Summit x150 series summit x250e series summit x350 series summit x450 series summit x450a series summit x450e series summit x460 series summit x480 series summit x650 series (388 pages)
Summit x150 series summit x250e series summit x350 series summit x450 series summit x450a series summit x450e series summit x480 series summit x650 series (274 pages)
Extremexos summit family switches summit x150 series summit x250e series summit x350 series summit x450 series summit x450a series summit x450e series (170 pages)
Edge power over ethernet (poe) and non-poe switch providing intelligent 10/100base-t connectivity (16 pages)
Summary of Contents for Extreme Networks Summit WM100
Page 1
Summit WM Getting Started Guide Extreme Networks, Inc. 3585 Monroe Street Santa Clara, California 95051 (888) 257-3000 (408) 579-2800 http://www.extremenetworks.com Published: March 2007 Part number: 120385-00 Rev 01...
The ExtremeXOS operating system is based, in part, on the Linux operating system. The machine-readable copy of the corresponding source code is available for the cost of distribution. Please direct requests to Extreme Networks for more information at the following address:...
• Summit SwitchWM1000 • Summit Switch WM100 The guide is written for Extreme Networks’ clients. You must be familiar with computer networking concepts to use this guide. This contents in this guide are organized under the following chapters: • Chapter 1, “About this guide”–...
WM-AD via the Summit WM Switch. • Chapter 9, “Availability and Mobility configuration” configure availability and mobility features via the Summit WM Switch. The document uses the following formatting conventions to make it easier to find information and follow procedures: •...
If you have any problems using this document, please contact the next level of support: • Customers should contact the Extreme Networks Technical Assistance Center (TAC). When you call, please have the following information ready. This will help us to identify the document that you are referring to.
Page 10
HWC_GSG_Preface.fm About this guide Document feedback 120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide...
The Summit WM Switch is driven by Summit WM-Series WLAN Switch Software. The software resides on the Summit WM Switch and provides an intuitive web- based interface — Extreme Networks Summit WM-Series Console to enable you to manage the entire wireless network from a wired laptop, or a PC connected to the network.
Extreme Networks Summit WM- Series Console. You can separately configure, enable, or disable each Altitude AP from the Summit WM Switch using the Extreme Networks Summit WM-Series Console. The Extreme Networks Summit WM-Series Console also allows you to group the APs of similar attributes into one of ten upgrade profiles for the purpose of deploying software upgrades.You can initiate the software updates on a profile...
Scan results are then forwarded to the Summit WM Switch; the Summit WM Switch processes and presents the data centrally. Rogue detection data can be viewed via the Extreme Networks Summit WM-Series Console. 2.1.1.5 Automatic assignment of IP addresses to the client...
Page 14
Ethernet Ethernet Figure 1 Summit WM-Series WLAN topology The Summit WM Switch supports the following network elements. • RADIUS Server (Remote Access Dial-in User Service) – An authentication server that assigns and manages ID and Password protection throughout the network. The RADIUS server system can be set-up for certain standard attributes such as filter ID, and for the vendor specific attributes (VSAs).
In larger installations, a directory agent collects information from service agents and creates a central repository. SLP is one of the several modes that the Summit WM Switch uses to discover the Altitude APs.
The mobility agents discover the mobility manager by one of the following modes: • SLP with DHCP Option 78 – The mobility agent on each Summit WM Switch discovers the address of the mobility manager using DHCP Option 78. •...
120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide Summit WM-Series WLAN Switch Software Solution 2.1.5.1 DHCP for Altitude APs DNS Server Summit WM Switch Altitude AP Wireless Device Figure 2 DHCP for Altitude APs You can use Windows 2003 server, amongst others, for deploying DHCP service for Altitude APs.
Altitude AP Wireless Device Figure 3 DHCP for WM-AD The DHCP configuration for WM-AD is done via Summit WM Switch. For more information, see Section 8.2, “Creating and configuring a Routed WM-AD”, on page * The wireless device requests an IP address from...
DHCP Server Wireless Device Figure 4 DHCP relay for WM-AD The DHCP relay configuration is done via Summit WM Switch. For more information, see Section 8.2, “Creating and configuring a Routed WM-AD”, on page Conceptual model * A wireless device sends a...
Wireless Device Figure 5 DHCP for traffic bridged locally at Altitude AP The DHCP relay configuration is done via Summit WM Switch. For more information, see Section 8.4, “Creating and configuring a Bridge Traffic Locally At WAP WM-AD”, on page 101.
Page 21
Figure 6 Summit Switch WM2000 front panel Media Flash 1000 Card Data Ports RJ45 Port Supervisor 1100 Card The Summit Switch WM2000 has five LED lights and two switches on its front panel. Seven-Segment Reset Display Switch Figure 7 Summit Switch WM2000’s LED lights and switches The description of the LED states and switches is provided below: •...
• Diagnostic Switch – Pressing the Reset and Diagnostic switch simultaneously reboots the system in diagnostic mode. Note: The diagnostic switch should be used only upon the request of a service technician. • INT LED – Not used in the current release.
Page 23
120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide Summit WM-Series WLAN Switch Software Solution Active Warning Error SSD Code Green Yellow Green Yellow Green Yellow Table 2 LED states and SSD codes during warning conditions Error conditions: Active...
ACTIVITY LED – For more information, see the ACTIVITY LED description in Section 2.2.4, “Summit Switch WM1000 back panel”, on page These two LED lights are also located on the back panel of the Summit Switch WM1000. Section 2.2.1, “Summit Switch WM2000 front panel”,...
The following figure identifies the main components on the back panel of Summit Switch WM1000. Management Port Note: Summit Switch WM1000 back panel The Summit Switch WM1000may have a standard power supply (one power supply) or a redundant power supply (two power supplies).
Summit WM Switch’s physical description • STATUS LED – Indicates the normal state of the Summit WM Switch as seen by the system’s software. This LED covers all stages of the Summit WM Switch, ranging from restarting, to shutting-down. As long as the Summit WM Switch is running normally, this LED will remain lit.
Figure 11 Summit Switch WM100 back panel Note: The Summit Switch WM100 has the same number of LED lights on the back panel as the Summit Switch WM1000. The LED description of their state is also identical to WM1000. For information on Summit Switch WM100’s LEDs’ states, see the descriptions of STATUS LED and ACTIVITY LED in panel”, on page...
You can use any IP address between 192.168.10.2 and time 192.168.10.255. • Factory default IP address of Summit WM Switch – The factory default IP address is https//192.168.10.1:5825. You must type this IP address in the address bar of your Web browser when you access the Summit WM Switch for the first time.
Page 29
IP Address – If you are using WM-AD, you will need the WM-AD’s installing DHCP IP address. service If you are not using WM-AD, you will need the Summit WM Switch IP address. Table 4 Information gathering table 120385-00 Rev 01, March 2007...
Page 30
IAS IAS service. in Windows 2003 • Accounting Port – Type the Summit WM Switch’s port # that is server used to access the accounting service. The values you record here should match what you define in the Port text box of Auth section in the Acc &...
Page 31
• OSPF routing cost – The OSPF cost value provides a relative cost indication to allow upstream routers to calculate whether or not to use the Summit WM Switch as a better fit, or lowest cost path to reach the devices in a particular network. The higher the...
Page 32
Authentication • Port – Used to access the RADIUS server. The default is 1812. and Accounting • # of Retries – The number of times the Summit WM Switch will information for attempt to access the RADIUS server. captive portal •...
Page 33
• IP address of primary Summit WM Switch’s physical port • IP address of secondary Summit WM Switch’s physical port Mobility manager • Port – The interface of the Summit WM Switch that is to be used information as the mobility manager. Ensure that the selected interface is routable on the network.
Page 34
HWC_GSG_Chapter 1_Overview.fm Summit WM-Series WLAN Switch Software Solution Collecting information for installation 120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide...
Generating a software license key • Applying a license key You can access the Summit WM-Series WLAN Switch (Summit WM Switch) by using a laptop computer with a Web browser. To access the Summit Switch using a web-enabled laptop: 1. Connect the Summit WM Switch’s management port to the web-enabled laptop computer with a cross-over RJ 45 Ethernet cable.
Page 36
Networks Summit WM-Series Console login screen is displayed. 5. In the User Name text box, type admin. 6. In the Password text box, type abc123. 7. Click Login. The Extreme Networks Summit WM-Series Console is displayed. 120385-00 Rev 01, March 2007...
Page 37
Summit WM, Getting Started Guide Summit WM-Series WLAN Switch configuration Accessing the Summit WM-Series WLAN Switch for the first time Note: In the footer of the Extreme Networks Summit WM-Series Console, the following is displayed: •[host name | product name | up time] •For example, [WM2000 | WM2000 | 1 days, 1:11].
Page 38
HWC_GSG_Chapter 2_Default_Settings.fm Summit WM-Series WLAN Switch configuration Accessing the Summit WM-Series WLAN Switch for the first time 9. In the left pane, click IP Addresses. The factory default settings for the Summit Switch are displayed. 120385-00 Rev 01, March 2007...
Page 39
Configuration screen is displayed. 11. Type the following information: • Hostname – Specifies the name of the Summit Switch by which it will be known. You must assign a unique name for the Summit Switch. • Domain – Specifies the IP domain name of the enterprise network.
2. Connect the Summit Switch management port to the enterprise Ethernet LAN. The Summit Switch resets automatically. 3. Log on to the Extreme Networks Summit WM-Series Console from any computer on the enterprise network. Type the following URL in a browser to access the Extreme Networks Summit WM-Series Console: tap://<IP...
3.4.1 Configuring the network time using the system’s time To configure the network time, using the system’s time: 1. Login on the Summit Switch. The Extreme Networks Summit WM-Series Console screen is displayed. 2. Click Summit Switch Configuration. The Summit Switch Configuration screen is displayed.
Page 42
System Time text box. The date is in mm-dd-yyyy format and the time is in hh:mm format. 9. Click Apply. 10. Reboot the Summit Switch. The WLAN network time is synchronized in accordance with the Summit Switch’s time. 120385-00 Rev 01, March 2007...
You must have the following information before you start the license generation process: • CLS URL – Is provided in the Summit WM Switch Base Software Activation document. • Login information (User Name and Password) – Is provided in the Summit WM Switch Base Software Activation document.
Page 44
3. Select the Summit Switch WM-Series WLAN Switch Software version for which you want to generate the license key. To view the software features, click the + node against the Summit Switch WM-Series WLAN Switch Software. 120385-00 Rev 01, March 2007...
Page 45
120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide Summit WM-Series WLAN Switch configuration 4. Click Generate Key. The License Generation Key Details screen is displayed. 5. In the MAC Address and Serial Number text boxes, type the MAC address and the serial number of the hardware.
Page 46
13. To save the file, click Save. The Save As window is displayed. 14. Save the file on your local drive. Now that you have generated a software license key, you must apply this key to the hardware (Summit WM Switch). For more information, see “Applying a license key”.
8. Save the file on your local drive. To apply the license: 1. Login on the Summit Switch. 2. From the main menu, click Summit Switch Configuration. The Summit Switch Configuration screen is displayed. 3. In the left pane, click Software Maintenance.
Page 48
5. In the Apply Product Key section, click Browse to navigate to the location of the software license file, and select the file. 6. Click Apply Now. The software license key is applied, and the Summit Switch reboots. Now you must configure the Summit WM Switch’s physical ports. The following chapter describes how to configure the Summit WM Switch’s physical ports.
The Summit WM Switch supports OSPF as the dynamic routing protocol. The Summit WM Switch is shipped from the factory with all of its data ports set- up as host ports. You must set-up or configure how each port should function.
VLAN ID to the port, all packets associated with the port would be tagged with the corresponding VLAN. This enables the Summit WM Switch to directly connect to a VLAN network without the need to remove VLAN tags at the connection port.
Page 51
Note: The number of ports displayed on the Management Port Settings screen (on the GUI) reflects the number of physical ports the Summit WM Switch has. For example, the Summit Switches, WM2000, WM 200, and WM100 have four data ports, and hence the Management Port Settings screen will display four ports.
Page 52
10. To save your changes, click Save. 11. Repeat Step 3 to Step 10 for every port that is to be enabled. Now you must configure the routing on the Summit WM Switch. The following chapter describes how to configure the Summit WM Switch’s physical ports.
• Configuring the OSPF routing To configure a static route: 1. From the main menu, click Summit Switch Configuration. The Summit Switch Configuration screen is displayed. 2. In the left pane, click Routing Protocols. The Routing Protocols screen is displayed.
5. Type the IP address of the specific router port or gateway that serves as the next-hop for the packets from Summit WM Switch (default gateway). This router port (or gateway) must be on the same subnet as the Summit WM Switch.
• Timer Settings – If the peer router has different timer settings, the protocol timer settings in the Summit WM Switch must be changed to the peer router to match in order to achieve OSPF adjacency. •...
3. Click the OSPF tab. 4. From the OSPF Status drop-down list, click ON to enable OSPF. 5. In the Router ID text box, type the IP address of the Summit WM Switch. The router ID must be unique across the OSPF area.
Note: If more than one port is enabled for OSPF, you must prevent the Summit WM Switch from serving as a router for the other traffic. In order to do this, you must set the Link Cost to its maximum value of 65535.
5.2.2.1 Confirming the ports are set for OSPF To confirm the ports are set for OSPF: 1. From the main menu, click Summit Switch Configuration. The Summit Switch Configuration screen is displayed. 2. On the Routing Protocols screen, click View Forwarding Table. The Forwarding Table is displayed.
Page 59
120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide 4. Click the OSPF Linkstate tab. If OSPF protocol is enabled, the report displays the link state advertisement (LSAs) received by the running OSPF protocol. 5. To update the screen, click Refresh. Now you must configure the DHCP, DNS and RADIUS servers on the network.
Page 60
HWC_GSG_RouterConfiguration.fm Routing configuration Configuring the OSPF routing 120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide...
IP addresses meant to be distributed by the DHCP server to the client devices on a subnet. The SLP DA is used by: • The Altitude APs to discover the Summit WM Switch. • The mobility agents to discover the mobility manager. Configuring DHCP, DNS and IAS services...
Page 62
DHCP service configuration To configure DHCP in Window 2003 Server: 1. Click Start, point to Administrative Tool, and then click DHCP. 2. In the console tree, right-click the DHCP server on which you want to create the new DHCP scope, and then click New Scope. 3.
Page 63
120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide A subnet mask defines how many bits of an IP address to use for the network/ subnet IDs and how many bits to use for the host ID. You can specify the subnet mask by length or as an IP address.
Page 64
DHCP service configuration 15. Click Next. The Domain Name and DNS Servers window is displayed. 16. In the Parent domain text box, type your company’s domain name. You must use the Parent Domain provided by your network administrator. 17. In the Server name text box, type your server name. You must use the Server name provided by your network administrator.
Note: here is no SLP deployment on the enterprise network, the Summit WM Switch is configured to act as a DA by default. If you put the Summit WM Switch’s IP address(es) in a DHCP server for Option 78, Altitude APs will interact with the Summit WM Switch for discovery.
Page 66
The following is the example of DHCP configuration on a Red Hat Linux Server. For Altitude AP subnet true For WM-AD subnets (In Summit WM Switch it is configured as Use DHCP Relay) if you are utilizing multiple WM-ADs you must configure the Red Hat Linux server for every WM-AD.
IAS service configuration 6.2.1 Installing IAS on Windows 2003 Server You must install IAS on Windows 2003 Server according to the documentation provided with the server. You may also visit how to install IAS on Windows 2003. 6.2.2 Enabling IAS to authenticate users in active directory To enable IAS to authenticate users in active directory: 1.
Page 69
7. In the Authentication text box, type the Summit WM Switch’s port # that is used to access the authentication (IAS) service. 8. In the Accounting text box, type the Summit WM Switch’s port # that is used to access the accounting service.
Page 70
Similarly, the values you type in the Accounting text box, should match the value that you define in the Port text box of Acct section in the Acc & Acct tab of Summit WM Switch’s WM-AD screen.For more information, see Section 8.5, “Configuring authentication mechanism for WM-AD”...
120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide 6.2.4 Configuring Summit WM Switch as IAS client To configure Summit WM Switch as IAS client: 1. Click Start, point to Administrative Tool, and then click Internet Authentication Service. 2. Right-click Clients, and then New Client.
Note: This password is case-sensitive. You can use alphanumeric characters as well as special characters. The password must be between 16 and 24 characters in length. You must configure the shared secret password in Summit WM Switch. For more information, see Section 8.5.1.2, “Configuring external Captive Portal authentication”,...
Page 73
HWC_GSG_ConfiguringExternalServers.fm Configuring DHCP, DNS and IAS services IAS service configuration 7. Click Next. The Policy Configuration Method window is displayed. 120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide...
Page 74
IAS service configuration 8. Select Use the wizard to set up a typical policy for a common scenario. 9. In the Policy name text box, type the name you want to assign to the policy, and then click Next. The Access Method window is displayed. 120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide...
Page 75
120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide 10. Select Wireless and then click Next. The User or Group Access window is displayed. 11. Select User or Group, and click Next. The Authentication Methods window is displayed. Configuring DHCP, DNS and IAS services IAS service configuration...
18. Click Add. The Attributes window is displayed. 19. Select IP address. The Client IP-Address window is displayed. 20. In the Client IP-Address window, type the Summit WM Switch’s IP address. 21. Click OK. The domain name system (DNS) stores and associates many types of information with domain names, but most importantly, it translates domain names (computer hostnames) to IP addresses.
120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide 6.3.1 Configuring DNS for internet access To configure DNS for internet access: 1. Click Start, point to All Programs, point to Administrative Tools, and then click Configure Your Server Wizard. 2.
DNS service configuration 5. In the Primary Server Location window, select This server maintains the zone, and then click Next. The Zone name window is displayed. 6. In the Zone name text box, type the name of the DNS zone for your network, and then click Next.
Page 79
7. In the Name text box, type the Summit WM Switch’s name. 8. In the IP address text box, type the Summit WM Switch’s IP address. 9. Select Create associated pointer (PTR) record checkbox. 10. Click Add Host. The new host is displayed in the right pane of the screen.
Page 80
HWC_GSG_ConfiguringExternalServers.fm Configuring DHCP, DNS and IAS services DNS service configuration 120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide...
• 5 GHz radio supporting the 802.11a standard The radios on the Altitude APs are enabled or disabled through the Extreme Networks Summit WM-Series Console. For more information, see the Chapter 5 – Configuring the Altitude AP of Summit WM-Series WLAN Switch Software WM2000 User Guide.
2. In the left pane, click WAP Registration. 3. In the Security Mode section, select one of the following options: Note: Security mode is a Summit WM Switch property. It defines how the Summit WM Switch behaves when registering new devices. During the registration process, the Summit WM Switch’s approval of the Altitude APs depends on the security mode that...
Page 83
Altitude AP. As long as the Altitude AP is in pending state, it receives minimum configuration that only allows it to maintain an active link with the Summit WM Switch for future state change. For more information, see approving pending Altitude •...
Configuring the Altitude APs for the first time 7.2.1 Manually approving pending Altitude APs If the Summit WM Switch does not recognize the Altitude AP, the Altitude AP’s registration record is created in pending state. You must manually approve a pending Altitude AP.
Name – By default, this text box contains the serial number of the Altitude • Description – Short description of the Altitude AP. • Port # – Summit WM Switch’s ethernet port to which the Altitude AP is connected. • Poll Timeout – The timeout value for polling the Summit WM Switch. The value is in seconds.
Maintain client session in event of poll failure – Select this option, if you want the Altitude AP to remain active in case the link with the Summit WM Switch is lost. This allows service for the branch WM-ADs to continue during temporary network outages.
Page 87
3. In the IP Address Assignment section, select Use DHCP. 4. In the Add text box, type the IP address of the Summit WM Switch that will manage this Altitude AP. 5. Click Add. The IP address is added to the list.
Page 88
Configuring static IP address for Altitude APs 8. From the main menu, click Reports & Displays. The Reports and Displays screen is displayed. 9. Click Active Altitude APs. A list of active Altitude APs is displayed with the corresponding IP addresses assigned to them by the DHCP server. 120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide...
Page 89
120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide 10. Locate the Altitude AP for which you are configuring the static IP address in the list, and the corresponding IP address. 11. From the main menu, click Altitude AP Configuration. The Altitude AP screen is displayed.
Page 90
Configuring static IP address for Altitude APs 12. Click the Static Configuration tab. 13. In the IP Address Assignment section, select Static Values. 14. In the IP Address text box, type the IP address that you obtained by using the DHCP server (or any other assigned IP address). 15.
Altitude AP will lose connection with the Summit WM Switch after it is rebooted (the Altitude AP reboots when the configuration settings are saved). If the Altitude AP does not lose connection with the Summit WM Switch after the reboot, it indicates that the VLAN ID has not been configured correctly.
The Altitude AP boot-up sequence includes a random delay interval, followed by a vulnerable time interval. During the vulnerable time interval (2 seconds), the LEDs flash in a particular sequence to indicate that the Summit WM Switch is in the vulnerable time interval. For more information, see LED states”, on page...
No DHCP reply has been received. Failed discovery (SLP) Summit WM Switch has been discovered. Registering the Altitude AP. Registration of the Altitude AP has failed. Standby, registered with a Summit WM Switch, waiting for configuration. Altitude AP’s configuration Altitude AP’s LED states...
Page 94
Note: Random delays do not occur during normal reboot. A random delay only occurs after vulnerable period power-down. Now you must configure the WM-AD via the Summit WM Switch using the Extreme Networks Summit WM-Series Console. The following chapter explains how to configure the WM-AD. 120385-00 Rev 01, March 2007...
120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide This chapter explains how to configure the WM-AD through the Summit WM Switch using the Extreme Networks Summit WM-Series Console. The topics in this chapter are organized as follows: •...
Page 96
• VLAN bridged WM-AD (Bridge Traffic Locally at SWM) – The user traffic is tunneled to the Summit WM Switch and is directly bridged with it to a specific VLAN. Note: Only the following models support VLAN bridged WM-AD (Bridge Traffic Locally at SWM): •...
8.2 Creating and configuring a Routed WM-AD 120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide The user traffic is tunneled to the Summit WM Switch in Routed WM-AD type. This is the default set-up. To create and configure a Routed WM-AD type: 1.
Page 98
5. From the DHCP drop-down list, click one of the two options: • Local DHCP Server: If you select Local DHCP Server, the built-in DHCP server in Summit WM Switch provides the IP addresses to the devices to the wireless network. For more information, see for WM-AD”, on page •...
Page 99
• Use DHCP Relay: If you select Use DHCP Relay, the local DHCP server on the Summit WM Switch is disabled and the Summit WM Switch instead forwards DHCP requests to the external DHCP server for dynamic IP addresses allocation. For more information, see relay for WM-AD”, on page 19...
Summit WM Switch as a better fit, or lowest cost path to reach the devices in a particular network. The higher the cost, the less likely that the Summit WM Switch will be chosen as a route for traffic, unless that Summit WM Switch is the only possible route for that traffic.
DHCP server or the local DHCP server on the Summit WM Switch. For more information, see Step # • VLAN ID – The ID #of VLAN that is mapped to a Summit WM Switch interface. • Interface – The name of the interface to which the VLAN is mapped.
RADIUS server. The RADIUS server is still needed. The internal Captive Portal within the Summit WM Switch displays the webpage to enable the users to supply their user name and password. The user name and password are sent to the configured RADIUS server for authentication.
120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide Configuring authentication mechanism for WM-AD Figure 13 Authentication options MAC-based authentication can be used in both SSID network assignment and AAA network type assignment. 8.5.1 Authentication mechanism for SSID network assignment The SSID network assignment provides the following authentication options: •...
6. Type the appropriate values in the Auth text boxes. • Port – Used to access the RADIUS server. The default is 1812. • # of Retries – Number of times the Summit WM Switch will attempt to access the RADIUS server. WM-AD”; 120385-00 Rev 01, March 2007...
Page 105
Summit WM, Getting Started Guide Configuring authentication mechanism for WM-AD • Timeout – Maximum time for which Summit WM Switch will wait for a response from the RADIUS server before making a re-attempt. • NAS Identifier – RADIUS attribute that identifies the server responsible for passing information to the designated servers and then acting on the response returned.
Page 106
Configuring authentication mechanism for WM-AD 11. Click Configure Captive Portal Settings. The Captive Portal Configurations screen is displayed. 12. Select the Internal Captive Portal option. 13. Type the values in the following text boxes: • Login Label – The text that will appear as a label for the user name. •...
Page 107
120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide Configuring authentication mechanism for WM-AD • Replace Gateway IP with FQDN – If you are using FQDN (Fully Qualified Domain Name) as the gateway address, you must type the FQDN in this text box. •...
2. Click Configure Captive Portal option. The Captive Portal Configuration screen is displayed. 3. Select the External Captive Portal option. 4. In the SWM Connection drop-down list, click the Summit WM Switch’s IP address. 5. In the Port text box, type the Summit WM Switch’s port.
By default, a new WM-AD with SSID network assignment type is assigned None authentication. A SSID WM-AD with this set-up circumvents all authentication mechanisms and the Summit WM Switch accepts all wireless devices without any authentication. However, even with None authentication option, you can still control access to the network by defining appropriate filtering rules for Non-authenticated filters.
• Port – Port used to access the RADIUS server. The default is 1812. • # of Retries – Number of times the Summit WM Switch will attempt to access the RADIUS server. • Timeout – Maximum time for which Summit WM Switch will wait for a response from the RADIUS server before making a re-attempt.
120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide Configuring authentication mechanism for WM-AD • Auth Type – Provides four options for the authentication protocol to be used by the RADIUS server to authenticate the wireless device users: • PAP –...
Now you must configure the WM-AD for filters. The following section describes how to configure the WM-AD filters. On a per WM-AD basis, the Summit WM Switch can be configured to apply a specific filtering policy on the user traffic that is routed through it. The filtering policies are applied after the authentication is returned.
Default Gateway (WM-AD interface IP) Any HTTP streams requested by the client for denied targets will be redirected to the specified location. For more information, see the Summit WM-Series WLAN Switch Software WM2000 User Guide. To configure rules for the Non-authenticated filter. WM-AD configuration...
Configuring filtering rules 1. From the main menu, click WM Access Domain Configuration. The WM Access Domain Configuration screen is displayed. 2. In the left pane, select the SSID WM-AD for which you want to configure the Non-authenticated filtering rules. The Topology tab is displayed. 3.
Privacy is a mechanism that protects data over wireless and wired networks using encryption techniques. The Summit WM Switch provides several privacy mechanism to protect data over the WLAN. The privacy mechanism can be classified on the basis of network assignment types —...
120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide • Input Hex – If you enable Input Hex, the WEP Key text box is displayed. Type the WEP Key manually in this text box. • Input String – If you select Input String, the following two text boxes are displayed –Strings and WEP Key.
Configuring privacy for WM-AD The Encryption drop-down menu offers you the following two options: • Auto – If you click Auto, the Altitude AP will advertise both TKIP and CCMP (counter mode with cipher block chaining message authentication code protocol). •...
120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide • Wi-fi Protected Access (WPA) version 2 with encryption by advanced encryption standard with counter-mode/CBC-MAC protocol (AES-CCMP) 8.7.2.1 Configuring Static WEP To configure Static WEP: 1. From the main menu, click WM Access Domain Configuration. The WM Access Domain Configuration screen is displayed.
Page 120
Step 1 – The wireless device associates with Altitude AP. • Step 2 – The Altitude AP blocks the wireless device’s network access while the authentication process is carried out. The Summit WM Switch sends the authentication request to the RADIUS authentication server. •...
Page 121
8. To save your changes, click Save. You have completed the WM-AD configuration. Now you must configure the Summit WM Switch’s availability and mobility features. The following chapter describes how to configure the Summit WM Switch’s availability and mobility features.
Page 122
HWC_GSG_VNSConfiguration.fm WM-AD configuration Configuring privacy for WM-AD 120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide...
Altitude APs are allowed to connect to the other Summit WM Switch. The Altitude APs that connect to a backup Summit WM Switch during a failover are assigned to the WM-AD that is defined in the Summit WM Switch’s default Altitude AP configuration.
High-level overview of the availability configuration process The following is a high-level overview of the availability configuration process: • Step 1 – Define a WM-AD with the same SSID on each Summit WM Switch. For more information on how to define a WM-AD, see configuration”.
To assign radios to WM-AD and change the poll timeout value: 1. Login on both the Summit WM Switches. 2. From the main menu of the primary Summit WM Switch, click Altitude AP Configuration. The Altitude A P Configuration screen is displayed.
Page 126
Configuring availability feature 1. Login on both the Summit WM Switches. 2. From the main menu of the primary Summit WM Switch, click Altitude AP Configuration. The Altitude AP Configuration screen is displayed. 3. In the left pane, click WAP. The WAP screen is displayed.
7. From the main menu of the primary Summit WM Switch, click Altitude AP Configuration. 8. In the Summit WM Switch IP Address text box, type the IP address of the physical port of the secondary Summit WM Switch. 9. Select Current Summit Switch is primary connection point.
Green – The Altitude AP is configured on the Summit WM Switch and is currently connected. • Red – The Altitude AP is configured on the Summit WM Switch but is currently not connected (not available to service this Summit WM Switch). 124.
120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide To view the Altitude AP availability display: 1. From the main menu, click Reports & Display. The Reports & Displays screen is displayed. 2. In the List of Displays, click Altitude AP Availability. The Altitude AP Availability Display appears.
Summit WM Switches as mobility agents. The wireless device keeps the IP address, WM-AD assignment, and filtering rules it received from its home Summit WM Switch— the Summit WM Switch to which it was first connected. The WM-AD on each Summit WM Switch must have the same SSID and RF privacy parameter settings for seamless roaming to occur.
Any user that roamed away from their home Altitude AP is terminated and must reconnect, re-authenticate and obtain a new IP address. To configure mobility feature, you must define one Summit WM Switch as the mobility manager and other Summit WM Switches as mobility agents.
Page 132
Configuring mobility Note: The Mobility Manager link is not displayed in the left pane with the demo license. 120385-00 Rev 01, March 2007 Summit WM, Getting Started Guide...
Page 133
4. Select the This Summit Switch is a Mobility Manager option. The mobility manager options are displayed. 5. In the Port drop-down list, click the interface of the Summit WM Switch that is to be used as the mobility manager.
Option 78 SLP DA, see DHCP in Windows 2003 Server”, on page 8. In the Add text box, type the IP address of the Summit WM Switch mobility agent. The IP address is displayed in the Permission List box.
Summit WM Switch that will serve as the mobility manager. 8. To save your changes, click Save. 9.4.2.1 Viewing the Mobility Manager display If you have configured a Summit WM Switch as a mobility manager, two additional displays appear on the Reports & Displays screen: •...
9.4.2.2 Viewing Mobility Agent display If you have configured a Summit WM Switch as a mobility agent, an additional display — Agent Mobility Tunnel Matrix — appears on the Reports & Displays screen.