Summary of Contents for SMC Networks ELITECONNECT SMC2502W
Page 1
♦ Full authentication support—supports RADIUS, LDAP, 802.1x, Kerberos, Windows NT/2000 domain and built-in database. ♦ VPN support allows secure wireless communications to and from wireless clients. ♦ Rights-based network access increases network security by providing network administrators full control on users’ access to a network, based on user identification, location, and time.
Page 3
LITE ONNECT WLAN S ECURITY YSTEM NSTALLATION ANUAL From SMC’s EliteConnect line of enterprise wireless LAN solutions 38 Tesla March 2002 Irvine, CA 92618 Part No. 01-111326-006 Phone: (949) 679-8000...
Information furnished by SMC Networks, Inc. (SMC) is believed to be accurate and reliable. However, no responsibility is assumed by SMC for its use, nor for any infringements of patents or other rights of third parties which may result from its use.
A product is considered to be “Active” while it is listed on the current SMC price list. As new technologies emerge, older technologies become obsolete and SMC will, at its discretion, replace an older product in its product line with one that incorporates these newer technologies. At that point, the obsolete product is discontinued and is no longer an “Active”...
Page 7
WARRANTY SHALL BE TAKEN TO AFFECT YOUR STATUTORY RIGHTS. * SMC will provide warranty service for one year following discontinuance from the active SMC price list. Under the limited lifetime warranty, internal and external power supplies, fans, and cables are covered by a standard one-year warranty from date of purchase.
Compliances FCC - Class A This equipment has been tested and found to comply with the limits for a Class A digital device, pursuant to Part 15 of the FCC Rules. These limits are designed to provide reasonable protection against harmful interference in a residential installation.
Rack Mounting the Chassis 2-8 Connecting Power to the Chassis 2-11 WLAN Secure Server Network Installation 3-1 Getting Started 3-2 Information Required 3-2 WLAN Secure Server Installation Alternatives 3-3 Installation Using DHCP 3-4 SMC EliteConnect WLAN Security System Installation Manual WLAN Security System...
Page 10
Installation Using the Command Line Interface 3-9 Connecting to a Serial Console 3-9 Issuing Commands from the Serial Console 3-10 Installation Using the Web-Based Interface 3-12 Completing the Installation 3-19 WLAN Access Manager Network Installation 4-1 Getting Started 4-2 Information Required 4-2 Access Manager Installation Alternatives 4-3 Installation Using DHCP 4-4 Installation Using the Command Line Interface 4-7...
Page 11
WLAN Security System Using Microsoft Windows 2000 DHCP Server B-3 Creating a SMC Networks Vendor Class B-3 Setting Predefined Options B-6 Assigning Values to SMC Networks Vendor-Specific Options B-7 Index -1 SMC EliteConnect WLAN Security System Installation Manual...
This document contains procedural information describing all installation, configuration, and management of the SMC Networks EliteConnect SMC2504W WLAN Secure Server and SMC2502W WLAN Access Manager. Each procedure is written in a task-oriented format consisting of numbered step-by-step instructions, which enable you to perform a series of actions to accomplish a stated objective.
Chapter 1— Introduction This chapter gives an overview of the installation procedure. Chapter 2— Hardware Installation This chapter describes the installation of the SMC Networks WLAN Secure Server, and WLAN Access Manager. Chapter 3— WLAN Secure Server Network Installation This chapter describes the network installation of a WLAN Secure Server after it has been physically installed.
One 6-ft. CAT5E shielded cross-over cable One 6-ft. CAT5E shielded straight-through cable Please register this product and upgrade the product warranty at www.smc.com. Please inform your dealer if there are any incorrect, missing or damaged parts. If possible, retain the carton, including the original packing materials. Use them again to repack the product in case there is a need to return it.
NTRODUCTION This chapter gives a brief description of the installation procedures for the SMC Networks EliteConnect WLAN Security System. It consists of the following sections 1.1 Overview ......... 1-2 1.2 Order of Network Installation .
Overview There are two products that make up the SMC Networks EliteConnect WLAN Security System: WLAN Secure Server WLAN Access Manager The physical or hardware installation for any of these products is essentially the same, and is described fully in Chapter 2, Hardware Installation. The hardware installation is always performed first.
Information Required Note: The information you gather here is required during configuration and is a reminder to find it while installing your SMC EliteConnect product—before beginning the network installation. To perform network installation on an Access Manager, or Secure Server, the...
Page 20
Note: Each WLAN Access Manager needs to know the IP address of its WLAN Secure Server and the shared secret that it uses to prove to the WLAN Secure Server that it is in fact a trusted WLAN Access Manager. A WLAN Secure Server that controls one or more WLAN Access Managers requires entry of that same shared secret.
ARDWARE NSTALLATION This chapter describes the hardware installation of the EliteConnect WLAN Secure Server and WLAN Access Manager. You must be sure that the site requirements are met and carefully follow the procedures described to physically install the equipment. This chapter consists of the following sections: 2.1 Hardware Description .
Hardware Description This section describes the hardware features of the WLAN Secure Server and WLAN Access Manager performance, high-density wiring-closet applications. Figure 2-1. Isometric View—WLAN Secure Server and WLAN Access Manager Note that both products are quite similar in appearance. Both the WLAN Secure Server and WLAN Access Manager have five RJ45 connectors.
Heat Dissipation." The system fan assemblies provide cooling air for the internal chassis components. The fans exhaust warm air from one end and draw in cool air at the other end. SMC EliteConnect WLAN Security System Installation Manual Figure 2-3.
Figure 2-4 shows the direction of airflow through either the WLAN Secure Server, or the WLAN Access Manager. The WLAN Secure Server and WLAN Access Manager systems monitor their internal fan speeds, internal chassis temperature, and power supply voltages. The status of these values are reported by system software.
Space Evaluation Space and layout Floor covering Impact and vibration Lighting Maintenance access Environmental Evaluation Ambient temperature Humidity Altitude SMC EliteConnect WLAN Security System Installation Manual WLAN Security System Power HD1 LED Reset ON LED...
Page 26
Atmospheric contamination Air flow Power Evaluation Input power type Proximity of receptacle to equipment Dedicated (separate) circuits for redundant power supplies UPS for power failures Grounding Evaluation Circuit breaker size Cable and Interface Equipment Evaluation Cable type Connector type Cable distance limitations Interface equipment (transceivers) EMI Evaluation Distance limitations for signaling...
Please inform your dealer if there are any incorrect, missing or damaged parts. If possible, retain the carton, including the original packing materials. Use them again to repack the product in case there is a need to return it. SMC EliteConnect WLAN Security System Installation Manual Value °...
2.3.2 Rack Mounting the Chassis A rack-mount kit is included for mounting the chassis in a standard 19-inch (48.3 am) equipment rack with two unobstructed outer posts. This kit is not suitable for racks with obstructions (such as a power strip) that could impair access to the device.
Page 29
Choose either a mid-mount or a front-mount location and the appropriate Step 2. L-brackets. Attach the left and right L-brackets using two 10-32 x 3/8 Phillips pan-head screws for each L-bracket SMC EliteConnect WLAN Security System Installation Manual Table 2-3 shows the parts and Quantity...
Page 30
Figure 2-6. Attaching the L Brackets Note: The L-brackets connect the chassis to the rack. You can mount the front L brackets to the front of the system or you can mount the mid-mount L-brackets to the mid-mounting holes. If you use the mid-mount L-brackets, you may mount the chassis facing in or out. Install the chassis in the rack as follows: Step 3.
Plug the power cord into the chassis. Step 2. Connect the other end of the power cord to an AC-power input source. Step 3. SMC EliteConnect WLAN Security System Installation Manual WLAN Security System 2-11...
WLAN S ECURE ERVER NSTALLATION This chapter describes the network installation of your WLAN Secure Server on an existing network to allow interoperability and proper network security between all equipment. It consists of the following sections: 3.1 Getting Started ........3-2 3.2 Installation Using DHCP .
Getting Started The network installation procedures in this chapter are performed after the hardware has been installed, as described in Chapter 2, Hardware Installation. The network installation procedures described in this chapter make a EliteConnect WLAN Secure Server usable on a network. Configuration, or the process of customizing the function of an EliteConnect system to a particular end-user environment, is not described in this manual.
3.1.2 WLAN Secure Server Installation Alternatives SMC WLAN Access Managers and WLAN Secure Servers all shipped with DHCP Client enabled by default to obtain an IP address (and other information) from a Dynamic Host Configuration Protocol (DHCP) server. This means that an Access...
Installation Using DHCP If you choose to install the WLAN Secure Server using DHCP, you must be familiar with the configuration of your DHCP server. This server must be configured to assign to the Secure Server the parameters specified in If the WLAN Secure Server controls one or more WLAN Access Managers, you must enter the shared secret used by those Access Managers to prove to the Secure Server that they are valid Access Managers.
Page 37
IP address: https://<IP address> You will be prompted for the Username and Password with the Administrator Login screen (Figure Figure 3-2. Login ID and Password Prompt SMC EliteConnect WLAN Security System Installation Manual 3-2). WLAN Security System...
Page 38
For both the Username and Password, enter admin, and click Login. The Step 4. Main Menu Click Network. The Network Configuration screen Step 5. Enter the values not supplied by your DHCP server, including Hostname, Step 6. IP Address, Subnet Mask (netmask), Gateway (Default Router), and Primary and Secondary DNS addresses in the appropriate fields.
Page 39
Figure 3-5. Admin Authorization Configuration Screen Enter the username and password and confirm the password. Enable Step 8. technical support access only if requested by an authorized SMC Networks support engineer. Click Submit Changes. Return to the Main Menu Step 9.
Page 40
Figure 3-6. Configure Access Managers Shared Secret Enter the shared secret that additional WLAN Access Managers will use to Step 10. validate themselves to this WLAN Secure Server, if necessary. Confirm your choice. Then click Submit Changes. Complete the configuration of the following items according to Step 11.
Configure the serial port on your management computer at 9600 baud, 8 bits, no parity, with hardware flow control. serial connector, and SMC EliteConnect WLAN Security System Installation Manual Table 3-2 shows the pin assignments for this Figure 3-8 shows the pin configuration.
At the end of the boot and initialization sequence you will see a prompt: SMC Serial Console Press return for console: Press Return and enter admin as the login id and admin as the initial Step 2.
Page 43
User Manual—syslog, time and date, SNMP, and location information. Complete the installation as described in Step 9. Installation." SMC EliteConnect WLAN Security System Installation Manual WLAN Security System (Figure 3-3) and complete the configuration of Section 3.5, "Completing the...
Installation Using the Web-Based Interface You can configure a WLAN Secure Server using one of the four Access Manager ports on the front of the chassis. Follow these steps. Connect one of the four Ethernet access ports to an external computer Step 1.
Page 45
Set the browser of the external management system to Step 5. https://42.0.0.1 You will be prompted for the Administrator username and password SMC EliteConnect WLAN Security System Installation Manual WLAN Security System Wire Wire Color/Cross- Color/Standard...
Page 46
Enter the username and password (default: admin), and click Login. The Step 6. Main Menu appears Click Network. The Network Configuration screen Step 7. 3-14 Figure 3-10. Administrator Login (Figure 3-11). Figure 3-11. Main Menu WLAN Secure Server Network Installation (Figure 3-12) appears.
Page 47
DHCP server. In this case, called DHCP relay, the Access Manager relays the client DHCP request to the DHCP server at the SMC EliteConnect WLAN Security System Installation Manual Figure 3-12. Network Configuration...
Page 48
Figure 3-13. Changing the Web Administrative Username and Password Enter the username, password, and confirm the password. Enable Step 12. technical support access only if requested by an authorized SMC Networks support engineer. Click Submit Changes. Return to the Main Menu. Click Shared Secret Authorization. The Step 13.
Page 49
Step 14. Changes. Connect the WLAN Secure Server Network Uplink port to your network Step 15. (Figure 3-15). Figure 3-15. Connecting the WLAN Secure Server Through the Uplink Port SMC EliteConnect WLAN Security System Installation Manual WLAN Security System 3-17...
Page 50
Verify that you can access the web administration interface from a Step 16. browser running on a computer system connected to your network through either the fully-qualified hostname: https://<fully-qualified hostname> or, if you choose not to assign a hostname, through the IP address: https://<IP address>...
Completing the Installation After configuring the WLAN Secure Server, you must complete the installation by connecting one or more wireless access points to the WLAN Secure Server ports using crossover 10Base-T/100Base-TX Ethernet cables. Note that the ports on the WLAN Secure Server are labeled 1 to 4, reading from left to right Figure 3-16.
Page 52
3-20 WLAN Secure Server Network Installation...
WLAN A CCESS ANAGER NSTALLATION This chapter describes the network installation of your WLAN Access Manager on an existing network to allow interoperability and proper network security between all equipment. It consists of the following sections: 4.1 Getting Started ......... . 4-2 4.2 Installation Using DHCP .
SMC WLAN Access Manager usable on a network. Configuration, or the process of customizing the function of a SMC system to a particular end-user environment, is not described in the manual. Configuration, performed after network installation is completed, is described in another manual, entitled EliteConnect WLAN Security System User Manual.
4.1.2 Access Manager Installation Alternatives SMC WLAN Access Managers and WLAN Secure Servers all ship with DHCP client enabled by default to obtain an IP address (and other information) from a Dynamic Host Configuration Protocol (DHCP) server. This means that a WLAN...
Access Manager the parameters previously defined in Table 4-1. Appendix B describes procedures to make your DHCP server assign these SMC-specific options. Follow these steps Connect the Access Manager Network Uplink port to your network Step 1.
Page 57
Administrator Login screen Figure 4-2. Login ID and Password Prompt For both the Username and Password, enter admin, and click Login. The Step 4. Main Menu SMC EliteConnect WLAN Security System Installation Manual (Figure 4-2). (Figure 4-3) appears. Figure 4-3. Main Menu...
Page 58
If you have not used DHCP to set the IP address and shared secret of the Step 5. WLAN Secure Server, do so now by clicking on Control Server in the Main Menu, and enter the Control Server IP Address, Secret Key, and Confirm Secret Key.
Configure the serial port on your management computer at 9600 baud, 8 bits, no parity, with hardware flow control. serial connector, and SMC EliteConnect WLAN Security System Installation Manual Table 4-2 shows the pin assignments for this Figure 4-6 shows the pin configuration.
Power up the WLAN Access Manager. You will see a series of messages Step 1. as the system boots and initializes itself. At the end of the boot and initialization sequence you will see a prompt: SMC Serial Console Press return for console: Symbol WLAN Access Manager Network Installation...
Page 61
Complete configuration according to instructions in the User Manual— Step 6. Location Information, and Time and Date. Complete the installation as described in Step 7. Installation." SMC EliteConnect WLAN Security System Installation Manual Section 4.5, "Completing the at the end of this chapter. WLAN Security System...
Installation Using the Web Based Interface You can configure a WLAN Access Manager using one of the four access manager ports on the front of the chassis. Follow these steps. Connect one of the four Ethernet access ports to an external computer Step 1.
Page 63
In general, any device attached through one of the Access Manager ports can always use the address of 42.0.0.1 as a shorthand way of accessing the administrative interface of that device. SMC EliteConnect WLAN Security System Installation Manual WLAN Security System Wire...
Page 64
Set the browser of the external management system to Step 5. https://42.0.0.1 You will be prompted for the username and password For both the username and password, enter admin, and click Login. The Step 6. Main Menu Click Network. The Network Configuration screen Step 7.
Page 65
Secure Server needs to know how to locate the DHCP server. In this case, called DHCP relay, the WLAN Access Manager relays the client DHCP request SMC EliteConnect WLAN Security System Installation Manual Figure 4-10. Network Configuration WLAN Security System...
Page 66
Configuration screen appears Figure 4-11. Admin Authorization Configuration Enter the username, password, and confirm the password. Enable Step 11. technical support access only if requested by an authorized SMC Networks support engineer. Click Submit Changes. 4-14 (Figure 4-9). Change the username and (Figure 4-11).
Page 67
Complete configuration according to instructions in the User Manual— Step 14. time and date, and SNMP. Complete the installation as described in Step 15. Installation." SMC EliteConnect WLAN Security System Installation Manual WLAN Security System (Figure 4-9). Click Control Server. The Specify Figure 4-12. Then click Submit Changes.
Completing the Installation After configuring the WLAN Access Manager, you must complete the installation by connecting its Network Uplink to your IP network using a standard 10Base- T/100Base-TX Ethernet cable. If the system was configured to use a static IP address, the system should now be accessible via its web server by specifying either the system hostname or its IP address from an external web browser.
Page 69
For a WLAN Access Manager, you complete installation by connecting Step 3. one to four wireless access points to the Access Manager ports, using crossover 10Base-T/100Base-TX Ethernet cables. Note that the ports on the Access Manager are labeled 1 to 4, reading from left to right 13).
ROUBLESHOOTING This chapter presents troubleshooting procedures for the EliteConnect WLAN Security System. Table 5-1 action for a non-responsive unit. Table 5-1 Troubleshooting Guide Symptom(s) Probable Cause LED Off No Power LED on but fans not Defective Fan running Improper Ethernet Cable Network uplink connected before configuration Management system not...
Page 72
Table 5-1 Troubleshooting Guide (Continued) Symptom(s) Unit inaccessible from management system after configuration Can’t get to Control Server or Rights Manager No traffic through access point No initial web page Incorrect Rights Can’t use NT domain login Probable Cause Recommended Action Incorrect configuration Access system through network uplink, check configuration.
Page 73
Table 5-1 Troubleshooting Guide (Continued) Symptom(s) Radius Authentication not working LDAP Authentication not working SMC EliteConnect WLAN Security System Installation Manual Probable Cause Recommended Action Radius configuration 1. Check Radius server incorrect configuration 2. Check Radius “secret” matches on unit and Radius server 3.
OMMAND NTERFACE This appendix documents the commands that are available on the serial console as part of the Command Line Interface (CLI). The CLI enables initial configuration and subsequent troubleshooting of WLAN Security System. The Command Line Interface are listed in the following categories: A.1 Syntax for Command Line Interface .
Syntax for Command Line Interface The following text explains the syntax used for the command line interface. indicates commands you can type. Bold courier Italics indicate variables. You must replace variables with the appropriate value for your network. An option inside a set of square brackets ([ ]) indicates that specifying this value is optional, for example: debug ip [interface] where specifying an interface is an option you can choose.
set admin login-name Change the console and web admin login and password. Prompts for password if not entered on the command line. clear admin Remove the console and web admin login and password. show admin Show the current console and web admin login. The password is not displayed.
Page 78
Translates to: tcpdump –en –i interface ip debug interface [interface] Show traffic on an interface. The console session is restarted after the command is completed. interface Translates to: tcpdump –en -i interface debug tcpport port [interface] Show specified TCP port traffic on an interface. The console session is restarted after the command is completed.
System Status Commands show status Display an overview of the system status. For a Control Server, includes up time and the IP address, MAC address and connect time for each connected Access Manager. For a Access Manager, this command includes up time and the IP address and the connect time for its Control Server.
clear logs Clear the error log. Active Client Management Commands Use these commands to manage Active Clients. show clients [mac [sort (mac | ip | user | machine | port | sessions | idle)] [reverse] List active clients. mac-address MAC (Ethernet) address to display. Format: xx:xx:xx:xx:xx:xx show client mac mac-address [ rights ] List active sessions for a client.
B.8.1 Upgrading the System Software get upgrade url key [reboot | version] Retrieve and install a software release. This command starts a background task that can be checked with the show upgrade command. reboot version show upgrade Show the status of the cancel upgrade Cancel the current set upgradeproxy [on | off] [host ip [port]] [user user [pass-...
downgrade same shutdown Shuts down the system. factoryreset Restores the user configurable data with factory defaults. B.8.3 Network Configuration set hostname hostname Set the system's hostname. The system hostname is also used as the SNMP system name. hostname clear hostname Clear the system's hostname.
clear sharedsecret Clear the Access Manager or Control Server shared secret. show sharedsecret Show whether the Access Manager or WLAN Secure Server shared secret is set. The shared secret is not displayed. set pptp on | off This command enables and disables PPTP. set l2tp on | off This command enables and disables L2TP.
Page 84
[secret secret] Set the IPSec shared secret. Prompts for the secret if not entered on the command line. A-10 Cisco Discovery Protocol Wireless Network Access Protocol IP Multicast Type any string The DHCP server IP address. forwardipbroadcasts Disable IP broadcast forwarding on all ports.
show ipsec This command shows PPTP and L2TP settings. set ipsec on | off Enable or disable IPSec. clear ipsecsecret If IPSec is enabled, this command disables it when clearing the secret. set espencryption [des] [3des] [blowfish] [cast] [none] Set the IPSec ESP encryption methods. You must specify at least one method.
B.8.5 Time Configuration set timezone general-tz specific-tz Set the local timezone. general-tz specific-tz set ntpserver ip-address | hostname [ip-address | hostname ] Set the NTP servers IP address or hostnames. Hostnames must be fully qualified if specified. ip-address hostname clear ntpserver Clear the NTP servers IP address or hostnames.
The URL encoded location to store the backup. The host must be an FTP server. The destination filename for the backup image. The default is smc-yyyy-mm-dd. The URL encoded location to store the backup. The host must be an FTP server.
Page 88
set snmplocation location Sets the SNMP sysLocation object defined in RFC 1213 as “the physical location of this node (for example, telephone closet, 3rd floor).” clear snmplocation Clears the SNMP location. set snmpcontact contact Sets the SNMP identification of the contact person for this managed node, together with information on how to contact this person.”...
DHCP S ONFIGURING A This appendix describes how to configure a DHCP server to include the SMC Networks-specific options of assigning a Control Server IP address and shared secret to an Access Manager. It consists of the following sections B.1 Preliminary Considerations ......B-2 B.2 ISC DHCP Package, Version 3.X .
If you are using version 3.0 or higher of the ISC DHCP server, you may Step 1. add the following in the file dhcpd.conf: # Here are the SMC Networks specific options. A user must edit # the values of cs-address and shared secret to set up a # SMC Networks AM option space SMC Networks;...
Page 91
A Microsoft DHCP server using the Windows 2000™ Server operating system is capable of specifying vendor-specific options. Refer to the help information for the Windows 2000 Server. The basic method is to create a SMC Networks scope and then create vendor-specific options for this scope. Two options must be created—...
Page 92
Figure B-1. DHCP Window Right-click the w2kserver tree node. The window of Figure B-2 appears. Step 2. Figure B-2. W2kserver Node Right Clicked Configuring a DHCP Server...
Page 93
Choose Define Vendor Classes. The DHCP Vendor Class window Step 3. (Figure B-3) appears. Figure B-3. DHCP Vendor Class Window Click Add. The New Class window appears Step 4. SMC EliteConnect WLAN Security System Installation Manual Figure B-4. New Class Window WLAN Security System (Figure B-4).
Page 94
Setting Predefined Options Right-click the w2kserver tree node Step 7. Options from the drop-down menu, and choose SMC Networks from the Option Class drop-down menu. Then click Add. The Option Type window appears. Enter the data as shown in Table 8-1.
Page 95
Figure B-7. Option Type Window—Shared Secret B.3.3 Assigning Values to SMC Networks Vendor-Specific Options In the current scope that contains the SMC Networks devices, right-click Step 9. on the Scope Options tree node. From the pop-up menu, choose Configure Options. The Scope Options window...
Page 96
— Figure B-8. Configure Options Window—Control Server IP Address Click the Advanced tab. For Vendor Class, choose SMC Networks Inc. For Step 10. User Class, choose Default User Class. Check the box 002 Control Server IP from the list, and type the Control Server IP Address. Be sure that the check box for the Control Server IP is checked, and click Apply and then Repeat Step 9.
Page 97
Click Apply and then OK. Step 12. Note: More information on creating a new DHCP user or vendor class is available from Microsoft document Q240247. It is available on the web at http://support.microsoft.com/default.aspx?scid=kb;en-us;Q240247 SMC EliteConnect WLAN Security System Installation Manual...
Page 103
PRC: Taiwan: Asia Pacific: Korea: Japan: Australia: India: If you are looking for further contact information, please visit www.smc.com or www.smc-europe.com. 38 Tesla Irvine, CA 92618 Phone: (949) 679-8000 SMC EliteConnect WLAN Security System Installation Manual (800) SMC-4-YOU; Fax (949) 679-1481 34-93-477-4935;...
Need help?
Do you have a question about the ELITECONNECT SMC2502W and is the answer not in the manual?
Questions and answers