Page 2
Colubris Networks, Inc. Colubris is a registered trademark, and the Colubris Networks logo, the tag line “The Intelligent Wireless Networking Choice” and TriPlane are trademarks of Colubris Networks, Inc., in the United States and other countries.
Although detailed configuration steps are provided for each scenario, the guide does not cover the basic procedures for operating and configuring Colubris Networks devices. This information can be found in the administrator’s guides. You should be familiar with this information before you attempt to use the scenarios in this guide.
Page 7
Wireless client bridge Wireless distribution system Related For information on related documentation, see the Colubris Networks Technical Documentation Road Map, available on the Colubris Networks Documentation CD and documentation for download on the Colubris Networks web site. Software For information on using Colubris Netwokrs products with different software revisions,...
Public access deployment - 3000 series Chapter 3 Public access deployment - 3000 series This chapter presents sample deployment strategies for common public access scenarios using an MSC-3000 series service controller and one or more MAPs operating in autonomous mode. These scenarios will give you a good idea about how to approach your installation.
Chapter 3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Public access deployment - 3000 series - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Chapter 3 Scenario 1a: Hotspot with Internet access (local config) This scenario shows you how to quickly deploy and test the MSC without installing a RADIUS server.
Page 15
• automatically choose the best operating channel (frequency) • support 802.11b/g clients • create a wireless network named Colubris Networks There is no need to change these settings for this scenario. Note: By default, one radio on the MSC-3300 is used to provide the wireless network and the other is placed into Monitor mode.
Page 18
Chapter 3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Public access deployment - 3000 series - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Chapter 3 Topology 2 In this version, the web server is located on local LAN B along with a router/firewall which handles the connection to the Internet.
Page 19
Chapter 3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Public access deployment - 3000 series - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Chapter 3 3. Copy the following files from the \Doc\Samples\Internal_Pages folder on the Colubris Networks documentation CD and place them in the newpages folder. • login.html •...
Page 21
• support 802.11b/g clients • automatically choose the best operating channel (frequency) • create a wireless network named Colubris Networks There is no need to change these settings for this scenario. Important: All wireless networks must have the same network name (SSID) to support roaming.
Page 22
Each MAP will use the services of the MSC to authenticate customer logins. Do the following on each MAP. 1. Select VSC > Profiles. 2. Click the Colubris Networks profile to edit it. 3. In the General box, select the Use Colubris access controller check box. 4. Click Save.
Page 24
Use the following steps to create three virtual service communities on all MAPs. 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the Colubris Networks profile to edit it. 3. On the Add/Edit Virtual Service Community page: •...
Page 25
Use the following steps to create virtual service communities on the MSC that match each VSC you configured on the MAPs: 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the Colubris Networks profile to edit it. 3. On the Add/Edit Virtual Service Community page: •...
Chapter 3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Public access deployment - 3000 series - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Chapter 3 Scenario 2a: Hotspot with Internet access (AAA server) This installation shows you how to create a public access network using an AAA (authentication, administration, accounting) RADIUS server to handle customer...
Page 27
• support 802.11b/g clients • automatically choose the best operating channel (frequency) • create a wireless network named “Colubris Networks” There is no need to change these settings for this scenario. Note: By default one radio on the MSC-3300 is used to provide the wireless network and the other is placed into Monitor mode.
Page 28
MSC will use to login. Enable RADIUS authentication of customers 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the Colubris Networks profile to edit it. 3. On the Add/Edit Virtual Service Community page: •...
Page 29
Chapter 3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Public access deployment - 3000 series - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Chapter 3 Test the public access interface To test your installation, use a wireless client station to log onto the public access interface.
Page 31
(recommended size less than 20K). This same image file is shared by all pages. 3. Copy the following files from the \Doc\Samples\Internal_Pages folder on the Colubris Networks documentation CD and place them in the newpages folder. • login.html • transport.html •...
Page 32
Chapter 3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Public access deployment - 3000 series - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Chapter 3 Define attributes on the RADIUS server On the RADIUS server, define an account for the MSC and add the following entries to login-page=web_server_URL/newpages/login.html...
Page 34
• support 802.11b/g clients • automatically choose the best operating channel (frequency) • create a wireless network named Colubris Networks There is no need to change these settings for this scenario. Note: By default, one radio on the MAP-330 and the MSC-3300 is used to provide the wireless network, and the other is placed into Monitor mode.
Page 35
Configure the connection to the MSC on the MAPs Configure the following on each MAP. 1. Select VSC > Profiles. 2. Click the Colubris Networks profile to edit it. 3. In the General box, select the Use Colubris access controller check box. 4. Click Save.
Page 37
Use the following steps to create three virtual service communities on all MAPs. 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the Colubris Networks profile to edit it. 3. On the Add/Edit Virtual Service Community page: •...
Page 38
Use the following steps to create virtual service communities on the MSC that match each VSC you configured on the MAPs: 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the Colubris Networks profile to edit it. 3. On the Add/Edit Virtual Service Community page: •...
This scenario adds support for 802.11a wireless clients to Scenario 2d. Important: This scenario is supported by dual-radio units only. Colubris Networks’ dual radio products can be configured to support the same SSID on two different radios. This enables a single device to support wireless clients regardless of the type of radio they have: 802.11a, b, or g.
Page 43
LAN port is always sent to the first VSC profile. 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the Colubris Networks profile to edit it. 3. On the Add/Edit Virtual Service Community page: •...
Page 44
Configure the MAP Create VSCs 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the Colubris Networks profile to edit it. 3. On the Add/Edit Virtual Service Community page: • Under General, enter the Name as Public.
Page 48
• Public: Installed in hotel rooms. Forwards public traffic on VLAN 50. 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the Colubris Networks profile to edit it. 3. On the Add/Edit Virtual Service Community page: •...
Page 49
• Click Save. Configure a VSC 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the Colubris Networks profile. 3. On the Add/Edit Virtual Service Community page: • Under General, enter the Name as Hotspot. • Under General, select the Use Colubris access controller check box.
Chapter 3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Public access deployment - 3000 series - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Chapter 3 Scenario 5: Custom HTML pages on each MAP This scenario shows you how to create a customized user experience based on the MAP with which a customer is associated.
Page 51
2. Create a file called logo.gif that contains a custom logo for the service being offered and place it in \newpages. 3. Copy the following files from the \Doc\Samples\External_Pages folder on the Colubris Networks documentation CD and place them in the newpages folder. • welcome.html • goodbye.html •...
Page 52
Configure the location-aware group name Set a unique group name on each MAP as follows: 1. Select VSC > Profiles. 2. Click the Colubris Networks profile to edit it. 3. Under General, make sure that the Use Colubris access controller checkbox is selected.
Page 53
Using the public access interface To use the condo internet service, tenants do the following: • Connect to the SSID Colubris Networks using 80211.b or g. • Start their web browser and enter the URL wireless.colubris.com which is the URL assigned to the MSC.
Page 55
• Click Save. Configure the VSC 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the Colubris Networks profile. 3. On the Add/Edit Virtual Service Community page: • Under HTML-based user logins: • Clear the Local authentication checkbox.
Page 56
(recommended size less than 20K). This same image file is shared by all pages. 3. Copy the following files from the \Doc\Samples\Internal_Pages folder on the Colubris Networks documentation CD and place them in the newpages folder. • login.html • transport.html •...
Page 57
Using the public access interface To use the internet service, customers do the following: • Connect to the SSID Colubris Networks using 80211.b or g. • Start their web browser and enter the URL wireless.colubris.com which is the URL assigned to the MSC.
Chapter 3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Public access deployment - 3000 series - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Chapter 3 Scenario 7: Multi-site installation (centralized architecture) This scenario shows you how to create a multi-site installation using multiple MSCs to tunnel traffic back to a central location.
Page 59
4. Click Save. Configure the VSC 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the Colubris Networks profile. 3. On the Add/Edit Virtual Service Community page: • Under General, select the Provide access control checkbox.
Public access deployment - 5000 series In this chapter you can find sample deployment strategies for common public access scenarios using a 5000 series MSC and one or more MAPs operating in controlled mode. When in controlled mode, all MAP configuration is handled by the MSC, greatly simplifying the task of deploying and managing a public access network.
(recommended size less than 20K). This same image file is shared by all pages. 3. Copy the following files from the \Doc\Samples\Internal_Pages folder on the Colubris Networks documentation CD and place them in the newpages folder. • login.html • transport.html •...
Page 68
Use the following steps to create three virtual service communities on all MAPs. 1. On the Main Menu, select VSCs. 2. In the VSC profiles table in the right pane, click the Colubris Networks profile to edit it. 3. On the VSC profile page: •...
Page 73
MSC will use to login. Enable RADIUS authentication of customers 1. On the Main Menu select VSCs. 2. In the VSC profiles table in the right pane, click the Colubris Networks profile to edit it. 3. On the VSC profile page: •...
(recommended size less than 20K). This same image file is shared by all pages. 3. Copy the following files from the \Doc\Samples\Internal_Pages folder on the Colubris Networks documentation CD and place them in the newpages folder. • login.html • transport.html •...
Page 77
Use the following steps to create three virtual service communities on all MAPs. 1. On the Main Menu, select VSCs. 2. In the VSC profiles table in the right pane, click the Colubris Networks profile to edit it. 3. On the VSC profile page: •...
802.11a, b, or g. How it works In this scenario an MSC-5000 series is used in conjunction with two MAP-330s. Both products support dual radios. The radios on all these devices are configured to operate as follows: •...
Page 84
LAN port is always sent to the first VSC profile. 1. On the Main Menu, select VSCs. 2. In the VSC profiles table in the right pane, click the Colubris Networks profile to edit it. 3. On the VSC profile page: •...
Page 89
A single VSC, called Hotspot, must be created to manage all traffic. 1. On the Main Menu, select VSCs. 2. In the VSC profiles table in the right pane, click the Colubris Networks profile to edit it. 3. On the VSC profile page: •...
Page 94
Using the public access interface To use the condo internet service, tenant’s do the following: • Connect to the SSID Colubris Networks using 80211.b or g. • Start their web browser and enter the URL wireless.colubris.com which is the URL assigned to the MSC.
Page 96
This enables them to obtain the list of available MSCs from any DHCP server that is properly configured to support the Colubris Networks Vendor Class. The Vendor Class enables an administrator to define a list of available MSC on the network that the MAPs can connect to.
Enterprise deployment Chapter 5 Enterprise deployment In this chapter you can find sample deployment strategies for common enterprise scenarios using series 3000 and series 5000 MSCs and one or more MAPs. These scenarios will give you a good idea about how to approach your installation.
Page 101
4. Set the static addressing parameters and click Save. Configure a VSC 1. Select VSC > Profiles. 2. Click the Colubris Networks profile in order to edit it. 3. Clear the Wireless security filters checkbox. 4. Under Wireless protection: • Select the checkbox and leave the default setting of WPA.
Page 103
RADIUS server. Under Confirm, reenter the shared secret. 5. Click Save. Configure a VSC 1. Select VSC > Profiles. 2. Click the Colubris Networks profile to edit it. 3. Clear the Wireless security filters checkbox. 4. Under Wireless protection • Select the checkbox.
Page 105
Use the following steps to define the three virtual service communities required for this scenario. 1. Select VSC > Profiles. 2. Click the Colubris Networks profile to edit it. • Under Name, enter Employee. • Under WLAN name (SSID), enter Employee.
Page 109
By default each MAP is configured to: • Automatically select the best operating frequency • Create a wireless network named Colubris Networks There is no need to change these settings for this scenario. Note: By default, one radio on the MAP-330 is used to provide the wireless network, and the other is placed into Monitor mode.
Page 113
1. On the Main Menu, select Service controller. 2. In the right pane, select Maintenance > Licenses. 3. Order a COS services pack license from Colubris Networks using the License ordering information. 4. Under Install license file, click Browse and select the license file sent to you by Colubris Networks.
Page 114
2 roaming on each MAP: 1. On the Main Menu, select VSCs. 2. In the right pane, click the Colubris Networks profile in the list. • Under General, disable Access control. This removes support for the public access interface and enables support for mobility features.
Page 116
1. On the Main Menu, select Service controller. 2. In the right pane, select Maintenance > Licenses. 3. Order a COS services pack license from Colubris Networks using the License ordering information. 4. Under Install license file, click Browse and select the license file sent to you by Colubris Networks.
In this scenario two MAPs are installed to provide wireless networking for an office. An MSC (3000 series or 5000 series) is also installed to provide a public access interface for guests. VLANs are used to segregate employee, guest, and management traffic on the backbone LAN.
Page 119
Chapter 5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Enterprise deployment - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Chapter 5 Configure the connection to the access controller By default, the MAPs are configured to use the default gateway returned by the DHCP server as the access controller.
Page 120
Use the following steps to define two VSCs (Private and Guest) on each MAP: 1. Select VSC > Profiles. 2. Click the Colubris Networks profile in the list to edit it. • Under General, set Name to Private. • Under General, disable Use Colubris access controller.
Page 121
Chapter 5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Enterprise deployment - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Chapter 5 Disable NAT on the Internet port For DHCP relay to work on the MSC, NAT must be disabled on the internet port.
Page 122
2. The Virtual service communities 2. In the VSC profiles table in the right page opens. Click the Colubris pane, click the Colubris Networks Networks profile in the list to edit it. profile to edit it. 3. Configure settings as follows: •...
WDS scenarios Chapter 6 WDS scenarios In this chapter you can find sample deployment strategies for using WDS—wireless distribution system—to wirelessly extend and interconnect networks.
Static links are best suited for deployments that rarely change, such as building-to- building links, or permanent wireless extensions. Using 802.1a Colubris Networks recommends using 802.11a for wireless bridging whenever possible. This optimizes throughput and reduces the potential for interference because: for WDS •...
Page 128
Chapter 6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - WDS scenarios- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Chapter 6 Configure the wireless network For optimum performance, the wireless channel used for the wireless bridge should be different and non-overlapping with the channel used to support wireless client stations.
Page 129
5. Click Save. Configure a VSC 1. Select VSC > Profiles. 2. Click the Colubris Networks profile in order to edit it. • Under General, set Name to 8021x. • Under SSID, set WLAN name to 8021x. • Clear the Wireless security filters checkbox.
Page 135
5. Click Save. Configure a VSC 1. Select VSC > Profiles. 2. Click the Colubris Networks profile in order to edit it. • Under General, set Name to 8021x. • Under SSID, set WLAN name to 8021x. • Clear the Wireless Security Filters checkbox.
Page 143
Use the following steps to create three virtual service communities on all MAPs. 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the Colubris Networks profile to edit it. 3. On the Add/Edit Virtual Service Community page: •...
Page 145
Use the following steps to create virtual service communities on the MSC that match each VSC you configured on the MAPs: 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the Colubris Networks profile to edit it. 3. On the Add/Edit Virtual Service Community page: •...
Page 149
Use the following steps to create three virtual service communities on all MAPs. 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the Colubris Networks profile to edit it. 3. On the Add/Edit Virtual Service Community page: •...
Page 151
Use the following steps to create virtual service communities on the MSC that match each VSC you configured on the MAPs: 1. On the Main Menu, select VSCs. 2. In the VSC profiles table in the right pane, click the Colubris Networks profile to edit it. 3. Configure settings as follows: •...
Page 159
Use the following steps to create virtual service communities on the MSC that match each VSC you configured on the MAPs: 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the Colubris Networks profile to edit it. 3. On the Add/Edit Virtual Service Community page: •...
• “ISC DHCP server” on page 166 A vendor class allows certain devices to request specific information from a Dynamic Host Configuration Protocol server. Specifically, the Colubris Networks vendor class enables you to define a list of available InMotion MultiService Controllers (MSCs) to which InReach MultiService Access Points (MAPs) can connect.
Windows Server 2003 This section shows you how to configure a Windows 2003 DHCP server to use the Colubris Networks vendor class. The following procedure assumes that you have a Windows 2003 Server that has a DHCP server configured and running.
This section shows you how to configure a Linux machine running an Internet Systems Consortium (ISC) DHCP server to use the Colubris Networks vendor class. The procedure assumes that you have a Linux or Unix server that is running the ISC DHCP server.
Configuring a legal intercept Chapter 8 Configuring a legal intercept This chapter explains how to configuring a legal intercept using a Colubris Networks MSC-3000 or MSC-5000 series MultiService Controller. “Wiretapping”—of which legal intercept is a part—comprises three steps: • Capture—Collecting a superset of information that contains the subset of what is desired.
Overview of In addition to a Colubris Networks MSC, this scenario requires a RADIUS server to process user login requests. In summary, you can redirect traffic into a GRE tunnel for...
Page 173
Note: The sample scenario shows screen shots from the MSC-5100; however, you can perform this procedure on any Colubris Networks MultiService Controller. In the left pane of 5000 series MSC, ensure that Service Controller remains selected, as shown in this scenario. This is not an issue for 3000 series MSCs.
Chapter 9: More from Colubris Chapter 9 More from Colubris In this chapter you can find information about the resources that are available to you at the Colubris website, as well as information about how to contact Colubris support, training, and sales.
• Software license agreement • Return Material Authorization (RMA) procedures and forms For Annual Colubris Networks offers a comprehensive set of annual support programs that focus on the hardware and software content of Colubris' award-winning family of secure Wi-Fi Maintenance solutions.