Polycom MP-422 Configuration Manual Download Page 7

 

Trapeze Networks: Mobility System for MP 422 Access Points 

PN: 1725-36060-001_D.doc 

7

Service profile commands (SSID & security policy setup)  

WPA2-PSK 

Assume you are creating service profile “vowlan-wpa2” to define the 
ESSID “phones,” as well as a WPA2-PSK security policy. The 
following commands are needed to setup the service for MP access 
points: 

set service-profile Voice ssid-name vowlan-wpa2 

# sets the name of the service profile and SSID to 

vowlan-wpa2 

set service-profile Voice auth-fallthru last-resort 

# specifies the authentication for the service 
profile to open access 

set service-profile Voice rsn-ie enable 

# enables WPA2 security 

set service-profile Voice cipher-tkip disable 

# disables TKIP 

set service-profile Voice cipher-ccmp enable 

# enables AES / CCMP 

set service-profile Voice psk-phrase <passphrase> 

# defines a passphrase  

set service-profile Voice auth-psk enable 

# enables pre-shared key authentication 

set service-profile Voice auth-dot1x disable 

# disables 802.1x authentication  

set service-profile Voice attr vlan-name default 

# maps the handsets to the vlan named default 

WPA-PSK 

Assume you are creating service profile “vowlan-wpa” to define the 
ESSID “phones,” as well as a WPA-PSK security policy. The following 
commands are needed to setup the service for MP access points: 

set service-profile Voice ssid-name vowlan-wpa 

# sets the name of the service profile and SSID to 
vowlan-wpa 

set service-profile Voice auth-fallthru last-resort 

# specifies the authentication for the service 
profile to open access 

set service-profile Voice wpa-ie enable 

# enables WPA security 

set service-profile Voice psk-phrase <passphrase> 

Summary of Contents for MP-422

Page 1: ...June 2008 Edition 1725 36060 001 Version D VIEW Certified Configuration Guide Trapeze Networks Mobility System for MP 422 Access Points...

Page 2: ...onsible for printing or clerical errors Information in this document is subject to change without notice and does not represent a commitment on the part of Polycom Inc Notice Polycom Inc has prepared...

Page 3: ...ucts MX 400 MX 216 216R MX 200 200R MX 20 MX 8 MX 8R MXR 2 MP 422 Security WPA PSK and WPA2 PSK MX MP software version certified Release 5 0 11 4 SpectraLink handset models certified e340 h340 i640 80...

Page 4: ...h are not forwarded through the Mobility Exchange Switch when IGMP snooping is enabled When a tunneled virtual LAN VLAN is configured over a Layer 3 network IGMP snooping must be disabled each time th...

Page 5: ...cation It is important to note that these do not necessarily represent all Certified configurations Both Layer 2 and Layer 3 roaming were tested Layer 3 roaming of SpectraLink Wireless Telephones requ...

Page 6: ...mand xxxxxxxx Encryption key domain name or other information specific to your system that needs to be entered xxxxxxxx Comment about a command or set of commands xxxxxxxx System response or other dis...

Page 7: ...rofile Voice cipher ccmp enable enables AES CCMP set service profile Voice psk phrase passphrase defines a passphrase set service profile Voice auth psk enable enables pre shared key authentication se...

Page 8: ...P from going off channel to scan set radio profile voice auto tune channel config disable disables dynamic channel tuning for radios in this profile set radio profile voice qos mode svp qos mode SVP m...

Page 9: ...1 mode disable if the radio is currently enabled Radio 1 is the 802 11b g radio set dap 1 radio 1 radio profile voice mode enable maps radio to the radio profile and enables it SVP configuration The f...

Page 10: ...other member MX switch set system ip address 1 1 3 1 set mobility domain mode member seed ip 1 1 1 1 Be sure to disable IGMP snooping temporarily on the MX that does NOT have the VLAN statically conf...

Page 11: ...o 1 1 2 Background 0 0 3 BestEffort 604 4 5 Video 0 6 7 Voice 79106 Voice should have the most traffic port 1 radio 2 1 2 Background 0 0 3 BestEffort 0 4 5 Video 0 6 7 Voice 0 The switch and AP are no...

Page 12: ...nable severity error set log session disable severity info set log buffer enable severity error set log trace enable severity debug mbytes 1 set web aaa enable set dot1x timeout supplicant 30 set dot1...

Page 13: ...service profile VoWLAN WPA tkip mc time 60000 set radius deadtime 0 set radius timeout 5 set radius retransmit 3 set enablepass password password set authentication admin local AP Radio Profile set ra...

Page 14: ...config disable set radio profile default auto tune channel interval 3600 set radio profile default auto tune power interval 600 set radio profile default auto tune channel holddown 300 set radio profi...

Page 15: ...rate 24 max_retransmissions 10 set arp agingtime 1200 set ip https server disable set ip snmp server disable set ip ssh server enable set ip ssh 22 set ip telnet server enable set ip telnet 23 set po...

Page 16: ...gmp oqi 255 vlan 1 set igmp qri 100 vlan 1 set igmp lmqi 10 vlan 1 set igmp rv 2 vlan 1 set igmp mrouter port 3 disable set igmp receiver port 3 disable disable router and receivers on other ports as...

Reviews: