Page 2
Proxim Corporation. Trademarks ORiNOCO is a registered trademark, and Proxim, and the Proxim logo are trademarks of Proxim Corporation. All other trademarks mentioned herein are the property of their respective owners. OpenSSL License Note This product contains software developed by the OpenSSL Project for use in the OpenSSL Toolkit (http://www.openssl.org/) and that is...
Page 8
Contents AP-4000 User Guide Attaching the Serial Port Cable ............129 Initializing the IP Address using CLI .
Page 9
Contents AP-4000 User Guide Enable 802.11d Support and Set the Country Code ..........146 Enable and Configure TX Power Control for the Wireless Interface(s) .
Page 10
Contents AP-4000 User Guide Serial Port Parameters ..............168 RADIUS Based Management Access Parameters .
Page 11
AP-4000 User Guide CLI Batch File Error Log ..............185 B ASCII Character Chart .
Page 12
AP-4000 User Guide Ask a Question or Open an Issue .............196 Other Adapter Cards .
AP-4000 User Guide Introduction • Document Conventions • Introduction to Wireless Networking • IEEE 802.11 Specifications • Management and Monitoring Capabilities Document Conventions • The term, AP, refers to an Access Point. • The term, 802.11, is used to describe features that apply to the 802.11a, 802.11b, and 802.11g wireless standards.
Introduction AP-4000 User Guide Introduction to Wireless Networking Guidelines for Roaming • An AP can only communicate with client devices that support its wireless standard. • All Access Points must have the same Network Name to support client roaming. •...
Introduction AP-4000 User Guide IEEE 802.11 Specifications IEEE 802.11 Specifications In 1997, the Institute of Electrical and Electronics Engineers (IEEE) adopted the 802.11 standard for wireless devices operating in the 2.4 GHz frequency band. This standard includes provisions for three radio technologies: direct sequence spread spectrum, frequency hopping spread spectrum, and infrared.
Introduction AP-4000 User Guide Management and Monitoring Capabilities SNMP Management In addition to the HTTP and the CLI interfaces, you can also manage and configure an AP using the Simple Network Management Protocol (SNMP). Note that this requires an SNMP manager program, like HP Openview or Castlerock’s SNMPc. The AP supports several Management Information Base (MIB) files that describe the parameters that can be viewed and/or configured over SNMP: •...
AP-4000 Rear Panel The AP-4000 has been designed to rest horizontally on a flat surface, but can be wall or ceiling mounted with the long axis vertical. The bottom of the unit includes screw slots in the bottom plastic for mounting to a flat wall or ceiling.
The Dual Band REA is a dual band indoor antenna that works with both 2.4 GHz (802.11b/g) and 5 GHz (802.11a) radios. The Dual Band REA can be used with either radio on the AP-4000. The Dual Band REA allows for better antenna placement for optimizing cell size.
Rebooting. Prerequisites Before installing an AP-4000, you need to gather certain network information. The following section identifies the information you need. Network Name (SSID of the wireless cards) You must assign the Access Point a Network Name before wireless users can communicate with it.
Getting Started AP-4000 User Guide Product Package Product Package Each AP-4000 comes with the following: • AP-4000 unit (with integrated 802.11a radio and 802.11b/g radio, and Active Ethernet) • Power adapter • One ceiling or wall mounting plate • Security cover •...
1. Plug the power cord into the power jack (the left port) and connect the unit to an AC power outlet (100~240V, 50~60Hz). 2. If using active Ethernet, connect power to the unit from a DC injector device, such as the ORiNOCO 1-Port Active Ethernet DC Injector hub.
You cannot connect an RS-232 cable to the AP-4000 when a security cover is installed. 1. Slide the hinging end of the security cover into the hole on the rear panel of the AP-4000 to the left of the connectors.
Figure 2-5 Dual Band Range Extender Antenna Perform the following procedures to mount the Dual Band REA to a wall or ceiling and to install it on the AP-4000: Wall Mount Installation Perform the following steps to wall mount the Dual Band REA: 1.
Perform the following steps to attach a Dual Band REA to the AP-4000. 1. Press down near the center of the compartment covering and slide open the External Antenna Access compartment on the AP-4000. The compartment closer to the LED panel contains the connectors for the 802.11 b/g radio, and the other compartment contains the connectors for the 802.11a radio.
NOTE There are four antenna connectors in the AP-4000, labeled 1 through 4. Connectors 1 and 2 are for the 802.11b/g radio, and connectors 3 and 4 and for the 802.11a radio. When connecting one REA to a radio, use connectors 1 or 4, as appropriate. The second REA for a radio should be connected to connectors 2 or 3.
4. Insert the Installation CD into the CD-ROM drive of the computer that you will use to configure the AP. – Result: The installation program will launch automatically. 5. Follow the on-screen instructions to install the Access Point software and documentation. NOTE The ORiNOCO Installation program supports the following operating systems: • Windows 98SE • Windows 2000 •...
Page 27
Getting Started AP-4000 User Guide Initialization Figure 2-8 Scan List 7. Locate the MAC address of the AP you want to initialize within the Scan List. NOTE If your Access Point does not show up in the Scan List, click the Rescan button to update the display. If the unit still does not appear...
Getting Started AP-4000 User Guide Initialization Click OK to save your changes. — Result: The Access Point will reboot automatically and any changes you made will take effect. When prompted, click OK a second time to return to the Scan List screen.
Page 29
Do not use quotation marks (single or double) in the Network Name; this will cause the AP to misinterpret the name. — Additional Network Names (SSIDs): The AP-4000 supports up to 16 SSIDs and VLANs per wireless interface (radio). Please refer to the Advanced Configuration chapter for information on the detailed rules on configuring multiple SSIDs, VLANs, and security profiles.
Dynamic Frequency Selection (DFS) for details). — Transmit Rate: Use the drop-down menu to select a specific transmit rate for the AP-4000’s radios. For the 802.11b/g radio operating in 802.11b mode, choose between 1, 2, 5.5, 11 Mbits/s, and Auto Fallback.
Getting Started AP-4000 User Guide Latest Software Availability NOTE If a TFTP server is not available in the network, you can perform similar file transfer operations using the HTTP interface. After the TFTP server is installed: • Check to see that TFTP is configured to point to the directory containing the AP Image.
Getting Started AP-4000 User Guide Logging into the HTTP Interface Logging into the HTTP Interface Once the AP has a valid IP Address and an Ethernet connection, you may use your web browser to monitor and configure the AP. (To...
Getting Started AP-4000 User Guide Related Topics Figure 2-13 System Status Screen The buttons on the left of the screen provide access to the monitoring and configuration options for the AP. See Viewing Status Information more information about the Status screen.
AP-4000 User Guide Viewing Status Information The first screen displayed after Logging into the HTTP Interface is the System Status screen. You can always return to this screen by clicking the Status button. Figure 3-1 System Status Screen Each section of the System Status screen provides the following information: •...
AP-4000 User Guide Performing Advanced Configuration • System: Configure specific system information such as system name and contact information. • Network: Configure IP settings, DNS client, DHCP server, DHCP Relay Agent, DHCP Relay Servers, and Link Integrity. • Interfaces: Configure the Access Point’s interfaces: Wireless A, Wireless B, and Ethernet. Configure a Wireless Distribution System (WDS).
Page 36
Performing Advanced Configuration AP-4000 User Guide To configure the AP via HTTP/HTTPS: 1. Click the Configure button located on the left-hand side of the screen. Figure 4-1 Configure Main Screen 2. Click the tab that corresponds to the parameter you want to configure. For example, click Network to configure the Access Point’s TCP/IP settings.
Performing Advanced Configuration AP-4000 User Guide System System You can configure and view the following parameters within the System Configuration screen: • Name: The name assigned to the AP. Refer to the Dynamic DNS Support Access Point System Naming Convention sections for rules on naming the AP.
Page 38
Performing Advanced Configuration AP-4000 User Guide System Image upgrades could cause the system to boot with an older system name format that is not DNS compliant. To prevent problems with dynamic DNS after an image upgrade, the system name will automatically be converted to a DNS compliant system name.
Performing Advanced Configuration AP-4000 User Guide Network Network The Network tab contains the following sub-tabs: • IP Configuration • DHCP Server • DHCP Relay Agent • Link Integrity IP Configuration This tab is used to configure the internet (TCP/IP) settings for the access point.
Performing Advanced Configuration AP-4000 User Guide Network DNS Client If you prefer to use host names to identify network servers rather than IP addresses, you can configure the AP to act as a Domain Name Service (DNS) client. When this feature is enabled, the Access Point contacts the network’s DNS server to translate a host name to the appropriate network IP address.
Performing Advanced Configuration AP-4000 User Guide Network You can configure and view the following parameters within the DHCP Server Configuration screen: • Enable DHCP Server: Place a check mark in the box provided to enable DHCP Server functionality. NOTE You cannot enable the DHCP Server functionality unless there is at least one IP Pool Table Entry configured.
Performing Advanced Configuration AP-4000 User Guide Network Figure 4-5 DHCP Relay Agent DHCP Server IP Address Table To add entries to the table of DHCP Relay Agents, click Add in the DHCP Server IP Address Table; the following window is displayed.
Performing Advanced Configuration AP-4000 User Guide Network Link Integrity The Link Integrity feature checks the link between the AP and the nodes on the Ethernet backbone. These nodes are listed by IP address in the Link Integrity IP Address Table. The AP periodically pings the nodes listed within the table. If the AP loses network connectivity (that is, the ping attempts fail), the AP disables its wireless interface(s).
Performing Advanced Configuration AP-4000 User Guide Interfaces Interfaces From the Interfaces tab, you configure the Access Point’s power control settings, wireless interface settings and Ethernet settings. You can configure the operational mode and the Transmit Power Control settings for each radio. You may also configure a Wireless Distribution System for AP-to-AP communications.
Performing Advanced Configuration AP-4000 User Guide Interfaces Operational Mode From this tab, you can configure and view the operational mode for the Wireless-A (802.11a radio) or Wireless-B (802.11b/g radio) Interface. The Wireless-A interface operates only in 802.11a mode. The Wireless-B interface can be configured to operate in the following modes: •...
Page 46
Performing Advanced Configuration AP-4000 User Guide Interfaces • 100% of the maximum transmit power level defined by the regulatory domain • • • 12.5% When Transmit Power Control is enabled, the transmit power level of the card in the AP is set to the configured transmit power level. The power level is advertised in Beacon and Probe Response frames as the 802.11d maximum transmit power level.
Performing Advanced Configuration AP-4000 User Guide Interfaces Wireless-A (802.11a Radio) and Wireless-B (802.11b/g Radio) Figure 4-10 Wireless Interface B You can view and configure the following parameters for the Wireless-A and Wireless-B interfaces: NOTE You must reboot the Access Point before any changes to these parameters take effect.
Performing Advanced Configuration AP-4000 User Guide Interfaces • Frequency Channel: When Auto Channel Select is enabled, this field is read-only and displays the Access Point’s current operating Channel. When Auto Channel Select is disabled, you can specify the Access Point’s operating channel. If you decide to manually set the unit’s Channel, ensure that nearby devices do not use the same frequency (unless you are setting up WDS links).
When the wireless service is shut down on a wireless interface, the AP generates a trap called oriTrapWirelessServiceShutdown. When the wireless service is resumed on a wireless interface, the AP generate a trap called oriTrapWirelessServiceResumed. NOTE In the AP-4000, which has dual wireless interfaces, wireless service can be shut down/resumed on each wireless interface individually. Multicast Rate The multicast rate determines the rate at which broadcast and multicast packets are transmitted by the Access Point to the wireless network.
AP that does not have Ethernet connectivity to a second AP that has Ethernet connectivity. WDS allows you to configure up to six (6) ports per radio, or up to 12 ports on the AP-4000. In the WDS example below, AP 1 and AP 2 communicate over a WDS link (represented by the blue line). This link provides Client 1 with access to network resources even though AP 1 is not directly connected to the Ethernet network.
Page 51
Performing Advanced Configuration AP-4000 User Guide Interfaces Bridging WDS Each WDS link is mapped to a logical WDS port on the AP. WDS ports behave like Ethernet ports rather than like standard wireless interfaces: on a BSS port, an Access Point learns by association and from frames; on a WDS or Ethernet port, an Access Point learns from frames only.
Page 52
Performing Advanced Configuration AP-4000 User Guide Interfaces Figure 4-14 Adding WDS Links 6. Select whether to use encryption in the WDS by checking the Enable WDS Security Mode checkbox. 7. If you enabled WDS Security Mode, enter the Encryption Key 0 used for encryption between the WDS links.
Performing Advanced Configuration AP-4000 User Guide Interfaces Ethernet Select the desired speed and transmission mode from the drop-down menu. Half-duplex means that only one side can transmit at a time and full-duplex allows both sides to transmit. When set to auto-duplex, the AP negotiates with its switch or hub to automatically select the highest throughput option supported by both sides.
Performing Advanced Configuration AP-4000 User Guide Management Management The Management tab contains the following sub-tabs: • Passwords • IP Access Table • Services • Automatic Configuration (AutoConfig) • Hardware Configuration Reset (CHRD) Passwords You can configure the following passwords: •...
Performing Advanced Configuration AP-4000 User Guide Management Services You can configure the following management services: Secure Management Secure Management allows the use of encrypted and authenticated communication protocols such as SNMPv3, Secure Socket Link (SSL), and Secure Shell (SSH) to manage the Access Point.
Performing Advanced Configuration AP-4000 User Guide Management Telnet Configuration Settings • Telnet Interface Bitmask: Select the interface (Ethernet, Wireless-Slot A, Wireless-Slot B, All Interfaces) from which you can manage the AP via telnet. This parameter can also be used to Disable telnet management.
Performing Advanced Configuration AP-4000 User Guide Management To manually generate or delete host keys on the AP: • Select Create to generate a new pair of host keys. • Select Delete to remove the host keys from the AP. If no host keys are present, the AP will not allows connections using SSH. When host keys are created or deleted, the AP updates the fingerprint information displayed on the Management >...
Performing Advanced Configuration AP-4000 User Guide Management • Serial Stop Bits: This is a read-only field that displays the number of stop bits used in serial communication (1 stop bit by default). NOTE The serial port bit configuration is commonly referred to as 8N1.
4. Enter the IP address of the TFTP server in the TFTP Server Address field. NOTE The default filename is “config”. The default TFTP IP address is “169.254.128.133” for AP-4000. 5. Click OK to save the changes. 6. Reboot the AP. When the AP reboots it receives the new configuration information and must reboot one additional time. If a Syslog server was configured, the following messages can be observed on the Syslog server: •...
Page 61
Performing Advanced Configuration AP-4000 User Guide Management Set up Automatic Configuration for Dynamic IP Perform the following procedure to enable and set up Automatic Configuration when you have a dynamic IP address for the TFTP server via DHCP. The Configuration filename and the TFTP server IP address are contained in the DHCP response when the AP gets its IP address dynamically from the DHCP server.
Page 62
Performing Advanced Configuration AP-4000 User Guide Management 6. Set the value of the Bootfile Name parameter to the Configuration filename. For example: AP-Config 7. If using Syslog, set the Log server IP address (option 7, Log Servers). 8. Reboot the AP. When the AP reboots it receives the new configuration information and must reboot one additional time. If a Syslog server was configured, the following messages can be observed on the Syslog server: •...
Performing Advanced Configuration AP-4000 User Guide Management Hardware Configuration Reset (CHRD) Hardware Configuration Reset Status is a parameter that defines the hardware configuration reset behavior of the AP (i.e., what effect pressing the reload button has on an AP operating in normal operating mode).
Page 64
Performing Advanced Configuration AP-4000 User Guide Management NOTE It is important to safely store the configuration reset password. If a user forgets the configuration reset password, the user will be unable to reset the AP to factory default configuration if the AP becomes inaccessible and the hardware configuration reset functionality is disable.
Performing Advanced Configuration AP-4000 User Guide Filtering Filtering The Access Point’s Packet Filtering features help control the amount of traffic exchanged between the wired and wireless networks. There are four sub-tabs under the Filtering heading: • Ethernet Protocol • Static MAC •...
Performing Advanced Configuration AP-4000 User Guide Filtering For example, if the MAC Address is 00:20:A6:12:54:C3 and the Mask is FF:FF:FF:00:00:00, the AP will examine the source and destination addresses of each packet looking for any MAC address starting with 00:20:A6. If the Mask is FF:FF:FF:FF:FF:FF, the AP will only look for the specific MAC address (in this case, 00:20:A6:12:54:C3).
Page 67
Performing Advanced Configuration AP-4000 User Guide Filtering Prevent Multiple Wireless Devices From Communicating With a Single Wired Device Configure the following settings to prevent Wireless Clients 1 and 2 from communicating with the Wired Server: • Wired MAC Address: 00:40:F4:1C:DB:6A •...
Performing Advanced Configuration AP-4000 User Guide Filtering Advanced You can configure the following advanced filtering options: • Enable Proxy ARP: Place a check mark in the box provided to allow the Access Point to respond to Address Resolution Protocol (ARP) requests for wireless clients.
Performing Advanced Configuration AP-4000 User Guide Alarms Alarms The Alarms tab has four sub-tabs: • Groups • Alarm Host Table • Syslog • Rogue Scan Groups There are seven alarm groups that can be enabled or disabled via the Web interface. Place a check mark in the box provided to enable a specific group.
Page 70
Performing Advanced Configuration AP-4000 User Guide Alarms Trap Name Description Severity Level MIC Attack Detected Supported in web interface only. Major MIC Attack Report Detected Supported in web interface only. Major • Wireless Interface/Card Trap Group Trap Name Description Severity Level...
Performing Advanced Configuration AP-4000 User Guide Alarms • Image Trap Group Trap Name Description Severity Level Zero Size Image oriTrapZeroSizeImage Major Invalid Image oriTrapInvalidImage Major Image Too Large oriTrapImageTooLarge Major Incompatible Image oriTrapIncompatibleImage Major Invalid Image Digital Signature oriTrapInvalidImageDigitalSignature Major In addition, the AP supports these standard traps, which are always enabled: •...
Performing Advanced Configuration AP-4000 User Guide Alarms Syslog The Syslog messaging system enables the AP to transmit event messages to a central server for monitoring and troubleshooting. The AP can send messages to one Syslog server (it cannot send messages to more than one Syslog server). The access point logs “Session Start (Log-in)”...
Performing Advanced Configuration AP-4000 User Guide Alarms – Comment: Enter an optional comment such as the host name. – Status: The entry is enabled automatically when saved (so the Status field is only visible when editing an entry). You can also disable or delete entries by changing this field’s value.
Performing Advanced Configuration AP-4000 User Guide Alarms Rogue Scan The Rogue Scan feature provides an additional security level for wireless LAN deployments. Rogue Scan uses the selected wireless interface(s) for scanning its coverage area for Access Points and clients. A centralized Network Manager receives MAC address information from the AP on all wireless clients detected by the AP. The Network Manager then queries all wired switches to find out the inbound switch/port of these wireless clients.
Performing Advanced Configuration AP-4000 User Guide Alarms Rogue Scan Data Collection The AP stores information gathered about detected stations during scanning in a Rogue Scan result table. The Rogue Scan result table can store a maximum of 2000 entries. When the table fills, the oldest entry gets overwritten. The Rogue Scan result table lists the following information about each detected station: •...
Performing Advanced Configuration AP-4000 User Guide Bridge Bridge The AP is a bridge between your wired and wireless networking devices. As a bridge, the functions performed by the AP include: • MAC address learning • Forward and filtering decision making •...
Performing Advanced Configuration AP-4000 User Guide Bridge Packet Forwarding The Packet Forwarding feature enables you to redirect traffic generated by wireless clients that are all associated to the same AP to a single MAC address. This filters wireless traffic without burdening the AP and provides additional security by limiting potential destinations or by routing the traffic directly to a firewall.
Performing Advanced Configuration AP-4000 User Guide Wireless Multimedia Extensions (WME)/Quality of Service (QoS) The AP supports Wireless Multimedia Enhancements which defines an intermediate solution for QoS functionality until the IEEE 802.11e specification is formally approved. WME is based on a subset of the 802.11e standard, and defines enhancements to the MAC for wireless LAN applications with Quality of Service requirements, which include transport of voice traffic over IEEE 802.11 wireless LANs.
Page 80
Performing Advanced Configuration AP-4000 User Guide Figure 4-27 Add QoS Policy 5. Enter the Policy Name. 6. Select the Policy Type: – inlayer2: inbound traffic direction, Layer 2 traffic type – inlayer3: inbound traffic direction, Layer 3 traffic type –...
Performing Advanced Configuration AP-4000 User Guide Priority Mapping Use this page to configure QoS 802.1p to 802.1d priority mappings (for layer 2 policies) and IP DSCP to 802.1d priority mappings (for layer 3 policies). The first entry in each table contains the recommended priority mappings. Custom entries can be added to each table with different priority mappings.
Page 82
Performing Advanced Configuration AP-4000 User Guide 2. Click Add in the 802.1p and 802.1d priority mapping table. Figure 4-29 Add Priority Mapping Entry 3. Select the 802.1p Priority (from 0-7) for 802.1d Priorities 0-7. 4. Click OK. 5. Click Add in the IP Precedence/DSCP ranges and 802.1d Priority table.
Performing Advanced Configuration AP-4000 User Guide Enhanced Distributed Channel Access (EDCA) WME uses Enhanced Distributed Channel Access, a prioritized CSMA/CA access mechanism used by WME-enabled clients/AP in a WME enabled BSS to realize different classes of differentiated Channel Access. A wireless Entity is defined as all wireless clients and APs in the wireless medium contending for the common wireless medium. EDCA uses a separate channel access function for each of the Access Categories (Index) within a wireless entity.
Page 84
Performing Advanced Configuration AP-4000 User Guide 2. Click Edit and configure the following parameters in each table: Figure 4-31 Edit EDCA Tables • Index: read-only. Indicates the index of the Access Category (1-4) being defined. • CWMin: minimum Contention Window. Configurable range is 0 to 255.
Performing Advanced Configuration AP-4000 User Guide Radius Profiles Radius Profiles Configuring Radius Profiles on the AP allows the administrator to define a profile for RADIUS Servers used by the system or by a VLAN. The network administrator can define RADIUS Servers per Authentication Mode and per VLAN.
Performing Advanced Configuration AP-4000 User Guide Radius Profiles Authentication servers for each VLAN shall be configured as part of the configuration options for that VLAN. RADIUS profiles are independent of VLANs. The user can define any profile to be the default and associate all VLANs to that profile. Four profiles are created by default, “MAC Authentication”, “EAP Authentication”, Accounting”, and “Management”.
Page 87
Performing Advanced Configuration AP-4000 User Guide Radius Profiles Figure 4-34 Add RADIUS Server Profile • Server Profile Name: the profile name. This is the name used to associated a VLAN to the profile. Refer to Configuring Security Profiles. The Server Profile Name is also used in the Configure > Management > Services page to specify the RADIUS profile to be used for RADIUS Based Management Access.
Performing Advanced Configuration AP-4000 User Guide Radius Profiles 3. Click OK. 4. Select the Profile and click Edit to configure the Secondary RADIUS Server, if required. MAC Access Control Via RADIUS Authentication If you want to control wireless access to the network and if your network includes a RADIUS Server, you can store the list of MAC addresses on the RADIUS server rather than configure each AP individually.
Page 89
Performing Advanced Configuration AP-4000 User Guide Radius Profiles – If the RADIUS server does not send a Session-Timeout, the AP will set the subscriber expiration time to 0, which means indefinite access. – The Termination Action attribute defines how the Session-Timeout attribute will be interpreted. If the Termination Action is DEFAULT, then the session is terminated on expiration of the Session-Timeout time interval.
Performing Advanced Configuration AP-4000 User Guide SSID/VLAN/Security SSID/VLAN/Security The AP provides several security features to protect your network from unauthorized access. The SSID/VLAN/Security tab contains the following sub-tabs that allow for configuration of security features: • Management VLAN • Security Profile •...
Performing Advanced Configuration AP-4000 User Guide SSID/VLAN/Security In the following figure, the numbered items correspond to the following components: VLAN-enabled access point VLAN-aware switch (IEEE 802.1Q uplink) AP management via wired host (SNMP, Web interface or CLI) DHCP Server RADIUS Server...
Performing Advanced Configuration AP-4000 User Guide SSID/VLAN/Security The three primary scenarios for using VLAN workgroups are as follows: 1. VLAN disabled: Your network does not use VLANs, and you cannot configure the AP to use multiple SSIDs. 2. VLAN enabled, each VLAN workgroup uses a different VLAN ID Tag 3.
Performing Advanced Configuration AP-4000 User Guide SSID/VLAN/Security Security Profile The AP supports the following Security features: • Encryption: The original encryption technique specified by the IEEE 802.11 standard. • 802.1x Authentication: An IEEE standard for client authentication. • Wi-Fi Protected Access (WPA/WPA2): A new standard that provides improved encryption security over WEP.
Performing Advanced Configuration AP-4000 User Guide SSID/VLAN/Security The AP acts as a pass-through device to facilitate communications between the client PC and the RADIUS server. The AP (2) and the client (1) exchange 802.1x messages using an EAPOL (EAP Over LAN) protocol (A). Messages sent from the client station are encapsulated by the AP and transmitted to the RADIUS (3) server using EAP extensions (B).
VLANs and Security Profiles The AP-4000 allows you to segment wireless networks into multiple sub-networks based on Network Name (SSID) and VLAN membership. A Network Name (SSID) identifies a wireless network. Clients associate with Access Points that share an SSID. During installation, the...
Page 96
Performing Advanced Configuration AP-4000 User Guide SSID/VLAN/Security — For 64-bit encryption, an encryption key is 10 hexadecimal characters (0-9 and A-F) or 5 ASCII characters (see ASCII Character Chart). — For 128-bit encryption, an encryption key is 26 hexadecimal characters or 13 ASCII characters.
Performing Advanced Configuration AP-4000 User Guide SSID/VLAN/Security MAC Access The MAC Access sub-tab allows you to build a list of stations, identified by their MAC addresses, authorized to access the network through the AP. The list is stored inside each AP within your network. Note that you must reboot the AP for any changes to the MAC Access Control Table to take effect.
Page 99
Performing Advanced Configuration AP-4000 User Guide SSID/VLAN/Security This tab allows you to select the index of the SSID/VLAN to be added or edited. It also allows you to configure the RADIUS Authentication Status, the MAC ACL Status, the Security Profile for the VLAN, the RADIUS Server Profiles, and gives you the option to enable or disable RADIUS accounting and SSID authorization in the VLAN.
Page 100
Performing Advanced Configuration AP-4000 User Guide SSID/VLAN/Security 3. Enter a unique Network Name (SSID), between 1 and 32 characters. This parameter is mandatory. NOTE Do not use quotation marks (single or double) in the Network Name; this will cause the AP to misinterpret the name.
Performing Advanced Configuration AP-4000 User Guide SSID/VLAN/Security NOTE If you have two or more SSIDs per interface using a security Profile with a security mode of Non Secure, be aware that security being applied in the VLAN is not being applied in the wireless network.
Page 102
Performing Advanced Configuration AP-4000 User Guide SSID/VLAN/Security The Add Entry or Edit Entry screen appears. See Figure 4-45 Figure 4-46. Figure 4-45 SSID/VLAN Add Entries Screen (VLAN Protocol Enabled) Figure 4-46 SSID/VLAN Edit Entries Screen (VLAN Protocol Enabled) 4. Enter a unique Network Name (SSID), between 1 and 32 characters. This parameter is mandatory.
Performing Advanced Configuration AP-4000 User Guide SSID/VLAN/Security – You can set the VLAN ID to “-1” or “untagged” if you do not want clients that are using a specific SSID to be members of a VLAN workgroup. Only one “untagged” VLAN ID is allowed per interface.
AP-4000 User Guide Monitoring the AP-4000 • Version: Provides version information for the Access Point’s system components. • ICMP: Displays statistics for Internet Control Message Protocol packets sent and received by the AP. • IP/ARP Table: Displays the AP’s IP Address Resolution table.
Monitoring the AP-4000 AP-4000 User Guide Version Version From the HTTP interface, click the Monitor button and select the Version tab. The list displayed provides you with information that may be pertinent when calling Technical Support. With this information, your Technical Support representative can verify compatibility issues and make sure the latest software are loaded.
Monitoring the AP-4000 AP-4000 User Guide ICMP ICMP This tab provides statistical information for both received and transmitted messages directed to the AP. Not all ICMP traffic on the network is counted in the ICMP (Internet Control Message Protocol) statistics.
There can be up 10,000 entries in the Learn Table. Figure 5-5 Learn Table IAPP This tab displays statistics relating to client handovers and communications between ORiNOCO Access Points. Figure 5-6 IAPP Screen...
Monitoring the AP-4000 AP-4000 User Guide RADIUS RADIUS This tab provides RADIUS authentication, EAP/802.1x authentication, and accounting information for both the Primary and Backup RADIUS servers for each RADIUS Server Profile. NOTE Separate RADIUS servers can be configured for each RADIUS Server Profile.
Monitoring the AP-4000 AP-4000 User Guide Interfaces Interfaces This tab displays statistics for the Ethernet and wireless interfaces. The Operational Status can be up, down, or testing. Figure 5-8 Wireless Interface Monitoring...
Monitoring the AP-4000 AP-4000 User Guide Station Statistics Station Statistics This tab displays information on wireless clients attached to the AP and on Wireless Distribution System links. Enable the Monitoring Station Statistics feature (Station Statistics are disabled by default) by checking Enable Monitoring Station Statistics and click OK.
Monitoring the AP-4000 AP-4000 User Guide Station Statistics Description of Station Statistics The following stations statistics are displayed: • MAC Address: The MAC address of the wireless client for which the statistics are gathered. For WDS links, this is the partner MAC address of the link.
AP-4000 User Guide Performing Commands • Introduction to File Transfer via TFTP or HTTP: Describes the available file transfer methods. • Update AP via TFTP: Download files from a TFTP server to the AP. • Update AP via HTTP: Download files to the AP from HTTP.
A TFTP server must be running and configured to point to the directory containing the file. If you do not have a TFTP server installed on your system, install the TFTP server from the ORiNOCO CD. HTTP File Transfer Guidelines HTTP file transfer can be performed either with or without SSL enabled.
Update AP via TFTP Command Screen If you do not have a TFTP server installed on your system, install the TFTP server from the ORiNOCO CD. You can either install the TFTP server from the CD Wizard or run OEM-TFTP-Server.exe found in the CD’s Xtras/SolarWinds sub-directory.
Performing Commands AP-4000 User Guide Update AP via HTTP Update AP via HTTP Use the Update AP via HTTP tab to download Configuration, AP Image, Bootloader files, and Certificate and Private Key files to the AP. Once on the Update AP screen, click on the via HTTP tab.
Page 116
Performing Commands AP-4000 User Guide Update AP via HTTP Figure 6-5 Update AP Successful If the operation did not complete successfully the following screen appears, and the reason for the failure is displayed. Figure 6-6 Update AP Unsuccessful...
If you don’t have a TFTP server installed on your system, install the TFTP server from the ORiNOCO CD. You can either install the TFTP server from the CD Wizard or run OEM-TFTP-Server.exe found in the CD’s Xtras/SolarWinds sub-directory.
Page 118
Performing Commands AP-4000 User Guide Retrieve File Figure 6-8 Retrieve File via HTTP Command Screen A confirmation message gets displayed that asks if the user wants to proceed with retrieving the file. Figure 6-9 Retrieve File Confirmation Dialog Click OK to continue with the operation or Cancel to abort the operation. On clicking OK, the File Download window appears.
Performing Commands AP-4000 User Guide Reboot Reboot Use the Reboot tab to save configuration changes (if any) and reset the AP. Entering a value of 0 (zero) seconds causes an immediate reboot. Note that Reset, described below, does not save configuration changes.
Performing Commands AP-4000 User Guide Reset Reset Use the Reset tab to restore the AP to factory default conditions. The AP may also be reset from the RESET button located on the side of the unit. Since this will reset the Access Point’s current IP address, a new IP address must be assigned. Refer to...
Performing Commands AP-4000 User Guide Help Link Help Link To open Help, click the Help button on any display screen. During initialization, the AP on-line help files are downloaded to the default location: C:/Program Files/ORiNOCO/AP4000/HTML/index.htm. NOTE Use the forward slash character ("/") rather than the backslash character ("\") when configuring the Help Link location.
AP-4000 User Guide Troubleshooting the AP-4000 • Troubleshooting Concepts • Symptoms and Solutions • Recovery Procedures • Related Applications NOTE This section helps you locate problems related to the AP device setup. For details about RADIUS, TFTP, serial communication programs (such as HyperTerminal), Telnet applications, or web browsers, please refer to the documentation that came with the application for assistance.
Troubleshooting the AP-4000 AP-4000 User Guide Symptoms and Solutions Symptoms and Solutions Connectivity Issues Connectivity issues include any problem that prevents you from powering up or connecting to the AP. AP Unit Will Not Boot - No LED Activity 1. Make sure your power source is operating.
Make sure you have configured your client software with the proper Network Name and Security settings. Network Names and WEP Keys are typically allocated and maintained by your network administrator. Client PC Card Does Not Work 1. Make sure you are using the latest PC Card driver software. 2. Download and install the latest ORiNOCO client software from http://www.proxim.com.
VLAN User IDs configured for the AP. NOTE The AP-4000 supports 16 VLAN/SSID pairs per wireless interface, each with a configured security profile. VLAN Workgroups The correct VLAN assignment can be verified by pinging the AP to ensure connectivity, by pinging the switch to ensure VLAN properties, and by pinging hosts past the switch to confirm the switch is functional.
Troubleshooting the AP-4000 AP-4000 User Guide Recovery Procedures I have just configured the Management ID and now I can't manage the AP? • Check to ensure your password is correct. If your password is incorrect or all inbound packets do NOT have the correct tag, then a manual override is necessary.
Troubleshooting the AP-4000 AP-4000 User Guide Recovery Procedures Forced Reload Procedure Use this procedure to erase the current AP Image and download a new AP Image. In some cases, specifically when a missing or corrupted AP Image prevents successful booting, you may need to use ScanTool or the Bootloader CLI to download a new executable AP Image.
Troubleshooting the AP-4000 AP-4000 User Guide Recovery Procedures 9. Enter the IP address of your TFTP server in the field provided. 10. Enter the Image File Name (including the file extension). Enter the full directory path and file name. If the file is located in the default TFTP directory, you need enter only the file name.
Troubleshooting the AP-4000 AP-4000 User Guide Recovery Procedures 7. Enter only the following statements: [Device name]> set ipaddrtype static [Device name]> set ipaddr <Access Point IP Address> [Device name]> set ipsubmask <IP Mask> [Device name]> set tftpipaddr <TFTP Server IP Address>...
Troubleshooting the AP-4000 AP-4000 User Guide Related Applications Follow these steps to assign the AP an IP address: 1. Open your terminal emulation program (like HyperTerminal) and set the following connection properties: • Com Port: <COM1, COM2, etc., depending on your computer>...
The “Trivial File Transfer Protocol” (TFTP) server allows you to transfer files across a network. You can upload configuration files from the AP for backup or copying, and you can download configuration files or new software images. The TFTP software is located on the ORiNOCO AP Installation CD-ROM.
AP-4000 User Guide Using the Command Line Interface (CLI) • General Notes • Command Line Interface (CLI) Variations • CLI Command Types • Using Tables & User Strings • Configuring the AP using CLI commands • Set Basic Configuration Parameters using CLI Commands •...
Using the Command Line Interface (CLI) AP-4000 User Guide Command Line Interface (CLI) Variations • Parameter - A fundamental network value that can be displayed and may be changeable. For example, the Access Point must have a unique IP Address and the Wireless interface must be assigned an SSID. Change parameters with the CLI set Command, and view them with the CLI show Command.
Page 134
Using the Command Line Interface (CLI) AP-4000 User Guide Command Line Interface (CLI) Variations • reboot command to reboot the device The parameters supported by the Bootloader CLI (for viewing and modifying) are: • System Name • IP Address Assignment Type •...
Using the Command Line Interface (CLI) AP-4000 User Guide CLI Command Types CLI Command Types This guide divides CLI Commands into two categories: Operational and Parameter Controls. Operational CLI Commands These commands affect Access Point behavior, such as downloading, rebooting, and so on. After entering commands (and parameters, if any) press the Enter key to execute the Command Line.
Page 136
Using the Command Line Interface (CLI) AP-4000 User Guide CLI Command Types Figure A-4 Result of “s?” CLI command Example 3. Display parameters for set and show Example 3a allows you to see every possible parameter for the set (or show) commands. Notice from example 3a that the list is very long.
Using the Command Line Interface (CLI) AP-4000 User Guide CLI Command Types Example 4. Display Prompts for Successive Parameters Enter the command, a space, and then ?. Then, when the parameter prompt appears, enter the parameter value. Result: The parameter is changed and a new CLI line is echoed with the new value (in the first part of the following example, the value is the IP Address of the TFTP server).
Using the Command Line Interface (CLI) AP-4000 User Guide CLI Command Types Figure A-8 Results of “help” CLI command 2. Complete command description and command usage can be provided by: [Device-Name]>help <command name> [Device-Name]><command name> help history Shows content of Command History Buffer. The Command History Buffer stores command statements entered in the current session. To avoid re-entering long command statements, use the keyboard “up arrow”...
Using the Command Line Interface (CLI) AP-4000 User Guide CLI Command Types upload Uploads a text-based configuration file from the AP to the TFTP Server. Executing upload with the asterisk character (“*”) will make use of the previously set/stored TFTP parameters. Executing upload without parameters will display command help and usage information.
Using the Command Line Interface (CLI) AP-4000 User Guide CLI Command Types Example 1: Configuring objects that require the device to be rebooted The following message is displayed every time the user has configured an object that requires the device to be rebooted.
Page 141
Using the Command Line Interface (CLI) AP-4000 User Guide CLI Command Types Example 3 - Modify a table entry or row Use the index to be modified and the table elements you would like to modify. For example, suppose the IP Access Table has one entry and you wanted to modify the IP address: [Device-Name]>set mgmtipaccesstbl 1 ipaddr 10.0.0.11...
Using the Command Line Interface (CLI) AP-4000 User Guide Using Tables & User Strings Syntax: [Device-Name]>show <parameter name> Example: [Device-Name]> show ipaddr Result: Displays the Access Point IP address. Figure A-11 Result of “show ipaddr” CLI Command 2. View all parameters in a table.
Using the Command Line Interface (CLI) AP-4000 User Guide Configuring the AP using CLI commands For example: [Device-Name]> set sysname Lobby - Does not need quote marks [Device-Name]> set sysname “Front Lobby” - Requires quote marks. The scenarios supported by this CLI are: “My Desk in the office”...
Using the Command Line Interface (CLI) AP-4000 User Guide Set Basic Configuration Parameters using CLI Commands • Set System Name, Location and Contact Information • Set Static IP Address for the AP • Download an AP Configuration File from your TFTP Server •...
Using the Command Line Interface (CLI) AP-4000 User Guide Set Basic Configuration Parameters using CLI Commands Set Network Names for the Wireless Interface [Device-Name]>set wif <index 3 (Wireless Interface A) or 4 (Wireless Interface B)> netname <Network Name (SSID) for wireless interface>...
Using the Command Line Interface (CLI) AP-4000 User Guide Set Basic Configuration Parameters using CLI Commands Enable 802.11d Support and Set the Country Code Perform the following command to enable 802.11d IEEE 802.11d support for additional regulatory domains. [Device-Name]>set wif <3 (Wireless Interface A) or 4 (Wireless Interface B)> dot11dstatus <enable/disable>...
Using the Command Line Interface (CLI) AP-4000 User Guide Set Basic Configuration Parameters using CLI Commands Enable and Configure TX Power Control for the Wireless Interface(s) The TX Power Control feature lets the user configure the transmit power level of the card in the AP at one of four levels: •...
The configuration filename and TFTP server IP address are configured only when the AP is configured for Static IP. If the AP is configured for Dynamic IP these parameters are not used and obtained from DHCP. The default filename is “config”. The default TFTP IP address is “169.254.128.133” for AP-4000. [Device-Name]>set autoconfigstatus <enable/disable>...
[Device-Name]>reboot 0 Change your Wireless Interface Settings Interfaces for information on the parameters listed below. The AP-4000 uses index 3 for Wireless Interface A (802.11a radio) and index 4 for Wireless Interface B (802.11b/g radio). Operational Mode [Device-Name]>set wif <index> mode <see table>...
Using the Command Line Interface (CLI) AP-4000 User Guide Other Network Settings Shutdown/Resume Wireless Service [Device-Name]>set wif <index> wssstatus <1 (resume)/2 (shutdown)> Set Load Balancing Maximum Number of Clients [Device-Name]>set wif <index> lbmaxclients <1-63> Set the Multicast Rate (802.11a) [Device-Name]>set wif 3 multrate <6, 12, 24 (Mbits/sec) >...
Using the Command Line Interface (CLI) AP-4000 User Guide Other Network Settings 100 Mbits/sec - full duplex 100fullduplex Auto Speed - half duplex autohalfduplex Auto Speed - auto duplex autoautoduplex (default) Set Interface Management Services Edit Management IP Access Table [Device-Name]>set mgmtipaccesstbl <index>...
Using the Command Line Interface (CLI) AP-4000 User Guide Other Network Settings Configure Serial Port Interface NOTE To avoid unexpected performance issues, leave Flow Control at the default setting (none) unless you are sure what this setting should be. [Device-Name]>set serbaudrate <2400, 4800, 9600, 19200, 38400, 57600>...
Using the Command Line Interface (CLI) AP-4000 User Guide Other Network Settings Set RADIUS Parameters Configure RADIUS Authentication servers Perform the following command to configure a RADIUS Server and assign it to a VLAN. The RADIUS Server Profile index is specified by the index parameter and the subindex parameter specifies whether you are configuring a primary or secondary RADIUS server.
Page 154
Using the Command Line Interface (CLI) AP-4000 User Guide Other Network Settings Server Addressing Format : ipaddr IP Address/Host Name : 0.0.0.0 Destination Port VLAN Identifier : -1 MAC Address Format : dashdelimited Response Time Maximum Retransmission Authorization Lifetime Accounting Update Interval...
Using the Command Line Interface (CLI) AP-4000 User Guide Other Network Settings Server Status : notReady Server Addressing Format : ipaddr IP Address/Host Name : 0.0.0.0 Destination Port : 1812 VLAN Identifier : -1 MAC Address Format : dashdelimited Response Time...
Using the Command Line Interface (CLI) AP-4000 User Guide CLI Monitoring Parameters Set Hardware Configuration Reset Parameters The Hardware Configuration Reset commands allows you to enable or disable the hardware reset functionality and to change the password to be used for configuration reset during boot up.
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables Parameter Tables Objects contain groups that contain both parameters and parameter tables. Use the following Tables to configure the Access Point. Columns used on the tables include: • Name - Parameter, Group, or Table Name •...
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables – MAC Access Control Parameters - Control wireless access based on MAC address – Rogue Scan Configuration Table - Enable and configure Rogue Scan to detect Rogue APs and clients.
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables Inventory Management Information Name Type Values Access CLI Parameter System Inventory Management Subgroup sysinvmgmt Component Table Subgroup sysinvmgmtcmptbl Component Interface Table Subgroup sysinvmgmtcmpiftbl NOTE The inventory management commands display advanced information about the AP’s installed components. You may be asked to report this information to a representative if you contact customer support.
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables DHCP Server Parameters Name Type Values Access CLI Parameter DHCP Server Group dhcp DHCP Server Status Integer enable (1) (default) dhcpstatus disable (2) delete (3) Gateway IP Address IpAddress...
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables DHCP Relay Server Table The DHCP Relay Server Table contains the commands to set the table entries. The AP supports the configuration of a maximum of 10 server settings in the DHCP Relay Agents server table.
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables Interface Parameters Wireless Interface Parameters The wireless interface group parameter is wif. Wireless Interface A (802.11a radio) uses table index 3 and Wireless Interface B (802.11b/g radio) uses table index 4.
Page 163
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables 802.11a Only Parameters Name Type Values Access CLI Parameter Operating Frequency Channel Integer Varies by regulatory channel domain and country. See 802.11a Channel Frequencies Supported Data Rates Octet String...
Page 164
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables 802.11b Only Parameters Name Type Values Access CLI Parameter Operating Frequency Channel Integer 1 - 14; available channels channel vary by regulatory domain/country; see 802.11b Channel Frequencies Multicast Rate...
Page 165
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables 802.11b/g Only Parameters Name Type Values Access CLI Parameter Wireless Operational Mode Integer dot11b-only mode dot11g-only dot11bg (default) Operating Frequency Channel Integer 1 - 14; available channel channels vary by regulatory domain/country;...
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables Wireless Interface SSID/VLAN/Profile Parameters The Wireless Interface SSID table manages the SSID/VLAN pairs, and the Security Profile and RADIUS Profiles associated to the VLAN. For configuration examples, refer to Configure SSID (Network Name) and VLAN Pairs, and Profiles.
Parameter Tables NOTE The default path for the Help files is C:/Program Files/ORiNOCO/AP/HTML/index.htm. (Use the forward slash character ("/") rather than the backslash character ("\") when configuring the Help Link location.) The AP Help information is available in English, French, German, Italian, Spanish, and Japanese.
Page 169
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables The AP SSH feature, open-SSH, confirms to the SSH protocol, and supports SSH version 2. The following SSH clients have been verified to interoperate with the AP’s server. The following table lists the clients, version number, and the website of the client.
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables Auto Configuration Parameters These parameters relate to the Auto Configuration feature which allows an AP to be automatically configured by downloading a specific configuration file from a TFTP server during the boot up process.
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables Filtering Parameters Ethernet Protocol Filtering Parameters Name Type Values Access CLI Parameter Ethernet Filtering Group etherflt Filtering Interface Interface Bitmask 0 or 2 - no interfaces etherfltifbitmask Bitmask (disable)
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables Proxy ARP Parameters Name Type Values Access CLI Parameter Proxy ARP Group parp Status Integer enable parpstatus disable (default) IP ARP Filtering Parameters Name Type Values Access CLI Parameter...
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables Protocol Name DisplayString User Defined protoname (there are also 4 pre-defined protocols, Port Number above) Interface Bitmask Integer32 0 or 2 - no interfaces ifbitmask (disable) 1 or 3 - Ethernet...
Page 174
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables Syslog Host Table The table described below configures the Syslog hosts that will receive message from the AP. You can configure up to ten Syslog hosts. Name Type Values...
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables Bridge Parameters Spanning Tree Parameters Name Type Values Access CLI Parameter Spanning Tree Group Spanning Tree Status Integer enable (default) stpstatus disable Bridge Priority Integer 0 – 65535 stppriority...
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables Intra BSS Subscriber Blocking The following parameters control the Intra BSS traffic feature, which prevent wireless clients that are associated with the same AP from communicating with each other:...
Page 177
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables Maximum Integer 0 – 4 maxretx Retransmissions 3 (default) (optional) RADIUS MAC Address Integer dashdelimited radmacaddrformat Format colondelimited singledashdelimited nodelimiter RADIUS Accounting Integer32 1-60 minutes radaccinactivetmr Inactivity Timer Authorization Lifetime...
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables Security Parameters MAC Access Control Parameters Name Type Values Access CLI Parameter MAC Address Control Group macacl Status Integer enable aclstatus disable (default) Operation Type Integer passthru (default) macacloptype...
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables Security Profile Table The Security Profile Table allows you to configure security profiles. A maximum of 16 security profiles are supported per wireless interface. Each security profile can be enable and configure one or more security modes (None Secure Station, WEP Station, 802.1x Station, WPA Station, WPA-PSK Station).
Page 180
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables Configuring a Security Profile with WPA-PSK Security Mode set secprofiletbl <index> secmode wpa-psk passphrase <value> status enable Example: set secprofiletbl 6 secmode wpa-psk passphrase 12345678 status enable Configuring a Security Profile with 802.11i Security Mode set secprofiletbl <index>...
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables Other Parameters IAPP Parameters Name Type Values Access CLI Parameter IAPP Group iapp IAPP Status Integer enable (default) iappstatus disable Periodic Announce Integer iappannint Interval (seconds) 120 (default) Announce Response...
Using the Command Line Interface (CLI) AP-4000 User Guide Parameter Tables NOTE A priority mapping needs to be specified for a QoS Policy. The priority mapping depends on the type of policy configured. For Layer 2 policy types (inbound or outbound) a mapping index from the 802.1p to 802.1D table should be specified. For Layer 3 policy types (inbound or outbound) a mapping index from the IP DSCP to 802.1D table should be specified.
Using the Command Line Interface (CLI) AP-4000 User Guide CLI Batch File CLI Batch File A CLI Batch file is a user-editable file that lists a series of CLI set commands, that can be uploaded to the Access Point to change its configuration.
Using the Command Line Interface (CLI) AP-4000 User Guide CLI Batch File CLI Batch File Error Log If there is any error during the execution of the CLI Batch file, the AP will stop executing the file. The AP generates traps for all errors and each trap contains the following information: •...
AP-4000 User Guide ASCII Character Chart You can configure WEP Encryption Keys in either Hexadecimal or ASCII format. Hexadecimal digits are 0-9 and A-F (not case sensitive). ASCII characters are 0-9, A-F, a-f (case sensitive), and punctuation marks. Each ASCII character corresponds to two hexadecimal digits.
Specifications • Software Features • Hardware Specifications • Radio Specifications Software Features The tables below list the software features available on the AP-4000. • Number of Stations per BSS • Management Functions • Advanced Bridging Functions • Medium Access Control (MAC) Functions •...
Specifications AP-4000 User Guide Hardware Specifications Network Functions Feature Supported by AP-4000 DHCP Client DHCP Server DHCP Relay Agent and IP Lease Renewal Inter Access Point Protocol (IAPP) Link Integrity System Logging (Syslog) RADIUS Accounting Support DNS Client TCP/IP Protocol Support...
Specifications AP-4000 User Guide Radio Specifications Radio Specifications • 802.11a Channel Frequencies • 802.11b Channel Frequencies • 802.11g Channel Frequencies • Wireless Communication Range NOTE Refer to the Regulatory Flyer included with the AP for the latest regulatory information. 802.11a Channel Frequencies The available 802.11a Channels vary by regulatory domain and/or country.
Specifications AP-4000 User Guide Radio Specifications 802.11b Channel Frequencies The available 802.11b channels vary by regulatory domain and/or country. 802.11b radio certification is available in the following regions: • FCC - U.S./Canada, Mexico, and Australia • ETSI - Most of Europe, including the United Kingdom and some Eastern block countries •...
Specifications AP-4000 User Guide Radio Specifications Wireless Communication Range The range of the wireless signal is related to the composition of objects in the radio wave path and the transmit rate of the wireless communication. Communications at a lower transmit range may travel longer distances. The range values listed in the Communications Range Chart are typical distances as calculated by Proxim’s development team for FCC-certified products.
Specifications AP-4000 User Guide Radio Specifications 802.11g Range Mbits/s Mbits/s Mbits/s Mbits/s Mbits/s Mbits/s Mbits/s Mbits/s Mbits/s Mbits/s Mbits/s Mbits/s Open 56 m 69 m 107 m 164 m 219 m 272 m 292 m 314 m 204 m 236 m...
– Can you reproduce the problem? – For each ORiNOCO product, describe the behavior of the device’s LEDs when the problem occurs Contact ORiNOCO Technical Support by online or by phone, as described below. Online Support Software and Documentation Downloads The latest software and documentation is available for download at <http://support.proxim.com/cgi-bin/proxim.cfg/php/enduser/std_alp.php>.
If Proxim reasonably determines that a returned Product is not defective or is not covered by the terms of this Warranty, Buyer shall be charged a service charge and return shipping charges. 1 LAN products include: ORiNOCO 2 WAN products include: Lynx, Tsunami, Tsunami MP, Tsunami Quickbridge...
For support for a PCMCIA card carrying a brand name other than Proxim, ORiNOCO, Lucent, Wavelan, or Skyline, Customer should contact the brand vendor's technical support for assistance.
AP-4000 User Guide Regulatory Information This regulatory flyer contains the following sections: • Information to the User Read this document prior to installation! User Documentation is provided on the CD-ROM. • Informations pour l’utilisateur Lisez ce document avant l'installation! La documentation utilisateur est fournie sur le CD-ROM.
Wireless Client products such as the PC Card, USB Client. • Wireless Base Station products such as the AP-700, AP-4000, AP-4000 11a Upgrade Kit, AP-4000 11g Cardbus Kit, AP-600 11abg Upgrade Kit, AP-2500, AP-4000, ORiNOCO AP-600, AP-600 11g Upgrade Kit.
Regulatory Information AP-4000 User Guide Information to the User Wireless LAN and Your Health Wireless LAN products, like other radio devices, emit radio frequency electromagnetic energy. The level of emitted energy however is far less than the electromagnetic energy emitted by other wireless devices like mobile phones, for example. Because Wireless LAN products operate within the guidelines found in radio frequency safety standards and recommendations, we believe that our Wireless LAN products are safe for use by consumers.
Page 200
Les produits client sans fil tels que PC Card, USB Client. • Les produits sans fil de la Base Station tels que AP-700, AP-4000, AP-4000 11a Upgrade Kit, AP-4000 11g Cardbus Kit, AP-600 11abg Upgrade Kit, AP-2500, AP-4000, ORiNOCO AP-600, AP-600 11g Upgrade Kit.
Page 201
Regulatory Information AP-4000 User Guide Information to the User Réseaux sans fil et votre santé Les produits pour un réseau sans fil, comme d’autres dispositifs radio, émettent de l’énergie électromagnétique de fréquence radio. Le niveau d’énergie émis par les dispositifs pour résaeu sans fil est toutefois beaucoup moins élevé que l’énergie électro-magnétique émise par des dispositifs comme par exemple les téléphones portables.
Page 202
Prodotti client wireless come la PC Card, USB Client. • Prodotti per Base Station wireless come il AP-700, AP-4000, AP-4000 11a Upgrade Kit, AP-4000 11g Cardbus Kit, AP-2500, AP-4000, ORiNOCO AP-600, AP-600 11g Upgrade Kit, AP-600 11abg Upgrade Kit. I prodotti cliente e delle Base Station sono prodotti senza fili della rete basati su IEEE 802.11 standard come definiti ed approvati dall'Institute of Electrical and Electronics Engineers.
Regulatory Information AP-4000 User Guide Information to the User Wireless LAN e la salute I prodotti LAN wireless, così come altri dispositivi radio, emettono energia elettromagnetica in radiofrequenza. L'energia emessa è tuttavia molto inferiore all'energia elettromagnetica emessa da altri dispositivi wireless come, ad esempio, i telefoni cellulari. Poiché i prodotti LAN wireless funzionano entro i limiti previsti dalle norme e dalle raccomandazioni sulla sicurezza delle emissioni in radiofrequenza, riteniamo che l'uso dei nostri prodotti LAN wireless non comporti rischi per la salute degli utenti.
Page 204
Funk-Client-Produkte wie die PC Card, USB Client. • Funk-Base Stations-Produkte wie der AP-700, AP-4000, AP-4000 11a Upgrade Kit, AP-4000 11g Cardbus Kit, AP-2500, AP-4000, ORiNOCO AP-600, AP-600 11g Upgrade Kit, AP-600 11abg Upgrade Kit. Funk-Client- und Funk-Base Stations-Produkte sind die drahtlosen Netzprodukte, die auf IEEE 802.11 Standards basieren, wie definiert und durch das Institute of Electrical and Electronics Engineers genehmigt.
Regulatory Information AP-4000 User Guide Information to the User Funk-LAN und gesundheitliche Sicherheit Funk-LAN-Produkte geben wie alle Hochfrequenzgeräte elektromagnetische Hochfrequenzenenergie ab. Bei Funk-LAN-Geräten ist jedoch eine deutlich geringere Emission elektromagnetischer Energie zu verzeichnen als bei anderen Funkgeräten, wie z. B. Mobiltelefonen. Da die Funk-LAN-Produkte den Richtlinien der HF-Sicherheitsstandards und -empfehlungen entsprechen, besteht beim Gebrauch von Funk-LAN-Produkten keine Gefährdung für den Kunden.
Page 206
Productos cliente inalámbricos como la PC Card, USB Client. • Productos de Base Station inalámbricos como el AP-700, AP-4000, AP-4000 11a Upgrade Kit, AP-4000 11g Cardbus Kit, AP-2500, AP-4000, ORiNOCO AP-600, AP-600 11g Upgrade Kit, AP-600 11abg Upgrade Kit. Los productos del cliente sin hilos y de la estación baja son productos sin hilos de la red basados en IEEE 802.11 estándares para LANs sin hilos según lo definidos y aprobados por el Institute of Electrical and Electronics Engineers.
Page 207
Regulatory Information AP-4000 User Guide Information to the User LAN inalámbrica y su salud Los productos de LAN inalámbrica, al igual que otros dispositivos de radiotecnología, emiten energía electromagnética de radiofrecuencia. Sin embargo, el nivel de energía que emiten es mucho menor que la energía electromagnética emitida por otros dispositivos inalámbricos, como por ejemplo los teléfonos móviles.
Page 208
・ PC Card、USB Client などの無線クライアント製品 ・ AP-700, AP - 4000, AP - 4000 11a Upgrade Kit, AP - 4000 11g Cardbus Kit, AP - 2500, AP-4000, ORiNOCO AP - 600, AP - 600 11g Upgrade Kit, AP-600 11abg Upgrade Kit, などの無線 Base Station 製品 .
Page 209
Regulatory Information AP-4000 User Guide Information to the User 無線 LAN と人体への影響 無線 LAN 製品は、他の無線装置と同様に、無線周波数電磁エネルギーを放出します。ただし、無線 LAN 装置が放出するエネルギーのレベルは、携 帯電話などの無線装置が放出する電磁エネルギーより、はるかに低く抑えられています。無線 LAN 製品は、無線周波数に関する各種安全基準や推 奨基準のガイドラインを反映するもので、広範な研究資料を検討している研究者によるパネルや委員会の審議の結果策定されています。 規制に関する情報 この装置は、製品に添付のユーザーマニュアルに記載されたメーカーの指示に従って取り付け、使用する必要があります。 無線の承認 国ごとの無線の承認については、この冊子の のセクションを参照してください。 ただし、建物の所有者または組織の代表者によって無線装置の使用が規制される場合もあります。たとえば、次のような場合です。 ・ 飛行機内での無線装置の使用 ・ 他の装置やサービスに対する干渉の危険性が認められるか、または有害であると考えられる環境での使用 空港などの特定の組織または環境で無線の使用が許可されているかどうかが不明な場合は、使用前に無線装置の使用の可否を確認してください。 このキットに含まれる装置を許可なく変更した場合、またはメーカーの指定以外の接続ケーブルおよび機器を使用した場合、ラジオまたはテレビに 干渉が発生しても、メーカーは一切責任を負いません。 上記のような許可のない変更や、代替製品の使用または取り付けによって発生した干渉については、ユーザーの責任において修正を行うものとしま す。 メーカーおよびその正規の代理店または販売店は、これらのガイドラインに従わないことによって生じる損害または法規違反については、一切責任 を負いません。...
Regulatory Information AP-4000 User Guide United States FCC Information United States FCC Information Federal Communications Commission (FCC) Declaration of Conformity Products marked with the FCC logo and comply with the limits for a Class B digital device, pursuant to Part 15 of the FCC Rules.
Regulatory Information AP-4000 User Guide Canada IC Information Canada IC Information Industry Canada (IC) This device complies with the limits for a class B digital device and conforms to Industry Canada standard ICES-003. Products that contain a radio transmitter comply with Industry Canada standard RSS 210 and are labelled with IC approval number.
Regulatory Information AP-4000 User Guide Europe Information Europe Information • Products labeled with the CE mark comply with EMC Directive 89/336/EEC and the Low Voltage Directive • 73/23/EEC implying conformity to the following European Norms. • Tous les produits portant la marque CE sont conformes à la directive EMC 89/336/EEC et à...
Page 213
Regulatory Information AP-4000 User Guide Europe Information • Proxim 802.11a Base Station products sold in Europe that operate in the middle frequency (5.25-5.35 GHz) band use a technique called Dynamic Frequency Selection (DFS) to automatically select an operating channel. The European Telecommunications Standard Institute (ETSI) requires that 802.11a devices use DFS to prevent interference with radar systems and other devices that already occupy the 5 GHz band.
Regulatory Information AP-4000 User Guide Japan Information Japan Information 日本の通達 Association of Radio Industries and Businesses (ARIB) 電波産業会 (ARIB) STD-T71) 通達 このセクションは、5.15 ~ 5.25 GHz 帯域で運用されている IEEE 802.11a 準拠の送信機のみに当てはまります。使用の際に適用される制限について は、本冊子の「Radio Approvals」セクションをご覧ください。 電波産業会 (ARIB) STD-T66) 通達 このセクションは、2.4 GHz 帯域で運用されている IEEE 802.11b 準拠の送信機のみに当てはまります。この製品は。 「第二世代低電力...
Regulatory Information AP-4000 User Guide South Korea Information South Korea Information (Product (Model Name) (Trade Name/Manufacturer) (Certification No.) (Date of (Made in) Name) Certification) PC Card PC24E-H-FC Agere Systems R-LARN-01-028 2001.10.15 Taiwan PC24E-11-FC/R Agere Systems R-LARN-02-0027 2002.01.26 Taiwan USB Client...
Regulatory Information AP-4000 User Guide Radio Approvals Radio Approvals To determine whether you are allowed to use your device in the countries listed below, please check the “contains transmitter” number that is printed on the identification label of your device.
Page 217
Regulatory Information AP-4000 User Guide Radio Approvals Country Radio Transmitter Approval Reference Restrictions Pays Émetteur Radio Numéro du Permis Restrictions Paese Trasmittente de Radio Numero di Approvazione Limitazioni Land Radio-Übermittler Zustimmung-Nummer Beschränkungen País Transmisor de Radio Número de Permiso Restricciones 国名...
Page 218
CE 1313 ! • Only indoor with integral or approved Range Extender Antenna. • Alleen voor gebruik binnenshuis met ingebouwde of goedgekeurde Belgium AP-4000: AP-AG-AT-02 CE 1313 ! reikwijdteversterkerantenne. • Pour usage intérieur uniquement, avec une antenne intégrale ou amplificatrice approuvée.
Page 219
Regulatory Information AP-4000 User Guide Radio Approvals Country Radio Transmitter Approval Reference Restrictions Pays Émetteur Radio Numéro du Permis Restrictions Paese Trasmittente de Radio Numero di Approvazione Limitazioni Land Radio-Übermittler Zustimmung-Nummer Beschränkungen País Transmisor de Radio Número de Permiso Restricciones 国名...
Page 220
CMII ID: 2003AP0741 China Alpha-1: C38WCW CMII ID: 2003DJ1055 • The use of external antennas is not allowed China AP-700: AP-AG-AT-01 CMII ID: pending • The use of external antennas is not allowed China AP-4000: AP-AG-AT-02 CMII ID: pending Chile PC24E-H-FC PC24E-11-FC/R...
Page 221
AP-700: AP-AG-AT-01 CE 1313 ! • Only indoor with integral or approved Range Extender Antenna • Kun til indendørs brug sammen med en integreret eller godkendt Denmark AP-4000: AP-AG-AT-02 CE 1313 ! afstandsforlængerantenne. Denmark Alpha-1: A04LAE CE 0336 ! • For indoor use only.
Page 222
CE 1313 ! • Only indoor with integral or approved Range Extender Antenna. Suomi • Ainoa sisä- avulla integraali eli hyväksytty Ala Avartaa Tuntosarvi. Finland AP-4000: AP-AT-AG-02 CE 1313 ! Suomi Finland Alpha-1: A04LAE CE 0336 ! • For indoor use only.
Page 223
AP-700: AP-AG-AT-01 CE 1313 ! • Only indoor with integral or approved Range Extender Antenna. • Pour usage intérieur uniquement, avec une antenne intégrale ou France AP-4000: AP-AG-AT-02 CE 1313 ! amplificatrice approuvée. France PC50E-4-ET/A CE 0336 ! • For indoor use only.
Page 224
Regulatory Information AP-4000 User Guide Radio Approvals Country Radio Transmitter Approval Reference Restrictions Pays Émetteur Radio Numéro du Permis Restrictions Paese Trasmittente de Radio Numero di Approvazione Limitazioni Land Radio-Übermittler Zustimmung-Nummer Beschränkungen País Transmisor de Radio Número de Permiso Restricciones 国名...
Page 225
AP-700: AP-AG-AT-01 CE 1313 ! • Only indoor with integral or approved Range Extender Antenna. Deutschland • Nur zum Einsatz innerhalb von Gebäuden AP-4000: AP-AG-AT-02 CE 1313 ! (mit der integrierten Antenne oder einer zugelassenen Reichweitenverstärkerantenne) Germany PC50E-4-ET/A CE 0336 ! •...
Page 226
• Only indoor with integral or approved Range Extender Antenna. Ísland Iceland AP-700: AP-AG-AT-01 CE 1313! • Only indoor with integral or approved Range Extender Antenna. Ísland Iceland AP-4000: AP-AG-AT-02 CE 1313! Ísland Iceland PC50E-4-ET/A CE 0336 ! • For indoor use only. Ísland • Fyrir inni- nota eini...
Page 227
Regulatory Information AP-4000 User Guide Radio Approvals Country Radio Transmitter Approval Reference Restrictions Pays Émetteur Radio Numéro du Permis Restrictions Paese Trasmittente de Radio Numero di Approvazione Limitazioni Land Radio-Übermittler Zustimmung-Nummer Beschränkungen País Transmisor de Radio Número de Permiso Restricciones 国名...
Page 228
TELEC: pending • Only indoor with integral or approved Range Extender Antenna. ・内蔵、あるいは認可された範囲拡張アンテナを使った、屋内の使用に ( 限 TELEC: pending 日本 TELEC: pending 定 ) されています。 Japan AP-4000: AP-AG-AT-02 TELEC: pending TELEC: pending 日本 TELEC: pending Korea PC24E-H-FC MIC: R-LARN-01-028 Product name: PC Card Certification date: 2002.10.15...
Page 229
AP-700: AP-AG-AT-01 MIC: pending Product name: Access Point Certification date: 2004.XX.XX Manufacturer: Proxim Corporation Made in: Taiwan Korea AP-4000: AP-AG-AT-02 MIC: pending Certification date: 2004.XX.XX Korea Alpha-1: A04VBA MIC: R-LARN-03-208 Product name: PC Card Certification date: 2003.05.13 Manufacturer: Proxim Corporation...
Page 230
• Only indoor with integral or approved Range Extender Antenna. Luxembourg • Pour usage intérieur uniquement, avec une antenne intégrale ou amplificatrice approuvée. Luxemburg AP-4000: AP-AG-AT-02 CE 1313 ! Luxembourg Luxemburg PC50E-4-ET/A CE 0336 ! • For indoor use only.
Page 231
Regulatory Information AP-4000 User Guide Radio Approvals Country Radio Transmitter Approval Reference Restrictions Pays Émetteur Radio Numéro du Permis Restrictions Paese Trasmittente de Radio Numero di Approvazione Limitazioni Land Radio-Übermittler Zustimmung-Nummer Beschränkungen País Transmisor de Radio Número de Permiso Restricciones 国名...
Page 232
CE 1313 ! • Only indoor with integral or approved Range Extender Antenna. Nederland • Alleen binnen te gebruiken met goedgekeurde Externe Antenne. Netherlands AP-4000: AP-AG-AT-02 CE 1313 ! Nederland Netherlands Alpha-1: A04LAE CE 0336 ! • For indoor use only.
Page 233
CE 1313 ! • Only indoor with integral or approved Range Extender Antenna. Norsk • Bare innendørs med integral eller godkjent antenne med utvidet rekkevidde. Norway AP-4000: AP-AG-AT-02 CE 1313 ! Norsk Norway PC50E-4-ET/A CE 0336 ! • For indoor use only.
Page 234
CE 1313 ! • Only indoor with integral or approved Range Extender Antenna. • Somente indoor com a antena integral ou aprovada do extender da escala. Portugal AP-4000: AP-AG-AT-02 CE 1313 ! Portugal PC50E-4-ET/A CE 0336 ! • For indoor use only.
Page 235
CE 0336 ! aprobada Spain AP-700: AP-AG-AT-01 CE 1313 ! • Only indoor with integral or approved Range Extender Antenna. España • Sólo en interiores, con antena integrada o antena de extensión de alcance aprobada Spain AP-4000: AP-AG-AT-02 CE 1313 ! España...
Page 236
• Only indoor with integral or approved Range Extender Antenna. Sverige • Endast inomhus med integrerad antenn eller godkänd antenn med längre räckvidd. Sweden AP-4000: AP-AG-AT-02 CE 1313 ! Sverige Sweden PC50E-4-ET/A CE 0336 ! • For indoor use only.
Page 237
• For indoor use only. Suisse • Pour usage intérieur uniquement. Schweiz • Nur für Innengebrauch. Svizzera • Per uso interno solo. Switzerland AP-4000: AP-AG-AT-02 CE 1313 ! Suisse Schweiz Svizzera Switzerland Alpha-1: A04LAE CE 0336 ! • For indoor use only.
Page 238
• Only indoor with integral or approved Range Extender Antenna. United Kingdom AP-700: AP-AT-AG-01 CE 1313 ! • Only indoor with integral or approved Range Extender Antenna. United Kingdom AP-4000: AP-AT-AG-02 CE 1313 ! United Kingdom PC50E-4-ET/A CE 0336 ! • For indoor use only. PC50E-8-ET/A...
Page 239
• For indoor use only. AP-700: AP-AG-AT-01 FCC ID: IXMAPAGAT01 • For indoor use only. • For indoor use only. AP-4000: AP-AG-AT-02 FCC ID: IXMAPAGAT01 Venezuela PC24E-11-FC/R CONATEL: 01388301 For Radio Type Numbers with the format PCxxE-y-zz: xx =24 identifies a IEEE 802.11b compliant WLAN radio product for the 2.4 GHz frequency band.
Page 240
Regulatory Information AP-4000 User Guide Radio Approvals ET/A ou ET/B ou ET/C identifie un émetteur radio IEEE 802.11a conforme aux normes de la Communauté Européene. FR ou FR/R identifie un émetteur radio conforme aux normes françaises. JP ou JP/R identifie un émetteur radio à 14 canaux conforme aux normes japonaises.
Page 241
Regulatory Information AP-4000 User Guide Radio Approvals FR oder FR/R kennzeichnet einen IEEE 802.11a Radioübermittler, der mit französische Regelungen gefällig ist. JP oder JP/R kennzeichnet einen Funksender mit 14 Kanälen, der mit den japanischen Bestimmungen konform ist. JP/A kennzeichnet einen IEEE 802.11a Radioübermittler, der mit japanische Regelungen gefällig ist.
Page 242
Regulatory Information AP-4000 User Guide Radio Approvals JP/A は、日本の規制に準拠した IEEE 802.11a 無線送信機であることを示します。 無線タイプ番号の形式は、qrrsss です。 q =B は、2.4 GHz 周波数帯域で使用される IEEE 802.11b 準拠の WLAN 無線製品であることを示します。 G は、2.4 GHz 周波数帯域で使用される IEEE 802.11g 準拠の WLAN 無線製品であることを示します。 A は、5 GHz 周波数帯域で使用される IEEE 802.11a 準拠の WLAN 無線製品であることを示します。...
Need help?
Do you have a question about the AP-4000 and is the answer not in the manual?
Questions and answers