background image

Known Problems

21

time. This can occur if the DHCP server that responds 
to the DHCP request after the second reboot is not 
the same server that responded to the first request.

This issue does not prevent the MAP from operating 
normally but can make managing the MAP more diffi-
cult if the address the MAP receives the second time is 
not predictable. To prevent the MAP from using more 
than one address, use static address assignment in 
your DHCP server.

An 802.11g radio might enter 802.11b protection 
mode if an 802.11g radio advertises its 802.11b 
and 802.11g rates separately. (17222)

Some third-party access points advertise the 802.11b 
transmit data rates they support in one information 
element (IE) and the extended 802.11g-only data 
rates they support in another IE. An AP2750 802.11g 
radio responds to this by assuming the other radio is 
an 802.11b radio and enters 802.11b protection 
mode. 

To guard against interference, an 802.11b/g radio in 
protection mode sends messages while 802.11g traf-
fic at higher data rates is being sent, to inform 
802.11b devices about the 802.11g traffic and 
reserve bandwidth for the traffic. Protection mode 
affects overall traffic throughput due to the additional 
messages sent by 802.11b/g radios. 

When the radio enters protection mode, a message 
such as the following appears in the WX switch’s log 
buffer:

MAP Jul 09 21:01:36.845822 WARNING Port 5 
ap_radio: 802.11b protection enabled due to 

proximity to network with BSSID of 
00:0b:0e:00:fd:c0

The display ap status command shows 802.11b 
protection enabled after an 802.11b/g radio is 
reconfigured for 802.11b or 802.11a. (15308)

If you reconfigure an 802.11b/g radio to support 
802.11b (without 802.11g) or 8012.11a, the 

display 

ap status

 command shows the radio’s state as con-

figure succeed (802.11b protect), even though pro-
tection mode is inapplicable because 802.11g is 
disabled on the radio. 

You can safely ignore the 802.11b protect indication 
in the command output. This issue is cosmetic only 
and does not affect the operation of the radio.

3WXM Issues

Deleting PEAP-MS-CHAP-V2 AAA methods in an 
802.1X policy with 3WXM might not be reflected 
on the WX switch. (14157)

If you specify multiple AAA methods (for example, 
multiple server groups) for a PEAP-MS-CHAP-V2 
802.1X policy, and you remove the last method with 
3WXM, the WX switch might still use the removed 
method. For example, if the 802.1X policy contains 
the following methods, and you use 3WXM to 
remove method sg3, the WX switch continues to use 
sg3:

set authentication dot1x ssid any EXAMPLE\* 
peap-mschapv2 sg1 sg2 sg3

Содержание OfficeConnect WX1200

Страница 1: ...cting exe that you have downloaded from the 3Com Web site Points to Note when using the WX1200 and WX4400 Follow these best practice recommendations during configuration and implementation to avoid or...

Страница 2: ...le below lists the NICs that have been used successfully with MSS The majority were tested using recently available drivers using the Microsoft native 802 1X client and a Microsoft IAS RADIUS server 3...

Страница 3: ...ds that you set up a sepa rate service profile for WPA CCMP with a different SSID for compatibility If you are migrating from Dynamic WEP to WPA TKIP 3Com recommends creat ing separate service profile...

Страница 4: ...e to the client through the MAP for the duration of the 802 1X quiet period timer which defaults to 60 seconds An error mes sage indicating that a client has failed authorization appears in the WX swi...

Страница 5: ...Some drivers install this automatically if you run the setup exe utility to install the driver 3Com strongly recommends that you update the driver manually using the driver properties in the Network c...

Страница 6: ...ble WEP encryption When using dynamic WEP in Windows 2000 select static WEP 128bit and enter any static WEP key as a placeholder This temporary key configures the driver to use WEP to encrypt packets...

Страница 7: ...the current Panther client If you need to run both WPA TKIP and Dynamic WEP at the same time you must configured separate service profiles for each encryption type in order to maintain compatibility w...

Страница 8: ...KB826942 or Hotfix KB822596 Windows 2000 requires hotfix KB822596 Using PEAP MS CHAP V2 with computer authenti cation will allow users who have never logged on to a PC authenticate wirelessly without...

Страница 9: ...LDAP with specific protocols as noted in the table The tests were initially performed using Dynamic WEP though subsequent testing has revealed no noticeable differ ences in RADIUS compatibility when...

Страница 10: ...pe in this case Dynamic WEP Additionally compatibility with wireless NICs is reduced Downloading the latest drivers for your wireless NIC is strongly recommended See 802 1X Cli ents for specific infor...

Страница 11: ...rmation Security Best Practices MSS and 3WXM provide robust options for securing management access to WX switches and to the 3WXM client and 3WXM monitoring service To opti mize security for managemen...

Страница 12: ...SNMP if not already disabled use the set ip snmp server disable command To change the community strings use the set snmp community command CLI Access MSS allows CLI access through the console through...

Страница 13: ...the one where you installed the certificate signed by the CA Communication between the WX Switch and 3WXM or Web Manager Administration certificate requirement 11974 Before the WX switch can communica...

Страница 14: ...atedly disables and reenables the link caus ing STP to repeatedly stop the other device s port from forwarding traffic As a result the boot attempt is never successful To allow a MAP to boot over a li...

Страница 15: ...c For a user ACL to take effect you must explicitly set both the source and destina tion addresses in the ACL Add Authentication Rules for Last Resort Access to Any SSID Last resort authentication is...

Страница 16: ...o use these strings you will need to con figure them manually To configure an SNMP commu nity string use the set snmp community command The quickstart command prompts for time and date parameters 1817...

Страница 17: ...ng on the license WX1200 20 configured 12 active Includes directly attached MAPs and Distributed MAPs Inactive configurations are backups Minimum link speed within a Mobility Domain 128 Kbps Network P...

Страница 18: ...t 18367 MSS can tunnel traffic for a VLAN through a WX switch that does not have that VLAN statically config ured If you attempt to add a static VLAN to a switch that is already tunneling traffic for...

Страница 19: ...ed Below is an example of the error message This applies to both MX1200 and MX4400 Example Starting supervisor 3 0 3 0_110304_WX1200 SPAN Nov 05 07 01 44 073135 ERROR SPAN_VLAN_ERR span_port_change po...

Страница 20: ...port group before you add the groups ports to the VLAN then add the port group to the VLAN MAP Issues WX1200 allows configuration of ports 7 and 8 as MAP access ports 18280 Ports 7 and 8 on the WX120...

Страница 21: ...e to the additional messages sent by 802 11b g radios When the radio enters protection mode a message such as the following appears in the WX switch s log buffer MAP Jul 09 21 01 36 845822 WARNING Por...

Страница 22: ...tem IP address from 3WXM causes the switch to be unmanageable from 3WXM 18414 If you use 3WXM to change a managed switch s system name or system IP address other changes to the switch are not received...

Страница 23: ...conds with the following command set arp agingtime 1200 Logging in to SSH requires hitting Enter twice 15613 When you start an SSH session with a WX switch the switch does not display the login prompt...

Страница 24: ...rt become congested and another instance of the RADIUS server on the same machine is configured to use a different UDP port number MSS does not allow you to specify the UDP port number of a RADIUS ser...

Страница 25: ...s However the commands that con figure MAC Web and last resort network access rules accept the value This is an invalid configuration and can provide unexpected results The command for configuring 802...

Страница 26: ...tatistics output The display radius command is not documented and has no output 18233 Web AAA Issues Web AAA users receive page not found error if RADIUS is the authentication method 17752 If you use...

Страница 27: ...he ACE name that starts with abc which is not a CLI keyword is accepted WX1200 set security acl ip port_abc deny 0 0 0 0 255 255 255 255 error Wrong ACL name input port_abc WX1200 set security acl ip...

Страница 28: ...tream through a MAP stop receiving the stream if one of the clients leaves the group Do not disable IGMP snooping The feature is enabled by default Invalid IP multicast forwarded 12784 IGMP multicast...

Отзывы: