ONTENTS Preface Audience Document Objectives Organization Related Publications Document Conventions Support Information Compliance and Safety Notices Chapter 1 Introduction to the ProCurve 700wl Series Overview Centralized Administration of the 700wl Series system Order of Network Installation Access Control Server with One or More Access Controller Modules Redundant Access Control Servers with One or More Access Controller Modules...
Page 6
Rack Mounting the Chassis Connecting Power to the Chassis Chapter 3 Network Setup Getting Started Access Control Server Setup IP Addressing Considerations Initial Configuration Using the CLI Initial Configuration Using the Administrative Console Access Controller Module Setup 3-14 IP Addressing Considerations 3-14 Initial Configuration Using the CLI 3-15...
Page 7
Power Requirements Physical Dimensions Safety and Regulatory Compliance Physical Interface Appendix D Cable and Connector Specifications Serial Console Port 10/100 Downlink Ethernet Cables Power Crossover Connector Appendix E Safety and EMC Regulatory Statements Safety Information U.S.A. Canada Australia/New Zealand Japan Korea BSMI E-10...
REFACE This preface describes the objective, audience, use, and organization of the Installation and Getting Started Guide. It also outlines the document conventions, related documentation, and support information. Audience The audience for this document is the network administrator who wants to enable network users to communicate using the 700wl Series system.
Page 10
Chapter 2— Hardware Installation This chapter describes the installation of the ProCurve Access Control Server 745wl. Installation of the XL Access Controller Module is described in the ProCurve Series 5300xl Switches Installation and Getting Started Guide. Chapter 3— Network Setup This chapter describes the network configuration of the Access Control Server after it has been physically installed.
. Click on and select www.procurve.com support services for a list of available support resources and options for contacting HP. Compliance and Safety Notices Technical specifications, safety information, and regulatory compliance statements can be found in Appendix C, “Technical Specifications”. This information should be read thoroughly before installing the HP system equipment.
NTRODUCTION TO THE URVE ERIES This chapter gives a brief description of the installation procedures for ProCurve 700wl Series products. It consists of the following sections Overview ..............1-1 Order of Network Installation .
Introduction to the ProCurve 700wl Series • Set up Identity Profiles to put users in groups that share the same access policies • Set up Connection Profiles that allow you to specify different Access Policies for users based on location, time of day, VLAN tags, and Authentication Policies •...
Introduction to the ProCurve 700wl Series Note the IP address and shared secret of the Access Control Server that you plan to designate as the Primary Access Control Server. Do not configure the Access Control Servers (yet) as redundant peers. Step 3.
Page 16
Introduction to the ProCurve 700wl Series Table 1-1. Installation Parameters Parameter Form Shared Secret Secret key used to establish trust relationship between an Access Control Server and an Access Controller Module. Alphanumeric string. The same shared secret must be configured on each system. Many of these parameters can be supplied by the DHCP server if the system is configured to obtain its IP address via DHCP.
ARDWARE NSTALLATION This chapter describes the hardware installation of the ProCurve Access Control Server 745wl. (The XL Access Controller Module is installed in the 5300xl switches, and, therefore, its installation is described in the ProCurve Series 5300xl Switches Installation and Getting Started Guide.) You must be sure that the site requirements are met and carefully follow the procedures described to physically install the equipment.
Hardware Installation Figure 2-2 shows a front panel view of the Access Control Server 745wl. Figure 2-2. Front panel view—Access Control Server 745wl System Memory/Storage The Access Control Server 745wl is equipped with a hard disk. Chassis The chassis is 17.00” (43.2 cm) wide, 22.00” (55.9 cm) deep, and 3.5” (8.9 cm) high, which is 2 rack units (RU) high.
Hardware Installation Table 2-1. I/O Ports Number Port Function Description of Ports Network Uplink RJ-45, 10Base-T/ 100Base-TX/1000Base-T Serial Console DB9, Serial Port Controls and Indicators Controls There is only one control on the front of the chassis, a power button, labeled I/0. The power button is a momentary switch and is used to turn on the system.
Hardware Installation Network Uplink Status Indicators A detailed view of the network interface (uplink port) is shown in Figure 2-4. Figure 2-4. Network Uplink port LED1 LED2 The two LEDs, LED1 and LED2, provide information on the port speed and data connection state of the default network uplink port as shown in Table 2-2.
— Software Release Notes — ProCurve Secure Access 700wl Series Installation and Getting Started Guide (this document) If any of the above are missing, contact HP immediately and do not attempt installation. Rack Mounting the Chassis Each Access Control Server 745wl comes with a steel mounting kit suitable for mounting the chassis in a standard 19-inch (48.3 cm) equipment rack.
Hardware Installation Due to the weight of the unit, we highly recommend using these rails to mount the unit. This unit is not suitable for mounting in racks with obstructions (such as a power strip) that could impair access to the device.
ETWORK ETUP This chapter describes the network setup of your 700wl Series system on an existing network to allow interoperability and proper network security for all equipment. It consists of the following sections: Getting Started ............. . 3-1 Access Control Server Setup .
Network Setup Access Control Server Setup You can perform the initial network configuration of an Access Control Server in one of three ways: • Connect a serial console to the Access Control Server’s serial console port and use the Command Line Interface (CLI).
Network Setup To install an Access Control Server onto a network, you need the information shown in Table 3-1: Table 3-1. Installation Parameters Parameter Description Access Control Server hostname Must be fully-qualified if provided. Example: (optional) am21b.corp.com Domain name (optional) Defines the Access Control Server’s domain if a hostname is not provided.
Page 28
At the login prompt, enter admin as the login and then enter admin as the password. login:admin Password: xxxxx The system then displays the command prompt: HP ProCurve Access Control Server 700wl Series #<MAC address> HP 700wl Series@[0.0.0.0]: Step 3. To configure the system with a static IP address, enter the following commands:...
Page 29
Network Setup set ip <ip address> <netmask> is the IP address you want to assign to the Access Control Server. Make sure <ip address> you assign an IP address that is valid for use as a device address. For example, IP addresses ending in .0 (xxx.xxx.xxx.0) are normally used as broadcast addresses and should not be used as a device address.
Page 30
Network Setup Step 7. Verify that you can access the Administrative Console from a browser running on a computer system connected to your network by entering the IP address of the unit: http://<ip address> The Administrator Logon page should appear (see Figure 3-3). Figure 3-3.
Page 31
Network Setup Password: xxxxx The system then displays the command prompt: HP ProCurve Access Control Server 700wl Series #<MAC address> HP 700wl Series@[0.0.0.0]: Note: The IP address of the Access Control Server will be reflected in the prompt instead of the 0.0.0.0 address.
Network Setup Initial Configuration Using the Administrative Console If you want to perform network installation of your Access Control Server using the browser-based Administrative Console, you must connect to the Access Control Server over the network. This requires that you know the IP address (or valid hostname) of your Access Control Server. Since the Access Control Server by default requests an IP address from a DHCP server, you can use the IP address assigned by the DHCP server to connect to the Administrative Console.
Page 33
Network Setup Step 3. Logon For both the username and password, enter admin, and click . The initial Administrative Console page appears, as shown in Figure 3-6. The Access Control Server will be displayed in the left panel of the page. Figure 3-6.
Page 34
Network Setup Figure 3-7. System Components Page Step 5. Local Networks Click the tab below the navigation bar. This brings up the Local Networks page (see Figure 3-8). 3-10 ProCurve Secure Access 700wl Series Installation and Getting Started Guide...
Page 35
Network Setup Figure 3-8. Local Networks Page Step 6. If appropriate, enter a fully-qualified hostname for this Access Control Server. Step 7. Enter the name of the domain in which this Access Control Server resides. Step 8. Using DHCP Configure To use DHCP to obtain an IP address for this unit, select from the drop-...
Page 36
Network Setup Step 11. Component Name Return to the System Component page (Figure 3-7), and in the column, click the IP address link for the Access Control Server. The Edit Access Control Server page appears (Figure 3-9). Figure 3-9. Edit Access Control Server Page Step 12.
Page 37
Network Setup Step 16. If you want to allow remote access to the CLI on this unit via a remote SSH client, leave the check Enable SSH command line interface in the box (this is the default). To disable remote access, uncheck the box.
Network Setup Note: You cannot set the time zone or NTP server in the same operation as manually setting the time. Note: If you are using NTP to get the date and time, the underlying GMT/UTC time difference between the Access Control Server and its associated Access Controller Modules should be less than 900 seconds for the clocks to be synchronized.
Network Setup Table 3-2. Installation Parameters Parameter Description Access Controller Module IP address This is assigned as a static IP address. Subnet mask (Netmask) Defines the Access Control Server’s subnet range. Can be obtained via DHCP. Example: 255.255.255.0. Gateway (default router) IP address Defines the default router.
Page 40
Network Setup Step 2. When the initial Administrative Console page appears (the Equipment Status page shown in Figure 3-11), verify that this Access Controller Module appears in the list of Access Controller Modules. Figure 3-11. Initial Administrative Console Page (Equipment Status) Access Controller Modules appear here.
Page 41
Network Setup Figure 3-12. System Components Page Local Networks Click the tab below the Navigation bar. This brings up the Local Networks page (see Figure 3-13). ProCurve Secure Access 700wl Series Installation and Getting Started Guide 3-17...
Page 42
Network Setup Figure 3-13. Local Networks Page From the System Components List in the left panel under the Local Networks heading, select Basic Setup the Access Controller Module you just installed. The page is displayed. Verify that the information for the Access Controller Module is correct, or enter additional Advanced Setup settings as necessary.
Page 43
Network Setup See the next chapter, “Basic Configuration” for instructions on configuring your 700wl Series system with a demonstration user account, setting up wireless data privacy using PPTP, and allowing a user to connect to the system as the demonstration user. ProCurve Secure Access 700wl Series Installation and Getting Started Guide 3-19...
ASIC ONFIGURATION This chapter will help you accomplish the following: • Create a demonstration user account that can log on and be authenticated through the 700wl Series system built-in user database • Configure the 700wl Series system as a VPN gateway using PPTP encryption •...
Basic Configuration Step 2. Directly connect a Windows client to the 700wl Series system through an Access Controller Module downlink port. Step 3. Log the user on using the default browser-based logon page. The user should have full IP access to the network. This shows that the user can successfully connect to the system and gain network access.
Basic Configuration Step 1. Point your browser to the IP address or hostname of your Access Control Server, and log on to the Administrative Console. Step 2. RIGHTS From the initial page, click the button to go to the Rights Manager. The Rights Setup page appears.
Basic Configuration Note: It may be necessary to remove any proxy configuration to successfully connect to the Logon Page. Note: The 700wl Series system comes with a self-signed SSL certificate. As a result, the client browser may display a security alert warning that the certificate is not from a trusted source. Click Yes to proceed.
Basic Configuration Figure 4-2. Enabling PPTP for the 700wl Series system Step 3. Encryption Protocols Enable PPTP Save Under , put a check mark in the check box, then click Configuring Access Policies for Encryption The next step is to configure the appropriate Access Policies to allow the use of encryption. You must allow encryption for the “Unauthenticated”...
Page 50
Basic Configuration Figure 4-3. Access Policies page Step 3. Unauthenticated Click on the name in the list of Access Policies to bring up the Edit Access Policy page for the Unauthenticated Access Policy. See Figure 4-4. ProCurve Secure Access 700wl Series Installation and Getting Started Guide...
Page 51
Basic Configuration Figure 4-4. Edit Unauthenticated Access Policy Page Step 4. Allowed, but not required From the Encryption drop-down list, select Step 5. Encryption Protocols PPTP Under , put a check mark in the check box. Leave the other settings as they are. Step 6.
Basic Configuration Now users will be able to log on either with PPTP or without encryption. In order to use PPTP, the client must be configured to use PPTP, as described in the following section. PPTP Client Configuration This next set of steps configures the PPTP client on the Windows PC. These instructions are for Windows XP, but the process is similar for Windows 2000.
Page 53
Basic Configuration Figure 4-6. Connection Wizard—VPN Server Selection Step 8. The Completing the New Connection Wizard dialog box appears. You may choose to add a shortcut to this connection on the desktop, then click Finish An icon representing the new connection appears in the Network Connections window under the Virtual Private Network section.
Page 54
Basic Configuration Figure 4-8. Connection Dialog Box—PPTP Properties Step 10. Networking Click the tab to specify the type of VPN. Step 11. PPTP VPN Type of VPN Select from the drop-down list for Make sure that Internet Protocol (TCP/IP) is selected. Step 12.
Basic Configuration Step 14. Deselect the Microsoft CHAP (MS-CHAP) protocol option (this protocol is selected by default). Leave Microsoft CHAP Version 2 selected. Only MS-CHAP v2 is set for use with the Authenticated Access Policy. Step 15. Maximum strength encryption (disconnect if server In the Data Encryption drop-down list, select declines) .
Page 56
Basic Configuration Note: Your RADIUS server must be configured to recognize the Access Control Server as a RADIUS client. To configure the Rights Manager to use a RADIUS server for authentication, do the following: Step 1. From your management station, point your browser to the IP address or hostname of your Access Control Server, and logon to the Administrative Console.
Page 57
Basic Configuration Figure 4-12. New RADIUS Authentication Service Step 7. Type the required information into the appropriate fields. Name • Enter a for this authentication service. Server Port • Enter the information for your RADIUS server. Secret Confirm Secret • Enter the that matches the RADIUS server secret, and enter it again in Group Identity Field...
Page 58
Basic Configuration Step 10. System Authentication Policy Click in the Authentication Policies table to display the Edit Authentication Policy page (Figure 4-13). The newly added authentication service appears at the bottom of the list of available Authentication Services for the System Authentication Policy. Figure 4-13.
Basic Configuration Verify the External Authentication Service This procedure verifies that your RADIUS server will correctly authenticate users: Step 1. RIGHTS Click the button to go to the Rights Manager. Step 2. Tools & Options Trace Transaction Click the tab, then click the link in the left panel.
ROUBLESHOOTING This chapter presents troubleshooting procedures for the 700wl Series system. Table A-1 shows the symptoms, probable cause and recommended action for a non-responsive unit. Table A-1. Troubleshooting Guide Symptom(s) Probable Cause Recommended Action Power LED Off No Power Check power cord and AC outlet Power LED on but fans Defective Fan Replace Fan...
Page 62
Troubleshooting Table A-1. Troubleshooting Guide (Continued) Symptom(s) Probable Cause Recommended Action No traffic through access No connection 1. Check cabling to access point. point 2. Use cross-over cable if required 3. Check power to Access Point Access point requires server Create Identity Profile for MAC address for WEP Key of access point that allows this traffic for...
LCD D ISPLAY ESCRIPTION This appendix describes the LCD display on the Access Control Server. The display can be used to view the system’s network parameters, and to power down the system. This appendix contains the following sections: Display Description ............B-1 Powering On and System Boot .
Checkmark The checkmark acts as a selection for a particular menu. When the checkmark is pressed, the display goes into a submenu. Currently only SHUTDOWN has a submenu. The X This button cancels the current menu. Powering On and System Boot At power-on, the display remains blank until the system has initialized itself and displays Status: Initializing.
• SHUTDOWN? Pressing the Checkmark button, the display becomes: ARE YOU SURE? This command will reset the system when the proper key sequence is pushed (press left and right buttons simultaneously). System Shutdown Pressing the up or down arrow button selects the SHUTDOWN? menu. This allows you to shut down and power off the system.
ECHNICAL PECIFICATIONS AFETY OMPLIANCE This appendix describes the technical specifications for the ProCurve 700wl Series. This appendix includes the following sections: Technical Specifications ............C-1 Safety and Regulatory Compliance .
Safety and Regulatory Compliance Safety Standards UL 60950 - 1:2001 CAN/CSA 22.2 No. 60950 EMC Compliance FCC Part 15 Class A EN 55022 (1998) Class A EN 61000-3-2 (2000) EN 61000-3-3 (1995) Physical Interface To the Access Control Server RJ45 10/100/1000 Base-T Downlink Interfaces 2-port 10/100/1000 Copper Ethernet card...
ABLE AND ONNECTOR PECIFICATIONS This appendix describes the console port and the standard Ethernet cables to be used. This appendix contains the following sections: Serial Console Port ............D-1 10/100 Downlink Ethernet Cables .
10/100 Downlink Ethernet Cables Table D-2 shows the RJ-45 pin assignments for 10/100 Ethernet cables. Table D-2. Pin Assignment for Ethernet Cables Number Standard Ethernet Incoming Data + (RD+) Incoming Data - (RD-) Outgoing Data + (TD+) No Connection (NC) No Connection (NC) Outgoing Data - (TD-) No Connection (NC)
Shielded Signal Cables Use only shielded cables for connecting peripherals to any HP ProCurve 700wl Series device to reduce the possibility of interference with radio communications services. Using shielded cables ensures that you maintain the appropriate EMC classification for the intended environment.
Page 72
Servicing There are no user-serviceable parts inside these products. Any servicing, adjustment, maintenance, or repair must be performed only by service-trained personnel. Note for Service Personnel Caution: There is a danger of a new battery exploding if it is incorrectly installed. Replace the battery only with the same or equivalent type recommended by the manufacturer.
Page 73
Informations concernant la sécurité Symbole de référence à la documentation. Si le produit est marqué de ce symbole, reportez-vous à la documentation du produit afin d'obtenir des informations plus détaillées. WARNING Dans la documentation, un WARNING indique un danger susceptible d'entraîner des dommages corporels ou la mort.
Page 74
Hinweise zur Sicherheit Symbol für Dokumentationsverweis. Wenn das Produkt mit diesem Symbol markiert ist, schlagen Sie bitte in der Produktdokumentation nach, um mehr Informationen über das Produkt zu erhalten. WARNING Symbol für Dokumentationsverweis. Wenn das Produkt mit diesem Symbol markiert ist, schlagen Sie bitte in der Produktdokumentation nach, um mehr Informationen über das Produkt zu erhalten.
Page 75
Considerazioni sulla sicurezza Simbolo di riferimento alla documentazione. Se il prodotto è contrassegnato da questo simbolo, fare riferimento alla documentazione sul prodotto per ulteriori informazioni su di esso. WARNING La dicitura WARNINGdenota un pericolo che può causare lesioni o morte. CAUTION La dicituraCAUTION denota un pericolo che può...
Page 76
Consideraciones sobre seguridad Símbolo de referencia a la documentación. Si el producto va marcado con este símbolo, consultar la documentación del producto a fin de obtener mayor información sobre el producto. WARNING Una WARNING en la documentación señala un riesgo que podría resultar en lesiones o la muerte.
EMC Regulatory Statements U.S.A. FCC Class A This equipment has been tested and found to comply with the limits for a Class A digital device, pursuant to Part 15 of the FCC Rules. These limits are designed to provide reasonable protection against interference when the equipment is operated in a commercial environment.
BSMI Regulatory Model Identification Number For regulatory identification purposes, the ProCurve Secure Access 700wl Series system components (Access Controller 720wl, Access Control Server 740wl, 745wl, Integrated Access Manager 760wl) are assigned a Regulatory Model Number. The Regulatory Model Number for these components areRSVLC-0206 and RSVLC-0601.
ECYCLE TATEMENTS Waste Electrical and Electronic Equipment (WEEE) Statements Disposal of Waste Equipment by Users in Private Household in the European Union This symbol on the product or on its packaging indicates that this product must not be disposed of with your other household waste.
Page 84
Élimination des appareils mis au rebut par les ménages dans l'Union européenne Le symbole apposé sur ce produit ou sur son emballage indique que ce produit ne doit pas être jeté avec les déchets ménagers ordinaires. Il est de votre responsabilité de mettre au rebut vos appareils en les déposant dans les centres de collecte publique désignés pour le recyclage des équipements électriques et électroniques.
Page 85
Para obter mais informações sobre locais que reciclam esse tipo de material, entre em contato com o escritório da HP em sua cidade, com o serviço de coleta de lixo ou com a loja em que o produto foi adquirido.
Page 86
Eliminación de residuos de equipos eléctricos y electrónicos por parte de usuarios particulares en la Unión Europea Este símbolo en el producto o en su envase indica que no debe eliminarse junto con los desperdicios generales de la casa. Es responsabilidad del usuario eliminar los residuos de este tipo depositándolos en un "punto limpio"...
NDEX Numerics 1/0 button boot prompt, serial console 10/100/1000 ports booting 3-18 10/100BaseTx system booting message, LCD browser interface accessing Access Control Server using accessing Control Server using Access Control Server network installation using accessing via browser browser-interface connecting a serial console login to connecting to network default router...
Page 88
reserved Access Control Server 3-11 RJ45 setting via browser interface Control Server setting via CLI humidity accessing via browser network installation procedure system ID (MAC address) I/O ports. See downlink ports Identity Profile DB9 connector Incorrect configuration default router Incorrect network configuration Access Control Server Incorrect password 3-15...
Page 89
Control Server system ID power cord mounting the chassis connecting power cord caution power switch powering a system on/off netmask 3-11 setting in browser interface network installation and DHCP rack-mounting order of regulatory statements procedure using CLI 3-ix related publications procedure, Control Server Reserved port 3-14...
Page 90
voltage input output 1-ii warranty web interface, see browser interface WEP Key IX-4 ProCurve Secure Access 700wl Series Installation and Getting Started Guide...
Need help?
Do you have a question about the ProCurve 745wl and is the answer not in the manual?
Questions and answers