Manuel d'utilisation / d'entretien du produit 3CRWX440095A du fabricant 3Com
Aller à la page of 536
http://www.3com.com/ Part No. 730-9502-0072, Revis ion B Published April 200 5 Wir eless LAN Mobility System W ir eless LAN Switch and Contr oller Command Refer ence 3CRWX120695A, 3 CRWX440095A.
3Com Corporati on 350 Campus Drive Marlborough, MA USA 01752-3064 Copyright © 2 004, 3Com Corporatio n. All rights reserv ed . No part of this documen tation may be repr oduced in any form or by any means or used to make any derivative work (such as translation, transformation, or adaptation) without writt en permission fr om 3Com Cor poration.
C ONTENTS A BOUT T HIS G UIDE Conventions 17 Documentation 18 Documentation Comments 19 1 U SING THE C OMMAND -L INE I NTERFACE Overview 21 CLI Conventions 22 Command Prompt s 22 Syntax Notation 22 T .
3 S YSTEM S ERVICE C OMMANDS Commands by Usage 37 clear banner motd 38 clear history 38 clear promp t 39 clear system 39 display banner mo td 40 display base-information 41 display license 41 display .
reset port 73 set dap 73 set port 76 set port-group 77 set port name 78 set port negotiation 7 9 set port poe 79 set port preference 80 set port speed 81 set port trap 82 set port type ap 83 set port .
clear ip telnet 112 clear ntp server 113 clear ntp update-interval 113 clear snmp trap receiver 114 clear summertime 115 clear system ip-address 115 clear timezone 116 display arp 117 display interfac.
set ntp server 148 set ntp update- interval 149 set snmp commun ity 150 set snmp trap 151 set snmp trap receiver 153 set summertime 154 set system ip-addr ess 155 set timedate 156 set timezone 157 tel.
set accounting {admin | console} 186 set accounting {dot1x | mac | web} 187 set authentication admin 189 set authentication cons ole 191 set authentication dot 1x 193 set authentication last-resort 19.
display {ap | dap} etherstats 243 display {ap | dap} gr oup 245 display {ap | dap} status 246 display auto-tune at tributes 249 display auto-tune neigh bors 251 display dap connection 253 display dap .
set radio-pr ofile mode 291 set radio-pr ofile pr eamble-leng th 294 set radio-pr ofile rts-thr eshold 295 set radio-pr ofile service-pr ofile 296 set radio-pr ofile short-r etry 299 set service-profi.
display spantree portfast 32 8 display spantree portvlancost 329 display spantree statistics 329 display spantree uplinkfast 335 set spantree 336 set spantr ee backbonefast 337 set spantr ee fwddel ay.
12 S ECURITY ACL C OMMANDS Security ACL Commands by Usage 369 clear security acl 370 clear security acl map 371 commit security acl 373 display security acl 374 display security acl hits 375 display s.
set radius server 415 set server gr oup 417 set server gr oup lo ad-balance 418 15 802.1X M ANAGEMENT C OMMANDS Commands by Usage 421 clear dot1x bonded-p eriod 422 clear dot1x max-req 423 clear dot1x.
17 RF D ETECTION C OMMANDS Commands by Usage 455 clear rfdetect countermeasu res mac 456 clear rfdetect ignore 457 display rfdetect countermeasures 458 display rfdetect data 459 display rfdetect ignor.
19 T RACE C OMMANDS Commands by Usage 491 clear log trace 491 clear trace 492 display trace 493 save trace 494 set trace authentication 494 set trace authorization 495 set trace dot1x 496 set trace sm.
version 524 A O BTAINING S UPPORT FOR YOUR P RODUCT Register Y our Product 527 Purchase V alue-Added Services 527 T roubleshoot Online 528 Access Software Downloads 528 T elephone T echnical S upport .
Conventions 17 A BOUT T HIS G UIDE This command refer ence explains Mobility System Softwar e (MSS™) command line interface (CLI) that you enter on a 3Com WX1200 W ireless Switch or WX4400 W ireless LAN Contro ller to configur e and manage the Mobility System™ wireless LAN (WLAN).
18 A BOUT T HIS G UIDE This manual uses the follo wi ng text and syntax conventions: Documentation The MSS documentation set includ es the following documents. Wireless LAN Switch Manage r (3WXM) Release Notes These notes provide information about the system software release, including new features and bug fixes.
Documentation Comments 19 Wireless LAN Switch Ma nager Refere nce Manual This manual shows you how to plan , configure, deploy , and manage a Mobility System wireless LAN (WL AN) using the 3Com Wireless LAN Switch Manage r (3WXM).
20 A BOUT T HIS G UIDE.
1 U SING THE C OMMAND -L INE I NTERFACE This chapter discusse s the 3Com W ireless Switch Manager (3WXM) command-line interface (CLI). Describe d are the CLI conventions (see “CLI Conventions” on .
22 C HAPTER 1: U SING THE C OMMAND -L INE I NTERFACE CLI Conventions Be awar e of the following MSS CL I conventions for command entry: “Command Prompts” on page 22 “Syntax Notation” o.
CLI Conventions 23 A vertical bar ( | ) separates mutually exclusive options within a list of possibilities. For example , you enter either enable or disable , not both, in the following command: .
24 C HAPTER 1: U SING THE C OMMAND -L INE I NTERFACE IP Addr ess and Mask Notation MSS displays IP addresses in dotte d d ecimal notation — for example, 192.
CLI Conventions 25 T able 3 giv es examples of user gl obs. MAC Address Globs A media access control (MAC) address glob is a similar method for matching some authentication, aut horization, and accounting (AAA) and forwarding database (FDB) commands to one or more 6-byte MAC addresses.
26 C HAPTER 1: U SING THE C OMMAND -L INE I NTERFACE VLAN Globs A VLAN glob is a method for matching one of a set of local rules on an wireless LAN switch, known as th e location policy , t o one or more users.
Command-Line Editing 27 A hyphen-separated ran ge of port numbers, with no spaces. For example: WX1200# reset port 1-3 Any combination of single numbers, lists, and ranges.
28 C HAPTER 1: U SING THE C OMMAND -L INE I NTERFACE History Buffer Th e history buffer stores the last 63 commands you entered during a terminal session . Y ou can use the Up Arr ow and Do wn Arr ow keys to select a command that yo u want to repeat fr om the history buffer .
Using CLI Help 29 Using CLI Help The CLI provides online help. T o see t he full range of commands available at your access level, type the help command.
30 C HAPTER 1: U SING THE C OMMAND -L INE I NTERFACE T o see all the variations, type one of the commands followed by a question mark (?). For exampl e: WX1200# display ip ? alias display ip aliases d.
Understanding Command Descriptions 31 One or more examples of the command in context, with the appropriate system prompt and r esponse. One or more r elated commands.
32 C HAPTER 1: U SING THE C OMMAND -L INE I NTERFACE.
2 A CCESS C OMMANDS This chapter describes access comma nds used to control access to the Mobility Software System (MSS) command-line interface (CLI). Commands by Usage This chapter presents access services comma nds alphabetically . Use T able 5 to located commands in this chapter based on their use.
34 C HAPTER 2: A CCESS C OMMAND S See Also enable on page 34 enable Places the CLI session in enabled mo de, which pro vides access to all commands requir ed for configur ing and monitoring the system. Syntax — enable Access — All. History — Introduced in MSS V ersion 3.
set enablepass 35 set enablepass Sets the password that provides enabled access (for configuration and monitoring) to the WX switch. Syntax — set enablepass Defaults — None. Access — Enabled. History — Introduced in MSS V ersion 3.0. Usage — After typing the set enablepa ss comman d, pr ess Enter .
36 C HAPTER 2: A CCESS C OMMAND S.
3 S YSTEM S ERVICE C OMMANDS Use system services commands to configur e and moni tor system information for a WX switch. Commands by Usage This chapter presents system services commands alph abetically . Use T able 6 to located commands in this chapter based on their use.
38 C HAPTER 3: S YSTEM S ERVICE C OMMANDS clear banner motd Deletes the message-of-the-day (MOTD) banner t hat is displayed before the login prompt for each CLI se ssion on the wir eless LAN switch. Syntax — clear banner motd Defaults — None. Access — Enabled.
clear prompt 39 Examples — T o clear the hist ory buf fer , type the f ollowing command: WX4400# clear history success: command buffer was flushed. See Also history on page 46 clear prompt Resets the system pr ompt to its previously configured value.
40 C HAPTER 3: S YSTEM S ERVICE C OMMANDS location — Resets the location o f the WX swi tch to nu ll. name — Resets the name of the WX switch to the default system name, which is the model number . Defaults — None. Access — Enabled. History — —Introduced in MSS V ersion 3.
display base-information 41 See Also clear banner motd on page 38 set banner motd on page 46 display base-information Provides an in-depth snapshot of th e status of the wireless LAN switch, which includes details about the bo ot image, the version, ports, and other configuration values.
42 C HAPTER 3: S YSTEM S ERVICE C OMMANDS Defaults — None. Access — All. Examples — T o view the WX switch license, type the following command: WX4400# display license Serial Number : M8XE4IBB8D.
display system 43 ==================================== ================================ =========== Fan status: fan1 OK fan2 OK fan3 O K Temperature: temp1 ok temp2 ok te mp3 ok PSU Status: Lower Power Supply DC ok AC ok Upper Power Supply mis sing Memory: 97.
44 C HAPTER 3: S YSTEM S ERVICE C OMMANDS See Also clear system on page 39 set system contact on page 51 set system countrycode on page 51 set system ip-address on page 53 set syst.
help 45 help Displays a list of commands that ca n be used to conf igur e and monitor the WX switch. Syntax — help Defaults — None. Access — All. History — Introduced in MSS V ersion 3.0. Examples — Use this command to se e a list of available commands.
46 C HAPTER 3: S YSTEM S ERVICE C OMMANDS See Also “Using CLI Help” on page 29 history Displays the command history buf fer for the current CLI session. Syntax — history Defaults — None. Access — All. History — Introduced in MSS V ersion 3.
set confirm 47 Usage — T ype a car et ( ^ ), then the message, then another caret. Do not use the following char acters wi th commands in which you set text to be displayed on the W X switch, such a.
48 C HAPTER 3: S YSTEM S ERVICE C OMMANDS MSS displays a message r equiring c onfirmation when you enter certain commands that can have a potentially large impact on the network.
set license 49 set license Installs an upgrade license, for managing more MAPs. Syntax — set license license-key activat ion-key license-key — License key , starting wi th WXL. Y ou can enter the key with or without the hyphens. activation-key — Activation key , starti ng with WXA.
50 C HAPTER 3: S YSTEM S ERVICE C OMMANDS set prompt Changes the CLI prompt for the WX switch to a string you specify . Syntax — set prompt string string — Alphanumeric string up to 32 characters long. T o include spaces in the prompt, you must enclose the string in double quotation marks ( “” ).
set system contact 51 set system contact Stores a contact name for the WX switch. Syntax — set system contact string string — Alphanumeric string up to 256 characters long, with no blank spaces. Defaults — None. Access — Enabled. History — Introduced in MSS V ersion 3.
52 C HAPTER 3: S YSTEM S ERVICE C OMMANDS Belgium BE Brazil BR Canada CA China CN Czech Republic CZ Denmark DK Finland FI France FR Germany DE Greece GR Hong Kong HK Hungary HU Iceland IS India IN Ire.
set system ip-address 53 Defaults — The factory default country code is None. Access — Enabled. History — Introduced in MSS V ersion 3.0. Usage — Y ou must set the system count y code to a valid value before using any set ap commands to configure a MAP .
54 C HAPTER 3: S YSTEM S ERVICE C OMMANDS Defaults — None. Access — Enabled. History — Introduced in MSS V ersion 3.0. Examples — The following co mmand sets the IP addr ess of the WX switch to 192.168.253.1: WX4400# set system ip-address 192.
set system name 55 set system contact on page 51 set system name on page 55 set system name Changes the name of the WX switch from the default system name and also provides content for the CLI prompt, if you do not specify a prompt.
56 C HAPTER 3: S YSTEM S ERVICE C OMMANDS.
4 P ORT C OMMANDS Use port commands to configure a nd manage individual ports and load-sharing port groups. Commands by Usage This chapter presents port command s alphabetically .
58 C HAPTER 4: P ORT C OMMANDS clear dap Removes a Distributed MAP . CAUTION: When you clear a Distributed MAP , MSS ends user sessions that are using the MAP . Syntax — clear dap dap-num dap-num — Number of the Distributed MAP(s) you want to remove.
clear port-group 59 Access — Enabled. History — Introduced in MSS V ersion 3.0. Examples — The following co mmand clears all port statistics counters and resets them to 0: WX4400# clear port cou.
60 C HAPTER 4: P ORT C OMMANDS Defaults — None. Access — Enabled. History — Introduced in MSS V ersion 3.0. Examples — The following co mmand clears the names of ports 1 through 3: WX4400# cle.
clear port type 61 clear port type Removes all configuration settings from a port and resets the port as a network port. CAUTION: When you clear a port, MSS ends user sessions that are using the port. Syntax — clear port type port-list port-list — List of physical ports.
62 C HAPTER 4: P ORT C OMMANDS Examples — The following co mmand clears port 5: WX1200# clear port type 5 This may disrupt currently authentic ated users. Are you sure? (y/n) [n] y success: change accepted. See Also set port type ap on page 83 set port type wir ed-auth on page 86 display port counters Displays port statistics.
display port-group 63 Examples — The following co mmand shows octet statistics for port 3: WX1200> display port counters octets port 3 Port Status Rx Octets Tx Octets ============================.
64 C HAPTER 4: P ORT C OMMANDS See Also clear port-group on page 59 set port-group on page 77 display port poe Displays status inf ormation for ports on which Power over Ether net (PoE) is enabled. Syntax — display port poe [ port-list ] port-list — List of physical ports.
display port preference 65 See Also set port poe on page 79 display port prefer ence Displays the interface prefer ences set on WX4400 gigabit Ethernet ports. Syntax — display port preference [ port-list ] port-list — List of physical ports.
66 C HAPTER 4: P ORT C OMMANDS Port Preference ==================================== ======================= 1 GBIC 2 RJ45 3 GBIC 4 GBIC T ab le 13 describes the fields in this display . See Also clear port prefer ence on page 6 0 set port prefer ence on page 8 0 display port status Displays configuration and status information for p orts.
display port st atus 67 WX1200# display port status Port Name Admin Oper Config Actual Type Media ==================================== ================================ =========== 1 1 up up auto 100/f.
68 C HAPTER 4: P ORT C OMMANDS See Also clear port type on page 61 set port on page 76 set port name on page 78 set port negotiation on page 79 set port speed on page 81 set port type ap on page 83 set port type wir ed-auth on page 86 monitor port counters Displays and continually updates port statistics.
monitor port counters 69 Defaults — All types of statistics ar e displayed for all ports. MSS refr eshes the statistics every 5 seconds. This interval cannot be configured.
70 C HAPTER 4: P ORT C OMMANDS Examples — The following command starts the port statistics monitor beginning with octet st at istics (the default): WX4400# monitor port counters As soon as you press Enter , MSS clears the window and displays statistics at the top of th e window .
monitor port counters 71 packets Rx Unicast Number of unicast packets received. This number does not include packets that contain errors. Rx NonUnicast Number of broadcast and multicast packets received. This number does not include packets that contain errors.
72 C HAPTER 4: P ORT C OMMANDS See Also display port counters on page 62 collisions Single Co ll Total number of frames transmitted that experienced one collision before 64 bytes of the frame were transmitted on the network.
reset port 73 reset port Resets a port by toggling its link state and Power over Ethe rnet (PoE) state. Syntax — reset port port-list port-list — List of physical ports. MSS r esets all the specified ports. Defaults — None. Access — Enabled.
74 C HAPTER 4: P ORT C OMMANDS dap-num — Number for the Distributed MAP . The range of valid connection numbers depends on the WX switch model: For a WX4400, you can specify a number from 1 to 256. For a WX1200, you can specify a number from 1 to 30.
set dap 75 mp-372 — Contains one 802.11a radio and one 802.11b radio, and a connector for an exter nal antenna for the 802.11b/g radio. Also contains a connecto r for an optional exter nal 802.11a antenna. T o specify the antenna mo del, use the following command: set {ap | dap} radio antennatype .
76 C HAPTER 4: P ORT C OMMANDS The following command removes Distributed MA P 1: WX4400# clear dap 1 This will clear specified DAP device s. Would you like to continue? (y/n) [n ] y See Also clear.
set port-group 77 See Also reset port on page 73 set port-group Configur es a load-sharing port group. All ports in the group function as a single logical link. Syntax — set port-group name group-name port-list mode { on | off } name group-name — Alphanumeric string of up to 255 characters, with no spaces.
78 C HAPTER 4: P ORT C OMMANDS The following commands disable the link for port group ser ver1, change the list of ports in the group, and r eenable the link: WX1200# set port-group name server1 1-5 mode off success: change accepted. WX1200# set port-group name server1 1-4,7 mode on success: change accepted.
set port negotiation 79 set port negotiation Disables or reenables autonegotiati on on gigabit Ether net or 10/100 Ether net ports. Syntax — set port negotiation port-list { enable | disable } port-list — List of physical ports. MSS disables or r eenables autonegotiation on all the specified ports.
80 C HAPTER 4: P ORT C OMMANDS Defaults — PoE is disabled on network and wire d authentication po rts. The state on MAP access point ports depends on whether you enabled or disabled PoE when setting the port type. See set port type ap on page 83. Access — Enabled.
set port speed 81 Access — Enabled. History — Introduced in MSS V ersion 3.0. Usage — This command applies only to the WX4400. If you set the prefer ence to RJ-45 (copper) on a port that already has an active fiber link, MSS immediately cha nges the link to the copper interface.
82 C HAPTER 4: P ORT C OMMANDS Examples — The follo wing command sets the port speed on ports 1 and 3 through 4 to 10 Mbps and sets the operating mode to fu ll-duplex: WX1200# set port speed 1,3-4 10 set port trap Enables or disab les Simple Netw ork Manage ment Pr otocol (S NMP) linkup and linkdown traps on an individu al port.
set port type ap 83 set port type ap Configures an WX switch port for an MAP access point. CAUTION: When you set the po rt type for MAP use, you must specify the PoE state (ena ble or disable) of the port. Use the WX switch’ s PoE to power 3Com MAP access points only .
84 C HAPTER 4: P ORT C OMMANDS mp-122 — Contains one 80 2.11a radio and one 802.11b/g r adio. mp-241 — Contains one radio that can be configur ed through software for 802.11a or 802.11b/g. mp-252 — Contains one 80 2.11a radio and one 802.
set port type ap 85 MAP model MP-262 requires an external antenna for the 802.11b/g radio. Y ou must specify the ante nna model. MAP models MP-341 and MP-352 have an intern al 802.1b/g an tenna as well as a connect or for an extern al antenna, so use of a n ex ternal antenna is optional on these models.
86 C HAPTER 4: P ORT C OMMANDS The following command sets ports 1 through 3 and port 5 for MAP access point model AP7250 an d enables PoE on the ports: WX1200# set port type ap 1-3,5 model ap7250 poe enable This may affect the power applied on the configured ports.
set port type wired-auth 87 Syntax — set port type wired-auth port-list [ tag tag-list ] [ max-sessions num ] port-list — List of physical ports. tag-list — One or more numbers between 1 and 4094 that subdivide a wired authentication port into virtual ports.
88 C HAPTER 4: P ORT C OMMANDS The following command sets port 7 for a wired authentication user and subdivides the port into three virtual ports to support thr ee simultaneous user sessions: WX1200# .
5 VLAN C OMMANDS Use virtual LAN (VLAN) c ommands to configure and manage parameters for individual por t VLANs on network ports, and to display information about clients roaming within a mobility domain. Commands by usage This chapte r pr esents V LAN comm ands alphabetically .
90 C HAPTER 5: VLAN C OMMANDS clear fdb Deletes an entry fr om the forwarding database (FDB). Syntax — clear fdb { perm | static | dynamic | port port-list } [ vlan vlan-id ] [ tag tag-valu e ] perm — Clears permanent entries. A permanent entry does not age out and remains in the database even after a r eboot, r eset, or power cycle.
clear vlan 91 The following command clears all dynamic forwarding database entries that match all VLANs: WX4400# clear fdb dynamic success: change accepted. The following command clears all dynamic forwarding database entries that match ports 3 and 5: WX4400# clear fdb port 3,5 success: change accepted.
92 C HAPTER 5: VLAN C OMMANDS Usage — If you do not spec ify a port-list , the entir e VLAN is r emoved from the configuration. Y ou cannot delete the default VLAN but you can remove ports from it. T o remove ports from the default VLAN, use the port port-list option.
display fdb 93 perm — Displays permanent entries. A permanent entry does not age out and remains in the database even after a reboot, r eset, or power cycle. static — Displays static entries. A static en try does not age out, but is removed from the database afte r a reboot, reset, or power cycle.
94 C HAPTER 5: VLAN C OMMANDS The following command displays all entries that begin with th e MAC address glob 00: WX4400# display fdb 00:* * = Static Entry.
display fdb cou nt 95 Defaults — None. Access — All. History —Introduced in MSS V ersion 3.0. Examples — The following co mmand displa ys the aging timeout period for all VLANs: WX1200# displa.
96 C HAPTER 5: VLAN C OMMANDS The following command lists the numb er of dynamic entries that the forwarding database contains: WX1200# display fdb count dynamic Total Matching Entries = 2 See Also display fdb on page 92 display roaming station Shows a list of the stations roaming to the wireless LAN switch thr ough a VLAN tunnel.
display roaming station 97 T ab le 21 describes the fields in the display . See Also display roaming vlan on pa ge 98 T able 21 Output for display roaming station Field Description User Name N ame of the user. This is the na me used for authentication.
98 C HAPTER 5: VLAN C OMMANDS display roaming vlan Shows all VLANs in the mobility doma in, the WX switches servicing the VLANs, and their tunnel affinity values configured on each switch for the VLANs. Syntax — display roaming vlan Defaults — None.
display tunnel 99 display tunnel Sh ows the tunnels fr om the wir eless LAN switch where you type the command. Syntax — display tunnel Defaults — None. Access — Enabled History —Introduced in MSS V ersion 3.0. Examples — T o display all tunnels from a WX switch to other WX switches in the Mobility Doma in, type the following command.
100 C HAPTER 5: VLAN C OMMANDS display vlan config Shows VLAN information. Syntax — display vlan config [ vlan-id ] vlan-id — VLAN name or number . If you do not specify a VLAN, information for all VLANs is displayed. Defaults — None. Access — All.
set fdb 101 See Also clear vlan on pa ge 91 set vlan name on page 103 set vlan port on page 104 set vlan tunnel-affinity on page 105 set fdb Adds a permanent or static en t ry to the forwar ding database. Syntax — set fdb { perm | static } mac-addr port port-list vlan vlan-id [ tag tag-value ] perm — Adds a permanent entry .
102 C HAPTER 5: VLAN C OMMANDS mac-addr — Destination MAC address of the entry . Use colons to separate the octets (for example, 00 :1 1:22:aa:bb:cc). port port-list — List of physical destin ation ports for which to add the entry . A separ ate entry is added for each port you specify .
set vlan name 103 Syntax — set fdb agingtime vlan-id age seconds vlan-id — VLAN name or number . The timeout period change applies only to entries that match the spe cified VLAN. age seconds — V alue for the timeo ut period, in seco nds.
104 C HAPTER 5: VLAN C OMMANDS 3Com recommends that you do not use the name default . This name is already used for VLAN 1. 3Com also r ecommends that you do not rename the default VLAN. Y ou cannot use a number as the first character in a VLAN name. 3Com recommends that you do not use the same name with dif ferent capitalizations for VLANs.
set vlan tunnel-affinity 105 Usage — Y ou can comb ine this command with the set port name command to assign the name and add the ports at the same time. If you do not specify a tag value, the WX switch se nds untagged frames for the VLAN. If you do specify a tag value, the WX s ends tagged frames only for the VLAN.
106 C HAPTER 5: VLAN C OMMANDS Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — Increasing a WX switch’ s affinity value increases the WX’ s preferability for forwar ding user traffic for the VLAN. If more than one WX switch has the highest affinity value, MSS randomly selects one of the WX switches for the tunnel.
6 IP S ERVICES C OMMANDS Use IP services commands to conf igur e and manage IP interfaces, management services, the Domain Name Service (DNS), Network Time Protocol (NTP), and aliases, and to ping a host or trace a route. Commands by Usage This chapter presents IP services commands alphabe tically .
108 C HAPTER 6: I P S ERVICES C OMMANDS HTTPS Management set ip https server on page 140 display ip https on page 121 DNS set ip dns on page 137 set ip dns domain on page 138 set ip dns serve r on pag.
clear interface 109 clear interface Removes an IP interface. Syntax — clear interface vlan-id ip vlan-id — VLAN name or number Defaults — None.
110 C HAPTER 6: I P S ERVICES C OMMANDS clear ip alias Removes an alias, which is a string that repr esents an IP addr ess. Syntax — clear ip alias name name — Alias name Defaults — None. Access — Enabled. History — Introduced in MSS V ersion 3.
clear ip dns server 111 set ip dns domain on page 138 set ip dns server on pa ge 139 clear ip dns server Removes a DNS server from a WX switch conf iguration. Syntax — clear ip dns server ip-addr ip-addr — IP addr ess of a DNS server .
112 C HAPTER 6: I P S ERVICES C OMMANDS ip-addr/mask-length — IP addr ess and subnet mask length in CIDR format (for example, 10.10.10.10/24). gateway — IP addr ess, DNS hostname, or alias of the next-hop r outer . Defaults — None. Access — Enabled.
clear ntp server 113 set ip telnet on page 146 set ip telnet server on page 147 clear ntp server Removes an NTP server from a WX switch conf iguration. Syntax — clear ntp server { ip-addr | all } ip-addr — IP addr ess of the server to r emove, in dotted decimal notation.
114 C HAPTER 6: I P S ERVICES C OMMANDS Examples — T o reset the NTP interval to the default value, type the following command: WX4400# clear ntp update-interval success: change accepted.
clear summertime 115 clear summertime Cl ears the summe rtime setting fr om a wir eless LAN switch. Syntax — clear summertime Defaults — None. Access — Enabled.
116 C HAPTER 6: I P S ERVICES C OMMANDS Usage — Clearing the system IP addr e ss can interfer e with system tasks that use the system IP address, including the following: Mobility Domain operati.
display arp 117 display summertime on page 130 display timedate on page 130 display timezone on page 131 display arp Shows the ARP table. Syntax — display arp [ ip-addr ] ip-addr — IP address. Defaults — If you do not specify an IP address, the whole ARP table is displayed.
118 C HAPTER 6: I P S ERVICES C OMMANDS See Also set arp on page 133 set arp agingtime on page 134 display interface Shows the IP interfaces configur ed on the wir eless LAN switch. Syntax — display interface [ vlan-id ] vlan-id — VLAN name or number .
display ip alias 119 WX4400# display interface VLAN Name Address Mask Enabled State ---- --------------- --------------- --------------- ------- ----- 1 default 10.10.10.10 255.255.255.0 YES Up 2 mauve 10.10.20.10 255.255.255.0 NO Down 4094 web-aaa 10.
120 C HAPTER 6: I P S ERVICES C OMMANDS Examples — The following co mmand displa ys all the aliases configur ed on a WX switch: WX4400# display ip alias Name IP Address -------------------- ------------ -------- HR1 192.168.1.2 payroll 192.168.1.3 radius1 192.
display ip https 121 T ab le 29 describes the fields in this display . See Also clear ip dns domain on page 110 clear ip dns server on page 111 set ip dns on page 137 set ip dns domain on page 138 set ip dns server on pa ge 139 display ip https Shows information about the HTTPS management port.
122 C HAPTER 6: I P S ERVICES C OMMANDS Examples — The following comman d shows the status and port number for the HTTP S management interface to the WX switch: WX4400# display ip https HTTPS is enabled HTTPS is set to use port 443 Last 10 Connections: IP Address Last Connected Time Ago (s) ------------ ----------------------- ------------ 10.
display ip ro ute 123 display ip r oute Shows the IP route table. Syntax — display ip route [ destination ] destination — Route destination IP addr ess, in dotted decimal notation. Defaults — None. Access — All. History —Introduced in MSS V ersion 3.
124 C HAPTER 6: I P S ERVICES C OMMANDS See Also clear ip route on page 111 display interface on page 118 display vlan config on page 100 set interface on page 135 set ip rou te on page 140 T able 31 Output of display ip route Field Description Destination/Mask IP address and subnet mask of the route destination.
display ip teln et 125 display ip telnet Shows information about the T elnet management port. Syntax — display ip telnet Defaults — None. Access — All.
126 C HAPTER 6: I P S ERVICES C OMMANDS display ntp Shows NTP client inf ormation. Syntax — display ntp Defaults — None. Access — All. History —Introduced in MSS V ersion 3.
display ntp 127 See Also clear ntp server on page 113 clear summertime on page 115 clear timezone on pa ge 116 display timezone on page 131 set ntp on page 148 set ntp serve r on page 148 set summertime on page 154 set timezone on pag e 157 Summertime Summertim e period configured on the W X switch.
128 C HAPTER 6: I P S ERVICES C OMMANDS display snmp configuration Shows SNMP settings on a wir eless LAN switch. Syntax — display snmp configuration Defaults — None.
display snmp configuration 129 CounterMeasureStopTraps YES ClientDot1xFailureTraps YES Community Access Community N ame ---------------- ----------- --- read-only public read-write private T ab le 34 describes the fields in this display .
130 C HAPTER 6: I P S ERVICES C OMMANDS display summertime Shows a wireless LAN switch’ s offs et fr om its r eal-time c lock. Syntax — display summertime Defaults — There is no summertime offset by default. Access — All. History —Introduced in MSS V ersion 3.
display timezone 131 Examples — T o display the time and date set on a WX switch’ s real-time clock, type the following command: WX1200# display timedate Sun Feb 29 2004, 23:59:02 PST See Also .
132 C HAPTER 6: I P S ERVICES C OMMANDS set timedate on page 156 set timezone on page 157 ping T est s IP connectivity between a wire less LAN switch and another device. MSS sends an Inter net Control Message Pr otocol (ICMP) echo packet to the specified WX switch and lis tens for a reply packet.
set arp 133 size — 56. Access — Enabled. History — Introduced in MSS V ersion 3.0. Usage — T o stop a ping command that is in progr ess, press Ctrl+C. Examples — The following co mmand pings a WX switch that has IP address 10.1.1.1: WX1200# ping 10.
134 C HAPTER 6: I P S ERVICES C OMMANDS Access — Enabled. History — Introduced in MSS V ersion 3.0. Examples — The following command adds a static ARP entry that maps IP address 10.10.10.1 to MAC address 00:bb:cc:dd:ee:f f: WX1200# set arp static 10.
set interface 135 See Also set arp on page 133 telnet on page 158 set interface Configures an IP interface on a VLAN. Syntax — set interface vlan-id ip { ip-addr mask | ip-addr/mask-length } vlan-id — VLAN name or number . ip-addr mask — IP addr ess and subnet mask in dotted decimal notation (for example, 10.
136 C HAPTER 6: I P S ERVICES C OMMANDS The following command configures IP interface 10.10.20.10 255.255.255.0 o n VLAN mauve: WX1200# set interface mauve ip 10.
set ip alias 137 set ip alias Configures an alias, which maps a na me to an IP add ress. Y ou can use aliases as shortcuts in CLI commands. Syntax — set ip alias name ip-addr name — String of up to 32 alphanumeric characters, with no spaces. ip-addr — IP addr ess in dotted decimal notation.
138 C HAPTER 6: I P S ERVICES C OMMANDS See Also clear ip dns domain on page 110 clear ip dns server on page 111 display ip dns on page 120 set ip dns domain on page 138 set ip dns server on page 139 set ip dns domain Configures a default domain name for DNS queries.
set ip dns server 139 set ip dns server on pa ge 139 set ip dns server Specifies a DNS server to use for re solving hostnames you enter in CLI commands. Syntax — set ip dns server ip-addr { primary | se condary } ip-addr — IP addr ess of a DNS server , in dotted decimal or CIDR notation.
140 C HAPTER 6: I P S ERVICES C OMMANDS set ip https server En ables the HTTPS server on a wireless LAN switch. The HTTPS server is requir ed for We b Manager access to the switch. CAUTION: If you disable the HTTPS ser ver , Web Manager access to the WX switch is also disabled.
set ip route 141 ip-addr mask — IP address and subnet mask for the r oute destination, in dotted decimal not ation (for example, 10 .10.10.10 255.255.255.0 ). ip-addr/mask-length — IP address and subnet mask length in CIDR format (for example, 10.
142 C HAPTER 6: I P S ERVICES C OMMANDS Examples — The following co mmand adds a default r oute that uses gateway 10.5.4.1 and gives the route a cost of 1: WX4400# set ip route default 10.5.4. 1 1 success: change accepted. The following commands add two default routes, and configure MSS to always use the route through 10.
set ip ssh 143 History — Introduced in MSS V ersion 3.0. Examples — The follo wing command enables the SNMP server on a WX switch: WX4400# set ip snmp server enable success: change accepted.
144 C HAPTER 6: I P S ERVICES C OMMANDS set ip ssh idle-timeout on page 145 set ip ssh server on page 145 set ip ssh absolute-timeout Changes the number of minutes an SSH session can remain open. The absolute-timeout value applies regardle ss of whether the session is active or idle.
set ip ssh id le-timeou t 145 set ip ssh idle-timeout Changes the number of minutes an SSH session can remain idle. Syntax — set ip ssh idle-timeout minutes minutes — Number of minutes an SSH session can r emain idle. Y ou can set the idle timeout to a value from 0 (disabled) to 2,147,483,64 7 minutes.
146 C HAPTER 6: I P S ERVICES C OMMANDS Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — Y ou must gen erate an SSH authentication key to use SSH.
set ip telnet server 147 display ip https on page 121 display ip telnet on page 125 set ip https server on page 140 set ip telnet server on page 147 set ip telnet server En ables the T e lnet server on a wireless LAN switch. CAUTION: If you disable the T elnet ser ver , T elnet access to the WX switch is also disabled.
148 C HAPTER 6: I P S ERVICES C OMMANDS set ntp Enables or disables the NTP client on a wireless LAN switch. Syntax — set ntp { enable | disable } enable — Enables the NTP cli ent. disable — Disables the NTP client. Defaults — The NTP client is disabled by default.
set ntp update-interval 149 History —Introduced in MSS V ersion 3.0. Usage — Y ou can configure up to thr ee N TP servers. MSS queries all the servers and selects the best response based on the method described in RFC 1305, Network T ime Protocol (V ersion 3) Specification, Implementation and Analysis.
150 C HAPTER 6: I P S ERVICES C OMMANDS See Also clear ntp server on page 113 clear ntp update-interval on pag e 113 display ntp on page 126 set ntp on page 148 set ntp serve r on .
set snmp trap 151 set ip snmp server on page 142 set snmp trap on page 15 1 set snmp trap receiver on page 153 set snmp trap Enables or disables the SNMP tr ap capability .
152 C HAPTER 6: I P S ERVICES C OMMANDS Defaults — All traps are disabled by default. Access — Enabled. ClientRoamingTraps Generated when a client roams. CounterMeasureStartTraps Generated when MSS be gins countermeasures agai nst a rogue access point.
set snmp trap receiver 153 History —Introduced in MSS V ersion 3.0. Usage — Y ou can enab le or disable the linkup and linkdown traps on an individual port basis with the set port trap command. The individual port setting overrides the global setting.
154 C HAPTER 6: I P S ERVICES C OMMANDS display snmp configuration on page 128 set ip snmp server on page 142 set snmp community on page 150 set snmp trap on page 151 set summertime Of.
set system ip-address 155 Usage — Y ou must first set the time zone with the set timezone command for the offset to work p r operly without the start and end values. Configure summertime before you se t the time and date. Otherwise, summertime’ s adjustment of the time w ill make the time incorr ect, if the date is within the summertime period.
156 C HAPTER 6: I P S ERVICES C OMMANDS History —Introduced in MSS V ersion 3.0. Usage — Y ou must use an add r ess that is configured on one of the WX switch’ s VLANs.
set timezone 157 Configure summertime before you se t the time and date. Otherwise, summertime’ s adjustment of the time w ill make the time incorr ect, if the date is within the summertime period.
158 C HAPTER 6: I P S ERVICES C OMMANDS History —Introduced in MSS V ersion 3.0. Examples — T o set the time zone for Paci fic Standard Time (PST ), type the following command: WX1200# set timezone PST -8 Timezone is set to 'PST', offset fro m UTC is -8:0 hours.
telnet 159 If the configuration of the WX switch from which you enter the telnet command has an ACL that denies T e lnet client traf fic, the ACL also denies access by the telnet command.
160 C HAPTER 6: I P S ERVICES C OMMANDS traceroute T r aces the r oute to an IP host. Syntax — traceroute host [ dnf ] [ no-dns ] [ port port-num ] [ queries num ] [ size size ] [ ttl hops ] [ wait ms ] host — IP address, hostname, or alias of the destination h ost.
traceroute 161 Examples — The followin g example traces the route to host server1: WX4400# traceroute server1 traceroute to server1.example.com (1 92.168.22.7), 30 hops max, 38 by te packets 1 engineering-1.example.com (192.168 .192.206) 2 ms 1 ms 1 ms 2 engineering-2.
162 C HAPTER 6: I P S ERVICES C OMMANDS See Also ping on page 132 !F Fragmentation needed but Do Not Fragment (DNF) bit was set. !S Source route failed.
7 AAA C OMMANDS Use authentication, authorization, and accounting (AAA) commands to provide a secur e network connection and a r ecord of user activity . Location policy commands override an y virtual LAN (VLAN) or security ACL assignment by AAA or the local WX database to help you control access locally .
164 C HAPTER 7: AAA C OMMANDS Local Authorization for Password Users set user on page 218 clear user on page 176 set user attr on page 219 clear user attr on page 177 set usergroup on page 220 clear u.
clear accounting 165 clear accounting Removes accountin g services for specified wir eless users with administrat ive acce ss or network access. Syntax — clear accounting { admin | dot1x } { user- glob } admin — Users with administrative access to the WX switch through a console connection or through a T elnet or Web Manager connection.
166 C HAPTER 7: AAA C OMMANDS clear authentication admin Removes an authentication rule for administrative access through T elnet or Web Manager . Syntax — clear authentication admin user-glob user-glob — A single user or set of users.
clear authentication console 167 clear authentication console Removes an authentication rule fo r administ rative access thr ough the Console. Syntax — clear authentication console user-glob user-glob — A single user or set of users.
168 C HAPTER 7: AAA C OMMANDS clear authentication dot1x Removes an 802.1X authenti cation rule. Syntax — clear authentication dot1x { ssid ssid-name | wired } user-glob ssid ssid-name — SSID name to which th is authentication rule applies. wired — Clears a rule used for access over an WX switch’ s wired-authentication port.
clear authentication last-resort 169 clear authentication last-resort Removes a last-resort authentication rule. Syntax — clear authentication last-resor t { ssid ssid-name | wired } ssid ssid-name —SSID name to which this authentication rule applies.
170 C HAPTER 7: AAA C OMMANDS mac-addr-glob — A single user or set of users with access via a MAC address. Specify a MAC address, or use the wildcard ( * ) character to specify a set of MAC addr esses. (For details, see “MAC Address Globs” on page 25.
clear location policy 171 Specify a username, use the doub le-asterisk wildcar d character ( ** ) to specify all user names, or use the single-asterisk wildcard character ( * ) to specify a set of usernames up to or following the first delimiter character—either an at sign (@) or a period (.
172 C HAPTER 7: AAA C OMMANDS Usage — T o determine the in dex numbers of locatio n policy rule s, use the display location policy command. Removing all the ACEs from the location po licy disables this functio n on the WX switch.
clear mac-user attr 173 set mac-user attr on page 208 clear mac-user attr Removes an authorization attribute fr om the user pr ofile in the local database on the WX switch, for a us er who is authenticated by a MAC address. (T o remove an authorization attribute in RADIUS, see the documentation for your RADIUS server .
174 C HAPTER 7: AAA C OMMANDS Syntax — clear mac-user mac-addr group mac-addr — MAC addr ess of the user , in hexadecimal numb ers separated by colons ( : ). Y ou can omit leading zeros. Defaults — None. Access — Enabled. History —Introduced in MSS V ersion 3.
clear mac-usergroup attr 175 Usage — T o remove a user fr om a MAC user gr oup, use the clear mac-user group command. Examples — The following co mmand de letes the MAC user gr oup eastcoasters from the local database: WX4400# clear mac-usergroup eastcoas ters success: change accepted.
176 C HAPTER 7: AAA C OMMANDS See Also clear mac-usergroup on page 174 display aaa on page 180 set mac-usergroup attr on page 214 clear mobility-profile Removes a Mobility Profile entirely . Syntax — clear mobility-profile name name — Name of an existing Mobility Profile.
clear user attr 177 History —Introduced in MSS V ersion 3.0. Usage — Deleting the user’ s pr ofile fr om the database deletes the assignment of any attributes in the profile to the user . Examples — The following co mmand delete s the user pr ofile for user Nin: WX4400# clear user Nin success: change accepted.
178 C HAPTER 7: AAA C OMMANDS set user attr on page 219 clear user gr oup Removes a user with a p asswor d from membership in a user group in the local database on the WX switch. (T o remove a user from a user gr oup in RADIUS, see the documentation for your RADIUS server .
clear usergroup attr 179 Syntax — clear usergroup group-name group-name — Name of an existing user gr oup. Defaults — None. Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — Removing a user group fr om the local WX database does not remove the user pr ofiles of the gr oup’ s members from the database.
180 C HAPTER 7: AAA C OMMANDS Examples — The following command r emoves the members of the use r group cardiology from a network access time r estriction by deleting the T ime-Of-Day attribute from the group: WX4400# clear usergroup cardiology a ttr time-of-day success: change accepted.
display aaa 181 set authentication dot1x ssid mycorp * peap-mschapv2 sg1 sg2 sg3 set authentication dot1x ssid any ** peap-mschapv2 sg1 sg2 sg3 set accounting dot1x Nin ssid mycorp stop-only sg2 set a.
182 C HAPTER 7: AAA C OMMANDS See Also set accounting {admin | console} on page 186 set authentication admin on page 189 set authentication console on page 191 set authentication dot1x.
display accounting s tatistics 183 display accounting statistics Displays the AAA accounting recor ds for wirele ss users. The recor ds ar e stored in the local database on the WX switch. (T o display RADIUS accoun ting r ecord s, see the documentation for your RADIUS server .
184 C HAPTER 7: AAA C OMMANDS See Also clear accounting on page 165 display aaa on page 180 set accounting {admin | console} on page 186 Acct-Authentic Location where the user was authenti.
display location poli cy 18 5 display location policy Displays the list of location policy ru les that make up the location policy on an WX switch. Syntax — display location policy Defaults — None. Access — Enabled. History —Introduced in MSS V ersion 3.
186 C HAPTER 7: AAA C OMMANDS Mobility Profiles Name Ports ========================= magnolia AP 2 See Also clear mobility-profile on page 176 set mobility-profile on page 215 set accounting {.
set accounting {dot1x | mac | web} 18 7 A method can be one o f the following: local — Stores accounting r ecords in the local database on the WX switch. When the local account ing storage space is full, MS S overwrites older recor ds with new ones.
188 C HAPTER 7: AAA C OMMANDS web — Users with network access through the WX switch who ar e authenticated by WebAAA ssid ssid-name — SSID name to which this accounting rule applies.
set authentication admin 189 Defaults — Accounting is disabled for all users by default. Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — For network users with start-sto p accounting whose recor ds are sent to a RADIUS server , MSS sen ds interim updates to the RADIUS server when the user r oams.
190 C HAPTER 7: AAA C OMMANDS server-group-name — Uses the defined group of RADIUS servers for authentication. Y ou can enter up to four names of existing RADIUS server groups as methods.
set authentication console 191 If a AAA rule specifies local as a se condary AAA method, to be used if the RADIUS serv ers are unavailable, and MSS authenticates a client w ith the local method, MSS starts again at the beginning of the met hod list when attempting to authorize the client.
192 C HAPTER 7: AAA C OMMANDS A method can be one o f the following: local — Uses the local database of usernames and user groups on the WX switch for authentication. server-group-name — Uses the defined gr oup of RADIUS servers for authentication.
set authenticatio n dot1x 193 However , if local appears first, followed by a RADIUS server group, MSS ignores any fail ed searches in th e local WX database and sends an authentication request to the RADIUS server group.
194 C HAPTER 7: AAA C OMMANDS bonded — Enables Bonded Auth™ (bonded authentication). When this feature is enabled, MSS authenti cates the user only if the machine the user is on has already been authenticated. protocol — Pr otocol used for authentication.
set authenticatio n dot1x 195 A method can be one o f the following: local — Uses the local database of usernames and user gr oups on the WX switch for authentication. server-group-name — Uses the defined gro up of RA DIUS servers for authentication.
196 C HAPTER 7: AAA C OMMANDS However , if local appears first, followed by a RADIUS server group, MSS overrides any failed searches in the local WX d atabase and sends an authentication request to the server group. If the user does not support 802.1X, MSS attempt s to perform MAC authentication for the user .
set authentication last-resort 197 set authentication last-resort Configures an authentication rule to grant network access to a user who is not otherwise granted or denied access by 802.
198 C HAPTER 7: AAA C OMMANDS Y ou can configur e a rule either for wireless access to an SSID, or for wired access through a WX switch’ s wired auth entication port. If the rule is for wireless access to an SSID, spec ify the SSID name or specify any to mat ch on all SSID names.
set authentication mac 199 See Also clear authentication last-resort on page 1 69 display aaa on page 180 set authentication admin on page 189 set authentication console on page 191 .
200 C HAPTER 7: AAA C OMMANDS Defaults — By default, authentication is deactivate d for all MAC users, which means MAC address authenticati on fails by default. When using RADIUS for authentication, a MAC user’ s MAC address is also used as the authorization password for that user , and no global authorization password is set.
set authentication web 201 See Also clear authentication mac on page 169 display aaa on page 180 set authentication admin on page 189 set authentication console on page 191 set aut.
202 C HAPTER 7: AAA C OMMANDS server-group-name — Uses the defined group of RADIUS servers for authentication. Y ou can enter up to four names of existing RADIUS server groups as methods. RADIUS servers cannot be used with the EAP-TLS pr otocol.
set location policy 203 The fallthru method is web . (For a wireless authentication rule, the fallthru method is specified by the set service-profile auth-fallthru command. For a wired authenticati on rule, the fallthru method is specified by the auth-fall-thru option of the set port type wired-auth command.
204 C HAPTER 7: AAA C OMMANDS permit — Allows access to the network or to a specified VLAN, and/or assigns a particular se curity ACL to users with characteristics that match the location policy rule.
set location policy 205 eq — Applies the location policy ru le to all usernames matching user -glob. neq — Applies the location polic y rule to all usernames not matching user -glob.
206 C HAPTER 7: AAA C OMMANDS The order of rules in the location policy is important to ensure users are properly granted or denied access. T o position rules within the location policy , use before rule-number and modify rule-number in the set location policy command, and the clear location policy rule-number command.
set mac-user 207 The following command authorizes users entering the network on WX ports 1 and 2 to use the floor2 VLAN, overriding any settings from AAA: WX4400# set location policy permit v lan floo.
208 C HAPTER 7: AAA C OMMANDS Examples — The following command creates a user profile for a user at MAC address 01:02:03:04:05:06 and assigns the user to the eastcoasters user group: WX4400# set mac-user 01:02:03:04:05: 06 group eastcoasters success: change accepted.
set mac-user attr 209 T able 40 Authentication Attributes for Local Users Attribute Description Valid Value(s) encryption-type Type of encryption required for access by the client. Clients who attempt to use an unauthorized encrypti on method are rejected.
210 C HAPTER 7: AAA C OMMANDS filter-id Inbound or outb ound ACL to apply to the user. If configured in the WX switch’s local database, this attribute can be an access control list (ACL) to filter outbound or inbound traffic. Use the following format: filter -id inboundacl .
set mac-user attr 211 service-type Type of access the user is requesting. One of the following numbers: 2 —Framed; for network user access 6 —Administrative; for administrative access to the WX switch, with authorization to access the enabled (configuration) mode.
212 C HAPTER 7: AAA C OMMANDS time-of-day (network access mode only) Day(s) and time(s) during which the user is permitted to log into the network. After authorization, the user’s session can last until either the Time-Of-Day range or the Session-Timeout duration (if set) expires, whichever is shorter.
set mac-user attr 213 Defaults — None. Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — T o change the value of an attribute, enter set mac-user attr with the new valu e. T o delete an attribute, use clear mac-user attr . Y ou cann ot set the Filter -ID attribute in the local database.
214 C HAPTER 7: AAA C OMMANDS The following command restri cts a user at MAC address 06:05:04:03:02:01 to n etwork access betwee n 7 p.m. on Mond ays and We dnesdays an d 7 a.m. on T uesdays and Thu rsdays: WX4400# set mac-user 06:05:04:03:02: 01 attr time-of-day mo1900-1159,tu0000-0700,we1900-1159, th0000-0700 success: change accepted.
set mobility-profile 215 Examples — The following co mmand cr eates the MAC user group eastcoasters and assigns the gr oup members to VLAN orange : WX4400# set mac-usergroup eastcoaste rs attr vlan-name orange success: change accepted.
216 C HAPTER 7: AAA C OMMANDS Usage — T o assign a Mobility Profile to a user or gr oup, specify it as an authorization attribute in one of the following commands: set user attr mobility-profile nam.
set mobility-profile mode 217 set user attr on page 219 set usergroup on page 220 set mobility-profile mode Enables or disables the Mobility Profil e feature on the WX switch.
218 C HAPTER 7: AAA C OMMANDS set user Configures a user profile in the local database on the WX switch for a user with a password. (T o configure a user profile in RADIUS, see the documentation for your RADIUS server .) Syntax — set user username password string username — Username of a user with a password.
set user attr 219 set user attr Configures an authorization attribut e in the local database on the WX switch for a user with a passwor d. (T o assign authorization attributes in RADIUS, see the documentation for your RADIUS server .) Syntax — set user username attr attribute-name v alue username — Username of a user with a password.
220 C HAPTER 7: AAA C OMMANDS set user group Adds a user to a user group. The user must have a passwor d and a profile that exists in the local database on the WX switch.
set web-aaa 221 attribute-name value — Name and value of an attribute you are using to authorize all users in the group for a particular service or session charac teristic. For a list of authorization att ributes and values that you can assign to users, see T ab le 40 on page 209.
222 C HAPTER 7: AAA C OMMANDS Usage — This command disables or reenables support for W ebAAA. However , WebAAA has additional configuration requirements. For information, see the “Configuring AAA for Network Users” chapter in the Wireless LAN Switch and Controller Configuration Guid e .
8 M OBILITY D OMAIN C OMMANDS Use Mobility Domain commands to configure and manage Mobility Domain groups. A Mobility Domain is a system of WX switches and MAP access points working together to support a roaming user (client). One WX swit ch acts as a seed switch, which maintains and distributes a list of IP addresses of the domain members.
224 C HAPTER 8: M OBIL ITY D OMAIN C OMMANDS clear mobility-domain Clears all Mobility Domain configur ation and information fr om a WX switch, regar dless of whether t he WX switch is a seed or a member of a Mobility Domain. Syntax — clear mobility-domain Defaults — None.
display mobility -domain config 225 Usage — This command has no effect if the WX switch member is not configured as part of a Mobility Domain or the current WX switch is not the seed. Examples — The following command clea rs a Mobility Domain member with the IP address 192.
226 C HAPTER 8: M OBIL ITY D OMAIN C OMMANDS History —Introduced in MSS V ersion 3.0. Examples — T o display Mobility Domain status, type the following command: WX4400# display mobility-domain stat us Mobility Domain name: Pleasanton Member State Status --------------- ------------- -------------- 192.
set mobility-domain member 227 set mobility-domain member On the seed WX switch, adds a memb er to the list of Mobi lity Domain members. If the current WX switch is not configur ed as a seed, this command is re jected. Syntax — set mobility-domain member ip-addr ip-addr — IP addr ess of the Mobility Domain member in dotted decimal notation.
228 C HAPTER 8: M OBIL ITY D OMAIN C OMMANDS Defaults — None. Access — Enabled. History —Introduced in MSS V ersion 3.0. Examples — The followin g command sets the current WX switch as a nonseed member of the Mobility Doma in whose seed has the IP addr ess 192.
set mobility-domain mode seed domain-name 229 Examples — The following command crea tes a Mobility Domain named Pleasanton with the curr en t WX switch as the seed: WX4400# set mobility-domain mode .
230 C HAPTER 8: M OBIL ITY D OMAIN C OMMANDS.
9 M ANAGED A CCESS P OINT C OMMANDS Use MAP access point commands to configu r e and manage MAP access points. Be sure to do the follo wing before using the commands: Define the country-speci fic IEEE 802.1 1 r egulations on the WX switch. (See set system countrycode on page 51.
232 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS set service-pr ofile ss id-type on page 312 set service-pr ofile beacon on page 303 Radio Properties set radio-profile 11g-o nly on page 280 set radio.
MAP Access Point Commands by Usage 23 3 RF Auto-T uning set radio-profile auto -tune channel-config on page 28 1 set radio-profile auto-t une channel-holddo wn on page 282 set radio-profile auto -tune.
234 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS clear {ap | dap} radio Disables a MAP radio and resets it to it s factory default settings. Syntax — clear { ap port-list | dap dap-num } radio { 1 | 2 | all } ap port-list — List of ports connect ed to the MAP access point(s) on which to reset a radio.
clear radio-profile 235 Usage — When you clear a radio, MSS performs the following actions: Clears the transmit power , channel, and exter nal ante nna setting fr om the radio. Removes the radio from its radio pr ofile and places the radio in the default radio pr ofile.
236 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS Defaults — If you reset an individual parameter , the parameter is returned to the default value listed in T able 57 on pag e 292. Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — If you specify a parameter , the setting for the parameter is reset to its default value.
display {ap | dap} config 237 Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — If the service profile is mapped to a radio pr ofile, you must remove it fr om the radio pr ofile first. (After disabl ing all radios that use the radio profile, use the clear radio-profile name service-pr ofile name command.
238 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS Usage — MSS lists information separa tely for each MAP access point. Examples — The following example shows configuration inf ormation for an MAP .
display {ap | dap} config 239 bias Bias of the WX conn ection to the MAP: High Low name MAP access point name. boot-download- enable State of the firmware upgrade option: YES (automatic up.
240 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS See Also display dap connection on page 253 display dap global on page 254 display dap unconfigur ed on page 2 56 display radio-profil.
display {ap | dap} counters 241 display {ap | dap} counters Displays MAP access point an d radio statistics counters. Syntax — display ap counters [ port-list [ r adio { 1 | 2 }]] Syntax — display.
242 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS 11.0: 8016 0 2590353 0 85479 3897587 0 0 1195 TOTL: 543705 52742 40087331 4445625 684050 17552381 0 0 46441 T ab le 46 describes the fields in this display . T able 46 Output for display ap counters Field Description Port WX port number.
display {ap | dap} etherstats 24 3 See Also display sessions network on page 446 display {ap | dap} etherstats Displays Ethernet statistics for a MAP’ s Ethernet ports. Syntax — display { ap | dap } etherstats [ port-list | dap-num ] port-list — List of WX switch ports directly connected to t he MAPs for which to d isplay counters.
244 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS RxAlignErrs: 0 TxMultiC oll: 47 RxShortFrames: 0 TxUnderr uns: 0 RxCrcErrors: 0 TxCarrie rLoss: 0 RxOverruns: 0 TxDeferr ed: 150 RxDiscards: 0 T ab le 47 describes the fields in this display . T able 47 Output of display ap etherstats Field Descri ption RxUnicast Number of unicast frames rece ived.
display {ap | dap} group 245 display {ap | dap} group Displays configuration in formation and load-balancing status for MAP access point groups. Syntax — display { ap | dap } group [ name ] name — Name of an MAP gr oup or Distributed MAP group.
246 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS See Also “set {ap | dap} group” on page 267 display {ap | dap} status Displays MAP access point and radio status information.
display {ap | dap} status 247 Examples — The follow ing command displays the status of a Distributed MAP: WX4400# display dap status 1 Dap: 1, IP-addr: 10.
248 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS T ab le 49 describes the fields in this display . T able 49 Output for display ap status Field Description DAP Connection ID for the Distributed MAP. Note: This field is applicab le only if the MAP is configured on the WX switch as a Distributed MAP.
display auto-tune attributes 249 display auto-tune attributes Displays the current values of the RF attributes RF Auto-T uning uses to decide whether to change channel or po wer settings.
250 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS radio 1 — Shows RF attribute information for radio 1. radio 2 — Shows RF attribute informatio n for radio 2. (This option does not apply to single-radio models.) radio all — Shows RF attribute information for both radios.
display auto-tune neighbors 251 display radio-profile on page 257 set {ap | dap} radio auto-tune max-power on page 270 set {ap | dap} radio auto-tune max- r etransmissions on page 271 .
252 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS Usage — For simplicity , this command disp lays a single entry for each 3Com radio, even if the radio is supporting multiple BSS IDs. However , BSSIDs for third-party 802.11 radios are listed separately , even if a radio is supporting more than one BSSID.
display dap connection 253 set radio-profile auto-tune channel-interval on page 283 set radio-profile auto-tune power -backof f- timer on page 284 set radio-profile auto-tune power -config.
254 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS 4 M9DE48B123400 10.10.3.34 10.3.8.111 The following command displays connec tion information specifically for a Distributed MAP with serial ID M9DE48B.
display dap glob al 255 History —Introduced in MSS V ersion 3.0. Usage — T o show info rmation only for Distributed MAPs that have active connections, use the display dap connection command.
256 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS See Also display {ap | dap} config on page 2 37 display dap connection on page 253 display dap unconfigur ed on page 2 56 set dap on p.
display radio-profile 25 7 T ab le 54 describes the fields in this display . See Also display dap connection on page 253 display dap global on page 254 display radio-profile Displays radio pr ofile information. Syntax — display radio-profile { name | ? } name — Displays information ab out the named rad io pr ofile.
258 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS WX4400# display radio-profile defaul t Beacon Interval: 100 DT IM Interval: 1 Max Tx Lifetime: 2000 Ma x Rx Lifetime: 2 000 RTS Threshold: 2346 Fr ag Threshold: 2 346 Short Retry Limit: 5 Lo ng Retry Limit: 5 Long Preamble: NO Al low 802.
display radio-profile 25 9 Long Preamble Indicates whether an 802.11b radio that uses th is radio profile advertises support for frames with long preambles only: YES — Advertises support for long pre ambles only. NO — Advertises support for long and short preambles.
260 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS See Also set radio-profile 11g-only on page 280 set radio-profile auto -tune channel-config on page 281 set radio-profile auto -tune chann.
display service-profile 261 display service-profile Displays service profi le information. Syntax — display service-profile { name | ? } name — Displays information about the named service profile. ? — Displays a list of service profil es.
262 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS auth-fallthru Secondary (fallthru) encryption type when a user tries to authenticate but the WX swit ch managing the radio does not have an authentication rule with a userglob that matches the username.
display service-profile 263 See Also set service-profile auth-dot1x on page 300 set service-profile auth-fallthru on page 301 set service-profile auth-psk on page 302 set service-profi.
264 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS set service-profile wep active-multicast- index on page 315 set service-profile we p active-unicast- index on page 316 set service-profile wep key-index on page 317 set service-profile wpa-ie on page 318 reset {ap | dap} Restarts an MAP access point.
set {ap | dap} bias 265 dap dap-num — Number of a Distributed MAP for which to change the bias. high — High bias. low — Low bias. Defaults — The default bias is high. Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — High bias is preferr ed over low bias.
266 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS set {ap | dap} blink Enables or disables LED blink mode on a MAP access point to make it easy to identify . When blink mode is enabled on an AP2750, the 11a LED blinks on and off. When blink mode is enabled on an AP7250, the Radio LED flashes r ed and the Power LED flashes green/or ange.
set {ap | dap} group 267 Examples — The following co mmand enables LED blink mode on the MAP access points connected to por ts 3 and 4: WX1200# set ap 3-4 blink enable success: change accepted. set {ap | dap} group Configures a named group of MAP access poin ts.
268 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS The following command r emoves the MAP access point on port 4 from all MAP access point groups: WX1200# set ap 4 group none success: change accepted. See Also “display {ap | dap} config” on page 237 display {ap | dap} gr oup on page 245 set {ap | dap} name Changes an MAP name.
set {ap | dap} radio antennatype 269 set {ap | dap} radio antennatype Sets the external antenna model for a MAP that supports exter nal antennas. Syntax — set { ap port-list | dap dap-num } radio { .
270 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS Usage — This command applies only to MAP models MP-372, MP-341, MP-352, and MP-262. Exter nal 802. 11a antennas are supported only on model MP-372. Examples — The following command conf igur es the 802.
set {ap | dap} radio auto-tune max- retransmissions 271 Examples — The following command se ts the maximum power tha t RF Auto-T uning can set on radio 1 on the MAP access point on port 6 to 12 dBm. WX1200# set ap 6 radio 1 auto-tune m ax-power 12 success: change accepted.
272 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS Usage — A retransmission is a packet sent from a client to a MAP radio that the radio receives mor e than once. This can occur when the client does not receive an 802.11 acknowle dgement for a packet sent to the radio.
set {ap | dap} radio channel 273 Examples — The following co mmand changes the max-r etransmissions value to 20: WX1200# set ap 6 radio 1 auto-tune m ax-retransmissions 20 success: change accepted.
274 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS This command is not valid if dynami c channel tuning (RF Auto-T uning) is enabled. Examples — The following co mmand configur es the channel on the 802.11a radio on the MAP access point connected to port 5: WX1200# set ap 5 radio 1 channel 36 success: change accepted.
set {ap | dap} radio min-client-rate 275 Defaults — The default minimum data tr ansmit rate depends on the radio type: The default minimum data rate fo r 802.11b/g and 802.11b radios is 5.5 Mbps. The default minimum data rate for 802.11a radios is 24 Mbps.
276 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS set {ap | dap} radio mode Enables or disables a radio on an MAP access point. Syntax — set { ap port-list | dap dap-num } radio { 1 | 2 } mode { enable | disable } ap port-list — List of ports connect ed to the MAP access point(s) on which to turn a radio on or of f.
set {ap | dap} radio radio-profile 277 set radio-profile mode on page 291 set {ap | dap} radio radio-profile Assigns a radio profile to an MAP radi o and enables or disables the radio. Syntax — set { ap port-list | dap dap-num } radio { 1 | 2 } radio-profile name mode { enable | di sable } ap port-list — List of ports.
278 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS set radio-profile mode on page 291 set {ap | dap} radio tx-power Sets an MAP radio’ s transmit power . Syntax — set { ap port-list | dap dap-num } radio { 1 | 2 } tx-power power-level ap port-list — List of ports connected to the MAP access points on which to set th e transmit power .
set {ap | dap} upgrade-firmware 279 Examples — The following command configures the transmit power on the 802.11a radio on the MAP access point connected to port 5: WX1200# set ap 5 radio 1 tx-power 10 success: change accepted. The following command configures the channel and tran smit power on the 802.
280 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS Examples — The following co mmand di sables automatic firmware upgrades on the MAP access point connected to port 6 : WX1200# set ap 6 upgrade-firmware di sable See Also display {ap | dap} config on page 2 37 set radio-profile 11g-only Configures each 802.
set radio-profile auto-tune channel-config 281 Examples — The following command configures the 802.11b/g radios in radio profile rp1 to allow associations from 802.11g clients only: WX4400# set radio-profile rp1 11g-on ly enable success: change accepted.
282 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS success: change accepted. See Also set radio-profile auto -tune channel-holddown on page 282 set radio-profile auto-tune ch annel-interval on .
set radio-profile auto-tune channel-interval 283 set radio-profile auto-tune channel-interval Sets the interval at which RF Auto-T un ing decides whether to change the channels on radios in a radio profil e.
284 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS set radio-profile auto-tune power -backoff- timer Sets the interval at which rad ios in a radio profile r educe power after temporarily increasing the power to ma intain the minimum data rate for an associated client.
set radio-profile auto-tune power-config 28 5 set radio-profile auto-tune power -config Enables or disables dynamic p ower tuning (RF Auto-T uning) for the MAP radios in a radio profile. Syntax — set radio-profile name auto-tune power-co nfig { enable | disable } name — Radio profile name.
286 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS set radio-profile auto-tune power -interval Sets the interval at which RF Auto-T uning decides whether to change the power level on radios in a radio profil e.
set radio-profile beacon-interval 287 set radio-profile beacon-interval Changes the rate at which each MAP radio in a radio profile advertises its service set identifier (SS ID). Syntax — set radio-profile name beacon-interva l interval name — Radio profile name.
288 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS Defaults — By default, MAP access point s send the DTIM once after each beac on. Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — Y ou must disable all rad ios that ar e using a radio profile befor e you can change pa rameters in t he pr ofile.
set radio-profile long-retry 289 Usage — Y ou must disable all rad ios that ar e using a radio profile befor e you can change pa rameters in t he pr ofile.
290 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS See Also display radio-profile on page 257 set radio-profile mode on page 291 set radio-profile short-r etry on page 299 set radio-profile max-rx-lifetime Changes the maximu m r eceive threshold for the MAP radios in a r adio profile.
set radio-profile max-tx-lifetime 291 set radio-profile max-tx-lifetime Changes the maximum transmit threshold for the MAP radios in a radio profile. The maximum transmit threshold specifies the number of milliseconds that a frame scheduled to be transmitted by a radio can remain in buf fer memory .
292 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS Use this command without the mode enable or mode disable option to create a new pr ofile. mode enable — Enables the radios that use this pr ofile. mode disable — Disables the radios that use this profile.
set radio-profile mode 293 Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — Use the command without any optional parameters to cr eate new profile. If the radio profile does not alr eady exist, MSS creates a new radio profile. Use the enable or disable option to enable or disable all the radios using a profile.
294 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS The following command enables the WP A IE on MAP radios in radio profile rp2 : WX4400# set radio-profile rp2 wpa-ie enable success: change accepted.
set radio-profile rts-threshold 295 Y ou must disable all radios that use a radio profile before you can change parameters in the profile. Use the set radio-profile mode command .
296 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS See Also set radio-profile mode on page 291 display radio-profile on page 257 set radio-profile service-profile Maps a service profile to a radio profile. All radios that use the radio profile also use the parameter settin gs, including SSID and encryption settings, in the service pr ofile.
set radio-profile service-profile 29 7 cipher-tkip enable When the WPA IE is enabled, uses Temporal Key Integrity Protocol (TKIP) to encrypt traffic sent to WPA clients. cipher-wep104 disable Does no t use Wired Equivalent Privacy (WEP) with 104-bit key s to encrypt traffic sent to WPA clients.
298 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — Y ou must configure the service profile befor e you can map it to a radio profile. Y ou can map the same service pr ofile to more than one radio profile.
set radio-profile short-retry 299 set service-profile ssid-type on page 312 set service-profile tkip-mc-time on page 313 set service-profile web-aaa-form on page 314 set service-profil.
300 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS set service-profile auth-dot1x Disables or reena bles 802.1X authen tication of W i-Fi Pr otected Access (WP A) clients by MAP radios, when th e WP A information eleme nt (IE) is enabled in the service profile that is mapped to the rad io pr ofile that the radios are using.
set service-profile auth-fallthru 301 set service-profile psk-phrase on page 308 set service-profile wpa-ie on page 318 set service-profile auth-fallthru Specifies the authentication type for users who do not match an 802.1X or MAC authentication rule for an SSID managed by the service profile.
302 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS History —Introduced in MSS V ersion 3.0. Usage — The last-resort fallthru authentication type allows any user to access any SSID managed by the service profile. This method does not requir e the user to pr ovide a username or password.
set service-profile beacon 303 Usage — This command affects authentication of WP A clients only . T o use PSK authentication, you also must configure a passphr ase or key .
304 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS Defaults — Beaconing is e nabled by default. Access — Enabled. History —Introduced in MSS V ersion 3.0. Examples — The following co mmand disa bles beaconing of the SSID managed by service profile sp2 : WX4400# set service-profile sp2 beacon disable success: change accepted.
set service-profile cipher-tkip 305 See Also set service-profile cipher -tkip on page 305 set service-profile cipher -wep104 on page 306 set service-profile cipher -wep40 on page 307 s.
306 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS set service-profile cipher -wep104 Enables dynamic W ir ed Equivalent Privacy (WEP) with 104-bit keys, in a service profile. Syntax — set service-profile name cipher-w ep104 { enable | disable } name — Service pr ofile name.
set service-profile cipher-wep40 30 7 set service-profile cipher -tkip on page 305 set service-profile cipher -wep40 on page 307 set service-profile wep key-index on page 317 set servi.
308 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS Examples — The following co mmand c onfigures service profile sp2 to use 40-bit WEP encr yption: WX4400# set service-profile sp2 cipher-wep40 enable success: change accepted.
set service-profile psk-raw 309 Examples — The following co mmand c onfigures service profile sp3 to use passphrase “123456789 0123<>?=+&% The quick brown fox jumps over the lazy sl”: .
310 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS Examples — The following co mmand c onfigures service profile sp3 to use a raw PSK with P SK clients: WX4400# set service-profile sp3 psk-raw c25d3fe4483e867 d1df96eaacdf8b02451fa0836162e758100f 5f6b87965e59d success: change accepted.
set service-profile shared-key-auth 31 1 set service-profile shar ed-key-auth Enables shared-key authentication, in a service profile. Use this command only if advised to do so by 3Com. This command does not enable preshared key (PSK) auth entication for W i-F i Protected Access (WP A).
312 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS History —Introduced in MSS V ersion 3.0. Examples — The following co mmand applies the name guest to the SSID managed by service profile clear_wlan : WX4400# set service-profile clear_wlan ssid-name guest success: change accepted.
set service-profile tkip-mc-time 313 set service-profile tkip-mc-time Changes the length of time that MA P radios use countermeasures if two message integrity code (MIC) failure s occur within 60 seconds.
314 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS set service-profile web-aaa-form Specifies a custom login page to serve to WebAAA users who r equest the SSID managed by the service profile. Syntax — set service-profile name web-aaa-fo rm url name — Service pr ofile name.
set service-profile wep active-multicast- index 315 Total: 1839 bytes used, 20657 7 Kbytes free WX4400# set service-profile corpa-se rvice web-aaa-form corpa-ssid/ corpa-login.
316 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS See Also set service-profile we p active-unicast- index on page 316 set service-profile wep key-index on page 317 set service-profile wep active-unicast- index Specifies the static W ired-Equivalent Privacy (WEP) key (one of four) to use for encrypting unicast frames.
set service-profile wep key-index 31 7 set service-profile wep key-index Sets the value of one of four static Wired-Equivalent Privacy (WEP) keys for static WEP encryption. Syntax — set service-profile name wep key-ind ex num key value name — Service pr ofile name.
318 C HAPTER 9: M ANAGED A CCESS P OINT C OMMANDS set service-profile wpa-ie Enables the WP A information element (IE) in wireless frames. The WP A IE advertises the WP A authent ication meth ods and cipher suites support ed by radios in the radio profil e mapped to the service profile.
10 STP C OMMANDS Use Spanning T r ee Protocol (STP) commands to configure and manage spanning trees on the virtual LANs (VLANs) configured on a wir eless LAN switch or controller , to maintain a loop-free network. STP Commands by Usage This chapter pr esents STP command s alphabetically .
320 C HAPTER 10: STP C OMMANDS clear spantree portcost Resets to the default value t he cost of a network port or ports on paths to the STP root bridge in all VLANs on a WX switch. Syntax — clear spantree portcost port-list port-list — List of ports.
clear spantree portpri 32 1 clear spantree portpri Resets to the default value the priority of a network port or ports for selection as part of the path to th e STP root bridge in all VLANs on a wireless LAN switch or contr oller . Syntax — clear spantree portpri port-list port-list — List of ports.
322 C HAPTER 10: STP C OMMANDS vlan vlan-id — VLAN name or number . MSS resets the cost for only the specified VLAN. Defaults — None. Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — MSS does not change a port’ s cost for VLANs other than the one(s) you specify .
clear spantree statistics 323 History —Introduced in MSS V ersion 3.0. Usage — MSS does not change a port’ s priorit y for VLANs other than the one(s) you specify . Examples — The following command r esets the STP priority for port 2 in VLAN avocado: WX4400# clear spantree portvlanpri 2 vlan avocado success: change accepted.
324 C HAPTER 10: STP C OMMANDS display spantree Displays STP configurat ion and port-state information. Syntax — display spantree [ port-list | vlan vlan-id ] [ active ] port-list — List of ports. If you do not specify any ports, MSS displays STP information for all ports.
display spantree 325 7 1 Disable d 19 128 Disabled 8 1 Disable d 19 128 Disabled T ab le 60 describes the fields in this display . T able 60 Output for display spantree Field Description VLAN VLAN number. Spanning tree mode In the current software version, the mode is always PVST+, which means Per VLAN Spanning T ree+.
326 C HAPTER 10: STP C OMMANDS See Also display spantree blockedports on page 327 display spantree backbonefast Indicates whether the STP backbone fa st convergence featur e is enabled or disabled. Syntax — display spantree backbonefast Defaults — None.
display spantree blockedports 327 Examples — The following example shows the command out put on a WX switch with backbone fast convergence enabled: WX4400# display spantree backbonefas t Backbonefas.
328 C HAPTER 10: STP C OMMANDS display spantree portfast Displays STP uplink fast convergence information for all network p orts or for one or more network ports . Syntax — display spantree portfast [ port-list ] port-list — List of ports. If you do not specify any ports, MSS displays uplink fast converge nce information for all por ts.
display spantree portvlancost 32 9 display spantree portvlancost Shows the cost o f a port on a path to the STP root bridge, for each of the port’ s VLANs. Syntax — display spantree portvlancost port-list port-list — List of ports. Defaults — None.
330 C HAPTER 10: STP C OMMANDS Usage — The command displays statistics separately for each port. Examples — The following co mmand shows STP statistics for port 1: WX4400# display spantree statist.
display spantree statistics 331 topology change timer value 0 hold timer INACTIVE hold timer value 0 delay root port timer INACTIVE delay root port timer value 0 delay root port timer restarted is FAL.
332 C HAPTER 10: STP C OMMANDS T able 62 Output for display spantree statistics Field Descri ption Port Port number. VLAN VLAN ID. Spanning Tree enabled for vlan State of the STP feature on the VLAN. port spanning tree State of the STP feature on the port.
display spantree statistics 333 config_pending I ndicates whether a configured BPDU is to be transmitted on expiration of the hold timer for the port. port_inconsistency Indicates whether the port is in an inconsistent state. config BPDU’s xmitted Number of BPDUs transmitted from the port.
334 C HAPTER 10: STP C OMMANDS hold timer Status of the hold timer. This timer ensures that configured BPDUs are not transmitted too frequently through any bridge port.
display spantree uplinkfast 335 See Also clear spantree stati stics on page 323 display spantree uplinkfast Shows uplink fast convergence infor m ation for one VLAN or all VLANs. Syntax — display spantree uplinkfast [ vlan vlan- id ] vlan vlan-id — VLAN name or number .
336 C HAPTER 10: STP C OMMANDS Examples — The following co mmand shows uplink fast convergence information for all VLANs: WX4400# display spantree uplinkfast VLAN port list ------------------------------------ -------------------------------- ---- 1 1(fwd),2,3 T ab le 63 describes the fields in this display .
set spantree backbonefast 337 Examples — The following co mmand enables STP on all VLANs configured on a WX switch: WX4400# set spantree enable success: change accepted. The following command disables STP on VLAN burgundy: WX4400# set spantree disable vlan bu rgundy success: change accepted.
338 C HAPTER 10: STP C OMMANDS See Also display spantree backbonefast on page 326 set spantree fwddelay Changes the period of time after a topology change that a WX switch which is not the root bridge waits to begin forwar ding Layer 2 traffic on one or all of its configured VLANs.
set spantree maxage 339 vlan vlan-id — VLAN name or number . MS S changes the interval on only the specified VLAN. Defaults — The default hello timer interval is 2 seconds.
340 C HAPTER 10: STP C OMMANDS Examples — The following command changes the maximum acceptable age for root bridge hello packets on all VLANs to 15 seconds: WX4400# set spantree maxage 15 all success: change accepted.
set spantree portfast 341 Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — This command applies only to the defa ult VLAN (V LAN 1).
342 C HAPTER 10: STP C OMMANDS Examples — The following co mmand enab les port fast convergence on ports 2, 5, and 7: WX1200# set spantree portfast port 2 ,4,7 enable success: change accepted.
set spantree portvlancost 343 set spantree portvlancost Changes the cost of a network por t or ports on paths to the STP root bridge for a specific VLAN on a wireless LAN switch. Syntax — set spantree portvlancost port-lis t cost cost { all | vlan vlan-id } port-list — List of ports.
344 C HAPTER 10: STP C OMMANDS set spantree portvlanpri Changes the priority of a network port or ports for selectio n as part of the path to the STP root bridge, on one VLAN or all VLANs. Syntax — set spantree portvlanpri port-list priority value { all | vlan vlan-id } port-list — List of ports.
set spantree uplinkfast 345 all — Changes the bridge priority on all VLANs. vlan vlan-id — VLAN name or number . MSS changes the bridge priority on only the specified VLAN. Defaults — The default root bridge priority for the switch on all VLANs is 32,768.
346 C HAPTER 10: STP C OMMANDS Examples — The following co mmand enab les uplink fast convergence: WX4400# set spantree uplinkfast enab le success: change accepted.
11 IGMP S NOOPING C OMMANDS Use Internet Group Management Pr otocol (IGMP) snooping commands to configure and manage multicast traff ic reduction on a WX. Commands by usage This chapter presents IGMP snooping commands alphabetically . Use the T ab le 65 to locate commands in this chapter based on their use.
348 C HAPTER 11: IGMP S NOOPING C OMMANDS clear igmp statistics Clears IGMP statistics count ers on one VLAN or all VLANs on a wir eless LAN switch and r esets them to 0. Syntax — clear igmp statistics [ vlan vlan-id ] vlan vlan-id — VLAN name or number .
display igmp 349 router information: Port Mrouter-IPaddr Mrouter-MAC Type TTL ---- --------------- --------------- -- ----- ----- 1 192.28.7.5 00:01:02:03:04:05 dvmrp 17 Group Port Receiver-IP Receiver-MAC TTL --------------- ---- --------------- ----------------- ----- 224.
350 C HAPTER 11: IGMP S NOOPING C OMMANDS T able 66 Output for display igmp Field Descri ption VLAN VLAN name. MSS displays info rmation separately for each VLAN. IGMP is enabled (disabled) IGMP state. Proxy reporting Proxy reporting state. Mrouter solicitation Multicast router solicitation state.
display igmp 351 TTL Number of seconds befo re this entry ages out if not refreshed. For static multicast route r entries, the time-to-live (TTL) value is undef . Static multicast router entries do not age out. Group IP address of a multicast group. The display igmp receiver -table command shows the sa me information as these receiver fields.
352 C HAPTER 11: IGMP S NOOPING C OMMANDS See Also display igmp mrouter on page 352 display igmp querier on page 353 display igmp receiver -table on pag e 355 display igmp statistic s on page 356 display igmp mrouter Displays the multicast routers in a WX’ s subnet, on one VLAN or all VLANs.
display igmp querier 35 3 See Also display igmp mrouter on page 352 set igmp mr outer on page 360 display igmp querier Shows information about the active multicast querier , on one VLAN or all VLANs. Queriers are listed separately for each VLAN.
354 C HAPTER 11: IGMP S NOOPING C OMMANDS History — Introduced in MSS V ersio n 3.0. Examples — The followin g command displa ys querier information for VLAN orange : WX1200# display igmp querier vlan or ange Querier for vlan orange Port Querier-IP Querier-MAC TTL ---- --------------- --------------- -- ----- 1 193.
display igmp receiver-table 355 See Also set igmp querier on page 366 display igmp receiver -table Displays the receivers to which a WX forwar ds multicast traffic. Y ou can display receivers for all VLANs, a si ngle VLAN, or a group or gr oups identified by group address and network mask.
356 C HAPTER 11: IGMP S NOOPING C OMMANDS The following command lists all r eceivers for multicast groups 237.255.255.1 t hr ough 237.255.255.2 55, in all VLANs: WX1200# display igmp receiver-table group 237.255.255.0/24 VLAN: red Session Port Receiver-IP Receiver-MAC TTL --------------- ---- --------------- ----------------- ----- 237.
display igmp stati stics 357 Defaults — None. Access — All. History — Introduced in MSS V ersion 3.0. Examples — The followin g command displays IGMP statistics for VLAN orange : WX1200# displ.
358 C HAPTER 11: IGMP S NOOPING C OMMANDS T able 70 Output of display igmp statistics Field Description IGMP statistics for vlan VLAN name. Statistics are lis ted separately for each VLAN.
set igmp 359 See Also clear igmp statistics on page 348 set igmp Disables or reenables IGMP snooping on one VLAN or all VLANs on a wireless LAN switch. Syntax — set igmp { enable | disable } [ vlan vlan-id ] enable — Enables IGMP snooping.
360 C HAPTER 11: IGMP S NOOPING C OMMANDS set igmp lmqi Changes the IGMP last member query interval timer on one VLAN or all VLANs on a wirel ess LAN switch.
set igmp mrsol 361 enable — Adds the port to the list of static multicast router ports. disable — Removes the port from the list of static multicast router ports. Defaults — By default, no ports are static multicast router ports. Access — Enabled.
362 C HAPTER 11: IGMP S NOOPING C OMMANDS History — Introduced in MSS V ersio n 3.0. Examples — The followin g command enables multicast router solicitation on VLAN orange : WX1200# set igmp mrsol.
set igmp oqi 363 set igmp oqi Changes the IGMP other -querier -present interval timer on one VLAN or all VLANs on a WX. Syntax — set igmp oqi seconds [ vlan vlan-id ] oqi seconds — Number of seconds that th e WX waits for a general query to arrive before electing itself the querier .
364 C HAPTER 11: IGMP S NOOPING C OMMANDS set igmp proxy-r eport Disables or reenables proxy r eporting by a WX on one VLAN o r all VLANs. Syntax — set igmp proxy-report { enable | disable } vlan vlan-id — VLAN name or number . If you do not specify a VLAN, proxy r eporting is disabl ed or r eenabled on all VLANs.
set igmp qri 365 Access — Enabled. History — Introduced in MSS V ersion 3.0. Usage — The query interval is applicable on ly when the WX is querier for the subnet.
366 C HAPTER 11: IGMP S NOOPING C OMMANDS History — Introduced in MSS V ersion 3.0. Usage — The query r esponse interval is applicable only when the WX is querier for the subnet.
set igmp receiver 367 Examples — The following example enables the pseu do-querier on the orange VLAN: WX1200# set igmp querier enable vlan orange success: change accepted. See Also display igmp querier on page 353 set igmp receiver Adds or r emoves a network port in the list of port s on which a WX forwards traffic to multicast receivers.
368 C HAPTER 11: IGMP S NOOPING C OMMANDS See Also display igmp receiver -table on pag e 355 set igmp rv Changes the robustness value for one VLAN or all VLANs on a WX. Robustness adjusts the IG MP timers to the amount of traf fic loss that occurs on the network.
12 S ECURITY ACL C OMMANDS Use security ACL commands to configure and monitor security access control lists (ACLs). Security ACLs filt er packets to restrict or permit network usage by certain users or traffic types, and can assign to packets a class of service (CoS) to define th e pr iority of tre atment for packe t filtering.
370 C HAPTER 12: S ECURITY ACL C OMM ANDS clear security acl Clears a specified security ACL, an access c ontrol e ntry (ACE), or all security ACLs, from the edit buffe r . When used with the command commit securi ty acl , clears the ACE fr om the running configuration.
clear security acl map 371 WX4400# display security acl info al l ACL information for all set security acl ip acl_133 (hits #1 0) ------------------------------------ --------------------- 1.
372 C HAPTER 12: S ECURITY ACL C OMM ANDS Syntax — clear security acl map { acl-name | all } { vlan vlan-id | port port-list [ tag tag-value ] | dap dap-num } { in | out } acl-name — Name of an existing security ACL to clear . ACL names start with a letter and ar e case-insensitive.
commit security acl 373 T o clear all physical port s, virtual ports , and VLANs on a WX switch of the ACLs mapped for incoming and outgoi ng traffic, type the following command: WX4400# clear security acl map all success: change accepted.
374 C HAPTER 12: S ECURITY ACL C OMM ANDS Examples — The following co mmands commit all the security ACLs in the edit buffer to the configuration, display a summary of the committed ACLs, and show t.
display security acl hi ts 375 Examples — T o display a summary of the committed security ACLs on a WX switch, type the following command: WX4400# display security acl ACL table ACL Type Class Mappi.
376 C HAPTER 12: S ECURITY ACL C OMM ANDS Examples — T o display the security ACL hits on a WX switch, type the following command: WX4400# display security acl hits ACL hit-counters Index Counter AC.
display security acl map 377 Examples — T o display the conten ts of all security ACLs committed on a WX switch, type the following command: WX4400# display security acl info al l ACL information for all set security acl ip acl_123 (hits #5 462) ------------------------------------ --------------------- 1.
378 C HAPTER 12: S ECURITY ACL C OMM ANDS Access — Enabled. History — Introduced in MSS V ersion 3.0. Examples — The following command displays the port to which security ACL acl_111 is mapped :.
display security acl resource-usage 379 Examples — T o display security ACL res ource usage, type the following command: WX4400# display security acl resourc e-usage ACL resources Classifier tree co.
380 C HAPTER 12: S ECURITY ACL C OMM ANDS T able 72 Output of display security acl resour ce-usage Field Description Number of rules Number of security ACEs cu rrently mapped to ports or VLANs. Number of leaf nodes Number of se curity ACL data en tries stored in the rule tree.
display security acl resource-usage 381 LUdef in use Number of the lookup definition (LUdef) table currently in use for packet handling. Default action pointer Memory address used for packet handling, from which default action data is obtained when necessary.
382 C HAPTER 12: S ECURITY ACL C OMM ANDS hit-sample-rate Specifies the time interval, in second s, at which the packet counter for each security ACL is sampled for disp lay . Th e counter counts the number of packets filtered by the security ACL — or “hits.
rollback security acl 383 Examples — The first command sets MSS to sample ACL hits every 15 seconds. The second and third commands display the r esults.
384 C HAPTER 12: S ECURITY ACL C OMM ANDS Examples — The following co mmands show the edit buf fer befor e a rollbac k, clear any change s in the edit buffe r to security acl_122 , and show the ed i.
set security acl 385 By ICMP packets Syntax — set security acl ip acl-name { permi t [ cos cos ] | deny } icmp { sourc e-ip-addr mask destination-ip-addr mask [ type icmp-type ] [ code icmp-code ] [.
386 C HAPTER 12: S ECURITY ACL C OMM ANDS 0 or 3—Best effort. Packets are queued in MAP forwarding queue 3. 4 or 5—Video. Packets are que ued in MAP forwarding queue 2. Use CoS level 4 or 5 for voice over IP (V oIP) packets other than SpectraLink V oice Priority (SVP).
set security acl 387 (For a complete list of TCP and UDP port numbers, see www .iana.or g/assign ments/port-numbers .) destination-ip-addr mask — IP addr ess and wildcar d mask of the network or host to which the packet is being sent. Specify both address and mask in dotted decimal not ation.
388 C HAPTER 12: S ECURITY ACL C OMM ANDS before editbuffer-index — Inserts the new ACE in fr ont of another ACE in the security ACL. Specify the number of the existing ACE in the edit buffer . Index numbers start at 1. (T o display the edit buffer , use display security acl editbuf fer .
set security acl map 389 The following command adds an ACE to acl_123 that denies packets from IP addr ess 192.168.2.11: WX4400# s et security acl ip acl_123 deny 192.168.2.11 0.0.0.0 The following command creates acl_125 by defining an ACE that denies TCP packets from sour ce IP addr ess 1 92.
390 C HAPTER 12: S ECURITY ACL C OMM ANDS Syntax — set security acl map acl-name { v l an vlan-id | port port-list [ tag tag-list ] | dap dap-num } { in | out } acl-name — Name of an existing security ACL to map. ACL names start with a letter and ar e case-insensitive.
set security acl map 391 See Also clear security acl map on page 371 commit security acl on page 373 set mac-user attr on page 208 set mac-usergroup attr on page 214 set security a.
392 C HAPTER 12: S ECURITY ACL C OMM ANDS.
13 C RYPTOGRAPHY C OMMANDS Use cryptography commands to co nfigur e and manage certificates and public-private key pairs for system authentication . Depending on your network configurat ion, you must create keys and certificates to authenticate the WX switch to IEEE 802.
394 C HAPTER 13: C RYPTOGRA PHY C OMMANDS crypto ca-certificate Installs a certificate authority’ s ow n PKCS #7 certificate into the WX certificate and ke y storage area.
crypto certificate 39 5 T o use this command, you must already have obtained a copy of the certificate authority’ s certificate as a PKCS #7 object file. Then do the following: 1 Open the PKCS #7 object file with an ASCII text editor such as Notepad or vi.
396 C HAPTER 13: C RYPTOGRA PHY C OMMANDS PEM-formatted certificate — ASCII text repr esentation of the PKCS #7 certificate, consist ing of up to 4096 characters, that you have obtained from th e certificate authority . Defaults — None. Access — Enabled.
crypto generate key 397 crypto generate key Generates an RSA public-private encrypti on key pair that is requir ed for a Certificate Signing Request ( CSR) or a self-signed certific ate.
398 C HAPTER 13: C RYPTOGRA PHY C OMMANDS crypto generate re quest Generates a Certificate Signing Reque st (CSR). Thi s command outputs a PEM-formatted PKCS #10 text string that you can cut and paste to another location for delivery to a certificate author ity .
crypto generate request 399 Defaults — None. Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — T o use th is command, you mu st alr eady have generated a public-private encryption key pair with the crypto generate key command.
400 C HAPTER 13: C RYPTOGRA PHY C OMMANDS See Also crypto certificate on page 395 crypto generate key on page 397 crypto generate self-signed Generates a self-signed certificate for either an administrative certificate for use with 3WXM or an EAP certificate for use with 802.
crypto generate self-signed 40 1 Note: If you are generating a WebAAA (webaaa) certificate, use a common name that look s like a doma in name (t wo or mor e st rings connected by dots, with no spaces ). For example, use common.name instead of common name.
402 C HAPTER 13: C RYPTOGRA PHY C OMMANDS BAMCBkAwSAYJYIZIAYb4QgENBDsWOXRoaXMg Y2VydGlmaWNhdGUgaXMgY29tcGxl dGVseSB1bnRydXN0d29ydGh5LiBJcyB0aGF0 IE9LPzAPBgNVHRMBAf8EBTADAQH/ MA0GCSqGSIb3DQEBBAUAA4GBAH.
crypto pkcs12 40 3 Question mark (?) Ampersan d (&) Defaults — None. Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — The password allows the public- private key pair and certificate to be installed together from the same PKCS #12 object file.
404 C HAPTER 13: C RYPTOGRA PHY C OMMANDS webaaa — Unpacks a PKCS #12 object file for a WebAAA certificate and key pair — and optionally the certificate authority’ s own certificate — for authenticating the WX switch to W ebAAA clients. file-location-url — Location of the PKCS #12 object file to be installed.
display crypto ca-certificate 405 display crypto ca-certificate Displays information about the certificate authority’ s PEM-encod ed PKCS #7 certificate.
406 C HAPTER 13: C RYPTOGRA PHY C OMMANDS See Also crypto ca-certificate on page 394 display crypto certificate on page 406 display crypto certificate Displays information about one of the cryptographic certificates installed on the WX switch.
display crypto key ssh 407 See Also crypto generate self-signed on page 400 display crypto ca-certificate on page 405 display crypto key ssh Displays SSH authentication key info rmation. This comma nd displays the checksum (also called a fingerprint ) of the public SSH authentication key .
408 C HAPTER 13: C RYPTOGRA PHY C OMMANDS.
14 RADIUS AND S ERVER G RO U P C OMMANDS Use RADIUS comma nds to set up communicatio n between an WX switch and groups of up to four RADIUS servers for re mote authentication, authorization, and accounting (AAA) of administrat ors and network users. Commands by Usage This chapter presents RADIUS commands alp habetically .
410 C HAPTER 14: RADIUS AND S ERVER G ROUP C OM MANDS clear radius Resets parameters that were globall y configured for RADIUS servers to their default values.
clear radius client system-ip 411 WX4400# clear radius timeout success: change accepted. See Also set radius on page 413 set radius server on page 415 display aaa on page 180 clear radius .
412 C HAPTER 14: RADIUS AND S ERVER G ROUP C OM MANDS clear radius server Removes the named RADIUS server from the WX configuration. Syntax — clear radius server server-name server-name — Name of a RADIUS server con figur ed to perfo rm remote AAA services for the WX switch.
set radius 413 Examples — T o remove the server gr oup sg-77 type the following command: WX4400# clear server group sg-77 success: change accepted. T o d isable load balancing in a server group shorebirds , type the following command: WX4400# set server group shorebirds load-balance disable success: change accepted.
414 C HAPTER 14: RADIUS AND S ERVER G ROUP C OM MANDS retransmit — 3 (the total number of attempts, including the first attempt) timeout — 5 seconds Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — Y ou can specify only one parameter per command line.
set radius server 415 Usage — The WX system IP addr ess must be set before you use this command. Examples — The followin g command sets the WX system IP address as the address of the RADIUS client: WX4400# set radius client system-ip success: change accepted.
416 C HAPTER 14: RADIUS AND S ERVER G ROUP C OM MANDS (24 hours). A zero value causes the switch to identify unresponsive servers as avail able. key string — Password (shared secr et key) the WX switch uses to authenticate to the RADIUS server .
set server group 417 Examples — T o set a RADIUS server named RS42 with IP address 198.162.1.1 to use the default acco unt ing and authorization ports with a timeout interval of 30 second s, two transmit attempts, 5 minutes of dead time, and a key string o f keys4u , type the following command: WX1200# set radius server RS42 address 198.
418 C HAPTER 14: RADIUS AND S ERVER G ROUP C OM MANDS Do not use the same name for a R ADIUS server and a RADIUS server group. Examples — T o set server group shorebirds with members her on , egret , and sandpiper , type the following command: WX1200# set server group shorebirds members heron egret sandpiper success: change accepted.
set server group load-balanc e 419 Examples — T o enable load balanc ing betwee n the memb ers of serv er group shorebirds , type the following command: WX1200# set server group shorebirds load-balance enable success: change accepted.
420 C HAPTER 14: RADIUS AND S ERVER G ROUP C OM MANDS.
15 802.1X M ANAGEMENT C OMMANDS Use 802. IEEE X management commands to modify the default settings for IEEE 802.1X sessions on an WX sw itch. For best r esults, change the settings only if you are awar e of a pr oblem with the WX switch’ s 802.1X performance.
422 C HAPTER 15: 802.1X M ANAGEMENT C OMMANDS clear dot1x bonded-period Resets the Bonded Auth™ (bonded authentication) perio d to its default value. The bonded period is the number of seconds MSS retains session information for an authenticated machin e while waiting for an 802.
clear dot1x max-req 423 See Also display dot1x on page 427 set dot1x bonded-period on page 431 clear dot1x max- req Resets to the default setting the nu mber of Extensible Authentication Protocol (EAP) r equests that the WX switch retransmits to a supplicant (client).
424 C HAPTER 15: 802.1X M ANAGEMENT C OMMANDS Usage — This command is overridden by the set dot1x authcontrol command. The clear dot1x port-control command r eturns port contr ol to the method configured. This command applies only to wired authentication ports.
clear dot1x reauth-max 425 clear dot1x re auth-max Resets the maxi mum number of reaut horization attempts to the default setting. Syntax — clear dot1x reauth-max Defaults — The default is 2 attempts. Access — Enabled. History —Introduced in MSS V ersion 3.
426 C HAPTER 15: 802.1X M ANAGEMENT C OMMANDS clear dot1x timeout auth-server Resets to the default setting the nu mber of seconds that must elapse before the WX times out a request to a RADIUS server . Syntax — clear dot1x timeout auth-server Defaults — The default is 3 0 seconds.
clear dot1x tx-period 427 set dot1x timeout supplicant on page 437 clear dot1x tx-period Resets to the default setting the nu mber of seconds that mus t elapse before the WX switch r etransmits an EAP over LAN (EAPoL) packet. Syntax — clear dot1x tx-period Defaults — The default is 5 seconds.
428 C HAPTER 15: 802.1X M ANAGEMENT C OMMANDS History —Introduced in MSS V ersion 3.0. Format of 80 2.1X authentication rule informat ion in display dot1x config output changed in MSS V e rsion 3. 2. The rules are still listed at the top of the display , but more information is shown for each rule.
display dot1x 429 802.1X parameter setting ---------------- ------- supplicant timeout 30 auth-server timeout 30 quiet period 5 transmit period 5 reauthentication period 3600 maximum requests 2 key tr.
430 C HAPTER 15: 802.1X M ANAGEMENT C OMMANDS set dot1x authcontrol Provides a global override mechanism for 802.1X authentication configuration on wired authentication ports. Syntax — set dot1x authcontrol { enable | d isable } enable — Allows all wir ed authentication ports running 802.
set dot1x bonded-period 431 Defaults — By default, authenticati on control for individual wir ed authentication is enabled. Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — This command applies only to wired authentication ports.
432 C HAPTER 15: 802.1X M ANAGEMENT C OMMANDS Usage — Normally , the Bonded Auth period needs to be set only if the network has Bonded Auth clients that use dynamic WEP , or use WEP-40 or WEP-104 encryption with WP A or RS N. These clients can be affected by the 802.
set dot1x max-req 433 success: dot1x key transmission enab led. See Also display dot1x on page 427 set dot1x max-req Sets the maximum number of times th e WX retransmits an EAP r equest to a supplicant (client) before ending the authentication session.
434 C HAPTER 15: 802.1X M ANAGEMENT C OMMANDS forceunauth — Forces the specified wired authentication port(s) to unconditionally reject all 802.1X authentication att empts with an EAP failure message. auto — Allows the specified wired authentication ports to pr ocess 802.
set dot1x reauth 435 Examples — T ype the following command to set the quiet period to 90 seconds: WX4400# set dot1x quiet-period 90 success: dot1x quiet period set to 9 0.
436 C HAPTER 15: 802.1X M ANAGEMENT C OMMANDS set dot1x re auth-max Sets the number of reauthentication attempts that the WX switch makes before the supplicant (client) becomes unauthorized. Syntax — set dot1x reauth-max number-of-at tempts number-of-attempts — Specify a value between 1 and 10.
set dot1x timeout auth-server 437 Examples — T ype the following command t o set the number of seconds to 100 before r eauthentication is attempted: WX4400# set dot1x reauth-period 100 success: dot1x auth-server timeout s et to 100.
438 C HAPTER 15: 802.1X M ANAGEMENT C OMMANDS Access — Enabled. History —Introduced in MSS V ersion 3.0. Examples — T ype the following command to set the number of seconds for authentication session timeout to 300: WX4400# set dot1x timeout supplicant 300 success: dot1x supplicant timeout se t to 300.
set dot1x wep-rekey 439 set dot1x wep-rekey Enables or d isables Wired Equiva lency Privacy (WEP) rekeying for broadcast and multica st encryption keys.
440 C HAPTER 15: 802.1X M ANAGEMENT C OMMANDS History —Introduced in MSS V ersion 3.0. Examples — T ype the following command to set the WEP-rekey period to 300 seconds: WX4400# set dot1x wep-reke.
16 S ESSION M ANAGEMENT C OMMANDS Use session management commands to display and cl ear administrative and ne twork user sessions. Commands by Usage This chapter pr esents session manage ment commands al phabeti cally . Use T ab le 79 to locate commands in this chapter based on their use.
442 C HAPTER 16: S ESSION M ANAGEMENT C OMMANDS Defaults — None. Access — Enabled. History —Introduced in MSS V ersion 3.0. Examples — T o clear all administrato r sessions type the following .
clear sessions network 443 character—either an at sign (@) or a period (.). (For details, see “User Globs” on page 24.) mac-addr mac-addr-glob — Clears all network sessions for a MAC address. Specify a MAC address in hexadecimal numbers separated by colons (:), or use the wildcar d character (*) to spec ify a set of MAC addresses.
444 C HAPTER 16: S ESSION M ANAGEMENT C OMMANDS T o clear the sessions of users whose name begins with the characters Jo , type the following command: WX1200# clear sessions network user Jo* T o clear.
display sessions 445 Examples — T o view information abo ut sessions of administrative users, type the following command: WX4400> display sessions admin Tty Username Ti me (s) Type ------- ------.
446 C HAPTER 16: S ESSION M ANAGEMENT C OMMANDS T able 81 describes the fields of the display sessions telnet client display . See Also clear sessions on page 441 display sessions network Displays.
display sessions network 447 Syntax — display sessions network [ user user-glob | mac-addr mac-addr- glob | ssid ssid-name vlan vlan-glob | session-id session-id | wired ] [ verbose ] user user-glob — Displays all network sessions for a single user or set of users.
448 C HAPTER 16: S ESSION M ANAGEMENT C OMMANDS Usage — MSS displays information about network sessions in three types of displays. See the follo wing tables for field descriptions. Summary display — See T a ble 82 on page 450. V erbose display — See T able 83 on page 450.
display sessions network 449 (T able 82 on page 450 describes the su mmary displays of display sessions network commands.) The following command displays detailed (verbose) session information about user nin@example.com: WX1200# display sessions network use r nin@example.
450 C HAPTER 16: S ESSION M ANAGEMENT C OMMANDS Tag: 1 Session Timeout: 1800 Authentication Method: PEAP, using s erver 10.10.70.20 Session statistics as updated from A P: Unicast packets in: 653 Unic.
display sessions network 451 State Status of the session: AUTH, ASSOC REQ — Client is being associated by the 802.1X protocol. AUTH AND ASSOC — Client is being associated by the 802.1X protocol, and the user is being authenticated. AUTHORIZING — User has been authenticated (for exam ple, by the 802.
452 C HAPTER 16: S ESSION M ANAGEMENT C OMMANDS T able 84 display sessions network session-id Output Field Description Global Id A u nique session identifier within the Mob ility Domain. State Status of the session: AUTH, ASSOC REQ — Client is being ass ociated by the 802.
display sessions network 453 See Also clear sessions network on page 442 Session Timeout Assigned session timeou t in seconds. Authentication Method Extensible Auth entication Protocol (EAP) type used to authenticate the session user, and the IP addr es s of the authentication server.
454 C HAPTER 16: S ESSION M ANAGEMENT C OMMANDS.
17 RF D ETECTION C OMMANDS MSS automatically performs RF detect ion scans on enabled and disabled radios to detect rogue access points. A rogue access point is a BSSID (MAC address associated with an SS ID) that does not belong to a 3Com switch and is not a member of the ignore list configured on the seed switch of the Mobility Domain.
456 C HAPTER 17: RF D ET ECTION C OMMANDS clear rfdetect countermeasures mac Removes a rogue BSSID fr om the list configured by the set rfdetect countermeasur es m ac command. Syntax — clear rfdetect countermeasu res mac { mac-addr | all } mac-addr — Basic service set identifier (BSSID) of the r ogue.
clear rfdetect ignore 457 If the clear rfdetect countermeasures mac command r emoves the last rogue fr om the list created by set rfdetect countermeasur es mac commands, RF detection returns to the default handling of countermeasures. Consequently , the rogue you cleared can still be attacked if it is still in the r ogue list.
458 C HAPTER 17: RF D ET ECTION C OMMANDS See Also display rfdetect ignore on page 461 set rfdetect ignore on page 467 display rfdetect countermeasures Displays the current status of countermeasures against rogues in the Mobility Domain. Syntax — display rfdetect countermeasure s Defaults — None.
display rfdetect data 459 See Also clear rfdetect countermeasures mac on page 456 set rf detect countermeasures on page 465 set rfdetect countermeasures mac on page 466 display rfdetect data Displays all the BSSIDs detected by an individual WX switch during an RF detection scan.
460 C HAPTER 17: RF D ET ECTION C OMMANDS Only one MAC addr ess is listed for each 3Com radio, e ven if th e radio is beaconing multiple SSIDs. Examples — The following command shows the devices det.
display rfdetect ignore 461 display rfdetect ignore Displays the BSSIDs of third-party devices that MSS ignor es during RF scans. MSS does not gene rate log messages or traps for the devices in the ignore list. Syntax — display rfdetect ignore Defaults — None.
462 C HAPTER 17: RF D ET ECTION C OMMANDS Examples — The following example displays in formation about the BSSIDs detected in the Mobility Domain manage d by the seed switch: WX1200# display rfdetec.
display rfdetect visible 463 See Also display rfdetect data on page 459 display rfdetect visible on page 463 display rfdetect visible Displays the BSSIDs discovered by a specific 3Com radio. The data includes BSSIDs transmitted by othe r 3Com radios as well as by third-party access points.
464 C HAPTER 17: RF D ET ECTION C OMMANDS Examples — The following co mmand displa ys the devices detected by 3Com ra dio 00:0 b:0e:0 0:0a:6a: WX1200# display rfdetect visible 00: 0b:0e:00:0a:6a Tot.
set rfdetect active-scan 465 set rfdetect active-scan Disables or reenables active RF dete ction scan ning on a WX switch . When active scanning is enabled, the MAP radios managed by the switch look for rogue devices by sending probe any r equests (probe requests with a null SSID name), to solicit probe responses fr om other access points.
466 C HAPTER 17: RF D ET ECTION C OMMANDS Usage — This command is valid only on the seed switch of the Mobility Domain. Examples — The following co mmand enab les countermeasures for the Mobility Domain managed by this seed switch: WX1200# set rfdetect countermeasures enable success: countermeasures are now en abled.
set rfdetect ignore 467 This command is valid only on the se ed switch of the Mobility Domain. The countermeasures take ef fect only if countermeasures are enabled for the Mobility Domain, using the set rfdetect countermeasures enable command.
468 C HAPTER 17: RF D ET ECTION C OMMANDS Examples — The following command config ur es MSS to ignor e BSSID aa:bb:cc:11:22:33 during RF scans: WX1200# set rfdetect ignore aa:bb:cc:11:22:33 success: MAC aa:bb:cc:11:22:33 is n ow ignored.
18 F ILE M ANAGEMENT C OMMANDS Use file management commands to ma nage system files and to display software and boot information. Commands by Usage This chapter presents file management co mmands alphabetically . Use T ab le 90 to locate commands in this chapter based on their use.
470 C HAPTER 18: F ILE M ANAGEMENT C OMMANDS backup Creates an ar chive of WX system file s and optionally , user file, in Unix tape archive ( tar ) format. Syntax backup system [tftp:/ip-addr/]filename [all | critical] Defaults — All. Access — Enabled.
clear boot config 471 Examples — The followin g command cr eates an archive of the system-critical files and copies the ar chive directly to a TF TP server . The filename in this example includes a TF TP server IP addr ess, so the ar chive is not stor ed locally on the switch.
472 C HAPTER 18: F ILE M ANAGEMENT C OMMANDS Examples — The following commands back up the configuration file on an WX switch, reset the switch to it s factory default configuration, and reboot the switch: WX4400# copy configuration tftp://10 .1.1.1/backupcfg success: sent 365 bytes in 0.
copy 473 If you are copying a system image f ile into nonvolatile storage, the filename must include the boot partition name. Y ou can specify one of the following: boot0: / filename boot1: / filename Defaults — None. Access — Enabled. History —Introduced in MSS V ersion 3.
474 C HAPTER 18: F ILE M ANAGEMENT C OMMANDS The following command copies system image WXA0 3001.Rel from a TF TP server to boo t partition 1 in nonvolatile storage: WX4400# copy tftp://10.1.1.107/WXA03 001.Rel boot1:WXA03001.Rel .....................
dir 475 Defaults — None. Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — Y ou might wan t to copy the file to a TF TP server as a backup before deleting the file. Examples — The follow ing co mmands copy file testconfig to a TF TP server and delete the file from nonvolatile storage: WX4400# copy testconfig tftp://10.
476 C HAPTER 18: F ILE M ANAGEMENT C OMMANDS Examples — The following co mmand displays the files in the r oot directory: WX4400# dir ==================================== ================================ =========== file: Filename Size Creat ed file:configuration 17 KB May 21 20 04, 18:20:53 file:configuration.
display boot 477 See Also copy on page 472 delete on page 474 display boot Displays the system image and configur ation filenames used after the last reboot and configured for use after the next reboot. Syntax — display boot Defaults — None.
478 C HAPTER 18: F ILE M ANAGEMENT C OMMANDS T ab le 93 describes the fields in the display boot output. See Also display version on pag e 480 reset system on page 485 set boot configuration-file on page 488 display config Displays the configuration ru nning on the WX switch.
display config 479 portconfig portgroup radio-profile rfdevice service-profile sm snmp spantree system trace vlan vlan-fdb If you do not specify a configuration area, nondefault information for all areas is displayed.
480 C HAPTER 18: F ILE M ANAGEMENT C OMMANDS save config on page 487 display version Displays software and har dwar e version information for an WX switch and, optionally , for an y a ttached MAP access points.
display version 481 Build Suffix: -d-O1-3com Model: WX1200 Hardware Mainboard: version 1 ; FPGA version 0 CPU Model: 405EP (Revision 9 .80) PoE board: version 0 ; FPGA version 0 Serial number M8WE48BB8C7A0 Flash: 3.0.1 - md0a Kernel: 3.0.1#130: Thu Se p 23 05:45:24 PDT 2004 BootLoader: 1.
482 C HAPTER 18: F ILE M ANAGEMENT C OMMANDS See Also display boot on page 477 load config Load s configuration commands fr om a file and replaces the WX switch’ s running configuration with the commands in the loaded file.
mkdir 483 Usage — This command completely replaces the running configuration with the configuration in the file. Examples — The following comman d r eloads the configuration from the most recently.
484 C HAPTER 18: F ILE M ANAGEMENT C OMMANDS Filename Size Creat ed file:configuration 17 KB May 21 20 04, 18:20:53 file:configuration.txt 379 bytes May 09 20 04, 18:55:17 corp2/ 512 bytes May 21 2004.
reset system 485 reset system Restar ts an WX switch and r eboots the software. Syntax — reset system [ force ] force — Immediately restarts the system and reboots, without comparing the running co nfiguration to the configuration file. Defaults — None.
486 C HAPTER 18: F ILE M ANAGEMENT C OMMANDS res to re Unzips a system archive created by the backup command and copies the files from the ar chive onto the switch. Syntax restore system [tftp:/ip-addr/]filename [al l | critical] Defaults — Critical.
rmdir 487 See Also backup on page 470 rmdir Removes a subdirectory fr om nonvolatile storage. Syntax — rmdir [ subdirname ] subdirname — Subdirectory name. Specify between 1 and 32 alphanumeric characters , with no spaces. Defaults — None.
488 C HAPTER 18: F ILE M ANAGEMENT C OMMANDS Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — If you do not specify a filename, MS S r eplaces the configuration file loaded during the most recent r eboot.
set boot partition 489 Access — Enabled. History —Introduced in MSS V ersion 3.0. Usage — The file must be located in the switch’ s nonvolatile storage. Examples — The following command sets th e boot configuration file to testconfig1 : WX4400# set boot configuration-file testconfig1 success: boot config set.
490 C HAPTER 18: F ILE M ANAGEMENT C OMMANDS.
19 T RACE C OMMANDS Use trace commands to perform diag nostic routines. While MSS allows you to run many types of traces, this chapter describes commands for those traces you are most likely to use. Fo r a complete listing of the types of traces MSS allows, type the set trace ? command.
492 C HAPTER 19: T RACE C OMMANDS Access — Enabled. History —Introduced in MSS V ersion 3.0. Examples — T o delete the trace log, type the following command: WX4400# clear log trace See Also display log buffer on page 500 set log on page 504 clear trace Deletes run ning trace commands and ends trace pr ocesses.
display trace 493 See Also display trace on page 493 set trace authentication on page 494 set trace authorization on page 495 set trace dot1x on page 496 set trace sm on page 497 display trace Displays information about traces that ar e currently configured on the WX switch, or all possible tr ace options.
494 C HAPTER 19: T RACE C OMMANDS save trace Saves the accumulated trace data for enabled traces to a file in the WX switch’ s no nvolatile storage. Syntax — save trace filename filename — Name for the trace file. T o save the file in a subdirectory , specify the subdir ectory name, then a slash.
set trace authorization 495 Examples — The following co mmand sta rts a trace for information about user jose’ s authent ication: WX4400# set trace authentication use r jose success: change accepted. See Also clear trace on page 492 display trace on page 493 set trace authorization T races au thorization information.
496 C HAPTER 19: T RACE C OMMANDS See Also clear trace on page 492 display trace on page 493 set trace dot1x T r aces 802.1X sessions. Syntax — set trace dot1x [ mac-addr mac-addr ess ] [ port port-num ] [ user username ] [ level level ] mac-addr mac-address — T races a MAC address.
set trace sm 497 set trace sm T races session manager activity . Syntax — set trace sm [ mac-addr mac-address ] [ port port-n um ] [ user username ] [ level level ] mac-addr mac-address — T races a MAC address. Spec ify a MAC address, using colons to separate the octets (for example, 00:11:22:aa:bb:cc).
498 C HAPTER 19: T RACE C OMMANDS.
20 S YSTEM L OG C OMMANDS Use the system log commands to recor d information for monitoring and troubleshooting. MSS system logs are based on RFC 3164, which defines the log protocol. Commands by Usage This chapter pr esent system log commands alphabetically .
500 C HAPTER 20: S YSTEM L OG C OMMANDS Access — Enabled. History — Introduced in MSS V ersion 3.0. Examples — T o stop sending system logging messages to a server at 192.168.253.11, type the following command: WX4400# clear log server 192.168.253 .
display log buffer 50 1 severity severity-level — Displays messages at a severity level greater than or equal to the leve l specified. Specify one of the following: emergency — The WX switch is unusable. alert — Action must be taken immediatel y .
502 C HAPTER 20: S YSTEM L OG C OMMANDS See Also clear log on page 499 display log config on page 502 display log config Displays log configur ation information. Syntax — display log config Defaults — None. Access — Enabled. History — Introduced in MSS V ersion 3.
display log trace 503 display log trace Displays system information sto r ed in the nonvolatile log buf fer or the trace buffer . Syntax — display log trace [{ + | - | / } number- of-messages ] [ facility facility-name ] [ matching s tring ] [ severity severity-level ] trace — Displays the log messa ges in the trace buffer .
504 C HAPTER 20: S YSTEM L OG C OMMANDS Defaults — None. Access — Enabled. History — Introduced in MSS V ersion 3.0. Examples — T ype the following command to see the facilities for which you .
set log 505 Logging state (enabled or disabled) T o override the session defaults for an individual session, type the set log command from within the session and use the current opt ion.
506 C HAPTER 20: S YSTEM L OG C OMMANDS disable — Disables messages to the specified target. Defaults — The following a re defaults for the set log commands. Events at the error level and higher are logged to the WX console. Events at the error level and higher are logged to the WX system buffer .
set log trace mbyte s 507 Examples — The following co mmand incr ea ses the trace buffer size to 4M B : WX4400# set log trace mbytes 4 success: change accepted.
508 C HAPTER 20: S YSTEM L OG C OMMANDS.
21 B OOT P RO M P T C OMMANDS Boot prompt commands enable you to perform basic tasks, including booting a system image file, from the boot prompt (boot>). A CLI session enters the bo ot pr ompt if MSS does no t boot successfully or you intentionally interrupt the boot process.
510 C HAPTER 21: B OOT P ROMPT C OMMANDS autoboot Displays or changes the state of the aut oboot option. The autoboot option controls whether a WX switch automat ically boots a system image after initializing the hardwar e, followi ng a system reset or power cycle.
boot 511 boot Loads and executes a system image file. Syntax — boot [ BT= type ] [ DEV= device ] [ FN= fi lename ] [ HA= ip-addr ] [ FL= num ] [ OPT= option ] [ OPT+= option ] BT= type — Boot type: c — Compact flash. Boots using nonvol atile storage or a flash card.
512 C HAPTER 21: B OOT P ROMPT C OMMANDS Usage — If you use an optional para meter , t he para meter setting overrides the setting of the same pa rameter in the currently active boot profile. However , the boot profile itself is not changed. T o display the currently active boot profile, use the display command.
change 513 change Changes parameters in the currently active boot profile. (For information about boot profiles, see display on page 517.) Syntax — change Defaults — The default boot type is c (compa ct flash) .
514 C HAPTER 21: B OOT P ROMPT C OMMANDS delete on page 515 display on page 517 next on page 521 create Cr eates a new boot pr ofile. (For information about boot profiles, see display on page 517.) Syntax — create Defaults — The new boot pr ofile has the same settings as the curr ently active boot profile by default.
delete 515 display on page 517 next on page 521 delete Removes the currently active boot pr ofile. (For information about boot profiles, see display on page 517.) Syntax — delete Defaults — None. Access — Boot prompt. History —Introduced in MSS V ersion 3.
516 C HAPTER 21: B OOT P ROMPT C OMMANDS diag Accesses the dia gnostic mode. Syntax — diag Defaults — The diagnostic mode is disabled by default. Access — Boot prompt. History —Introduced in MSS V ersion 3.0. Usage — Access to the diagnostic mode requir es a password, which is not user configurable.
display 517 WXA30001.Rel 8863722 bytes Internal Compact Flash Directory ( Secondary): WXA30001.Rel 8862885 bytes See Also fver on page 519 version on page 524 display Displays the curr ently active boot pr ofile. A boot profile is a set of parameters that a WX switch uses to control the boot process.
518 C HAPTER 21: B OOT P ROMPT C OMMANDS BOOT TYPE: c DEVICE: boot1: FILENAME: default FLAGS: 00000000 OPTIONS: run=nos;boot=0 T ab le 98 describes the fields in the display .
fver 519 fver Displays the version of a system image file installed in a specific location on a WX switch. Syntax — fver { c: | d: | e: | f: | boot0: | boot1: } [ filename ] c: — Nonvolatile storage ar ea containing boot partition 0 (primary).
520 C HAPTER 21: B OOT P ROMPT C OMMANDS help Displays a list of all the boot prompt commands or detailed information for an individual command. Syntax — help [ command-name ] command-name — Boot pr ompt command. Defaults — None. Access — Boot prompt.
next 521 Usage — T o display help for an indivi dual command, type help followed by the command name (for example, help boot ). Examples — T o display a list of the commands available at the boot prompt, type the following command: boot> ls ls Display a list of all commands and descriptions.
522 C HAPTER 21: B OOT P ROMPT C OMMANDS Examples — T o activate the boot profile in the next slot and display the profile, type the following command: boot> next BOOT Index: 0 BOOT TYPE: c DEVIC.
test 523 3Com WX-4400 Bootstrap/Bootloade r Version 3.0.2 Re lease Compiled on Wed Sep 22 09:18:47 PDT 2004 by Bootstrap 0 version: 3.1 Active Bootloader 0 version: 3. 0.2 Active Bootstrap 1 version: 3.1 Bootloader 1 version: 3. 0.1 WX-4400 Board Revision: 2.
524 C HAPTER 21: B OOT P ROMPT C OMMANDS Examples — The following command displays the current setting of the poweron test flag: boot> test The diagnostic execution flag is not set. See Also boot on page 511 version Displays version informatio n for a WX switch’ s hardwar e and boot code.
version 525 See Also dir on page 516 fver on page 519.
526 C HAPTER 21: B OOT P ROMPT C OMMANDS.
A O BTAINING S UPPORT FOR YOUR P R ODUCT Register Y our Product W arranty and other service benefits start from the date of purchase, so it is important to register your product quickly to ensure you get full use of the warranty and other service benefits available to you.
528 A PPENDIX A: O BTAINING S UPPORT FOR YOUR P RODUCT T roubleshoot Online Y ou will find support tools posted on the 3Com web site at http://www.3com.com/ 3Com Knowledgebase helps you troubleshoot 3Com products. This query-based interactive tool is located at http://knowledgebase.
Contact Us 529 T o sen d a pr oduct dire ctly to 3Com for repair , you must first obt ain a return authorization number (RMA). Pr oducts sent to 3Com, without authorization numbers clearly marked on the outside of the package, will be returned to the sender unopened, at the sender’ s expense.
530 A PPENDIX A: O BTAINING S UPPORT FOR YOUR P RODUCT Austria Belgium Denmark Finland France Germany Hungary Ireland Israel Italy 01 7956 7124 070 700 770 7010 7289 01080 2783 0825 809 622 01805 404 747 06800 12813 1407 3387 1800 945 379 4 199 161346 Luxembourg Netherlands Norway Poland Portugal South Africa Spain Sweden Switzerland U.
I NDEX A autoboot 510 B boot 511 C change 513 clear {ap | dap} radio 234 clear accounting 165 clear authentication admin 166 clear authentication console 167 clear authentication dot1x 168 clear authe.
532 I NDEX clear usergroup 178 clear usergroup attr 179 clear vlan 91 commit security acl 37 3 copy 472 create 514 crypto certificate 395 crypto certificate admin 395 crypto certificate eap 395 crypto.
I NDEX 533 display timezone 131 display trace 493 display tunnel 99 display version 480 display vlan config 100 F fver 519 H help 45, 520 history 46 hit-sample-rate 382 L load config 482 ls 520 M mkdi.
534 I NDEX set ip https server 140 set ip r oute 140 set ip snmp server 142 set ip s sh 143 set ip ssh absolute-timeout 144 set ip ssh id le-timeout 145 set ip ssh server 145 set ip telnet 146 set ip .
I NDEX 535 set spantree maxage 339 set spantree portcost 340 set spantree portfast 341 set spantree portpri 342 set spantree portvlancost 343 set spantree portvlanpri 344 set spantree priority 344 set.
536 I NDEX.
Un point important après l'achat de l'appareil (ou même avant l'achat) est de lire le manuel d'utilisation. Nous devons le faire pour quelques raisons simples:
Si vous n'avez pas encore acheté 3Com 3CRWX440095A c'est un bon moment pour vous familiariser avec les données de base sur le produit. Consulter d'abord les pages initiales du manuel d'utilisation, que vous trouverez ci-dessus. Vous devriez y trouver les données techniques les plus importants du 3Com 3CRWX440095A - de cette manière, vous pouvez vérifier si l'équipement répond à vos besoins. Explorant les pages suivantes du manuel d'utilisation 3Com 3CRWX440095A, vous apprendrez toutes les caractéristiques du produit et des informations sur son fonctionnement. Les informations sur le 3Com 3CRWX440095A va certainement vous aider à prendre une décision concernant l'achat.
Dans une situation où vous avez déjà le 3Com 3CRWX440095A, mais vous avez pas encore lu le manuel d'utilisation, vous devez le faire pour les raisons décrites ci-dessus,. Vous saurez alors si vous avez correctement utilisé les fonctions disponibles, et si vous avez commis des erreurs qui peuvent réduire la durée de vie du 3Com 3CRWX440095A.
Cependant, l'un des rôles les plus importants pour l'utilisateur joués par les manuels d'utilisateur est d'aider à résoudre les problèmes concernant le 3Com 3CRWX440095A. Presque toujours, vous y trouverez Troubleshooting, soit les pannes et les défaillances les plus fréquentes de l'apparei 3Com 3CRWX440095A ainsi que les instructions sur la façon de les résoudre. Même si vous ne parvenez pas à résoudre le problème, le manuel d‘utilisation va vous montrer le chemin d'une nouvelle procédure – le contact avec le centre de service à la clientèle ou le service le plus proche.