3Com WX4400 3CRWX440095A, WXR100 3CRWXR10095A, WX1200 3CRWX120695A, WX2200 3CRWX220095A manual Ccmp

Page 297

Configuring RSN (802.11i) 297

Specifying the RSN To use RSN, at least one cipher suite must be enabled. You can enable Cipher Suites one or more of the following cipher suites:

„CCMP

„TKIP

„40-bit WEP

„104-bit WEP

By default, TKIP is enabled and the other cipher suites are disabled.

To enable or disable cipher suites, use the following commands:

set service-profile name cipher-ccmp {enable disable} set service-profile name cipher-tkip {enable disable} set service-profile name cipher-wep104 {enable disable} set service-profile name cipher-wep40 {enable disable}

To enable the CCMP cipher suite in service profile rsn, type the following command:

WX1200# set service-profile rsn cipher-ccmp enable success: change accepted.

After you type this command, the service profile supports both TKIP and

CCMP.

Microsoft Windows XP does not support WEP with RSN. To configure a service profile to provide WEP for XP clients, leave RSN disabled and see “Configuring WEP” on page 299.

Image 297
Contents Wireless LAN Mobility System United States Government Legend 3Com Corporation 350 Campus Drive Marlborough, MA USAContents Managing User Passwords Configuring AAA for Administrative and Local AccessConfiguring and Managing Ports and Vlans Configuring and Managing IP Interfaces and ServicesDisplaying Password Information 108 Configuring and Managing Mobility Domain Roaming Configuring SnmpConfiguring Network Domains Configuring MAP Access PointsMAP Overview Country of Operation 179 Configuring RF Load Balancing for Maps RF Load Balancing Overview 267268 Configuring User Encryption Configuring Wlan Mesh ServicesConfiguring RF AUTO-TUNING Configuring Maps to be Aeroscout ListenersConfiguring Quality of Service Configuring and Managing Spanning Tree Protocol Configuring and Managing Igmp Snooping Configuring and Managing Security Acls380 Managing Keys and Certificates Why Use Keys and Certificates? 413414 416475 Using an ACL Other Than portalacl Configuring AAA for Network Users460 479496 494 Clearing a Security ACL from a User or Group 495503 514Managing 802.1X on the WX Switch Configuring Communication with RadiusManaging Sessions Configuring Soda Endpoint Security for a WX SwitchRogue Detection and Countermeasures Troubleshooting a WX Switch 631 Using the Trace CommandManaging System Files Enabling and Logging Into WEB View Supported Radius Attributes Glossary Index Command IndexTraffic Ports Used by MSS Obtaining Support for Your 3COM ProductsConventions List conventions that are used throughout this guideIcon Description 3WXM for advanced configuration and management Including new features and bug fixesDocumentation This manual uses the following text and syntax conventionsPddtechpubscomments@3com.com CommentsAbout this Guide Overwrite a parameter with another set command. Use display To configure and manage the switch and its attached MAPsOverview Network operationsConventions Text EntryCase-insensitive Alphanumeric characters, except for tabs and spaces, and isIP Address and Mask Notation MAC Address NotationUser Globs User GlobsUser Glob Users Designated Vlan Globs MAC Address GlobsWX1200# reset port WX1200# set port enableMatching Order for Globs WX1200# display port poe 1,2,4,6Editing Command-LineOperating systems CLI Keyboard ShortcutsCommands that begin with those characters. For example Using CLI HelpAt your access level, type the following command Wildcard CharactersWX1200# display i? WX1200# display ip ?WX1200# display ip telnet Set ap name command has the following complete syntax Understanding Command DescriptionsSet ap Set ap apnumber auto security„ CLI quickstart command SwitchesMethods „ Web Quick Start WXR100, WX1200, and WX2200WX Setup Methods Gets its Configuration How a WX SwitchWX2200 Only Quick Start Accessing the Web To access the Web Quick StartWX Setup Methods Web Quick Start WXR100, WX1200 and WX2200 Only CLI quickstart Set enablepass command WX Setup Methods Single-Switch Deployment Verify the configuration changes Remote WX To open the network plan Select File Switch Network PlanStart 3WXM by doing one of the following „ On Linux systems, change directories to3Com Mobility System Software MSS supports authentication Here is an overview of configuration topicsOperation Configuring AAA for Administrative and Local Access Building Access AdministrativeBefore You Start AboutAdministrator Configuration viaFirst-Time ConsoleSetting the WX Enable Password for the First Time PasswordWX1200# set enablepass WX1200# save config3WXM Enable Password WX1200# set authentication console * localWX1200# set authentication console * none Configuring AAA for Administrative and Local Access Configuring Configuring AAA for Administrative and Local Access Configuration, all changes are lost Configday. To do this, type the following commandDisplaying the AAA SavingAdministrative AAA ScenariosRadius Administrative AAA Configuration Scenarios Success configuration saved Restrictions apply to user passwords Passwords, and how to display password informationSet user username password encrypted password Configuring PasswordsWX# set user Jose password spRin9 Clear user usernameSet authentication password-restrict enable disable Setting the Maximum Number of Login AttemptsWX# set authentication password-restrict enable Set authentication max-attempts numberPassword Length Configuring Password Expiration Time Clear user username lockout WX# clear user Nin lockoutWX# display aaa Managing Ports ConfiguringVlan Port Type Parameter MAP Access Wired Authentication NetworkMaximum MAPs Supported Per Switch Setting a Port for a Directly Connected MAPConfiguring a MAP Connection Switch Model Valid Range Setting a Port for a Wired Authentication UserWX1200# set port type wired-auth 7 success change accepted Valid dap-num ValuesClearing a Port Name Setting a Port Name Clearing a Distributed MAPRemoving a Port Name Set port media-type port-listrj45 Clear port media-type port-listDisplay port media-type port-list Parameters 10/100 Ports-Autonegotiation and Port SpeedSet port speed port-list10 100 auto Disabling or Reenabling Power over Ethernet Gigabit Ports Autonegotiation and Flow ControlDisabling or Reenabling a Port Resetting a Port To reset a port, use the following commandDisplaying Port Configuration and Status To display port statistics, use the following command Displaying PoE StateDisplaying Port Statistics Counters begin incrementing again, starting from Clearing Statistics CountersMonitoring Port Statistics Clear port countersKey Controls for Monitor Port Counters Display Use the keys listed in to control the monitor displayKey Effect on monitor display WX1200# monitor port countersTo configure a port group, use the following command Configuring a Port GroupGroups can participate in a port group Load SharingWX1200# display vlan config To remove a port group, use the following commandRemoving a Port Group Clear port-group name nameInteroperating with Cisco Systems EtherChannel Displaying Port Group InformationDisplay port-group name group-name WX1200# display port-group name server2Users and VLANs VLANs, IP Subnets, and IP AddressingRoaming and VLANs Vlan NamesTraffic Forwarding 802.1Q TaggingTunnel Affinity To create a VLAN, use the following command Creating a VlanSet vlan vlan-numname name Adding Ports to a Vlan To add a port to a VLAN, use the following commandYou can specify a tag value from 1 through WX1200# set vlan 2 name redTo change the tunneling affinity, use the following command To completely remove Vlan ecru, type the following commandSpecify a value from 1 through 10. The default is Removing an Entire Vlan or a Vlan PortDisplay security l2-restrict vlan vlan-idall WX1200# display vlan config burgundy Display vlan config vlan-idSecurity l2-restrict Clear security l2-restrict counters vlan vlan-idallForwarding DatabasePort associated with the MAC address Displaying Information Displaying the Size of the Forwarding DatabaseDisplaying Forwarding Database Entries Removing Entries from the Forwarding Database Adding an Entry to the Forwarding DatabaseWX1200# display fdb WX1200# clear fdb dynamic success change acceptedChanging the Aging Timeout Period Displaying the Aging Timeout PeriodConfiguration change. Type the following commands Port and VlanScenario WX1200# set port type ap 2-4 model ap2750 poe enable Port statusWX1200# display port poe Set port type wired-auth 5,6 Save the configuration. Type the following commandWX1200# set vlan default port Display Port statusMTU Support Statically Configuring an IP Interface Configuring Managing IP InterfacesTo add an IP interface to a VLAN, use the following command Adding an IP InterfaceConfiguring and Managing IP Interfaces Set interface vlan-idip dhcp-client enable disable WX1200# set interface corpvlan ip dhcp-client enableWX1200# display interface To remove an IP interface, use the following command Disabling or Reenabling an IP InterfaceDisplaying IP Configuring the System IP Address To display the system IP address, use the following commandTo clear the system IP address, use the following command Configuring and Managing IP Routes WX1200# display ip route Display ip route destinationWX1200# display ip route To remove a static route, use the following command Login Timeouts Managing Management ServicesSet ip ssh server enable disable Managing SSHYou can verify the key using the following command For exampleAdding an SSH User Use the following commands to manage SSH server sessions Changing the SSH Service Port NumberThese commands display and clear SSH server sessions Managing SSH Server SessionsSet ip telnet server enable disable Telnet Login TimersEnabling Telnet Adding a Telnet UserResetting the Telnet Service Port Number to Its Default Changing the Telnet Service Port NumberUse the following commands to manage Telnet server sessions Displaying Telnet StatusDisplaying Https Information Managing Https Enabling HttpsSet system idle-timeout seconds Clear system idle-timeoutSessions To specify a Motd banner, use the following command Following command sets the Motd banner on the WXPrompting the User to Acknowledge the Motd Banner To remove a DNS server, use the following command To add a DNS server, use the following commandAdding a DNS Server Removing a DNS ServerTo add the default domain name, use the following command Adding the Default Domain NameRemoving the Default Domain Name Specify a domain name of up to 64 alphanumeric charactersSet ip alias name ip-addr Here is an exampleClear ip alias name Display ip alias nameManaging Time ParametersDaylight savings time or similar summertime period To clear the time zone, use the following command To display the time zone, use the following commandDisplaying the Time Zone Clearing the Time ZoneTo clear the summertime period, use the following command To display the summertime period, use the following commandDisplaying the Summertime Period Clearing the Summertime PeriodSet timedate date mmm dd yyyy time hhmmss Statically Configuring System Time DateWX1200# set timedate date feb 29 2004 time 235800 Display timedateTo remove an NTP server, use the following command NTP client is disabled by defaultResetting the Update Interval to Default To display NTP information, use the following commandDisplaying NTP Information IP address to the ARP table Managing the ARPPermanent entries to the ARP table EntriesSet arp permanent static dynamic ip-addrmac-addr Set arp agingtime secondsWX1200# set arp agingtime Device Pinging AnotherLogging In to a Remote DeviceTracing a Route WX1200# traceroute server1 Time and date parameters IP InterfacesWX1200# set ip dns enable WX1200# Set ip Dns ServerIp dns Sun Feb 29 2004, 235902 PST Configuring and Managing IP Interfaces and Services USM users, with individually configurable access levels „ SNMPv3-SNMPv3 adds authentication and encryption optionsAuthentication options, and encryption options All Snmp versions are disabled by defaultConfiguring Community Strings SNMPv1 SNMPv2c Only To enable an Snmp protocol, use the following commandSet snmp protocol v1 v2c usm all enable disable Set system location string set system contact stringTo clear a USM user, use the following command To create a USM user for SNMPv3, use the following commandClear snmp community name comm-string Clear snmp usm usm-usernameConfiguring Snmp Command Examples To clear a notification profile, use the following command WX1200# set snmp security encrypted success change acceptedClear snmp notify profile profile-name ClientRoamingTraps-Generated when a client roams Configuring Snmp Command Examples Configuring Snmp To clear a notification target, use the following command Security unsecured authenticated encryptedClear snmp notify target target-num Command Examples Following command enables the Snmp service To enable the MSS Snmp service, use the following commandTo display USM settings, use the following command InformationDisplay snmp notify profile To display notification profiles, use the following commandDisplay snmp notify target Display snmp countersMobility Domain Roaming Configuring the System IP Address on Configuring aSet mobility-domain mode seed domain-name mob-domain-name Mobility DomainSet mobility-domain member ip-addr Set mobility-domain mode member seed-ip ip-addrOn the other member switches in the Mobility Domain On the primary seedOn the secondary seed Domain Status display mobility-domain command. For example Displaying Mobility Domain ConfigurationSwitch WX-WX Security VLANs and Tunnels MonitoringA Mobility DomainWX1200# display tunnel WX1200# display roaming vlanUnderstanding Sessions Roaming Users Vlan WX1200 display sessions network verboseMobility-domain WX1200# set mobility-domain member seed-ipVlan-wep 192.168.12.7 192.168.15.5 Domains Network Domain How a user connects to a remote Vlan in a Network Domain Configuring a WX Switch’s affinity for a Network Domain seed Network Domain Set network-domain mode seed domain-name net-domain-nameSet network-domain peer ip-addr Set network-domain mode member seed-ip ip-addraffinity numSet network-domain mode member seed-ip ip-addraffinity num WX4400# display network-domain Clear network-domain mode seed member WX Switch following commandClear network-domain Clear network-domain seed-ip ip-addrConfiguring Network Domains WX1200# display network-domain Upseed Upmember 30.30.30.1 „ Two direct connections to a single WX or two WX switches Through radio signalsMAP Overview Combinations of multiple connectionsExample 3Com Network MAP Overview Distributed MAP Network Requirements Distributed MAPs and STP Distributed MAPs and Dhcp Option No configuration is required on the WXMAP Parameters Resiliency and Dual-Homing Options for MAPs Dual-Homed Direct Connections to a Single WX Dual-Homed Configuration ExamplesDual-Homed Direct and Distributed Connections to WX Switches Network Backbone WX switch How a Distributed MAP Obtains an IP Address through Dhcp Establishing Connectivity on the NetworkStatic IP Address Configuration for Distributed MAPs DNS server replies with the system IP address of a WX switch Configuring MAP Access Points MAP Overview Configuring MAP Access Points MAP Boot Examples MAP Booting over Layer 2 Network MAP Overview MAP sends Dhcp Discover message from the MAP’s port MAP Booting over Layer 3 NetworkMAP sends a unicast Find WX message to WX1 Dual-Homed MAP Booting MAP sends a Dhcp Discover message from the MAP’s port MAP Booting with a Static IP AddressAuth-dot1x Enable Defaults for Service Profile ParametersBeacon Enable Auth-psk DisableCipher-ccmp Disable Cipher-tkip EnableProxy-arp Disable No-broadcast DisableSet radio-profile auth-psk command Soda Disable12.0,24.0 User-idle-timeout 180Web-portal TimeoutWeb-portal-form Web-portal-sessionEach radio can support the following types of SSIDs Public and Private SSIDsMAC Address Allocations on MAPs Model Address AllocationSSIDs Radios AP2750AP7250 AP8250Not configured Defaults for Radio Profile ParametersEncryption Beacon-interval 100Rfid-mode Disable Parameter Default Value Frag-threshold 2346Service-profile Max-rx-lifetime 2000Default Radio Profile RF Auto-TuningLists the defaults for these parameters Radio-Specific ParametersMax-power Parameter Default Value Description AntennatypeMode Disable ANT-5360-OUTTo specify the country, use the following command You specify the country of operationSet system countrycode code Country Codes Country Codes Country Codes CountryCode How an Unconfigured MAP Finds a WX To Configure It WX switch can have one Auto-AP profileConfigured MAPs Have Precedence Over Unconfigured MAPs Example WX1200 MAP Capacities and LoadsWX1200 a WX1200 B WX1200# set ap auto success change accepted Configuring an Auto-AP ProfileConfigurable Profile Parameters for Distributed MAPs WX# set ap auto mode enable success change accepted MAP ParametersRadio Parameters Set ap auto persistent apnumber all WX# display ap status autoMAP configuration persistent across switch restarts Auto-AP profile is not used to configure the MAP. Instead,Configuring a MAP Configure the MAP using the following commandConfiguring Static IP Addresses on Distributed MAPs Success change accepted To clear a MAP, use the following command Clearing a MAP from the ConfigurationChanging MAP Names Changing BiasSet ap apnumber upgrade-firmware enable disable Disabling or Reenabling Automatic Firmware UpgradesForcing a MAP To Download its Operational Image from the WX WX# set ap 1 bias low success change acceptedSet ap apnumber blink enable disable Enabling LED Blink ModeEncryption Options Encryption Key FingerprintVerifying a MAP Fingerprint on a WX Switch MAP Can EstablishWX# display ap status Setting the MAP Security Requirement on a WX Set ap security require optional noneWX# set ap security require Set service-profile name ssid-name ssid-name Creating a Service ProfileFingerprint Log Message An Ssid can be up to 32 alphanumeric characters longChanging a Service Profile Setting Removing a Service ProfileDisabling or Reenabling Encryption for an Ssid Disabling or Reenabling Beaconing of an SsidChanging the Fallthru Authentication Type SSIDs are beaconed by defaultTo change the fallthru method, use the following command Lists the rate settings and their defaults11b-1.0,2.0 Transmit Rates11g-1.0,2.0,5.5,11.0 Beacon-rateTransmit Rates Enforcing the Data RatesWX# set radio-profile rp1 rate-enforcement mode enable WX# set radio-profile rp1 service-profile sp1Disabling Idle-Client Probing Changing the User Idle Timeout Threshold can be a value from 1 through 15. The default isChanging the Short Retry Threshold Changing the Long Retry Threshold Set service-profile name long-retry thresholdTo create a radio profile, use the following command Creating a New ProfileChanging Radio Parameters Set radio-profile name dtim-interval interval To change the Dtim interval, use the following commandSet radio-profile name rts-threshold threshold To change the RTS threshold, use the following commandSet radio-profile name frag-threshold threshold Set radio-profile name max-rx-lifetime timeSet radio-profile name max-tx-lifetime time Resetting a Radio Profile Parameter to its Default Value To remove a radio profile, use the following commandRemoving a Radio Profile Configuring the Channel and Transmit Power Model Type Gain dBi Description Configuring the External Antenna Model and LocationMP-341, MP-352, MP-262 External Antenna Models Specifying the External Antenna ModelMP-620 External Antenna Models Beamwidth Model Type Horizontal VerticalSpecifying the External Antenna Location Set radio-profile name service-profile nameProfiles Assigning a Radio Profile and Enabling RadiosReenabling Radios Disabling orReset ap apnumber To restart a MAP, use the following commandClear ap apnumber radio 1 2 all WX1200# clear ap 3 radioConfiguring MAP Access Points Configuring a Vlan Profile Enabling Local Switching on a MAPSet ap apnumber local-switching mode enable disable Clear ap ap-numberlocal-switching vlan-profile Set ap apnumber local-switching vlan-profile profile-nameApplying a Vlan Profile to a MAP Clearing the Vlan Profile from a MAPTo remove Vlan profile locals, type the following command Removing a Vlan Profile from the WX SwitchClear vlan-profile profile-namevlan vlan-name WX# clear vlan-profile locals vlan redDisplay ap config apnumber radio 1 Displaying MAP Configuration InformationWX1200# display ap config Displaying MAP InformationDisplaying Connection Information for Distributed MAPs Display ap global apnumber serial-id serial-IDWX4400# display ap global Displaying a List Distributed MAPs That Are Not Configured ConnectionInformation for WX# display service-profile sp1 Display service-profile name ?Displaying MAP WX# display radio-profile defaultDisplay radio-profile name ? Display ap status terse apnumber all radio 1Displaying Static IP Following command displays the status of a Distributed MAPWX# display ap counters Display ap counters apnumber radio 1Following command displays ARP entries for AP Displaying Vlan Profile InformationDisplaying the ARP Table for a MAP Displaying Forwarding Database For a MAP Following command displays FDB entries for APDisplay ap acl hits ap-number WX# display ap acl hitsDisplay ap acl map ap-number WX# display ap acl map Configuring RF Load Configuring RF Load Balancing Set load-balancing mode enable disableDisabling or Re-Enabling RF Load Balancing Set band-preference none 11bg 11a Clear ap apnumber radio radio-numload-balancing groupSet load-balancing strictness low med high max Exempting an Ssid From RF Load Balancing Displaying RF Load Balancing InformationRadios in the same load-balancing group as ap2/radio1 WX# display load-balancing group ap 2 radioConfiguring RF Load Balancing for Maps Services Mesh Services Configuring WlanUse the following command to specify the pre-shared key Set ap num boot-configuration mesh mode enable disableSet ap num boot-configuration mesh ssid mesh-ssid Mesh Services following commands Set ap num radio num link-calibration mode enable disable Following illustration Wireless BridgingDisplaying Wlan Rfid Reports Inactive Antenna Link Calibration EnabledWX# display ap status terse Total number of entries AP, m = mesh AP = mesh portalBssid1 000b0efdfdcd, ssid mesh-ssid mesh Then authorized to join a Vlan Encryption settings are configured in the service profile„ WPA2 Robust Security Network 802.11i standardWireless Encryption Defaults Configuration RequiredEncryption Type Client Support Default State MSS Default Encryption Configuring User Encryption WPA Encryption with Tkip Only WPA Encryption with Tkip and WEP Configuring WPA Configuring User Encryption Configuring WPA Encryption Support for WPA and Non-WPA Clients Lists the encryption support for WPA and non-WPA clientsCreating a Service Profile for WPA Enabling WPASpecifying the WPA Cipher Suites Enabling PSK Authentication Changing the Tkip Countermeasures Timer ValueSet service-profile name tkip-mc-time wait-time Set service-profile name auth-psk enable disableSet service-profile name auth-dot1x enable disable Set service-profile name psk-raw hexDisplaying WPA Settings WPA settings appear at the bottom of the outputWX1200# display service-profile sp1 Set radio-profile name service-profile name Set service-profile name rsn-ie enable disable WX1200# set service-profile rsn success change acceptedCcmp RSN settings appear at the bottom of the output Assigning the Service Profile to Radios Enabling the RadiosConfiguring WEP Encryption for Dynamic and Static WEP To set the value of a WEP key, use the following command Traffic, use the following commandsSet service-profile name wep key-index num key value Tkip Encryption Configuration ScenariosEncryption Configuration Scenarios WX1200# set service-profile wpa-wep success change accepted 305 Clients WX1200# display aaa Default Values WX1200# display service-profile sp1 Save the configuration. Type the following command Configuring User Encryption Power setting if needed RF Auto-Tuning can perform the following tasksDisabled for power configuration RF Auto-TuningHow Channels Are Selected Channel Tuning Power TuningDefaults for RF Auto-Tuning Parameters Tuning the Transmit Data RateDefaults for RF Auto-Tuning Parameters RF Auto-Tuning SettingsChanging Enabling Power Tuning Changing the Channel Tuning IntervalChanging the Channel Holddown Interval Set radio-profile name auto-tune channel-interval secondsChanging the Power Tuning Interval Tuned SettingsChanging the Maximum Default Power Allowed On a Radio Channel or set ap dap radio tx-power command for each radioDisplaying Displaying RF Auto-Tuning SettingsRadios in radio profile rp2 Values of RF attributesWX# display ap config WX# display ap config 2 radioCommands Display auto-tune Neighbors ap 2 radioWX1200# display auto-tune attributes ap 2 radio Configuring RF AUTO-TUNING Aeroscout Listeners Configuring MAP Radios to Listen for AeroScout Rfid Tags Status Using an AeroScout EngineSelect Locate AeroScout Tag Optimized forwarding of wireless traffic for time-sensitive MSS and how to configure and manage themAbout QoS QoS ParametersSet service-profile cac-mode QoS Parameters Set service-profile proxy-arp QoS Feature Description Configuration CommandKeepalives and timeouts for clients set service-profile Set service-profile idle-client-probingOn page 332 shows how WX switches classify ingress traffic QoS on WX Switches-Classification of Ingress Packets QoS on WX Switches-Marking of Egress Packets Configuring Quality of Service WMM QoS Mode Service Forwarding Type WMM QoS on the WX SwitchWMM Priority Mappings IP ToSCoS MAP Forwarding Queue Default CoS-to-MAP-Forwarding-Queue MappingsWMM QoS in a 3Com Network MAP B receives the packet and does the following To configure CAC, see Configuring Call Admission Control on SVP QoS ModeWMM QoS Mode Changing QoS Settings Set radio-profile name wmm-powersave enable disableSet radio-profile name qos-mode svp wmm Set service-profile name cac-session max-sessions Set service-profile name cac-mode none sessionEnabling CAC Changing the Maximum Number of Active SessionsUsing the Client’s Dscp Value to Classify QoS Level To change CoS mappings, use the following commandsSet service-profile name use-client-dscp enable disable Changing CoS MappingsProfile’s QoS Settings following command Displaying QoS InformationWX1200# display radio-profile rp1 This example, the QoS mode is WMM Displaying a ServiceQoS Mode Wmm Display service-profile name cac session Displaying the Default CoS MappingsWX# display service-profile sp1 cac session WX1200# display qos defaultDisplaying a CoS-to-DSCP Mapping Displaying a DSCP-to-CoS MappingDisplay qos dscp-to-cos-map dscp-value Display qos cos-to-dscp-map cos-valueWX1200# display qos dscp-table Displaying MAP Forwarding Queue StatisticsDisplay ap qos-stats apnumber clear WX# display ap qos-statsConfiguring Quality of Service Tree protocol PVST+ Loop in the topology and blocks one or more redundant pathsAll network ports as untagged members of the same Vlan Separate instance of PVST+ on each tagged VlanEnabling Spanning TreeProtocol Port Speed Link Type Default Port Path Cost Snmp Port Path Cost DefaultsPort Priority Set spantree priority value all vlan vlan-idChanging the STP Port Cost Resetting the STP Port Cost to the Default ValueWX1200# clear spantree portcost 3-4 success change accepted Changing the STP Port PriorityResetting the STP Port Priority to the Default Value Changing the STP Forwarding Delay To change the hello interval, use the following commandTo change the forwarding delay, use the following command Changing the STP Hello IntervalManaging STP Fast FeaturesConvergence Changing the STP Maximum AgeSet spantree portfast port port-listenable disable This example, backbone fast convergence is enabled Configuring Backbone Fast ConvergenceDisplaying Port Fast Convergence Information Displaying Backbone Fast Convergence StateDisplaying Spanning Tree Information Fast ConvergenceDisplaying Uplink Fast Convergence Information Displaying the STP Port Cost on a Vlan Basis Active optionWX1200# display spantree vlan mauve Display spantree portvlancost port-listDisplay spantree blockedports vlan vlan-id WX1200# display spantree blockedports Vlan defaultDisplay spantree statistics port-listvlan vlan-id WX1200# display spantree statisticsInactive Clearing STP Statistics Enables STP on the Vlan to prevent loopsCounters again Clear spantree statistics port-listvlan vlan-idWX1200# set vlan 10 name backbone port Set port enable Configuring and Managing Spanning Tree Protocol Feature on an individual Vlan basis Traffic. Igmp snooping is enabled by defaultDisabling or Reenabling Igmp Snooping IP address, the group addressReenabling Proxy Changing Igmp TimersReporting Pseudo-QuerierYou can specify a value from 2 through 255. The default is Changing Other-Querier Present IntervalChanging the Last Member Query Interval Set igmp mrsol mrsi seconds vlan vlan-id Set igmp mrsol enable disable vlan vlan-idDisplaying Multicast Information Displaying Multicast Configuration Information StatisticsClearing Multicast Statistics Displaying Multicast Statistics OnlyDisplay igmp statistics vlan vlan-id Clear igmp statistics vlan vlan-idDisplay igmp querier vlan orange Display igmp querier vlan vlan-idDisplay igmp mrouter vlan vlan-id WX1200# display igmp Mrouter vlan orangeIgmp receiver-table group 237.255.255.0/24 ACL Commands Access Control ListsAbout Security Overview of SecuritySetting Security ACLs Traffic Direction „ VlanCommitting a CreatingSecurity ACL ACLSet security acl ip acl-namepermit cos cos deny WX1200# set security acl ip acl-1 permit 192.168.1.4Wildcard Masks Class of ServiceCommon IP Protocol Numbers Number ProtocolClass-of-Service CoS Packet Handling Icmp Message Type Number Icmp Message Code Number Common Icmp Message Types and CodesFollowing command filters TCP packets Setting a TCP ACLFollowing command filters UDP packets Setting a UDP ACLCommit acl-99, type the following command WX1200# commit security acl acl-99 success change acceptedWX1200# commit security acl all success change accepted Viewing the Edit Buffer Viewing Committed Security ACLsViewing Security ACL Details WX1200# display security acl hits Displaying Security ACL HitsACLs Mapping SecurityWX1200# commit security acl acl-222 success change accepted To map a security ACL to a user session, follow these stepsWX1200# display security acl map Acl-999 Displaying ACL Maps to Ports, VLANs, and Virtual PortsWX1200# display security acl map acljoe Clearing a Security ACL MapModifying a Security ACL Modifying a Security ACL To view the results, type the following command WX1200# display security acl infoSet security acl ip acl-111 hits #4 ACL edit-buffer table WX1200# rollback security acl acl-111 Change CoS Using ACLs toFiltering Based on Dscp ValuesUsing the precedence and tos Options Using the dscp OptionPrioritization for Following commands perform the same CoS reassignment asLegacy Voice over Are forwarded to any 10.10.90.x address on Distributed MAPConfiguring and Managing Security Acls Service VoIPWX4400# set security acl ip voip permit any Commit the ACL to the configuration Known LimitationsWX4400# commit security acl voip Configuring a Service Profile for WPA Configuring a Service Profile for RSN WPA2Configuring a Radio Profile Configuring an ACL to Prioritize Voice Traffic Configuring a Vlan for Voice ClientsConfiguring and Managing Security Acls Client-To-Client RestrictingForwarding Among IP-Only ClientsWX1200# set security acl ip c2c permit 0.0.0.0 Address, and how to map the ACL to a port and a userWX1200# commit security acl c2c WX1200# set security acl map c2c vlan vlan-1 OutTo save your configuration, type the following command Configuring and Managing Security Acls Certificates Managing Keys and Certificates About Keys and Certificates Managing Keys and Certificates Generate request command. Copy Generate key commandPkcs Object Files Supported by 3Com File Type Standard PurposeCertificates AutomaticallyGenerated by MSS Creating Keys and Certificates For Your Network more complex to use Procedures for Creating and Validating CertificatesFile Type Steps Required Instructions Self-signed Certificate# crypto generate key admin 1024 admin key pair generated Crypto generate key admin domain eap ssh web 128 512 1024# crypto generate self-signed admin Country Name US Crypto generate self-signed admin eap webFilename is the location of the file on the WX switch To enter the one-time password, use the following commandCrypto otp admin eap web one-time-password Crypto pkcs12 admin eap web filenameCrypto generate request admin eap web # crypto generate request admin Country Name USCrypto certificate admin eap web PEM-formatted END Certificate # crypto ca-certificate admin Enter PEM-encoded certificateDisplaying Certificate and Key Information # display crypto certificate admin CertificateKey and Certificate For SSH configuration information, see Managing SSH onObject files Generate self-signed certificatesDisplay certificate information for verification WX1200# display crypto certificate adminWX1200# crypto generate self-signed web WX1200# display crypto certificate eapWX1200# display crypto certificate web Pkcs12 admin 2048admn.p12 WX1200# crypto otp admin SeC%#6@o%cWX1200# crypto otp eap SeC%#6@o%d WX1200# crypto otp web SeC%#6@o%eCSR and a Pkcs #7 Object File WX1200# crypto generate request adminWX1200# crypto certificate admin WX1200# crypto ca-certificate adminWX1200# display crypto ca-certificate admin About AAA for Network Users AuthenticationMSS provides the following types of authentication Authentication Types„ Web „ Last-resort „ None Authentication AlgorithmAuthentication Flowchart for Network Users Ssid Name Any Last-Resort ProcessingUser Credential Requirements Configuring AAA for Network Users About AAA for Network Users Configuring AAA for Network Users Network Users AAA Tools forWildcard Any for Ssid Matching Local Override Exception AAA Rollover ProcessRemote Authentication with Local Backup Shows the results of this combination of methods EAP Type Description Use EAP Authentication Protocols for Local ProcessingApproach Description Three Basic WX Approaches to EAP AuthenticationEncryption Available to Various Authentication Methods Effects Authentication Type On Encryption MethodAuthentication Last-Resort WebAAA EapConfiguring 802.1X Authentication Success change accepted Configuring 802.1X Authentication Authentication Rule Requirements Bonded Auth Period To set the Bonded Auth period, use the following commandSet dot1x bonded-period seconds Clear dot1x bonded-periodDisplaying Bonded Auth Configuration Information Bonded Auth Configuration ExampleDisplay dot1x config WX1200# set dot1x bonded-period 60 success change acceptedWX1200# display dot1x config Authentication Authorization byMAC Address Clear mac-user mac-addrgroup Clearing MAC Users and GroupsClear mac-user mac-address WX1200# clear mac-user 010f03040506 success change acceptedFor example, to add the MAC user 000102030405 to Vlan red For a complete list of authorization attributes, see onSet radius server server-nameauthor-password password How WebAAA Portal Works Display of the Login WebAAA WX Switch RequirementsConfiguring Web Portal WebAAA Configuring AAA for Network Users Portal ACL and User ACLs „ Configure the NIC to use Dhcp to obtain its IP address WX Switch RecommendationsNetwork Requirements Client NIC RequirementsConfiguring Web To configure Web Portal WebAAA Web Portal WebAAA Configuration ExamplePortal WebAAA Configure individual WebAAA users Display the service profile to verify the changesWX1200# display config Display the configurationDisplaying Session Information for Web Portal WebAAA Users Display sessions network user user-globWX4400# display sessions network ssid mycorp Configuring Web Portal WebAAA Copying and Modifying the Web Login „ If the switch nonvolatile storage has a page in web namedMap a radio to the temporary radio profile and enable it Custom Login Page ScenarioSave the modified Change the logoChange the warning statement if desired Change the greetingURLs variables you can include in a redirect URL Variables for Redirect URLsValues for Literal Characters Display security acl info acl-nameall editbuffer Add the last rule contained in portalaclSet service-profile name web-portal-acl aclname PeriodCommit security acl Set service-profile name web-portal-session-timeout seconds Last-Resort Access WX1200# display service-profile last-resort-srvcprof 481 Process for Users of a Third-Party AP Configuring AAA for Users of Third-Party APsRequirements Third-Party AP Requirements Radius Server Requirements Set authentication mac wired mac-addr-glob method1 Set authentication proxy ssid ssid-nameuser-globSet radius proxy port port-listtag tag-valuessid WX4400# set authentication proxy ssid mycorp ** srvrgrp1 WX4400# set authentication mac wired aabbcc010101 srvrgrp1Authorization AssigningAttributes Authentication Attributes for Local Users Attribute Description Valid Values End-date Idle-timeoutStart-date,end-date, or both Filter-idAttribute Description Valid Values Service-type Session-timeoutSsid Time-of-day Attribute Description Valid Values Start-dateOr group in the local WX database and specify its value Attribute Description Valid Values UrlVlan-name Set service-profile name attr attribute-name value Assigning a Security ACL Locally Commands for Assigning a Security ACL LocallyAssigning a Security ACL on a Radius Server Encryption-Type Encryption Algorithm Value Assigned Assigning and Clearing Encryption Types LocallyEncryption Type Values and Associated Algorithms Assigning and Clearing Encryption Types on a Radius ServerVlan Assignment After Roaming from One WX to Another After RoamingLocation Policy Vlan Assigned ByOverriding or Configuring AAA for Network Users Set location policy deny if Set location policy permitWX1200# set location policy deny if user eq *.theirfirm.com Displaying and Positioning Location Policy Rules Applying Security ACLs in a Location Policy RuleClearing Location Policy Rules Disabling To delete a location policy rule, use the following commandWX1200 display location policy Clear location policy rule-numberAccounting for Wireless NetworkUsers Network resource usageUser roamed to WX1200-0017 User started on WX1200-0013WX1200# display accounting statistics WX1200-0013#display accounting statisticsUser terminated the session on WX1200-0017 WX1200# display aaa Configuration Order ProblemsWX switch and how to avoid them Avoiding AAAConfiguration for a Correct Processing Order Configuration Producing an Incorrect Processing OrderAccessing any MAP access ports, Distributed MAPs, or wired Name and identifying the accessible port or portsMobility Profile All of the ports or Distributed MAPsTo remove a Mobility Profile, type the following command WX1200# display mobility-profile Mobility ProfilesClear mobility-profile name Network User NamePorts ========================= Tulip WX1200# set user Natasha password moon Save the configurationWX1200# set radius server r1 address 10.1.1.1 key sunny WX1200# set server group sg1 members r1WX1200 save config WX1200# set user Natasha attr session-timeoutWX1200# set user Natasha attr vlan-name red WX1200# set radius server r1 address 10.1.1.1 key starrySave the configuration WX1200# display location policy Redirect bldga-prof-VLAN users to the Vlan bldgb-engConfiguring AAA for Network Users With Radius Wireless Client, MAP, WX Switch, and Radius Servers Before You Begin „ Timeout WX wait for a server response 5 secondsRadius Servers „ Transmission attemptsClear radius deadtime key retransmit timeout WX switch uses to authenticate itself to the Radius serverWX1200# clear radius deadtime success change accepted Configuring Individual Radius ServersWX1200# set radius client system-ip success change accepted Set radius server server-nameaddress ip-address key stringRadius Server Radius servers, type the following command Ordering Server GroupsSet server group group-namemembers server-name1 To configure load balancing, use the following command Configuring Load BalancingEnable load balancing by typing the following command Set server group group-nameload-balance enableAdding Members to a Server Group To remove a server group, type the following commandSet server group group-namemembers Clear server group group-nameConfigure Radius servers. Type the following commands Radius and ServerGroup Display the configuration. Type the following command Configuring Communication with Radius Managing On WiredPorts EnablingWX1200# clear dot1x port-control success change accepted Set dot1x port-control Forceauth forceunauth auto port-listConfiguring Key Transmission Time Intervals AuthenticationSet dot1x key-tx enable disable Set dot1x tx-period secondsWX1200# clear dot1x tx-period success change accepted Setting EAP RetransmissionAttempts Setting the Maximum Number Reauthentication Attempts Enabling Disabling ReauthenticationSet dot1x reauth enable disable Set dot1x reauth-max number-of-attemptsWX1200# clear dot1x reauth-max success change accepted Setting Reauthentication PeriodSet dot1x reauth-period seconds WX1200# set dot1x reauth-periodSet dot1x quiet-period seconds Clear dot1x max-reqType the following command to reset the timeout period Setting Timeout for an Authorization ServerSet dot1x timeout auth-server seconds Set dot1x timeout supplicant secondsConfiguration Display dot1x clients stats configWX1200# display dot1x clients WX1200# display dot1x stats Managing 802.1X on the WX Switch Endpoint Security About SodaSoda Endpoint Security Support on WX Switches About Soda Endpoint Security Functionality tasks Configuring Soda Functionality Https//hostname/soda/ssid/xxx.html Install soda agent agent-fileagent-directory directory WX1200# install soda agent soda.ZIP agent-directory sp1WX1200# copy tftp//172.21.12.247/soda.ZIP soda.ZIP Enabling Soda Functionality for the Service Profile Set service-profile name soda mode enable disableSet service-profile name enforce-checks enable disable Set service-profile name soda success-page Clear service-profile name soda success-pageSet service-profile name soda failure-page Clear service-profile name soda failure-page Set service-profile name soda remediation-acl acl-nameClear service-profile name soda remediation-acl Set service-profile name soda logout-page Clear service-profile name soda logout-pageSet ip https server enable Set service-profile name soda agent-directory directory Uninstalling the Soda Agent Files from the WX SwitchClear service-profile name soda agent-directory Uninstall soda agent agent-directory directoryWX1200# uninstall soda agent agent-directory sp1 Configuring Soda Endpoint Security for a WX Switch Displaying Clearing Administrative Sessions Display sessions admin console telnet clientClear sessions admin console telnet client session-id Displaying Clearing an Administrative Console Session Displaying Clearing All Administrative SessionsWX1200 display sessions admin WX1200# clear sessions adminDisplaying Clearing Administrative Telnet Sessions Displaying Clearing Client Telnet SessionsWX1200 display sessions telnet Displaying Clearing Network Sessions Display sessions networkWX1200# display sessions network Network Session to get more in-depth information WX1200# display sessions network user E Displaying Clearing Network Sessions by UsernameClear sessions network user user-glob WX1200# clear sessions network user BobFor example, to clear all sessions for MAC address Address set of MAC addresses, type the following commandClear sessions network vlan vlan-glob WX1200# clear sessions network vlan redWX1200 display session network session-id Session Timers Session-id commandChanging Network To disable the user idle timeout, use the following command Changing or Disabling the User Idle TimeoutRF Detection About RoguesRogue Classification Rogue Detection Lists Rogue Detection Algorithm Dynamic Frequency Selection DFS Rogue Detection and Countermeasures Detection Features Summary of Rogue lists the rogue detection features in MSSRogue Detection Features Countermeasures Clear rfdetect vendor-list client ap mac-addrall Set rfdetect vendor-list client ap mac-addrSet rfdetect ssid-list ssid-name WX1200# display rfdetect ssid-list Total number of entriesClear rfdetect ssid-list ssid-name Following example shows the client black list on WX switch To display the client black list, use the following commandSet rfdetect black-list mac-addr Rfdetect Black-listFollowing example shows the attack list on a switch To display the attack list, use the following commandSet rfdetect attack-list mac-addr Rfdetect Attack-listMac-addris the Bssid of the device you want to ignore To display the ignore list, use the following commandSet rfdetect ignore mac-addr Clear rfdetect ignore mac-addrCountermeasures Enabling Countermeasures Scan Reenabling ActiveEnabling MAP SignaturesSet rfdetect signature key encrypted keyvalue Creating an Encrypted RF Fingerprint Key as MAP SignatureWXR100desk# set rfdetect ? WXR100desk# set rfdetect signature ?Rogues Reenabling LoggingEnabling Rogue NotificationsIDS and DoS Alerts Rogue Detection and Countermeasures Examples IDS and DoS Log MessagesMessage Type Example Log Message Client aabbccddeeff is sending rsvd mgmt frame D IDS and DoS Log Messages Rogue Detection Display Commands You can use the CLI commands listed in to display rogueDisplaying RF DetectionRogue Detection Display Commands WX# display rfdetect clients Display rfdetect clients mac mac-addrDetection Counters command Display rfdetect countersWX1200# display rfdetect counters Displaying Ssid or Bssid Information for a Mobility Domain Display rfdetect mobility-domain ssid ssid-namebssidWX1200# display rfdetect mobility-domain Displaying RF Detection Information Display rfdetect data Displaying the APs Detected by MAP RadioWX1200# display rfdetect data WX1200# display rfdetect visible ap RadioDisplaying Countermeasures Information Display rfdetect countermeasuresWX# display rfdetect countermeasures Rogue Detection and Countermeasures About System Files Displaying SoftwareVersion Information To also display MAP information, type the following command WX# display versionWX# display version details Boot To display boot information, type the following commandWorking with Files WX1200# dir file Following command displays the files in the old subdirectoryWX1200# dir boot0 URL can be one of the followingWX1200# dir core WX1200# copy floor2wx tftp//10.1.1.1/floor2wx „ boot0/filename „ boot1/filenameMd5 boot0 boot1filename WX1200# copy tftp//10.1.1.107/wxb04102.rel boot1wxb04102.relTo delete a file, use the following command WX1200# md5 boot0wxb04102.relDelete url To remove subdirectory corp2, type the following example WX1200# mkdir corp2 success change accepted. WX1200# dirWX1200# rmdir corp2 success change accepted Running Configuration FilesSave config filename WX1200# display config area vlanSet boot configuration-file filename WX1200# save config newconfigLoad config url WX1200# load config newconfigWX1200# clear boot backup-config Set boot backup-configuration filenameBackup boot configuration Backup.cfg Clear boot configSystem Managing System Files WX1200# backup system tftp/10.10.20.9/sysabak critical Upgrade Switch forUpgrading System ImageReset system force Upgrading an Individual Switch Using the CLIWX1200# backup system tftp//172.16.0.10/sysabak Upgrade ScenarioWX1200# copy tftp//172.16.0.10/WX040101.20 boot1WX040100.20 WX1200# reset systemTroubleshooting a WX Setup Problems and Remedies Type the save config WX Setup Problems and RemediesEnable Password RecoveringSystem When Is LostLog Message System LogComponents LevelsEvent Severity Levels System Log Destinations and DefaultsDisplay log buffer trace Clear log buffer traceClear log server ip-addr WX1200# display log buffer severity error Logging to the Log BufferSet log buffer severity severity-level To clear the buffer, type the following command To disable console logging, type the following commandLogging to the Console Set log sessions severity severity-levelenable Setting Telnet Session DefaultsLogging Messages to a Syslog Server For information on severity levels, see onChanging the Current Telnet Session Defaults To disable session logging, use the following commandTo disable trace logging, use the following command Logging to the Trace BufferSaving Trace Messages in a File Displaying the Log ConfigurationCommand Using the TraceTracing Authentication Activity Tracing Session Manager ActivityTracing 802.1X Sessions Tracing Authorization ActivityWX1200# display trace Clear trace all trace areaWX1200# display log trace severity error WX1200# set trace ? WX1200# display log trace facilityCommands Using displayFor more information about Vlan interfaces, see Configuring InterfacesDatabase FDB information, type the following command Port Mirroring Configuring PortRequirements MirroringMonitoring Traffic RemotelyMonitoring Remote TrafficWX1200# set snoop snoop1 observer 10.10.30.2 snap-length To delete a snoop filter, use the following command Displaying Configured Snoop FiltersEditing a Snoop Filter Deleting a Snoop FilterDisplaying the Snoop Filters Mapped to a Radio Following command shows the mapping for snoop filter snoop1Displaying the Snoop Filter Mappings for All Radios Removing Snoop Filter MappingsFollowing command enables snoop filter snoop1 Filter operates until you manually disable itFollowing command shows statistics for snoop filter snoop1 Preparing an Observer Capturing TrafficSet snoop filter-nameall mode enable disable Capturing System Sending it toTechnical Support Corenetsys.core.217.tar Corenetsys.core.217.tar Support System Requirements WEB ViewLogging Into Web View On page 652. Also supported are 3Com vendor-specific 3Com Mobility System Software MSS supports the standardAttributes VSAs, listed in on StatedSupported Standard Extended Attributes Rcv Sent Access Acct Attribute Type Resp? Reqst? DescriptionSupported Standard and Extended Attributes Filter-id outboundacl.out Filter-id inboundacl.inDisplayed, they must NAS Radius Acct-Output Yes 3Com Vendor-SpecificUsers, on YY/MM/DD-HHMM 3Com VSAsProtocol Port Function Traffic Ports Used by MSSIP/ICMP Dhcp Server Chapter E Dhcp Server Set interface dhcp-server command’s primary-dns Set ip dns server commandDhcp Server Displaying Dhcp Server InformationDisplayed instead Solve Problems Online Service BenefitsRegister Your Product to GainAccess Software WarrantyPurchase Extended ProfessionalCountry Telephone Number US and Canada Telephone Technical Support and Repair Latin America Telephone Technical Support and RepairGlossary 802.11a Radio that can receive and transmit signals at Ieee 802.11bGHz and data rates of up to 54 Mbps 802.11bSee security ACL See ACEAES BSS CBC-MAC BssidCCI CcmpChap CPCCRC CSR Dhcp DESDynamic Host See Dhcp Configuration Protocol EAP-TLS EAPESS EtsiFCC FDB FhssGbic GMK GTKHmac Https HpovIAS ICVIndustry Canada Igmp snoopingInformation element InfrastructureISO ISLLawn LdapMAC MD5 MAPMIC MpduMS-CHAP-V2 MSS MsduMTU NATPEM PeapPIM PkcsPMK PRF PrngPSK PVST+ PTKRC4 RSA RSNRssi SIP SHASSH SsidSTP SSLTLS TLVTtls Vlan NIIVSA Vlan globWatch list Web ViewWEP Wlan WispWPA WPA IEGlossary Glossary Numbers IndexSessions, clearing 557 sessions, displaying Cipher suites, RSN enabling ARP Index Index See also MAC addresses MAC addresses Names Https Radius 717 Repair support, Europe, Middle East, and Africa ConfiguringSeed, Mobility Domain configuring 154 defined STP Index Usernames Invalid certificate Case-sensitive Index Command Index Clear summertime Load config 61 Md5 606 mkdir Monitor port counters Command Index 729 Set radius proxy portCommand Index
Related manuals
Manual 198 pages 38.27 Kb

WX1200 3CRWX120695A, WX4400 3CRWX440095A, WXR100 3CRWXR10095A, WX2200 3CRWX220095A specifications

The 3Com WX2200 (3CRWX220095A), WX4400 (3CRWX440095A), WX1200 (3CRWX120695A), and WXR100 (3CRWXR10095A) are part of a robust suite of wireless networking solutions offered by 3Com, designed to meet the needs of modern enterprise environments. These devices provide reliable connectivity, flexibility, and scalability, making them ideal for businesses of all sizes.

The 3Com WX2200 is a high-performance wireless switch that supports up to 64 access points, making it suitable for medium to large deployments. It boasts advanced features such as dynamic RF management, which optimizes channel selection and power levels based on real-time network conditions. This ensures maximum coverage and minimizes interference, leading to improved user experiences. Additionally, it supports dual-band operation and can seamlessly integrate with various wireless access points, providing enhanced throughput and robust performance.

The WX4400 is designed for high-density environments and offers extensive scalability. It supports up to 128 access points and is equipped with advanced security features, including WPA2 enterprise encryption and role-based access control. This switch also features intelligent load balancing, allowing it to dynamically distribute user traffic across available access points, thus enhancing overall network efficiency.

The WX1200, positioned as an entry-level solution, is well-suited for small to medium-sized businesses. It offers a user-friendly management interface, allowing IT staff to quickly configure and monitor the network. This device supports a variety of deployment scenarios and can be easily integrated into existing infrastructure. It also comes equipped with essential security features to protect the network from unauthorized access.

The WXR100 complements the series by providing simplified management for access points, ensuring that businesses can easily deploy and maintain their wireless networks. It supports various management protocols and integrates with a variety of third-party systems, enhancing inter-operability. With Power over Ethernet (PoE) support, the WXR100 can deliver power to connected access points, reducing the complexity and costs associated with additional power infrastructure.

Together, these solutions embody 3Com's commitment to delivering high-quality networking products that enhance connectivity and performance. With features such as scalability, advanced security, dynamic load balancing, and centralized management, the WX2200, WX4400, WX1200, and WXR100 form a comprehensive wireless networking ecosystem tailored for today’s enterprise challenges.