background image

http://www.3com.com/

Part No. 730-9502-0077, Revision 

B

Published 

November 

2004

Wireless LAN Mobility System

Wireless LAN Switch Manager
Reference Manual

3CRWX120695A, 3CRWX440095A

Summary of Contents for 3CRWX120695A

Page 1: ...http www 3com com Part No 730 9502 0077 Revision B Published November 2004 Wireless LAN Mobility System Wireless LAN Switch Manager Reference Manual 3CRWX120695A 3CRWX440095A...

Page 2: ...une 1987 whichever is applicable You agree not to remove or deface any portion of any legend provided on any licensed program or documentation contained in or delivered to you in conjunction with this...

Page 3: ...vileges 21 Serial Number and License Key 21 HP OpenView Network Node Manager 22 Installation Task Overview 22 Unpacking Files 22 Using the Installation Wizard 23 Installing the HP OpenView Plug In 28...

Page 4: ...ETTING STARTED Starting 3WXM 71 Restricting Access to 3WXM 75 Creating an Administrator Account 75 Creating Provision or Monitor Accounts 77 Deleting 3WXM User Accounts 77 Disabling Access Control 77...

Page 5: ...26 Changing an Individual Floor s Properties 127 Specifying the RF Characteristics of a Floor 128 Recommendations 129 Converting Objects into RF Obstacles 129 Drawing RF Obstacles 132 Defining Wireles...

Page 6: ...To create a new WX switch based on a configured switch 184 To add a switch by uploading its basic configuration from the network 184 Accessing the Modify Switch Wizard 185 Configuring Basic WX Proper...

Page 7: ...ring an SSID 255 Configuring a Service Profile 257 Configuring Encryption 260 Mapping a Service Profile to a Radio Profile 264 Configuring a Radio Profile 265 To create a radio profile 266 To change 8...

Page 8: ...dress Globs 317 Creating Administrator and Console Access Rules 318 Managing Administrator and Console Access Rules 323 Configuring and Managing Access Rules for Network Users 323 Authentication 324 A...

Page 9: ...390 To deploy network plan changes to the network 391 To deploy WX switches from a network plan to the network 392 Distributing Image and Configuration Files 393 Using the Image Repository 393 Distri...

Page 10: ...ng Client Session Information 432 Managing the Client Watch List 440 Displaying a Client s Geographical Location 445 Terminating a Client s Session 445 Using the RF Monitor Window 446 Displaying RF Ne...

Page 11: ...nown addresses list 479 To display the known address list 479 To remove an address from the known address list 480 Converting a Rogue into a Third Party AP 480 To convert a rogue into a third party AP...

Page 12: ...g Tools Options 506 Changing Certificate Management Options 507 Changing Options for RF Planning 508 Configuring the Typical Client s Transmit Power 508 Changing Colors 509 Changing 3WXM Logging Optio...

Page 13: ...Database 558 Restoring the Database 558 E OBTAINING SUPPORT FOR YOUR PRODUCT Register Your Product 561 Purchase Value Added Services 561 Troubleshoot Online 561 Access Software Downloads 562 Telephon...

Page 14: ......

Page 15: ...ation in this guide follow the instructions in the release notes Most user guides and release notes are available in Adobe Acrobat Reader Portable Document Format PDF or HTML on the 3Com World Wide We...

Page 16: ...Conventions Convention Description Menu Name Command Indicates a menu item that you select For example File New indicates that you select New from the File menu Monospace text Sets off command syntax...

Page 17: ...SS CLI Wireless LAN Switch and Controller Command Reference This reference provides syntax information for all MSS commands supported on WX switches Documentation Comments Your suggestions are very im...

Page 18: ...18 ABOUT THIS GUIDE...

Page 19: ...When combining client and monitoring services on the same machine please use the requirements indicated for the monitoring service The monitoring service is not required to configure and manage WX sw...

Page 20: ...ch supported on the following operating systems Microsoft Windows Server 2003 Microsoft Windows XP with Service Pack 1 SP1 or later Microsoft Windows 2000 with Service Pack 4 Table 4 Hardware Requirem...

Page 21: ...integrate 3WXM into an HP OpenView environment make sure that HP OpenView is already installed User Privileges Before you install 3WXM make sure that you are logged in as a user who has permission to...

Page 22: ...ation Unpack files See Unpacking Files on page 22 Use the installation wizard See Using the Installation Wizard on page 23 Install the HP OpenView plug in optional See Installing the HP OpenView Plug...

Page 23: ...WXM and the plug in required to use HP OpenView Network Node Manager with 3Com products click the 3WXM HP OpenView Plug in icon If you do not choose this option now and later you want to use HP OpenVi...

Page 24: ...ding the 3WXM license agreement select whether to accept the terms of the agreement If you choose not to accept the terms of the license agreement you cannot proceed with the installation 4 Click Next...

Page 25: ...e and browsing the filesystem To revert to the default installation directory click Restore Default Folder 6 Click Next The Choose Network Plan Folder page appears 7 Type the name of the directory in...

Page 26: ...able if the monitoring service is not installed The monitoring service is started automatically when you complete installation and starts automatically whenever you restart your system See Starting or...

Page 27: ...ges 13 Click Install The installer installs the 3WXM client application 3WXM The monitoring service also is installed if you left this option selected When installation is complete you see a page simi...

Page 28: ...tion on getting started with 3WXM Installing the HP OpenView Plug In To install the HP OpenView plug in 1 Complete step 10 of the procedure in Using the Installation Wizard on page 23 2 In the Choose...

Page 29: ...ready be installed on the system You must specify the correct directory for Network Node Manager for the HP OpenView plug in to be installed correctly The default Network Node Manager installation dir...

Page 30: ...yed to report that the installation was successful The page also identifies the directory in which 3WXM was installed 9 Click Done See Getting Started on page 71 for more information on getting starte...

Page 31: ...on a regular basis to ensure that you have copies of your network plans CAUTION If you uninstall a previous version of 3WXM before upgrading make sure you do not delete the serial number Uninstalling...

Page 32: ...nerate a new serial number if it is ever reinstalled You will then require new licenses to register against the new serial number If you delete the serial number the license information will also be d...

Page 33: ...Uninstalling 3WXM 33...

Page 34: ...34 CHAPTER 1 INSTALLING 3WXM...

Page 35: ...n a network plan you define components of the network WX switches MAP access points and optionally third party access points Regardless of whether you intend to use physical planning features you must...

Page 36: ...window also contains panels for navigating to and displaying information The main 3WXM window contains the following panels See Figure 1 on page 36 Organizer panel Provides a tree like display of obj...

Page 37: ...th 3WXM usernames When you close 3WXM 3WXM remembers the panel sizes and window arrangements you assigned and restores them the next time you run 3WXM The Network Activity icon displays statistics for...

Page 38: ...rt Import a WX configuration file Export Export a WX configuration file Exit Close 3WXM Edit Insert Add an object This option displays a wizard to a child object to the selected object in the Organize...

Page 39: ...in the tab remain focused on the object that was selected in the Organizer panel when you opened the new tab The content does not change when you select another object To distinguish between the two...

Page 40: ...image and configuration information to WX switches Distribute Certificates Distribute certificates to WX switches box Reboot WX MAP Devices Reboot WX switches or MAP access points Apply Auto Tune Sett...

Page 41: ...tes Watch List Client Generate a report of detailed information for a client on the watch list For more information about the client watch list see Managing the Client Watch List on page 440 Network U...

Page 42: ...n a Telnet connection to a selected device Launch Browser Open a Web connection to a selected device Window Close All Close all tabs or windows that are open in the Content panel This menu also has an...

Page 43: ...ections Mobility Domains Roaming domains of 3Com switches and MAP access points within which network clients can roam Sites Named sets of buildings and floors where 3Com equipment is deployed About 3W...

Page 44: ...to display the buildings in a site click on the plus sign next to the site name To display the floors in the building click next to the building name and so on Details Checkbox In the Mobility Domain...

Page 45: ...r an object in the Organizer panel select the object Details about the object appear in the Information panel located at the bottom right of the main 3WXM window For example select a Mobility Domain t...

Page 46: ...WX switch to another within the network 3WXM contains a default Mobility Domain that you can copy or modify You also can create new Mobility Domains A Mobility Domain contains the following types of...

Page 47: ...ard see Accessing the Modify Switch Wizard on page 185 To edit configuration parameters for an object right click on the object s icon and select Properties To create a new instance of an object where...

Page 48: ...ier SSID names and the network access rules and service profiles associated with each SSID Radio Profiles Sets of radio parameters that can be applied to multiple radios including the beacon interval...

Page 49: ...ettings Address Resolution Protocol ARP settings Table 8 WX Switch Objects Object Description Management Services Same as Management Services in Domain Polices but applicable to this WX switch only Ra...

Page 50: ...Services in Domain Polices but applicable to this WX switch only 802 1X Same as Management Services in Domain Polices but applicable to this WX switch only ACLs Same as Management Services in Domain P...

Page 51: ...appears to alert you when a new warning or error condition occurs Warnings are indicated with a yellow flag and errors are indicated with a red flag Here is an example of the warning flag Table 10 Si...

Page 52: ...differences between all WX switches in the network and their counterparts in the network plan Select this alert to open the Network Verification tab of the Verification tab in the Content panel You ca...

Page 53: ...ze maximize or close a window by clicking on the corresponding option in the upper left corner of the window For example to close a window click on the close button the X Monitor Tab The Monitor tab d...

Page 54: ...ent object in the Organizer panel The View Monitor in new Window or Monitor in new Window option continues to display data for the same object even if you select another object after opening the tab Y...

Page 55: ...s selected In either view the operational status of 3Com equipment is indicated by the following colors Green Up Yellow Up but with minor service degradation Orange Up but with major service degradati...

Page 56: ...lumn shows the equipment status using the same colors as the Explore window Additional information is displayed for each equipment type You can double click on a row in the Status Summary window to di...

Page 57: ...abs Client Activity displays association and 802 1X information for the clients Client Sessions lists bandwidth signal to noise ratio SNR and received signal strength indicator RSSI information for cl...

Page 58: ...ironment lists 802 11 statistics for the radio Monitor Tab RF Trends Window The RF trends window shows current and historical 802 11 statistics and shows graphs of the data You can graph absolute valu...

Page 59: ...verify the results If you want to instead disregard specific error or warning messages you can disable the messages The verification tab has two pages a Config Verification page and a Network Verifica...

Page 60: ...running on WX switches continually performs RF scans to detect rogue access points Normally if a scan detects a third party access point MSS assumes the access point is a rogue and issues countermeas...

Page 61: ...Panel 61 You can display data about rogues that are currently in operation as well as currently inactive rogues that were detected in the past You can even display the estimated physical location of...

Page 62: ...d 3Com equipment The wizards provide a general workflow for configuration and enable you to easily set or change the parameters for an object You display the configuration wizard for an object by sele...

Page 63: ...utton saves the changes you make in the wizard CAUTION None of the information you enter in a wizard is saved until you click Finish If you want to stop working in a wizard and return to finish later...

Page 64: ...WXM USER INTERFACE Clicking the New RADIUS Server button opens the Create RADIUS Server wizard The Modify RADIUS Server wizard remains open in the background After you enter information in the Create...

Page 65: ...wo of the wizards are more complex Building wizard Enables you to import or create floor drawings characterize RF obstacles plan wireless coverage and generate work orders for 3Com equipment installat...

Page 66: ...t Mobility Domain Configuration WX Configuration Network client reports Client Summary Client Details Client Errors Watch List Client RF reports Network Usage RF Summary Radio Details Rogue reports Ro...

Page 67: ...e the copy and paste options to create a new object Use the copy and paste replace options to replace an object with a copy of another instance of the same type of object You can copy and paste object...

Page 68: ...ew WX switch in a Mobility Domain 1 Expand the view of a Mobility Domain in the Organizer panel to display the WX switches in the Mobility Domain 2 Select the switch you want to copy then right click...

Page 69: ...s as needed For example you will need to modify the switch name as well as its IP interfaces and system IP address Then click Finish to close the wizard and complete the copy The new switch appears un...

Page 70: ...Effects 4 Clear the box labeled Hide underlined letters for keyboard navigation until I press the Alt key Clearing this option allows programs to show the underlined character for mnemonics in 3WXM 5...

Page 71: ...main Starting 3WXM The following steps describe how to start 3WXM 1 To start 3WXM select Start Programs 3Com 3WXM 3WXM or double click the 3WXM icon on the desktop If you are starting 3WXM for the fir...

Page 72: ...btain an activation key 4 Copy the activation key from the web page and paste it into the Activation Key box of the Activation Key page 5 If you plan to manage 10 or fewer wireless LAN switches click...

Page 73: ...Type the upgrade license key in the License Key box and click Next The Activation Key page appears 7 Click Get Activation Key A 3Com web page appears Register your upgrade license in order to obtain...

Page 74: ...an If you select this option wizard pages guide you in setting up a network plan For more information see Creating and Managing Network Plans on page 78 Open an existing network plan You can open one...

Page 75: ...can run 3WXM You can restrict the users allowed to access 3WXM on a system and define their access privileges by creating three types of 3WXM user accounts Administrator This account can monitor the...

Page 76: ...plication The Add Account dialog box appears The name of the user currently logged in appears in the Account Name box 3 Type a new password for the administrator 1 to 80 alphanumeric characters with n...

Page 77: ...hanges Deleting 3WXM User Accounts To delete a 3WXM user account 1 Select Tools Access Control The Access Control dialog box appears 2 Select a user account from the Allowed Accounts list 3 Click Remo...

Page 78: ...a network plan can represent a campuswide network You also can define a physical representation of the network sites buildings and floors In this case you can import drawings of your floor plans into...

Page 79: ...be deployed You must select a country code before continuing 4 In the Channel Set list select the set of operating channels for any 802 11b g MAP radios you plan to use The choices in the list are de...

Page 80: ...eatures go to Configuring WX System and Administrative Parameters on page 177 Click Finish to save the changes and close the wizard 3WXM saves your work only when you click Finish not when you click N...

Page 81: ...ve a network plan 1 In the main 3WXM window select File Save 2 Click Finish You can also save a network plan with a new name enable the autosave option so that a network plan is saved at specified int...

Page 82: ...y you can select an existing network plan name to replace it 3 Click Next You see the status of the save process 4 Click Finish Saving Versions of Network Plans You can save multiple versions of a net...

Page 83: ...ion name in the title bar of the main 3WXM window To save a version of a network plan 1 Select File Save As Version 2 In the Version Label box type the label to be associated with this version of the...

Page 84: ...can be used to roll back configuration changes For more information see Saving Versions of Network Plans on page 82 Opening a Network Plan Every time you start 3WXM you have the option to open one of...

Page 85: ...g a Network Plan You can close a network plan at any time If you have unsaved changes you are asked whether you want to save the changes To close a network plan 1 In the main 3WXM window select File C...

Page 86: ...indow select File Delete Network Plan The Delete Network Plan wizard appears 2 Select the network plan you want to delete from the list 3 Click Next The network plan is deleted 4 Click Finish Sharing...

Page 87: ...locked plan 1 To override the lock and open the plan in edit mode select Override lock and enter edit mode This option is available only if you have administrator privileges 2 To include pending chan...

Page 88: ...n Interval box 5 Click Close Defining a Mobility Domain A Mobility Domain is a collection of WX switches that work together to support roaming users One of the WX switches is defined as a seed device...

Page 89: ...authorization failure clears the client session Depending on when the failure occurs roaming can be disqualified or delayed The client uses the same authorization parameters for the new session as for...

Page 90: ...etween them Within a Mobility Domain the WX switches exchange information and other types of traffic depending on your configuration of AAA and various management services Table 12 provides a summary...

Page 91: ...window select Edit Insert Mobility Domain In the Network Plan wizard click Mobility Domain at the top of the wizard then click New Mobility Domain 2 In the Mobility Domain Name box type the name for...

Page 92: ...92 CHAPTER 3 GETTING STARTED 4 Do one of the following To close the wizard click Finish To create a WX switch and add it to the Mobility Domain see Adding a WX Switch to the Network Plan on page 183...

Page 93: ...erage needs You can display projected coverage and even experiment with network changes In addition when you add the geographical information about your network to 3WXM you can use 3WXM to visually fi...

Page 94: ...on how you access the wizard the wizard s title can be Create Building Modify Building Create Floor or Modify Floor The wizard is the same regardless of the title The Building wizard contains the fol...

Page 95: ...tings for unit of measurement and ceiling attenuation Table 13 lists the toolbar icons in the edit options area of the page Table 13 Toolbar Options on Setup Page Option Description Edit floor propert...

Page 96: ...fy imported floor drawings or create new ones and characterize RF obstacles You can assign attenuation information to objects The edit options area has icons for free drawing objects and for inserting...

Page 97: ...Open the Information pane The Information pane appears under the Floor display Show the zoom navigator pane Zoom in Zoom out Fit view in window Print the view displayed in the Floor display area Copy...

Page 98: ...3Com access points You also can calculate channel and power settings although 3Com access points are enabled to configure their own channel and power settings by default The edit options area has ico...

Page 99: ...on Plan RF Coverage Page Option Description Define the drawing scale Change the grid size Open the Information pane The Information pane appears under the floor display area Show the zoom navigator p...

Page 100: ...also can display 3Com equipment inventories and other network information Table 16 lists the toolbar icons at the top of the floor display area Table 16 Toolbar Options on Report Page Option Descripti...

Page 101: ...ter you have saved the plan The wizards for configuring network plans and sites have additional pages for creating or modifying Mobility Domains and third party access points APs For information about...

Page 102: ...ork plan To create a site when you create a network plan use the following procedure 1 Access the Create Network Plan wizard if not already open Then type the plan name and select the country code and...

Page 103: ...Creating a Site 103 3 Click New Site The Create Site wizard appears 4 In the Site Name box type a name for the site 1 to 80 alphanumeric characters with no spaces or tabs...

Page 104: ...ure building information click Next and see Creating or Modifying Buildings in a Site on page 106 To save the changes and close the wizard click Finish To create a site in a saved network plan To crea...

Page 105: ...Creating a Site 105 4 Click New Site The Create Site wizard appears 5 In the Site Name box type a name for the site 1 to 80 alphanumeric characters with no spaces or tabs...

Page 106: ...following To configure building information click Next and see Creating or Modifying Buildings in a Site To save the changes and close the wizard click Finish Creating or Modifying Buildings in a Sit...

Page 107: ...t this manual unless otherwise noted references to a Create or Modify wizard apply whether the wizard says Create or Modify at the top 3 In the Building Name box type the name of the building 1 to 30...

Page 108: ...Do one of the following Click the Floor Defaults tab to change the default values for unit of measurement ceiling height and attenuation caused by ceilings See Modifying Floor Defaults Click Next to c...

Page 109: ...gnore Changes to clear the changes without applying them 7 Do one of the following Click Next to configure floor information for the building See Importing or Drawing Floor Details Click Finish to sav...

Page 110: ...use a DWG or DXF drawing These types of drawings are made of vector graphics line objects lines which you can easily convert into RF obstacles after importing the drawing into 3WXM In addition the dra...

Page 111: ...th all layers unfrozen and visible In AutoCAD when you load the drawing file you might see messages about the files not being found To check for external references you can select Insert Xref Manager...

Page 112: ...es and so is unnecessary in the floor plan The information you need to keep is the structural information to which you will assign RF values in 3WXM To check the contents of the invisible layers to ma...

Page 113: ...you can easily select all objects in the layer and assign the same RF attenuation value to them Create RF IntWalls for interior walls and RF Windows for windows If walls or windows are shown with mult...

Page 114: ...ame and number then click on the toolbar Go to step 4 In the Building wizard click Edit Content at the top of the wizard An empty Floor View tab appears in the View panel Go to step 2 Table 17 Operati...

Page 115: ...click Open The drawing appears After you import a drawing 3WXM remembers the directory you chose If you originally imported a DXF or DWG file you can import a DXF DWG GIF or JPEG file and layer it ove...

Page 116: ...es how to adjust the scale The drawing is displayed in the View panel Figure 2 Floor Plan After Importing 6 Do one of the following Click Finish to save the changes and close the wizard Change floor p...

Page 117: ...permanently removed To crop the paper space 1 Access the floor plan in the Edit Content page 2 Click con the toolbar 3 Click and diagonally drag the cursor over the area you want to keep 4 Release the...

Page 118: ...ors are located so that 3WXM can take RF from those MAPs into account when assigning channels If an imported drawing has an origin point defined 3WXM tries to use that origin point Otherwise 3WXM plac...

Page 119: ...erior walls by moving the origin farther up and left To adjust the origin point 1 Access the floor plan in the Edit Content page 2 Drag and drop the crosshairs icon to the new location The following e...

Page 120: ...f the drawing because the units used in these drawings might not have a one to one correspondence to meters and feet To adjust the scale of the drawing you draw a line between two points of known dist...

Page 121: ...calculations only with information in visible layers Each drawing that you import into 3WXM has a layer 0 which contains information that 3WXM creates You can hide layer 0 but you cannot delete it an...

Page 122: ...To add a new layer to a drawing do the following in the Edit Content page 1 Right click the list of layers next to the View panel 2 Select Add Layer from the menu that is displayed 3WXM adds the new l...

Page 123: ...down arrow to display the list of layers in the drawing and select the layer to which you want to move the object s 4 Click OK Cleaning Up a Drawing 3WXM can simplify an imported CAD drawing by remov...

Page 124: ...p 3WXM removes all these items by default 3 To change the short line length type the new length in the Short Line Length box 3WXM removes all lines that are this length or shorter 4 To change the para...

Page 125: ...lect the layers you want to clean up You can select individual layers or all layers 3WXM removes the specified objects only from the layers you select By default no layers are selected 7 Click Next Th...

Page 126: ...ancel the changes Drawing Floor Objects Manually You can use the Free Draw palette to add objects to your floor drawing that are not related to RF obstacles for example a conference room table The too...

Page 127: ...oor Properties dialog box appears Object Action circle Diagonally drag the cursor over the area where you want the circle to appear square Diagonally drag the cursor over the area where you want the s...

Page 128: ...attenuation information in the floor plan when calculating how many MAPs you need and where to place them to provide the wireless coverage required for the floor The RF attenuation information comes...

Page 129: ...bjects in a layer of a CAD drawing into RF obstacles Convert all objects in an area of the drawing into RF obstacles Convert multiple objects in the drawing into RF obstacles Convert grouped objects i...

Page 130: ...veral objects in a drawing to specify them as one RF obstacle For example if a wall consists of several lines the lines can be grouped If you subsequently ungroup the objects the RF obstacle informati...

Page 131: ...11a and 802 11b g technology 0 to 100 dB The default is the typical attenuation factor for the material chosen 4 Click Finish to save the changes and close the dialog box If you created RF obstacles...

Page 132: ...r the area where you want the square to appear 3WXM treats squares as one solid object when calculating RF attenuation To draw a square outline draw four lines in a square shape which are treated as f...

Page 133: ...planned for general use with lower bandwidth requirements You must also identify the wireless technology required 802 11a or 802 11b g for coverage areas For areas requiring multiple wireless technolo...

Page 134: ...set and specify them as switches to be used when 3WXM calculates how many MAP access points are required If you do not have any WX switches placed in the wiring closet 3WXM automatically creates and c...

Page 135: ...3 In the Name box type the name of the wiring closet 1 to 60 characters with no tabs 4 If you have not defined a WX switch in 3WXM click Finish to save the changes Otherwise go to step 5 3WXM determin...

Page 136: ...w the coverage area on the floor See Drawing a Coverage Area on page 138 2 Specify the wireless technology to be used in the coverage area See Specifying the Wireless Technology for a Coverage Area on...

Page 137: ...s can overlap Figure 7 Unsupported Shared Coverage Area Example Keep the following in mind when planning shared coverage areas Two coverage areas using the same wireless technology cannot be shared A...

Page 138: ...re not too close Figure 8 Unsupported Polygon Shape If you are using a complex concave polygon as a coverage area computation of MAP access points might take longer than the computation for an area wi...

Page 139: ...ram 1 Click at a vertex and drag the cursor to the next vertex 2 Click again and drag the cursor until the parallelogram takes the shape you want 3 Click to finish polygon 1 Click at a vertex then mov...

Page 140: ...overage Area Specifying the Wireless Technology for a Coverage Area To draw a coverage area see Drawing a Coverage Area on page 138 To specify wireless technology for a coverage area 1 In the Technolo...

Page 141: ...two areas that completely overlap each other one area for 802 11a and another for 802 11b g An area requiring 802 11a and 802 11b uses a dual radio MAP model for calculation even if you specify a sing...

Page 142: ...ology selection is correct 3 For 802 11g to prevent the association of 802 11b clients to any radio in this coverage area select Exclude 802 11b clients To allow 802 11b clients to associate to radios...

Page 143: ...cond Kbps for a station The throughput value cannot exceed the value you selected for the baseline association rate in step 8 3Com recommends that per station throughput values do not exceed 1 Mbps fo...

Page 144: ...ain that contains the MAPs used for this coverage area 2 In the Radio Profile list select the radio profile used for this coverage area The profiles available depend on the Mobility Domain you selecte...

Page 145: ...switches through the network a wiring closet is not required 6 In the Redundant Wiring Closet list select the wiring closet that will provide redundant connection to the MAP access points This is req...

Page 146: ...eight in the MAP Placement Height box 12 To change the WX switch model select the model from the Use WX Type list WX1200 Provides eight 10 100 Ethernet ports the first six of which support PoE WX4400...

Page 147: ...Distributed MAPs can be indirectly attached through intermediate Layer 2 or Layer 3 devices If the MAP access points are directly connected to the WX ensure that UTP Cat 5 cabling distances between th...

Page 148: ...ct MAP connections only 20 To change the number of redundant connections for the distributed connection type type the number in the Redundant Level box For direct connections the redundancy level is a...

Page 149: ...dio 802 11a and 802 11b or 802 11b g AP Single Radio 802 11a 802 11b or 802 11g 4 Select one of the following 11a 11b 11g The choices available depend on the selection you made in step 3 5 In the Name...

Page 150: ...oor list select the floor on which the access point is located The list shows the floors you created 12 Do one of the following To close the wizard and save the changes click Finish To configure radio...

Page 151: ...Location When you finish creating a third party AP 3WXM places an icon for the AP on the Objects To Place tab for the floor from which you can move it to its location 1 In the Building wizard navigate...

Page 152: ...s when you make adjustments to MAP location or power levels Computing and Placing MAP Access Points for a Coverage Area When you perform Compute and Place for one or more coverage areas 3WXM automatic...

Page 153: ...s points See To compute and place MAP access points on page 156 3 Review coverage area computation progress See To review coverage area computation on page 157 To specify design constraints 1 In the C...

Page 154: ...adio model MP 341 Single radio model MP 252 Dual radio model MP 241 Single radio model MP 52 Dual radio model MP 122 Dual radio model MP 101 Single radio model AP Single Radio Third party single radio...

Page 155: ...er models with one Ethernet port can support redundant distributed connections 10 To use the same WX switch for redundant connections select Use the Same WX for Redundancy This option places both of a...

Page 156: ...polygon as a coverage area computation of MAP access points might take longer than the computation for a simpler area To compute and place MAP access points 1 On the Plan RF Coverage page click on Co...

Page 157: ...column to display the wiring closet list and select a wiring closet from the list This step is optional 5 Click Next The Coverage Area Progress page appears 6 Go to To review coverage area computatio...

Page 158: ...rea either in the organizer list or on the floor and select Show RF Coverage If the area supports more than one radio technology you also need to select the technology The choices available depend on...

Page 159: ...k the MAP or radio and select one of the following Show RF Coverage 802 11a Show RF Coverage 802 11b Show RF Coverage 802 11g The choices available depend on the wireless technology you chose for the...

Page 160: ...verage Areas After you create a coverage area it is locked If you need to move or resize a coverage area you can unlock it To unlock a coverage area 1 Select the coverage area on the floor or from the...

Page 161: ...MAP in the network and you want to add it to the network plan do the following 1 Use the Network Verification tab to upload the MAP configuration into 3WXM See Verifying Configuration Information on...

Page 162: ...ons when calculating optimal power If you changed a MAP model to MP 341 MP 352 or MP 262 and you are using an external antenna specify the antenna model and the direction of the antenna s coverage bef...

Page 163: ...e or more coverage areas could not be optimized show the RF coverage at baseline association and minimum transmit rates for the coverage areas by doing the following 1 In the Show RF coverage using li...

Page 164: ...o not plan to use the RF Auto Tuning feature to automatically set the channels on the MAPs after deployment and installation use the Assign Channels to MAPs option to assign channels to the MAPs Appro...

Page 165: ...must be lower than or equal to the starting floor number 4 To change the radio type for which to assign channels select the radio type from the Technology list By default 3WXM assigns channels for al...

Page 166: ...802 11b g channel assignments are listed on the 802 11b g Radio s tab 8 Click Finish to accept the channel assignments The new channel assignments are reflected in the Coverage Areas panel 9 Do one o...

Page 167: ...or below do the following 4 In the Coverage Areas section navigate to the floor 5 Expand the floor to display its coverage areas 6 Right click on a coverage area and select Show RF Coverage 7 Select t...

Page 168: ...he floor 3 Modify the coverage area so that the capacity requirements are higher If you manually add MAP access points to a coverage area they might be moved or removed when you next perform Compute a...

Page 169: ...nt select Show Unreachable MAPs To list disabled access points select Show Disabled MAPs To list access on other floors that can be detected from this RF measurement point select Show MAPs on Other Fl...

Page 170: ...from that measurement point are shown in the RF measurement table X Y coordinates for the measurement point and display options are also available to customize the RSSI table Using this interactive m...

Page 171: ...wing information Floor layout with MAP access points and other objects defined for the floor List of MAPs Work order Accessing the Report Page To access the Report page 1 Open the Building wizard see...

Page 172: ...G THE 3COM MOBILITY SYSTEM Reviewing Layout Information To see the floor layout click View Layout Reviewing the MAP List To review the MAP list click View MAP List The list of MAP access points appear...

Page 173: ...power level for each MAP access point Coverage area in which each MAP access point is located Generating a Work Order You can generate a work order as part of your wireless network planning The work...

Page 174: ...er Floors only available if RSSI Projections is selected 2 In the Language list select English or German The language you select is the language used when you next access this page 3 To select the dir...

Page 175: ...o close the wizard Applying RF Auto Tuning Settings to the Network Plan If RF Auto Tuning is running on MAP radios in the network you can update the radios in the network plan with the channel and pow...

Page 176: ...the change is also applied to the Domain Policies in the Mobility Domain 3 Select the RF Auto Tuning settings you want to apply Both channel and power settings are selected by default 4 If you access...

Page 177: ...he WX Switch wizard Depending on how you access the wizard the wizard s title can be Create Wireless Switch or Modify followed by the WX switch name For simplicity the documentation refers to the wiza...

Page 178: ...178 CHAPTER 5 CONFIGURING WX SYSTEM AND ADMINISTRATIVE PARAMETERS Figure 10 WX Switch Wizard System and Administrative Page The wizard has the following pages System and Administrative Wireless AAA...

Page 179: ...he window The parameter configuration status is indicated by the color of the box around the parameter s checkmark Green The parameters on the page are ready to be deployed All required parameters are...

Page 180: ...e enable password for the switch is not specified Since the enable password is required for 3WXM to access and manage a WX switch but is optional on the WX switch itself the box around the WX Properti...

Page 181: ...Wireless page enables you to configure MAP access point and radio parameters For example to create a new radio profile select Radio Profile in the organizer list on the left then click New Radio Prof...

Page 182: ...a new wizard the other wizard remains open in the background However you can enter information only in the new wizard After you click Finish to save your changes and close the new wizard you can conti...

Page 183: ...RADIUS parameters users and access filters To configure AAA parameters see Configuring Authentication Authorization and Accounting Parameters on page 291 Adding a WX Switch to the Network Plan You ca...

Page 184: ...he WX Properties portion of the System and Administrative page The Wireless and AAA pages do not become available until the switch has a name To create a new WX switch based on a configured switch To...

Page 185: ...guration Files on page 396 to import the switch s configuration file 2 In the Organizer panel select the Mobility Domain where you placed the switch 3 Select the new WX switch and do one of the follow...

Page 186: ...rd on page 185 2 Select System and Administrative at the top of the wizard if not already selected 3 Select WX Properties from the organizer list on the left side of the page if not already selected 4...

Page 187: ...witch in a closet at this time select Not Assigned 9 In the VLAN IP list select the VLAN IP address used by the 3WXM client to connect to the WX If required you can specify a different IP address for...

Page 188: ...ou configure a VLAN by assigning a name and network ports to the VLAN Optionally you can assign VLAN tag values on individual network ports You can configure multiple VLANs on a WX switch s network po...

Page 189: ...col Support VLAN Name This attribute is a 3Com vendor specific attribute VSA You cannot configure the Tunnel Private Group ID attribute in the local user database Specify the VLAN name not the number...

Page 190: ...to belong to VLAN 3 As a result traffic between port 4 and port 5 is switched but traffic between port 4 and 6 needs to be routed by an external router 802 1Q Tagging The tagging capabilities of the W...

Page 191: ...affinity value This is a numeric value that each WX within the Mobility Domain advertises for each of its local VLANs to all other WX switches in the Mobility Domain The WX selects the WX with the hi...

Page 192: ...hese VLANs 4 Do one of the following To create a new VLAN click New VLAN The Create VLAN wizard appears Go to step 5 To modify an existing VLAN select the VLAN then click Modify The Modify VLAN wizard...

Page 193: ...ility Domain advertises for each of its VLANs The default is 5 A higher tunnel affinity indicates a greater preference 8 In the IP Address box specify the IP address and subnet mask in classless inter...

Page 194: ...age 194 To close the wizard and save the changes click Finish Adding Ports to a VLAN You can add ports or port groups if you have defined them to a VLAN After adding a port or port group you can also...

Page 195: ...ntication ports to a VLAN 2 From the list of available members select a port or port group if you previously created port groups If a port or port group is currently a member of a VLAN the VLAN name i...

Page 196: ...a port or port group from the VLAN select a port or port group and click Remove To make multiple selections press Shift for contiguous items or Control for noncontiguous items while clicking items 7...

Page 197: ...VLANs on the WX switch The IEEE 802 1D spanning tree specifications refer to networking devices that forward Layer 2 traffic as bridges In this context a WX switch is a bridge Where this manual or the...

Page 198: ...pecify the amount of time 4 to 30 seconds a bridge waits after a topology change to begin forwarding data packets The default is 15 seconds 7 Do one of the following To configure STP port information...

Page 199: ...e STP port information 1 In the Create VLAN wizard click Spanning Tree Port Setup The Spanning Tree Port Setup page appears 2 Select the port whose STP information you want to modify 3 Click Modify Th...

Page 200: ...VLAN spanning tree packets are forwarded transparently through the VLAN to and from that port 5 In the Port Priority box specify a priority value 0 to 255 The default is 128 6 In the Path Cost box sp...

Page 201: ...WX by forwarding packets for a multicast group only on the ports that are connected to members of the group IGMP is especially useful for WLANs because bandwidth is relatively constrained The WX liste...

Page 202: ...3 In the Version list select Version 1 or Version 2 of IGMP 4 If IGMP queriers are not on the subnet for example multicast routers select Querier Enabled 3Com recommends that you use the pseudo queri...

Page 203: ...elect Proxy Report 11 To enable multicast router solicitation which allows the WX to discover multicast routers on the subnet select Multicast Router Solicitation 12 In the Solicitation Interval box s...

Page 204: ...tic multicast ports However MSS can dynamically add these port types to the list of multicast ports based on multicast traffic To add or remove static multicast router and receiver ports 1 In the Crea...

Page 205: ...directly connected to the link does not detect the link change until the maximum age timer expires Backbone fast convergence enables the WX switch to listen for bridge protocol data units BPDUs sent b...

Page 206: ...etwork core To configure fast convergence features 1 In the Organizer panel navigate to the domain policy or WX switch you want to configure 2 Expand the policy or switch to see the configuration opti...

Page 207: ...the VLAN you want to delete 5 Click Delete The Delete Objects dialog box appears 6 Click Finish to delete the VLAN The VLAN is deleted Configuring the System IP Address You can designate one of the I...

Page 208: ...box 5 Optionally enter the IP address of the switch s default gateway router in the first row of the Gateway IP Address section You can enter up to four gateway addresses You also can configure gatew...

Page 209: ...12 SSH By default SSH is enabled You can use SSH for encrypted access to the CLI See Configuring SSH on page 213 SNMP By default SNMP is disabled You can enable SNMP traps and trap receivers and speci...

Page 210: ...nformation under Management Services in the organizer list of the System and Administrative page In the Organizer panel select Management Services under a WX switch or Domain Policies then select Edit...

Page 211: ...zard Click Finish to close the wizard and save changes Enabling HTTPS By default HTTPS is enabled on the WX allowing you to use Web Manager on port 443 for a secure session If you disable HTTPS you ca...

Page 212: ...to Configuring Telnet Select another item in the WX Switch wizard if you are using this wizard Click Finish to close the wizard and save changes Configuring Telnet To configure Telnet access to the WX...

Page 213: ...ou must use the CLI to generate an encryption key on each WX switch you want to manage using SSH You cannot generate the key with 3WXM For information see the Wireless LAN Switch and Controller Config...

Page 214: ...are using this wizard Click Finish to close the wizard and save changes Configuring SNMP You can monitor your network by using the Simple Network Management Protocol SNMP SNMP is a protocol used to ex...

Page 215: ...lect Enabled to enable SNMP service on the WX or clear Enabled to disable SNMP service By default SNMP is disabled 3 You can edit the Read and Write community strings by double clicking in the Communi...

Page 216: ...n the WX switch is initially able to contact a mobility domain seed member or can contact the seed member after a timeout MobilityDomainTimeout Generated when a timeout occurs after a WX switch has un...

Page 217: ...Auto Tuning feature changes the channel on a radio CounterMeasureStart Generated when MSS begins countermeasures against a rogue access point CounterMeasureStop Generated when MSS stops countermeasur...

Page 218: ...be viewed with Web Manager or archived and viewed in Event Viewer see Accessing the Event Log on page 461 Events can be displayed on the console port of the WX Events can be displayed in an active Te...

Page 219: ...t Enabled To disable the option clear Enabled b In the Severity Filter list select the lowest level of severity to be logged Emergency The WX is unusable Alert Action must be taken immediately Critica...

Page 220: ...ect the lowest level of severity of the event or condition to be logged see the list in step 2 The default severity level is Error 4 Configure logging to the current login session a To specify that lo...

Page 221: ...o handle different syslog messages from different sources You can use a facility in the range of Local 0 through Local 7 To set up a syslog server 1 Do one of the following Open the WX Switch wizard t...

Page 222: ...222 CHAPTER 5 CONFIGURING WX SYSTEM AND ADMINISTRATIVE PARAMETERS 2 Click New Syslog Server The Create Syslog Server dialog box appears...

Page 223: ...uire the facility to be set to a standard local facility name 6 In the Map to Local Facility List select the local facility Local 0 to Local 7 that all the facilities are mapped to The default value i...

Page 224: ...more information see Configuring Logging on page 218 Configuring Tracing Properties In addition to specifying the area of MSS to trace you can optionally specify the level of tracing to output as well...

Page 225: ...cluster_event cluster_packet cluster_sifa cluster_sosa config copp copp_data copping crypto dot1x eap files httpd httpd_core httpd_test httpd_xmlcfg igmp ims interface ip loadbal mid nose_ipc nose_soc...

Page 226: ...acters that contains no spaces or tab characters 10 Optionally in the MAC Address box type the MAC address to trace Specify a MAC address using colons to separate the octets for example 00 11 22 aa bb...

Page 227: ...s time or similar summertime period To set up a time zone 1 Do one of the following Open the WX Switch wizard then select Timezone under Management Services in the organizer list of the System and Adm...

Page 228: ...no spaces or tabs 2 In the Start Month list select the month of the year when the time change starts 3 In the Start Week list select the week of the month when the time change starts First Second Thir...

Page 229: ...users that are connected to the WX switch over Ethernet can be authenticated before they can be authorized to use the network However data for wired users is not encrypted after they are authenticated...

Page 230: ...f the Setup area If the port is currently a MAP access port you are prompted to choose whether to reconfigure it 3 Click in the Name column for a wired authentication port you enabled and type a name...

Page 231: ...item in the WX Switch wizard if you are using this wizard Click Finish to close the wizard and save changes Any ports you configure as wired authentication ports are represented in 3WXM with a wired...

Page 232: ...232 CHAPTER 5 CONFIGURING WX SYSTEM AND ADMINISTRATIVE PARAMETERS 2 Select an Ethernet port to modify 3 Click Modify The Modify Port dialog box appears...

Page 233: ...h no spaces or tabs 5 To enable the port select Enabled To disable the port clear Enabled By default the port is enabled 6 To enable PoE select PoE Enabled CAUTION Although you can enable PoE on a net...

Page 234: ...one of the following from the PHY Media Preference list box GBIC The port uses the fiber link as the active link RJ45 The port uses the RJ 45 link as the active link The PHY Media Preference list box...

Page 235: ...or new traffic flows Traffic that belonged to the port before it failed continues to be assigned to other ports Configuration Changes Based on Port Groups Layer 2 configuration changes apply collectiv...

Page 236: ...236 CHAPTER 5 CONFIGURING WX SYSTEM AND ADMINISTRATIVE PARAMETERS 2 Select New Port Group The Create Port Group wizard appears...

Page 237: ...Configuring Load Sharing 237 3 In the Port Group Name box type the name of the port group 1 to 16 alphanumeric characters with no spaces or tabs 4 Click Next The Port Group Selection page appears...

Page 238: ...u are using this wizard Click Finish to close the wizard and save changes Configuring IP Services You can configure the following IP services Static routes See Configuring Static Routes on page 238 IP...

Page 239: ...a maximum of four routes per destination This includes default routes which have a destination of 0 0 0 0 0 Each route to a given destination must have a unique gateway address When the routing table...

Page 240: ...tic route 1 Do one of the following Open the WX Switch wizard then select IP Routes under IP Services in the organizer list of the System and Administrative page In the Organizer panel select IP Servi...

Page 241: ...fault is 1 6 To close the Create Static Route dialog box click Finish Configuring Default Routes You can configure a maximum of four default routes You must specify a default route before the WX can b...

Page 242: ...sh to close the wizard and save changes Configuring IP Aliases You can map an IP address to a name by creating an IP alias For example if you create an IP alias carmel for IP address 10 20 30 40 you c...

Page 243: ...Configuring IP Services 243 2 Click New IP Alias The Create IP Alias dialog box appears...

Page 244: ...iguring DNS on page 244 Select another item in the WX Switch wizard if you are using this wizard Click Finish to close the wizard and save changes Configuring DNS You can configure the WX switch to re...

Page 245: ...rties To set up DNS basic properties 1 Do one of the following Open the WX Switch wizard then select DNS under IP Services in the organizer list of the System and Administrative page In the Organizer...

Page 246: ...next step 4 In the Default DNS Domain box type the default domain suffix that is appended to a hostname if the hostname cannot be resolved as entered The suffix can be up to 64 characters long with n...

Page 247: ...y servers 6 To add more DNS servers repeat step 1 through step 4 for every server You can add a total of six DNS servers 7 Do one of the following Go to Configuring NTP Select another item in the WX S...

Page 248: ...em and Administrative page In the Organizer panel select IP Services under a WX switch or Domain Policies then select Edit Properties The Modify IP Services wizard appears Click on NTP at the top of t...

Page 249: ...er IP Services in the organizer list of the System and Administrative page In the Organizer panel select IP Services under a WX switch or Domain Policies then select Edit Properties The Modify IP Serv...

Page 250: ...or Using 3WXM you can add permanent entries to the ARP table In addition to adding permanent ARP entries you can set the amount of time unused dynamic entries remain in the table before they are remov...

Page 251: ...ble The value range for the aging timeout is 0 to 1 000 000 seconds The default value is 1200 seconds To disable aging specify 0 as the aging timeout The local entry for the WX static entries and perm...

Page 252: ...box type the MAC address that the IP address is to be mapped to In the IP Address box type the IP address for the ARP entry Click Finish Do one of the following Select another item in the WX Switch w...

Page 253: ...re the following wireless parameters for WX switches Service Set Identifiers SSIDs Service profiles which enable or disable beaconing for an SSID and define the encryption used for that SSID s wireles...

Page 254: ...ge 177 When a wireless client requests access to the network the client requests access to a specific Service Set Identifier SSID Beaconing encryption and authentication settings for the SSID are cont...

Page 255: ...X authentication or preshared key PSK authentication For Web AAA file location of customized Web page to serve clients for login Configuring an SSID This section enables you to configure SSIDs For eac...

Page 256: ...256 CHAPTER 6 CONFIGURING WIRELESS PARAMETERS 4 To create an SSID click New SSID The Create SSID wizard appears...

Page 257: ...rtisement and encryption for an SSID You can specify the following Whether SSIDs that use the service profile are beaconed Whether the SSIDs are encrypted or clear unencrypted For encrypted SSIDs the...

Page 258: ...whether the SID is encrypted or unencrypted New SSIDs are encrypted by default 8 To disable beaconing advertisement of the SSID by 3com radios click on the Yes checkbox next to Beacon to disable beac...

Page 259: ...address 10 If the fallthru authentication method is Web AAA specify the file location in the WX switch s nonvolatile memory of a customized web page to serve the client for login in the WebAAA page b...

Page 260: ...e Security Mode list select WEP WPA or WEP WPA The default is WEP Microsoft Windows XP does not support WEP with WPA To configure a radio profile to provide WEP for XP clients select WEP Do not select...

Page 261: ...6 character ASCII string representing a 13 digit hexadecimal number ASCII characters in the following ranges are supported 0 to 9 A to F a to f 3 In the WEP Unicast Key Index box specify the WEP key 1...

Page 262: ...ared key PSK a MAP and a client authenticate one another based on a key that is statically configured on both devices The devices use the key in a handshake to derive a unique key for the session For...

Page 263: ...MIC used by CCMP CBC MAC is stronger than the one used by Michael and does not require or provide countermeasures WEP does not use a MIC Instead WEP performs a cyclic redundancy check CRC on the fram...

Page 264: ...e the TKIP countermeasures time in the TKIP Countermeasures Time box By default TKIP countermeasures are used for 60 000 ms 60 seconds after a second MIC failure within a one minute interval 5 To enab...

Page 265: ...to move the profile name to the Current Radio Profiles column 4 Click Finish to save the changes and close the wizard Configuring a Radio Profile A radio profile is a set of attributes that you can a...

Page 266: ...for a floor 3WXM automatically copies the new profile to the domain policy of the Mobility Domain selected for the coverage area Later when you configure WX switches in the Mobility Domain using the...

Page 267: ...Configuring a Radio Profile 267 4 Select New Radio Profile The Create Radio Profile wizard appears...

Page 268: ...d against interference an 802 11b g radio in protection mode sends messages while 802 11g traffic at higher data rates is being sent to inform 802 11b devices about the 802 11g traffic and reserve ban...

Page 269: ...s 1 to 31 the MAP transmits before transmitting the multicast and broadcast frames stored in its buffers The default is 1 4 In the Fragment Threshold box specify the maximum length 256 to 2346 bytes a...

Page 270: ...threshold are not sent using the RTS CTS method The default is 2346 bytes 9 In the Short Retry Limit box specify the number of times 1 to 15 the MAP transmits an unacknowledged unicast frame that is s...

Page 271: ...cides whether to change the power level on radios change the value in the Tx Power Tuning Interval box You can specify from 1 to 65535 seconds The default is 300 seconds 4 To change the interval at wh...

Page 272: ...rval to 0 RF Auto Tuning does not reevaluate the channel at regular intervals However RF Auto Tuning can still change the channel in response to RF anomalies 7 To change the minimum number of seconds...

Page 273: ...rofile Selection page appears 2 Select the service profile in the Available Service Profiles list 3 Click Add to move the profile name to the Current Service Profiles column 4 Do one of the following...

Page 274: ...74 and Configuring Distributed MAP Access Points on page 284 After you configure the MAP access points return to this wizard page to apply the radio profile to radios 2 Select the radios from the Avai...

Page 275: ...not configure any gigabit Ethernet port or port 7 or 8 on a WX1200 switch as a MAP port To manage a MAP access point on a WX4400 switch configure a Distributed MAP connection on the WX switch See Conf...

Page 276: ...t the port has been labeled as a MAP port and has PoE enabled Enable all ports as MAP ports by selecting MAP Enabled in the MAP Enabled column heading 5 Click in the Name column for a MAP port you ena...

Page 277: ...l MP 101 Single radio model 7 To select the radio type for a single radio model click the MAP Radio Type box and select the radio type from the list 11a 802 11a 11b 802 11b only 11g 802 11b g 8 To dis...

Page 278: ...of the WX Switch wizard select a MAP port then click Modify MAP The Modify MAP wizard appears 2 Select the MAP model from the MAP Model list AP2750 Single radio model MP 352 Dual radio model MP 341 Si...

Page 279: ...MAP selects the WX switch that has the greatest capacity to add more active MAPs For example if a MAP is dual homed to two WX4400 switches and one of the WX switches has 50 active MAPs while the other...

Page 280: ...nnection on page 283 To save changes and close the wizard click Finish To modify radio settings To modify radio settings use the following procedure 1 On the MAP page of the Wireless page of the WX Sw...

Page 281: ...of antenna box 3WXM assumes that the external antenna will be installed so that the front faces in the direction of coverage not up or down and so that the antenna cable connector faces down or up and...

Page 282: ...48 36 24 18 12 9 or 6 The default minimum data transmit rate depends on the radio type The default minimum data rate for 802 11b g and 802 11b radios is 5 5 Mbps The default minimum data rate for 802...

Page 283: ...connection for redundancy 1 On the MAP page of the Wireless page of the WX Switch wizard select a MAP port then click Modify MAP The Modify MAP wizard appears 2 Select the connection you want to chang...

Page 284: ...alue form the Bias listbox d To add the MAP to a MAP group for session load balancing type the group name in the Load Balance Group box 4 Click Finish to close the dialog 5 Click Finish again to save...

Page 285: ...Connected MAP Access Points on page 274 To configure a distributed MAP To configure a distributed MAP use the following procedure 1 Access the WX Switch wizard for the WX switch See Accessing the Modi...

Page 286: ...286 CHAPTER 6 CONFIGURING WIRELESS PARAMETERS 4 Click New Distributed MAP The Create Distributed MAP wizard appears...

Page 287: ...l list AP2750 Single radio model MP 352 Dual radio model MP 341 Single radio model MP 262 Dual radio model MP 252 Dual radio model MP 241 Single radio model MP 52 Dual radio models MP 122 Dual radio m...

Page 288: ...that has only 50 active MAPs Bias applies only to WX switches that are indirectly attached to the MAP through an intermediate Layer 2 or Layer 3 network A MAP always attempts to boot on MAP port 1 fir...

Page 289: ...ons and probe responses Passive scanning is always enabled and cannot be disabled You can disable active scanning if required 1 Access the Modify Switch wizard for the WX switch See Accessing the Modi...

Page 290: ...290 CHAPTER 6 CONFIGURING WIRELESS PARAMETERS...

Page 291: ...AAA processing of administrator and network client access Network client access rules based on SSID Location policies for overriding authorization parameters assigned by AAA to network clients Mobili...

Page 292: ...and Server Groups Remote Authentication Dial In User Service RADIUS is a client server security protocol that provides authentication authorization and accounting for network users and devices A RADIU...

Page 293: ...ault Values You can set default values for certain RADIUS parameters that apply to RADIUS servers and server groups you create for an individual WX The following RADIUS parameters except system IP add...

Page 294: ...a RADIUS request The default is 3 6 In the Dead Time box specify the amount of time 0 to 1440 minutes that must elapse before the WX switch attempts to reach an unresponsive RADIUS server The default...

Page 295: ...rd For MAC users the password is the user s MAC address by default MSS obtains the MAC address from frames received from the device For last resort users the password is 3Com Changing the password app...

Page 296: ...296 CHAPTER 7 CONFIGURING AUTHENTICATION AUTHORIZATION AND ACCOUNTING PARAMETERS 4 Click New RADIUS Server The Create RADIUS Server wizard appears...

Page 297: ...ation Port box specify the UDP destination port to which the WX switch listens for authentication and authorization The default port is 1812 9 In the Accounting Port box specify the UDP destination po...

Page 298: ...om Changing the password applies both to MAC users and to last resort users 14 Do one of the following To define RADIUS servers go to Defining RADIUS Server Groups Click Finish to save the changes and...

Page 299: ...Connecting to RADIUS Servers and Server Groups 299 4 Click New RADIUS Server Group The Create RADIUS Server Group wizard appears...

Page 300: ...rvers Authentication and accounting requests for a given user are always sent to the same server Each new authentication event uses the next server in the list If load balancing is not enabled the fir...

Page 301: ...servers in a RADIUS server group 11 In the Create RADIUS Server Group wizard select the RADIUS server whose position in the list you want to change 12 Click Move Up to move the RADIUS server up the li...

Page 302: ...base You can group these users by creating user groups MAC address users and user groups cannot be assigned administrative access to the WX switch Creating Named Users When creating named users you co...

Page 303: ...Creating and Managing Users in the Local User Database 303 4 Click New and select New User The Create User wizard appears...

Page 304: ...y a VLAN 7 In the Password box type the password for the user 1 to 80 alphanumeric characters with no spaces or tabs You must specify a password if you want the password to be encrypted in the configu...

Page 305: ...a user group you define common properties for the group You can optionally define user attributes which are stored in the local database Attributes defined for an individual user override those attrib...

Page 306: ...306 CHAPTER 7 CONFIGURING AUTHENTICATION AUTHORIZATION AND ACCOUNTING PARAMETERS 4 Click New and select New User Group The Create User Group wizard appears...

Page 307: ...hoose Available 8 Select a user to be included in this user group To select multiple contiguous users click Shift while selecting To select multiple noncontiguous users click Ctrl while selecting 9 Re...

Page 308: ...ew and select New MAC Address User The Create MAC Address User wizard appears 5 In the User MAC Address box type the MAC address for the user device using colons as delimiters You must specify all 6 b...

Page 309: ...group you define properties for the group You can optionally define user attributes which are stored in the local database Attributes defined for an individual user override attributes defined for a...

Page 310: ...llowing To configure user attributes see Configuring User Authorization Attributes To close the Create MAC User Group wizard and save the changes click Finish Configuring User Authorization Attributes...

Page 311: ...er group wizard The User Attributes page appears 2 In the attribute row you want to configure click the Attribute Value column See Table 22 for a description of user attributes and their values In 3WX...

Page 312: ...vanced Encryption Standard using Counter with CBC MAC 2 Reserved 4 TKIP Temporal Key Integrity Protocol 8 WEP_104 the default Wired Equivalent Privacy protocol using 104 bits of key strength 16 WEP_40...

Page 313: ...y the values depends on the RADIUS server Regardless of whether the attributes are defined locally or on a RADIUS server the ACLs must already be configured on the WX switch For more information see M...

Page 314: ...network users receive Framed access session timeout network access mode only Maximum number of seconds for the user s session Number between 0 and 4 294 967 296 seconds approximately 136 2 years ssid...

Page 315: ...y designations required and a time range in hhmm hhmm 4 digit 24 hour format optional mo Monday tu Tuesday we Wednesday th Thursday fr Friday sa Saturday su Sunday wk Any day between Monday and Friday...

Page 316: ...s with this access rule connect to the WX switch using a console cable that is plugged directly to the WX switch By default if no authentication has been set for console users any username and passwor...

Page 317: ...gle user or a set of users A user glob can be up to 80 characters long and cannot contain spaces or tabs A single asterisk wildcard character matches any characters up to but not including a separator...

Page 318: ...one or more users MSS compares the VLAN glob which can optionally contain wildcard characters against the VLAN Name attribute returned by AAA to determine whether to apply the rule To match all VLANs...

Page 319: ...Managing Access Rules for Administrative Users 319 3 Select Admin Access from the organizer list on the left side of the page if not already selected 4 Click New Admin Access The Create Admin Access...

Page 320: ...ic characters with no spaces or tabs You can use asterisks as wildcards The user glob it_ specifies all users with it_ in their usernames for example it_tamara 6 Do one of the following To specify whe...

Page 321: ...group that you have configured previously LOCAL The WX switch s local database You can add one or both methods to the list If you specify a RADIUS server group as the first method and a user is denie...

Page 322: ...Finish To set the accounting method for administrator access 1 Click Accounting at the top of the wizard to display the following page 2 To enable this accounting rule select Enabled By default a rul...

Page 323: ...h to save changes and close the wizard Managing Administrator and Console Access Rules After you create administrative access rules you can do the following to manage the access rules Modify access ru...

Page 324: ...wired authentication port the authentication rule must match the user s username or MAC address If a matching rule is found MSS then checks RADIUS servers or the WX switch s local user database for cr...

Page 325: ...grants access Otherwise MSS attempts the fallthru authentication type which can be Web last resort or none Fallthru authentication is described in more detail in Authentication Algorithm on page 326 W...

Page 326: ...ID or wired authentication port The fallthru authentication type can be one of the following Web Last resort None Web and last resort are described in Authentication Types None means the user is autom...

Page 327: ...es Yes Yes No Yes Yes No No No No Client requests encrypted SSID Client 802 1X rule that matches SSID responds Yes MAC rule that matches SSID No to 802 1X Authent succeeds Allow Client Yes Authent suc...

Page 328: ...name in the authentication rule is any MSS checks the RADIUS servers or local database for username last resort any exactly as spelled here Access is granted only if this username is found Otherwise...

Page 329: ...o For a user to be successfully authenticated for last resort access the RADIUS servers or local database whichever method is used by the last resort authentication rule must contain a user named last...

Page 330: ...e Controls the WX switch ports a user can access For wireless users an MSS Mobility Profile specifies the MAP access points through which the user can access the network For wired authentication users...

Page 331: ...an configure authentication rules and settings To configure authentication rules 1 Do one of the following From the AAA page of the WX Switch wizard select Network Access From the Create SSID wizard c...

Page 332: ...nt match a username and password in the WX switch s local database or on a RADIUS server the WX switch allows the client onto the SSID If none of these methods results in the client being successfully...

Page 333: ...letters For example EXAMPLE sydney or EXAMPLE which specifies all usernames whose usernames contain periods For EAP with Transport Layer Security EAP TLS clients the format is username domain_name For...

Page 334: ...D box contains any and you do not change the SSID name the authentication rule allows clients who match the userglob or MAC address glob to access any SSID 5 To enable the authentication rule for use...

Page 335: ...Configuring and Managing Access Rules for Network Users 335 4 Click Authentication at the top of the wizard to display the following page The page contents are the same for MAC last resort and Web AAA...

Page 336: ...Protocol EAP with message digest algorithm 5 Select this protocol for wired authentication clients Uses challenge response to compare hashes Provides no encryption or integrity checking for the connec...

Page 337: ...authentication and authorization are attempted with the other methods specified in the list If you specify LOCAL as the first method and a user is not in the local user database on the WX authenticati...

Page 338: ...abled By default a rule you configure in 3WXM is disabled which means 3WXM does not add the rule to a WX switch s configuration 3 Select one of the following record options Select Start Stop to specif...

Page 339: ...the access rules is based on the order in which you created them This determines the order in which the WX matches users to user globs The arrangement of access rules is important to avoid unintention...

Page 340: ...d against each entry in the order in which they appear in the location policy If a match is found the parameters defined in the location policy override previously configured user attributes Any user...

Page 341: ...g Location Policies 341 3 Select Location Policy Rule from the organizer list on the left side of the page if not already selected 4 Click New Location Policy Rule The Create Location Policy Rule wiza...

Page 342: ...the location policy to all usernames not matching a specified user glob In the User Glob box type the user glob for the users to which the location policy does not apply When specifying a user glob en...

Page 343: ...b Click Close 8 To select Distributed MAPs click Distributed MAP List Click Choose Available then select a Distributed MAP connection from the list Repeat for each Distributed MAP connection you want...

Page 344: ...ted MAPs or wired authentication ports are to be included Typically you include ports that are defined as MAP ports or Distributed MAPs You can specify that all or no ports are included or you can spe...

Page 345: ...Configuring Mobility Profiles 345 4 Click New Mobility Profile The Create Mobility Profile wizard appears...

Page 346: ...n ports Go to step 11 Selected Include a selected list of ports Go to the next step None Include no ports Go to step 11 7 Click Choose Available and select a port Repeat for each port 8 In the Distrib...

Page 347: ...ere are no ACE matches in the ACL an ACL contains an implicit rule that denies all access If there is not at least one ACE that permits access in an ACL no traffic will be allowed The implicit deny al...

Page 348: ...basic properties 1 Access the WX Switch wizard for the WX switch See Accessing the Modify Switch Wizard on page 185 2 Select AAA at the top of the wizard if not already selected 3 Select Mobility Prof...

Page 349: ...o Defining Access Control Entries Defining Access Control Entries As part of defining ACL properties you need to define access control entries ACEs for the ACL You can add the following types of ACEs...

Page 350: ...DP ACE on page 352 Layer 4 Protocol Filters packets by source and destination IP addresses TOS precedence or Layer 4 protocol For more information see Creating a Layer 4 Protocol ACE on page 357 Creat...

Page 351: ...hether to forward or filter packets The ACL checks the bits in IP addresses that correspond to zeros in the mask but does not check the bits that correspond to ones The zero bit must start at the begi...

Page 352: ...cedence list select one of the following Any 1 All packets are subject to the ACL regardless of whether precedence is set Routine 0 Packets with routine precedence are filtered Priority 1 Packets with...

Page 353: ...Using Access Control Lists for Security 353 To create a TCP ACE click New TCP ACE The Create TCP ACE dialog box appears To create a UDP ACE click New UDP ACE The Create UDP ACE dialog box appears...

Page 354: ...en configuring an IP ACE See step 6 on page 351 through step 9 on page 352 8 In the Operator list of the Create TCP ACE or Create UDP ACE dialog box select one of the following None No source port is...

Page 355: ...tep 10 13 Click Finish Creating an ICMP ACE To create an ICMP ACE 1 In the ACL Setup page of the Create ACL wizard click New A list of ACEs appears 2 Select New ICMP ACE The Create ICMP ACE dialog box...

Page 356: ...egardless of ICMP type Table 23 lists some common ICMP types For a complete list of ICMP types see www iana org assignments icmp parameters 6 If the ICMP type you specified in step 5 has codes availab...

Page 357: ...ist select Permit to allow access if the conditions in the ACE are matched or Deny to refuse access if the conditions are matched 4 If you select Permit in the CoS box specify a class of service level...

Page 358: ...en you create an ACL the ACEs are listed in the order in which you created them You can change the order of ACEs using the ACL Setup page Table 24 Commonly Used IP Protocol Numbers IP Protocol Number...

Page 359: ...e other ACEs repeat step 1 and step 3 until all ACEs are in the order you want An ACL contains an implicit rule that denies all access If you create an ACL with multiple ACEs the implicit rule is plac...

Page 360: ...ify an inbound ACL and use the filter id out attribute to specify an outbound ACL If you are configuring the attributes on a RADIUS server MSS can receive the Filter ID attribute with the Profile valu...

Page 361: ...o ports VLANs or virtual ports 1 In the Create ACL wizard click ACL Map The ACL Map page appears 2 Do one of the following To map an ACL to a Distributed MAP see Mapping an ACL to a VLAN To map an ACL...

Page 362: ...lect New ACL Distributed MAP Map The Create ACL Distributed MAP Map dialog box appears 3 In the Direction list select In to filter incoming packets or Out to filter outgoing packets 4 In the DAP list...

Page 363: ...oing packets 4 In the Type list select ID to identify the VLAN by number or Name to identify it by name 5 If you selected Name in step 4 go to step 6 Otherwise specify a VLAN number in the ID box and...

Page 364: ...t Map dialog box appears 3 In the Direction list select In to filter incoming packets or Out to filter outgoing packets 4 In the Port list select the port or port group to which you want to map the AC...

Page 365: ...kets 4 In the Tag Value box specify the 802 1Q tag value that identifies a virtual port in a VLAN The tag value can be a number from 1 to 4095 The default value is 1 Make sure that you do not specify...

Page 366: ...ch To configure 802 X authentication 1 In the Mobility Domains panel in the main 3WXM window navigate to the domain policy or WX you want to configure 2 Expand the domain policy or WX switch to see th...

Page 367: ...two ID requests even if this parameter is set to a higher value Setting the parameter to a higher value does affect all other types of EAP messages 12 To enable encryption key information to be sent t...

Page 368: ...seconds 2 5 days 16 To enable WEP key rolling rotation of the broadcast and multicast WEP keys select WEP Key Rolling 17 To specify the time to wait before rotating the WEP key specify the value from...

Page 369: ...guration files Table 25 lists the options and the sections in this chapter where the options are described Table 25 WX File Management Options in 3WXM Option Description Upload configuration Creates a...

Page 370: ...hes from a Network Plan to the Network on page 390 Verify configuration changes Checks WX switch configuration changes against a set of configuration rules alerts you to configuration items that do no...

Page 371: ...ep the following in mind when managing WX switches Managing You can manage WX switches running their original MSS versions with any version of 3WXM For example you can use 3WXM Version 3 0 to manage a...

Page 372: ...nfiguration Guide 4 Click Next The uploading progress is shown 5 Click Next The verification progress is shown When you upload a WX its configuration is verified if the Verify before deployment and up...

Page 373: ...WX switch s configuration in 3WXM or in the live network are automatically evaluated by comparing the changes to the rules If the evaluation detects any error or warning conditions the information in...

Page 374: ...plan again to ensure that the errors have been resolved Warnings are noncritical issues that do not stop deployment Review any warnings and consider resolving the issues before deployment Details abo...

Page 375: ...k on Edit newwx in the Resolutions section The Modify WX switch wizard appears Use the wizard to edit the System IP address After you save the configuration change 3WXM reevaluates the WX switch s con...

Page 376: ...message 2 In the Resolutions section click disable this rule for this instance only As soon as you click on this option the message disappears from the list 3WXM will not display this particular insta...

Page 377: ...any change in that configuration occurs Verify on edits 3WXM performs verification whenever you edit a WX switch s configuration Verify on deploy and export 3WXM performs verification when you select...

Page 378: ...ion Options dialog box to reenable the rule You also can disable rules for the entire network plan or for specific instances To disable or reenable a rule 1 On the toolbar of the Verification tab clic...

Page 379: ...es in the selected class b Select a rule class from the listbox The list of rules changes to list the rules in the selected class In this example the selected rule class is 802 1X Network Access 4 In...

Page 380: ...are displayed and become editable If the rule is disabled for all instances the Disable All Instances option is selected If individual instances of the rule are disabled the Disable Selected Instances...

Page 381: ...lected To reenable an individual instance of a rule click on the checkbox next to the instance Repeat for each instance you want to reenable Alternatively if you want to reenable all the disabled inst...

Page 382: ...MANAGING WX SYSTEM IMAGES AND CONFIGURATIONS 9 To leave all instances disabled go to step 10 To disable only specific instances a Select Disable Selected Instances The individual instances of the rul...

Page 383: ...displays a popup dialog with the following message Network changes have been detected Please use the Local Network Changes option to handle the changes WX switch configuration changes also are indica...

Page 384: ...each WX switch The Local Status and Network Status columns indicate where changes have occurred If you make a configuration change on a WX switch in the network then reverse that change 3WXM still ale...

Page 385: ...e selection of a local software image as described in Configuring Basic WX Properties on page 186 then the deploy function also simultaneously downloads and installs the specified image If the image u...

Page 386: ...To select multiple WX switches press Shift for contiguous WX switches or Control for noncontiguous WX switches while clicking b Click Review in the Local Changes group box to review local changes or...

Page 387: ...hanges To accept network changes go to To accept network changes To undo changes go to To undo changes To deploy local changes 1 Select one or more WX switches To select multiple switches press Shift...

Page 388: ...s shown on the History tab at the bottom of the dialog box If errors occur click Selected Errors to view the errors If there are errors fix them and verify the changes before trying to deploy again Yo...

Page 389: ...deploy is not performed and the following message is displayed instead wx is not synchronized To synchronize the changes do one of the following Review and either deploy local changes or accept networ...

Page 390: ...inutes 5 To be notified of network changes by a popup message select Prompt when network changes are detected To disable the popup message deselect the option Disabling the popup message does not affe...

Page 391: ...ab To deploy network plan changes to the network To deploy network plan changes to the network use the following procedure 1 Select one or more WX switches To select multiple WX switches press Shift f...

Page 392: ...deploy WX switches from a network plan to the network use the following procedure 1 Select the WX switches to which you want to deploy the changes To select more than one WX click Shift while clickin...

Page 393: ...etwork plan at this time Distributing Image and Configuration Files You can manage WX system image and configuration files by using the Distribute Images Configuration dialog box You can distribute sy...

Page 394: ...To close the Image Repository dialog box click Close Distributing System Images You can distribute a system image to one or more WX switches in a Mobility Domain Optionally you can distribute compatib...

Page 395: ...items 4 To select the system image to be distributed click Select Image The Image File Selection dialog box appears 5 Select the system image file you want to distribute 6 Click Close 7 To distribute...

Page 396: ...ches To select multiple items press Shift for contiguous items or Control for noncontiguous items while clicking items 4 Select Distribute Config 5 Click Distribute The status of the download process...

Page 397: ...page 186 To import a configuration To import a configuration use the following procedure 1 In the main 3WXM window select File Import The Import Configurations dialog box appears 2 In the Import Into...

Page 398: ...guous items or Control for noncontiguous items while clicking items 6 Click Select Files To Import The file or files you selected appear in the File Import Results list To remove all the files you pre...

Page 399: ...k the Choose button which is labeled with the current output directory The Select dialog box appears Navigate to the directory you want to use as the output directory and click Select On UNIX and Linu...

Page 400: ...hem to all WX switches in the Mobility Domain Every Mobility Domain has a default domain policy that applies to all the WX switches created in that Mobility Domain Working with a domain policy is like...

Page 401: ...Manager The Policy Manager dialog box appears 2 Make sure that the arrow at the top of the dialog box is pointing from Policy to Wireless Switch If not click the arrow to reverse its direction 3 In t...

Page 402: ...ly choose the specific commands that you want the domain policy to inherit Once they are merged changes apply to all WX switches controlled by the domain policy For explanations of CLI commands see th...

Page 403: ...can apply the changes to one or more WX switches as described in Applying Domain Policy Changes to WX Switches on page 400 Rebooting WX Switches or MAP Access Points You can use 3WXM to reboot WX swit...

Page 404: ...ect it from the list on the Wireless Switch tab To reboot a MAP click Managed Access Point and select the MAP s you want to reboot To select multiple items press Shift for contiguous items or Control...

Page 405: ...ificate for a WX switch Certificate authority certificate to validate the administrator s certificate Certificate authority certificate to validate user and the EAP server certificates When 3Com Wirel...

Page 406: ...dialog affect those connections too 1 If you do not want to see the Certificate Check dialog box each time 3WXM connects to a WX switch select one of the following options Always accept self signed ce...

Page 407: ...as the time frame for which the certificate is valid and who issued the certificate To review certificate details 1 Select Tools Certificate Management from the toolbar in the main 3WXM window 2 Selec...

Page 408: ...The password is removed after the PKCS 12 file is installed Although you can distribute one PKCS 12 file to many WX switches as a best practice you should install a unique certificate and key pair pe...

Page 409: ...To install an 802 1X EAP certificate Web To install a Web AAA certificate Admin To install an administrative certificate 7 Click Start Download Download progress appears in the Status column When the...

Page 410: ...410 CHAPTER 9 MANAGING CERTIFICATES...

Page 411: ...hows the operational status of 3Com equipment WX switches MAP access points and radios Status Summary Shows tables of basic information for the 3Com equipment Client Monitor Shows activity errors and...

Page 412: ...ding SNMP traps must be enabled on the WX switches both on the monitoring service and on the switches themselves Also the monitoring service must be a trap receiver for the switches For the Client Sta...

Page 413: ...s when you select a different object The other tab s title is not bold and that tab remains focused on the same object until you close the tab regardless of the objects you select in the Organizer pan...

Page 414: ...bar Options in Link View of Explore Window Icon Description Show the zoom navigator panel Zoom in Zoom out Refresh the information Fit the view in the Explore window Print the view displayed in the Ex...

Page 415: ...e Using Modifies display of wireless coverage based on one of the following Baseline association rate Data rate RSSI SNR by data rate Load by data rate SNR by RSSI bands Load by RSSI bands Note To dis...

Page 416: ...ice See Changing Monitoring Service Preferences on page 535 For example a red flag next to a MAP access point might indicate that the threshold for the number of active clients on a MAP has been cross...

Page 417: ...lick on the object All Monitor windows including the Explore window itself are updated to display information specifically about the selected object For example if the Explore window is showing link s...

Page 418: ...splays 802 11b coverage Displays 802 11g coverage Table 30 Coverage Display Options in Explore Window Display Option Description Baseline association rate Coverage is shown based on the MAP radio s ba...

Page 419: ...MAPs 3 Click on a spot on the floor plan RF measurements for that spot appear A triangle is also displayed where you clicked Table 31 lists the RF measurement information that is displayed for the mea...

Page 420: ...w Additional information is displayed for each equipment type Double click on a row in the Status Summary window to display more information about the object Using the Client Monitor Window The Client...

Page 421: ...n Description Refresh Refreshes the data by immediately polling the monitoring service when you click the icon Auto Refresh Sets the window to automatically refresh the data at regular intervals based...

Page 422: ...ation The Client Activity tab displays current statistics for client activity on the network The data fields in the display depend on the scope If a Mobility Domain is selected a row of data is displa...

Page 423: ...ation Failures Number of times authorization for a client who has been authenticated failed Common causes of authorization failures include the following Time of day start date or end date attributes...

Page 424: ...s include the following A radio has already failed the client and the 802 1X quiet period was in effect The authentication request sent to a RADIUS server on behalf of the client timed out Bonded auth...

Page 425: ...p Association Failure ClientAssociationFailure trap Authentication Failure ClientAuthenticationFailure trap Authorization Failure ClientAuthorizationFailure trap Authorization Successful ClientAuthori...

Page 426: ...s point and radio that was dealing with the client SSID SSID the client was requesting Failure Cause Description Cause of the failure Table 36 Activity Details for Authentication Failure Column Descri...

Page 427: ...s using a RADIUS server to authenticate the client SSID SSID the client was requesting Failure Cause Description Cause of the failure Table 37 Activity Details for Authorization Failure Column Descrip...

Page 428: ...stem IP address of the WX switch that was attempting to authenticate the client Note The system IP address is listed even if the switch was using a RADIUS server to authenticate the client SSID SSID t...

Page 429: ...onnection in the new location is established Updated_to_roam User is roaming Session statistics have been collected and will be transmitted to the new location Web_authing User is being authenticated...

Page 430: ...by 3Com equipment to track the session within the Mobility Domain Client IP Address IP address of the client Auth Server IP System IP address of the WX switch that was attempting to authenticate the c...

Page 431: ...se of the failure Table 41 Activity Details for Roam Column Description User Name Username of the client MAC Address MAC address of the client SSID SSID the client was associated with Roamed from Clie...

Page 432: ...e Client Monitor window s Client Sessions tab displays a row of information for each WX switch in the Mobility Domain Table 42 lists the data displayed on the Client Sessions tab when the scope is a M...

Page 433: ...rmation for each client session Table 43 lists the data displayed on the Client Sessions tab when the scope is a WX switch MAP access point or individual radio SNR average Average SNR of data transmis...

Page 434: ...sed to log on to the network The username is shown in one of the following formats Named user Windows domain users using PEAP MAC address for devices that are authenticated by MAC authentication IP Ad...

Page 435: ...tion Server System IP address of the WX switch that was attempting to authenticate the client Note The system IP address is listed even if the switch was using a RADIUS server to authenticate the clie...

Page 436: ...AP Roaming_away User is roaming a connection in the new location is established Updated_to_roam User is roaming Session statistics have been collected and will be transmitted to the new location Web_a...

Page 437: ...he entire roaming history select Lifetime Table 45 lists the information displayed on the tab Table 45 Session Statistics Columns Column Description Operational Rate Data rate of the last packet recei...

Page 438: ...ient during this session Unicast Packets In Number of unicast packets received by the radio from the client during this session Multicast Bytes In Number of multicast bytes received by the radio from...

Page 439: ...roaming Sessions in the location history are sorted from newest to oldest with the oldest session at the bottom of the list and the newest session at the top Table 46 lists the information displayed...

Page 440: ...ork performance 3WXM monitors the clients on the watch list by MAC address Adding a Client to the Watch List You can add a client to the watch list using either of the following methods On the Client...

Page 441: ...earch for individual users based on specific criteria or you can find all users in a Mobility Domain 1 In the Client Monitor window click on the window s toolbar The Find Clients dialog box appears 2...

Page 442: ...h For a username you can also specify the prefix of the username For example to find natasha example com you could specify the following natasha example com nat Wildcards are not supported in search c...

Page 443: ...x in the user row Repeat for all users that you want to add to the watch list 8 Click Finish Displaying the Client Watch List To display the watch list select the Client Watch List tab in the Client M...

Page 444: ...RSSI trend data You can display trend data for periods covering the most recent one hour 24 hours 7 days or 30 days The data is also shown in a graph Trend Lifetime AP Stats Shows byte and packet stat...

Page 445: ...ent s Geographical Location To display the location of a client within a site select the client then click on the Client Monitor window s toolbar The floor the client is currently on is displayed as w...

Page 446: ...SID the radio can hear Activity lists log messages for the radio RF Environment lists 802 11 statistics for the radio If data does not appear in the window check the bottom of the window for a message...

Page 447: ...io can hear select Transmitters To list the other transmitters that can hear the selected radio select Listeners Information is displayed for a radio if the radio sends beacon frames or responds to pr...

Page 448: ...This information comes from the site plan and is displayed only if the MAP is in the plan BSSID BSSID detected by the radio Note This column displays a single entry for each 3Com radio even if the rad...

Page 449: ...Type Type of event that caused the message Counter Measure Start The radio began countermeasures against a rogue transmitter Event information comes from the CounterMeasureStart trap Tx Power Change T...

Page 450: ...ists the information displayed in the top section of the RF Trends window Table 50 RF Monitor Environment Columns Column Description Channel Radio channel to which the other columns apply Noise Noise...

Page 451: ...d by the radio Throughput Rate at which data is transmitted by the radio in bits per second Associated Clients Number of clients associated with the radio Client Failures Combined number of the follow...

Page 452: ...ically 1 Click the checkbox next to Auto Refresh on the RF Trends window s toolbar to enable the option 2 Click Refresh Accessing Realtime Performance Statistics In addition to information supplied by...

Page 453: ...multiple contiguous objects click Shift while selecting To select multiple noncontiguous objects click Ctrl while selecting 4 Select the statistic type from the Monitoring Options box Ethernet Statist...

Page 454: ...are seeing the sum of the data of the sub objects For example a WX consists of ports Performance data for a WX is the sum of per port performance data values 7 To change the level of detail click the...

Page 455: ...interval value at beginning of polling interval time difference in seconds For example if the number of octets in is 11 101 288 at the beginning of the polling period the number of octets in is 11 14...

Page 456: ...le in the scope click the button next to Select Detail the button text depends on what scope you selected and select the object whose performance data you want to see You can also select the category...

Page 457: ...y Domain WX switches in the Mobility Domain or WX ports To see the objects available in the scope click the button next to Select Detail the button text depends on what scope you selected and select t...

Page 458: ...d on the polling interval you selected To see details for percentage based performance data You can see percentage data for the objects in the selected scope For example if you selected a Mobility Dom...

Page 459: ...ou can graph click Hide Object Selector Doing this allows you to see the graph in the full width of the Statistics tab Figure 15 shows the delta values for Octets In and Octets Out for the entire Mobi...

Page 460: ...directory of the user running 3WXM 3WXM remembers the directory you select when you next access the Export Data dialog box 3 To overwrite existing files select Overwrite Existing Files By default thi...

Page 461: ...itches in the network plan messages generated by the WX switches in the network plan that are being monitored by the monitoring service Displaying the event log To display the event log select View Ev...

Page 462: ...ent Filters To use predefined filters select one of the following from the Name list in the Stored Filters group box All Entries Shows all entries in the log 3WXM Shows only 3WXM client events Server...

Page 463: ...you want to see only 3WXM events If you have a WX named wx1 type wx1 to see only events related to wx1 To see events related to all WX switches whose names start with wx type wx To set the search crit...

Page 464: ...art box click the arrow to use the calendar to specify the day month and year Specify the starting time Between Only events that occurred between specified times In the Start box click the arrow to us...

Page 465: ...mational messages only No problems exist Debug Output from debugging By default all severity levels are selected Toggle the All checkbox to select or clear all severity levels 3 After selecting the se...

Page 466: ...ting Filtered Data You can export the filtered data shown in Event Viewer to a comma delimited text csv file To export filtered data 1 In the Event tab s toolbar click The Export Data dialog appears 2...

Page 467: ...le is copied to a file with a bak extension 5 Click Export You can see the status of the export process in the Results box 6 Click Close Reviewing Event Details To see the details for a specific event...

Page 468: ...468 CHAPTER 10 MONITORING THE NETWORK...

Page 469: ...ess points in your network or neighbor s network you can add them to the known devices list You also can enable countermeasures to prevent clients from using the devices that truly are rogues With 3WX...

Page 470: ...scan in the 2 4 GHz to 2 4835 GHz spectrum 802 11a radios scan in the 5 15 GHz to 5 85 GHz spectrum Both enabled radios and disabled radios perform these scans Dynamic Frequency Selection DFS Some re...

Page 471: ...ueDisappear CounterMeasureStart CounterMeasureStop The first two traps provide data about rogues when they are detected or disappear The latter two traps provide data for countermeasures Monitoring Se...

Page 472: ...eless service on a radio When a MAP radio is sending countermeasures the radio is disabled for use by network traffic until the radio finishes sending the countermeasures 1 In the Organizer panel righ...

Page 473: ...he toolbar in the main 3WXM window The Rogue Detection tab appears in the Content panel The Rogue Detection tab lists information about the rogue devices detected in the network The rogue list section...

Page 474: ...during the most recent polling interval the most recent hour the most recent day or detected farther back in the past The monitoring service keeps events in a circular log Once the log becomes full th...

Page 475: ...g service when you click the icon Auto Refresh Sets the window to automatically refresh the data at regular intervals based on the polling interval set on the monitoring service for rogue detection Fi...

Page 476: ...the period you selected To change the scope of the rogue list 1 Select the scope in the Organizer panel 2 Select Show for selected scope in the toolbar of the Rogue Detection tab 3WXM updates the rogu...

Page 477: ...tivity Log However at the end of the hour when the activity data is consolidated and moved to the Current Hour tab only one entry appears on that tab for the rogue On each tab the Polled Results colum...

Page 478: ...ot be current To display the location of a rogue within a site 1 Select the rogue in the rogue list 2 Click on the toolbar The Location tab appears next to the details tab The likely location of the r...

Page 479: ...he Rogue Detection tab you still can move a rogue to the known address list using the following procedure 1 Do one of the following to display the Create Known Address wizard In the Organizer panel ex...

Page 480: ...Current and click the Refresh option on the tab s toolbar Converting a Rogue into a Third Party AP If a device in the rogue list belongs to a third party AP in your network you can convert the rogue i...

Page 481: ...listed To remove a third party AP To remove a third party AP use the following procedure 1 In the Organizer panel click on Third Party APs The third party APs are listed 2 Right click on the third par...

Page 482: ...482 CHAPTER 11 DETECTING AND COMBATTING ROGUE DEVICES...

Page 483: ...r describes the reports you can generate with 3WXM Inventory Mobility Domain Configuration WX Configuration Client Summary Client Details Client Errors Watch List Client Network Usage RF Summary Radio...

Page 484: ...rders When you generate a report you can specify the scope of the report and the location where 3WXM saves the report Some reports also have additional options 3WXM saves the reports in HTML format Ge...

Page 485: ...n Report dialog box appears 2 Select the Mobility Domain for which you want the report The scope is always Mobility Domain and cannot be changed 3 To change the output directory for the report click o...

Page 486: ...me type with this new report click next to Overwrite Existing Files to deselect this option 5 Click Generate 6 When the report is generated click the report link to view it Table 58 lists the sections...

Page 487: ...0 Ports 10 100 Ethernet port settings configured on the WX switch Gig Ports Gigabit port settings if applicable configured on the WX switch VLANs VLANs configured on the WX switch Spanning Tree STP se...

Page 488: ...ctory and click Select 5 To prevent 3WXM from replacing an existing report of the same type with this new report click next to Overwrite Existing Files to deselect this option 6 Click Generate 7 When...

Page 489: ...wing from the listbox User Name IP Address MAC Address 4 Click on the Value field Erase the text in the field and type the username IP address or MAC address of the user depending on the selection cri...

Page 490: ...nable RF trending option located in the RF Monitor group box must be enabled See Changing Monitoring Settings on page 552 1 Select Reports Client Errors from the toolbar in the main 3WXM window The Cl...

Page 491: ...r clients on the watch list The data for this report comes from the monitoring service The Collect client connection roaming traps option located in the Client Monitor group box of the Monitoring Sett...

Page 492: ...tains the following sections Session Properties Location History Session Statistics AP Statistics See Using the Client Monitor Window on page 420 for information about the data columns in each section...

Page 493: ...nerate 8 When the report is generated click the report link to view it The network usage report contains the following sections Cumulative statistics for the scope of the report Usage statistics on in...

Page 494: ...generated click the report link to view it The RF summary report contains the following sections Cumulative data for the scope of the report Detailed data for each WX switch within the scope of the r...

Page 495: ...located in the Rogue Detection group box of the Monitoring Settings tab must be enabled See Changing Monitoring Settings on page 552 1 Select Reports Rogue Details from the toolbar in the main 3WXM w...

Page 496: ...Domain Site Building Floor 3 Select the instance for which you want the report For example if the scope is Building select the building 4 Select the time period for the report 1 Hour 24 Hours 7 Days...

Page 497: ...pe for the work order You can select the network plan a site a building or an individual floor 3 Select the options you want to use for the report RF Coverage RSSI Projections Show Disabled MAPs only...

Page 498: ...498 CHAPTER 12 GENERATING REPORTS...

Page 499: ...enView and 3WXM make sure you have the following configured SNMP trap receivers See Configuring SNMP on page 214 Syslog servers See Configuring Logging on page 218 Starting 3WXM from Network Node Mana...

Page 500: ...500 APPENDIX A USING 3WXM WITH HP OPENVIEW...

Page 501: ...3WXM logging Overview You can set 3WXM preferences for a user session on the system on which 3WXM is installed The preferences you set are valid only for that user on that system This chapter describ...

Page 502: ...nfiguration changes events and status changes on WX switches You can configure checking also called polling for configuration changes in the network made with the CLI Web Manager or another instance o...

Page 503: ...s unsuccessful 5 To have network status changes sent by email select Enable e mail notification To disable this option clear Enable e mail notification By default this option is disabled A message is...

Page 504: ...tion prompt after you close a wizard select the Warn checkbox To disable the confirmation prompt clear the Warn checkbox By default if you close a wizard a pop up box appears asking whether you want t...

Page 505: ...g box or click another tab to continue making changes Changing Persistence Options 3WXM can automatically save a network plan at regular intervals if you make changes while you are working If you do n...

Page 506: ...rval from 1 to 1440 minutes 24 hours in the Plan Change Notification Interval box The default is 1 minute 7 Click Close to close the Preferences dialog box or click another tab to continue making chan...

Page 507: ...em 5 Click Close to close the Preferences dialog box or click another tab to continue making changes Changing Certificate Management Options By default 3WXM does not accept self signed certificates fr...

Page 508: ...ou can change the following RF planning options Typical transmit power for clients in the 3Com network Color schemes for showing RF information Configuring the Typical Client s Transmit Power To chang...

Page 509: ...heme you can change a color using any of the following methods Select a color from a predefined palette Change the hue saturation and brightness HSB properties of a color Change the red blue and green...

Page 510: ...nformation about using the color palette see Defining a Color from the Palette on page 511 For more information about using HSB see Defining a Color by Changing HSB Properties on page 512 For more inf...

Page 511: ...color you want In the Preview box you can see the swatches and text in the color you chose The Recent box shows the colors you have chosen so far Click Reset to choose the original predefined color an...

Page 512: ...and 100 percent indicating full saturation Brightness is the amount of light in the color Brightness is also measured in percentages with 0 percent indicating black and 100 percent indicating white T...

Page 513: ...x specify a value between 0 and 100 percent Use the slider to specify the brightness value 5 Click OK to accept the color The RF Planning Options tab in the Preferences dialog box is active 6 Do one o...

Page 514: ...Close to close the Preferences dialog box Changing 3WXM Logging Options You can change the severity and type of 3WXM events that are logged By default the event logging level is set to Critical and al...

Page 515: ...o action is required Debug All events are shown including debug messages Select the Debug option only if 3Com Technical Support has advised you to do so Debug level logging significantly impacts netwo...

Page 516: ...516 APPENDIX B CHANGING 3WXM PREFERENCES...

Page 517: ...ual MAP check Verifies that a MAP in the network is also in the network plan Error Dual homed check Verifies that a MAP is either dual homed in both the network plan and the network or is not dual hom...

Page 518: ...e network unless the rule is enabled in 3WXM Warning Accounting server group check Verifies that no more than four server groups are specified for the accounting methods Error Bonded authentication pe...

Page 519: ...ion does not contain duplicate ACEs of the same type Warning Invalid ACL name Verifies that ACL names start with a letter and do not contain the terms all default action map help or editbuffer Error O...

Page 520: ...entication method Warning Table 65 Coverage Area Rules Title Description Classification 802 11g coverage area exclude 802 11b check Verifies that the 802 11g only mode or mixed 802 11b g mode setting...

Page 521: ...at manages the MAP Error Serial number check Verifies that the serial number is specified for a Distributed MAP Error Table 68 Dual Homed MAP Rules Title Description Classification MAP configuration c...

Page 522: ...itches in the network unless the rule is enabled in 3WXM Warning Accounting server group check for network users Verifies that no more than four server groups are specified for the accounting methods...

Page 523: ...ort list Error Table 73 Log Rules Title Description Classification Syslog servers check Verifies that a maximum of four syslog servers are configured Error Table 74 MAC Address User Rules Title Descri...

Page 524: ...Access rule disabled check Verifies whether the access rule is enabled in 3WXM The rule does not take effect and is not deployed to WX switches in the network unless the rule is enabled in 3WXM Warni...

Page 525: ...ger from 1 to 11 Error AAA user group attribute session timeout check Verifies that the Session Timeout attribute is in the range of 0 to 4 294 967 296 seconds Error AAA user group attribute start dat...

Page 526: ...le Description Classification Coverage area WX check Verifies that a coverage area within a Mobility Domain uses a WX in that Mobility Domain Error Duplicate IP address check Verifies that VLANs have...

Page 527: ...nt has a connection with the 3WXM monitoring service for the network plan The rule checks to ensure that the monitoring option is enabled in the client the IP address specified in the client for the m...

Page 528: ...ns that use trap data are enabled Error SNMP trap receiver check Verifies that the option to add the monitoring service s IP address to a monitored WX switch s list of trap receivers is enabled Error...

Page 529: ...mode Error Table 88 STP Port Rules Title Description Classification STP portfast check Verifies that all STP port members for a port or port group have the same STP PortFast settings for all VLANs Err...

Page 530: ...s that a Mobility Profile attribute specified for a user or user group exists Warning AAA user group attribute service type check Verifies that the Service Type is an integer from 1 to 11 Error AAA us...

Page 531: ...t YY MM DD HH MM Error Table 92 VLAN Rules Title Description Classification Broadcast address check Ensures that the IP address assigned to the VLAN is not a broadcast address Error Empty IP address c...

Page 532: ...an authentication method Error Local user database check Verifies that at least one user is configured in the local database if LOCAL is specified as an authentication method Warning Missing service p...

Page 533: ...stem IP address for the WX is assigned if the WX is managed Assignment means that the system IP address has been assigned to a VLAN and the VLAN has a non zeros IP address Error Table 94 Wireless Swit...

Page 534: ...534 APPENDIX C 3WXM VERIFICATION RULES...

Page 535: ...ttings changing monitoring settings and accessing the monitoring service log Overview To set monitoring service preferences select Tools 3WXM Services Setup from the toolbar in the main 3WXM window Se...

Page 536: ...bs the monitoring service verifies the changes If the changes are valid the service implements the changes Otherwise the service displays error messages and does not implement the changes By default t...

Page 537: ...n Windows XP The window might look different on your system 2 Scroll down and select 3WXM Services 3 Select the Start or Stop option 4 Close the Services window 5 Within 3WXM enable it to access the s...

Page 538: ...alified hostname of the machine on which the service is installed If the service is installed on the same machine as the one you are using to run 3WXM enter 127 0 0 1 as the IP address This is a stand...

Page 539: ...number Verify that the service is running on the server Connection error for address ip addr tcp port number Verify that the service has been started If the service is running verify that the certifi...

Page 540: ...the certificate presented by the monitoring service to ensure that the certificate is valid The certificate is in a key store file on the server The default key store file is services_keystore This f...

Page 541: ...se the following procedure 1 Select one or both of the following options Always accept self signed certificates Use this option to configure the 3WXM client to always accept a self signed certificate...

Page 542: ...e port number in the HTTPS Server Port box The default is 443 CAUTION When you click Save all instances of the 3WXM client lose connection with the service and will need to reconnect on the new port n...

Page 543: ...g on other machines to access the monitoring service on this machine select Allow remote access By default only local access is allowed 11 To restrict access to the monitoring service to specific user...

Page 544: ...f WX switches monitored by the service Add Monitor Account Users with the monitor role can enable 3WXM to access the service but cannot change any service preferences b Enter a username The name does...

Page 545: ...cting WX Switches to Monitor You must specify the WX switches you want the service to monitor You can add all the WX switches from a Mobility Domain in the network plan or individual WX switches The i...

Page 546: ...ice does not automatically monitor the WX switches CAUTION If the IP address or other information about a monitored WX switch changes do not delete and readd the switch using the Add From Plan option...

Page 547: ...Selecting WX Switches to Monitor 547 3 To add all the WX switches from a Mobility Domain in the network plan click Add From Plan The Network Plan WX dialog box is displayed...

Page 548: ...column select the row for the WX switch then click Modify Go to step 4c 4 To add an individual WX switch click Add The Monitored WX dialog box is displayed a Type the WX switch name in the Name box b...

Page 549: ...or a WX switch select the WX switch then click Modify The Monitored WX dialog box is displayed See step 4 7 To enable SNMP traps on a monitored WX switch and add the monitoring service to the WX switc...

Page 550: ...el the changes 11 Click another tab to configure more settings or click Close to close the 3WXM Services Setup dialog box Changing WX Connection Settings The WX connection settings control the timeout...

Page 551: ...conds 4 To change the number of times the monitoring service will reattempt to query a WX switch if the monitoring service does not receive a reply to the first query attempt within the connect timeou...

Page 552: ...ryptography Standard number 12 the standard format used by Unix machines JKS Java Key Store a format used by Java platforms and applications c Enter the password in the Password box When both the Acce...

Page 553: ...r tab Client Monitor window Enable client session collection option Disabled Collect client connection failure traps option which uses these SNMP traps received by the monitoring service from monitore...

Page 554: ...ng service from monitored WX switches AutoTuneRadioChannelChange AutoTuneRadioPowerChange CounterMeasureStart CounterMeasureStop Disabled Monitor tab RF Trends window Collect radio activity traps opti...

Page 555: ...ervices Setup The 3WXM Services Setup dialog box appears See Figure 17 on page 536 2 Click the Monitoring Settings tab 3 To change the number of minutes between status queries from the monitoring serv...

Page 556: ...nterval is 5 minutes and cannot be changed b To enable the monitoring service to track client connection failures select Collect client connection failure traps This option enables the monitoring serv...

Page 557: ...ng sensitivity can increase without triggering a TCA You can specify from 0 to 20 decibels dB The default is 6 dB When a TCA is triggered the alert is displayed as a red flag in the link view of the E...

Page 558: ...king Up the Database The monitoring service regularly backs up the database based on the backup settings specified on the Service Settings tab In addition to these regular backups you can create a bac...

Page 559: ...ice on page 537 2 Access a command line interface on the machine where the monitoring service is installed 3 Enter the following command dbtools restore filename zip where filename zip is the name of...

Page 560: ...560 APPENDIX D CHANGING MONITORING SERVICE PREFERENCES...

Page 561: ...oduct please contact 3Com Global Services for assistance Purchase Value Added Services To enhance response times or extend warranty benefits contact 3Com or your authorized 3Com reseller Value added s...

Page 562: ...d related documentation you must first purchase a service contract from 3Com or your reseller Telephone Technical Support and Repair To enable telephone support and other service benefits you must fir...

Page 563: ...0 446 398 61 2 9937 5083 Philippines P R of China Singapore S Korea Taiwan Thailand 1235 61 266 2602 or 1800 1 888 9469 800 810 3033 800 6161 463 080 333 3308 00801 611 261 001 800 611 2000 You can al...

Page 564: ...ama Paraguay Peru Puerto Rico Salvador Trinidad and Tobago Uruguay Venezuela Virgin Islands AT T 800 998 2112 57 1 657 0888 AT T 800 998 2112 1 800 998 2112 571 657 0888 01 800 849CARE AT T 800 998 21...

Page 565: ...347 dynamic 360 mapping 359 naming guidelines 349 static 361 ad hoc users 470 administrative access 316 administrative users 316 administrator access rules accounting 322 authentication 321 creating...

Page 566: ...lying changes to WX switches 400 applying WX configuration changes to 402 double asterisks in user globs 317 in VLAN globs 318 drawing cropping cropping paper space 117 dynamic ACLs 360 Dynamic Freque...

Page 567: ...local user database 301 location policies configuring 339 creating location policy rules 340 log files installation 30 logging configuring 218 setting up a syslog server 221 setting up system logging...

Page 568: ...autosave 505 certificate management 507 logging 514 network synchronization 502 resetting all preferences 502 resetting tab values 502 RF planning colors 508 tools 506 user interface 504 R radio prof...

Page 569: ...P ACE creating 352 unauthorized access points 469 unpacking installation files 22 uplink fast convergence 205 uploading WX configuration 370 user attributes configuring 310 user globs 317 delimiter ch...

Page 570: ...list adding users to 443 Web authentication enabling 214 WEP Wired Equivalent Privacy protocol configuring 260 dynamic 260 encryption choices 264 static 261 wildcards in user globs 317 in VLAN globs 3...

Reviews: