H3C WX Configuration Manual
H3C WX Configuration Manual

H3C WX Configuration Manual

Access controllers

Advertisement

H3C WX Series Access Controllers
Access Controller Module Configuration Guide
Hangzhou H3C Technologies Co., Ltd.
http://www.h3c.com
Document Version: 6W105-20101124

Advertisement

Table of Contents
loading

Summary of Contents for H3C WX

  • Page 1 H3C WX Series Access Controllers Access Controller Module Configuration Guide Hangzhou H3C Technologies Co., Ltd. http://www.h3c.com Document Version: 6W105-20101124...
  • Page 2 SecPro, SecPoint, SecEngine, SecPath, Comware, Secware, Storware, NQA, VVG, V G, V G, PSPT, XGbus, N-Bus, TiGem, InnoVision and HUASAN are trademarks of Hangzhou H3C Technologies Co., Ltd. All other trademarks that may be mentioned in this manual are the property of their respective owners.
  • Page 3 Preface The H3C WX series documentation set describes the software features for the H3C WX Series Access Controllers and guides you through the software configuration procedures. The configuration guides also provide configuration examples to help you apply the software features to different network scenarios.
  • Page 4 Convention Description Asterisk marked square brackets enclose optional syntax choices separated by [ x | y | ... ] * vertical bars, from which you may select multiple choices or none. The argument or keyword and argument combination before the ampersand (&) &<1-n>...
  • Page 5 Convention Description Represents omnidirectional signals. Represents directional signals. About the H3C WX Series Documentation Set The H3C WX series documentation set includes: Category Documents Purposes WX3000 Series Unified Wired and Wireless Switches Brochure Product Describe product specifications and description and benefits.
  • Page 6 Obtaining Documentation You can access the most up-to-date H3C product documentation on the World Wide Web at http://www.h3c.com. Click the links on the top navigation bar to obtain different categories of product documentation: [Technical Support & Documents > Technical Documents] –...
  • Page 7 Read Compatibility Matrixes before using an H3C WX series access controller. Support of the H3C WX series access controllers for features and commands may vary by AC model. For more information, see “Feature Matrixes” and “Command Matrixes” in Compatibility Matrixes.
  • Page 8: Table Of Contents

    Table of Contents 1 Applicable Models and Software Versions ·····························································································1-1 2 Typical Network Scenarios·······················································································································2-1 AC Networking ········································································································································2-1 Access Controller Module Networking ····································································································2-1 Unified Switch Networking ······················································································································2-2 3 Feature Matrixes ········································································································································3-1 Feature Matrix for the WX5000 Series····································································································3-1 Feature Matrix for the WX6000 Series····································································································3-7 Feature Matrix for the WX3000 Series··································································································3-11 4 Command Matrixes····································································································································4-1 Command Matrix for the WX5000 Series ·······························································································4-1...
  • Page 9: Applicable Models And Software Versions

    Applicable Models and Software Versions H3C WX series access controllers include the WX3000 series unified switches, and WX5000 and WX6000 series access controllers. Table 1-1 shows the applicable models and software versions. Table 1-1 Applicable models and software versions Model...
  • Page 10: Typical Network Scenarios

    Typical Network Scenarios AC Networking As shown in the following figure, the AC is connected to Switch (Layer 2 or Layer 3) through GE1/0/1, which can be connected to APs directly or connected to APs over an IP network. Clients can be connected to the network through the APs to implement WLAN user access.
  • Page 11: Unified Switch Networking

    Figure 2-2 Access controller module networking Unified Switch Networking As shown in Figure 2-3, Unified switch (functions as both an AC and a Layer 2 switch) can be connected to APs directly or connected to APs over an IP network. Clients can be connected to the network through the APs to implement WLAN user access.
  • Page 12: Feature Matrixes

    Feature Matrixes In this document, Yes means a feature or command is supported, and No means not supported. Feature Matrix for the WX5000 Series The LS8M1WCMA0, LSWM1WCM10, and LSWM1WCM20 on the WX5000 series adopt the OAP architecture. Installed on the expansion slots of switches, they work as OAP cards to exchange data and status and control information with the switches through their internal service interfaces.
  • Page 13 Document Module Feature WX5002 WX5002V2 LS8M1WCMA0 WX5004 LSWM1WCM10 LSWM1WCM20 File system Configuration file management encryption configuration Storage media Flash Flash Flash supported Supports 32 Supports concurrent Supports 32 APs by concurren concurrent Supports 64 Supports 32 Device management default, and t APs by APs by concurrent APs...
  • Page 14 Document Module Feature WX5002 WX5002V2 LS8M1WCMA0 WX5004 LSWM1WCM10 LSWM1WCM20 Internal Internal Internal loopback Yes on Configuring loopback Yes on GE Yes on GE loopback testing loopback testing testing supported detection on an interfaces interfaces supported on supported on on GE interfaces interfaces Ethernet interface only...
  • Page 15 Document Module Feature WX5002 WX5002V2 LS8M1WCMA0 WX5004 LSWM1WCM10 LSWM1WCM20 Configuration IPv6 static routing IPv6 static routing Guide configuration configuration MLD snooping MLD snooping IP Multicast configuration Configuration IPv6 multicast VLAN Guide IPv6 multicast VLAN configuration ACL configuration IPv6 ACL ACL and QoS Configuring line rate Configuration Configuring CAR...
  • Page 16 Document Module Feature WX5002 WX5002V2 LS8M1WCMA0 WX5004 LSWM1WCM10 LSWM1WCM20 Establishing a connection between an SSH client and an IPv6 SSH server Specifying a source IPv6 address or interface for an SFTP client Establishing a connection between an SFTP client and an IPv6 SFTP server IPv6 SFTP client ICMP,...
  • Page 17 Document Module Feature WX5002 WX5002V2 LS8M1WCMA0 WX5004 LSWM1WCM10 LSWM1WCM20 11MAC/802. 1X/ARP/DH UDP/TCP/ CP/HWTAC 11MAC/802.1X/ UDP/TCP/8 802.1X/D AS/ICMP/IG ARP/DHCP/HW 02.1X/DHC HCP/IGM UDP/TCP/802.1 UDP/TCP/802.1 MP/MLD/L TACAS/ICMP/IG P/IGMP/NT P/NTP/AR X/DHCP/IGMP/ X/DHCP/IGMP/ WAPP/ND/ MP/MLD/LWAP P/ARP/LWA P/LWAPP NTP/ARP/LWA NTP/ARP/LWA NTP/PIM/R P/ND/NTP/PIM Other protocol packets PP/LooPbac /LooPbac PP/LooPback/P PP/LooPback/P...
  • Page 18: Feature Matrix For The Wx6000 Series

    Feature Matrix for the WX6000 Series The switch interface module on the WX6103, and the LSQM1WCMB0, LSBM1WCM2A0, and LSRM1WCM2A1 access controller modules on the WX6000 series adopt the OAP architecture. Installed on the expansion slots of switches, they work as OAP cards to exchange data and status and control information with the switches through their internal service interfaces.
  • Page 19 Volume Module Feature WX6103 LSQM1WCMB0 LSBM1WCM2A0 LSRM1WCM2A1 Guide configuration Maximum number of SSIDs supported The MPU does not Combo port configuration support the Combo port. Shutting down an Ethernet interface Ethernet interface Internal loopback Internal loopback Internal loopback Internal loopback configuration Configuring flow control testing supported...
  • Page 20 Volume Module Feature WX6103 LSQM1WCMB0 LSBM1WCM2A0 LSRM1WCM2A1 IPv6-related displaying IP routing basics and maintaining configuration Layer 3 – IP Routing commands Configuration Guide IPv6 static routing IPv6 static routing configuration configuration MLD snooping MLD snooping configuration IP Multicast Configuration Guide IPv6 multicast VLAN IPv6 multicast VLAN configuration...
  • Page 21 Volume Module Feature WX6103 LSQM1WCMB0 LSBM1WCM2A0 LSRM1WCM2A1 Establishing a connection between an SSH client and an IPv6 SSH server Specifying a source IPv6 address or interface for an SFTP client Establishing a connection between an SFTP client and an IPv6 SFTP server IPv6 SFTP client ICMP, IEC, Telnet,...
  • Page 22: Feature Matrix For The Wx3000 Series

    Volume Module Feature WX6103 LSQM1WCMB0 LSBM1WCM2A0 LSRM1WCM2A1 ACSEI client configuration Access Controller Access Controller Access Controller Module Basic Module Basic Module Basic Configuration Guide Configuration Configuration Feature Matrix for the WX3000 Series The access controller engine and switching engine on the WX3000 series adopt the OAP architecture. The switching engine is integrated on the access controller engine as an OAP card.
  • Page 23 Volume Module Feature WX3024 WX3010 WX3008 Storage media supported Flash Flash Flash Device management 24 APs at most by 12 APs at most by configuration License default, and can be default, and can be extended to 48 APs. extended to 24 APs. Hot AC backup WLAN Configuration WLAN services configuration...
  • Page 24 Volume Module Feature WX3024 WX3010 WX3008 IPv6 application IPv6 application configuration configuration IP routing basics IPv6-related displaying and configuration maintaining commands Layer 3 – IP Routing Configuration Guide IPv6 static routing IPv6 static routing configuration configuration MLD snooping configuration MLS snooping IP Multicast Configuration Guide IPv6 multicast VLAN...
  • Page 25 Volume Module Feature WX3024 WX3010 WX3008 Specifying a source IPv6 address or interface for an SFTP client Establishing a connection between an SFTP client and an IPv6 SFTP server IPv6 SFTP client ICMP, IEC, Telnet, and ICMP, IEC, Telnet, and ICMP, IEC, Telnet, and Management protocol packets SNMP packets whose...
  • Page 26: Command Matrixes

    Command Matrixes In this document, Yes means a feature or command is supported, and No means not supported. Command Matrix for the WX5000 Series Table 4-1 Command matrix for the WX5000 series Volume Module Command WX5002 WX5002V2 LS8M1WCMA0 WX5004 LSWM1WCM10 LSWM1WCM20 Fundamentals Login commands...
  • Page 27 Volume Module Command WX5002 WX5002V2 LS8M1WCMA0 WX5004 LSWM1WCM10 LSWM1WCM20 Console and VTY user Console and AUX and VTY AUX and VTY interfaces AUX and VTY AUX and VTY VTY user user interfaces user interfaces user interfaces user interfaces interfaces are are supported.
  • Page 28 Volume Module Command WX5002 WX5002V2 LS8M1WCMA0 WX5004 LSWM1WCM10 LSWM1WCM20 Console and VTY user Console and AUX and VTY AUX and VTY interfaces AUX and VTY AUX and VTY VTY user user interfaces user interfaces user interfaces user interfaces interfaces are are supported.
  • Page 29 Volume Module Command WX5002 WX5002V2 LS8M1WCMA0 WX5004 LSWM1WCM10 LSWM1WCM20 No on the license append WX5002-128 By default, By default, By default, By default, By default, lower-value is lower-valu lower-value is 5, lower-value is 5, lower-value is 0, temperature-limit 0, and e is 0, and and upper-value and upper-value...
  • Page 30 Volume Module Command WX5002 WX5002V2 LS8M1WCMA0 WX5004 LSWM1WCM10 LSWM1WCM20 hellointerv al ranges hellointerval hellointerval from 100 to ranges from ranges from 100 2000 100 to 2000 to 2000 hot-backup millisecond milliseconds, milliseconds, hellointerval s, and and defaults to and defaults to defaults to 2000 2000...
  • Page 31 Volume Module Command WX5002 WX5002V2 LS8M1WCMA0 WX5004 LSWM1WCM10 LSWM1WCM20 value ranges value ranges value ranges value ranges value ranges value ranges from 1600 from 1600 to from 1600 to from 1600 to from 1600 to from 1600 to jumboframe to 4096 9216 bytes and 4096 bytes and 4096 bytes and...
  • Page 32 Volume Module Command WX5002 WX5002V2 LS8M1WCMA0 WX5004 LSWM1WCM10 LSWM1WCM20 All commands in Layer 2 forwarding the Layer 2 commands commands manual All commands in Port mirroring the port mirroring commands commands manual number pppoe-server number ranges number ranges number ranges ranges number ranges number ranges...
  • Page 33 Volume Module Command WX5002 WX5002V2 LS8M1WCMA0 WX5004 LSWM1WCM10 LSWM1WCM20 All commands in IPv6 basics commands manual IPv6 basics number commands number ranges number ranges number ranges ranges number ranges number ranges ipv6 neighbors from 1 to 256 from 1 to 1024 from 1 to 256 from 1 to from 1 to 1024...
  • Page 34 Volume Module Command WX5002 WX5002V2 LS8M1WCMA0 WX5004 LSWM1WCM10 LSWM1WCM20 All commands in IPv6 static routing IPv6 static routing commands commands manual Layer 2 Layer 2 Layer 2 Layer 2 Layer 2 Layer 2 IP Multicast aggregate igmp-snooping aggregate aggregate aggregate aggregate aggregate Command...
  • Page 35 Volume Module Command WX5002 WX5002V2 LS8M1WCMA0 WX5004 LSWM1WCM10 LSWM1WCM20 Layer 2 Layer 2 Layer 2 Layer 2 Layer 2 Layer 2 port aggregate aggregate aggregate aggregate aggregate aggregate multicast-vlan interface interface view interface view interface view interface view interface view ipv6 view not supported...
  • Page 36 Volume Module Command WX5002 WX5002V2 LS8M1WCMA0 WX5004 LSWM1WCM10 LSWM1WCM20 classifier tcl-name classifier supported tcl-name not classifier classifier inbound-i supported tcl-name not tcl-name not nterface inbound-interf supported supported interface-ty inbound-interfa inbound-interfa interface-type interface-n ce interface-type ce interface-type interface-numb umber not interface-numbe interface-number er not supported...
  • Page 37 Volume Module Command WX5002 WX5002V2 LS8M1WCMA0 WX5004 LSWM1WCM10 LSWM1WCM20 [ ebs [ ebs [ ebs excess-burst-si qos lr excess-burst-siz excess-burst-siz ze ] not e ] not supported e ] not supported supported redirect Security nas device-id AAA commands Command device-id Reference user-numb user-number...
  • Page 38 Volume Module Command WX5002 WX5002V2 LS8M1WCMA0 WX5004 LSWM1WCM10 LSWM1WCM20 max-numb max-number max-number max-number max-number max-number portal max-user er ranges ranges from 1 to ranges from 1 ranges from 1 to ranges from 1 to ranges from 1 to max-number from 1 to 2048.
  • Page 39 Volume Module Command WX5002 WX5002V2 LS8M1WCMA0 WX5004 LSWM1WCM10 LSWM1WCM20 display logfile summary info-center logfile enable info-center logfile frequency info-center logfile size-quota info-center logfile switch-directory logfile save Yes on the Yes on the device side of device side of mcms connect the access the access controller...
  • Page 40: Command Matrix For The Wx6000 Series

    Command Matrix for the WX6000 Series Table 4-2 Command matrix for the WX6000 series Volume Module Command WX6103 LSQM1WCMB0 LSBM1WCM2A0 LSRM1WCM2A1 Fundamentals Login commands telnet ipv6 Command Reference AUX, console and AUX, console and AUX, console and AUX, console and VTY user interfaces VTY user interfaces VTY user interfaces...
  • Page 41 Volume Module Command WX6103 LSQM1WCMB0 LSBM1WCM2A0 LSRM1WCM2A1 mount open ipv6 tftp ipv6 umount display device display fan fan-id can only be 1. fan-id can only be 1. fan-id can only be 1. fan-id can only be 1. power-id takes the power-id takes the power-id takes the power-id takes the...
  • Page 42 Volume Module Command WX6103 LSQM1WCMB0 LSBM1WCM2A0 LSRM1WCM2A1 hellointerval ranges hellointerval ranges hellointerval ranges hellointerval ranges from 30 to 2000 from 30 to 2000 from 30 to 2000 from 30 to 2000 hot-backup milliseconds, and milliseconds, and milliseconds, and milliseconds, and hellointerval defaults to 2000 defaults to 2000...
  • Page 43 Volume Module Command WX6103 LSQM1WCMB0 LSBM1WCM2A0 LSRM1WCM2A1 loopback loopback-detection control enable loopback-detection enable loopback-detection interval-time shutdown speed interface The maximum value The maximum value The maximum value The maximum value VLAN commands vlan-interface is 1024. is 1024. is 1024. is 1024. MAC address table mac-address count ranges from 0...
  • Page 44 Volume Module Command WX6103 LSQM1WCMB0 LSBM1WCM2A0 LSRM1WCM2A1 ip redirects enable IP performance ip ttl-expires enable optimization commands ip unreachables enable Adjacency table display commands adjacent-table All commands IPv6 basics number ranges from number ranges from number ranges from number ranges from ipv6 neighbors commands 1 to 1024 and...
  • Page 45 Volume Module Command WX6103 LSQM1WCMB0 LSBM1WCM2A0 LSRM1WCM2A1 reset ipv6 routing-table statistics IPv6 static routing All commands commands Layer 2 aggregate Layer 2 aggregate Layer 2 aggregate Layer 2 aggregate igmp-snooping interface view not interface view not interface view not interface view not fast-leave supported supported...
  • Page 46 Volume Module Command WX6103 LSQM1WCMB0 LSBM1WCM2A0 LSRM1WCM2A1 green action not green action not green action not green action not supported supported supported supported remark-lp-pass remark-lp-pass remark-lp-pass remark-lp-pass new-local-precedenc new-local-precedenc new-local-precedenc new-local-precedenc e not supported e not supported e not supported e not supported display qos lr interface...
  • Page 47 Volume Module Command WX6103 LSQM1WCMB0 LSBM1WCM2A0 LSRM1WCM2A1 user-number ranges user-number ranges user-number ranges user-number ranges 802.1X commands dot1x max-user from 1 to 20480. from 1 to 20480. from 1 to 20480. from 1 to 20480. mac-authentication user-number ranges user-number ranges user-number ranges user-number ranges MAC authentication...
  • Page 48 Volume Module Command WX6103 LSQM1WCMB0 LSBM1WCM2A0 LSRM1WCM2A1 display anti-attack { 11mac | admin | all | arp | data | dhcp | dot1x | hwtacas | icmp | igmp | lwapp | nd | ntp | pim | radius } display anti-attack { protocol protocol | all }...
  • Page 49: Command Matrix For The Wx3000 Series

    Volume Module Command WX6103 LSQM1WCMB0 LSBM1WCM2A0 LSRM1WCM2A1 ACSEI server configuration commands ACSEI client configuration commands Command Matrix for the WX3000 Series Table 4-3 Command matrix for the WX3000 series Volume Module Command WX3024 WX3010 WX3008 Fundamentals Login commands telnet ipv6 Command Reference AUX and VTY user AUX and VTY user...
  • Page 50 Volume Module Command WX3024 WX3010 WX3008 configuration encrypt ftp ipv6 File management mount configuration open ipv6 commands tftp ipv6 umount cf-card and usb not cf-card and usb not cf-card and usb not display device supported supported supported fan-id takes the value of 1 display fan fan-id ranges from 1 to 3.
  • Page 51 Volume Module Command WX3024 WX3010 WX3008 hot-backup hellointerval group-id ranges from 1 to group-id ranges from 1 to group-id ranges from 1 to wlan ap-group group-id ranges from 1 to group-id ranges from 1 to group-id ranges from 1 to wlan permit-ap-group member ipv6 member ipv6...
  • Page 52 Volume Module Command WX3024 WX3010 WX3008 loopback-detection interval-time No on GE1/0/1 of the No on GE1/0/1 of the No on GE1/0/1 of the access controller engine access controller engine access controller engine shutdown and GE1/0/29 on the and GE1/0/11 on the and GE1/0/9 on the switching engine switching engine...
  • Page 53 Volume Module Command WX3024 WX3010 WX3008 All commands for IPv6 DNS DNS commands configuration ip redirects enable IP performance optimization ip ttl-expires enable commands ip unreachables enable Adjacency table display adjacent-table commands All commands IPv6 basics ipv6 neighbors commands max-learning-num IPv6 application All commands commands...
  • Page 54 Volume Module Command WX3024 WX3010 WX3008 Layer 2 aggregate Layer 2 aggregate Layer 2 aggregate igmp-snooping group-limit interface view not interface view not interface view not supported supported supported Layer 2 aggregate Layer 2 aggregate Layer 2 aggregate igmp-snooping static-group interface view not interface view not interface view not...
  • Page 55 Volume Module Command WX3024 WX3010 WX3008 display qos map-table display qos lr interface classifier tcl-name not classifier tcl-name not supported supported classifier tcl-name not inbound-interface inbound-interface supported interface-type interface-type inbound-interface interface-number not interface-number not interface-type supported supported interface-number not local-precedence local-precedence supported if-match...
  • Page 56 Volume Module Command WX3024 WX3010 WX3008 user-number ranges from 1 user-number ranges from 1 user-number ranges from 1 MAC authentication mac-authentication to 1024 and defaults to to 1024 and defaults to to 1024 and defaults to commands max-user user-number 1024. 1024.
  • Page 57 Volume Module Command WX3024 WX3010 WX3008 System ping ipv6 maintenance and debugging tracert ipv6 commands display logfile buffer display logfile summary Network Management info-center logfile enable and Monitoring Command Reference info-center logfile Information center frequency commands info-center logfile size-quota info-center logfile switch-directory logfile save mcms connect...
  • Page 58: Access Controller Module Basic Configuration

    Access Controller Module Basic Configuration Access Controller Module and Ethernet Switch Compatibility Matrix The access controller modules in this manual refer to the access controller modules inserted on the expansion slots on the switch. For the compatibility matrix of the access controller modules and the Ethernet switches, see Table 5-1.
  • Page 59: Access Controller Module Basic Configuration

    An access controller module installed in the expansion slot on the switch is connected to the switch through internal ports of the switch. To enable the H3C S7500/S7500E/S9500 switch to collaborate with the module, you need to configure the ports on the switch.
  • Page 60: Configuring The Access Controller Module

    The numbers of the internal ports connecting the access controller module are related to the slot where the access controller module is seated. For example, in slot 2, the two internal ports are numbered GE 2/0/1 and GE 2/0/2. The manual link aggregation approach must be adopted. For the configuration commands of the switch, refer to the user manual of the switch.
  • Page 61: Configuration Examples

    Configuration Examples Configuring LS8M1WCMA0 Network requirements An access controller module LS8M1WCMA0 is inserted in slot 4 of the switch. Packets on VLAN 1, VLAN 8, VLAN 9, and VLAN 10 are permitted to transfer between the module and the switch. By default, packets on VLAN 1 are permitted to transfer between the module and the switch.
  • Page 62: Configuring Lswm1Wcm20 Or Lswm1Wcm10

    You can create VLANs on the Ten-GigabitEthernet interface connecting the switch and the access controller module LSQM1WCMB0, LSBM1WCM2A0, or LSRM1WCM2A1, and then configure the port of the switch. Configuration procedure Configure the switch <Switch>system-view # Create VLAN 8 through VLAN 10. [Switch]vlan 8 to 10 # Configure the port of the switch.
  • Page 63 <Switch> system-view # Create VLAN 8 through VLAN 10. [Switch] vlan 8 to 10 # Create a Layer 2 aggregation port. [Switch]interface Bridge-Aggregation 1 [Switch-Bridge-Aggregation1]quit # Add the GigabitEthernet port corresponding to the interface GigabitEthernet 1/0/1 of LSWM1WCM20 to the aggregation port. [Switch]interface GigabitEthernet 1/0/1 [Switch-GigabitEthernet1/0/1]port link-aggregation group 1 [Switch-GigabitEthernet1/0/1]quit...
  • Page 64: Index

    Index AC Networking Access Controller Module and Ethernet Switch Compatibility Matrix Access Controller Module Basic Configuration Access Controller Module Networking Command Matrix for the WX3000 Series 4-24 Command Matrix for the WX5000 Series Command Matrix for the WX6000 Series 4-15 Configuration Examples Feature Matrix for the WX3000 Series 3-11...

Table of Contents