3com WXR100 3CRWXR10095A Manuel d'utilisateur

Naviguer en ligne ou télécharger Manuel d'utilisateur pour Accessoires pour ordinateurs 3com WXR100 3CRWXR10095A. 3Com WXR100 3CRWXR10095A User Manual Manuel d'utilisatio

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 800
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 0
http://www.3Com.com/
Part No. 10015910 Rev AC
Published July 2008
Wireless LAN Mobility System
Wireless LAN Switch and Controller
Command Reference
WX4400 3CRWX440095A
WX2200 3CRWX220095A
WX1200 3CRWX120695A
WXR100 3CRWXR10095A
Vue de la page 0
1 2 3 4 5 6 ... 799 800

Résumé du contenu

Page 1 - Command Reference

http://www.3Com.com/Part No. 10015910 Rev ACPublished July 2008Wireless LAN Mobility SystemWireless LAN Switch and ControllerCommand ReferenceWX4400 3

Page 2 - 01752-3064

set snmp notify profile 235set snmp notify target 240SNMPv3 with Informs 240SNMPv3 with Traps 241SNMPv2c with Informs 242SNMPv2c with Traps 243SNMPv1

Page 3 - CONTENTS

100 CHAPTER 3: SYSTEM SERVICE COMMANDSSee Also clear history on page 91quickstart Runs a script that interactively helps you configure a new switch.(

Page 4

set auto-config 101When the 3WXM server in the corporate network receives the configuration request, the server looks in the currently open network pl

Page 5 - 2 ACCESS COMMANDS

102 CHAPTER 3: SYSTEM SERVICE COMMANDSExamples — The following commands stage a WX switch to use the auto-config option. The network where the switch

Page 6 - 4 PORT COMMANDS

set banner acknowledge 103 message — Up to 32 alphanumeric characters, but not the delimiting character.Defaults — None.Access — Enabled.History —

Page 7 - 5 VLAN COMMANDS

104 CHAPTER 3: SYSTEM SERVICE COMMANDSset banner motd Configures the banner string that is displayed before the beginning of each login prompt for eac

Page 8 - 7 IP SERVICES COMMANDS

set confirm 105set confirm Enables or disables the display of confirmation messages for commands that might have a large impact on the network. Syntax

Page 9

106 CHAPTER 3: SYSTEM SERVICE COMMANDSHistory — Introduced in MSS Version 3.0.Usage — Use this command if the output of a CLI command is greater than

Page 10 - 8 AAA COMMANDS

set prompt 10748 ports are enabledsuccess: license was installedThe additional ports refers to the number of additional MAPs the switch can boot and a

Page 11 - 9 MOBILITY DOMAIN COMMANDS

108 CHAPTER 3: SYSTEM SERVICE COMMANDS display config on page 723 set system name on page 116set system contact Stores a contact name for the WX swi

Page 12 - 10 NETWORK DOMAIN COMMANDS

set system countrycode 109set system countrycodeDefines the country-specific IEEE 802.11 regulations to enforce on the WX switch. Syntax — set system

Page 13

clear usergroup 275clear usergroup attr 276display aaa 277display accounting statistics 280display location policy 282display mobility-profile 283set

Page 14

110 CHAPTER 3: SYSTEM SERVICE COMMANDSEgypt EG Estonia EE Finland FI France FR Germany DE Greece GR Guatemala GT Honduras HN Hong Kong HK Hungary HU I

Page 15

set system countrycode 111Mexico MX Morocco MA Namibia NA Netherlands NL New Zealand NZ Nigeria NG Norway NO Oman OM Pakistan PK Panama PA Paraguay PY

Page 16 - 12 STP COMMANDS

112 CHAPTER 3: SYSTEM SERVICE COMMANDSDefaults — The factory default country code is None.Access — Enabled.History — Introduced in MSS Version 3.0.Usa

Page 17 - 14 SECURITY ACL COMMANDS

set system idle-timeout 113set system idle-timeoutSpecifies the maximum number of seconds a CLI management session with the switch can remain idle bef

Page 18 - 15 CRYPTOGRAPHY COMMANDS

114 CHAPTER 3: SYSTEM SERVICE COMMANDSset system ip-addressSets the system IP address so that it can be used by various services in the WX switch. CAU

Page 19 - 17 802.1X MANAGEMENT COMMANDS

set system location 115set system location Stores location information for the WX switch.Syntax — set system location string string — Alphanumeric st

Page 20 - 20 FILE MANAGEMENT COMMANDS

116 CHAPTER 3: SYSTEM SERVICE COMMANDSset system name Changes the name of the WX switch from the default system name and also provides content for the

Page 21 - 22 SNOOP COMMANDS

4PORT COMMANDSUse port commands to configure and manage individual ports and load-sharing port groups. Commands by UsageThis chapter presents port com

Page 22 - 24 BOOT PROMPT COMMANDS

118 CHAPTER 4: PORT COMMANDSclear ap Removes a Distributed MAP. CAUTION: When you clear a Distributed MAP, MSS ends user sessions that are using the M

Page 23 - Contact Us 788

clear port counters 119clear port counters Clears port statistics counters and resets them to 0. Syntax — clear port countersDefaults — None.Access —

Page 24

display mobility-domain config 330display mobility-domain status 331set mobility-domain member 332set mobility-domain mode member secondary seed-ip 33

Page 25 - ABOUT THIS GUIDE

120 CHAPTER 4: PORT COMMANDSclear port media-typeDisables the copper interface and reenables the fiber interface on an WX4400 gigabit Ethernet port.Sy

Page 26 - Table 2 Text Conventions

clear port mirror 121Examples — The following command clears the names of ports 1 through 3:WX4400# clear port 1-3 nameSee Also display port status o

Page 27 - Comments

122 CHAPTER 4: PORT COMMANDSHistory — Introduced in MSS Version 3.0.Usage — This command applies only to the WX4400. This command does not affect a li

Page 28 - 28 ABOUT THIS GUIDE

display port counters 123Examples — The following command clears port 5:WX1200# clear port type 5This may disrupt currently authenticated users. Are y

Page 29 - NEW FEATURES SUMMARY

124 CHAPTER 4: PORT COMMANDS receive-etherstats — Shows Ethernet statistics for received packets. transmit-etherstats — Shows Ethernet statistics fo

Page 30 - Configuration

display port mirror 125Examples — The following command displays the configuration of port group server2:WX1200# display port-group name server2Port g

Page 31 - 802.11n

126 CHAPTER 4: PORT COMMANDSSee Also display port mirror on page 125 set port mirror on page 140display port poe Displays status information for por

Page 32 - EW FEATURES SUMMARY

display port status 127See Also set port poe on page 142display port status Displays configuration and status information for ports.Syntax — display

Page 33 - Portal Support

128 CHAPTER 4: PORT COMMANDSExamples — The following command displays information for all ports on a WX1200 switch:WX1200# display port statusPort Na

Page 34 - Extensions

display port media-type 129See Also clear port type on page 122 set port on page 137 set port name on page 141 set port negotiation on page 141 s

Page 35

display ap vlan 385display auto-tune attributes 386display auto-tune neighbors 388display ap boot-configuration 390display ap connection 391display ap

Page 36 - Authentication

130 CHAPTER 4: PORT COMMANDSExamples — The following command displays the enabled interface types on all four ports of a WX4400 switch:WX4400# display

Page 37 - Enhancements

monitor port counters 131 transmit-etherstats — Displays Ethernet statistics for transmitted packets first.Defaults — All types of statistics are dis

Page 38 - Location Policy

132 CHAPTER 4: PORT COMMANDSFor error reporting, the cyclic redundancy check (CRC) errors include misalignment errors. Jumbo packets with valid CRCs a

Page 39

monitor port counters 133packets Rx Unicast Number of unicast packets received. This number does not include packets that contain errors.Rx NonUnicast

Page 40 - Management

134 CHAPTER 4: PORT COMMANDSSee Also display port counters on page 123collisions Single Coll Total number of frames transmitted that experienced one

Page 41

reset port 135reset port Resets a port by toggling its link state and Power over Ethernet (PoE) state. Syntax — reset port port-list port-list — List

Page 42

136 CHAPTER 4: PORT COMMANDS ap-number — Number for the Distributed MAP. The range of valid connection numbers depends on the WX switch model: For a

Page 43 - RF Scanning

set port 137 clear port type on page 122 set port type ap on page 145 set system countrycode on page 109set port Administratively disables or reena

Page 44 - RF Detection

138 CHAPTER 4: PORT COMMANDSset port-group Configures a load-sharing port group. All ports in the group function as a single logical link.Syntax — set

Page 45

set port media-type 139See Also clear port-group on page 119 display port-group on page 124set port media-type Disables the fiber interface and enab

Page 46

set ap radio channel 435set ap radio link-calibration 436set ap radio load balancing 437set ap radio load balancing group 438set ap radio mode 439set

Page 47

140 CHAPTER 4: PORT COMMANDSset port mirror Configures port mirroring. Port mirroring is a troubleshooting feature that copies (mirrors) traffic sent

Page 48 - Replacements

set port name 141set port name Assigns a name to a port. After naming a port, you can use the port name or number in other CLI commands.Syntax — set p

Page 49

142 CHAPTER 4: PORT COMMANDSAccess — Enabled.History — Introduced in MSS Version 3.0.Usage — WX1200 10/100 Ethernet ports support half-duplex and full

Page 50

set port speed 143History — Introduced in MSS Version 3.0.Usage — This command does not apply to any gigabit Ethernet ports or to ports 7 and 8 on the

Page 51

144 CHAPTER 4: PORT COMMANDSUsage — 3Com recommends that you do not configure the mode of a WX port so that one side of the link is set to autonegotia

Page 52

set port type ap 145See Also set ip snmp server on page 228 set snmp community on page 233set port type ap Configures an WX switch port for a MAP ac

Page 53

146 CHAPTER 4: PORT COMMANDSMAP access point models AP2750, MAP-241, and MAP-341 have a single radio that can be configured for 802.11a or 802.11b/g.

Page 54

set port type ap 147This command does not apply to any gigabit Ethernet ports or to ports 7 and 8 on the WX1200 switch or port 3 on the WX2200 switch.

Page 55

148 CHAPTER 4: PORT COMMANDSSee Also clear ap on page 118 clear port type on page 122 set ap radio antennatype on page 431 set ap on page 135 set

Page 56

set port type wired-auth 149Usage — You cannot set a port’s type if the port is a member of a port VLAN. To remove a port from a VLAN, use the clear v

Page 57

set radio-profile wmm 478set radio-profile wmm-powersave 478set service-profile attr 479set service-profile auth-dot1x 481set service-profile auth-fal

Page 58

150 CHAPTER 4: PORT COMMANDSExamples — The following command sets port 2 for a wired authentication user:WX1200# set port type wired-auth 2success: ch

Page 59

5VLAN COMMANDSUse virtual LAN (VLAN) commands to configure and manage parameters for individual port VLANs on network ports, and to display informatio

Page 60

152 CHAPTER 5: VLAN COMMANDSclear fdb Deletes an entry from the forwarding database (FDB). Syntax — clear fdb {perm | static | dynamic | port port-lis

Page 61 -  A number - for example, 1

clear security L2-restrict 153History —Introduced in MSS Version 3.0.Usage — You can delete forwarding database entries based on entry type, port, or

Page 62

154 CHAPTER 5: VLAN COMMANDSAccess — Enabled.History —Introduced in MSS Version 4.1.Usage — If you clear all MAC addresses, Layer 2 forwarding is no l

Page 63

clear vlan 155Examples — The following command clears Layer 2 forwarding restriction statistics for VLAN abc_air:WX4400# clear security L2-restrict co

Page 64 - Output example:

156 CHAPTER 5: VLAN COMMANDSExamples — The following command removes port 1 from VLAN green:WX4400# clear vlan green port 1This may disrupt user conne

Page 65

display fdb 157If a VLAN profile is changed so that traffic that had been tunneled to an VX switch is now locally switched by MAPs, or vice-versa, the

Page 66

158 CHAPTER 5: VLAN COMMANDS dynamic — Displays dynamic entries. A dynamic entry is automatically removed through aging or after a reboot, reset, or

Page 67

display fdb agingtime 159Table 21 describes the fields in the display fdb output.See Also clear fdb on page 152 set fdb on page 169display fdb aging

Page 68

set service-profile tkip-mc-time 514set service-profile static-cos 515set service-profile transmit-rates 516set service-profile use-client-dscp 518set

Page 69

160 CHAPTER 5: VLAN COMMANDSVLAN 2 aging time = 600 secVLAN 1 aging time = 300 secBecause the forwarding database aging timeout period can be configur

Page 70

display roaming station 161display roaming stationShows a list of the stations roaming to the wireless LAN switch through a VLAN tunnel.Syntax — displ

Page 71

162 CHAPTER 5: VLAN COMMANDSSee Also display roaming vlan on page 163State State of the session: Setup — Station is attempting to roam to this WX sw

Page 72

display roaming vlan 163display roaming vlanShows all VLANs in the mobility domain, the WX switches servicing the VLANs, and their tunnel affinity val

Page 73

164 CHAPTER 5: VLAN COMMANDSdisplay security L2-restrictDisplays configuration information and statistics for Layer 2 forwarding restriction.Syntax —

Page 74 - 74 NEW FEATURES SUMMARY

display tunnel 165See Also clear security L2-restrict on page 153 clear security L2-restrict counters on page 154 set security L2-restrict on page

Page 75 - USING THE COMMAND-LINE

166 CHAPTER 5: VLAN COMMANDSSee Also display vlan config on page 166display vlan config Shows VLAN information. Syntax — display vlan config [vlan-id

Page 76

display vlan config 167Table 26 describes the fields in this display.See Also clear security L2-restrict on page 153 set security L2-restrict on pag

Page 77 - CLI Conventions 77

168 CHAPTER 5: VLAN COMMANDSdisplay vlan-profile Displays the contents of the VLAN profiles configured on the WX switch. A VLAN profile lists the VLAN

Page 78

set fdb 169set fdb Adds a permanent or static entry to the forwarding database.Syntax — set fdb {perm | static}mac-addr port port-list vlan vlan-id [t

Page 79 - Table 4 User Globs

set spantree portpri 555set spantree portvlancost 556set spantree portvlanpri 557set spantree priority 558set spantree uplinkfast 55813 IGMP SNOOPING

Page 80 - WX1200# set port enable 6

170 CHAPTER 5: VLAN COMMANDSSee Also clear fdb on page 152 display fdb on page 157set fdb agingtime Changes the aging timeout period for dynamic ent

Page 81 - Command-Line

set security L2-restrict 171set security L2-restrictRestricts Layer 2 forwarding between clients in the same VLAN. When you restrict Layer 2 forwardin

Page 82

172 CHAPTER 5: VLAN COMMANDSset vlan name Creates a VLAN and assigns a number and name to it. Syntax — set vlan vlan-num name name vlan-num — VLAN nu

Page 83

set vlan port 173set vlan port Assigns one or more network ports to a VLAN. You also can add a virtual port to each network port by adding a tag value

Page 84 - Descriptions

174 CHAPTER 5: VLAN COMMANDSset vlan tunnel-affinityChanges a wireless LAN switch’s preferability within a mobility domain for tunneling user traffic

Page 85 - ACCESS COMMANDS

set vlan profile 175set vlan profile Configures entries in a VLAN profile that can be applied to an MAP for local switching.Syntax — set vlan-profile

Page 86 - HAPTER 2: ACCESS COMMANDS

176 CHAPTER 5: VLAN COMMANDS

Page 87 -  enable on page 86

6QUALITY OF SERVICE COMMANDSUse Quality of Service (QoS) commands to configure packet prioritization in MSS. Packet prioritization ensures that WX swi

Page 88 - 88 CHAPTER 2: ACCESS COMMANDS

178 CHAPTER 6: QUALITY OF SERVICE COMMANDS Classify inbound packets by mapping their DSCP values to one of eight internal QoS values Classify outbou

Page 89 - SYSTEM SERVICE COMMANDS

set qos cos-to-dscp-map 179set qos cos-to-dscp-mapChanges the value to which MSS maps an internal QoS value when marking outbound packets. Syntax — se

Page 90 -  quickstart on page 100

display security acl resource-usage 595rollback security acl 599set security acl 600set security acl map 605set security acl hit-sample-rate 60715 CRY

Page 91 -  history on page 99

180 CHAPTER 6: QUALITY OF SERVICE COMMANDSset qos dscp-to-cos-mapChanges the internal QoS value to which MSS maps a packet’s DSCP value when classifyi

Page 92

display qos 181display qos Displays the switch’s QoS settings.Syntax — display qos [default] default — Displays the default mappings.Defaults — None.

Page 93

182 CHAPTER 6: QUALITY OF SERVICE COMMANDSdisplay qos dscp-tableDisplays a table that maps Differentiated Services Code Point (DSCP) values to their e

Page 94

7IP SERVICES COMMANDSUse IP services commands to configure and manage IP interfaces, management services, the Domain Name Service (DNS), Network Time

Page 95 - WX4400# display load

184 CHAPTER 7: IP SERVICES COMMANDSHTTPS Management set ip https server on page 225display ip https on page 203DNS set ip dns on page 223set ip dns do

Page 96

clear interface 185clear interface Removes an IP interface.Syntax — clear interface vlan-id ip vlan-id — VLAN name or numberDefaults — None.Access —

Page 97

186 CHAPTER 7: IP SERVICES COMMANDS Topology reporting for dual-homed MAP access points Default source IP address used in unsolicited communications

Page 98

clear ip dns domain 187clear ip dns domain Removes the default DNS domain name.Syntax — clear ip dns domainDefaults — None.Access — Enabled. History —

Page 99 -  Using CLI Help on page 83

188 CHAPTER 7: IP SERVICES COMMANDSSee Also clear ip dns domain on page 187 display ip dns on page 202 set ip dns on page 223 set ip dns domain on

Page 100 -  clear history on page 91

clear ip telnet 189clear ip telnet Resets the Telnet server TCP port number to its default value. A WX listens for Telnet management traffic on the Te

Page 101 -  Gateway address

17 802.1X MANAGEMENT COMMANDSCommands by Usage 641clear dot1x bonded-period 642clear dot1x max-req 643clear dot1x port-control 643clear dot1x quiet-pe

Page 102

190 CHAPTER 7: IP SERVICES COMMANDSExamples — The following command removes NTP server 192.168.40.240 from a WX switch configuration:WX4400# clear ntp

Page 103 -  set banner motd on page 104

clear snmp community 191clear snmp communityClears an SNMP community string.Syntax — clear snmp community name comm-string comm-string — Name of the

Page 104

192 CHAPTER 7: IP SERVICES COMMANDSSee Also set snmp notify profile on page 235 display snmp notify profile on page 210clear snmp notify targetClear

Page 105

clear summertime 193Examples — The following command clears SNMPv3 user snmpmgr1:WX1200# clear snmp usm snmpmgr1success: change accepted.See Also set

Page 106

194 CHAPTER 7: IP SERVICES COMMANDSclear system ip-addressClears the system IP address.CAUTION: Clearing the system IP address disrupts the system tas

Page 107 -  clear prompt on page 91

display arp 195Examples — To return the WX real-time clock to UTC, type the following command:WX4400# clear timezonesuccess: change accepted.See Also

Page 108

196 CHAPTER 7: IP SERVICES COMMANDSTable 30 describes the fields in this display.See Also set arp on page 216 set arp agingtime on page 217display d

Page 109 - Table 9 Country Codes

display dhcp-client 197Examples — The following command displays DHCP client information:WX1200# display dhcp-clientInterface: corpvlan(4)

Page 110

198 CHAPTER 7: IP SERVICES COMMANDSdisplay dhcp-server Displays MSS DHCP server information.Syntax — display dhcp-server [interface vlan-id] [verbose]

Page 111

display dhcp-server 199 Default Gateway: 10.10.20.1 DNS Servers: 10.10.20.4 10.10.20.5 DNS Domain Name: mycorp.comTable 32 and Table 33 d

Page 112 -  display config on page 723

3Com Corporation350 Campus DriveMarlborough, MA USA 01752-3064Copyright © 2007, 3Com Corporation. All rights reserved. No part of this documentation m

Page 113 -  display system on page 95

19 RF DETECTION COMMANDSCommands by Usage 677clear rfdetect attack-list 678clear rfdetect black-list 679clear rfdetect ignore 679clear rfdetect ssid-l

Page 114 -  set interface on page 218

200 CHAPTER 7: IP SERVICES COMMANDSSee Also set interface dhcp-server on page 220display interface Displays the IP interfaces configured on the WX.Sy

Page 115 -  set system name on page 116

display ip alias 201See Also clear interface on page 185 set interface on page 218 set interface dhcp-client on page 219display ip alias Displays t

Page 116

202 CHAPTER 7: IP SERVICES COMMANDSTable 35 describes the fields in this display.See Also clear ip alias on page 186 set ip alias on page 222display

Page 117 - PORT COMMANDS

display ip https 203See Also clear ip dns domain on page 187 clear ip dns server on page 187 set ip dns on page 223 set ip dns domain on page 223

Page 118 - HAPTER 4: PORT COMMANDS

204 CHAPTER 7: IP SERVICES COMMANDSSee Also clear ip telnet on page 189 display ip telnet on page 206 set ip https server on page 225 set ip telne

Page 119 -  set port-group on page 138

display ip route 205Usage — When you add an IP interface to a VLAN that is up, MSS adds direct and local routes for the interface to the route table.

Page 120

206 CHAPTER 7: IP SERVICES COMMANDSSee Also clear ip route on page 188 display interface on page 200 display vlan config on page 166 set interface

Page 121 -  set port mirror on page 140

display ntp 207Examples — The following command shows the status and port number for the Telnet management interface to the WX switch:WX4400> displ

Page 122 - 122 CHAPTER 4: PORT COMMANDS

208 CHAPTER 7: IP SERVICES COMMANDSExamples — To display NTP information for a WX switch, type the following command:WX4400> display ntpNTP client:

Page 123

display snmp community 209See Also clear ntp server on page 189 clear summertime on page 193 clear timezone on page 194 display timezone on page 2

Page 124

copy 715delete 717dir 718install soda agent 721display boot 722display config 723display version 725load config 727md5 729mkdir 729reset system 731res

Page 125

210 CHAPTER 7: IP SERVICES COMMANDSSee Also clear snmp community on page 191 set snmp community on page 233display snmp countersDisplays SNMP statis

Page 126

display snmp status 211See Also clear snmp notify target on page 192 set snmp notify target on page 240display snmp status Displays SNMP version and

Page 127

212 CHAPTER 7: IP SERVICES COMMANDSdisplay snmp usm Displays information about SNMPv3 users.Defaults — None. Access — Enabled.History —Introduced in M

Page 128

display timedate 213 set timedate on page 252 set timezone on page 253display timedate Shows the date and time of day currently set on a WX real-tim

Page 129

214 CHAPTER 7: IP SERVICES COMMANDSExamples — To display the offset from UTC, type the following command:WX4400# display timezoneTimezone set to &apos

Page 130

ping 215Because the WX switch adds header information, the ICMP packet size is 8 bytes larger than the size you specify. source-ip ip-addr — IP addre

Page 131

216 CHAPTER 7: IP SERVICES COMMANDSset arp Adds an ARP entry to the ARP table.Syntax — set arp {permanent | static | dynamic }ip-addr mac-addr perman

Page 132

set arp agingtime 217set arp agingtime Changes the aging timeout for dynamic ARP entries.Syntax — set arp agingtime seconds seconds — Number of secon

Page 133

218 CHAPTER 7: IP SERVICES COMMANDSset interface Configures an IP interface on a VLAN.Syntax — set interface vlan-id ip {ip-addr mask | ip-addr/mask

Page 134 - See Also

set interface dhcp-client 219See Also clear interface on page 185 display interface on page 200 set interface dhcp-client on page 219set interface

Page 135 -  set port on page 137

display snoop 754display snoop info 754display snoop map 755display snoop stats 75623 SYSTEM LOG COMMANDSCommands by Usage 759clear log 759display log

Page 136

220 CHAPTER 7: IP SERVICES COMMANDSSee Also clear interface on page 185 display dhcp-client on page 196 display interface on page 200set interface

Page 137

set interface status 221Access — Enabled.History —Introduced in MSS Version 4.0.Usage — By default, all addresses except the host address of the VLAN,

Page 138

222 CHAPTER 7: IP SERVICES COMMANDSExamples — The following command disables the IP interface on VLAN mauve:WX4400# set interface mauve status downsuc

Page 139

set ip dns 223set ip dns Enables or disables DNS on a wireless LAN switch.Syntax — set ip dns {enable | disable} enable — Enables DNS. disable — Dis

Page 140 - WX4400# set port 1 observer 2

224 CHAPTER 7: IP SERVICES COMMANDSAliases take precedence over DNS. When you enter a hostname, MSS checks for an alias with that name first, before u

Page 141

set ip https server 225success: change accepted.WX1200# set ip dns server 10.10.30.69/24 secondarysuccess: change accepted.See Also clear ip dns doma

Page 142

226 CHAPTER 7: IP SERVICES COMMANDSset ip route Adds a static route to the IP route table.Syntax — set ip route {default | ip-addr mask | ip-addr/mask

Page 143

set ip route 227When you add multiple routes to the same destination, MSS groups the routes and orders them from lowest cost at the top of the group t

Page 144

228 CHAPTER 7: IP SERVICES COMMANDSset ip snmp server Enables or disables the SNMP service on the WX.Syntax — set ip snmp server {enable | disable}ena

Page 145

set ip ssh server 229See Also set ip ssh server on page 229set ip ssh server Disables or reenables the SSH server on a WX.CAUTION: If you disable the

Page 146

Purchase Extended Warranty and Professional Services 788Access Software Downloads 788Contact Us 788Telephone Technical Support and Repair 789INDEX

Page 147

230 CHAPTER 7: IP SERVICES COMMANDSDefaults — The default Telnet port number is 23.Access — Enabled.History —Introduced in MSS Version 3.0.Examples —

Page 148

set ntp 231See Also clear ip telnet on page 189 display ip https on page 203 display ip telnet on page 206 set ip https server on page 225 set ip

Page 149

232 CHAPTER 7: IP SERVICES COMMANDSset ntp server Configures a WX to use an NTP server.Syntax — set ntp server ip-addr ip-addr — IP address of the NT

Page 150 - 150 CHAPTER 4: PORT COMMANDS

set ntp update-interval 233set ntp update-intervalChanges how often a WX sends queries to the NTP servers for updates.Syntax — set ntp update-interval

Page 151 - VLAN COMMANDS

234 CHAPTER 7: IP SERVICES COMMANDS read-notify — Allows an SNMP management application using the string to get object values on the switch but not t

Page 152 - HAPTER 5: VLAN COMMANDS

set snmp notify profile 235See Also clear snmp community on page 191 set ip snmp server on page 228 set snmp notify target on page 240 set snmp no

Page 153 - L2-restrict

236 CHAPTER 7: IP SERVICES COMMANDS APTimeoutTraps—Generated when a MAP access point fails to respond to the WX switch. AuthenTraps—Generated when t

Page 154 - L2-restrict counters

set snmp notify profile 237 DAPConnectWarningTraps—Generated when a Distributed MAP whose fingerprint has not been configured in MSS establishes a ma

Page 155

238 CHAPTER 7: IP SERVICES COMMANDS RFDetectDoSPortTraps—Generated when MSS detects an associate request flood, reassociate request flood, or disasso

Page 156

set snmp notify profile 239WX1200# set snmp notify profile snmpprof_rfdetect send RFDetectAdhocUserTrapssuccess: change accepted.WX1200# set snmp noti

Page 158

240 CHAPTER 7: IP SERVICES COMMANDSSee Also clear snmp notify profile on page 191 set ip snmp server on page 228 set snmp community on page 233 se

Page 159 -  set fdb on page 169

set snmp notify target 241 username — USM username. This option is applicable only when the SNMP version is usm. If the user will send informs rather

Page 160

242 CHAPTER 7: IP SERVICES COMMANDS username — USM username. This option is applicable only when the SNMP version is usm. profile profile-name — Not

Page 161

set snmp notify target 243SNMPv2c with Traps To configure a notification target for traps from SNMPv2c, use the following command:Syntax — set snmp no

Page 162

244 CHAPTER 7: IP SERVICES COMMANDSUsage — The inform or trap option specifies whether the MSS SNMP engine expects the target to acknowledge notificat

Page 163

set snmp protocol 245set snmp protocol Enables an SNMP protocol. MSS supports SNMPv1, SNMPv2c, and SNMPv3. Syntax — set snmp protocol {v1 | v2c | usm

Page 164

246 CHAPTER 7: IP SERVICES COMMANDSset snmp security Sets the minimum level of security MSS requires for SNMP message exchanges.Syntax — set snmp secu

Page 165

set snmp usm 247 set snmp usm on page 247 display snmp status on page 211set snmp usm Creates a USM user for SNMPv3.This command does not apply to S

Page 166

248 CHAPTER 7: IP SERVICES COMMANDS notify-only—The switch can use the string to send notifications. read-write—An SNMP management application using

Page 167

set snmp usm 249Defaults — No SNMPv3 users are configured by default. When you configure an SNMPv3 user, the default access is read-only, and the defa

Page 168 - Field Description

Conventions 25ABOUT THIS GUIDEThis command reference explains Mobility System Software (MSS™) command line interface (CLI) that you enter on a 3Com WX

Page 169

250 CHAPTER 7: IP SERVICES COMMANDSset summertime Offsets the real-time clock of a WX by +1 hour and returns it to standard time for daylight savings

Page 170

set system ip-address 251Examples — To enable summertime and set the summertime time zone to PDT (Pacific Daylight Time), type the following command:W

Page 171 - 2-restrict

252 CHAPTER 7: IP SERVICES COMMANDSExamples — The following commands configure an IP interface on VLAN taupe and configure the interface to be the sys

Page 172

set timezone 253Examples — The following command sets the date to March 13, 2003 and time to 11:11:12:WX4400# set timedate date feb 29 2004 time 23:58

Page 173

254 CHAPTER 7: IP SERVICES COMMANDSExamples — To set the time zone for Pacific Standard Time (PST), type the following command:WX1200# set timezone PS

Page 174

traceroute 255Examples — In the following example, an administrator establishes a Telnet session with another device and enters a command on the remot

Page 175

256 CHAPTER 7: IP SERVICES COMMANDS dnf — Sets the Do Not Fragment bit in the ping packet to prevent the packet from being fragmented. no-dns — Prev

Page 176 - 176 CHAPTER 5: VLAN COMMANDS

traceroute 257The first row of the display indicates the target host, the maximum number of hops, and the packet size. Each numbered row displays info

Page 177 - QUALITY OF SERVICE COMMANDS

258 CHAPTER 7: IP SERVICES COMMANDS

Page 178

8AAA COMMANDSUse authentication, authorization, and accounting (AAA) commands to provide a secure network connection and a record of user activity. Lo

Page 179 -  display qos on page 181

26 ABOUT THIS GUIDEThis manual uses the following text and syntax conventions: Documentation The MSS documentation set includes the following document

Page 180

260 CHAPTER 8: AAA COMMANDSLocal Authorization for Password Usersset user on page 319clear user on page 272set user attr on page 321clear user attr on

Page 181

clear accounting 261clear accounting Removes accounting services for specified wireless users with administrative access or network access.Syntax — cl

Page 182

262 CHAPTER 8: AAA COMMANDSExamples — The following command removes accounting services for authorized network user Nin:WX4400# clear accounting dot1x

Page 183 - IP SERVICES COMMANDS

clear authentication console 263 clear authentication mac on page 265 clear authentication mac on page 265 clear authentication proxy on page 266

Page 184

264 CHAPTER 8: AAA COMMANDS clear authentication mac on page 265 clear authentication proxy on page 266 set authentication console on page 289clear

Page 185 -  Mobility domain operations

clear authentication mac 265 clear authentication proxy on page 266 display aaa on page 277 set authentication dot1x on page 291clear authenticatio

Page 186

266 CHAPTER 8: AAA COMMANDSclear authentication proxyRemoves a proxy rule for third-party AP users.Syntax — clear authentication proxy ssid ssid-name

Page 187

clear location policy 267Examples — The following command removes WebAAA for SSID research and userglob temp*@thiscorp.com: WX4400# clear authenticati

Page 188

268 CHAPTER 8: AAA COMMANDSSee Also display location policy on page 282 set location policy on page 304clear mac-user Removes a user profile from th

Page 189

clear mac-user attr 269clear mac-user attr Removes an authorization attribute from the user profile in the local database on the WX switch, for a user

Page 190

Documentation Comments 27 Wireless Switch Manager Reference ManualThis manual shows you how to plan, configure, deploy, and manage a Mobility System

Page 191

270 CHAPTER 8: AAA COMMANDSAccess — Enabled.History —Introduced in MSS Version 3.0.Usage — Removing a MAC user from a MAC user group removes the group

Page 192

clear mac-usergroup attr 271See Also clear mac-usergroup attr on page 271 display aaa on page 277 set mac-usergroup attr on page 315clear mac-userg

Page 193

272 CHAPTER 8: AAA COMMANDSclear mobility-profileRemoves a Mobility Profile entirely. Syntax — clear mobility-profile name name — Name of an existing

Page 194 -  Mobility Domain operations

clear user attr 273Examples — The following command deletes the user profile for user Nin:WX4400# clear user Ninsuccess: change accepted.See Also dis

Page 195

274 CHAPTER 8: AAA COMMANDSclear user group Removes a user with a password from membership in a user group in the local database on the WX.(To remove

Page 196

clear usergroup 275History — Introduced in MSS 6.0.Usage — If a user’s password has expired, or the user is unable to log in within the configured li

Page 197

276 CHAPTER 8: AAA COMMANDSSee Also clear usergroup attr on page 276 display aaa on page 277 set usergroup on page 323clear usergroup attr Removes

Page 198

display aaa 277display aaa Displays all current AAA settings.Syntax — display aaaDefaults — None.Access — Enabled.History —Introduced in MSS Version 3

Page 199

278 CHAPTER 8: AAA COMMANDSuser last-resort-guestssidVlan-Name = k2user last-resort-anyVlan-Name = foomac-user 01:02:03:04:05:06usergroup eastcoasters

Page 200

display aaa 279See Also set accounting {admin | console} on page 283 set authentication admin on page 287 set authentication console on page 289 s

Page 201

28 ABOUT THIS GUIDEPlease note that we can only respond to comments and questions about 3Com product documentation at this e-mail address. Questions r

Page 202 -  set ip alias on page 222

280 CHAPTER 8: AAA COMMANDSdisplay accounting statisticsDisplays the AAA accounting records for wireless users. The records are stored in the local da

Page 203

display accounting statistics 281AAA_ACCT_SVC_ATTR=2AAA_VLAN_NAME_ATTR=defaultCalling-Station-Id=00-06-25-12-06-38Nas-Port-Id=3/1Called-Station-Id=00-

Page 204

282 CHAPTER 8: AAA COMMANDSSee Also clear accounting on page 261 display aaa on page 277 set accounting {admin | console} on page 283display locati

Page 205 -  IP — MSS added the route

display mobility-profile 283display mobility-profileDisplays the named Mobility Profile. If you do not specify a Mobility Profile name, this command s

Page 206

284 CHAPTER 8: AAA COMMANDS Specify a username, use the double-asterisk wildcard character (**) to specify all usernames, or use the single-asterisk

Page 207

set accounting {dot1x | mac | web | last-resort} 285See Also clear accounting on page 261 display accounting statistics on page 280set accounting {d

Page 208 -  Disabled

286 CHAPTER 8: AAA COMMANDS start-stop — Sends accounting records at the start and end of a network session. stop-only — Sends accounting records on

Page 209

set authentication admin 287set authentication adminConfigures authentication and defines where it is performed for specified users with administrativ

Page 210

288 CHAPTER 8: AAA COMMANDSHistory —Introduced in MSS Version 3.0.The syntax descriptions for the set authentication commands are separated for clarit

Page 211

set authentication console 289 set authentication mac on page 295 set authentication web on page 302set authentication consoleConfigures authenticat

Page 212 - default

NEW FEATURES SUMMARYThis summary describes new features and commands available in Version 7.0 of the Wireless LAN Mobility System that affect this gui

Page 213 - Sun Feb 29 2004, 23:59:02 PST

290 CHAPTER 8: AAA COMMANDSDefaults — By default, authentication is deactivated for all console users, and the default authentication method in a cons

Page 214 - is -8 hours

set authentication dot1x 291 set authentication admin on page 287 set authentication dot1x on page 291 set authentication mac on page 295 set auth

Page 215

292 CHAPTER 8: AAA COMMANDSProvides mutual authentication, integrity-protected negotiation, and key exchangeRequires X.509 public key certificates on

Page 216

set authentication dot1x 293Defaults — By default, authentication is unconfigured for all clients with network access through MAP ports or wired authe

Page 217 -  telnet on page 254

294 CHAPTER 8: AAA COMMANDSIf the username does not match an authentication rule for the SSID the user is attempting to access, MSS uses the fallthru

Page 218

set authentication mac 295set authentication macConfigures authentication and defines where it is performed for specified non-802.1X users with networ

Page 219

296 CHAPTER 8: AAA COMMANDSIf you specify multiple authentication methods in the set authentication mac command, MSS applies them in the order in whic

Page 220

set authentication max-attempts 297set authentication max-attemptsSpecifies the maximum number of login attempts users can make before being locked ou

Page 221

298 CHAPTER 8: AAA COMMANDSset authentication max-attemptsSpecifies the maximum number of login attempts users can make before being locked out of the

Page 222

set authentication minimum-password-length 299set authentication minimum-password-lengthSpecifies the minimum allowable length for user passwords.Synt

Page 223

CONTENTSABOUT THIS GUIDEConventions 25Documentation 26Documentation Comments 27NEW FEATURES SUMMARYVirtual Controller Clustering Configuration 30set c

Page 224

30 NEW FEATURES SUMMARY display ap config Enhancements on page 54 display load Enhancements on page 55 display radio-profile Enhancements on page 5

Page 225

300 CHAPTER 8: AAA COMMANDSset authentication password-restrictActivates password restrictions for network and administrative users.Syntax — set auth

Page 226

set authentication proxy 301See Also clear user lockout on page 274 set authentication minimum-password-length on page 299 set authentication max-a

Page 227 -  clear ip route on page 188

302 CHAPTER 8: AAA COMMANDSSee Also clear authentication proxy on page 266 set radius proxy client on page 633 set radius proxy port on page 634set

Page 228 -  port-num — TCP port number

set authentication web 303Defaults — By default, authentication is unconfigured for all clients with network access through MAP ports or wired authent

Page 229

304 CHAPTER 8: AAA COMMANDSExamples — The following command configures a WebAAA rule in the local WX database for SSID ourcorp and userglob rnd*:WX440

Page 230

set location policy 305 inacl inacl-name — Name of an existing security ACL to apply to packets sent to the WX with attributes matching the location

Page 231

306 CHAPTER 8: AAA COMMANDSFor user-glob, specify a username, use the double-asterisk wildcard character (**) to specify all usernames, or use the sin

Page 232

set location policy 307When applying security ACLs:Use inacl inacl-name to filter traffic that enters the WX from users via a MAP access port or wired

Page 233

308 CHAPTER 8: AAA COMMANDSThe following command places all users who are authorized for SSID tempvendor_a into VLAN kiosk_1:WX1200# set location poli

Page 234

set mac-user attr 309See Also clear mac-user on page 268 display aaa on page 277set mac-user attr Assigns an authorization attribute in the local da

Page 235

AP 3950 PoE Configuration 31Syntax — set cluster preempt {enable | disable}Defaults — None.Access — Enabled.History —Introduced in MSS Version 7.0.Usa

Page 236

310 CHAPTER 8: AAA COMMANDSTable 45 Authentication Attributes for Local UsersAttribute Description Valid Value(s)encryption-type Type of encryption

Page 237

set mac-user attr 311filter-id Inbound or outbound ACL to apply to the user.If configured in the WX local database, this attribute can be an access co

Page 238

312 CHAPTER 8: AAA COMMANDSservice-type Type of access requested by the user.One of the following numbers:2—Framed; for network user access6—Administr

Page 239

set mac-user attr 313time-of-day(network access mode only)Day(s) and time(s) during which the user is permitted to log into the network. After authori

Page 240

314 CHAPTER 8: AAA COMMANDSDefaults — None.Access — Enabled.History —Introduced in MSS Version 3.0.Usage — To change the value of an attribute, enter

Page 241

set mac-usergroup attr 315You can assign attributes to individual MAC users and to MAC user groups. If attributes are configured for a MAC user and al

Page 242

316 CHAPTER 8: AAA COMMANDS attribute-name value — Name and value of an attribute used to authorize all MAC users in the group for a particular servi

Page 243

set mobility-profile 317set mobility-profile Creates a Mobility Profile and specifies the MAP access point and/or wired authentication ports on the WX

Page 244

318 CHAPTER 8: AAA COMMANDSCAUTION: When the Mobility Profile feature is enabled, a user is denied access if assigned a Mobility-Profile attribute in

Page 245

set mobility-profile mode 319set mobility-profile modeEnables or disables the Mobility Profile feature on the WX switch.CAUTION: When the Mobility Pro

Page 246

32 NEW FEATURES SUMMARYset service-profile 11n A new command to configure maximum MPDU and MSDU packet length, frame aggregation, and the short guard

Page 247

320 CHAPTER 8: AAA COMMANDS encrypted — Indicates that the password string you entered is already in its encrypted form. If you use this option, MSS

Page 248

set user attr 321set user attr Configures an authorization attribute in the local database on the WX switch for a user with a password. (To assign aut

Page 249

322 CHAPTER 8: AAA COMMANDSThe following command limits the days and times when user Student1 can access the network, to 5 p.m. to 2 a.m. every weekda

Page 250

set user group 323set user group Adds a user to a user group. The user must have a password and a profile that exists in the local database on the WX.

Page 251 - WX1200# set summertime PDT

324 CHAPTER 8: AAA COMMANDS attribute-name value — Name and value of an attribute you are using to authorize all users in the group for a particular

Page 252

set usergroup expire-password-in 325set usergroup expire-password-inSpecifies how long the passwords for the users in user group are valid before they

Page 253

326 CHAPTER 8: AAA COMMANDSset web-portal Globally enables or disables WebAAA on a WX switch.Syntax — set web-portal {enable | disable} enable — Enab

Page 254 - UTC is -8:0 hours

9MOBILITY DOMAIN COMMANDSUse Mobility Domain commands to configure and manage Mobility Domain groups.A Mobility Domain is a system of WX switches and

Page 255 -  clear sessions on page 661

328 CHAPTER 9: MOBILITY DOMAIN COMMANDSclear mobility-domainClears all Mobility Domain configuration and information from a WX , regardless of whether

Page 256

display mobility-domain 329Usage — This command has no effect if the WX member is not configured as part of a Mobility Domain or the current WX is not

Page 257 -  ping on page 214

External Captive Portal Support 33Syntax — set service-profile profile-name transmit-rates 11ng mandatory {1.0 |2.0 |5.5 |6.0 |9.0 |11.0 |12.0 |18.0 |

Page 258

330 CHAPTER 9: MOBILITY DOMAIN COMMANDSSee Also clear mobility-domain on page 328 set mobility-domain member on page 332 set mobility-domain mode m

Page 259 - AAA COMMANDS

display mobility-domain status 331display mobility-domain statusOn the seed WX, displays the Mobility Domain status and members. Syntax — display mobi

Page 260 - HAPTER 8: AAA COMMANDS

332 CHAPTER 9: MOBILITY DOMAIN COMMANDSset mobility-domain memberOn the seed WX, adds a member to the list of Mobility Domain members. If the current

Page 261

set mobility-domain mode member secondary seed-ip 333set mobility-domain mode member secondary seed-ipSets the IP address of the secondary seed WX on

Page 262

334 CHAPTER 9: MOBILITY DOMAIN COMMANDSset mobility-domain mode member seed-ipOn a nonseed WX, sets the IP address of the seed WX. This command is use

Page 263

set mobility-domain mode secondary-seed domain-name 335set mobility-domain mode secondary-seed domain-nameSets the current WX as a secondary-seed devi

Page 264

336 CHAPTER 9: MOBILITY DOMAIN COMMANDSExamples — The following command configures this WX as the secondary seed in a Mobility Domain named Pleasanto

Page 265

set domain security 337See Also clear mobility-domain member on page 328 display mobility-domain status on page 331set domain security Sets mobility

Page 266

338 CHAPTER 9: MOBILITY DOMAIN COMMANDS

Page 267

10NETWORK DOMAIN COMMANDSUse Network Domain commands to configure and manage Network Domain groups.A Network Domain is a group of geographically dispe

Page 268 - 268 CHAPTER 8: AAA COMMANDS

34 NEW FEATURES SUMMARYSimultaneous Login SupportYou can now limit the number of concurrent sessions that a user can have on the network. You can use

Page 269 -  display aaa on page 277

340 CHAPTER 10: NETWORK DOMAIN COMMANDSclear network-domainClears all Network Domain configuration and information from a WX , regardless of whether t

Page 270

clear network-domain mode 341clear network-domain modeRemoves the Network Domain seed or member configuration from the WX.Syntax — clear network-domai

Page 271

342 CHAPTER 10: NETWORK DOMAIN COMMANDSclear network-domain peerRemoves the configuration of a Network Domain peer from a WX configured as a Network D

Page 272

clear network-domain seed-ip 343clear network-domain seed-ipRemoves the specified Network Domain seed from the WX configuration. When you enter this c

Page 273

344 CHAPTER 10: NETWORK DOMAIN COMMANDSdisplay network-domainDisplays the status of Network Domain seeds and members. Syntax — display network-domainD

Page 274 - Enabled

display network-domain 345Table 50 describes the fields in the display.See Also clear network-domain on page 340 set network-domain mode member seed

Page 275 - Introduced in MSS 6.0

346 CHAPTER 10: NETWORK DOMAIN COMMANDSset network-domain mode member seed-ipSets the IP address of a Network Domain seed. This command is used for co

Page 276

set network-domain peer 347See Also clear network-domain on page 340 display network-domain on page 344set network-domain peerOn a Network Domain se

Page 277

348 CHAPTER 10: NETWORK DOMAIN COMMANDSset network-domain mode seed domain-nameCreates a Network Domain by setting the current WX as a seed device and

Page 278 - Table 43 display aaa Output

11MANAGED ACCESS POINT COMMANDSUse MAP access point commands to configure and manage MAP access points. Be sure to do the following before using the c

Page 279

Dynamic RADIUS Extensions 35Access — Enabled.History —Introduced in MSS Version 6.2.Examples — WX# set radius das-port 65539success:change acceptedcle

Page 280

350 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset ap radio auto-tune max- retransmissions on page 433set ap radio link-calibration on page 436set ap ra

Page 281 -  2 — Local WX database

MAP Access Point Commands by Usage 351set radio-profile max-tx-lifetime on page 463set radio-profile preamble-length on page 467set radio-profile rts-

Page 282

352 CHAPTER 11: MANAGED ACCESS POINT COMMANDSQoS and VoIP set radio-profile qos-mode on page 468set radio-profile wmm-powersave on page 478set service

Page 283 - {admin

MAP Access Point Commands by Usage 353set radio-profile auto-tune channel-lockdown on page 453set radio-profile auto-tune power-config on page 454set

Page 284

354 CHAPTER 11: MANAGED ACCESS POINT COMMANDSdisplay ap unconfigured on page 395display ap qos-stats on page 374display ap etherstats on page 375MAP L

Page 285 - {dot1x

clear ap local-switching vlan-profile 355clear ap local-switching vlan-profileClears the VLAN profile that had been applied to an MAP to use with loca

Page 286

356 CHAPTER 11: MANAGED ACCESS POINT COMMANDSclear ap radio Disables a MAP radio and resets it to its factory default settings.Syntax — clear ap ap-nu

Page 287

clear ap radio 357Access — EnabledHistory —Introduced in MSS Version 3.0. Version 6.0 removed the dap option for distributed MAPs.Usage — When you cle

Page 288 - 288 CHAPTER 8: AAA COMMANDS

358 CHAPTER 11: MANAGED ACCESS POINT COMMANDSclear ap boot-configurationRemoves the static IP address configuration for a Distributed MAP.Syntax — cle

Page 289

clear ap radio load-balancing group 359clear ap radio load-balancing groupRemoves a MAP radio from its load-balancing group.Syntax clear ap ap-number

Page 290 - 290 CHAPTER 8: AAA COMMANDS

36 NEW FEATURES SUMMARYset usergroup group-name attr termination-action valuewhere value is 0 or 1. This attribute supports reauthentication of all ac

Page 291

360 CHAPTER 11: MANAGED ACCESS POINT COMMANDSclear radio-profile Removes a radio profile or resets one of the profile’s parameters to its default valu

Page 292

clear service-profile 361The following commands disable the radios using radio profile rptest and remove the profile:WX4400# set radio-profile rptest

Page 293

362 CHAPTER 11: MANAGED ACCESS POINT COMMANDSAccess — Enabled.History — Introduced in MSS Version 3.0. Options added to clear SODA parameters in Versi

Page 294

display ap arp 363Examples — The following command displays ARP entries for AP 7:WX# display ap arp 7AP 7:Host HW Address VLAN State Type-------------

Page 295

364 CHAPTER 11: MANAGED ACCESS POINT COMMANDSdisplay ap config Displays global and radio-specific settings for a MAP access point.Syntax — display ap

Page 296 - 296 CHAPTER 8: AAA COMMANDS

display ap config 365Table 54 Output for display ap configField DescriptionPort WX port number to which the MAP is connected, if specified for the M

Page 297

366 CHAPTER 11: MANAGED ACCESS POINT COMMANDSSee Also display ap connection on page 391 display ap global on page 393 display ap unconfigured on pa

Page 298

display ap counters 367 set ap radio mode on page 439 set ap radio antennatype on page 431  set ap radio channel on page 435 set ap radio radio-pr

Page 299 -  set user on page 319

368 CHAPTER 11: MANAGED ACCESS POINT COMMANDSExamples — The following command shows statistics counters for Distributed MAP 7:WX1200# display ap count

Page 300

display ap counters 369Table 55 describes the fields in this display.Table 55 Output for display ap countersField DescriptionAP Distributed MAP numb

Page 301

MAC Authentication Request Format 37Usage — You can configure different authentication methods for different groups of MAC addresses by “globbing.”Exa

Page 302

370 CHAPTER 11: MANAGED ACCESS POINT COMMANDSCCMP Pkt Transfer CtTotal number of CCMP packets sent and received by the radio.Radio Recv Phy Err Ct Num

Page 303

display ap counters 371User Sessions Number of clients currently associated with the radio. Generally, this counter is equal to the number of sessions

Page 304

372 CHAPTER 11: MANAGED ACCESS POINT COMMANDSNoise Floor Received signal strength at which the MAP can no longer distinguish 802.11 packets from ambie

Page 305

display ap fdb 373See Also display sessions network on page 668display ap fdb Displays the entries in a specified AP’s forwarding database. Syntax —

Page 306 - 306 CHAPTER 8: AAA COMMANDS

374 CHAPTER 11: MANAGED ACCESS POINT COMMANDSSee Also set ap local-switching mode on page 427 set vlan profile on page 175display ap qos-stats Displ

Page 307

display ap etherstats 375Table 57 describes the fields in this display.display ap etherstatsDisplays Ethernet statistics for an Ethernet port on a MAP

Page 308

376 CHAPTER 11: MANAGED ACCESS POINT COMMANDSExamples — The following command displays Ethernet statistics for the Ethernet ports on Distributed MAP 1

Page 309 -  clear mac-user on page 268

display ap group 377display ap group Deprecated in MSS Version 6.0. To display information about RF load balancing, see “display load-balancing group”

Page 310

378 CHAPTER 11: MANAGED ACCESS POINT COMMANDSExamples — The following command mesh link information for AP 7:WX# display ap mesh-links 7AP: 7 IP-addr:

Page 311

display ap status 379See Also set ap boot-configuration mesh ssid on page 421 set service-profile mesh on page 498display ap status Displays MAP acc

Page 312

38 NEW FEATURES SUMMARYset mac-user mac-addr attr user-name valueset usergroup group-name attr user-name valueset mac-usergroup group-name attr user-n

Page 313

380 CHAPTER 11: MANAGED ACCESS POINT COMMANDSExamples — The following command displays the status of a MAP access point:WX4400# display ap status 7Dap

Page 314 - Access — Enabled

display ap status 381The following command uses the terse option to display brief information for MAPs:WX# display ap status terseTotal number of entr

Page 315

382 CHAPTER 11: MANAGED ACCESS POINT COMMANDSState State of the MAP: init — The MAP has been recognized by the WX but has not yet begun booting. boo

Page 316 - 316 CHAPTER 8: AAA COMMANDS

display ap status 383Radio 1 typeRadio 2 type802.11 type and configuration state of the radio.  The configure succeed state indicates that the MAP ha

Page 317

384 CHAPTER 11: MANAGED ACCESS POINT COMMANDSRadio 1 typeRadio 2 type(cont.) The following information appears for external antennas:External antenna

Page 318

display ap vlan 385display ap vlan Displays information about the VLANs that are either locally switched by the specified MAP or tunneled from the MAP

Page 319

386 CHAPTER 11: MANAGED ACCESS POINT COMMANDSTable 62 describes the fields in the display ap vlan output.See Also set ap local-switching mode on page

Page 320

display auto-tune attributes 387Examples — The following command displays RF attribute information for radio 1 on the directly connected MAP access po

Page 321

388 CHAPTER 11: MANAGED ACCESS POINT COMMANDSdisplay auto-tune neighborsDisplays the other 3Com radios and third-party 802.11 radios that a 3Com radio

Page 322

display auto-tune neighbors 389Examples — The following command displays neighbor information for radio 1 on the directly connected MAP access point o

Page 323

RADIUS Ping Utility 39RADIUS Ping Utility A command provides a diagnostic tool to enhance troubleshooting capabilities for RADIUS servers on the netwo

Page 324 - 324 CHAPTER 8: AAA COMMANDS

390 CHAPTER 11: MANAGED ACCESS POINT COMMANDSdisplay ap boot-configurationDisplays information about the static IP address configuration (if any) on a

Page 325

display ap connection 391display ap connectionDisplays the system IP address of the WX switch that booted a Distributed MAP. Syntax — display ap conne

Page 326

392 CHAPTER 11: MANAGED ACCESS POINT COMMANDSHistory —Introduced in MSS Version 3.0. Version 6.0 removed the dap option.Usage — The serial-id paramete

Page 327 - MOBILITY DOMAIN COMMANDS

display ap global 393See Also display ap config on page 364 display ap global on page 393 display ap unconfigured on page 395display ap global Disp

Page 328

394 CHAPTER 11: MANAGED ACCESS POINT COMMANDSExamples — The following command displays configuration information for all the Distributed MAPs configur

Page 329 -  STATE_DOWN

display ap unconfigured 395display ap unconfiguredDisplays Distributed MAPs that are physically connected to the network but that are not configured o

Page 330

396 CHAPTER 11: MANAGED ACCESS POINT COMMANDSSee Also display ap connection on page 391 display ap global on page 393display load-balancing groupDis

Page 331

display load-balancing group 397Examples — The following command displays information about the MAP radios that are in the same group as radio 1 on MA

Page 332

398 CHAPTER 11: MANAGED ACCESS POINT COMMANDSdisplay radio-profileDisplays radio profile information.Syntax — display radio-profile {name | ?} name —

Page 333

display radio-profile 399Table 70 describes the fields in this display.Table 70 Output for display radio-profileField DescriptionBeacon Interval Rat

Page 334

Bandwidth Management 40set qos profile 40set radio-profile weighted-fair-queuing 41set service-profile max-bw 42clear qos-profile 42RF Scanning Enhanc

Page 335

40 NEW FEATURES SUMMARYTo send an accounting request to the RADIUS server, use the following command:WX# radping alpha request acct-startTo stop the a

Page 336

400 CHAPTER 11: MANAGED ACCESS POINT COMMANDSSee Also set radio-profile active-scan on page 448 set radio-profile auto-tune channel-config on page 4

Page 337

display service-profile 401 set radio-profile max-tx-lifetime on page 463 set radio-profile mode on page 464 set radio-profile preamble-length on p

Page 338

402 CHAPTER 11: MANAGED ACCESS POINT COMMANDS CAC mode CAC sessions User idle timeout Idle client probing Web Portal Session Timeout Transmit ra

Page 339 - NETWORK DOMAIN COMMANDS

display service-profile 403Examples — The following command displays information for service profile spl:WX1200# display service-profile sp1ssid-name:

Page 340

404 CHAPTER 11: MANAGED ACCESS POINT COMMANDSTable 71 Output for display service-profileField Descriptionssid-name Service set identifier (SSID) man

Page 341

display service-profile 405Sygate On-Demand (SODA)Whether SODA functionality is enabled for the service profile. When SODA functionality is enabled, c

Page 342

406 CHAPTER 11: MANAGED ACCESS POINT COMMANDSCAC mode Call Admission Control mode: none—CAC is disabled. session—CAC is based on the number of activ

Page 343

display service-profile 407WEP Key 3 value State of static WEP key number 3: none — The key is not configured. preset — The key is configured.WEP Ke

Page 344

408 CHAPTER 11: MANAGED ACCESS POINT COMMANDSSee Also set service-profile auth-dot1x on page 481 set service-profile auth-fallthru on page 482 set

Page 345

display service-profile 409 set service-profile no-broadcast on page 499 set service-profile proxy-arp on page 500 set service-profile psk-phrase o

Page 346

Bandwidth Management 41[cos static-cos-value][max-bandwidth max-bw-kb][use-client-dscp enable | disable] profile-name — Name of the QoS profile. acc

Page 347

410 CHAPTER 11: MANAGED ACCESS POINT COMMANDSreset ap Restarts a MAP access point. Syntax — reset ap ap-number ap ap-number — Index value that identi

Page 348

set ap auto 411The profile uses the default radio profile by default. You can change the profile using the set ap auto radio radio-profile command. Yo

Page 349 - MANAGED ACCESS POINT

412 CHAPTER 11: MANAGED ACCESS POINT COMMANDS set ap blink on page 416 set ap group on page 427 set ap radio auto-tune max-power on page 432 set a

Page 350

set ap auto radiotype 413set ap auto radiotypeSets the radio type for single-MAP radios that use the MAP configuration profile. Syntax — set ap auto [

Page 351

414 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset ap auto mode Enables a WX profile for automatic Distributed MAP configuration.Syntax — set ap auto mo

Page 352

set ap bias 415set ap bias Changes the bias for a MAP. Bias is the priority of one WX over other WX switches for booting and configuring the MAP. Synt

Page 353

416 CHAPTER 11: MANAGED ACCESS POINT COMMANDSExamples — The following command changes the bias for a Distributed MAP to low:WX4400# set dap 1 bias low

Page 354

set ap boot- configuration ip 417set ap boot- configuration ipSpecifies static IP address information for a Distributed MAP.Syntax — set ap ap-number

Page 355

418 CHAPTER 11: MANAGED ACCESS POINT COMMANDSSee Also clear ap boot-configuration on page 358 display ap boot-configuration on page 390 set ap boot

Page 356

set ap boot-configuration mesh psk-phrase 419set ap boot-configuration mesh psk-phraseSpecifies a preshared key (PSK) phrase that a Mesh AP uses for a

Page 357

42 NEW FEATURES SUMMARYExamples — To configure weighted queuing for a radio and service profile, use the following command:WX# set radio-profile wirel

Page 358

420 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset ap boot-configuration mesh psk-rawConfigures a raw hexadecimal preshared key (PSK) to use for authent

Page 359

set ap boot-configuration mesh ssid 421set ap boot-configuration mesh ssidSpecifies the name of the SSID a Mesh AP attempts to associate with when it

Page 360

422 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset ap boot- configuration switchSpecifies the WX a Distributed MAP contacts and attempts to use as its b

Page 361

set ap boot-configuration vlan 423WX1200# set ap 1 boot- configuration switch switch-ip 172.16.0.21 mode enable success: change accepted.The following

Page 362

424 CHAPTER 11: MANAGED ACCESS POINT COMMANDSUsage — When this command is configured, all Ethernet frames emitted from the Distributed MAP are formatt

Page 363

set ap fingerprint 425 fingerprint — The 16-digit hexadecimal number of the fingerprint. Use a colon between each digit. Make sure the fingerprint yo

Page 364

426 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset ap force-image-downloadConfigures a MAP to download a software image from the WX instead of loading t

Page 365

set ap group 427set ap group Deprecated in MSS Version 6.0. To configure RF load balancing, see “set load-balancing mode” on page 446.set ap location

Page 366

428 CHAPTER 11: MANAGED ACCESS POINT COMMANDSIf local switching is enabled on an MAP, but no VLAN profile is configured, then a default VLAN profile i

Page 367

set ap name 429Examples — The following command specifies that MAP 7 use VLAN profile locals:WX# set ap 7 local-switching vlan-profile localssuccess:

Page 368 - Distributed MAP 7:

RF Scanning Enhancements 43success: change acceptedRF Scanning EnhancementsA new attribute, sentry, is now available to independently configure and co

Page 369

430 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset ap radio antenna-locationSpecifies the location (indoors or outdoors) of an external antenna. Use thi

Page 370

set ap radio antennatype 431set ap radio antennatypeSets the model number for an external antenna. Syntax — set ap ap-number radio {1|2} antennatype {

Page 371

432 CHAPTER 11: MANAGED ACCESS POINT COMMANDSDefaults — All radios use the internal antenna by default, if the MAP model has an internal antenna. The

Page 372

set ap radio auto-tune max- retransmissions 433Defaults — The default maximum power setting that RF Auto-Tuning can set on a radio is the highest sett

Page 373

434 CHAPTER 11: MANAGED ACCESS POINT COMMANDSDefaults — The default is 10 percent. Access — Enabled.History —Introduced in MSS Version 3.0. Option aut

Page 374

set ap radio channel 435A radio also can increase power, in 1 dBm increments, if a client falls below the minimum allowed data rate. After a radio inc

Page 375

436 CHAPTER 11: MANAGED ACCESS POINT COMMANDSUsage — You can configure the transmit power of a radio on the same command line. Use the tx-power option

Page 376

set ap radio load balancing 437Usage — A Mesh Portal MAP can be configured to emit link calibration packets to assist with positioning the Mesh AP. A

Page 377

438 CHAPTER 11: MANAGED ACCESS POINT COMMANDSUsage — By default, RF load balancing is enabled on all MAP radios. Use this command to disable or re-en

Page 378

set ap radio mode 439Access — Enabled.History — Introduced in MSS Version 6.0.Usage — Assigning radios to specific load balancing groups is optional.

Page 379

44 NEW FEATURES SUMMARYset radio-profilerf-scanningchannel-scopeConfigures the channel scope for RF scanning.Syntax — set radio-profile profile-name r

Page 380

440 CHAPTER 11: MANAGED ACCESS POINT COMMANDSHistory —Introduced in MSS Version 3.0. Option auto added for configuration of the MAP configuration prof

Page 381

set ap radio tx-power 441Defaults — None.Access — Enabled.History —Introduced in MSS Version 3.0. Option auto added for configuration of the MAP confi

Page 382

442 CHAPTER 11: MANAGED ACCESS POINT COMMANDScountry maximum: on an 802.11a radio, 11 dBm for channel numbers less than or equal to 64, or 10 dBm for

Page 383

set ap security 443set ap security Sets security requirements for management sessions between a WX and its Distributed MAPs. This feature applies to D

Page 384

444 CHAPTER 11: MANAGED ACCESS POINT COMMANDSExamples — The following command configures a WX to require Distributed MAPs to have encryption keys:WX44

Page 385

set band-preference 445set band-preference Configures MSS to steer clients that support both the 802.11a and 802.11b/g radio bands to a specific radio

Page 386

446 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset load-balancing modeDisables or reenables RF load balancing globally on the WXMAP.Syntax — set load-ba

Page 387

set load-balancing strictness 447set load-balancing strictnessControls the degree to which MSS balances the client load among MAPs when performing RF

Page 388

448 CHAPTER 11: MANAGED ACCESS POINT COMMANDSAt the other end of the spectrum, when max strictness is specified, if an MAP radio has reached its maxim

Page 389

set radio-profile auto-tune 11a-channel-range 449 disable — Configures radios to scan only passively for rogues by listening for beacons and probe re

Page 390 -  Field Mesh PSK

RF Detection Configuration 45Replaced Commands The following table lists pre-MSS 7.0 commands that are now obsolete and their MSS 7.0 replacements:Par

Page 391

450 CHAPTER 11: MANAGED ACCESS POINT COMMANDSExamples — The following command enables the 802.11a radio to select any available channel in the 802.11a

Page 392

set radio-profile auto-tune channel-holddown 451Examples — The following command disables dynamic channel tuning for radios in the rp2 radio profile:W

Page 393

452 CHAPTER 11: MANAGED ACCESS POINT COMMANDSExamples — The following command changes the channel holddown for radios in radio profile rp2 to 600 seco

Page 394

set radio-profile auto-tune channel-lockdown 453Examples — The following command sets the channel interval for radios in radio profile rp2 to 2700 sec

Page 395

454 CHAPTER 11: MANAGED ACCESS POINT COMMANDSExamples — The following command locks down the channel settings for radios in radio profile rp2:WX# set

Page 396

set radio-profile auto-tune power-interval 455Examples — The following command enables dynamic power tuning for radios in the rp2 radio profile:WX4400

Page 397 - MAP radios that

456 CHAPTER 11: MANAGED ACCESS POINT COMMANDSSee Also display service-profile on page 401 set ap radio auto-tune max- retransmissions on page 433 s

Page 398

set radio-profile auto-tune power-ramp-interval 457set radio-profile auto-tune power-ramp-intervalChanges the interval at which power is increased or

Page 399

458 CHAPTER 11: MANAGED ACCESS POINT COMMANDSAccess — Enabled.History —Introduced in MSS Version 3.0.Usage — You must disable all radios that are usin

Page 400

set radio-profile countermeasures 459 configured — Configures radios to attack only devices in the attack list on the WX switch (on-demand countermea

Page 401

46 NEW FEATURES SUMMARYExamples — To configure MSS to detect ad-hoc networks and classify them as rogue devices, use the following command:WX# set rfd

Page 402

460 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset radio-profile dtim-intervalChanges the number of times after every beacon that each MAP radio in a ra

Page 403

set radio-profile frag-threshold 461set radio-profile frag-thresholdChanges the fragmentation threshold for the MAP radios in a radio profile. The fra

Page 404

462 CHAPTER 11: MANAGED ACCESS POINT COMMANDSSee Also display radio-profile on page 398 set radio-profile mode on page 464 set radio-profile rts-th

Page 405

set radio-profile max-tx-lifetime 463See Also display radio-profile on page 398 set radio-profile mode on page 464 set radio-profile max-tx-lifetim

Page 406 -  none—CAC is disabled

464 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset radio-profile modeCreates a new radio profile, and disables or reenables all MAP radios that are usin

Page 407

set radio-profile mode 465Access — Enabled.History —Introduced in MSS Version 3.0.Version 4.2 made the following changes: Removed the following param

Page 408

466 CHAPTER 11: MANAGED ACCESS POINT COMMANDSTo change a parameter in a radio profile, you must first disable all the radios in the profile. After you

Page 409

set radio-profile preamble-length 467set radio-profile preamble-lengthChanges the preamble length for which an 802.11b/g MAP radio advertises support.

Page 410

468 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset radio-profile qos-modeSets the prioritization mode for forwarding queues on MAP radios managed by the

Page 411 -  set ap bias on page 415

set radio-profile rfid-mode 469set radio-profile rfid-modeEnables MAP radios managed by a radio profile to function as location receivers in an AeroSc

Page 412

RF Detection Configuration 47Examples — To configure MSS to detect devices seen on the network and classify them as rogue devices, use the following c

Page 413

470 CHAPTER 11: MANAGED ACCESS POINT COMMANDSDefaults — Data rate enforcement is disabled by default.Access — Enabled.History — Introduced in MSS Vers

Page 414

set radio-profile rts-threshold 471See Also display ap counters on page 367 set service-profile transmit-rates on page 516set radio-profile rts-thre

Page 415 -  low — Low bias

472 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset radio-profile service-profileMaps a service profile to a radio profile. All radios that use the radio

Page 416

set radio-profile service-profile 473cipher-ccmp disable Does not use Counter with Cipher Block Chaining Message Authentication Code Protocol (CCMP) t

Page 417

474 CHAPTER 11: MANAGED ACCESS POINT COMMANDSshared-key-auth disable Does not use shared-key authentication.This parameter does not enable PSK authent

Page 418

set radio-profile service-profile 475transmit-rates 802.11a:mandatory: 6.0,12.0,24.0beacon-rate: 6.0multicast-rate: autodisabled: none802.11b:mandator

Page 419

476 CHAPTER 11: MANAGED ACCESS POINT COMMANDSAccess — Enabled.History —Introduced in MSS Version 3.0.Usage — You must configure the service profile be

Page 420

set radio-profile service-profile 477 set service-profile cac-mode on page 486 set service-profile cac-session on page 487 set service-profile ciph

Page 421

478 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset radio-profile short-retryDeprecated in MSS Version 4.2. In 4.2, this parameter is associated with ser

Page 422

set service-profile attr 479Usage — U-APSD is supported only for QoS mode WMM. If WMM is not enabled on the radio profile, use the set radio-profile q

Page 423

48 NEW FEATURES SUMMARYdisplay aaa Command ReplacementsIn previous releases, the display aaa command displayed RADIUS, users, and mac-users configurat

Page 424

480 CHAPTER 11: MANAGED ACCESS POINT COMMANDSThe SSID default attributes are applied in addition to any attributes supplied for the user by the RADIUS

Page 425 -  set ap security on page 443

set service-profile auth-dot1x 481See Also display service-profile on page 401 display sessions network on page 668set service-profile auth-dot1xDis

Page 426

482 CHAPTER 11: MANAGED ACCESS POINT COMMANDSSee Also display service-profile on page 401 set service-profile auth-psk on page 483 set service-prof

Page 427

set service-profile auth-psk 483Access — Enabled.History —Introduced in MSS Version 3.0. Option for WebAAA fallthru authentication type changed from w

Page 428

484 CHAPTER 11: MANAGED ACCESS POINT COMMANDSAccess — Enabled.History —Introduced in MSS Version 3.0.Usage — This command affects authentication of WP

Page 429

set service-profile bridging 485 enable — Enables beaconing of the SSID managed by the service profile. disable — Disables beaconing of the SSID man

Page 430

486 CHAPTER 11: MANAGED ACCESS POINT COMMANDSUsage — WLAN mesh services can be used in a wireless bridge configuration, implementing MAPs as bridge en

Page 431

set service-profile cac-session 487Examples — The following command enables session-based CAC on service profile sp1:WX4400# set service-profile sp1 c

Page 432

488 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset service-profile cipher-ccmpEnables Counter with Cipher Block Chaining Message Authentication Code Pro

Page 433

set service-profile cipher-tkip 489set service-profile cipher-tkipDisables or reenables Temporal Key Integrity Protocol (TKIP) encryption in a service

Page 434

display aaa Command Replacements 49Dynamic Authordisplay user Displays summary or verbose status relating to users or users matching a glob. For user

Page 435

490 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset service-profile cipher-wep104Enables dynamic Wired Equivalent Privacy (WEP) with 104-bit keys, in a s

Page 436

set service-profile cipher-wep40 491See Also display service-profile on page 401 set service-profile cipher-ccmp on page 488 set service-profile ci

Page 437 - Disabled

492 CHAPTER 11: MANAGED ACCESS POINT COMMANDSTo support non-WPA clients that use static WEP, you must configure static WEP keys. Use the set service-p

Page 438

set service-profile dhcp-restrict 493WX4400# set service-profile sp1 cos 7success: change accepted.See Also display service-profile on page 401 set

Page 439

494 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset service-profile idle-client-probingDisables or reenables periodic keepalives from MAP radios to clien

Page 440

set service-profile keep-initial-vlan 495set service-profile keep-initial-vlanConfigures MAP radios managed by the radio profile to leave a roamed use

Page 441

496 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset service-profile load-balancing-exemptExempts a service profile from performing RF load balancing.Synt

Page 442

set service-profile long-retry-count 497set service-profile long-retry-countChanges the long retry threshold for a service profile. The long retry thr

Page 443

498 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset service-profile meshCreates a service profile for use with WLAN mesh services.Syntax — set service-pr

Page 444

set service-profile no-broadcast 499set service-profile no-broadcastDisables or reenables the no-broadcast mode. The no-broadcast mode helps reduce tr

Page 445 - 802.11a and

display service-profile Enhancements 61display rfdetect Changes 66Deprecated Commands 66display rfdetect data 66display rfdetect data ap 69display rfd

Page 446

50 NEW FEATURES SUMMARYWX# display user *john* verboseacct-interim-interval: 180User name: johnsmithStatus: enabledPassword: iforgot2(encypted)Group:

Page 447

500 CHAPTER 11: MANAGED ACCESS POINT COMMANDSExamples — The following command enables the no-broadcast mode on service profile sp1:WX4400# set service

Page 448 - 11g-only

set service-profile psk-phrase 501Examples — The following command enables proxy ARP on service profile sp1:WX4400# set service-profile sp1 proxy-arp

Page 449 - 11a-channel-range

502 CHAPTER 11: MANAGED ACCESS POINT COMMANDSExamples — The following command configures service profile sp3 to use passphrase “1234567890123<>?

Page 450 -  name — Radio profile name

set service-profile rsn-ie 503Examples — The following command configures service profile sp3 to use a raw PSK with PSK clients:WX4400# set service-pr

Page 451

504 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset service-profile shared-key-authEnables shared-key authentication, in a service profile.Use this comma

Page 452

set service-profile soda agent-directory 505 threshold — Number of times a radio can send the same short unicast frame. You can enter a value from 1

Page 453

506 CHAPTER 11: MANAGED ACCESS POINT COMMANDSExamples — The following command specifies soda-agent as the location for SODA agent files for service pr

Page 454

set service-profile soda failure-page 507When the enforce checks option is enabled, upon successful completion of the SODA agent checks, the client pe

Page 455

508 CHAPTER 11: MANAGED ACCESS POINT COMMANDSUsage — Use this command to specify a custom page to be loaded by the client when the SODA agent checks f

Page 456

set service-profile soda logout-page 509History —Introduced in MSS Version 4.2.Usage — When a client closes the SODA virtual desktop, the client is au

Page 457

display aaa Command Replacements 51display mac-user Displays summary or verbose status relating to a specific mac-user or all mac-users. WX# display m

Page 458

510 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset service-profile soda modeEnables or disables Sygate On-Demand (SODA) functionality for a service prof

Page 459

set service-profile soda remediation-acl 511set service-profile soda remediation-aclSpecifies an ACL to be applied to a client if it fails the checks

Page 460

512 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset service-profile soda success-pageSpecifies a page on the WX that loads when a client passes the secur

Page 461

set service-profile ssid-name 513See Also display service-profile on page 401 set service-profile soda enforce-checks on page 506 set service-profi

Page 462

514 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset service-profile ssid-typeSpecifies whether the SSID managed by a service profile is encrypted or unen

Page 463

set service-profile static-cos 515History —Introduced in MSS Version 3.0.Usage — Countermeasures apply only to TKIP and WEP clients. This includes WPA

Page 464

516 CHAPTER 11: MANAGED ACCESS POINT COMMANDSDefaults — Static CoS is disabled by default.Access — Enabled.History —Introduced in MSS Version 4.2.Usag

Page 465 -  short-retry

set service-profile transmit-rates 517The valid rates depend on the radio type: 11a—6.0, 9.0, 12.0, 18.0, 24.0, 36.0, 48.0, 54.0 11b—1.0, 2.0, 5.5,

Page 466

518 CHAPTER 11: MANAGED ACCESS POINT COMMANDS beacon-rate: 11a—6.0 11b—2.0 11g—2.0 multicast-rate—auto for all radio types.Access — Enabled.Histo

Page 467

set service-profile user-idle-timeout 519History —If this command is enabled in the service profile, the 802.11 QoS level is ignored, and MSS classifi

Page 468

52 NEW FEATURES SUMMARYWX# display mac-user 00:11:11:21:11* verbosedisplay usergroup Displays summary status for all user groups or verbose status for

Page 469

520 CHAPTER 11: MANAGED ACCESS POINT COMMANDSWX4400# set service-profile sp1 user-idle-timeout 360success: change accepted.See Also display service-p

Page 470

set service-profile web-portal-form 521The Web-Portal ACL applies only to users who log on using Web Portal, and applies only during authentication. A

Page 471

522 CHAPTER 11: MANAGED ACCESS POINT COMMANDSTo use WebAAA, the fallthru authentication type in the service profile that manages the SSID must be set

Page 472

set service-profile web-portal-logout logout-url 523set service-profile web-portal-logout logout-urlSpecifies the URL that is requested when the user

Page 473

524 CHAPTER 11: MANAGED ACCESS POINT COMMANDSExamples — The following command configures the Web Portal logout URL as: wifizone.3Com.com/logout.html f

Page 474

set service-profile web-portal-session-timeout 525Examples — The following command enables the Web Portal logout functionality for service profile sp

Page 475

526 CHAPTER 11: MANAGED ACCESS POINT COMMANDSNote that the Web Portal WebAAA session timeout period applies only to Web Portal WebAAA sessions already

Page 476

set service-profile wep active-unicast- index 527See Also display service-profile on page 401 set service-profile wep active-unicast- index on page

Page 477

528 CHAPTER 11: MANAGED ACCESS POINT COMMANDSset service-profile wep key-indexSets the value of one of four static Wired-Equivalent Privacy (WEP) keys

Page 478 -  disable — Disables U-APSD

set service-profile wpa-ie 529set service-profile wpa-ieEnables the WPA information element (IE) in wireless frames. The WPA IE advertises the WPA aut

Page 479

display aaa Command Replacements 53Users in this group:WX# display usergroup Guests2No users in this group.display mac-usergroup Displays summary stat

Page 480

530 CHAPTER 11: MANAGED ACCESS POINT COMMANDS

Page 481

12STP COMMANDSUse Spanning Tree Protocol (STP) commands to configure and manage spanning trees on the virtual LANs (VLANs) configured on a wireless LA

Page 482

532 CHAPTER 12: STP COMMANDSclear spantree portcostResets to the default value the cost of a network port or ports on paths to the STP root bridge in

Page 483

clear spantree portpri 533clear spantree portpriResets to the default value the priority of a network port or ports for selection as part of the path

Page 484

534 CHAPTER 12: STP COMMANDS vlan vlan-id — VLAN name or number. MSS resets the cost for only the specified VLAN. Defaults — None.Access — Enabled.Hi

Page 485

clear spantree statistics 535History —Introduced in MSS Version 3.0.Usage — MSS does not change a port’s priority for VLANs other than the one(s) you

Page 486

536 CHAPTER 12: STP COMMANDSdisplay spantree Displays STP configuration and port-state information.Syntax — display spantree [port-list | vlan vlan-id

Page 487

display spantree 5377 1 Forwarding 19 128 Disabled8 1 Disabled 19 128 Disabled9 1 Disabled 19 12

Page 488

538 CHAPTER 12: STP COMMANDSPort Port number. Only network ports are listed. STP does not apply to 3Com Wireless LAN Managed Access Point AP2750 ports

Page 489

display spantree backbonefast 539See Also display spantree blockedports on page 540display spantree backbonefastIndicates whether the STP backbone fa

Page 490

54 NEW FEATURES SUMMARYMAC users in this group:WX# display mac-usergroup AdminNo MAC users in this group. display ap config EnhancementsNew commands a

Page 491

540 CHAPTER 12: STP COMMANDSExamples — The following example shows the command output on a WX switch with backbone fast convergence enabled:WX4400# di

Page 492

display spantree portfast 541display spantree portfastDisplays STP uplink fast convergence information for all network ports or for one or more networ

Page 493

542 CHAPTER 12: STP COMMANDSdisplay spantree portvlancostShows the cost of a port on a path to the STP root bridge, for each of the port’s VLANs.Synta

Page 494

display spantree statistics 543Usage — The command displays statistics separately for each port.Examples — The following command shows STP statistics

Page 495

544 CHAPTER 12: STP COMMANDStopology change timer value 0hold timer INACTIVEhold timer value

Page 496

display spantree statistics 545Table 78 Output for display spantree statisticsField DescriptionPort Port number.VLAN VLAN ID.Spanning Tree enabled f

Page 497

546 CHAPTER 12: STP COMMANDSconfig_pending Indicates whether a configured BPDU is to be transmitted on expiration of the hold timer for the port.port_

Page 498

display spantree statistics 547hold timer Status of the hold timer. This timer ensures that configured BPDUs are not transmitted too frequently throug

Page 499

548 CHAPTER 12: STP COMMANDSSee Also clear spantree statistics on page 535display spantree uplinkfastShows uplink fast convergence information for on

Page 500

set spantree 549See Also set spantree uplinkfast on page 558set spantree Enables or disables STP on one VLAN or all VLANs configured on a WX switch.S

Page 501

display load Enhancements 55display ap config Displays all attributes of the specified AP. WX# display ap config apnumdisplay ap config radio Displays

Page 502

550 CHAPTER 12: STP COMMANDSSee Also display spantree on page 536set spantree backbonefastEnables or disables STP backbone fast convergence on a wire

Page 503

set spantree fwddelay 551set spantree fwddelayChanges the period of time after a topology change that a WX switch which is not the root bridge waits t

Page 504

552 CHAPTER 12: STP COMMANDSAccess — Enabled.History —Introduced in MSS Version 3.0.Examples — The following command changes the hello interval for al

Page 505

set spantree portcost 553set spantree portcostChanges the cost that transmission through a network port or ports in the default VLAN on a wireless LAN

Page 506

554 CHAPTER 12: STP COMMANDSSee Also clear spantree portcost on page 532 clear spantree portvlancost on page 533 display spantree on page 536 disp

Page 507

set spantree portpri 555set spantree portpri Changes the STP priority of a network port or ports for selection as part of the path to the STP root bri

Page 508

556 CHAPTER 12: STP COMMANDSset spantree portvlancostChanges the cost of a network port or ports on paths to the STP root bridge for a specific VLAN o

Page 509

set spantree portvlanpri 557set spantree portvlanpriChanges the priority of a network port or ports for selection as part of the path to the STP root

Page 510

558 CHAPTER 12: STP COMMANDSset spantree priorityChanges the STP root bridge priority of a wireless LAN switch on one or all of its VLANs.Syntax — set

Page 511

set spantree uplinkfast 559History —Introduced in MSS Version 3.0.Usage — The uplink fast convergence feature is applicable to bridges that are acting

Page 512

56 NEW FEATURES SUMMARYThe following information is displayed: System CPU loadSummary data displayed: Last second (also called instant load) Last m

Page 513

560 CHAPTER 12: STP COMMANDS

Page 514

13IGMP SNOOPING COMMANDSUse Internet Group Management Protocol (IGMP) snooping commands to configure and manage multicast traffic reduction on a WX. C

Page 515

562 CHAPTER 13: IGMP SNOOPING COMMANDSclear igmp statistics Clears IGMP statistics counters on one VLAN or all VLANs on a wireless LAN switch and rese

Page 516

display igmp 563Examples — The following command displays IGMP information for VLAN orange:WX1200# display igmp vlan orangeVLAN: orangeIGMP is enabled

Page 517

564 CHAPTER 13: IGMP SNOOPING COMMANDSTable 82 describes the fields in this display.Table 82 Output for display igmpField DescriptionVLAN VLAN name.

Page 518

display igmp 565TTL Number of seconds before this entry ages out if not refreshed. For static multicast router entries, the time-to-live (TTL) value i

Page 519 - QoS level is

566 CHAPTER 13: IGMP SNOOPING COMMANDSSee Also display igmp mrouter on page 566 display igmp querier on page 567 display igmp receiver-table on pag

Page 520 -  name—Service profile name

display igmp querier 567See Also display igmp mrouter on page 566 set igmp mrouter on page 575display igmp querierShows information about the active

Page 521

568 CHAPTER 13: IGMP SNOOPING COMMANDSHistory — Introduced in MSS Version 3.0.Examples — The following command displays querier information for VLAN o

Page 522

display igmp receiver-table 569See Also set igmp querier on page 581display igmp receiver-tableDisplays the receivers to which a WX forwards multicas

Page 523

display load Enhancements 57Last hour: 38486 KBLast day: 40708 KBLast 3 days: 40931 KBTotal system memory: 131072 KBdisplay load c

Page 524

570 CHAPTER 13: IGMP SNOOPING COMMANDSThe following command lists all receivers for multicast groups 237.255.255.1 through 237.255.255.255, in all VLA

Page 525

display igmp statistics 571display igmp statisticsShows IGMP statistics.Syntax — display igmp statistics [vlan vlan-id] vlan vlan-id — VLAN name or n

Page 526

572 CHAPTER 13: IGMP SNOOPING COMMANDSTable 86 Output of display igmp statisticsField DescriptionIGMP statistics for vlanVLAN name. Statistics are l

Page 527

set igmp 573See Also clear igmp statistics on page 562set igmp Disables or reenables IGMP snooping on one VLAN or all VLANs on a wireless LAN switch.

Page 528

574 CHAPTER 13: IGMP SNOOPING COMMANDSset igmp lmqi Changes the IGMP last member query interval timer on one VLAN or all VLANs on a wireless LAN switc

Page 529

set igmp mrouter 575set igmp mrouter Adds or removes a port in a WX’s list of ports on which it forwards traffic to multicast routers. Static multicas

Page 530

576 CHAPTER 13: IGMP SNOOPING COMMANDSset igmp mrsol Enables or disables multicast router solicitation by a WX.Syntax — set igmp mrsol {enable | disab

Page 531 - STP COMMANDS

set igmp oqi 577Usage — You cannot add MAP access ports or wired authentication ports as static multicast ports. However, MSS can dynamically add thes

Page 532 - HAPTER 12: STP COMMANDS

578 CHAPTER 13: IGMP SNOOPING COMMANDSSee Also set igmp lmqi on page 574 set igmp qi on page 579 set igmp qri on page 580 set igmp querier on page

Page 533

set igmp qi 579set igmp qi Changes the IGMP query interval timer on one VLAN or all VLANs on a WX.Syntax — set igmp qi seconds [vlan vlan-id] qi seco

Page 534

58 NEW FEATURES SUMMARYdisplay load cpu history Output example:display radio-profile EnhancementsThe display radio-profile command is used to display

Page 535

580 CHAPTER 13: IGMP SNOOPING COMMANDSset igmp qri Changes the IGMP query response interval timer on one VLAN or all VLANs on a WX.Syntax — set igmp q

Page 536

set igmp querier 581set igmp querier Enables or disables the IGMP pseudo-querier on a WX, on one VLAN or all VLANs.Syntax — set igmp querier {enable |

Page 537

582 CHAPTER 13: IGMP SNOOPING COMMANDSDefaults — By default, no ports are static multicast receiver ports. Access — Enabled.History — Introduced in MS

Page 538

set igmp rv 583See Also set igmp oqi on page 577 set igmp qi on page 579 set igmp qri on page 580

Page 539

584 CHAPTER 13: IGMP SNOOPING COMMANDS

Page 540

14SECURITY ACL COMMANDSUse security ACL commands to configure and monitor security access control lists (ACLs). Security ACLs filter packets to restri

Page 541 -  Disable

586 CHAPTER 14: SECURITY ACL COMMANDSclear security acl Clears a specified security ACL, an access control entry (ACE), or all security ACLs, from the

Page 542

clear security acl map 587WX4400# display security acl info allACL information for allset security acl ip acl_133 (hits #1 0)-------------------------

Page 543

588 CHAPTER 14: SECURITY ACL COMMANDSSyntax — clear security acl map {acl-name | all} {vlan vlan-id | port port-list [tag tag-value] | ap ap-num} {in

Page 544

commit security acl 589To clear all physical ports, virtual ports, and VLANs on a WX switch of the ACLs mapped for incoming and outgoing traffic, type

Page 545

display radio-profile Enhancements 59display radio-profile Displays all configured attributes of the specified radio profile. WX# display radio-profil

Page 546

590 CHAPTER 14: SECURITY ACL COMMANDSExamples — The following commands commit all the security ACLs in the edit buffer to the configuration, display a

Page 547

display security acl editbuffer 591WX4400# display security aclACL tableACL Type Class Mapping---------------------------- ---- ------ -------acl_123

Page 548

592 CHAPTER 14: SECURITY ACL COMMANDSTo view details about these uncommitted ACLs, type the following command. WX4400# display security acl info all e

Page 549

display security acl info 593Examples — To display the security ACL hits on a WX switch, type the following command:WX4400# display security acl hitsA

Page 550

594 CHAPTER 14: SECURITY ACL COMMANDSExamples — To display the contents of all security ACLs committed on a WX switch, type the following command:WX44

Page 551

display security acl resource-usage 595Access — Enabled.History — Introduced in MSS Version 3.0.Examples — The following command displays the port to

Page 552

596 CHAPTER 14: SECURITY ACL COMMANDSExamples — To display security ACL resource usage, type the following command:WX4400# display security acl resour

Page 553

display security acl resource-usage 597Table 88 Output of display security acl resource-usageField DescriptionNumber of rules Number of security ACE

Page 554

598 CHAPTER 14: SECURITY ACL COMMANDSLUdef in use Number of the lookup definition (LUdef) table currently in use for packet handling. Default action p

Page 555

rollback security acl 599rollback security acl Clears changes made to the security ACL edit buffer since it was last saved. The ACL is rolled back to

Page 556

3 SYSTEM SERVICE COMMANDSCommands by Usage 89clear banner motd 90clear history 91clear prompt 91clear system 92display banner motd 93display base-info

Page 557

60 NEW FEATURES SUMMARYdisplay sessions network ap Enhancements New commands and output now allow you to see AP statistics of a network session. The n

Page 558

600 CHAPTER 14: SECURITY ACL COMMANDSExamples — The following commands show the edit buffer before a rollback, clear any changes in the edit buffer to

Page 559

set security acl 601By ICMP packetsSyntax — set security acl ip acl-name {permit [cos cos] | deny} icmp {source-ip-addr mask destination-ip-addr ma

Page 560 - 560 CHAPTER 12: STP COMMANDS

602 CHAPTER 14: SECURITY ACL COMMANDS 0 or 3—Best effort. Packets are queued in MAP forwarding queue 3. 4 or 5—Video. Packets are queued in MAP forw

Page 561 - IGMP SNOOPING COMMANDS

set security acl 603(For a complete list of TCP and UDP port numbers, see www.iana.org/assignments/port-numbers.)  destination-ip-addr mask — IP addr

Page 562

604 CHAPTER 14: SECURITY ACL COMMANDS before editbuffer-index — Inserts the new ACE in front of another ACE in the security ACL. Specify the number o

Page 563 - VLAN orange:

set security acl map 605The following command adds an ACE to acl_123 that denies packets from IP address 192.168.2.11:WX4400# set security acl ip acl_

Page 564

606 CHAPTER 14: SECURITY ACL COMMANDSSyntax — set security acl map acl-name {vlan vlan-id | port port-list [tag tag-list] | ap ap-num} {in | out} acl

Page 565

set security acl hit-sample-rate 607See Also clear security acl map on page 587 commit security acl on page 589 set mac-user attr on page 309 set

Page 566

608 CHAPTER 14: SECURITY ACL COMMANDSExamples — The first command sets MSS to sample ACL hits every 15 seconds. The second and third commands display

Page 567

15CRYPTOGRAPHY COMMANDSA digital certificate is a form of electronic identification for computers. The WX requires digital certificates to authenticat

Page 568

clear sessions network Enhancements 61WX# display sessions network ap 1, 7, 8 radio 16 of 16 sessions matchedAP 1, Conference RoomAP 1, Conference Roo

Page 569

610 CHAPTER 15: CRYPTOGRAPHY COMMANDSCommands by UsageThis chapter presents cryptography commands alphabetically. Use Table 89 to locate commands in t

Page 570

crypto ca-certificate 611 PEM-formatted certificate — ASCII text representation of the certificate authority PKCS #7 certificate, consisting of up to

Page 571

612 CHAPTER 15: CRYPTOGRAPHY COMMANDScrypto certificate Installs one of the WX switch’s PKCS #7 certificates into the certificate and key storage area

Page 572

crypto generate key 613Examples — The following command installs a certificate:WX4400# crypto certificate adminEnter PEM-encoded certificate-----BEGIN

Page 573 -  set igmp rv on page 582

614 CHAPTER 15: CRYPTOGRAPHY COMMANDSHistory —Introduced in MSS Version 3.0. Webaaa option renamed to web in MSS Version 4.1.Usage — You can overwrite

Page 574 -  set igmp qi on page 579

crypto generate request 615 State Name string — (Optional) Specify the name of the state, in up to 64 alphanumeric characters. Spaces are allowed. L

Page 575

616 CHAPTER 15: CRYPTOGRAPHY COMMANDSExamples — To request an administrative certificate from a certificate authority, type the following command:WX44

Page 576

crypto generate self-signed 617After you type the command, you are prompted for the following variables: Country Name string — (Optional) Specify the

Page 577 -  set igmp mrsol on page 576

618 CHAPTER 15: CRYPTOGRAPHY COMMANDSTo generate a self-signed administrative certificate, type the following command:WX4400# crypto generate self-sig

Page 578

crypto otp 619Note: On an WX switch that handles communications to and from Microsoft Windows clients, use a one-time password of 31 characters or few

Page 579

62 NEW FEATURES SUMMARYThere are two possible forms for the display service-profile command: display service-profile name  display service-profile n

Page 580

620 CHAPTER 15: CRYPTOGRAPHY COMMANDScrypto pkcs12 Unpacks a PKCS #12 object file into the certificate and key storage area on the WX switch. This obj

Page 581

display crypto ca-certificate 621Examples — The following commands copy a PKCS #12 object file for an EAP certificate and key pair—and optionally the

Page 582

622 CHAPTER 15: CRYPTOGRAPHY COMMANDSAccess — Enabled.History —Introduced in MSS Version 3.0. Webaaa option renamed to web in MSS Version 4.1.Examples

Page 583

display crypto certificate 623Defaults — None.Access — Enabled.History —Introduced in MSS Version 3.0. Webaaa option renamed to web in MSS Version 4.1

Page 584

624 CHAPTER 15: CRYPTOGRAPHY COMMANDSdisplay crypto key domainDisplays domain key information.Syntax — display crypto key domainDefaults — None.Access

Page 585 - SECURITY ACL COMMANDS

16RADIUS AND SERVER GROUP COMMANDSUse RADIUS commands to set up communication between a WX switch and groups of up to four RADIUS servers for remote a

Page 586

626 CHAPTER 16: RADIUS AND SERVER GROUP COMMANDSclear radius Resets parameters that were globally configured for RADIUS servers to their default value

Page 587

clear radius client system-ip 627WX4400# clear radius timeoutsuccess: change accepted.See Also display aaa on page 277 set radius on page 630 set r

Page 588

628 CHAPTER 16: RADIUS AND SERVER GROUP COMMANDSclear radius proxy clientRemoves RADIUS proxy client entries for third-party APs.Syntax — clear radius

Page 589

clear radius server 629clear radius server Removes the named RADIUS server from the WX configuration.Syntax — clear radius server server-name server-

Page 590

display service-profile Enhancements 63Encryption type string*End date string*Filter ID string [, string]*Idle timeout string*Mobility profile string*

Page 591

630 CHAPTER 16: RADIUS AND SERVER GROUP COMMANDSExamples — To remove the server group sg-77 type the following command:WX4400# clear server group sg-7

Page 592

set radius 631MSS encrypts the display form of the string in display config and display aaa output. retransmit number — Number of transmission attemp

Page 593

632 CHAPTER 16: RADIUS AND SERVER GROUP COMMANDSSee Also clear radius server on page 629 display aaa on page 277 set radius server on page 635set r

Page 594

set radius proxy client 633set radius proxy clientAdds a RADIUS proxy entry for a third-party AP. The proxy entry specifies the IP address of the AP a

Page 595 - Port 4 in

634 CHAPTER 16: RADIUS AND SERVER GROUP COMMANDSset radius proxy portConfigures the WX port connected to a third-party AP as a RADIUS proxy for the SS

Page 596

set radius server 635set radius server Configures RADIUS servers and their parameters. By default, the WX switch automatically sets all these values e

Page 597

636 CHAPTER 16: RADIUS AND SERVER GROUP COMMANDS author-password password — Password used for authorization to a RADIUS server for MAC users. Specify

Page 598

set server group 637Examples — To set a RADIUS server named RS42 with IP address 198.162.1.1 to use the default accounting and authorization ports wit

Page 599

638 CHAPTER 16: RADIUS AND SERVER GROUP COMMANDSDo not use the same name for a RADIUS server and a RADIUS server group.Examples — To set server group

Page 600

set server group load-balance 639Examples — To enable load balancing between the members of server group shorebirds, type the following command:WX1200

Page 601

64 NEW FEATURES SUMMARY* - option present only if a value is setThe Options list displays only enabled attributes.Output example:WX# display service-p

Page 602

640 CHAPTER 16: RADIUS AND SERVER GROUP COMMANDS

Page 603

17802.1X MANAGEMENT COMMANDSUse 802. IEEE X management commands to modify the default settings for IEEE 802.1X sessions on an WX. For best results, ch

Page 604

642 CHAPTER 17: 802.1X MANAGEMENT COMMANDSclear dot1x bonded-periodResets the Bonded Auth™ (bonded authentication) period to its default value. The bo

Page 605

clear dot1x max-req 643See Also display dot1x on page 647  set dot1x bonded-period on page 651clear dot1x max-req Resets to the default setting the

Page 606

644 CHAPTER 17: 802.1X MANAGEMENT COMMANDSUsage — This command is overridden by the set dot1x authcontrol command. The clear dot1x port-control comman

Page 607

clear dot1x reauth-max 645clear dot1x reauth-maxResets the maximum number of reauthorization attempts to the default setting. Syntax — clear dot1x rea

Page 608

646 CHAPTER 17: 802.1X MANAGEMENT COMMANDSclear dot1x timeout auth-serverResets to the default setting the number of seconds that must elapse before t

Page 609 - CRYPTOGRAPHY COMMANDS

clear dot1x tx-period 647clear dot1x tx-periodResets to the default setting the number of seconds that must elapse before the WX switch retransmits an

Page 610 - Commands by

648 CHAPTER 17: 802.1X MANAGEMENT COMMANDSHistory —Introduced in MSS Version 3.0. Format of 802.1X authentication rule information in display dot1x co

Page 611

display dot1x 649 802.1X parameter setting ---------------- ------- supplicant timeout

Page 612

display service-profile Enhancements 65Pre-shared-key: e647c43e9a166bb15724384b5b57f98c664dbe2069aaa1352ec1d28dacb1975SSID attributesFilter id: traffi

Page 613

650 CHAPTER 17: 802.1X MANAGEMENT COMMANDSset dot1x authcontrolProvides a global override mechanism for 802.1X authentication configuration on wired a

Page 614

set dot1x bonded-period 651Defaults — By default, authentication control for individual wired authentication is enabled.Access — Enabled.History —Intr

Page 615

652 CHAPTER 17: 802.1X MANAGEMENT COMMANDSUsage — Normally, the Bonded Auth period needs to be set only if the network has Bonded Auth clients that us

Page 616

set dot1x max-req 653Examples — Type the following command to enable key transmission:WX4400# set dot1x key-tx enablesuccess: dot1x key transmission e

Page 617

654 CHAPTER 17: 802.1X MANAGEMENT COMMANDSset dot1x port-controlDetermines the 802.1X authentication behavior on individual wired authentication ports

Page 618

set dot1x quiet-period 655set dot1x quiet-periodSets the number of seconds a WX remains quiet and does not respond to a supplicant after a failed auth

Page 619 -  crypto pkcs12 on page 620

656 CHAPTER 17: 802.1X MANAGEMENT COMMANDSSee Also display dot1x on page 647 set dot1x reauth-max on page 656 set dot1x reauth-period on page 657se

Page 620

set dot1x reauth-period 657set dot1x reauth-periodSets the number of seconds that must elapse before the WX switch attempts reauthentication.Syntax —

Page 621 -  crypto otp on page 618

658 CHAPTER 17: 802.1X MANAGEMENT COMMANDSSee Also display dot1x on page 647 clear dot1x timeout auth-server on page 646set dot1x timeout supplicant

Page 622

set dot1x wep-rekey 659Examples — Type the following command to set the number of seconds before the WX switch retransmits an EAPoL packet to 300:WX44

Page 623

66 NEW FEATURES SUMMARY11bBeacon rate: 2Multicast rate: autoMandatory rates: 1, 2Standard rates: 5.5, 1111gBeacon rate: 2Multicast rate: autoMandatory

Page 624

660 CHAPTER 17: 802.1X MANAGEMENT COMMANDSset dot1x wep-rekey-periodSets the interval for rotating the WEP broadcast and multicast keys.Syntax — set d

Page 625 - RADIUS AND SERVER GROUP

18SESSION MANAGEMENT COMMANDSUse session management commands to display and clear administrative and network user sessions. Commands by UsageThis chap

Page 626

662 CHAPTER 18: SESSION MANAGEMENT COMMANDS telnet client [session-id] — Clears all Telnet client sessions from the CLI to remote devices, or clears

Page 627 -  set radius on page 630

clear sessions network 663clear sessions networkClears all network sessions for a specified username or set of usernames, MAC address or set of MAC ad

Page 628

664 CHAPTER 18: SESSION MANAGEMENT COMMANDSExamples — To clear all sessions for MAC address 00:01:02:03:04:05, type the following command:WX4400# clea

Page 629

display sessions 665 telnet — Displays sessions for all users with administrative access to the WX switch through a Telnet connection. telnet client

Page 630

666 CHAPTER 18: SESSION MANAGEMENT COMMANDSTo view information about Telnet client sessions, type the following command:WX4400# display sessions telne

Page 631

display sessions mesh-ap 667display sessions mesh-apDisplays summary or verbose information about Mesh AP sessions on the WX.Syntax — display sessions

Page 632

668 CHAPTER 18: SESSION MANAGEMENT COMMANDSSee also “clear sessions” on page 661display sessions networkDisplays summary or verbose information about

Page 633

display sessions network 669Defaults — None.Access — All.History —Introduced in MSS Version 3.0. Output added to the display network sessions verbose

Page 634

display rfdetect Changes 67You can further refine the output using the options listed below:bssidThe entire BSSID in the format XX:XX:XX:XX:XX:XX or i

Page 635

670 CHAPTER 18: SESSION MANAGEMENT COMMANDSThe following command displays summary information about all the sessions of users whose names begin with E

Page 636

display sessions network 671Start-Date=05/04/11-10:00 (AAA)1 sessions total(Table 100 on page 672 describes the additional fields of the verbose outpu

Page 637

672 CHAPTER 18: SESSION MANAGEMENT COMMANDSSess ID Locally unique number that identifies this session. An asterisk (*) next to the session ID indicate

Page 638

display sessions network 673State Status of the session: AUTH, ASSOC REQ — Client is being associated by the 802.1X protocol. AUTH AND ASSOC — Clien

Page 639

674 CHAPTER 18: SESSION MANAGEMENT COMMANDSTable 101 display sessions network session-id OutputField DescriptionGlobal Id A unique session identifie

Page 640

display sessions network 675See Also clear sessions network on page 663Authentication MethodExtensible Authentication Protocol (EAP) type used to aut

Page 641 - 802.1X MANAGEMENT

676 CHAPTER 18: SESSION MANAGEMENT COMMANDS

Page 642

19RF DETECTION COMMANDSMSS automatically performs RF detection scans on enabled and disabled radios to detect rogue access points. A rogue access poin

Page 643 - WX4400# clear dot1x max-req

678 CHAPTER 19: RF DETECTION COMMANDSclear rfdetect attack-listRemoves a MAC address from the attack list.Syntax — clear rfdetect attack-list mac-addr

Page 644 -  display dot1x on page 647

clear rfdetect black-list 679See Also clear rfdetect attack-list on page 678 display rfdetect attack-list on page 683clear rfdetect black-listRemove

Page 645

68 NEW FEATURES SUMMARYclassSort output by classification as a rogue, neighbor, member, suspect, or none.WX# display rfdetect data classTotal number o

Page 646

680 CHAPTER 19: RF DETECTION COMMANDSExamples — The following command removes BSSID aa:bb:cc:11:22:33 from the ignore list for RF scans:WX1200# clear

Page 647

clear rfdetect vendor-list 681clear rfdetect vendor-listRemoves an entry from the permitted vendor list.Syntax — clear rfdetect vendor-list {client |

Page 648

682 CHAPTER 19: RF DETECTION COMMANDSrfping Provides information about the RF link between the WX and the client based on sending test packets to the

Page 649

display rfdetect attack-list 683See Also display rfdetect data on page 690 display rfdetect visible on page 698display rfdetect attack-listDisplays

Page 650

684 CHAPTER 19: RF DETECTION COMMANDSdisplay rfdetect black-listDisplays information abut the clients in the client black list.Syntax — display rfdete

Page 651

display rfdetect clients 685display rfdetect clientsDisplays the wireless clients detected by a WX switch. Syntax — display rfdetect clients [mac mac-

Page 652

686 CHAPTER 19: RF DETECTION COMMANDSTable 104 display rfdetect clients OutputField DescriptionClient MAC MAC address of the client.Client Vendor Co

Page 653

display rfdetect countermeasures 687display rfdetect countermeasuresDisplays the current status of countermeasures against rogues in the Mobility Doma

Page 654

688 CHAPTER 19: RF DETECTION COMMANDSTable 106 describes the fields in this display.See Also  set radio-profile countermeasures on page 458display rf

Page 655

display rfdetect counters 689Examples — The following command shows counters for rogue activity detected by a WX switch:WX4400# display rfdetect count

Page 656

display rfdetect Changes 69 If the class is set to Member, there are two possible Reason codes: AP is part of the Mobility Domain AP is not part of

Page 657

690 CHAPTER 19: RF DETECTION COMMANDSdisplay rfdetect dataDisplays all the BSSIDs detected by an individual WX switch during an RF detection scan. The

Page 658

display rfdetect data 691See Also display rfdetect mobility-domain on page 692 display rfdetect visible on page 698Table 107 display rfdetect data

Page 659

692 CHAPTER 19: RF DETECTION COMMANDSdisplay rfdetect ignoreDisplays the BSSIDs of third-party devices that MSS ignores during RF scans. MSS does not

Page 660

display rfdetect mobility-domain 693Usage — This command is valid only on the seed switch of the Mobility Domain. To display rogue information for an

Page 661 - SESSION MANAGEMENT

694 CHAPTER 19: RF DETECTION COMMANDS WX-IPaddress: 10.8.121.102 Port/Radio/Ch: 3/1/1 Mac: 00:0b:0e:00:0a:6a Device-type: interfering Adhoc: no Cryp

Page 662

display rfdetect mobility-domain 695Table 108 and Table 109 describe the fields in these displays.Table 108 display rfdetect mobility-domain OutputF

Page 663

696 CHAPTER 19: RF DETECTION COMMANDSSee Also display rfdetect data on page 690 display rfdetect visible on page 698Crypto-Types Encryption type:cle

Page 664

display rfdetect ssid-list 697display rfdetect ssid-listDisplays the entries in the permitted SSID list.Syntax — display rfdetect ssid-listDefaults —

Page 665

698 CHAPTER 19: RF DETECTION COMMANDSExamples — The following example shows the permitted vendor list on WX switch:WX1200# display rfdetect vendor-lis

Page 666 -  Telnet

display rfdetect visible 699Usage — If a 3Com radio is supporting more than one SSID, each of the corresponding BSSIDs is listed separately. To displa

Page 667

clear port type 122display port counters 123display port-group 124display port mirror 125display port poe 126display port status 127display port media

Page 668

70 NEW FEATURES SUMMARYdisplay rfdetect dataclientsThis command can be used to display client data in two ways: generic, and based on the MAC address

Page 669 - 00:05:5d:7e:98:1a:

700 CHAPTER 19: RF DETECTION COMMANDSSee Also display rfdetect data on page 690 display rfdetect mobility-domain on page 692set rfdetect active-scan

Page 670

set rfdetect attack-list 701set rfdetect attack-listAdds an entry to the attack list. The attack list specifies the MAC addresses of devices that MSS

Page 671

702 CHAPTER 19: RF DETECTION COMMANDSset rfdetect black-listAdds an entry to the client black list. The client black list specifies clients that are n

Page 672

set rfdetect countermeasures mac 703Syntax — set rfdetect countermeasures {enable | disable} enable — Enables countermeasures. disable — Disables co

Page 673

704 CHAPTER 19: RF DETECTION COMMANDSYou can start countermeasures against more than one BSSID by typing additional set rfdetect countermeasures mac c

Page 674

set rfdetect log 705Usage — Use this command to identify third-party APs and other devices you are already aware of and do not want MSS to report foll

Page 675

706 CHAPTER 19: RF DETECTION COMMANDSHistory —Introduced in MSS Version 3.0.Usage — This command is valid only on the seed switch of the Mobility Doma

Page 676

set rfdetect signature key 707Examples — The following command enables MAP signatures on a WX switch:WX1200# set rfdetect signature enablesuccess: si

Page 677 - RF DETECTION COMMANDS

708 CHAPTER 19: RF DETECTION COMMANDSIf you add a device that MSS has classified as a rogue to the permitted SSID list, but not to the ignore list, MS

Page 678

test rflink 709If you add a device that MSS has classified as a rogue to the permitted vendor list, but not to the ignore list, MSS can still classify

Page 679

display rfdetect Changes 71WX# display rfdetect data ssid Trapeze* verbose3 of 12 entries matchedConnected BSSID: 00:0b:0e:14:d4:81BSSID vendor: Trape

Page 680

710 CHAPTER 19: RF DETECTION COMMANDSExamples — The following command tests the RF link between the WX switch and the client with MAC address 00:0e:9b

Page 681

20FILE MANAGEMENT COMMANDSUse file management commands to manage system files and to display software and boot information. Commands by UsageThis chap

Page 682 - Table 103 rfping Output

712 CHAPTER 20: FILE MANAGEMENT COMMANDSbackup Creates an archive of WX system files and optionally, user file, in Unix tape archive (tar) format.Synt

Page 683

backup 713Archive files created by the all option are larger than files created by the critical option. The file size depends on the files in the user

Page 684

714 CHAPTER 20: FILE MANAGEMENT COMMANDSclear boot backup-configurationClears the filename specified as the backup configuration file. In the event th

Page 685

copy 715WX4400# reset system force... rebooting ...See Also display config on page 723 reset system on page 731copy Performs the following cop

Page 686

716 CHAPTER 20: FILE MANAGEMENT COMMANDSDefaults — None.Access — Enabled.History —Introduced in MSS Version 3.0.Usage — The filename and file:filename

Page 687

delete 717The following commands rename test-config to new-config by copying it from one name to the other in the same location, then deleting test-co

Page 688

718 CHAPTER 20: FILE MANAGEMENT COMMANDSExamples — The following commands copy file testconfig to a TFTP server and delete the file from nonvolatile s

Page 689

dir 719Examples — The following command displays the files in the root directory:WX4400# dir==========================================================

Page 690

72 NEW FEATURES SUMMARYdisplay rfdetect datasummaryThis command has two forms: client and general. The client form displays a summary of all detected

Page 691

720 CHAPTER 20: FILE MANAGEMENT COMMANDSThe following command limits the output to the contents of the user files area:WX4400# dir file:==============

Page 692

install soda agent 721See Also copy on page 715 delete on page 717install soda agent Installs Sygate On-Demand (SODA) agent files in a directory on

Page 693

722 CHAPTER 20: FILE MANAGEMENT COMMANDSUsage — The install soda agent command installs a .zip file containing SODA agent files into a directory on th

Page 694

display config 723Table 115 describes the fields in the display boot output.See Also display version on page 725 reset system on page 731 set boot

Page 695

724 CHAPTER 20: FILE MANAGEMENT COMMANDS ip-config l2acl log mobility-domain network-domain ntp portconfig port-group qos radio-profile rfd

Page 696

display version 725Usage — If you do not use one of the optional parameters, configuration commands that set nondefault values are displayed for all c

Page 697

726 CHAPTER 20: FILE MANAGEMENT COMMANDSExamples — The following command displays version information for a WX switch:WX1200# display version M

Page 698

load config 727Table 116 describes the fields in the display version output.See Also display boot on page 722load config Loads configuration commands

Page 699

728 CHAPTER 20: FILE MANAGEMENT COMMANDSDefaults — The default file location is nonvolatile storage. The current version supports loading a configurat

Page 700

md5 729md5 Calculates the MD5 checksum for a file in the switch’s nonvolatile storage.Syntax — md5 [boot0: | boot1:]filename boot0: | boot1: — Boot p

Page 701

display rfdetect Changes 73

Page 702

730 CHAPTER 20: FILE MANAGEMENT COMMANDSExamples — The following commands create a subdirectory called corp2 and display the root directory to verify

Page 703

reset system 731reset system Restarts an WX switch and reboots the software.Syntax — reset system [force] force — Immediately restarts the system and

Page 704 - set rfdetect ignore mac-addr

732 CHAPTER 20: FILE MANAGEMENT COMMANDSrestore Unzips a system archive created by the backup command and copies the files from the archive onto the s

Page 705

rmdir 733See Also backup on page 712rmdir Removes a subdirectory from nonvolatile storage. Syntax — rmdir [subdirname] subdirname — Subdirectory nam

Page 706

734 CHAPTER 20: FILE MANAGEMENT COMMANDSAccess — Enabled.History —Introduced in MSS Version 3.0.Usage — If you do not specify a filename, MSS replaces

Page 707

set boot configuration-file 735History —Introduced in MSS Version 4.1.Examples — The following command specifies a file called backup.cfg as the backu

Page 708

736 CHAPTER 20: FILE MANAGEMENT COMMANDSset boot partition Specifies the boot partition in which to look for the system image file following the next

Page 709

uninstall soda agent 737Usage — The uninstall soda command removes the SODA agent directory and all of its contents. All files in the specified direct

Page 710

738 CHAPTER 20: FILE MANAGEMENT COMMANDS

Page 711 - FILE MANAGEMENT COMMANDS

21TRACE COMMANDSUse trace commands to perform diagnostic routines. While MSS allows you to run many types of traces, this chapter describes commands f

Page 712

74 NEW FEATURES SUMMARY

Page 713 - Table 113 Output for backup

740 CHAPTER 21: TRACE COMMANDSclear log trace Deletes the log messages stored in the trace buffer.Syntax — clear log traceDefaults — None.Access — Ena

Page 714 -  display boot on page 722

display trace 741To clear the session manager trace, type the following command:WX4400# clear trace smsuccess: clear trace smSee Also display trace o

Page 715

742 CHAPTER 21: TRACE COMMANDSsave trace Saves the accumulated trace data for enabled traces to a file in the WX switch’s nonvolatile storage. Syntax

Page 716

set trace authorization 743Examples — The following command starts a trace for information about user jose’s authentication:WX4400# set trace authenti

Page 717 -  dir on page 718

744 CHAPTER 21: TRACE COMMANDSSee Also clear trace on page 740 display trace on page 741set trace dot1x Traces 802.1X sessions.Syntax — set trace do

Page 718

set trace sm 745set trace sm Traces session manager activity. Syntax — set trace sm [mac-addr mac-address] [port port-num] [user username] [level leve

Page 719

746 CHAPTER 21: TRACE COMMANDS

Page 720

22SNOOP COMMANDSUse snoop commands to monitor wireless traffic, by using a MAP as a sniffing device. The MAP copies the sniffed 802.11 packets and sen

Page 721 - Table 114 Output for dir

748 CHAPTER 22: SNOOP COMMANDSclear snoop Deletes a snoop filter.Syntax — clear snoop filter-name filter-name — Name of the snoop filter.Defaults — N

Page 722

set snoop 749Examples — The following command removes snoop filter snoop2 from radio 2 on Distributed MAP 3:WX1200# clear snoop map snoop2 ap 3 radio

Page 723

1USING THE COMMAND-LINE INTERFACEThis chapter discusses the 3Com Wireless Switch Manager (3WXM) command-line interface (CLI). Described are: CLI conv

Page 724

750 CHAPTER 22: SNOOP COMMANDSTo match on packets to or from a specific MAC address, use the dest-mac or src-mac option. To match on both send and rec

Page 725 -  save config on page 733

set snoop 751 The MAP that is running a snoop filter forwards snooped packets directly to the observer. This is a one-way communication, from the MAP

Page 726 - WX switch:

752 CHAPTER 22: SNOOP COMMANDSset snoop map Maps a snoop filter to a radio on a MAP. A snoop filter does take effect until you map it to a radio and e

Page 727

set snoop mode 753set snoop mode Enables a snoop filter. A snoop filter does not take effect until you map it to a MAP radio and enable the filter. Sy

Page 728

754 CHAPTER 22: SNOOP COMMANDSdisplay snoop Displays the MAP radio mapping for all snoop filters.Syntax — display snoopDefaults — None.Access — Enable

Page 729 -  copy on page 715

display snoop map 755Examples — The following command shows the snoop filters configured in the examples above:WX1200# display snoop infosnoop1:

Page 730

756 CHAPTER 22: SNOOP COMMANDSdisplay snoop stats Displays statistics for enabled snoop filters.Syntax — display snoop stats [filter-name [ap-num [rad

Page 731 -  display version on page 725

display snoop stats 757Table 119 describes the fields in this display.Table 119 display snoop stats OutputField DescriptionFilter Name of the snoop

Page 732

758 CHAPTER 22: SNOOP COMMANDS

Page 733 -  mkdir on page 729

23SYSTEM LOG COMMANDSUse the system log commands to record information for monitoring and troubleshooting. MSS system logs are based on RFC 3164, whic

Page 734

76 CHAPTER 1: USING THE COMMAND-LINE INTERFACECLI Conventions Be aware of the following MSS CLI conventions for command entry: “Command Prompts” on p

Page 735

760 CHAPTER 23: SYSTEM LOG COMMANDSAccess — Enabled.History — Introduced in MSS Version 3.0.Examples — To stop sending system logging messages to a se

Page 736

display log buffer 761 severity severity-level — Displays messages at a severity level greater than or equal to the level specified. Specify one of t

Page 737

762 CHAPTER 23: SYSTEM LOG COMMANDSSee Also clear log on page 759 display log config on page 762display log config Displays log configuration inform

Page 738

display log trace 763display log trace Displays system information stored in the nonvolatile log buffer or the trace buffer. Syntax — display log trac

Page 739 - TRACE COMMANDS

764 CHAPTER 23: SYSTEM LOG COMMANDSDefaults — None. Access — Enabled.History — Introduced in MSS Version 3.0.Examples — Type the following command to

Page 740 - HAPTER 21: TRACE COMMANDS

set log 765 Logging state (enabled or disabled)To override the session defaults for an individual session, type the set log command from within the s

Page 741

766 CHAPTER 23: SYSTEM LOG COMMANDSIf you do not specify a local facility, MSS sends the messages with their default MSS facilities. For example, AAA

Page 742

set log mark 767set log mark Configures MSS to generate mark messages at regular intervals. The mark messages indicate the current system time and dat

Page 743

768 CHAPTER 23: SYSTEM LOG COMMANDS

Page 744

24BOOT PROMPT COMMANDSBoot prompt commands enable you to perform basic tasks, including booting a system image file, from the boot prompt (boot>).

Page 745

CLI Conventions 77 A vertical bar (|) separates mutually exclusive options within a list of possibilities. For example, you enter either enable or di

Page 746

770 CHAPTER 24: BOOT PROMPT COMMANDSautoboot Displays or changes the state of the autoboot option. The autoboot option controls whether a WX switch au

Page 747 - SNOOP COMMANDS

boot 771boot Loads and executes a system image file. Syntax — boot [BT=type] [DEV=device] [FN=filename] [HA=ip-addr] [FL=num] [OPT=option] [OPT+=optio

Page 748 - HAPTER 22: SNOOP COMMANDS

772 CHAPTER 24: BOOT PROMPT COMMANDSUsage — If you use an optional parameter, the parameter setting overrides the setting of the same parameter in the

Page 749

change 773change Changes parameters in the currently active boot profile. (For information about boot profiles, see display on page 778.)Syntax — chan

Page 750

774 CHAPTER 24: BOOT PROMPT COMMANDSThe following command enters the configuration mode for the currently active boot profile and configures the WX sw

Page 751

delete 775Usage — A WX switch can have up to four boot profiles. The boot profiles are stored in slots, numbered 0 through 3. When you create a new pr

Page 752

776 CHAPTER 24: BOOT PROMPT COMMANDSUsage — When you type the delete command, the next-lower numbered boot profile becomes the active profile. For exa

Page 753

diag 777Examples — The following command displays the current setting of the DHCP option:boot> dhcpDHCP is currently enabled.The following command

Page 754

778 CHAPTER 24: BOOT PROMPT COMMANDSAccess — Boot prompt.History —Introduced in MSS Version 3.0.Usage — To display the system image software versions,

Page 755

display 779A WX switch can have up to four boot profiles, numbered 0 through 3. Only one boot profile can be active at a time. You can create, change,

Page 756

78 CHAPTER 1: USING THE COMMAND-LINE INTERFACEIP Address and MaskNotationMSS displays IP addresses in dotted decimal notation — for example, 192.168.1

Page 757 -  stopped—disabled

780 CHAPTER 24: BOOT PROMPT COMMANDSSee Also change on page 773 create on page 774 delete on page 775 next on page 783fver Displays the version of

Page 758

help 781Access — Boot prompt.History —Introduced in MSS Version 3.0.Usage — To display the image filenames, use the dir command. This command does not

Page 759 - SYSTEM LOG COMMANDS

782 CHAPTER 24: BOOT PROMPT COMMANDSExamples — The following command displays detailed information for the fver command:boot> help fver fver

Page 760

next 783Examples — To display a list of the commands available at the boot prompt, type the following command:boot> lsls Display a list of all com

Page 761

784 CHAPTER 24: BOOT PROMPT COMMANDSExamples — To activate the boot profile in the next slot and display the profile, type the following command:boot&

Page 762 -  set log on page 764

test 785 3Com WX-4400 Bootstrap/Bootloader Version 3.0.2 Release Compiled on Wed Sep 22 09:18:47 PDT 2004 by Bootstrap 0

Page 763

786 CHAPTER 24: BOOT PROMPT COMMANDSExamples — The following command displays the current setting of the poweron test flag:boot> testThe diagnostic

Page 764

AOBTAINING SUPPORT FOR YOUR 3COM PRODUCTS3Com offers product registration, case management, and repair services through eSupport.3com.com. You must ha

Page 765

788 APPENDIX A: OBTAINING SUPPORT FOR YOUR 3COM PRODUCTSPurchase Extended Warranty and Professional ServicesTo enhance response times or extend your w

Page 766

Contact Us 789Telephone TechnicalSupport and RepairTo obtain telephone support as part of your warranty and other service benefits, you must first reg

Page 767

CLI Conventions 79Table 4 gives examples of user globs.MAC Address GlobsA media access control (MAC) address glob is a similar method for matching som

Page 768

790 APPENDIX A: OBTAINING SUPPORT FOR YOUR 3COM PRODUCTSPakistan Call the U.S. direct by dialing 00 800 01001, then dialing 800 763 6780Sri Lanka Call

Page 769 - BOOT PROMPT COMMANDS

Contact Us 791US and Canada — Telephone Technical Support and RepairAll locations: Network Jacks; Wired or Wireless Network Interface Cards:All other

Page 770 -  boot on page 771

792 APPENDIX A: OBTAINING SUPPORT FOR YOUR 3COM PRODUCTS

Page 771

INDEXAautoboot 770Bbackup 712boot 771Cchange 773clear accounting 261clear ap 118clear ap boot-configuration 358clear ap local-switching vlan-profile 3

Page 772 -  display on page 778

794 INDEXclear sessions network 61, 663clear snmp community 191clear snmp notify profile 191clear snmp notify target 192clear snoop 748clear snoop map

Page 773

INDEX 795display location policy 282display log buffer 760display log config 762display log trace 763display mac-user 51display mac-usergroup 53displa

Page 774

796 INDEXNnext 783Pping 214Qquickstart 100quit 86Rradping 39reset 784reset ap 410reset port 135reset system 731restore 732rfdetect 47rfping 682rmdir 7

Page 775 -  next on page 783

INDEX 797set igmp mrsol 576set igmp mrsol mrsi 576set igmp oqi 577set igmp proxy-report 578set igmp qi 579set igmp qri 580set igmp querier 581set igmp

Page 776

798 INDEXset rfdetect attack-list 701set rfdetect black-list 702set rfdetect classification ad-hoc 45set rfdetect classification default 46set rfdetec

Page 777

INDEX 799set trace authorization user 743set trace dot1x 744set trace dot1x mac-addr 744set trace dot1x port 744set trace dot1x user 744set trace sm 7

Page 778

display vlan-profile 168set fdb 169set fdb agingtime 170set security L2-restrict 171set vlan name 172set vlan port 173set vlan tunnel-affinity 174set

Page 779

80 CHAPTER 1: USING THE COMMAND-LINE INTERFACEVLAN GlobsA VLAN glob is a method for matching one of a set of local rules on an wireless LAN switch, kn

Page 780

800 INDEX

Page 781 -  version on page 786

Command-Line Editing 81 A hyphen-separated range of port numbers, with no spaces. For example:WX1200# reset port 1-3 Any combination of single numbe

Page 782 -  ls on page 782

82 CHAPTER 1: USING THE COMMAND-LINE INTERFACEHistory Buffer The history buffer stores the last 63 commands you entered during a terminal session. You

Page 783 -  help on page 781

Using CLI Help 83Using CLI Help The CLI provides online help. To see the full range of commands available at your access level, type the help command.

Page 784 -  create on page 774

84 CHAPTER 1: USING THE COMMAND-LINE INTERFACETo see all the variations, type one of the commands followed by a question mark (?). For example:WX1200#

Page 785

2ACCESS COMMANDSThis chapter describes access commands used to control access to the Mobility Software System (MSS) command-line interface (CLI). Comm

Page 786 -  fver on page 780

86 CHAPTER 2: ACCESS COMMANDSenable Places the CLI session in enabled mode, which provides access to all commands required for configuring and monitor

Page 787 - 3COM PRODUCTS

set enablepass 87set enablepass Sets the password that provides enabled access (for configuration and monitoring) to the WX switch. Syntax — set enabl

Page 788

88 CHAPTER 2: ACCESS COMMANDS

Page 789 - ■ Diagnostic error messages

3SYSTEM SERVICE COMMANDSUse system services commands to configure and monitor system information for a WX switch.Commands by UsageThis chapter present

Page 790 - +61 2 9937 5048, or send an

display interface 200display ip alias 201display ip dns 202display ip https 203display ip route 204display ip telnet 206display ntp 207display snmp co

Page 791

90 CHAPTER 3: SYSTEM SERVICE COMMANDSclear banner motd Deletes the message-of-the-day (MOTD) banner that is displayed before the login prompt for each

Page 792

clear history 91clear history Deletes the command history buffer for the current CLI session. Syntax — clear historyDefaults — None.Access — All.Histo

Page 793

92 CHAPTER 3: SYSTEM SERVICE COMMANDSclear system Clears the system configuration of the specified information.CAUTION: If you change the IP address,

Page 794

display banner motd 93display banner motdShows the banner that was configured with the set banner motd command.Syntax — display banner motdDefaults —

Page 795 - NDEX 795

94 CHAPTER 3: SYSTEM SERVICE COMMANDSSee Also display boot on page 722 display config on page 723 display license on page 94 display system on pag

Page 796

display load 95display load Displays CPU usage on a WX switch.Syntax — display loadDefaults — None.Access — Enabled.History — Introduced in MSS Versio

Page 797 - NDEX 797

96 CHAPTER 3: SYSTEM SERVICE COMMANDSExamples — To show system information, type the following command:WX4400# display system=========================

Page 798

display system 97System idle timeout Number of seconds MSS allows a CLI management session (console, Telnet, or SSH) to remain idle before terminating

Page 799 - NDEX 799

98 CHAPTER 3: SYSTEM SERVICE COMMANDSSee Also clear system on page 92 set system contact on page 108 set system countrycode on page 109 set system

Page 800 - 800 INDEX

history 99crypto Crypto, use 'crypto help' for more informationdelete Delete urldir Show list of files on flash devicedisable Disable pri

Commentaires sur ces manuels

Pas de commentaire