Radio management commands WLAN is supported only on the MSR954(JH297A/JH298A/JH299A). The term "AP" in this document refers to MSR routers that support WLAN. a-mpdu Use a-mpdu enable to enable the A-MPDU aggregation method. Use a-mpdu disable to disable the A-MPDU aggregation method. Use undo a-mpdu to restore the default.
Predefined user roles network-admin Usage guidelines This command is applicable only to 802.11n radios. Changing the radio mode to 802.11a, 802.11b, or 802.11g invalidates the command. The device can receive but cannot send A-MSDUs. Examples # Disable the A-MSDU aggregation method. <Sysname>...
undo antenna type Default The antenna type is external. Views Radio interface view Predefined user roles network-admin Parameters antenna-type: Specifies an antenna type, a string of 1 to 10 characters. Usage guidelines Perform this task to set the antenna type for the AP. The antenna type setting for the AP must be consistent with the type of the antenna used on the AP.
channel Use channel to specify a working channel for a radio interface. Use undo channel to restore the default. Syntax channel { channel-number | auto } undo channel Default The auto mode is used. Views Radio interface view Predefined user roles network-admin Parameters channel-number: Specifies a channel by its number.
Parameters 20: Sets the bandwidth mode to 20 MHz. 40: Sets the bandwidth mode to 40 MHz. Usage guidelines This command is applicable only to 802.11n radios. When you change the mode of a radio, the default setting of this command for the new radio mode is restored. If the current channel of a radio does not support the specified bandwidth mode, the radio clears the channel configuration and selects another channel.
Use client dot11n-only disable to disable the client dot11n-only feature. Use undo client dot11n-only to restore the default. Syntax client dot11n-only { disable | enable } undo client dot11n-only Default The client dot11n-only feature is disabled. Views Radio interface view Predefined user roles network-admin Usage guidelines...
Examples # Set the maximum number of clients that can associate with the AP to 38. <Sysname> system-view [Sysname] interface wlan-radio 0/0 [Sysname-WLAN-Radio0/0] client max-count 38 custom-antenna gain Use custom-antenna gain to set the antenna gain. Use undo custom-antenna gain to restore the default. Syntax custom-antenna gain antenna-gain undo custom-antenna gain...
Default The maximum transmission distance is 1 km (0.62 miles). Views Radio interface view Predefined user roles network-admin Parameters distance: Specifies the maximum transmission distance in the range of 1 to 40 km (0.62 to 24.86 miles). Examples # Set the maximum transmission distance to 5 km (3.11 miles). <Sysname>...
[Sysname-WLAN-Radio0/1] dot11g protection enable Related commands protection-mode dot11n mandatory maximum-mcs Use dot11n mandatory maximum-mcs to set the maximum mandatory MCS index. Use undo dot11n mandatory maximum-mcs to restore the default. Syntax dot11n mandatory maximum-mcs index undo dot11n mandatory maximum-mcs Default No maximum mandatory MCS index is set.
Views Radio interface view Predefined user roles network-admin Parameters index: Specifies the multicast MCS index in the range of 0 to 76. Usage guidelines This command is applicable only to 802.11n radios. Changing the radio mode to 802.11a, 802.11b, or 802.11g invalidates the command.
Examples # Enable 802.11n protection. <Sysname> system-view [Sysname] interface wlan-radio 0/1 [Sysname-WLAN-Radio0/1] dot11n protection enable Related commands protection-mode dot11n support maximum-mcs Use dot11n support maximum-mcs to set the maximum supported MCS index. Use undo dot11n support maximum-mcs to restore the default. Syntax dot11n support maximum-mcs index undo dot11n support maximum-mcs...
Default The DTIM interval is 1. The AP sends buffered broadcast and multicast frames after every beacon frame. Views Radio interface view Predefined user roles network-admin network-operator Parameters counter: Specifies the DTIM interval in the range of 1 to 31. Usage guidelines An AP periodically broadcasts a beacon compliant with the DTIM.
Examples # Set the fragmentation threshold to 2048 bytes. <Sysname> system-view [Sysname] interface wlan-radio 0/1 [Sysname-wlan-radio0/1] fragment-threshold 2048 green-energy-management Use green-energy-management enable to enable the energy-saving feature. Use green-energy-management disable to disable the energy-saving feature. Use undo green-energy-management to restore the default. Syntax green-energy-management { disable | enable } undo green-energy-management...
Views Radio interface view Predefined user roles network-admin Usage guidelines This command is applicable only to 802.11n radios. Changing the radio mode to 802.11a, 802.11b, or 802.11g invalidates the command. The device can receive but cannot send LDPC packets. Examples # Disable LDPC.
Related commands short-retry threshold max-power Use max-power to set the maximum transmit power. Use undo max-power to restore the default. Syntax max-power radio-power undo max-power Default The AP uses the maximum supported transmit power. Views Radio interface view Predefined user roles network-admin Parameters radio-power: Specifies the maximum transmit power.
Views Radio interface view Predefined user roles network-admin Parameters 1x1: Sends and receives signals through one spatial stream. 2x2: Sends and receives signals through two spatial streams. Usage guidelines MIMO enables a radio to send and receive wireless signals through multiple spatial streams. This improves system capacity and spectrum usage without requiring higher bandwidth.
[Sysname-WLAN-Radio0/1] type dot11g [Sysname-WLAN-Radio0/1] preamble long protection-mode Use protection-mode to specify a collision avoidance mode. Use undo protection-mode to restore the default. Syntax protection-mode { cts-to-self | rts-cts } undo protection-mode Default The CTS-to-self mode is used. Views Radio interface view Predefined user roles network-admin Parameters...
Syntax protection-threshold size undo protection-threshold Default The RTS threshold is 2346 bytes. Views Radio interface view Predefined user roles network-admin Parameters size: Specifies the RTS threshold in the range of 0 to 2346 bytes. Usage guidelines The system performs collision avoidance only for packets larger than the RTS threshold. Examples # Set the RTS threshold to 2048 bytes.
Mandatory rates—1, 2, 5.5, and 11. Multicast rate—Selected from the mandatory rates. Supported rates—6, 9, 12, 18, 24, 36, 48, and 54. Views Radio interface view Predefined user roles network-admin Parameters disabled: Specifies rates that cannot be used by an AP. mandatory: Specifies rates that the clients must support to associate with an AP.
Predefined user roles network-admin Usage guidelines This command is applicable only to 802.11n radios. Changing the radio mode to 802.11a, 802.11b, or 802.11g invalidates the command. Examples # Disable short GI. <Sysname> system-view [Sysname] interface wlan-radio 0/1 [Sysname-WLAN-Radio0/1] short-gi disable short-retry threshold Use short-retry threshold to set the maximum number of hardware retransmissions for small frames.
Use smart-antenna disable to disable the smart antenna feature. Use undo smart-antenna to restore the default. Syntax smart-antenna { disable | enable } undo smart-antenna Default The smart antenna feature is enabled. Views Radio interface view Predefined user roles network-admin Usage guidelines This command is applicable only to 802.11n radios.
Usage guidelines This command is applicable only to 802.11n radios. Changing the radio mode to 802.11a, 802.11b, or 802.11g invalidates the command. The smart antenna mode configuration takes effect only after you enable the smart antenna feature. Examples # Set the smart antenna mode to high-availability. <Sysname>...
Page 28
Default Interface WLAN-radio 0/0 operates in dot11an mode and interface WLAN-radio 0/1 operates in dot11gn mode. Views Radio interface view Predefined user roles network-admin Parameters dot11a: Specifies the 802.11a radio mode. dot11an: Specifies the 802.11n (5 GHz) radio mode. dot11b: Specifies the 802.11b radio mode. dot11g: Specifies the 802.11g radio mode.
WLAN radio resource measurement commands WLAN is supported only on the MSR954(JH297A/JH298A/JH299A). The term "AP" in this document refers to MSR routers that support WLAN. display wlan measure-report Use display wlan measure-report to display measurement reports for clients. Syntax display wlan measure-report interface interface-type interface-number [ client mac-address mac-address ] Views Any view...
Page 30
Frame report entry: BSSID : a072-2351-e253 PHY type : fhss Average RCPI : -10 dBm Last RSNI : 2 dBm Last RCPI : -20 dBm Frames Dot11BSSAverageAccessDelay group: Average access delay : 32 ms BestEffort average access delay : 1 ms Background average access delay : 1 ms Video average access delay...
Field Description Transmit power Transmission power of the client. Whether the client has detected wireless packets from other BSSs. OFDM preamble Whether the client has detected OFDM preambles. Radar Whether the client has detected radar signals. Unidentified signal Whether the client has detected unknown signals. CCA utilization is expressed as a percentage of time that the CCA busy fraction channel is busy (during the measurement period).
Use undo measure to restore the default. Syntax measure { all | link | neighbor | radio | spectrum | tpc } { disable | enable } undo measure Default Measurement is disabled. Views Radio interface view Predefined user roles network-admin Parameters all: Specifies all measurement features.
Syntax measure-duration time undo measure-duration Default The measurement duration is 500 TUs. Views Radio interface view Predefined user roles network-admin Parameters time: Specifies the measurement duration in the range of 1 to 10000 TUs. One TU is equal to 1024 microseconds.
Examples # Set the measurement interval to 35 seconds. <Sysname> system-view [Sysname] interface wlan-radio 0/0 [Sysname-WLAN-Radio0/0] measure-interval 35 Related commands measure measure-duration resource-measure Use resource-measure enable to enable radio resource measurement. Use resource-measure disable to disable radio resource measurement. Use undo resource-measure to restore the default. Syntax resource-measure { disable | enable } undo resource-measure...
Default The match mode is none for client radio resource measurement capabilities. Views Radio interface view Predefined user roles network-admin Parameters all: Specifies the all mode. A client is allowed to associate with the AP only when all its radio resource measurement capabilities match the AP's radio resource measurement capabilities.
Page 36
This feature is supported only on 5 GHz radio interfaces. Examples # Enable spectrum management. <Sysname> system-view [Sysname] interface wlan-radio 0/0 [Sysname-WLAN-Radio0/0] spectrum-management enable...
Band navigation commands WLAN is supported only on the MSR954(JH297A/JH298A/JH299A). The term "AP" in this document refers to MSR routers that support WLAN. wlan band-navigation aging-time Use wlan band-navigation aging-time to set the client information aging time. Use undo wlan band-navigation aging-time to restore the default. Syntax wlan band-navigation aging-time aging-time undo wlan band-navigation aging-time...
Default An AP does not reject 5 GHz association requests. Views System view Predefined user roles network-admin Parameters access-denial: Specifies the maximum number of denials for 5 GHz association requests, in the range of 1 to 10. Usage guidelines If the number of times that a 5 GHz radio rejects a client reaches the specified maximum number, the radio accepts the association request of the client.
Examples # Enable load balancing for band navigation, and set the client number threshold and session gap threshold to 10 and 5, respectively. <Sysname> system-view [Sysname] wlan band-navigation balance session 10 gap 5 wlan band-navigation enable Use wlan band-navigation enable to enable band navigation. Use undo wlan band-navigation enable to restore the default.
Page 40
Predefined user roles network-admin Parameters rssi-threshold: Specifies the RSSI threshold for band navigation, in the range of 5 to 100. Usage guidelines A client might be detected by multiple radios. A 5 GHz radio rejects the association request of a client if the client's RSSI is lower than the band navigation RSSI threshold.
WLAN access commands The term "AP" in this document refers to MSR routers that support WLAN. WLAN is supported only on the MSR954(JH297A/JH298A/JH299A). beacon ssid-hide Use beacon ssid-hide to disable advertising of the Service Set Identifier (SSID) in beacon frames. Use undo beacon ssid-hide to restore the default.
Examples # Display static blacklist entries. <Sysname> display wlan blacklist static Total number of clients: 3 MAC addresses: 000e-35b2-000e 0019-5b8e-b709 001c-f0bf-9c92 # Display dynamic blacklist entries. <Sysname> display wlan blacklist dynamic Total number of clients: 3 MAC address APID Lifetime (s) Duration (hh:mm:ss) 000f-e2cc-0001 00:02:11...
Page 44
Examples # Display brief information about all clients. <Sysname> display wlan client Total number of clients: 3 MAC address Username APID/RID IP address IPv6 address VLAN 000f-e265-6400 N/A 1.1.1.1 000f-e265-6401 user 1024/1 3.0.0.3 84db-ac14-dd08 N/A 5.5.5.3 1::2:0:0:3 Table 3 Command output Field Description MAC address...
Page 45
SM power save mode : Dynamic Short GI for 20MHz : Supported Short GI for 40MHz : Supported Short GI for 80MHz : Supported Short GI for 160/80+80MHz : Not supported STBC RX capability : Not supported STBC TX capability : Not supported LDPC RX capability : Not supported...
Page 46
Field Description NOTE: If the client uses portal authentication, this field does not display the portal username of the client. Association ID. AP ID ID of the AP that the client is associated with. AP name Name of the AP that the client is associated with. Radio ID ID of the radio that the client is associated with.
Page 47
Field Description • Not supported. Client STBC receive capability; • STBC Rx Capability Not Supported. • Supported. Client STBC transmission capability: • Not Supported. STBC Tx Capability • Supported. Client LDPC receive capability; • LDPC Rx capability Not Supported. • Supported.
Page 48
Field Description • PRE-RSN—Beacons and probe responses do not carry RSN IE or WPA AKM mode: • 802.1X. AKM mode • PSK. Cipher suite: • N/A. • WEP40. • Cipher suite WEP104. • WEP128. • CCMP. • TKIP. User authentication mode: •...
Field Description • Policy-name. Online time Client online duration. Fast BSS transition (FT): • FT status Active—FT is enabled. • Inactive—FT is disabled. display wlan service-template Use display wlan service-template to display service template information. Syntax display wlan service-template [ service-template-name ] Views Any view Predefined user roles...
Page 50
Intrusion protection : Disabled Intrusion protection mode : Temporary-block Temporary block time : 180 sec Temporary service stop time : 20 sec Fail VLAN ID 802.1X handshake : Enabled 802.1X handshake secure : Disabled 802.1X domain : my-domain MAC-auth domain : Not configured Max 802.1X users per BSS : 4096...
Page 51
Field Description ID of the VLAN to which clients belong after coming online through the VLAN ID service template. AKM mode: • 802.1X. AKM mode • PSK. Security IE: • Security IE RSN. • WPA. Cipher suite: • WEP40. • WEP104.
Page 52
Field Description • Temporary-service-stop—Temporarily stops the access service provided by the BSS that receives illegal packets. Temporary block time Temporary block time in seconds. Temporary service stop time Temporary service stop time in seconds. ID of the VLAN to which clients are added if they cannot pass the Fail VLAN ID authentication when the authentication server can be reached.
Predefined user roles network-admin Usage guidelines This command disables APs from performing load balancing or band navigation on clients associated with the specified service template. Examples # Enable quick association for service template 1. <Sysname> system-view [Sysname] wlan service-template 1 [Sysname-wlan-st-1]quick-association enable region-code Use region-code to specify a region code.
Page 57
Country Code Country Code Brunei Darussalam Monaco Bolivia Moldova Brazil Macedonia Bahamas Macau Belarus Martinique Belize Malta Canada Mauritius Switzerland Mexico Cote d'ivoire Malay Archipelago Chile Namibia China Nigeria Colombia Nicaragua Costarica Netherlands Serbia Norway Cyprus New Zealand Czech Republic Oman Germany Panama...
Country Code Country Code Croatia Turkey Hungary Trinidad and Tobago Taiwan, Province of Iceland China India Ukraine Indonesia United States of America Ireland Uruguay Israel Uzbekistan Iraq The Vatican City State Italy Venezuela Iran Virgin Islands Jamaica Vietnam Jordan Yemen Japan South Africa Democratic People's...
Predefined user roles network-admin Parameters A locked region code cannot be changed. Examples # Lock the global region code. <Sysname> system-view [Sysname] wlan global-configuration [Sysname-wlan-global-configuration] region-code-lock enable Related commands region-code reset wlan client Use reset wlan client to log off a client or all clients. Syntax reset wlan client { all | mac-address mac-address } View...
Parameters mac-address mac-address: Specifies a client by its MAC address. If you do not specify this option, the command removes all clients from the dynamic blacklist. Examples # Remove all clients from the dynamic blacklist. <Sysname> reset wlan dynamic-blacklist # Remove the specified client from the dynamic blacklist. <Sysname>...
undo service-template enable Default A service template is disabled. Views Service template view Predefined user roles network-admin Usage guidelines If the number of BSSs on an AC exceeds the limit, you cannot enable a new service template. Examples # Enable service template service1. <Sysname>...
Syntax ssid ssid-name undo ssid Default No SSID is configured for a service template. Views Service template view Predefined user roles network-admin Parameters ssid-name: Specifies an SSID name, a case-sensitive string of 1 to 32 characters. Usage guidelines Disable the service template before you execute this command. Examples # Set the SSID to lynn for service template service1.
vlan Use vlan to assign clients coming online through a service template to the specified VLAN. Use undo vlan to restore the default. Syntax vlan vlan-id undo vlan Default Clients join VLAN 1 after coming online through a service template. Views Service template view Predefined user roles...
AP that does not have any GPS antennas, the AP does not output or send GPS information. Examples # Enable GPS information reporting. <Sysname> system-view [Sysname] wlan gps-report enable [Sysname] %Jan 1 12:45:33:697 2014 HPE APMGR/6/APMGR_AP_GPSREPORT: SN=CN51GTG0GK, Lng=117.788887, Lat=30.822136, Velocity=25.445878, Orientation=8.054548, DayTime=2016-03-28 15:32:19, Elevation=156.655897. Table 8 Command output Field Description Serial number of the AP.
wlan dynamic-blacklist lifetime Use wlan dynamic-blacklist lifetime to set the aging time for dynamic blacklist entries. Use undo wlan dynamic-blacklist lifetime to restore the default. Syntax wlan dynamic-blacklist lifetime lifetime undo wlan dynamic-blacklist lifetime Default The aging time is 300 seconds for dynamic blacklist entries. Views System view Predefined user roles...
Page 67
Examples # Test the quality of the wireless link to the client with MAC address 60a4-4cda-eff0. <Sysname> wlan link-test 60a4-4cda-eff0 Testing link to 60a4-4cda-eff0. Press CTRL + C to break. Link Status ----------------------------------------------------------------------- MAC address: 60a4-4cda-eff0 ----------------------------------------------------------------------- VHT-MCS Rate(Mbps) TxCnt RxCnt RSSI Retries...
Field Description Retries Number of wireless link quality retransmission frames sent by the AP. RTT(ms) Round trip time for link quality test frames from the AP to the client. Number of spatial streams for link quality test on 802.11n or 802.11ac clients.
Views System view Predefined user roles network-admin Parameters mac-address mac-address: Specifies a client by its MAC address. Usage guidelines If you add an online client to the static blacklist, the command logs off the client. You cannot add a client to both the whitelist and the static blacklist. The undo form of the command removes all clients from the static blacklist if you do not specify the mac-address mac-address option.
Examples # Add MAC address 001c-f0bf-9c92 to the whitelist. <Sysname> system-view [Sysname] wlan whitelist mac-address 001c-f0bf-9c92 This command will disconnect all clients. Continue? [Y/N]: Related commands display wlan whitelist...
WLAN security commands The term "AP" in this document refers to MSR routers that support WLAN. WLAN is supported only on the MSR954(JH297A/JH298A/JH299A). akm mode Use akm mode to set an authentication and key management (AKM) mode. Use undo akm mode to restore the default. Syntax akm mode { dot1x | private-psk | psk | anonymous-dot1x } undo akm mode...
Related commands cipher-suite security-ie cipher-suite Use cipher-suite to specify the cipher suite used for frame encryption. Use undo cipher-suite to remove the cipher suite configuration. Syntax cipher-suite { ccmp | tkip | wep40 | wep104 | wep128 } undo cipher-suite { ccmp | tkip | wep40 | wep104 | wep128 } Default No cipher suite is specified.
gtk-rekey client-offline enable Use gtk-rekey client-offline enable to enable offline-triggered GTK update. Use undo gtk-rekey client-offline to restore the default. Syntax gtk-rekey client-offline enable undo gtk-rekey client-offline enable Default Offline-triggered GTK update is disabled. Views WLAN service template view Predefined user roles network-admin Usage guidelines Enable offline-triggered GTK update only when GTK update is enabled.
gtk-rekey method Use gtk-rekey method to set a GTK update method. Use undo gtk-rekey method to restore the default. Syntax gtk-rekey method { packet-based [ packet ] | time-based [ time ] } undo gtk-rekey method Default The GTK is updated at an interval of 86400 seconds. Views WLAN service template view Predefined user roles...
key-derivation Use key-derivation to set the key derivation function (KDF). Use undo key-derivation to restore the default. Syntax key-derivation { sha1 | sha1-and-sha256 | sha256 } undo key-derivation Default The KDF is the HMAC-SHA1 algorithm. Views WLAN service template view Predefined user roles network-admin Parameters...
Views WLAN service template view Predefined user roles network-admin Parameters mandatory: Specifies the mandatory mode. Only clients that support management frame protection can access the WLAN. optional: Specifies the optional mode. All clients can access the WLAN. Usage guidelines Management frame protection takes effect only for a network that uses the RSNA mechanism and is configured with the CCMP cipher suite and RSN security information element.
<Sysname> system-view [Sysname] wlan service-template 1 [Sysname-wlan-st-1] pmf association-comeback 2 pmf saquery retrycount Use pmf saquery retrycount to maximum retransmission attempts for SA query requests. Use undo pmf saquery retrycount to restore the default. Syntax pmf saquery retrycount count undo pmf saquery retrycount Default The maximum retransmission attempt number is 4 for SA query requests.
Views WLAN service template view Predefined user roles network-admin Parameters timeout: Specifies the interval for the AP to send SA query requests, in the range of 100 to 500 milliseconds. Examples # Set the interval for sending SA query requests to 300 milliseconds. <Sysname>...
Usage guidelines Set the PSK only when the WLAN service template is disabled and the AKM mode is PSK. If you set the PSK when the AKM mode is 802.1X, the WLAN service template can be enabled but the PSK configuration does not take effect.
Syntax security-ie { osen | rsn | wpa } undo security-ie { osen | rsn | wpa } Default OSEN IE, RSN IE, and WPA IE are disabled. Views WLAN service template view Predefined user roles network-admin Parameters osen: Enables the OSEN IE in the beacon and probe response frames sent by the AP. The OSEN IE advertises the OSEN capabilities of the AP.
Predefined user roles network-admin Usage guidelines To report critical WLAN security events to an NMS, enable SNMP notifications for WLAN security. For WLAN security event notifications to be sent correctly, you must also configure SNMP on the device. For more information about SNMP configuration, see the network management and monitoring configuration guide for the device.
Related commands cipher-suite wep key-id wep key-id Use wep key-id to apply a WEP key. Use undo wep key-id to restore the default. Syntax wep key-id { 1 | 2 | 3 | 4 } undo wep key-id Default Key 1 is applied. Views WLAN service template view Predefined user roles...
Page 84
Syntax wep mode dynamic undo wep mode dynamic Default The dynamic WEP mechanism is disabled. Views WLAN service template view Predefined user roles network-admin Usage guidelines Enable the dynamic WEP mechanism only when the WLAN service template is disabled. The dynamic WEP mechanism requires 802.1X authentication for user access authentication. Do not apply WEP key 4 if the dynamic WEP mechanism is enabled.
WLAN authentication commands WLAN is supported only on the MSR954(JH297A/JH298A/JH299A). The term "AP" in this document refers to MSR routers that support WLAN. This chapter describes WLAN-specific authentication commands. For more information about 802.1X and MAC authentication commands, see Security Command Reference. client url-redirect enable Use client url-redirect enable to enable URL redirection for WLAN clients.
Use undo client-security authentication fail-vlan to restore the default. Syntax client-security authentication fail-vlan vlan-id undo client-security authentication fail-vlan Default No Auth-Fail VLAN exists. Views Service template view Predefined user roles network-admin Parameters vlan-id: Specifies the ID of the Auth-Fail VLAN, in the range of 1 to 4094. Make sure the VLAN has been created.
Parameters dot1x: Performs 802.1X authentication only. dot1x-then-mac: Performs 802.1X authentication first, and then MAC authentication. If the client passes 802.1X authentication, MAC authentication is not performed. mac: Performs MAC authentication only. mac-then-dot1x: Performs MAC authentication first, and then 802.1X authentication. If the client passes MAC authentication, 802.1X authentication is not performed.
Examples # Enable the authorization-fail-offline feature for service template service1. <Sysname> system-view [Sysname] wlan service-template service1 [Sysname-wlan-st-service1] client-security authorization-fail offline client-security ignore-authorization Use client-security ignore-authorization to configure the device to ignore the authorization information received from the authentication server (a RADIUS server or the local device). Use undo client-security ignore-authorization to restore the default.
Default The intrusion protection action is temporary-block. Views Service template view Predefined user roles network-admin Parameters service-stop: Stops the BSS where an illegal frame is received until the BSS is enabled manually on the radio interface. temporary-block: Adds the source MAC address of an illegal frame to the blocked MAC address list for a period.
Predefined user roles network-admin Usage guidelines This command is configurable when the service template is disabled, and it takes effect after the service template is enabled. When the device receives an association request from an illegal client, the device takes the predefined protection action on the BSS where the request is received.
[Sysname-wlan-st-service1] client-security intrusion-protection action temporary-block [Sysname-wlan-st-service1] client-security intrusion-protection timer temporary-block Related commands client-security intrusion-protection action client-security intrusion-protection enable client-security intrusion-protection timer temporary-service-stop Use client-security intrusion-protection timer temporary-service-stop to set the BSS silence period for intrusion protection. Use undo client-security intrusion-protection timer temporary-service-stop to restore the default.
display wlan client-security block-mac Use display wlan client-security block-mac to display blocked MAC address information for WLAN clients. Syntax display wlan client-security block-mac Views Any view Predefined user roles network-admin network-operator Usage guidelines A MAC address that fails authentication is added to the blocked MAC address list when the intrusion protection action is temporary-block.
Default No authentication domain is specified for 802.1X clients on a service template. Views Service template view Predefined user roles network-admin Parameters domain-name: Specifies an ISP domain by its name, a case-insensitive string of 1 to 255 characters. Usage guidelines This command is configurable when the service template is disabled, and it takes effect after the service template is enabled.
Usage guidelines This command is configurable when the service template is disabled, and it takes effect after the service template is enabled. When you configure this command, specify the extended keyword for Hewlett Packard Enterprise iNode clients and the standard keyword for other clients. This command is required only when an IMC server is used as the RADIUS server.
dot1x handshake secure enable Use dot1x handshake secure enable to enable the 802.1X online user handshake security feature. Use undo dot1x handshake secure enable to disable the 802.1X online user handshake security feature. Syntax dot1x handshake secure enable undo dot1x handshake secure enable Default The 802.1X online user handshake security feature is disabled.
Predefined user roles network-admin Parameters count: Specifies the maximum number of concurrent 802.1X clients. The value range is 1 to 4096. Usage guidelines This command is configurable when the service template is disabled, and it takes effect after the service template is enabled. When the maximum number is reached, the service template denies subsequent 802.1X clients.
• If the termination action is Radius-request, the periodic online user reauthentication configuration on the template does not take effect. The device reauthenticates the online 802.1X clients after the session timeout timer expires. Examples # Enable the 802.1X periodic online user reauthentication feature on service template service1. <Sysname>...
mac-authentication max-user Use mac-authentication max-user to set the maximum number of concurrent MAC authentication clients on a service template. Use undo mac-authentication max-user to restore the default. Syntax mac-authentication max-user count undo mac-authentication max-user Default A maximum of 4096 concurrent MAC authentication clients are allowed on a service template. Views Service template view Predefined user roles...
WLAN QoS commands WLAN is supported only on the MSR954(JH297A/JH298A/JH299A). The term "AP" in this document refers to MSR routers that support WLAN. bandwidth-guarantee Use bandwidth-guarantee enable to enable bandwidth guaranteeing. Use bandwidth-guarantee disable to disable bandwidth guaranteeing. Use undo bandwidth-guarantee to restore the default. Syntax bandwidth-guarantee { disable | enable } undo bandwidth-guarantee...
Default A service template does not have a guaranteed bandwidth. Views Radio interface view Predefined user roles network-admin Parameters service-template service-template-name: Specifies a service template by its name, a case-insensitive string of 1 to 63 characters. Make sure the specified service template has been bound to the radio.
Predefined user roles network-admin Parameters channelutilization: Specifies the channel usage-based admission policy. channelutilization-value: Specifies the maximum channel usage in percentage, in the range of 0 to 100. The maximum channel usage refers to the medium time of the accepted AC-VO and AC-VI traffic to the valid time within a certain time.
Usage guidelines For this command to take effect, make sure service-template-based client rate limiting is enabled. You can repeat this command multiple times to limit the rates of both the incoming and outgoing traffic. Examples # Configure rate limiting for service template 1: set the CIR to 567 Kbps for each client's incoming traffic.
display wlan wmm Use display wlan wmm radio to display WMM statistics for radios. Use display wlan wmm client to display WMM statistics for clients. Syntax display wlan wmm { radio { all | ap ap-name } | client { all | ap ap-name | mac-address mac-address } } Views Any view...
Page 104
Radio max AIFSN : 15 Radio max ECWmin : 10 Radio max TXOPLimit : 32767 Radio max ECWmax : 10 CAC information Client accepted Voice Video Total request mediumtime(µs) Voice(µs) Video(µs) Calls rejected due to insufficient resources Calls rejected due to invalid parameters Calls rejected due to invalid mediumtime Calls rejected due to invalid delaybound Table 11 Command output...
[Sysname-WLAN-Radio0/1] edca radio ac-vo aifsn 2 qos priority Use qos priority to set the port priority. Use undo qos priority to restore the default. Syntax qos priority priority-value undo qos priority Default The port priority is 0. Views Service template view Predefined user roles network-admin Parameters...
Predefined user roles network-admin Usage guidelines Hewlett Packard Enterprise devices support the following trust modes: • Packet trust mode—Uses the 802.1e priority carried in packets for priority mapping. • Port trust mode—Uses the configured port priority for priority mapping. Both the port trust mode and the packet trust mode are applicable to uplink packets. Examples # Enable the packet trust mode for service template 1.
dot11an: Specifies 802.11an clients. dot11b: Specifies 802.11b clients. dot11g: Specifies 802.11g clients. dot11gn: Specifies 802.11gn clients. inbound: Limits the rate of incoming traffic. outbound: Limits the rate of outgoing traffic. cir cir: Specifies the CIR in Kbps for each client. The value range for the cir argument is 1 to 2097152.
dot11b: Specifies the 802.11b radio mode. dot11g: Specifies the 802.11g radio mode. dot11gn: Specifies the 802.11gn radio mode. bandwidth: Specifies the maximum bandwidth in Kbps. The value range varies as follows depending on radio modes: • 16 to 30000 for dot11a and dot11g. •...
Document conventions and icons Conventions This section describes the conventions used in the documentation. Port numbering in examples The port numbers in this document are for illustration only and might be unavailable on your device. Command conventions Convention Description Boldface Bold text represents commands and keywords that you enter literally as shown.
Network topology icons Convention Description Represents a generic network device, such as a router, switch, or firewall. Represents a routing-capable device, such as a router or Layer 3 switch. Represents a generic switch, such as a Layer 2 or Layer 3 switch, or a router that supports Layer 2 forwarding and other Layer 2 features.
Support and other resources Accessing Hewlett Packard Enterprise Support • For live assistance, go to the Contact Hewlett Packard Enterprise Worldwide website: www.hpe.com/assistance • To access documentation and support services, go to the Hewlett Packard Enterprise Support Center website: www.hpe.com/support/hpesc Information to collect •...
For more information and device support details, go to the following website: www.hpe.com/info/insightremotesupport/docs Documentation feedback Hewlett Packard Enterprise is committed to providing documentation that meets your needs. To help us improve the documentation, send any errors, suggestions, or comments to Documentation Feedback (docsfeedback@hpe.com). When submitting your feedback, include the document title,...
Page 118
part number, edition, and publication date located on the front cover of the document. For online help content, include the product name, product version, help edition, and publication date located on the legal notices page.
Index A B C D E F G K L M P Q R S T U V W distance,7 Documentation feedback,112 mode,66 dot11g protection,8 a-mpdu,1 dot11n mandatory maximum-mcs,9 a-msdu,1 dot11n multicast-mcs,9 ani,2 dot11n protection,10 antenna type,2 dot11n support maximum-mcs,11 dot1x domain,87 dot1x...
Need help?
Do you have a question about the FlexNetwork MSR Series and is the answer not in the manual?
Questions and answers