On the main menu select Security and then select RADIUS profiles on the sub menu For Password specify secret22 In the field Password enter the text secret22 exactly as shown Example Description use access list Command name Specify it as shown ip_address Items in italics are parameters for which you must supply a v...

Page 10: ...HP MSM313 MSM323 Deployment Guide 8 1 Introduction ...

Page 11: ...b Hotspot with custom interface via RADIUS server 25 Scenario 2c Hotspot with satellites and roaming via RADIUS server 28 Scenario 2d Hotspot with layer 2 security AAA server 30 Scenario 2e Using two radios to support A B G traffic 33 Scenario 3 Shared hotspot for public and private traffic 34 Scenario 4 Delivering custom HTML pages using VLANs 39 Scenario 5 Custom HTML pages on each AP 45 Scenari...

Page 12: ...or public guest network access deployments using MSM313 MSM323 Integrated Services Access Points operating alone or with one or more MSM Access Points Note In this chapter the MSM313 and MSM323 Integrated Services Access Points are often referred to as service controller and MSM Access Points are often referred to as AP ...

Page 13: ...red users The service controller acts as the DHCP server on both the wireless and wired networks which are bridged together on subnet 192 168 1 0 User authentication is handled locally by the service controller and accounts are created on the service controller for each user There is no support for accounting The default public access interface resident on the service controller is used to control...

Page 14: ...ressing option supported by your ISP and click Configure 3 Define all settings as required by your ISP D Define the list of users 1 Select Users Users 2 Add usernames and passwords for all users E Test the public access interface To test your installation use a wireless client station to log onto the public access interface The wireless client should be configured as a DHCP client 1 Start the clie...

Page 15: ...st networks 3 Specify a valid user name and password and click Go 4 The Session page should open and you are automatically redirected to the web site you originally requested Note The session page may not appear if your web browser has a popup blocker ...

Page 16: ...ce The service controller loads these pages instead of using the default pages In this version the web server is located on local LAN B however it could also be located on the Internet The router is also the DHCP server for LAN B operating on subnet 192 168 5 0 The service controller s Internet port is set to operate as a DHCP client Configuration road map Note Start with the configuration defined...

Page 17: ...e image file is shared by all pages 3 Copy the following files from the MSM Public Access Examples zip file to the newpages folder on the web server login html transport html session html fail html 4 Edit login html to meet the requirements of your site keeping the following restrictions in mind Do not alter the ID tags Colubris Custom located at the top of the page Do not alter any existing JavaS...

Page 18: ...our installation use a wireless client station to log onto the public access interface The wireless client should be configured as a DHCP client 1 Start the client station s web browser and try to connect to a web site on the Internet 2 The service controller will intercept the URL and display the Login page Depending on the type of certificate that is installed on the service controller you may s...

Page 19: ...lient and obtains its address from the service controller which by default is configured as the DHCP server User authentication is handled locally by the service controller using accounts created on the service controller for each user There is no support for accounting The following diagram illustrates how the topology described in Scenario 1b can be modified to support additional APs and roaming...

Page 20: ...shared secret on the service controller 1 Select Public access Access control 2 In the Access controller shared secret box set Shared secret and Confirm shared secret to a unique string For example xr2t56 This password will be used by the APs to connect to the service controller when they send authentication requests 3 Click Save E Configure the connection to the service controller on the APs Each...

Page 21: ... use Roaming is supported since the same VSCs are defined on all APs Configuration road map Note Start with the configuration defined in Scenario 1c A Create VSCs on the APs Follow this procedure to create three virtual service communities on all APs 1 Select VSC Profiles 2 On the Virtual Service Communities page click the HP ProCurve profile to edit it 3 On the Add Edit Virtual Service Community ...

Page 22: ... select the Use HP ProCurve MSM controller check box Under Virtual AP set WLAN name SSID to WPA Under Wireless protection Select the checkbox and leave the default setting of WPA For Mode select WPA TKIP or WPA2 AES CCMP For Key source select Preshared key For Key and Confirm key set a unique key value Click Save B Create VSCs on the service controller Follow this procedure to create virtual servi...

Page 23: ...characters you defined on the APs Click Save 6 On the Virtual Service Communities page click Add New Profile 7 On the Add Edit Virtual Service Community page Under General set Name to WPA Under Virtual AP set WLAN name SSID to WPA Under Wireless protection Select the checkbox and leave the default setting of WPA For Mode select WPA TKIP or WPA2 AES CCMP For Key source select Preshared key For Key ...

Page 24: ...ks which are bridged together on subnet 192 168 1 0 A RADIUS server provides services for user authentication and accounting The RADIUS server is located on local LAN B along with a router firewall which handles the connection to the Internet and acts as a DHCP server on LAN B Configuration road map A On the RADIUS server Define RADIUS accounts for all users that will use the public access network...

Page 25: ...ich must match the method supported by the RADIUS server 5 In the Primary RADIUS server box specify the address of the RADIUS server and the secret the service controller will use to login F Enable RADIUS authentication of users 1 Select VSC Profiles 2 On the Virtual Service Communities page click the HP ProCurve profile to edit it 3 On the Add Edit Virtual Service Community page Under HTML based ...

Page 26: ...certificate that is installed on the service controller you may see a security warning first Accept the certificate to continue 3 Specify a valid user name and password and click Go 4 The Session page should open and you automatically redirected to the web site you originally requested Note The session page may not appear if your web browser has a popup blocker ...

Page 27: ...e controller and presented to users in place of the default public access pages The following diagrams show how the two topologies described in Scenario 2a can be extended to support a web server In both cases the configuration procedure is the same Configuration road map Note Start with the configuration defined in Scenario 2a A Customize the login page and logo Before you can customize the pages...

Page 28: ...e service controllers RADIUS account login page 192 168 5 1 newpages login html transport page 192 168 5 1 newpages transport html session page 192 168 5 1 newpages session html fail page 192 168 5 1 newpages fail html logo 192 168 5 1 newpages logo gif Note The pages must be changed as a group So even if you did not change all the pages you must still supply new files for all the pages and define...

Page 29: ...ges D Test the public access interface To test your installation use a wireless client station to log onto the public access interface The wireless client should be configured as a DHCP client 1 Start the client station s web browser and try to connect to a web site on the Internet 2 The service controller will intercept the URL and display the Login page Depending on the type of certificate that ...

Page 30: ... since the same VSCs are defined on all access points Authentication of client stations is done by the service controller using accounts defined on a RADIUS server Configuration road map Note Start with the configuration defined in Scenario 2b A Install the APs Install the APs as described in the appropriate Quickstart guide B Switch the APs to autonomous mode By default the APs are configured to ...

Page 31: ...e Access controller shared secret box set Shared secret and Confirm shared secret to a unique string For example xr2t56 This password will be used by the APs to send authentication requests to the service controller 3 Click Save E Configure the connection to the service controller on the APs Configure the following on each AP 1 Select VSC Profiles 2 Click the HP ProCurve profile to edit it 3 In th...

Page 32: ...on that they want to use Roaming is supported since the same VSCs are defined on all access points Authentication of client stations is done by the service controller using accounts defined on a RADIUS server Configuration road map Note Start with the configuration defined in Scenario 2c A Create VSCs on the APs Follow this procedure to create three virtual service communities on all APs 1 Select ...

Page 33: ... setting of WPA For Mode select WPA TKIP or WPA2 AES CCMP Leave Key source as RADIUS Click Save 6 On the Virtual Service Communities page click Add new profile 7 On the Add Edit Virtual Service Community page Under General set Name to 8021X Under General select the Use HP ProCurve MSM controller check box Under Virtual AP set WLAN name SSID to 8021X Under Wireless protection Select the checkbox an...

Page 34: ...e select WPA TKIP or WPA2 AES CCMP Leave Key source as RADIUS For RADIUS profile select RADIUS Profile 1 which was defined in Scenario 2a Clear the HTML based user logins checkbox Under Access controlled clear the Redirect HTML users to login page checkbox Click Save 6 On the Virtual Service Communities page click Add new profile 7 On the Add Edit Virtual Service Community page Under General set N...

Page 35: ...de Radio 2 802 11a mode The two wireless profiles created in Scenario 2d are changed to transmit and receive on both radio 1 and radio 2 Users are now able to connect regardless of their radio type and since 802 11a users are on a separate radio they do not share bandwidth with users using 802 11 b g Network topology Note See scenario 2d for a diagram of the network topology Configuration road map...

Page 36: ... access for mobile employees Employees connect using the SSID Private and are routed to the corporate network on VLAN 50 The service controller authenticates employees using the Corporate RADIUS server Once authenticated employee traffic is forwarded on VLAN 50 so that it can reach the corporate intranet Employees use 802 1X to login The service controller validates their login credentials using t...

Page 37: ...will restart Configure the service controller A Configure the Internet port 1 Select Network Ports Internet port 2 Select No address Support VLAN traffic only 3 Click Save B Create two RADIUS profiles 1 Select Security RADIUS profiles 2 Click Add New Profile In the Profile name box assign CorporateRADIUS to the new profile In the Settings box use the defaults except for Authentication method which...

Page 38: ...ssign IP address via select DHCP client Click Save D Create VSCs Use the following steps to create two virtual service communities on the service controller Note This Private profile must be defined first to enable it to also support wired employees since untagged incoming traffic on the LAN port is always sent to the first VSC profile 1 Select VSC Profiles 2 On the Virtual Service Communities pag...

Page 39: ...thentication Advanced Settings 2 In the Access controller shared secret box set Shared secret and Confirm shared secret to a unique string For example xr2t56 This password will be used by the AP to send authentication requests to the service controller 3 Click Save Configure the AP A Create VSCs 1 Select VSC Profiles 2 On the Virtual Service Communities page click the HP ProCurve profile to edit i...

Page 40: ...e B Configure the connection to the service controller 1 Select Security Access controller 2 Set the Access controller shared secret to match the secret set on the service controller 3 Click Save By default the AP is set up to use the same default gateway assigned by DHCP as the access controller Do not change this setting ...

Page 41: ...ng The APs serving the hotel rooms on each floor are configured to return user traffic on VLAN 40 The APs serving the hotel lobby terrace and restaurant are configured to return user traffic on VLAN 50 VLAN 30 is defined for management purposes It is used by the network administrator to reach the management tool on the service controller and APs One advantage to this strategy is that it enables al...

Page 42: ...e appropriate Quickstart guide 2 Before you connect each unit to the LAN start the management tool and configure each unit as described in the sections that follow C Switch the APs to autonomous mode By default the APs are configured to operate in controlled mode Switch each one to autonomous mode as follows 1 Start the management tool and login 2 On the home page click Switch to Autonomous Mode T...

Page 43: ...troller to retrieve attributes from the RADIUS server 1 Select Public access Attributes 2 Select the Retrieve attributes using RADIUS option 3 Select the RADIUS profile you defined RADIUS Profile 1 4 Specify the username and password the service controller will use to login to the RADIUS server 5 Click Retrieve Now The service controller will login and retrieve the attributes 6 Click Save D Create...

Page 44: ...ed on the service controller Guest Used for APs installed in hotel rooms Forwards guest traffic on VLAN 40 Public Used for APs installed in public spaces Forwards public traffic on VLAN 50 1 Select VSC Profiles 2 On the Virtual Service Communities page click the HP ProCurve profile to edit it 3 On the Add Edit Virtual Service Community page Under General set Name to Guest Under General select the ...

Page 45: ...ng For example xr2t56 This password will be used by the APs to send authentication requests to the service controller 3 Click Save Configure the APs A Set static addressing and management VLAN 1 Select Network Ports 2 Under Port configuration click Bridge port Under Assign IP address via select Static then click the Configure button Define the following For each AP set IP address to a unique addre...

Page 46: ... HP ProCurve MSM controller check box Under Virtual AP set WLAN name SSID to Hotspot Under Egress VLAN If the AP is serving a hotel room set VLAN ID to 40 which corresponds to the Guest VLAN If the AP is serving a public area set VLAN ID to 50 which corresponds to the Public VLAN Click Save D Configure the connection to the service controller 1 Select Security Access controller 2 Set the Access co...

Page 47: ...ler using a locally defined user list To offer personalized service for each building a set of custom web pages are created for each building and stored in a separate folder on a web server A third party server on the Internet is used to keep costs down Users are redirected to the appropriate set of pages based on the location aware group name assigned to each AP About the location aware feature T...

Page 48: ...folder on the web server newpages 2 Create a file called logo gif that contains a custom logo for the service being offered and place it in newpages 3 Copy the following files from the MSM Public Access Examples zip file and place them in the newpages folder welcome html goodbye html fail html 4 Create the following three folders on the web server newpages complex_1 newpages complex_2 newpages com...

Page 49: ...k the HP ProCurve profile to edit it 3 Under General make sure that the Use HP ProCurve MSM controller checkbox is selected 4 Under Location aware For AP 1 set Group name to Complex_1 For AP 2 set Group name to Complex_2 For AP 3 set Group name to Complex_3 5 Click Save C Configure the connection to the service controller on the APs Each AP will use the services of the service controller to authen...

Page 50: ...alls these pages replacing the G with the group name assigned to the AP that the tenant is associated with login url web_server_URL newpages G login html welcome url web_server_URL newpages G welcome html goodbye url web_server_URL newpages G goodbye html By default the service controller blocks access to any resources that are connected to its Internet port until a client station successfully log...

Page 51: ...ic access interface To use the condo internet service tenants do the following Connect to the SSID HP ProCurve using 80211 b or g Start their web browser and specify the URL wireless colubris com which is the URL assigned to the service controller The service controller will redirect the browser to the login page on the web server After the tenant logs in and is validated the Welcome page is displ...

Page 52: ...series 3x3 service controllers are installed to offer public access networking at a number of different physical locations Each service controller is connected to the Internet using a broadband modem The Internet connection is protected by the service controller s firewall and NAT features A NOC network operations center is located at a remote site and provides a RADIUS server for authentication a...

Page 53: ...figure 3 Define all settings as required D Configure the wireless network By default the service controller is configured to support 802 11b g clients automatically choose the best operating channel frequency create a wireless network named HP ProCurve There is no need to change these settings for this scenario E Create a RADIUS profile 1 Select Security RADIUS profiles 2 Click Add New Profile In ...

Page 54: ...s than 20K This same image file is shared by all pages 3 Copy the following files from the MSM Public Access Examples zip file and place them in the newpages folder login html transport html session html fail html 4 Edit login html to meet the requirements of your site keeping the following restrictions in mind Do not alter the ID tags Colubris Custom located at the top of the page Do not alter an...

Page 55: ...he username and password the service controller will use to login to the RADIUS server 5 Click Retrieve Now The service controller will login and retrieve the attributes 6 Click Save J Using the public access interface To use the internet service users do the following Connect to the SSID HP ProCurve using 80211 b or g Start their web browser and specify the URL wireless colubris com which is the ...

Page 56: ...number of different physical locations The service controllers provide wireless network services at each site but do not authenticate users Instead all user traffic is forwarded to the third party access controller at the NOC via secure GRE tunnels Configuration road map A Install the service controllers 1 Install the service controllers at each site as described in the appropriate Quickstart guid...

Page 57: ...ings For Name specify a name for this profile For example GRE_Tunnel For Local tunnel IP address specify the IP address of the service controller inside the tunnel For Remote tunnel IP address specify the IP address inside the tunnel of the GRE terminator in the NOC For Tunnel IP mask specify the mask associated with the IP addresses inside the tunnel For GRE peer IP address specify the IP address...

Page 58: ...HP MSM313 MSM323 Deployment Guide 56 2 Public guest networks ...

Page 59: ...Chapter 3 Local mesh deployment 3 Local mesh deployment Contents Scenario 1a Dynamic local mesh 58 Scenario 1b Dynamic local mesh with load balancing 65 Scenario 2 Creating a self healing network 67 ...

Page 60: ...ts are referred to as service controllers and MSM Access Points are referred to as APs How it works In this scenario an MSM323 is used in conjunction with several dual radio APs to provide wireless networking to a large exhibition hall To eliminate setup time and to increase the flexibility of wireless coverage dynamic wireless bridges are used to link the APs to the backbone network The APs are c...

Page 61: ... are configured to operate in controlled mode Switch them to autonomous mode as follows 1 Start the management tool and login 2 On the home click Switch to Autonomous Mode The AP will restart 3 Before you connect each unit to the LAN start the management tool and configure each unit as described in the sections that follow AP configuration A Configure addressing By default APs operate as a DHCP cl...

Page 62: ...ly Set Wireless mode to 802 11b 802 11g Set Channel to Automatic 3 Under Radio 2 Set Operating mode to Local mesh only Set Wireless mode to 802 11a Set Channel to Automatic 4 Click Save C Configure the local mesh links Configure all APs as follows 1 Select Wireless Local mesh 2 Click Add New Profile 3 Set Name to Local mesh 1 4 Under Settings Select Enabled For Use select Radio 2 5 Under Security ...

Page 63: ... On the Virtual Service Communities page click the HP ProCurve profile to edit it 3 On the Add Edit Virtual Service Community page Under General set Name to None Under General select the Use HP ProCurve MSM controller check box Under Virtual AP set WLAN name SSID to None Click Save 4 On the Virtual Service Communities page click Add new profile 5 On the Add Edit Virtual Service Community page Unde...

Page 64: ...shared secret to a unique string For example xr2t56 This password will be used by the APs to send authentication requests to the service controller 3 Click Save C Create a RADIUS profile 1 Select Security RADIUS profiles 2 Click Add New Profile 3 In the Profile name box assign RADIUS Profile 1 to the new profile 4 In the Settings box use the defaults except for Authentication method which must mat...

Page 65: ...ng of WPA For Mode select WPA TKIP or WPA2 AES CCMP Leave Key source as RADIUS For RADIUS profile select RADIUS Profile 1 Clear the HTML based user logins checkbox Under Access controlled clear the Redirect HTML users to login page checkbox Click Save 6 On the Virtual Service Communities page click Add new profile 7 On the Add Edit Virtual Service Community page Under General set Name to 8021X Und...

Page 66: ... Click Save F Configure the local mesh link 1 Select Wireless Local mesh 2 Click Add New Profile 3 Set Name to Local mesh 1 4 Under Settings Select Enabled For Use select Radio 1 5 Under Security Enable the checkbox Select AES CCMP For PSK specify between 8 and 64 ASCII characters It is recommended that the key be at least 20 characters long and be a mix of letters and numbers 6 Under Addressing S...

Page 67: ...ks In this scenario service controller 2 is added to the network defined in Scenario 1a to support traffic from additional slaves Service controller 2 is also configured as a master node but with a different local mesh ID from service controller 1 As additional slaves are added to the network traffic can be balanced by setting their local mesh ID to either 1 or 2 Note The SSIDs created on service ...

Page 68: ...ngs used for the APs in scenario 1a with the following difference when configuring the local mesh links change the Mesh ID from its default setting of 1 to 2 B Install and configure service controller 2 Install and configure the service controller 2 with the same settings used for service controller 1 in scenario 1a with the following difference when configuring the local mesh links change the Mes...

Page 69: ...nodes The links between the nodes are automatically established based on a balance between SNR signal to noise ratio and hops to provide the most efficient network topology If a node becomes unavailable the links automatically adjust to find the optimum path to the master Router Firewall RADIUS server 192 168 5 0 5 1 5 2 Web server 5 3 ALTERNATE MASTER AP 1 MASTER Service controller ALTERNATE MAST...

Page 70: ...ent tool and configure each unit as described in the sections that follow AP configuration A Configure addressing By default APs operate as a DHCP client In the sample topology they are automatically assigned IP addresses by the DHCP server on the service controller To make the APs easier to manage however it may be useful to assign a static IP address to them as follows 1 Select Network Ports 2 U...

Page 71: ... follows 1 Select Wireless Local mesh 2 Click Add New Profile 3 Set Name to Local mesh 1 4 Under Settings Select Enabled For Use select Radio 2 5 Under Security Enable the checkbox Select AES CCMP For PSK specify between 8 and 63 ASCII characters It is recommended that the key be at least 20 characters long and be a mix of letters and numbers 6 Under Addressing Select Dynamic For Mode select Alter...

Page 72: ...al Service Community page Under General set Name to None Under General select the Use HP ProCurve MSM controller check box Under Virtual AP set WLAN name SSID to None Click Save 4 On the Virtual Service Communities page click Add new profile 5 On the Add Edit Virtual Service Community page Under General set Name to WPA Under General select the Use HP ProCurve MSM controller check box Under Virtual...

Page 73: ...que string For example xr2t56 This password will be used by the APs to send authentication requests to the service controller 3 Click Save C Create a RADIUS profile 1 Select Security RADIUS profiles 2 Click Add New Profile 3 In the Profile name box assign RADIUS Profile 1 to the new profile 4 In the Settings box use the defaults except for Authentication method which must match the method supporte...

Page 74: ...ng of WPA For Mode select WPA TKIP or WPA2 AES CCMP Leave Key source as RADIUS For RADIUS profile select RADIUS Profile 1 Clear the HTML based user logins checkbox Under Access controlled clear the Redirect HTML users to login page checkbox Click Save 6 On the Virtual Service Communities page click Add new profile 7 On the Add Edit Virtual Service Community page Under General set Name to 8021X Und...

Page 75: ...re the local mesh link 1 Select Wireless Local mesh 2 Click Add New Profile 3 Set Name to Local mesh 1 4 Under Settings Select Enabled For Use select Radio 1 5 Under Security Enable the checkbox Select AES CCMP For PSK specify between 8 and 64 ASCII characters It is recommended that the key be at least 20 characters long and be a mix of letters and numbers 6 Under Addressing Select Dynamic For Mod...

Page 76: ...HP MSM313 MSM323 Deployment Guide 74 3 Local mesh deployment ...

Page 77: ......

Page 78: ...rd Development Company L P The information contained herein is subject to change without notice The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services Nothing herein should be construed as constituting an additional warranty HP will not be liable for technical or editorial errors or omissions contained herein ...

Reviews: