-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06 1
2015-12-14
INTEROPERABILITY REPORT Ascom i62 Extreme Networks C25 / C2110 /
C2400 / C4110 / C5110 and V2110 AP 36xx / 37xx / 38xx i62 and OEM
derivatives version 5.4.2
Extreme Networks software version 09.15.06
Ascom, July 2015
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06 2
2015-12-14
TABLE OF CONTENT: INTRODUCTION
...........................................................................................................................
3
Ascom solution
.........................................................................................................................
3 Extreme Networks solution
.......................................................................................................
3
SUMMARY
....................................................................................................................................
5 Known issues
............................................................................................................................
6 General conclusion
...................................................................................................................
6 Compatibility information
..........................................................................................................
6
APPENDIX A: TEST CONFIGURATIONS
....................................................................................
7 Extreme Networks V2110 Controller v. 09.15.06
......................................................................
7
Overview
...............................................................................................................................
7 Extreme Networks controller overview.
.................................................................................
7 Security settings (PSK)
.........................................................................................................
8 Security settings (802.1X / PEAP-MSCHAPv2)
..................................................................
10 General settings (SSID, QoS, Radio )
.................................................................................
13
Ascom i62 network settings
....................................................................................................
20 APPENDIX B: DETAILED TEST RECORDS
..............................................................................
23
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06 3
2015-12-14
INTRODUCTION This document describes necessary steps and
guidelines to optimally configure the Extreme Networks Wireless
platform with Ascom i62 VoWiFi handsets.
The guide should be used in conjunction with both Extreme
Networks and Ascom’s configuration guide(s).
Ascom solution
Ascom Wireless Solutions (www.ascom.com/ws) is a leading
provider of on-site wireless communications for key segments such
as hospitals, manufacturing industries, retail and hotels. More
than 75,000 systems are installed at major companies all over the
world. The company offers a broad range of voice and professional
messaging solutions, creating value for customers by supporting and
optimizing their Mission-Critical processes. The solutions are
based on VoWiFi, IP-DECT, DECT, Nurse Call and paging technologies,
smartly integrated into existing enterprise systems. The company
has subsidiaries in 10 countries and 1,200 employees worldwide.
Founded in the 1950s and based in Göteborg, Sweden, Ascom Wireless
Solutions is part of the Ascom Group, listed on the Swiss Stock
Exchange.
Extreme Networks solution Extreme Networks, Inc. (EXTR) is a
software and services-led networking solutions company committed to
solving IT's toughest networking challenges. Extreme Networks is
headquartered in San Jose, CA, with more than 14,000 customers in
over 80 countries. For more information, visit Extreme's website.
Extreme Networks and the Extreme Networks logo are registered
trademarks of Extreme Networks, Inc. in the United States and/or
other countries.
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06 4
2015-12-14
SITE INFORMATION Test Site: Ascom US 300 Perimeter aprk drive
Morrisville, NC, US-27560 USA Participants: Karl-Magnus Olsson,
Ascom Sweden, Gothenburg TEST TOPOLOGY
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06 5
2015-12-14
SUMMARY Please refer to Appendix B for detailed results. WLAN
Controller Features
High Level Functionality Result Association, Open with No
Encryption OK Association, WPA2-PSK / AES Encryption OK
Association, PEAP-MSCHAPv2 Auth, AES Encryption OK Association with
EAP-TLS authentication OK Association, Multiple ESSIDs OK Beacon
Interval and DTIM Period OK PMKSA Caching OK
WPA2-opportunistic/proactive Key Caching OK WMM Prioritization OK
802.11 Power-save mode OK 802.11e U-APSD OK 802.11e U-APSD (load
test) OK Roaming
High Level Functionality Result Roaming, Open with No Encryption
OK (typical roaming time 16ms) * Roaming, WPA2-PSK, AES Encryption
OK (typical roaming time 32ms) *
Roaming, PEAP-MSCHAPv2 Auth, AES Encryption OK (typical roaming
time 33ms)* *) Measured times is with opportunistic key caching
enabled and for 802.11an. For detailed results see Appendix B.
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06 6
2015-12-14
Known issues
No known issues.
For additional information regarding the known issues please
contact [email protected] or [email protected]
General conclusion The verification, including association,
authentication and call stability tests generated in general very
good results. Roaming times were measured in the range of around
35ms when using both WPA2-PSK/AES and PEAP-MSCHAPv2 (WPA2/AES).
Load tests showed that it was possible to maintain 12 simultaneous
calls on one access point (radio) when using the minimum basic rate
set to 12Mbps for both 802.11bgn. The same number of simulations
calls could be maintained also for 802.11an. The majority of the
test cases were performed in B@HWC mode. Several tests were however
verified also in B@AP mode. No difference in functionality or
performance was noticed. Inter controller roaming was verified with
B@AP, B@HWC and Routed topology.
Compatibility information All tests were done on AP3610 AP3715
and AP3825 on a v2110 controller. Due to similar chipsets in other
access points we consider all access points listed below supported.
All Extreme Networks controllers are considered to be covered based
on testing towards V2110. Supported access points with Extreme
Networks version 09.15.06: AP3605, 3610, 3620 AP3630, 3640
(Converted to Fit Mode) AP3705, 3710, 3715, 3765, 3767 AP3801,
3805, 3825, 3865 Supported controller platforms with Extreme
Networks version 09.15.06: C25 V2110 C5110 C5210
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06 7
2015-12-14
APPENDIX A: TEST CONFIGURATIONS
Extreme Networks V2110 Controller v. 09.15.06 In the following
chapter you will find screenshots and explanations of basic
settings in order to get an Extreme Networks wireless system to
operate with an Ascom i62. Please note that security settings were
modified according to requirements in individual test cases.
Overview
Extreme Networks controller overview.
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06 8
2015-12-14
Security settings (PSK)
General SSID settings.
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06 9
2015-12-14
Security profile WPA2-PSK, AES encryption
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06
10 2015-12-14
Security settings (802.1X / PEAP-MSCHAPv2)
Configuration of authentication using external Radius sever,
802.1X (Step 1). In this example is WPA2-AES/CCMP used.
“Opportunistic Keying” is strongly recommended as Key Management
Option in order to allow faster roaming between access points.
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06
11 2015-12-14
Configuration of authentication using external Radius sever
(Step 2). Select the server to use. The server is
created/configured in next step.
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06
12 2015-12-14
Configuration of authentication using external Radius sever
(Step 3). The IP address and the secret must correspond to the IP
and the credential used by the Radius server. Note that depending
on which Authentication method used it might be necessary to add a
certificate into the i62. PEAP-MSCHAPv2 requires a Root certificate
and EAP-TLS requires both a Root certificate and a client
certificate. Server certificate validation can however be
overridden in version 4.1.12 and above per handset setting. Note.
To enable fast inter-controller roaming with opportunistic key
caching, the “pair” option under “Wireless controller ->
availability” has to be enabled. Please consult Extreme Networks
for details.
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06
13 2015-12-14
General settings (SSID, QoS, Radio )
Make sure that WMM. In this example U-APSD is enabled which is
strongly recommended in order to increase battery performance.
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06
14 2015-12-14
Ascom recommended settings for 802.11gn are to use 3 channel
plan (channel 1, 6 and 11). Due to the limited number of
non-overlapping channels using 802.11g/n it is recommended to use
20MHz channel width. Note that Tx Power was adjusted in order to
test roaming.
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06
15 2015-12-14
Radio 2 -> Advanced; Set DTIM period to value 5 and beacon
period to 100ms. These values are recommended in order to allow
maximum battery conservation without impacting the quality. A lower
DTIM value is possible but will impact the standby time negatively.
It is recommended to set the Min Basic Rate to 11Mbps to increase
the performance.
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06
16 2015-12-14
Configuration of 802.11a/n/ac: Refer to general guidelines on
page 18. Note that Tx Power was adjusted in order to test
roaming.
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06
17 2015-12-14
Radio 1 -> Advanced; Set DTIM period to value 5 and beacon
period to 100ms. These values are recommended in order to allow
maximum battery conservation without impacting the quality. A lower
DTIM value is possible but will impact the standby time
negatively.
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06
18 2015-12-14
General guidelines when deploying Ascom i62 handsets in
802.11a/n/ac environments:
1. Enabling more than 8 channels will degrade roaming
performance. Ascom recommends against going above this limit.
2. Using 40 MHz channels (or “channel-bonding”) will reduce the
number of non-DFS* channels to two in ETSI regions (Europe). In FCC
regions (North America), 40MHz is a more viable option because of
the availability of additional non-DFS channels. The handset can
co-exist with 40MHz stations in the same ESS.
3. Ascom do support and can coexist in 80MHz channel bonding
environments. The recommendations is however to avoid 80Mhz channel
bonding as it severely reduces the number of available non
overlapping channels.
4. Make sure that all non-DFS channel are taken before resorting
to DFS channels. The handset can cope in mixed non-DFS and DFS
environments; however, due to “unpredictability” introduced by
radar detection protocols, voice quality may become distorted and
roaming delayed. Hence Ascom recommends if possible avoiding the
use of DFS channels in VoWIFI deployments.
*) Dynamic Frequency Selection (radar detection)
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06
19 2015-12-14
Controller configuration See attached file
(controller_config.cli) for controller configuration.
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06
20 2015-12-14
Ascom i62 network settings
Ascom i62 Network configurations (WPA2-PSK) Note. Refer to
general guidelines on page 18 concerning 802.11a/n channels. It’s
important that the channels in the handset match the channel plan
used in the system Note. FCC is no longer allowing 802.11d to
determine regulatory domain. Devices deployed in USA must set
Regulatory domain to “USA”.
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06
21 2015-12-14
i62 network settings for 802.1X authentication (PEAP-MSCHAPv2)
Note. Refer to general guidelines on page 18 concerning 802.11a/n
channels. It’s important that the channels in the handset match the
channel plan used in the system Note. FCC is no longer allowing
802.11d to determine regulatory domain. Devices deployed in USA
must set Regulatory domain to “USA”.
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06
22 2015-12-14
802.1X Authentication requires a root certificate to be uploaded
to the phone by “right clicking” -> Edit certificates. EAP-TLS
will require both a root and a client certificate. Note that both a
root and a client certificate are needed for TLS. Otherwise only a
root certificate is needed. Server certificate validation can be
overridden in version 4.1.12 and above per handset setting
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06
23 2015-12-14
APPENDIX B: DETAILED TEST RECORDS VoWIFI Pass 17 Fail 0 Comments
0 Untested 2 Total 19 See attached file
(WLANinteroperabilityTestReport_Extreme_networks.xls) for detailed
test results. MISCELLANEOUS Please refer to the test specification
for WLAN systems on Ascom’s interoperability web page for explicit
information regarding each test case. See URL (requires login):
https://www.ascom-ws.com/AscomPartnerWeb/en/startpage/Sales-tools/Interoperability
-
Interoperability Report - Ascom i62 – Extreme Version 09.15.06
24 2015-12-14
Document History Rev Date Author DescriptionPA 2013-10-29 SEKMO
Draft 1PB 2013-10-31 SEKMO Minor changes after review. Draft2 R1
2013-11-11 SEKMO Revision 1 R1a 2014-12-02 SEKMO Added outdoor AP
3765/3767 P2 2015-07-22 SEKMO Updated with Extreme Networks look
and AP38xx R2 2015-08-24 SEKMO Minor corrections. Revision 2. R2a
2015-12-14 SEKMO Added AP3801, 3805 and 3865
WLAN TR
WLAN Interoperability Test ReportWLAN configuration:
Beacon Interval: 100ms
Test object - Handset:DTIM Interval: 5
Ascom i62 v 5.4.2802.11d Regulatory Domain: XX
Test object - WLAN system:WMM Enabled (Auto/WMM)
Extreme Networks V2110, version 09.15.06.0010No Auto-tune
AP 3610, 2715, 3825AP2610AP2715AP2825Single Voice VLAN
2.4Ghz5.0Ghz2.4Ghz5.0Ghz2.4Ghz5.0Ghz
Test
CaseDescriptionVerdictVerdictVerdictVerdictVerdictVerdictComment
TEST AREA ASSOCIATION / AUTHENTICATION
#101Association with open authentication, no
encryptionPASSPASSPASSPASSPASSPASS
#107Association with WPA2-PSK authentication, AES-CCMP
encryptionPASSPASSPASSPASSPASSPASS
#110Association with PEAP-MSCHAPv2 auth, AES-CCMP
encryptionPASSPASSPASSPASSPASSPASSFreeRADIUS; RootCA loaded to
Device.FAIL
TEST AREA POWER-SAVE AND QOSPASS
#150802.11 Power-save modePASSPASSPASSPASSPASSPASSFAIL
#151Beacon period and DTIM intervalPASSPASSPASSPASSPASSPASSDTIM
1,3 5 , Beacon Period 100tu.NOT TESTED
#152802.11e U-APSDPASSPASSPASSPASSPASSPASSSee Comment
#202WMM prioritizationPASSPASSPASSPASSPASSPASSiperf used to
generate load
TEST AREA "PERFORMANCE"
#308Power-save mode U-APSD –
WPA2-PSKPASSPASSPASSPASSPASSPASS12hs ok
TEST AREA ROAMING AND HANDOVER TIMES
#401Handover with open authentication and no
encryptionPASSPASSPASSPASSPASSPASS802.11an: 16ms 802.11gn: 21ms
#404Handover with WPA2-PSK auth and AES-CCMP
encryptionPASSPASSPASSPASSPASSPASS802.11an: 32ms 802.11gn: 35ms
#408Handover with PEAP-MSCHAPv2 authentication and AES-CCMP
encryptionPASSPASSPASSPASSPASSPASS802.11an: 33ms 802.11gn: 38ms
#411Handover using PMKSA and opportunistic/proactive key
cachingPASSPASSPASSPASSPASSPASS
TEST AREA BATTERY LIFETIME
#501Battery lifetime in idlePASSPASSNOT TESTEDNOT
TESTEDPASSPASS
#504Battery lifetime in call with power save mode
U-APSDPASSPASSPASSPASSPASSPASS
TEST AREA STABILITY
#602Duration of call – U-APSD
modePASSPASSPASSPASSPASSPASS24h
TEST AREA 802.11n
#801Frame aggregation A-MSDUNOT TESTEDNOT TESTEDNOT TESTEDNOT
TESTEDNOT TESTEDNOT TESTED
#802Frame aggregation A-MPDUNOT TESTEDNOT TESTEDNOT TESTEDNOT
TESTEDNOT TESTEDNOT TESTEDno downlink frame aggregation noticed.
Uplink OK
#80440Mhz channelsNOT TESTEDPASSNOT TESTEDPASSNOT TESTEDPASS
#805802.11n ratesPASSPASSPASSPASSPASSPASS
## System Configuration# CLI Version 9.15##
## Topologytopology internal-vlanid 4094 mac-key
"00:0C:29:CF:5D:EC" apply end
topology "Admin" apply l3 ip 192.168.10.1/24 gateway none cert
default cert default ipv6 gateway-ipv6 none apply exit exit end
topology create "esa0" physical 1 port esa0 untag
192.168.0.24/24 "esa0" name "esa0" 3rd-party disable l3presence
enable apply l3 ip 192.168.0.24/24 ap-register enable mgmt enable
cert default cert default ipv6 apply dhcp mode none apply exit exit
l2 port esa0 tagged disable vlanid 1 apply exit exit end
topology "Bridged at AP untagged" name "Bridged at AP untagged"
dynamic-egress enable sync-timestamp 1429885530 apply l2 tagged
disable vlanid 4093 arp-proxy disable apply multicast filter
disable apply exit exit exit end
topology create "br@ewc" b@ac 4093 port esa0 tag "br@ewc" mode
b@ac name "br@ewc" l3presence disable dynamic-egress enable apply
l2 port esa0 tagged enable vlanid 4093 apply multicast filter
disable apply exit exit exit end
topology multicast-support "esa0" apply end## VNS Globalvnsmode
das port 3799 replay_interval 300 apply exit adminctr
max-voice-reassoc 80 max-voice-assoc 60 max-video-reassoc 60
max-video-assoc 40 flex-client-access 100%-airtime egress-filtering
wlan auto-login hide radius-accounting enable policy-invalid-action
default hybrid-policy combined apply exit radius strict disable
include-service-type disable delay-client-msg 20 radius-mac-format
1 usage-mode exclusive apply exit radius create "IntopRadius"
192.168.0.2 "" "IntopRadius" auth-port 1812 acct-port 1813
auth-prio 1 acct-prio 1 auth-retries 3 acct-retries 3 auth-timeout
5 acct-timeout 5 interim 30 protocol PAP shared-secret
"840BF4ABD0931E74659206F63A198E40" name "IntopRadius" ip
"192.168.0.2" polling-mechanism actual-user polling-interval 60
apply exit exit nac exit rateprofile create "5M" 5000 snmpid 1 exit
end## CoScos "No CoS" apply exit end
cos create "Scavenger" snmpid -1 -1 0 2 "Scavenger"
tos-dscp-mask none transmit-queue 0 sync-timestamp 1429885541 apply
exit end
cos create "Best Effort" snmpid -1 -1 2 3 "Best Effort"
tos-dscp-mask none transmit-queue 1 sync-timestamp 1429885542 apply
exit end
cos create "Bulk Data" snmpid -1 -1 4 4 "Bulk Data"
tos-dscp-mask none transmit-queue 2 sync-timestamp 1429885543 apply
exit end
cos create "Critical Data" snmpid -1 -1 6 5 "Critical Data"
tos-dscp-mask none transmit-queue 3 sync-timestamp 1429885544 apply
exit end
cos create "Network Control" snmpid -1 -1 8 6 "Network Control"
tos-dscp-mask none transmit-queue 4 sync-timestamp 1429885545 apply
exit end
cos create "Network Management" snmpid -1 -1 10 7 "Network
Management" tos-dscp-mask none transmit-queue 5 sync-timestamp
1429885546 apply exit end
cos create "RTP/Voice/Video" snmpid -1 -1 12 8 "RTP/Voice/Video"
tos-dscp-mask none transmit-queue 6 sync-timestamp 1429885547 apply
exit end
cos create "High Priority" snmpid -1 -1 14 9 "High Priority"
tos-dscp-mask none transmit-queue 7 sync-timestamp 1429885548 apply
exit end
cos create "5M" snmpid 1 1 -1 10 "5M" name "5M" use-wlan-marking
disable priority none tos-dscp-mask none rateprf-in "5M"
rateprf-out "5M" transmit-queue none apply exit end## VNS Default
Policyvnsmode default-role topology-name "Bridged at AP untagged"
sync disable apply apfilters create 1 proto any eth any mac any
0.0.0.0/0 in dst out none allow priority none tos-dscp none create
2 proto any eth any mac any 0.0.0.0/0 in none out src allow
priority none tos-dscp none apply exit acfilters create 1 proto any
eth any mac any 0.0.0.0/0 in dst out none allow priority none
tos-dscp none cos none create 2 proto any eth any mac any 0.0.0.0/0
in none out src allow priority none tos-dscp none cos none apply
exit exit end## L2portsl2ports esa0 port enable apply exit esa1
port enable apply exit end## Host Attributeshost-attributes
hostname EWC domain extremenetworks.com apply # DNS Servers dns no
dns 1 no dns 1 no dns 1 apply exit end## OSPFip ospf area 0.0.0.0
areatype default status disable apply ospfinterface exit exit end##
Static Routesip route default 192.168.0.50 nofloat apply end## Port
speed
## lbslbs service disable apply end## Network Timetime ntp 2
ntpip 1 192.168.0.12 tz import America/Kentucky/Monticello apply
end## System Logsyslog no svcmsg no audmsg stationevents disable
facility application 0 end## Web Settingsweb timeout 1:00 no
showvns guestportal-admin-timeout 1:00 apply end## Secure
Connectionssecureconnection weak-ciphers enable apply end## FTP
Serversftp_server BU_RESTORE 192.168.0.176 anonymous
2E84B8B6E517E9188F9044827FAF7735 \/
EWC.27052015.031251.zipftp_server UPGRADE 172.20.106.236 anonymous
2E84B8B6E517E9188F9044827FAF7735 \/ AC-MV-09.15.06.0010-1.bge
## Mobilitymobility mrole none apply end## SNMPsnmp enable none
rcommunity public rwcommunity private context severity 1 port 162
publish-ap enable engine-id controller_000C29CF5DEC apply end##
Scheduled Backupschedule_backup protocol ftp type all freq never
destination local apply end## Management Userslogin end## User
Interfaceno runinstallwizard
## Session Availabilityavailability no pair apply end##
Mitigatormitigator no analysis apply end## APap defaults std no
telnet poll_timeout 15 client_session no persistent no
bcast_disassoc country United States no lldp led-mode normal
lbs-status enable balanced-power enable apply radio1 mode a dtim 5
beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain
tx_max_power 18 divtx alternate divrx best hwretries 00000
max-distance 100 no atpc minbrate 6 maxbrate 24 maxoprate 54
admin-mode off optimized-mcast disable mcast-adaptable disable
mcast2ucast disabled dcs mode off channel_plan all-non-dfs exit
apply exit radio2 mode bg dtim 5 beaconp 100 nonUnicastQuota 100
rts 2346 frag 2346 domain MyDomain tx_max_power 18 divtx alternate
divrx best hwretries 00000 max-distance 100 no atpc minbrate 1
maxbrate 11 maxoprate 54 pmode auto prate 11 preamble long ptype
cts only admin-mode on optimized-mcast disable mcast-adaptable
disable mcast2ucast disabled dcs mode off channel_plan auto exit
apply exit exit 11n ssh enable poll_timeout 15 client_session no
persistent no bcast_disassoc country United States no lldp led-mode
normal lbs-status enable secure-tunnel disable ipmcast-assembly
disable balanced-power enable apply radio1 mode an dtim 5 beaconp
100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain
tx_max_power 18 antsel left-middle-right n_chlwidth 40
n_guardinterval short max-distance 100 no atpc minbrate 6 n_pmode
none n_ptype cts only n_pbthreshold 50 no n_aggr_msdu n_aggr_mpdu
n_aggr_mpdu_max 65535 n_aggr_mpdu_max_subframes 64 n_addba_support
admin-mode off optimized-mcast disable mcast-adaptable disable
mcast2ucast disabled dcs mode off channel_plan all-non-dfs exit
apply exit radio2 mode bg dtim 5 beaconp 100 nonUnicastQuota 100
rts 2346 frag 2346 domain MyDomain tx_max_power 18 antsel
left-middle-right max-distance 100 no atpc minbrate 1 pmode auto
prate 11 preamble long ptype cts only admin-mode on optimized-mcast
disable mcast-adaptable disable mcast2ucast disabled dcs mode off
channel_plan auto exit apply exit exit dualband no telnet
poll_timeout 15 client_session no persistent no bcast_disassoc
country United States no lldp led-mode normal lbs-status enable
balanced-power enable apply radio1 mode a dtim 5 beaconp 100
nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power
18 divtx alternate divrx best hwretries 00000 max-distance 100 no
atpc minbrate 6 maxbrate 24 maxoprate 54 preamble long admin-mode
off optimized-mcast disable mcast-adaptable disable mcast2ucast
disabled dcs mode off channel_plan all-non-dfs exit apply exit
radio2 mode bg dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag
2346 domain MyDomain tx_max_power 18 divtx alternate divrx best
hwretries 00000 max-distance 100 no atpc minbrate 1 maxbrate 11
maxoprate 54 pmode auto prate 11 preamble long ptype cts only
admin-mode on optimized-mcast disable mcast-adaptable disable
mcast2ucast disabled dcs mode off channel_plan auto exit apply exit
exit 4102 no telnet poll_timeout 15 client_session no persistent no
bcast_disassoc country United States no lldp led-mode normal
lbs-status enable mic-error enable balanced-power enable apply
radio1 mode a dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag
2346 domain MyDomain tx_max_power 18 divtx alternate divrx best
hwretries 00000 max-distance 100 no atpc minbrate 6 maxbrate 24
maxoprate 54 admin-mode off optimized-mcast disable mcast-adaptable
disable mcast2ucast disabled dcs mode off channel_plan all-non-dfs
exit apply exit radio2 mode bg dtim 5 beaconp 100 nonUnicastQuota
100 rts 2346 frag 2346 domain MyDomain tx_max_power 18 divtx
alternate divrx best hwretries 00000 max-distance 100 no atpc
minbrate 1 maxbrate 11 maxoprate 54 pmode auto prate 11 preamble
long ptype cts only admin-mode on optimized-mcast disable
mcast-adaptable disable mcast2ucast disabled dcs mode off
channel_plan auto exit apply exit exit ap37xx ssh enable
poll_timeout 15 client_session no persistent no bcast_disassoc
country United States no lldp led-mode normal lbs-status enable
secure-tunnel disable ipmcast-assembly disable balanced-power
enable apply radio1 mode an dtim 5 beaconp 100 nonUnicastQuota 100
rts 2346 frag 2346 domain MyDomain tx_max_power 18 antsel
left-middle-right n_chlwidth 40 n_guardinterval short max-distance
100 no atpc minbrate 6 n_pmode none n_ptype cts only n_pbthreshold
50 no n_aggr_msdu n_aggr_mpdu n_aggr_mpdu_max 65535
n_aggr_mpdu_max_subframes 64 n_addba_support admin-mode off ldpc
disable stbc disable txbf disable optimized-mcast disable
mcast-adaptable disable mcast2ucast disabled dcs mode off
channel_plan all-non-dfs exit apply exit radio2 mode bg dtim 5
beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain
tx_max_power 18 antsel left-middle-right max-distance 100 no atpc
minbrate 1 pmode auto prate 11 preamble long ptype cts only
admin-mode on optimized-mcast disable mcast-adaptable disable
mcast2ucast disabled dcs mode off channel_plan auto exit apply exit
exit ap38xx ssh enable poll_timeout 15 client_session no persistent
no bcast_disassoc country United States no lldp led-mode normal
lbs-status enable secure-tunnel disable ipmcast-assembly disable
balanced-power enable apply radio1 mode anac dtim 5 beaconp 100
nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power
18 antsel left-middle-right n_chlwidth 80 n_guardinterval long no
atpc minbrate 6 n_pmode none n_ptype cts only n_pbthreshold 50 no
n_aggr_msdu no n_aggr_mpdu n_aggr_mpdu_max 1048575
n_aggr_mpdu_max_subframes 64 no n_addba_support admin-mode off ldpc
disable stbc disable optimized-mcast disable mcast-adaptable
disable mcast2ucast disabled dcs mode off channel_plan all-non-dfs
exit apply exit radio2 mode bgn dtim 5 beaconp 100 nonUnicastQuota
100 rts 2346 frag 2346 domain MyDomain tx_max_power 18 antsel
left-middle-right n_chlwidth auto n_guardinterval long max-distance
100 no atpc minbrate 1 pmode auto prate 11 preamble long ptype cts
only n_pmode none n_ptype cts only n_pbthreshold 50 no n_aggr_msdu
no n_aggr_mpdu n_aggr_mpdu_max 65535 n_aggr_mpdu_max_subframes 64
no n_addba_support admin-mode on ldpc disable stbc disable txbf
disable optimized-mcast disable mcast-adaptable disable mcast2ucast
disabled dcs mode off channel_plan auto exit apply exit exit
learnac apply exit maintenance upgrd default apply exit
registration no security dinterval 3 dretry 3 cluster-encryption
enable cluster-shared-secret 58460398844AD629180E2AE824A80152
pwhash 88fb408278749b41eee77bdca13def56 sshhash
243124747755696724666B396B6631372E2E3936334E6B5175626B70636230
8CDC94A8AF01A7ACF2E3A1AB0E7FF9B8 apply exit blacklist mac-list-mode
black apply exit end
ap serial import 10280904235J0000 "10280904235J0000" AP3610-1 ap
LOCAL 10280904235J0000 usedhcp poll_timeout 15 client_session no
persistent no bcast_disassoc no vlanid no lldp led-mode normal
lbs-status enable balanced-power enable port-setting auto
tunnel-mtu 1500 ssh enable dedicated_scanner disable secure-tunnel
disable ipmcast-assembly disable country United States bindkey
8276CB9A64A43DA74A2DDA38C6A53B9F wired-mac 00:1F:45:93:D4:C3 apply
radio1 mode an dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag
2346 domain MyDomain tx_max_power 10 antsel left-middle-right no
atpc minbrate 6 n_chlwidth 40 ch 149 ch_req Auto n_guardinterval
long n_pmode none n_ptype cts only n_pbthreshold 50 no n_aggr_msdu
n_aggr_mpdu n_aggr_mpdu_max 65535 n_aggr_mpdu_max_subframes 64
n_addba_support max-distance 100 admin-mode on optimized-mcast
disable mcast-adaptable disable mcast2ucast disabled dcs mode off
channel_plan all-non-dfs exit apply exit radio2 mode gn dtim 5
beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain
antsel left-middle-right preamble auto tx_max_power 9 pmode auto
prate 11 ptype cts only no atpc minbrate 12 n_chlwidth 20 ch 6
ch_req 6 n_pmode none n_ptype cts only no n_aggr_msdu n_aggr_mpdu
n_aggr_mpdu_max 65535 n_aggr_mpdu_max_subframes 64 n_addba_support
max-distance 100 admin-mode on optimized-mcast disable
mcast-adaptable disable mcast2ucast disabled dcs mode off
channel_plan auto exit apply exit exit end
ap serial import 13251116085A0000 "WS-AP3715I" AP3715i ap LOCAL
13251116085A0000 ap_env indoor usedhcp poll_timeout 15
client_session no persistent no bcast_disassoc no vlanid no lldp
led-mode normal lbs-status enable balanced-power enable
port-setting auto tunnel-mtu 1500 ssh enable dedicated_scanner
disable secure-tunnel disable ipmcast-assembly disable country
United States bindkey AC66A4838A39950C8539B9403C1DA049 wired-mac
20:B3:99:A9:B6:AE apply radio1 mode an dtim 5 beaconp 100
nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power
10 antsel left-middle-right no atpc minbrate 6 n_chlwidth 40 ch
None ch_req Auto n_guardinterval short n_pmode none n_ptype cts
only n_pbthreshold 50 no n_aggr_msdu n_aggr_mpdu n_aggr_mpdu_max
65535 n_aggr_mpdu_max_subframes 64 n_addba_support max-distance 100
admin-mode on ldpc disable stbc disable txbf disable
optimized-mcast disable mcast-adaptable disable mcast2ucast
disabled dcs mode off channel_plan all-non-dfs exit apply exit
radio2 mode gn dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag
2346 domain MyDomain antsel left-middle-right preamble long
tx_max_power 8 pmode auto prate 11 ptype cts only no atpc minbrate
6 n_chlwidth 20 ch None ch_req 0 n_guardinterval long n_pmode none
n_ptype cts only no n_aggr_msdu n_aggr_mpdu n_aggr_mpdu_max 65535
n_aggr_mpdu_max_subframes 64 n_addba_support max-distance 100
admin-mode on ldpc disable stbc disable txbf disable
optimized-mcast disable mcast-adaptable disable mcast2ucast
disabled dcs mode off channel_plan auto exit apply exit exit
end
ap serial import 14252471085C0000 "14252471085C0000" AP3825i ap
LOCAL 14252471085C0000 ap_env indoor usedhcp poll_timeout 15
client_session no persistent no bcast_disassoc no vlanid no lldp
led-mode normal lbs-status enable balanced-power enable
port-setting auto tunnel-mtu 1500 ssh enable dedicated_scanner
disable secure-tunnel disable ipmcast-assembly disable lacp disable
country United States bindkey 3D40D05E039FE312164CBADB77CDA101
wired-mac 20:B3:99:E4:7A:B8 apply radio1 mode anac dtim 3 beaconp
100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain
tx_max_power 14 antsel left-middle-right no atpc minbrate 6
n_chlwidth 40 ch None ch_req 36 n_guardinterval long n_pmode none
n_ptype cts only n_pbthreshold 50 no n_aggr_msdu no n_aggr_mpdu
n_aggr_mpdu_max 1048575 n_aggr_mpdu_max_subframes 64 no
n_addba_support admin-mode on ldpc disable stbc disable
optimized-mcast disable mcast-adaptable disable mcast2ucast
disabled dcs mode off channel_plan all-non-dfs exit apply exit
radio2 mode gn dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag
2346 domain MyDomain antsel left-middle-right preamble long
tx_max_power 8 pmode auto prate 11 ptype cts only no atpc minbrate
12 n_chlwidth 20 ch None ch_req 11 n_guardinterval long n_pmode
none n_ptype cts only no n_aggr_msdu no n_aggr_mpdu n_aggr_mpdu_max
65535 n_aggr_mpdu_max_subframes 64 no n_addba_support max-distance
100 admin-mode on ldpc disable stbc disable txbf disable
optimized-mcast disable mcast-adaptable disable mcast2ucast
disabled dcs mode off channel_plan auto exit apply exit exit
end
## rolerole create "Voice" snmpid 1 0 "Voice" filter-status
enable ulfilterap enable apcustom disable name "Voice" default-cos
"RTP/Voice/Video" access-control allow apply acfilters apply exit
exit end## WLANSwlans create "ExtremeIntopPSK" mode std ssid
"ExtremeIntopPSK" rfsid 1 "ExtremeIntopPSK" status enable remotable
disable auto-enable disable interwlan-roaming enable
egress-filtering disable aplist "10280904235J0000" both aplist
"WS-AP3715I" both aplist "14252471085C0000" both ssid
"ExtremeIntopPSK" timeout-pre 5 timeout-post 30 timeout-session 0
direct-client-traffic disable default-cos "No CoS" apply auth mac
disable mode disabled cdr disable radius-namespace DISABLED apply
exit priv mode wpa-psk psk "CB26EC49C0CCA932CD2A566ACBA9392A"
wpa-broadcast-rekey 3600 wpa-v2 aes group-key-ps disable apply exit
qos-policy dot11e disable priority-map import
02000000000000000000020002000200010003000300030003000400040004000400050005000500050000000000060006000000000000000700000000000000
video-admission-control disable voice-admission-control disable
legacy disable priority-override-up 1 priority-override disable
turbo-voice disable uapsd enable wmm enable flex-client-access
disable apply exit rf process-client-ie disable 11h-support disable
11h-power-reduction disable ssid-suppress disable energy-save-mode
disable apply exit unauth-behavior nonauth-policy apply exit
end
wlans create "ExtremeIntop" mode std ssid "ExtremeIntop" rfsid 2
"ExtremeIntop" status enable remotable disable auto-enable disable
interwlan-roaming enable egress-filtering disable aplist
"10280904235J0000" both aplist "WS-AP3715I" both aplist
"14252471085C0000" both ssid "ExtremeIntop" timeout-pre 5
timeout-post 30 timeout-session 0 direct-client-traffic disable
default-cos "No CoS" apply auth mac disable mode disabled cdr
disable radius-namespace DISABLED apply exit priv mode none apply
exit qos-policy dot11e disable priority-map import
02000000000000000000020002000200010003000300030003000400040004000400050005000500050000000000060006000000000000000700000000000000
video-admission-control disable voice-admission-control disable
legacy disable priority-override-up 1 priority-override disable
turbo-voice disable uapsd enable wmm enable flex-client-access
disable apply exit rf process-client-ie disable 11h-support disable
11h-power-reduction disable ssid-suppress disable energy-save-mode
disable apply exit unauth-behavior nonauth-policy apply exit
end
wlans create "ExtremeIntop1x" mode std ssid "ExtremeIntop1x"
rfsid 3 "ExtremeIntop1x" status enable remotable disable
auto-enable disable interwlan-roaming enable egress-filtering
disable aplist "10280904235J0000" both aplist "WS-AP3715I" both
aplist "14252471085C0000" both ssid "ExtremeIntop1x" timeout-pre 5
timeout-post 30 timeout-session 0 direct-client-traffic disable
default-cos "No CoS" apply auth mac disable mode 8021x vsa-ap
disable vsa-ssid disable vsa-vns disable vsa-policy disable
vsa-topology disable vsa-ingress disable vsa-egress disable interim
0 cdr disable aaa-redir disable use-zone disable radius-namespace
DISABLED apply config "IntopRadius" role auth nasid vnsname nasip
vnsip apply config exit exit priv mode wpa wpa-broadcast-rekey 3600
wpa-v2 aes wpa-v2-key-mgmt okc group-key-ps disable apply exit
qos-policy dot11e disable priority-map import
02000000000000000000020002000200010003000300030003000400040004000400050005000500050000000000060006000000000000000700000000000000
video-admission-control disable voice-admission-control disable
legacy disable priority-override-up 1 priority-override disable
turbo-voice disable uapsd enable wmm enable flex-client-access
disable apply exit rf process-client-ie disable 11h-support disable
11h-power-reduction disable ssid-suppress disable energy-save-mode
disable apply exit unauth-behavior discard-unauth-traffic apply
exit end## AP post configurationap defaults assign wlan-foreign-ap
enable apply exit exit load-groups exit logs collection disable
frequency 1 destination local apply exit end## VNSvnsmode create
"ExtremIntop" wlans "ExtremeIntop" pol "Voice" "ExtremIntop"
wlans-name "ExtremeIntop" non-auth "Voice" auth non-auth status
enable name "ExtremIntop" apply exit end
vnsmode create "ExtremeIntopPSK" wlans "ExtremeIntopPSK" pol
"Voice" "ExtremeIntopPSK" wlans-name "ExtremeIntopPSK" non-auth
"Voice" auth non-auth status enable name "ExtremeIntopPSK" apply
exit end
vnsmode create "ExtremeIntop1x" wlans "ExtremeIntop1x" pol
"Voice" "ExtremeIntop1x" wlans-name "ExtremeIntop1x" non-auth
"Voice" auth non-auth status enable name "ExtremeIntop1x" apply
exit end## site## Threat definition
## RF Locationlocation location-engine disable auto-tracking
disable default-height 300 default-env-mode 2 publish push disable
interval 60 unit 0 apply exit apply floor-plan end## System
Maintenanceloglevel ac 3 stationlog disable send_station_trap
disable send2wm enableloglevel ap 2healthpoll enable
## maintenance cyclemaintain_cycle freq never platform
AP2600,AP2605,AP2650,AP4102,W786 starttime 00:00 duration 3 apply
end## SNMP COS REF MAPPINGsnmp-cos-mapping 1 1 1snmp-cos-mapping 2
1 1snmp-cos-mapping 3 0 0snmp-cos-mapping 3 1 0snmp-cos-mapping 3 2
1snmp-cos-mapping 3 3 1snmp-cos-mapping 3 4 2snmp-cos-mapping 3 5
2snmp-cos-mapping 3 6 3snmp-cos-mapping 3 7 3snmp-cos-mapping 3 8
4snmp-cos-mapping 3 9 4snmp-cos-mapping 3 10 5snmp-cos-mapping 3 11
5snmp-cos-mapping 3 12 6snmp-cos-mapping 3 13 6snmp-cos-mapping 3
14 7snmp-cos-mapping 3 15 7