Wlan AP User Manual (v100r006c00 - 07) (PDF) - en
Wlan AP User Manual (v100r006c00 - 07) (PDF) - en
Wlan AP User Manual (v100r006c00 - 07) (PDF) - en
V100R006C00
User Manual
Issue 07
Date 2016-02-27
and other Huawei trademarks are trademarks of Huawei Technologies Co., Ltd.
All other trademarks and trade names mentioned in this document are the property of their respective
holders.
Notice
The purchased products, services and features are stipulated by the contract made between Huawei and
the customer. All or part of the products, services and features described in this document may not be
within the purchase scope or the usage scope. Unless otherwise specified in the contract, all statements,
information, and recommendations in this document are provided "AS IS" without warranties, guarantees or
representations of any kind, either express or implied.
The information in this document is subject to change without notice. Every effort has been made in the
preparation of this document to ensure accuracy of the contents, but all statements, information, and
recommendations in this document do not constitute a warranty of any kind, express or implied.
Website: http://www.huawei.com
Email: [email protected]
Contents
3 Installation.................................................................................................................................... 19
3.1 Safety Precautions .......................................................................................................................................... 19
3.1.1 General Safety Precautions ................................................................................................................... 19
3.1.2 Local Rules and Regulations ................................................................................................................. 19
3.1.3 Requirements on Operators ................................................................................................................... 19
3.1.4 Personnel Safety.................................................................................................................................... 19
3.1.5 Equipment Safety .................................................................................................................................. 20
3.2 Installation Scenarios ..................................................................................................................................... 20
3.3 Space Requirements ....................................................................................................................................... 22
3.4 Installation Preparations ................................................................................................................................. 22
3.4.1 Documentation Preparations ................................................................................................................. 22
3.4.2 Tool Preparations .................................................................................................................................. 23
3.4.3 Unpacking and Checking ...................................................................................................................... 25
3.4.4 Skills and Requirements for Onsite Personnel ...................................................................................... 26
3.5 Installation Requirements ............................................................................................................................... 26
7 Security Configuration............................................................................................................... 62
7.1 Configuring an Access Control List (ACL) .................................................................................................... 62
7.1.1 Configuring a Whitelist ......................................................................................................................... 62
7.1.2 Configuring a Blacklist ......................................................................................................................... 63
1.1 Purpose
This document describes the Huawei WLAN AP V100R006C00 in terms of products and
networking, installation, initial configurations, WLAN configurations, service verification,
security configuration, and routine maintenance.
AP WA131SN-NZ V100R006C00
WA201DK-NE
WA251DK-NE
WA251DT-NE
Wi-Fi card WA173DD-NE
1.4 Conventions
1.4.1 Symbol Conventions
The symbols that may be found in this document are defined as follows.
Symbol Description
Indicates a hazard with a high level of risk, which if not
avoided, will result in death or serious injury.
DANGER
Indicates a hazard with a medium or low level of risk,
which if not avoided, could result in minor or moderate
WARNING injury.
TIP Indicates a tip that may help you solve a problem or save
time.
Convention Description
Times New Roman Normal paragraphs are in Times New Roman.
Convention Description
Convention Description
[] Items (keywords or arguments) in square brackets [ ] are
optional.
{ x | y | .. } Optional items are grouped in braces and separated by
vertical bars. One item is selected.
[ x | y | .. ] Optional items are grouped in brackets and separated by
vertical bars. One item is selected or no item is selected.
{ x | y | .. } * Optional items are grouped in braces and separated by
vertical bars. A minimum of one item or a maximum of all
items can be selected.
[ x | y | .. ] * Optional items are grouped in brackets and separated by
vertical bars. Several items or no item can be selected.
Convention Description
Format Description
Key Press the key. For example, press Enter and press Tab.
Key 1+Key 2 Press the keys concurrently. For example, pressing Ctrl+Alt+A means
the three keys should be pressed concurrently.
Key 1, Key 2 Press the keys in turn. For example, pressing Alt, A means the two
keys should be pressed in turn.
Action Description
Click Select and release the primary mouse button without moving the
pointer.
Double-click Press the primary mouse button twice continuously and quickly
without moving the pointer.
Drag Press and hold the primary mouse button and move the pointer to a
certain position.
Issue 07 (2016-02-25)
This is the seventh commercial release.
Compared with 06 (2015-12-25), issue 07(2016-02-28) added one CLI commands.
Issue 06(2015-12-25)
This is the sixth commercial release.
Compared with 05 (2015-02-28), issue 06 (2015-12-25) added two CLI commands.
Issue 05 (2015-02-28)
This is the fifth commercial release.
Compared with 04 (2014-12-20), issue 05 (2015-02-28) modified some CLI commands.
Issue 04 (2014-12-20)
This is the fourth commercial release.
Compared with 03 (2014-10-30), issue 04 (2014-12-20) modified some description.
Issue 03 (2014-10-30)
This is the third commercial release.
Compared with 02 (2014-08-30), issue 03 (2014-10-30) modified some description.
Issue 02 (2014-08-30)
This is the second commercial release.
Issue 01 (2014-06-30)
This is the first commercial release.
Compared with draft A (2014-03-30), issue 01 (2014-06-30) deleted the description about
WA206DK-CE and modified some CLI commands.
Draft A (2014-03-30)
This is a draft.
Exterior
Antenna 2.4 GHz 2.4 GHz/5 GHz 2.4 GHz/5 GHz 2.4 GHz/5 GHz 2.4 GHz/5 GHz
1x1 Internal (supporting 3x3 MIMO 3x3 MIMO 3x3 MIMO
External external antenna) Internal Internal External (5 GHz)
Internal (2.4GHz)
Power Supply PoE power supply Powered by the Dock PoE+ capable PoE+ supporting PoE+ supporting
AC power supply switches, compatible switches switches
(AC/DC power with PoE PSE adapter PSE adapter
adapter required) PSE adapter (converting AC (converting AC
Supporting IEEE (converting AC power supply to power supply to
802.3af PoE power supply to PoE+) PoE+)
PoE+) Supporting IEEE Supporting IEEE
Supporting IEEE 802.3at PoE 802.3at PoE
802.3at PoE
Supporting IEEE
802.3af PoE
(providing lower
transmit power in this
mode)
Ground cable Not required Not required Not required Required Required
Port Description
Indicator Description
Power (Green) Power supply indicator:
Steady on: The power supply and the AP are working properly.
Off: The AP is not powered on or the power supply is not working
properly.
WLAN (Green) Operating status of the radio module:
Steady on: The radio module is not sending or receiving data.
Blinking fast (on for 0.25s and off for 0.25s): The radio module is
sending or receiving data.
Blinking slowly (on for 1s and off for 1s): The radio module is
starting. During the start-up, the Link and WLAN indicators are
simultaneously blinking slowly.
Steady off: A radio module is not detected.
Link (Green) Operating status of the Ethernet:
Steady on: The Ethernet is working properly.
If the indicator is blinking fast (on for 0.25s and off for 0.25s), the
Ethernet link is transmitting or receiving data.
Blinking slowly (on for 1s and off for 1s): The radio module is
starting. During the start-up, the Link and WLAN indicators are
simultaneously blinking slowly.
Steady off: The Ethernet cable is disconnected or is not properly
connected.
Port Description
Lock Lock slot for connecting to the chain of the lock. Anti-theft locks are
not delivered, and they must be prepared by customers if required.
ETH/PoE Ethernet port that is 10/100/1000 Mbit/s adaptive and supports
PoE/PoE+
Reset Hold down this button for less than three seconds to reset the device
and for longer than ten seconds to restore the factory settings.
Port Description
ETH/PoE Transmission/power supply port that connects a PoE port of a PSE
device or to a switch.
It is 10/100/1000 Mbit/s adaptive and supports PoE+.
Grounding port
It is used for connecting a ground cable.
Port Description
ETH/PoE Transmission/power supply port that connects a PoE port of a PSE
device or to a switch.
It is 10/100/1000 Mbit/s adaptive and supports PoE+.
5G_A 5 GHz RF port. If a 3x3 MIMO-capable antenna providing three ports
is used, connect the 5G_A port to an antenna port marked V or an
antenna port marked ±45°.
If a 2x2 MIMO-capable antenna providing two ports is used, connect
the 5G_A port to one of the antenna ports. If an antenna providing one
port is used, connect the antenna to the 5G_A port. Connect the 5G_A
and 5G_B ports to the antenna ports of different polarization.
5G_B 5 GHz RF port. If a 3x3 MIMO-capable antenna providing three ports
is used, connect the 5G_B port to an antenna port marked H or an
antenna port marked ±45°.
If a 2x2 MIMO-capable antenna providing two ports is used, connect
the 5G_B port to the vacant antenna port. If an antenna providing one
port is used, the 5G_B port is not used and must be waterproofed using
a waterproof plug. Connect the 5G_A and 5G_B ports to the antenna
Port Description
ports of different polarization.
5G_C 5 GHz RF port. If a 3x3 MIMO-capable antenna providing three ports
is used, connect the 5G_C port to the vacant antenna port. If a 2x2
MIMO-capable antenna providing two ports or an antenna providing
one port is used, the 5G_C port is not used and must be waterproofed
using a waterproof plug.
Grounding port
It is used for connecting a ground cable.
AP: base station in the WLAN DHCP server: address server Switch: convergence switch
AC: access controller in the WLAN OSS: operations support system
AP: base station in the WLAN DHCP server: address server Switch: convergence switch
AC: access controller in the WLAN OSS: operations support system DAS: distributed antenna
system
In the typical networking, the WLAN AP works as a fit AP to bridge the AC and STAs and
forward data between them. The AC is responsible for user access, AP network access,
authentication, routing, AP management, security protocol configuration, and QoS functions.
3 Installation
This chapter does not contain information about installation of the WA173DD-NE. For details about the
WA173DD-NE installation, see LampSite Installation Guide.
Power off the equipment before performing any operation on the power supply
equipment.
To prevent inhalation of or eye contact with dust, take adequate preventive measures
before drilling holes.
When working at heights, take preventive measures to prevent objects from falling
down.
WA131SN-NZ
WA251DK-NE
WA251DT-NE
Hammer drill (with a Ø8, and ESD gloves Network cable tester
Ø6)
Before installing a WA201DK-NE, ensure that all tools and instruments required listed in
Table 3-4 are ready.
Before installing a WA131SN-NZ, ensure that all tools and instruments required listed in
Table 3-5 are ready.
NOTE
Before installing an AP, unpack the AP and check the items in the package. In addition, you must:
Prevent the equipment, components, or parts from colliding with doors, walls, shelves, or other objects.
Avoid touching the uncoated metal surface of the equipment, components, or parts with sweat-soaked or
dirty gloves.
WARNING
To protect the equipment and help find out the cause of a possible damage, keep the unpacked
equipment and packing materials in indoor environment, and take photos of the stocking
environment, rusted or eroded equipment, packing case or carton, and packing materials and
then file the photos.
Step 1 Check whether the total number of goods is in conformity with the packing list attached to the
packing case.
If... Then...
The total number of the goods is in conformity with Go to Step 2.
the number on the packing list
The total number of the goods is not in conformity Find out the cause and contact the
with the number on the packing list local office of Huawei.
If... Then...
The packing case is in good condition. Go to Step 3.
The packing case is damaged or soaked. Find out the cause and contact the local
office of Huawei.
The shockwatch label is red Do not unpack the case and claim
compensation against the shipping company.
Step 3 Check whether the number and types of goods in the packing cases are in conformity with the
packing list.
If... Then...
Types and quantity of the goods are in Sign the Packing List for confirmation
conformity with those on the packing list together with the customer.
There is any short or wrong shipment or Fill in the Cargo Problem Report and submit
damage to the goods to the local office of Huawei.
----End
NOTE
If a cable listed below is not required, skip the routing requirements of the cable.
Labeling
Outdoor waterproof labels are stuck on devices and at both ends of cables.
Cables are also need labeling with colored insulation tape, as shown in Figure 3-1.
Colored insulation tape is made of polyvinyl chloride (PVC) and has the following
characteristics:
Easy to read and distinguish
Firmly and durably labeled
Simple to use
Colored insulation tape is about 20 mm wide and can be red, blue, and green.
Following is a description about how to label cables through colored insulation tape.
Step 1 Determine the labeling position.
Different cables have different labeling positions:
Antenna jumper: 200 mm from the outdoor feeder connector.
Outdoor feeder: 200 mm from the outdoor feeder connector.
Outdoor feeder: 1 meter from the tower platform
Outdoor feeder: 1 meter from the feeder window of the indoor-routing feeder
Indoor feeder: 200 mm from the indoor feeder connector.
Cabinet jumper: 200 mm from the indoor feeder connector.
The positions for wrapping colored insulation tapes at 1 meter from the tower platform and 1
meter from the feeder window of the indoor-routing feeder must be determined after the cable
routing is completed.
Step 2 Wrap colored insulation tape around the cable at the determined position using the insulation
tape of the required color and quantity.
Wrap two to three layers of colored insulation tape in the same direction, ensuring that each
layer of tape overlaps the preceding layer tightly and neatly.
Figure 3-2 shows how to wrap colored insulation tape.
Ensure that two adjacent colored insulation tapes are spaced from 10 mm to 15 mm apart.
Ensure that the color and quantity of colored insulation tapes are consistent on the same feeder or
jumper.
----End
1 Insulation tape
2 Waterproof tape
3 Cable tie
NOTE
Before wrapping waterproof tape, stretch the tape evenly until the length is two times the original length.
Do not stretch the insulation tape before wrapping. For details, see Figure 3-4.
Waterproof tape
PVC insulation tape
Lower ring
Upper ring
Stretch the waterproof tape to Each layer overlaps more than
Do not stretch the insulation tape.
double its length 50% of the preceding layer.
NOTE
Wrap each layer of tape tightly and neatly, ensuring that each layer of tape overlaps more than 50% of
the preceding layer.
Ensure that the side with adhesive tape is covered on the wrapped tape.
Wrap the middle RF connector first and then the RF connectors on the two sides.
Ensure that the top of the RF connector are covered by the waterproof tape during wrapping.
Use outdoor waterproof tape. Do not use colored insulation tape to wrap the RF jumper and connector.
The ground cable is green or yellow, terminated with OT terminals on both ends.
The cross-section area of ground cables is 6 mm2 or 10 AWG depending on specific countries,
and the length of ground cables is determined according to actual situations.
Figure 3-5 shows the exterior of a ground cable.
NOTE
OT terminals should be assembled in accordance with the local regulations and laws.
CAUTION
The shield layer of the network cable is reliably connected to the shielded sheath of the RJ45
connector in all directions.
Shielded RJ45 connectors are required.
Make PG connectors prepared on ground to facilitate installations at heights.
Step 2 Install shielded RJ45 connectors for network cables and mark both ends of network cables.
NOTE
The WA151DD-NZ, WA251DK-NE, and WA251DT-NE require outdoor shielded network cable. The
WA101DD-NZ, WA131SN-NZ, and WA201DK-NE require indoor unshielded straight-through network
cable.
For details about how to prepare a shielded network cable or unshielded network cable, see the Quick
Installation Guide of the respective APs.
Step 3 (Optional) Place outdoor network cables through PVC pipes, as shown in Figure 3-8.
----End
Figure 3-9 shows how to install a lightning rod for WA251DT-NE on a pole.
Figure 3-10 Ground cable installation for the surge protection of PSE adapters in a tower
installation scenario (WA251DT-NE as an example)
Figure 3-11 Ground cable installation for the surge protection of PSE adapters in an off-tower
scenario (WA251DT-NE as an example)
Start
Install cables.
End.
4 Initial Configuration
This chapter describes how to perform AP initial configurations on the MAG9811. For details,
see MAG9811 Production Documentation. The configurations allow an AP to go online
(connected to the MAG9811).
NOTE
The AC refers to the MAG9811 in this document.
WLAN APs connect to an IP network in static IP address mode or DHCP mode. DHCP mode is used by
default. If the AP fails to connect to an IP network in DHCP mode, troubleshoot the fault by referring to
section 8.7 "Local Maintenance Commands."
Command arguments are in italics and need to be replaced with actual values.
1
2
...
----End
----End
WARNING
An AP can be authenticated in mac-auth, sn-auth, or no-auth mode.
If mac-auth or sn-auth mode is used, an AP needs to be added in offline mode before going
online.
Before adding an offline AP, information about the offline AP needs to be obtained.
An offline AP can be added through mac-auth authentication or sn-auth authentication:
Add an offline AP through mac-auth authentication:
5 WLAN Configuration
This chapter describes the AP WLAN configurations. With these configurations, an AP can
connect to a WLAN.
NOTE
The WLAN RF modes supported on the AP are 80211an, 80211bgn, 80211gn, 80211n, 80211b, 80211a,
80211bg and 80211g.
Step 3 (Optional) Configure the channel mode in the RF profile. By default, it is set to fix.
[MAG9811-wlan-radio-prof-ratest1]channel-mode fix
Step 4 (Optional) Configure the power mode in the RF profile. By default, it is set to fix.
[MAG9811-wlan-radio-prof-ratest1]power-mode fix
Step 5 (Optional) Configure the short GI in the RF profile. By default, it is set to normal.
[MAG9811-wlan-radio-prof-ratest1]80211n guard-interval-mode short
Step 6 (Optional) Configure the a-mpdu. By default, it is enabled, and the frame length value
converged on the MAC protocol data unit (MPDU) is set to 3.
[MAG9811-wlan-radio-prof-ratest1]80211n a-mpdu max-length-exponent 3
----End
By default, it is set to 0.
The AP actual power equals to the AP maximum power minus the AP power level.
For example, if the AP maximum power is 27 dBm, the AP power level is 5, and the AP
power step is 2, then the AP actual power equal to 17 dBm.
Step 4 Configure the AP channel and frequency bandwidth. The frequency bandwidths supported on
the AP are 20 MHz, 40 MHz+, and 40 MHz-.
[MAG9811-wlan-radio-0/0]channel 20mhz 1
Step 5 (Optional) Configure modulation and coding scheme (MCS) of the specified 802.11n AP. By
default, it is set to 23.
[MAG9811-wlan-radio-0/0]80211n mcs 23
----End
----End
Step 2 Configure the upper and lower rate thresholds in units of kbit/s for a STA accessing the AP.
[MAG9811-wlan-traffic-prof-trtest1]rate-limit client down 1024
[MAG9811-wlan-traffic-prof-trtest1]rate-limit client up 1024
Step 3 Configure the upper and lower rate thresholds in units of kbit/s for the VAP.
[MAG9811-wlan-traffic-prof-trtest1]rate-limit vap down 1024
[MAG9811-wlan-traffic-prof-trtest1]rate-limit vap up 1024
----End
Step 2 Specify the VLAN mapping mode and VLAN ID for user data.
[MAG9811-wlan-ac-view]vlan-mapping ess name ess1 mode ess
[MAG9811-wlan-ac-view]vlan-mapping ess name ess1 type tag vlan 220
Step 3 (Optional) Configure the maximum number of associated users of the ESS. By default, it is
set to 32.
[MAG9811-wlan-ac-view]ess modify name ess1 max-user-number 10
----End
6 Service Verification
Type Requirements
A laptop With CPU of 1 GHz or higher and RAM of 512 MB or higher.
Configured with internal radio network adapter.
Running Windows Vista or a later-released Windows operating
system.
Using Microsoft IE 6.0 or a later version, with proxy function
disabled.
A mobile phone Supporting Wi-Fi
Step 2 Choose the target SSID from the SSID list and click Connect.
Then, the STA is associated with the WLAN network.
Step 3 After the status of the target WLAN network is Connected, verify services on the WLAN
network, including browsing web pages, watching videos, and downloading files.
----End
Step 2 Choose the target SSID from the SSID list and click Connect.
Then, the STA is associated with the WLAN network.
Step 3 After the status of the target WLAN network is Connected, open the Internet Explorer and
enter an IP address in the address box.
Then the STA is redirected to the portal page.
Step 4 On the portal page, enter the user name and password, and click Log In.
Step 5 After the login succeeds, verify services on the WLAN network, including browsing web
pages, watching videos, and downloading files.
----End
Then, the Wireless & networks page is displayed, as shown in Figure 6-5.
Step 4 In the displayed Wireless & networks page, touch WLAN settings.
If the WLAN check box is light blued, WLAN is already enabled and Step 5 is not required.
After the scanning is complete, SSIDs of the available wireless networks are displayed, as
shown in Figure 6-7.
Step 6 In the searched SSID list under Networks, touch xiansim.
Then, the xiansim page is displayed as shown in Figure 6-9. The PEAP configuration items
include EAP method, Phase 2 authentication, CA certificate, and User certificate.
Step 8 Configure xiansim by following the configurations shown on Figure 6-10 and Figure 6-11
and then touch Connect.
NOTE
In this step, Figure 6-10 and Figure 6-11 are the same displayed page for configuring the xiansim.
Enter the WLAN account (phone number) and password (service password of the phone number) in the
identity and password text boxes in Figure 6-11, and touch Save.
When the WLAN account and password are entered, the Connect button is replaced by the Save button.
After the Save button is touched, the Connect button shows again.
Then, the phone starts to connect to the wireless network, as shown in Figure 6-12.
If the status of the xiansim network is Connected in a few seconds as shown in Figure 6-13,
the mobile phone successfully connects to the AP through PEAP authentication.
----End
7 Security Configuration
NOTE
A blacklist or whitelist is used to control the access of STAs to a WLAN network.
A blacklist or whitelist contains a maximum of 512 MAC addresses. After the added MAC reaches the
maximum, no more MAC address can be added.
----End
----End
8 Routine Maintenance
8.1 AP Alarms
AP alarms are collected through the interface that links the AP to the AC and reported to and
displayed on the NMS.
The most frequently reported AP alarms include CPU overload alarms, AP offline alarms,
interference alarms, and software upgrade failure alarms.
Despite different methodologies of different vendors for displaying and reporting AP alarms
on their network management system (NMS) equipment, the Management Information Base
for Network Management of TCP/IP-based Internets (MIB-II) [RFC1213] standards are all
observed.
8.4 AP Replacement
The MAG9811 supports AP replacement that enables a new AP to carry services of an AP to
be replaced without reconfiguring the new AP. This helps implement quick recovery of
services when an AP on a live network becomes faulty.
Configurations of an AP are bound with the MAC address or SN of the AP. During a
replacement, the AP to be replaced can be identified by its ID, MAC address, or SN. The new
AP can be identified by either the MAC address or SN of the new AP, or both during the
replacement.
If the new AP is already in use on live networks, use the ap modify command to delete all
original information and configurations before using for a replacement.
8.4.2 Procedure
Following is a short description about how to replace an AP.
Step 1 Run the system-view command to enter the system view.
Step 2 Run the wlan ac command to enter the wlan-ac view.
Step 3 Run the ap modify command to change the MAC address or SN of the AP to be replaced to
that of the new AP.
Step 4 Remove the AP to be replaced and install the new AP.
For details about how to remove and install an AP, see Quick Installation of the AP.
Step 5 Run the display ap all command to check whether the replacement succeeds.
----End
8.4.3 Example
To use the AP with the MAC address 1212-4545-4547 to replace AP 4, first run the following
commands on the AC:
<AC>system-view
[AC]wlan ac
After executing the commands, remove the AP to be replaced and install the new AP.
WARNING
The default password has security vulnerabilities. Change the default password of an AP by
running the ap-modify-password command on the AC immediately after the AP is installed.
For details about how to change the AP default password, see MAG9811 Command Reference.
display ap all Used to query the types, operating status, and MAC addresses of
all APs.
display ap id 0 Used to query information about AP 0, including AP type ID,
AP type, AP MAC address, and IP address.
8.5.3 Example
Run the following command to query information about AP 0, including operating status,
software version, hardware version, CPU type, CPU frequency, memory type, running
duration, and IP address:
<MAG9811>display ap-run-info id 0
AP 0 run information:
----------------------------------------------------------------------------
Software version: V100R005C00SPC120
Hardware version: Ver.A
BIOS version: -
Cpu type: AR9342-32 bit MIPS 74K 600MHz
Cpu frequency: 600 MHZ
Memory type: SDRAM-EM6AA160TS
Domain: China(CN)
AP System software description: WLAN AP:V100R005C00SPC120
AP System hardware description: WLAN AP:Ver.A
AP manufacture: Huawei Technologies Co., Ltd.
AP software name: Huawei Outdoor Bridge Access Point Software
AP software vendor: Huawei Technologies Co., Ltd.
AP online time: 67553
Ip address: 192.168.4.245
Ip mask: 255.255.255.0
Gateway ip: 192.168.4.1
DNS server: 0.0.0.0
Memory size: 64 MB
Flash size: 16 MB
Run time: 67568 S
Up ethernet port speed: 100 Mbps
Up ethernet port speed mode: auto
Up ethernet port duplex: full
Up ethernet port duplex mode: auto
Lineate port 0 state: up
Lineate port 0 speed: 100 b/s
Lineate port 0 ip address: 192.168.4.245
Lineate port 0 mac address: 707b-e88f-15f8
----------------------------------------------------------------------------
NOTE
Ensure that the IP address of the computer is in the same network segment as that of the AP. For
example, if the AP uses the default local maintenance IP address 192.168.1.1 and subnet mask
255.255.255.0, you can change the IP address of the computer and subnet mask to 192.168.1.2 and
255.255.255.0, respectively.
NOTE
WARNING
The default password has security vulnerabilities. Change the default password of an AP by
running the ap-modify-password command on the AC immediately after the AP is installed.
For details about how to change the AP default password, see MAG9811 Command Reference.
The IP address configured for an AP must be the IP address of the AP IP address pool configured on the
AC.
Step 6 (Optional) Run the ip ap address command to configure a static IP address for the AP.
Step 7 Run the ip ac address command to configure a static IP address for the AC.
Step 8 Run the exit command to exit the configuration mode.
Step 9 Run the reset board command to restart the AP to make the change take effect.
----End
NOTE
Ensure that the IP address of the STA is in the same network segment as that of the AP. For example, if
the management VAP uses the local maintenance IP address 192.168.1.1 and subnet mask 255.255.255.0,
you can change the IP address of the computer and subnet mask to 192.168.1.2 and 255.255.255.0,
respectively.
Then, users can log in to the AP for maintenance purpose. For details about how to log in to
the AP, see Step 3 to Step 8 in section 8.6.1 "In Scenarios Where a STA Connects to an AP
over an Ethernet Port."
----End
NOTE
In this example, assume that the configured ESSID name is mgmt_test, and the management VAP is
configured for AP 0.
The management VAP configured on the AC only supports open authentication and WEP authentication.
NOTE
If the MAG9811 V100R001C00 is used, this step is not required because management VAP is always
enabled on the MAG9811 V100R001C00.
8.7.1 Overview
This chapter provides the functions and usage guidelines of commands available on the
command line interface (CLI) after a user logs in to an AP in security shell (SSH) mode.
1 main A user enters the main view by default upon a login. The main
view also enables a user to enter other views.
2 configure The configure view provides a set of commands for configuring
the working mode and IP configuration mode of an AP and
performing one-step information collection.
3 fatap The fatap view provides a set of commands for operating APs
that work in fat AP mode.
4 shelltool The shelltool view provides a set of commands for querying the
AP system status.
5 debug The debug view provides a set of commands for configuring AP
parameters.
8.7.2 main
A user enters the main view by default upon a login. The main view provides one-step
information collection commands, ping commands, AP-restarting commands, and upgrade
commands. The view also functions as an entry to other views.
Table 8-8 describes commands in the main view.
ping ping {host-ip-address The ping command is used to check host-ip-address: Specifies the
[source-ip-address] | whether a host is reachable on an IP IP address of the target host. It
ipv6 ipaddr6} network. is in the dotted decimal format.
The ping host-ip-address command source-ip-address: Specifies the
is used to ping the host with the IP source IP address.
address specified by ipaddr. ipaddr6: Specifies an IPv6
The ping host-ip-address address in the format of
source-ip-address command is used XX::XX:XX:XX:XX, with each X
to ping the host with the IP address represents a hexadecimal
specified by ipaddr from the AP number.
with the IP address specified by
source-ip-address.
The ping ipv6 ipaddr6 command is
used to ping the host with the IPv6
address specified by ipaddr6.
reset reset { board | The reset command is used to reset -
configuration } an AP.
The reset board command is used
to reset an AP.
The reset configuration command
is used to restore the default
configuration of an AP.
show show { ap mode | ap The show command is used to bridge-index: Specifies the ID
vlan | bridge stp { all display information about an AP. of a bridge. It is an integer from
| bridge-index } | The show ap mode command is 0 to 4094.
capwap | dual-image used to display the AP working radio-id: Specifies the ID of a
| interface { ethernet | mode. radio band at which an AP is
wireless radio-id vap working. It can be set to 0 (2.4
vap-id } | ip-config | The show ap vlan command is
used to display the VLAN GHz) or 1 (5 GHz).
system |mgt-vap}
information of an AP. vap-id: Specifies the ID of a
The show bridge stp command is VAP of an AP. It is an integer
used to display the bridge from 0 to 15.
information.
The show capwap command is
used to display the current state of
CAPWAP tunnels.
The show dual-image command is
used to display the activity status of
a boot partition.
The show interface ethernet
command is used to display
information about the Ethernet
ports of an AP.
upgrade upgrade { ftp | sftp } The upgrade command is used to file-name: Specifies the file
file-name locally upgrade an AP. name of the upgrade file
ftp-ip-address The upgrade ftp command is used package. It is a character string.
user-name password to locally upgrade an AP in FTP ftp-ip-address: Specifies the IP
[source-ip-address] mode. address of an FTP or SFTP
The upgrade sftp command is used server. It is in the dotted decimal
to locally upgrade an AP in SFTP format.
mode. user-name: Specifies the FTP
or SFTP user name. It is a
The SFTP server is preferred to
character string.
ensure security. password: Specifies the FTP or
SFTP user password. It is a
character string.
source-ip-address: Specifies the
source IP address of the FTP or
SFTP client.
debug debug The debug command is used to -
enter the debug view.
8.7.3 configure
To enter the configure view, type configure in the main view and press Enter.
Table 8-9 describes commands in the configure view.
ap ap { mode { fat | fit | The ap mode command mode: Specifies the working mode of an AP.
cal } | vlan vlan-id } is used to configure the It is an enumerated type that has three values:
mgt-vap mgt-vap offline The mgt-vap offline The configuration made by using the mgt-vap
{open | close} open command is used offline command takes effect unless the AP on
to enable a which the management VAP is created is
management VAP. restarted.
The mgt-vap offline
close command is used
to disable a
management VAP.
8.7.4 fatap
To enter the fatap view, type fatap in the configure view and press Enter. The commands
described in this chapter are applicable only when an AP works in fat AP mode.
NOTE
Fat AP can only be used in test scenarios. Do not enable an AP to work in fat mode on a commercial
network.
8.7.5 shelltool
To enter the configure view, type shelltool in the main view and press Enter. The commands
described in this chapter are used to debug APs.
8.7.6 debug
main
To enter the debug view, type debug in the main view and press Enter.
Table 8-12 describes the commands in the debug view.
nettest nettest src dst The nettest src dst [bandwidth | src: Specifies the MAC address of
[bandwidth | stop] [uplink | downlink bidir] the source AP during a test. It is in
delay | stop] [filesize | pkt size pkt send freq the format of
[uplink | pktsend duration] command is to test XX-XX-XX-XX-XX-XX.
downlink bidir] mesh services by making test calls in dst: Specifies the MAC address of
[filesize | pkt size FTP mode. the destination AP during a test. It
pkt send freq The nettest src dst [delay | stop] is in the format of
pktsend duration] [uplink | downlink bidir] [filesize | XX-XX-XX-XX-XX-XX.
pkt size pkt send freq pktsend bandwidth: A dialing test for
duration] command is to test mesh mesh services is performed by
services by using the ping command. using file transfer in FTP mode.
delay: A dialing test for mesh
services is performed by using the
ping command.
stop: A dialing test for mesh
services is stopped.
uplink: A dialing test for mesh
services is performed in the
upstream.
Downlink: A dialing test for mesh
services is performed in the
downstream.
bidir: A dialing test for mesh
services is performed in both the
downstream and upstream.
filesize: Size of data to be
transferred in the unit of MB
during an FTP dialing test for
mesh services. It can be set to a
number ranging from 1 to 1024.
pkt size: Specifies the size of a
ping packet ping in the unit of byte
during a ping test. It can be set a
number ranging from 20 to 8100.
pkt send freq: Specifies the
packet sending frequency in the
unit of packets per second during a
ping test. It can be set a number
ranging from 1 to 10.
pkt send duration: Specifies
duration of a ping test in the unit
of second. It is an integer from 1
to 360.
icmp_rate icmp_ratemask The icmp_ratemask command is By default, icmp_ratemask is set
mask [ 6160|6168 ] used to set icmp_ratemask to 6160 to 6168. If a UDP scan needs to be
or 6168 to speed up UDP scan. accelerated, set cmp_ratemask is
set to 6160.
wlanconfig
To enter the wlanconfig view, type wlanconfig in the debug view and press Enter.
Table 8-13 describes commands in the wlanconfig view.
vap-id vap-id vap-index The vap-id vap-index list command vap-index: Specifies
list[ap |sta| chan is used to query information about the ID of a VAP. It
| caps] STAs associated with a VAP. is an integer from 0
The vap-id vap-index listap to 31.
command is used to query the list of
neighboring APs.
The vap-id vap-index liststa
command is used to query
information about STAs associated
with a VAP.
The vap-id vap-index listchan
command is used to query the lists of
channels that can be used by a VAP.
The vap-id vap-index listcaps
command is used to query the
capability of a VAP.
iwpriv
To enter the iwpriv view, type iwpriv in the debug view and press Enter.
Table 8-14 describes commands in the iwpriv view.
iwpriv wifiN iwpriv wifiN The iwpriv wifiN wifiN: Specifies the ID of a radio band at
getbwstadns getbwstadnspec getbwstadnspec command which an AP is working. It can be set to 0
pec mac-address pad is used to query the state (2.4 GHz) or 1 (5 GHz).
mac-address of the downstream mac-address: Specifies the MAC address of
pad bandwidth limit switch of a STA that has associated with the radio
a STA. This command has band of an AP. It is in the format of
two outputs: 0 (disabled) XX:XX:XX:XX:XX:XX.
and 1 (disabled).
pad: It is a useless pad parameter, and can
be set to any non-key character. Generally, it
is set to 1.
iwpriv wifiN iwpriv wifiN The iwpriv wifiN wifiN: Specifies the ID of a radio band at
getbwstadnt getbwstadnthsp getbwstadnthspec which an AP is working. It can be set to 0
hspec ec mac-address mac-address pad (2.4 GHz) or 1 (5 GHz).
mac-address pad command is used to query mac-address: Specifies the MAC address of
pad the threshold of a STA that has associated with the radio
downstream bandwidth band of an AP. It is in the format of
limit for a STA. The XX:XX:XX:XX:XX:XX.
command output is in the
unit of kbit/s. pad: It is a useless pad parameter, and can
be set to any non-key character. Generally, it
is set to 1.
iwpriv wifiN iwpriv wifiN The iwpriv wifiN wifiN: Specifies the ID of a radio band at
getbwstaups getbwstaupspec getbwstaupspec which an AP is working. It can be set to 0
pec mac-address pad mac-address pad (2.4 GHz) or 1 (5 GHz).
mac-address command is used to query mac-address: Specifies the MAC address of
pad the state of the upstream a STA that has associated with the radio
bandwidth limit switch of band of an AP. It is in the format of
a STA. This command has XX:XX:XX:XX:XX:XX.
two outputs: 0 (disabled)
and 1 (disabled). pad: It is a useless pad parameter, and can
be set to any non-key character. Generally, it
is set to 1.
iwpriv wifiN iwpriv wifiN The iwpriv wifiN wifiN: Specifies the ID of a radio band at
getbwstaupt getbwstaupthsp getbwstaupthspec which an AP is working. It can be set to 0
hspec ec mac-address mac-address pad (2.4 GHz) or 1 (5 GHz).
mac-address pad command is used to query mac-address: Specifies the MAC address of
pad the threshold of upstream a STA that has associated with the radio
bandwidth limit for a STA. band of an AP. It is in the format of
The command output is in XX:XX:XX:XX:XX:XX.
iwconfig
To enter the iwconfig view, type iwconfig in the debug view and press Enter.
Table 8-15 describes commands in the iwconfig view.
show show [vap-id vap-id] The show command is vap-id: Specifies the ID of a
used to query VAP. It is an integer from 0
information about a radio to 31.
band.
iwlist
To enter the iwlist view, type iwlist in the debug view and press Enter.
Table 8-16 describes commands in the iwlist view.
stats
To enter the stats view, type stats in the debug view and press Enter.
Table 8-17 describes commands in the stats view.
stats80211 stats80211 [athX] The sstats80211 [athX] athX: Specifies the ID of a VAP, with X an
[ type] [type] command is used integer from 0 to 31.
to query statistics of a type: Specifies which statistics are displayed. It
VAP. is an enumerated type that contains two
options: all (all STAs) and stamac (a STA in
the format of XX:XX:XX:XX:XX).
apstats apstats [ grep The apstats command chars: Specifies the character string that is used
chars] is used to query the as a search criterion for searching the required
summary of packets information.
statistics of a VAP and grep: Specifies the information that contains
an AP. the character string specified by chars in the
command output.
athstats athstats The athstats command wifi0/wifi1: Specifies the ID of a radio band. It
[ wifi0/wifi1] is used to query the is an enumerated type that contains two
[ grep chars] details of packet options: wifi0 and wifi1. The default value is
statistics of a VAP. wifi0.
chars: Specifies the character string that is used
as a search criterion for searching the required
information.
grep: Specifies the information that contains
the character string specified by chars in the
command output.
ethstats ethstats [grep The ethstats command grep: Specifies the keywords with which
chars] is used to query the information will be displayed in the command
packet statistics of AP. output.
chars: Specifies the character string that is used
as a search criterion for searching the required
information.
ifconfig
To enter the ifconfig view, type ifconfig in the debug view and press Enter.
Table 8-18 describes commands in the ifconfig view.
apshell
To enter the apshell view, type apshell in the debug view and press Enter.
Table 8-19 describes commands in the apshell view.
brctl
To enter the brctl view, type brctl in the debug view and press Enter.
Table 8-20 describes commands in the apshell view.
showstp showstp bridge The showstp command is brX: Specifies the name of a bridge, with X a
brX used to query information decimal integer from 0 to 4094.
about the STP.
The showstp bridge brX
command is used to query
information about the STP of
the bridge named brX.
showmacs showmacs The showstp command is brX: Specifies the name of a bridge, with X a
sysdbg
To enter the sysdbg view, type sysdbg in the debug view and press Enter.
Table 8-21 describes commands in the apshell view.
set_pkt_tr set_pkt_track The set_pkt_track trackMac: Specifies the MAC address of the
command is used to trace STA to be traced. It is in the format of
disable_ipv disable_ipv6 The disable_ipv6 get value: Specifies an IPv6 switch value. It can
6 {get|set value} command is used to be 0 (enabled) or 1 (enabled).
query the status of an
IPv6 switch.
The disable_ipv6 set
value command is used
to configure an IPv6
switch.
detect_airp detect_airport The detect_airport radio: Specifies the ID of a radio band. It can
ort {get_para|detect_ command is used to be set to 0 (2.4 GHz) or 1 (5 GHz).
enable radio state| configure interference state: Specifies the status of the interference
{com_threshold|a detection. detection switch. It can be set to 0 (2.4 GHz)
dj_threshold|sta_t
autowds autowds The autowds ShowDig level: Specifies the display level for WDS
{ShowDig command is used to diagnosis information. It is an enumerated
|printLVL level} query the diagnosis type that has four values: 0, 1, 2, and 3.
information about a 0: Indicates that display of WDS diagnosis
WDS network. information is disabled.
The autowds printLVL 1: Indicates that diagnosis information at the
level command is used to error and higher alarm severities is
configure the display displayed.
level for diagnosis
2: Indicates that diagnosis information at the
information about a
WDS network. warning or higher alarm severities is
displayed.
3: Indicates that diagnosis information at all
alarm severities is displayed.
stastats stastats wifiN The stastats wifiN value wifiN: Specifies the ID of a radio band at
value command is used to turn which an AP is working. It can be set to 0 (2.4
on or turn off the STA GHz) or 1 (5 GHz).
statistics switch. value: Specifies the state of the STA statistics
switch. It can be set to 0 (ON) or 1 (OFF).
show_softg show_softgre_tun show_softgre_tunnel_st -
re_tunnel_ nel_stat at
stat command is used to get
the statistics of softgre
mesh
To enter the mesh view, type mesh in the debug view and press Enter.
Table 8-22describes commands in the apshell view.
Number of stations: 1
Query information about the devices associated with AP 10, such as their MAC
addresses and SSIDs.
− Radio-id 0 indicates that the information about 2.4-GHz radio profile of the AP is
queried.
− Radio-id 1 indicates that the information about 5-GHz radio profile of the AP is
queried.
<MAG9811>display station assoc-info ap 10 radio 0
------------------------------------------------------------------------------
STA MAC AP-ID RADIO-ID ESS-ID SSID
------------------------------------------------------------------------------
60d8-19c8-1651 10 0 101 huawei
--------------------------------------------------------------------------
Step 2 Configure self-healing time for an AP. The value in units of hours ranges from 12 to 120, with
the default of 0.
[MAG9811-wlan-ap-prof-profile0]idle-reset-time 12
----End
A Appendix
This chapter is a complement to this document and describes how to connect terminals to an
AP.
Step 5 On the General tab page, choose Internet Protocol (TCP/IP) and then click Properties.
Then, the Internet Protocol (TCP/IP) Properties window is displayed, as shown in Figure
A-3.
Figure A-3 Configuring an IP address for a wireless NIC and DNS server
Step 6 On the displayed page as shown in Figure A-3, choose Obtain an IP address automatically
and Obtain DNS server address automatically and click OK.
NOTE
In this step, you can also configure a specific IP address and DNS server address in the Use the
following IP address and Use the following DNS server addresses panes.
Step 7 On the Wireless Networks tab page, choose the Use Windows to configure my wireless
network settings check box, and check for the target SSID in the Preferred networks option
box, as shown in Figure A-4.
Step 8 If the target SSID is not listed, click Add to add it.
Then, the Wireless network properties window is displayed.
Step 9 On the Association tab page as shown in Figure A-5, enter the SSID in the Network name
(SSID) text box, specify Network Authentication and Data encryption, and then enter the
network key in Network key and Confirm network key text boxes, and then click OK.
The SSID is case-sensitive and needs to be the same as that configured on the terminal.
In this example, the network name or SSID is auto-tool-wap2, and the terminal works in WPA-PSK
encryption mode and the network key is 12345678.
Step 10 In the displayed wireless Properties window, click View Wireless Networks, as shown in
Figure A-6.
Step 13 In the displayed dialog box as shown in Figure A-8, enter the network key in Network key
and Confirm network key text boxes. Then, click Connect.
If the status of the wireless network is Connected as shown in Figure A-9 in a few seconds
later, the terminal successfully connects to the wireless network.
----End
Then, the Wireless & networks page is displayed, as shown in Figure A-12.
Step 4 In the displayed Wireless & networks page, touch WLAN settings.
If the WLAN check box is light blued, WLAN is already enabled and Step 5 is not required.
----End
Then, the Wireless & networks page is displayed, as shown in Figure A-16.
Step 4 In the displayed Wireless & networks page, touch WLAN settings.
If the WLAN check box is light blued, WLAN is already enabled and Step 5 is not required.
After the scanning is complete, SSIDs of the available wireless networks are displayed, as
shown in Figure A-18.
Step 6 In the searched SSID list under Networks, touch xiansim, as shown in Figure A-18.
Step 8 Configure xiansim by following the configurations shown on Figure A-21 and Figure A-22.
NOTE
In this step, Figure A-21 and Figure A-22 are the same displayed page for configuring the xiansim.
Enter the WLAN account (phone number) and password (service password of the phone number) in the
identity and password text boxes in Figure A-22 and touch Save.
When the WLAN account and password are entered, the Connect button is replaced by the Save button.
After the Save button is touched, the Connect button shows again.
Then, the phone starts to connect to the wireless network, as shown in Figure A-23.
If the status of the xiansim network is Connected in a few seconds as shown in Figure A-24,
the mobile phone successfully connects to the AP through PEAP authentication.
----End
Then, the mobile phone starts to connect the wireless network, as shown in Figure A-26.
If Status of the xiansim network is Connected, the mobile phone successfully connects to the
target network, as shown in Figure A-27.
NOTE
For a UMTS android mobile phone, touch AKA on the EAP method page. The method for a UMTS
android phone to connect a wireless network is the same as that for a a GSM phone.
----End
AC Access Controller A device that controls and manages all associated access
points (APs) in a WLAN. An AC can work with the
authentication server to provide the authentication service for
WLAN users.
AP Access Point A device that bridges a STA to a WLAN and converts radio
frames from a STA into Ethernet frames and converts Ethernet
frames from the WLAN into radio frames.
CAPWAP Control And A protocol that defines how communication is implemented
Provisioning of between an access point (AP) and an access controller (AC)
Wireless Access and provides a universal encapsulation and transmission
Points mechanism for the interoperation between the AP and the AC.
CAPWAP tunnel – A tunnel transmitting management packets and data packets
between the AC and the AP when the AP is registering with
the AC. The management packets exchanged between the AC
and the AP must be encapsulated in the CAPWAP tunnel for
transmission. This means that a CAPWAP management tunnel
needs to be set up, and such a tunnel requires no additional
hardware. Whether the data packets exchanged between the
AC and the AP need to be encapsulated in the CAPWAP
tunnel depends on actual configuration scenarios. If yes, a
CAPWAP data tunnel needs to be set up between the AC and
the AP. This tunnel requires additional hardware, which
implements tunnel encapsulation and decapsulation. If no, data
packets of the AP are directly forwarded.
OPEN-SYS Open system –
authentication
VAP Virtual Access Point –
VLAN Virtual Local Area –
Network
WAPI WLAN –
Authentication and