26
Interoperability Report - Ascom i62 – Extreme Version 09.15.06 1 2017-02-22 INTEROPERABILITY REPORT Ascom i62 Extreme Networks C25 / 35 / C2110 / C5110 / C5210 and V2110 AP 37xx / 38xx / 39xx i62 and OEM derivatives version 5.5.0 Extreme Networks software version 10.11.04.0008 Ascom, Jan 2017

Interoperability report Ascom i62 Extreme 10.11.04 R1 · 2017-02-22 · Interoperability Report - Ascom i62 – Extreme Version 09.15.06 3 2017-02-22 INTRODUCTION This document describes

  • Upload
    others

  • View
    19

  • Download
    0

Embed Size (px)

Citation preview

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 1 2017-02-22

    INTEROPERABILITY REPORT Ascom i62 Extreme Networks C25 / 35 / C2110 / C5110 / C5210 and V2110 AP 37xx / 38xx / 39xx i62 and OEM derivatives version 5.5.0

    Extreme Networks software version 10.11.04.0008

    Ascom, Jan 2017

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 2 2017-02-22

    TABLE OF CONTENT: INTRODUCTION ........................................................................................................................... 3 

    Ascom solution ......................................................................................................................... 3 Extreme Networks solution ....................................................................................................... 3 

    SUMMARY .................................................................................................................................... 5 Known issues ............................................................................................................................ 6 General conclusion ................................................................................................................... 6 Compatibility information .......................................................................................................... 6 

    APPENDIX A: TEST CONFIGURATIONS .................................................................................... 7 Extreme Networks V2110 Controller v. 10.11.04 ...................................................................... 7 

    Overview ............................................................................................................................... 7 Extreme Networks controller overview. ................................................................................. 7 Security settings (PSK) ......................................................................................................... 8 Security settings (802.1X / PEAP-MSCHAPv2) .................................................................. 10 General settings (SSID, QoS, Radio ) ................................................................................. 13 

    Ascom i62 network settings .................................................................................................... 22 APPENDIX B: DETAILED TEST RECORDS .............................................................................. 25 

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 3 2017-02-22

    INTRODUCTION This document describes necessary steps and guidelines to optimally configure the Extreme Networks Wireless platform with Ascom i62 VoWiFi handsets.

    The guide should be used in conjunction with both Extreme Networks and Ascom’s configuration guide(s).

    Ascom solution Ascom is a global solutions provider focused on healthcare ICT and mobile workflow solutions. The vision of Ascom is to close digital information gaps allowing for the best possible decisions – anytime and anywhere. Ascom’s mission is to provide mission-critical, real-time solutions for highly mobile, ad hoc, and time-sensitive environments. Ascom uses its unique product and solutions portfolio and software architecture capabilities to devise integration and mobilization solutions that provide truly smooth, complete and efficient workflows for healthcare as well as for industry, security and retail sectors. Ascom is headquartered in Baar (Switzerland), has subsidiaries in 15 countries and employs around 1,300 people worldwide. Ascom registered shares (ASCN) are listed on the SIX Swiss Exchange in Zurich.

    Extreme Networks solution Extreme Networks, Inc. (EXTR) is a software and services-led networking solutions company committed to solving IT's toughest networking challenges. Extreme Networks is headquartered in San Jose, CA, with more than 14,000 customers in over 80 countries. For more information, visit Extreme's website. Extreme Networks and the Extreme Networks logo are registered trademarks of Extreme Networks, Inc. in the United States and/or other countries.

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 4 2017-02-22

    SITE INFORMATION Test Site: Ascom US 300 Perimeter park drive Morrisville, NC, US-27560 USA Participants: Karl-Magnus Olsson, Ascom Sweden, Gothenburg TEST TOPOLOGY

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 5 2017-02-22

    SUMMARY Please refer to Appendix B for detailed results. WLAN Controller Features

    High Level Functionality Result Association, Open with No Encryption OK Association, WPA2-PSK / AES Encryption OK Association, PEAP-MSCHAPv2 Auth, AES Encryption OK Association with EAP-TLS authentication OK Association, Multiple ESSIDs OK Beacon Interval and DTIM Period OK PMKSA Caching OK WPA2-opportunistic/proactive Key Caching OK WMM Prioritization OK 802.11 Power-save mode OK 802.11e U-APSD OK 802.11e U-APSD (load test) OK Roaming

    High Level Functionality Result Roaming, Open with No Encryption OK (typical roaming time 16ms) * Roaming, WPA2-PSK, AES Encryption OK (typical roaming time 32ms) *

    Roaming, PEAP-MSCHAPv2 Auth, AES Encryption OK (typical roaming time 33ms)* *) Measured times is with opportunistic key caching enabled and for 802.11an. For detailed results see Appendix B.

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 6 2017-02-22

    Known issues

    No known issues.

    For additional information regarding the known issues please contact [email protected] or [email protected]

    General conclusion The verification, including association, authentication and call stability tests generated in general very good results. Roaming times were measured in the range of around 35ms when using both WPA2-PSK/AES and PEAP-MSCHAPv2 (WPA2/AES). Load tests showed that it was possible to maintain 12 simultaneous calls on one access point (radio) when using the minimum basic rate set to 12Mbps for both 802.11bgn. The same number of simulations calls could be maintained also for 802.11an. The majority of the test cases were performed in B@AP mode.

    Compatibility information All tests were done on AP3715, AP3825 3935 on a v2110 controller. Due to similar chipsets in other access points we consider all access points listed below supported. All Extreme Networks controllers are considered to be covered based on testing towards V2110. Supported access points with Extreme Networks version 10.11.04: AP3705, 3710, 3715, 3765, 3767 AP3801, 3805, 3825, 3865 AP 3935 Supported controller platforms with Extreme Networks version 10.11.04: C25 C35 V2110 C5110

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 7 2017-02-22

    APPENDIX A: TEST CONFIGURATIONS

    Extreme Networks V2110 Controller v. 10.11.04 In the following chapter you will find screenshots and explanations of basic settings in order to get an Extreme Networks wireless system to operate with an Ascom i62. Please note that security settings were modified according to requirements in individual test cases.

    Overview

    Extreme Networks controller overview.

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 8 2017-02-22

    Security settings (PSK)

    General SSID settings.

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 9 2017-02-22

    Security profile WPA2-PSK, AES encryption

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 10 2017-02-22

    Security settings (802.1X / PEAP-MSCHAPv2)

    Configuration of authentication using external Radius sever, 802.1X (Step 1). In this example is WPA2-AES/CCMP used. “Opportunistic Keying” is strongly recommended as Key Management Option in order to allow faster roaming between access points.

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 11 2017-02-22

    Configuration of authentication using external Radius sever (Step 2). Select the server to use. The server is created/configured in next step.

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 12 2017-02-22

    Configuration of authentication using external Radius sever (Step 3). The IP address and the secret must correspond to the IP and the credential used by the Radius server. Note that depending on which Authentication method used it might be necessary to add a certificate into the i62. PEAP-MSCHAPv2 requires a Root certificate and EAP-TLS requires both a Root certificate and a client certificate. Server certificate validation can however be overridden in version 4.1.12 and above per handset setting. Note. To enable fast inter-controller roaming with opportunistic key caching, the “pair” option under “Wireless controller -> availability” has to be enabled. Please consult Extreme Networks for details.

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 13 2017-02-22

    General settings (SSID, QoS, Radio )

    Make sure that WMM. In this example U-APSD is enabled which is strongly recommended in order to increase battery performance.

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 14 2017-02-22

    Ascom recommended settings for 802.11g/n are to use 3 channel plan (channel 1, 6 and 11). Due to the limited number of non-overlapping channels using 802.11g/n it is recommended to use 20MHz channel width. Note that Tx Power was adjusted in order to test roaming.

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 15 2017-02-22

    Radio 2 -> Advanced; Set DTIM period to value 5 and beacon period to 100ms. These values are recommended in order to allow maximum battery conservation without impacting the quality. A lower DTIM value is possible but will impact the standby time negatively. It is recommended to set the Min Basic Rate to 11Mbps to increase the performance.

    Radio 2 -> Advanced (continued). Additional settings left as default.

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 16 2017-02-22

    Configuration of 802.11a/n/ac: Refer to general guidelines on page 18. Note that Tx Power was adjusted in order to test roaming.

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 17 2017-02-22

    Radio 1 -> Advanced; Set DTIM period to value 5 and beacon period to 100ms. These values are recommended in order to allow maximum battery conservation without impacting the quality. A lower DTIM value is possible but will impact the standby time negatively.

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 18 2017-02-22

    Configuration of 802.11a/n/ac: Refer to general guidelines on page 18. Note that Tx Power was adjusted in order to test roaming.

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 19 2017-02-22

    General guidelines when deploying Ascom i62 handsets in 802.11a/n/ac environments:

    1. Enabling more than 8 channels will degrade roaming performance. Ascom recommends against going above this limit.

    2. Using 40 MHz channels (or “channel-bonding”) will reduce the number of non-DFS* channels to two in ETSI regions (Europe). In FCC regions (North America), 40MHz is a more viable option because of the availability of additional non-DFS channels. The handset can co-exist with 40MHz stations in the same ESS.

    3. Ascom do support and can coexist in 80MHz channel bonding environments. The recommendations is however to avoid 80Mhz channel bonding as it severely reduces the number of available non overlapping channels.

    4. Make sure that all non-DFS channel are taken before resorting to DFS channels. The handset can cope in mixed non-DFS and DFS environments; however, due to “unpredictability” introduced by radar detection protocols, voice quality may become distorted and roaming delayed. Hence Ascom recommends if possible avoiding the use of DFS channels in VoWIFI deployments.

    *) Dynamic Frequency Selection (radar detection)

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 20 2017-02-22

    Virtual Network set up including the Roles.

    Voice role configuration.

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 21 2017-02-22

    Controller configuration See attached file (controller_config.cli) for controller configuration.

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 22 2017-02-22

    Ascom i62 network settings

    Ascom i62 Network configurations (WPA2-PSK) Note. Refer to general guidelines on page 18 concerning 802.11a/n channels. It’s important that the channels in the handset match the channel plan used in the system Note. FCC is no longer allowing 802.11d to determine regulatory domain. Devices deployed in USA must set Regulatory domain to “USA”.

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 23 2017-02-22

    i62 network settings for 802.1X authentication (PEAP-MSCHAPv2) Note. Refer to general guidelines on page 18 concerning 802.11a/n channels. It’s important that the channels in the handset match the channel plan used in the system Note. FCC is no longer allowing 802.11d to determine regulatory domain. Devices deployed in USA must set Regulatory domain to “USA”.

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 24 2017-02-22

    802.1X Authentication requires a root certificate to be uploaded to the phone by “right clicking” -> Edit certificates. EAP-TLS will require both a root and a client certificate. Note that both a root and a client certificate are needed for TLS. Otherwise only a root certificate is needed. Server certificate validation can be overridden in version 4.1.12 and above per handset setting

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 25 2017-02-22

    APPENDIX B: DETAILED TEST RECORDS VoWIFI Pass 17 Fail 0 Comments 0 Untested 2 Total 19 See attached file (WLANinteroperabilityTestReport_Extreme_networks.xls) for detailed test results. MISCELLANEOUS Please refer to the test specification for WLAN systems on Ascom’s interoperability web page for explicit information regarding each test case. See URL (requires login): https://www.ascom-ws.com/AscomPartnerWeb/en/startpage/Sales-tools/Interoperability

  • Interoperability Report - Ascom i62 – Extreme Version 09.15.06 26 2017-02-22

    Document History Rev Date Author DescriptionP1 2016-12-16 SEKMO Draft 1R1 2017-01-13 SEKMO Updates after review. Revision R1

    WLAN TR

    WLAN Interoperability Test ReportWLAN configuration:

    Beacon Interval: 100ms

    Test object - Handset:DTIM Interval: 5

    Ascom i62 v 5.5.0802.11d Regulatory Domain: XX

    Test object - WLAN system:WMM Enabled (Auto/WMM)

    Extreme Networks V2110, version 10.11.04.0008No Auto-tune

    AP 2715, 3825, 3935AP2715AP2825AP3935Single Voice VLAN

    2.4Ghz5.0Ghz2.4Ghz5.0Ghz2.4Ghz5.0Ghz

    Test CaseDescriptionVerdictVerdictVerdictVerdictVerdictVerdictComment

    TEST AREA ASSOCIATION / AUTHENTICATION

    #101Association with open authentication, no encryptionPASSPASSPASSPASSPASSPASS

    #107Association with WPA2-PSK authentication, AES-CCMP encryptionPASSPASSPASSPASSPASSPASS

    #110Association with PEAP-MSCHAPv2 auth, AES-CCMP encryptionPASSPASSPASSPASSPASSPASSFreeRADIUS; RootCA loaded to Device.FAIL

    #116Association with EAP-TLS authenticationPASSPASSPASSPASSPASSPASSFreeRADIUS; RootCA and client loaded to Device.

    TEST AREA POWER-SAVE AND QOSPASS

    #150802.11 Power-save modePASSPASSPASSPASSPASSPASSFAIL

    #151Beacon period and DTIM intervalPASSPASSPASSPASSPASSPASSDTIM 1,3 5 , Beacon Period 100tu.NOT TESTED

    #152802.11e U-APSDPASSPASSPASSPASSPASSPASSSee Comment

    #202WMM prioritizationPASSPASSPASSPASSPASSPASSiperf to generate background lload. No noticable degenerations of voice quality

    TEST AREA "PERFORMANCE"

    #308Power-save mode U-APSD – WPA2-PSKPASSPASSPASSPASSPASSPASS12hs ok

    #310CAC - TSPECNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDPASSPASS

    TEST AREA ROAMING AND HANDOVER TIMES

    #401Handover with open authentication and no encryptionPASSPASSPASSPASSPASSPASS802.11an:26 ms 802.11gn: 26ms

    #404Handover with WPA2-PSK auth and AES-CCMP encryptionPASSPASSPASSPASSPASSPASS802.11an: 47 ms 802.11gn: 56ms

    #408Handover with PEAP-MSCHAPv2 authentication and AES-CCMP encryptionPASSPASSPASSPASSPASSPASS802.11an: 52 ms 802.11gn: 57 ms

    #411Handover using PMKSA and opportunistic/proactive key cachingPASSPASSPASSPASSPASSPASSSame test case as #408

    TEST AREA BATTERY LIFETIME

    #501Battery lifetime in idleNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDPASSPASS80h +, Non DFS channles configured

    #504Battery lifetime in call with power save mode U-APSDPASSPASSPASSPASSPASSPASS10-14h, Non DFS channles configured

    TEST AREA STABILITY

    #602Duration of call – U-APSD modePASSPASSPASSPASSPASSPASS24h call mantained

    TEST AREA 802.11n

    #801Frame aggregation A-MSDUNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTED

    #802Frame aggregation A-MPDUPASSPASSPASSPASSPASSPASS

    #80440Mhz channelsNOT TESTEDPASSNOT TESTEDPASSNOT TESTEDPASSChannel bonding only recomended on 5GHz band

    #805802.11n ratesPASSPASSPASSPASSPASSPASS

    =~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2016.12.16 09:19:40 =~=~=~=~=~=~=~=~=~=~=~= ���show run-configCLI Export start: Fri Dec 16 03:20:39 2016

    CLI Export end: Fri Dec 16 03:20:42 2016temp_directory= /tmp/__cliagent_1481876439file_name=/tmp/__cliagent_1481876439/controller_config.cli## System Configuration# CLI Version 10.11#### Topologytopology internal-vlanid 4094 mac-key "00:0C:29:CF:5D:EC"topology "Admin" l3 ip 192.168.10.1/24 cert default cert default ipv6 gateway-ipv6 nonetopology create "esa0" physical 1 port esa0 untag 192.168.0.24/24 "esa0" name "esa0" 3rd-party disable l3presence enable l3 ip 192.168.0.24/24 ap-register enable mgmt enable cert default cert default ipv6 dhcp mode none l2 port esa0 tagged disable vlanid 1topology multicast-support "esa0"topology "Bridged at AP untagged" name "Bridged at AP untagged" dynamic-egress enable l3 netmask none l2 tagged disable vlanid 4093 arp-proxy disable multicast filter disabletopology create "br@ewc" b@ac 4093 port esa0 tag "br@ewc" mode b@ac name "br@ewc" l3presence disable dynamic-egress enable l3 netmask none l2 port esa0 tagged enable vlanid 4093 multicast filter disabletopology topology-group## VNS Globalvnsmode das port 3799 replay_interval 300 adminctr max-voice-reassoc 80 max-voice-assoc 7 max-video-reassoc 60 max-video-assoc 40 max-beffort-reassoc 40 max-beffort-assoc 30 max-bground-reassoc 30 max-bground-assoc 20 flex-client-access 100%-airtime egress-filtering wlan auto-login hide policy-invalid-action default hybrid-policy combined tg-selection mac rule-redirect disable radius strict disable include-service-type enable delay-client-msg 20 radius-mac-format 1 usage-mode exclusive mac-format-1x disable radius-accounting enable defer-acct-start disable service-type-login disable radius create "FreeRadius" 192.168.0.2 "" "FreeRadius" auth-port 1812 acct-port 1813 auth-prio 1 acct-prio 1 auth-retries 3 acct-retries 3 auth-timeout 5 acct-timeout 5 interim 30 protocol MS-CHAP2 shared-secret "840BF4ABD0931E74659206F63A198E40" name "FreeRadius" ip "192.168.0.2" polling-mechanism actual-user polling-interval 60 nac rateprofile netflow-mirror snmp-traffic-mirrorn-idx 1 netflow-export-dest "0.0.0.0" netflow-export-interval 60 traffic-mirror-firstn 15 traffic-mirror-l2port none custom-app## CoScos "No CoS"cos create "Scavenger" snmpid -1 -1 0 2 "Scavenger" tos-dscp-mask none transmit-queue 0cos create "Best Effort" snmpid -1 -1 2 3 "Best Effort" tos-dscp-mask none transmit-queue 1cos create "Bulk Data" snmpid -1 -1 4 4 "Bulk Data" tos-dscp-mask none transmit-queue 2cos create "Critical Data" snmpid -1 -1 6 5 "Critical Data" tos-dscp-mask none transmit-queue 3cos create "Network Control" snmpid -1 -1 8 6 "Network Control" tos-dscp-mask none transmit-queue 4cos create "Network Management" snmpid -1 -1 10 7 "Network Management" tos-dscp-mask none transmit-queue 5cos create "RTP/Voice/Video" snmpid -1 -1 12 8 "RTP/Voice/Video" tos-dscp-mask none transmit-queue 6cos create "High Priority" snmpid -1 -1 14 9 "High Priority" tos-dscp-mask none transmit-queue 7cos create "5M" snmpid -1 -1 -1 10 "5M" name "5M" use-wlan-marking disable priority none tos-dscp-mask none transmit-queue none## VNS Default Policyvnsmode default-role topology-name "Bridged at AP untagged" sync disable apfilters create 1 proto any eth any mac any 0.0.0.0/0 in dst out none allow priority none tos-dscp none create 2 proto any eth any mac any 0.0.0.0/0 in none out src allow priority none tos-dscp none acfilters create 1 proto any eth any mac any 0.0.0.0/0 in dst out none allow priority none tos-dscp none cos none traffic-mirror none create 2 proto any eth any mac any 0.0.0.0/0 in none out src allow priority none tos-dscp none cos none traffic-mirror none## L2portsl2ports esa0 port enable esa1 port enable## Host Attributeshost-attributes hostname EWC domain extremenetworks.com gateway none # DNS Servers dns no dns 1 no dns 1 no dns 1## OSPFip ospf area 0.0.0.0 areatype default status disable ospfinterface## Static Routesip route default 192.168.0.50 nofloat## Port speed## lbslbs service disable## Network Timetime ntp 2 ntpip 1 192.168.0.12 tz import America/Kentucky/Monticello## System Logsyslog no svcmsg no audmsg stationevents disable facility application 0## Web Settingsweb timeout 1:00 no showvns guestportal-admin-timeout 1:00## Secure Connectionssecureconnection weak-ciphers enable message-bus-ciphers none## FTP Serversftp_server BU_RESTORE 192.168.0.166 test 4C2C3AA113A46BD9F2EC63A0E305C815 \/ EWC.20072015.102609.zipftp_server CLONE 172.20.106.243 test 4C2C3AA113A46BD9F2EC63A0E305C815 \/ EWC-bge-09.15.06.0010-rescue-user.tgzftp_server UPGRADE 172.20.106.238 test 4C2C3AA113A46BD9F2EC63A0E305C815 \/ AC-MV-10.11.04.0008-1.bge## Mobilitymobility mrole none## SNMPsnmp enable none rcommunity public rwcommunity private context severity 1 port 162 publish-ap enable engine-id controller_000C29CF5DEC## Scheduled Backupschedule_backup protocol ftp type all freq never destination local## Management Userslogin## User Interfaceno runinstallwizard## Session Availabilityavailability no pair## Mitigatormitigator no analysis scprof gsprof maintenance## APap defaults 3935FCC ssh enable poll_timeout 15 no client_session no persistent no bcast_disassoc country United States lldp 30 2 led-mode normal lbs-status enable secure-tunnel disable ipmcast-assembly disable balanced-power enable radio1 mode a dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power 18 no atpc minbrate 6 admin-mode off optimized-mcast disable mcast-adaptable disable mcast2ucast disabled probe-suppression disable dcs mode monitor channel_plan all-non-dfs noise_threshold -80 occupancy_threshold 100 update_period 5 radio2 mode bg dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power 18 no atpc minbrate 1 pmode auto prate 11 preamble long ptype cts only admin-mode on optimized-mcast disable mcast-adaptable disable mcast2ucast disabled probe-suppression disable dcs mode monitor channel_plan auto noise_threshold -80 occupancy_threshold 100 update_period 5 interference-wait-time 10 interference-event-type noneap defaults 3965FCC ssh enable poll_timeout 15 no client_session no persistent no bcast_disassoc country United States lldp 30 2 led-mode normal lbs-status enable secure-tunnel disable ipmcast-assembly disable balanced-power enable radio1 mode an dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power 18 n_chlwidth 40 n_guardinterval short no atpc minbrate 6 n_pmode none n_ptype cts only no n_aggr_msdu n_aggr_mpdu n_aggr_mpdu_max 65535 n_aggr_mpdu_max_subframes 64 n_addba_support admin-mode off ldpc enable stbc disable txbf mu_mimo optimized-mcast disable mcast-adaptable disable mcast2ucast disabled probe-suppression disable dcs mode monitor channel_plan all-non-dfs noise_threshold -80 occupancy_threshold 100 update_period 5 radio2 mode bg dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power 18 no atpc minbrate 1 pmode auto prate 11 preamble long ptype cts only admin-mode on optimized-mcast disable mcast-adaptable disable mcast2ucast disabled probe-suppression disable dcs mode monitor channel_plan auto noise_threshold -80 occupancy_threshold 100 update_period 5 interference-wait-time 10 interference-event-type noneap defaults ap37xx ssh enable poll_timeout 15 client_session no persistent no bcast_disassoc country United States no lldp led-mode normal lbs-status enable secure-tunnel disable ipmcast-assembly disable balanced-power enable draeger-mode disable radio1 mode an dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power 18 antsel left-middle-right n_chlwidth 40 n_guardinterval short max-distance 100 no atpc minbrate 6 n_pmode none n_ptype cts only n_pbthreshold 50 no n_aggr_msdu n_aggr_mpdu n_aggr_mpdu_max 65535 n_aggr_mpdu_max_subframes 64 n_addba_support admin-mode off ldpc disable stbc disable txbf disable optimized-mcast disable mcast-adaptable disable mcast2ucast disabled probe-suppression disable dcs mode monitor channel_plan all-non-dfs noise_threshold -80 occupancy_threshold 100 update_period 5 radio2 mode bg dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power 18 antsel left-middle-right max-distance 100 no atpc minbrate 1 pmode auto prate 11 preamble long ptype cts only admin-mode on optimized-mcast disable mcast-adaptable disable mcast2ucast disabled probe-suppression disable dcs mode monitor channel_plan auto noise_threshold -80 occupancy_threshold 100 update_period 5 interference-wait-time 10 interference-event-type noneap defaults ap38xx ssh enable poll_timeout 15 client_session no persistent no bcast_disassoc country United States no lldp led-mode normal lbs-status enable secure-tunnel disable ipmcast-assembly disable balanced-power enable draeger-mode disable radio1 mode anac dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power 18 antsel left-middle-right n_chlwidth 80 n_guardinterval long no atpc minbrate 6 n_pmode none n_ptype cts only no n_aggr_msdu no n_aggr_mpdu n_aggr_mpdu_max 1048575 n_aggr_mpdu_max_subframes 64 no n_addba_support admin-mode off ldpc disable stbc disable optimized-mcast disable mcast-adaptable disable mcast2ucast disabled probe-suppression disable dcs mode monitor channel_plan all-non-dfs noise_threshold -80 occupancy_threshold 100 update_period 5 radio2 mode bgn dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power 18 antsel left-middle-right n_chlwidth auto n_guardinterval long max-distance 100 no atpc minbrate 1 pmode none prate 1 preamble long ptype rts cts n_pmode none n_ptype cts only n_pbthreshold 50 no n_aggr_msdu no n_aggr_mpdu n_aggr_mpdu_max 65535 n_aggr_mpdu_max_subframes 64 no n_addba_support admin-mode on ldpc disable stbc disable txbf disable optimized-mcast disable mcast-adaptable disable mcast2ucast disabled probe-suppression disable dcs mode monitor channel_plan auto noise_threshold -80 occupancy_threshold 100 update_period 5 interference-wait-time 10 interference-event-type noneap defaults ap3801 ssh enable poll_timeout 15 no client_session no persistent no bcast_disassoc country United States no lldp led-mode normal lbs-status enable secure-tunnel disable ipmcast-assembly disable balanced-power enable draeger-mode disable radio1 mode anac dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power 18 n_chlwidth 80 n_guardinterval short no atpc minbrate 6 n_pmode auto n_ptype cts only n_aggr_msdu n_aggr_mpdu n_aggr_mpdu_max 1048575 n_aggr_mpdu_max_subframes 30 n_addba_support admin-mode on ldpc enable stbc disable optimized-mcast disable mcast-adaptable disable mcast2ucast disabled probe-suppression disable dcs mode monitor channel_plan all-non-dfs noise_threshold -80 occupancy_threshold 100 update_period 5 radio2 mode gn dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power 18 n_chlwidth auto n_guardinterval short max-distance 100 no atpc minbrate 6 pmode none prate 1 ptype rts cts n_pmode auto n_ptype cts only n_pbthreshold 50 n_aggr_msdu n_aggr_mpdu n_aggr_mpdu_max 65535 n_aggr_mpdu_max_subframes 30 n_addba_support admin-mode off ldpc enable stbc disable txbf disable optimized-mcast disable mcast-adaptable disable mcast2ucast disabled probe-suppression disable dcs mode monitor channel_plan auto noise_threshold -80 occupancy_threshold 100 update_period 5 interference-wait-time 10 interference-event-type noneap defaults ap3805FCC ssh enable poll_timeout 15 no client_session no persistent no bcast_disassoc country United States no lldp led-mode normal lbs-status enable secure-tunnel disable ipmcast-assembly disable balanced-power enable draeger-mode disable radio1 mode anac dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power 18 n_chlwidth 40 n_guardinterval short no atpc minbrate 6 n_pmode auto n_ptype cts only no n_aggr_msdu n_aggr_mpdu n_aggr_mpdu_max 1048575 n_aggr_mpdu_max_subframes 30 n_addba_support admin-mode on ldpc enable stbc disable optimized-mcast disable mcast-adaptable disable mcast2ucast disabled probe-suppression disable dcs mode monitor channel_plan all-non-dfs noise_threshold -80 occupancy_threshold 100 update_period 5 radio2 mode gn dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power 18 n_chlwidth 20 n_guardinterval short max-distance 100 no atpc minbrate 6 pmode auto prate 11 ptype cts only n_pmode auto n_ptype cts only no n_aggr_msdu n_aggr_mpdu n_aggr_mpdu_max 65535 n_aggr_mpdu_max_subframes 30 n_addba_support admin-mode on ldpc enable stbc disable txbf disable optimized-mcast disable mcast-adaptable disable mcast2ucast disabled probe-suppression disable dcs mode monitor channel_plan auto noise_threshold -80 occupancy_threshold 100 update_period 5 interference-wait-time 10 interference-event-type noneap defaults learnac maintenance upgrd default registration no security dinterval 3 dretry 3 cluster-encryption enable cluster-shared-secret 58460398844AD629180E2AE824A80152 sshhash 2431245930755576783249247A397649773146453357447663754A5077485342682F 8CDC94A8AF01A7ACF2E3A1AB0E7FF9B8 blacklist mac-list-mode black mac-list-sync-mode disableap serial import 13151013915L0000 "13151013915L0000" AP3705i ap LOCAL 13151013915L0000 usedhcp poll_timeout 15 client_session no persistent no bcast_disassoc no vlanid no lldp led-mode normal lbs-status enable balanced-power enable port-setting auto tunnel-mtu 1500 ssh enable dedicated_scanner disable secure-tunnel disable ipmcast-assembly disable draeger-mode disable country United States bindkey 4D4554C1C7BAC770F85ED28F237DF9BE wired-mac 20:B3:99:A1:0E:82 radio1 mode an dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power 9 no atpc minbrate 6 n_chlwidth 40 ch None ch_req 36 n_guardinterval short n_pmode none n_ptype cts only n_pbthreshold 50 no n_aggr_msdu n_aggr_mpdu n_aggr_mpdu_max 65535 n_aggr_mpdu_max_subframes 64 n_addba_support max-distance 100 probe-suppression disable admin-mode on ldpc disable stbc disable txbf disable optimized-mcast disable mcast-adaptable disable mcast2ucast disabled dcs mode monitor channel_plan all-non-dfs noise_threshold -80 occupancy_threshold 100 update_period 5 radio2 mode bg dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain preamble long tx_max_power 9 pmode auto prate 11 ptype cts only no atpc minbrate 1 ch None ch_req 1 max-distance 100 probe-suppression disable admin-mode on optimized-mcast disable mcast-adaptable disable mcast2ucast disabled dcs mode monitor channel_plan auto noise_threshold -80 occupancy_threshold 100 update_period 5 interference-wait-time 10 interference-event-type noneap serial import 13251116085A0000 "WS-AP3715I" AP3715i ap LOCAL 13251116085A0000 ap_env indoor usedhcp poll_timeout 15 client_session no persistent no bcast_disassoc no vlanid no lldp led-mode normal lbs-status enable balanced-power enable port-setting auto tunnel-mtu 1500 ssh enable dedicated_scanner disable secure-tunnel disable ipmcast-assembly disable draeger-mode disable country United States bindkey 16597615366CC353DA550C3D189B623A wired-mac 20:B3:99:A9:B6:AE radio1 mode an dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power 10 antsel left-middle-right no atpc minbrate 6 n_chlwidth 40 ch 157 ch_req Auto n_guardinterval short n_pmode none n_ptype cts only n_pbthreshold 50 no n_aggr_msdu n_aggr_mpdu n_aggr_mpdu_max 65535 n_aggr_mpdu_max_subframes 64 n_addba_support max-distance 100 probe-suppression disable admin-mode on ldpc disable stbc disable txbf disable optimized-mcast disable mcast-adaptable disable mcast2ucast disabled dcs mode monitor channel_plan all-non-dfs noise_threshold -80 occupancy_threshold 100 update_period 5 radio2 mode gn dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain antsel left-middle-right tx_max_power 8 pmode auto prate 11 ptype cts only no atpc minbrate 6 n_chlwidth 20 ch 11 ch_req 11 n_guardinterval long n_pmode none n_ptype cts only no n_aggr_msdu n_aggr_mpdu n_aggr_mpdu_max 65535 n_aggr_mpdu_max_subframes 64 n_addba_support max-distance 100 probe-suppression disable admin-mode on ldpc disable stbc disable txbf disable optimized-mcast disable mcast-adaptable disable mcast2ucast disabled dcs mode monitor channel_plan auto noise_threshold -80 occupancy_threshold 100 update_period 5 interference-wait-time 10 interference-event-type noneap serial import 14252471085C0000 "14252471085C0000" AP3825i ap LOCAL 14252471085C0000 ap_env indoor usedhcp poll_timeout 15 client_session no persistent no bcast_disassoc no vlanid no lldp led-mode normal lbs-status enable balanced-power enable port-setting auto tunnel-mtu 1500 ssh enable dedicated_scanner disable secure-tunnel disable ipmcast-assembly disable lacp disable draeger-mode disable country United States bindkey 7A33EFD7D7DC6DCF748D8F55D31C4BD6 wired-mac 20:B3:99:E4:7A:B8 radio1 mode anac dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power 10 antsel left-middle-right no atpc minbrate 6 n_chlwidth 40 ch None ch_req 149 n_guardinterval long n_pmode none n_ptype cts only no n_aggr_msdu no n_aggr_mpdu n_aggr_mpdu_max 1048575 n_aggr_mpdu_max_subframes 64 no n_addba_support probe-suppression disable admin-mode on ldpc disable stbc disable optimized-mcast disable mcast-adaptable disable mcast2ucast disabled dcs mode monitor channel_plan all-non-dfs noise_threshold -80 occupancy_threshold 100 update_period 5 radio2 mode gn dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain antsel left-middle-right tx_max_power 8 pmode auto prate 11 ptype cts only no atpc minbrate 12 n_chlwidth 20 ch None ch_req 11 n_guardinterval long n_pmode auto n_ptype cts only no n_aggr_msdu n_aggr_mpdu n_aggr_mpdu_max 65535 n_aggr_mpdu_max_subframes 64 n_addba_support max-distance 100 probe-suppression disable admin-mode on ldpc enable stbc disable txbf disable optimized-mcast disable mcast-adaptable disable mcast2ucast disabled dcs mode monitor channel_plan auto noise_threshold -80 occupancy_threshold 100 update_period 5 interference-wait-time 10 interference-event-type noneap serial import 1548Y-1286800000 "1548Y-1286800000" AP3935i-FCC ap LOCAL 1548Y-1286800000 usedhcp poll_timeout 15 no client_session no persistent no bcast_disassoc no vlanid lldp 30 2 led-mode normal lbs-status enable balanced-power enable port-setting auto tunnel-mtu 1500 ssh enable dedicated_scanner disable secure-tunnel disable ipmcast-assembly disable lacp disable lpm-override disable country United States bindkey 2897DDC0B526B156B3064F4E5BFCF30F wired-mac D8:84:66:31:F1:16 radio1 mode anac dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power 10 no atpc minbrate 6 n_chlwidth 40 ch None ch_req 36 n_guardinterval short n_pmode auto n_ptype cts only no n_aggr_msdu n_aggr_mpdu n_aggr_mpdu_max 1048575 n_aggr_mpdu_max_subframes 30 n_addba_support probe-suppression disable admin-mode on ldpc enable stbc disable txbf disable optimized-mcast disable mcast-adaptable disable mcast2ucast disabled dcs mode monitor channel_plan all-non-dfs noise_threshold -80 occupancy_threshold 100 update_period 5 radio2 mode gn dtim 5 beaconp 100 nonUnicastQuota 100 rts 2346 frag 2346 domain MyDomain tx_max_power 10 pmode auto prate 11 ptype cts only no atpc minbrate 12 n_chlwidth 20 ch None ch_req 6 n_guardinterval short n_pmode auto n_ptype cts only no n_aggr_msdu n_aggr_mpdu n_aggr_mpdu_max 65535 n_aggr_mpdu_max_subframes 30 n_addba_support probe-suppression disable admin-mode on ldpc enable stbc disable optimized-mcast disable mcast-adaptable disable mcast2ucast disabled dcs mode monitor channel_plan 3-channel noise_threshold -80 occupancy_threshold 100 update_period 5 interference-wait-time 10 interference-event-type none## WLANSwlans create "ExtremeIntopPSK" mode std ssid "ExtremeIntopPSK" rfsid 1 "ExtremeIntopPSK" status enable remotable disable auto-enable disable interwlan-roaming enable egress-filtering disable aplist "13151013915L0000" both aplist "WS-AP3715I" both aplist "14252471085C0000" both aplist "1548Y-1286800000" both ssid "ExtremeIntopPSK" default-topology "Bridged at AP untagged" timeout-pre 5 timeout-post 30 timeout-session 0 direct-client-traffic disable default-cos "No CoS" default-traffic-mirror prohibited netflow disable appl-visibility disable auth mac disable mode disabled cdr disable radius-namespace DISABLED include-cui-type disable priv mode wpa-psk psk "CB26EC49C0CCA932CD2A566ACBA9392A" wpa-broadcast-rekey 3600 wpa-v2 aes group-key-ps disable mfp disable qos-policy legacy disable wmm enable dot11e disable turbo-voice disable uapsd enable voice-admission-control disable video-admission-control disable beffort-admission-control disable bground-admission-control disable uplink do-nothing downlink do-nothing flex-client-access disable priority-override disable priority-map import 02000000000000000000020002000200010003000300030003000400040004000400050005000500050000000000060006000000000000000700000000000000 priority-override-up 1 rf process-client-ie disable 11h-support disable 11h-power-reduction disable ssid-suppress disable energy-save-mode disable 11k-support disable 11k-quiet-ie disable unauth-behavior nonauth-policywlans create "ExtremeIntop" mode std ssid "ExtremeIntop" rfsid 2 "ExtremeIntop" status enable remotable disable auto-enable disable interwlan-roaming enable egress-filtering disable aplist "13151013915L0000" both aplist "WS-AP3715I" both aplist "14252471085C0000" both aplist "1548Y-1286800000" both ssid "ExtremeIntop" timeout-pre 5 timeout-post 30 timeout-session 0 direct-client-traffic disable default-cos "No CoS" default-traffic-mirror prohibited netflow disable appl-visibility enable auth mac disable mode disabled cdr disable radius-namespace DISABLED include-cui-type disable priv mode none qos-policy legacy disable wmm enable dot11e disable turbo-voice disable uapsd enable voice-admission-control disable video-admission-control disable beffort-admission-control disable bground-admission-control disable uplink do-nothing downlink do-nothing flex-client-access disable priority-override disable priority-map import 02000000000000000000020002000200010003000300030003000400040004000400050005000500050000000000060006000000000000000700000000000000 priority-override-up 1 rf process-client-ie disable 11h-support disable 11h-power-reduction disable ssid-suppress disable energy-save-mode disable 11k-support disable 11k-quiet-ie disable unauth-behavior nonauth-policywlans create "ExtremeIntop1x" mode std ssid "ExtremeIntop1x" rfsid 3 "ExtremeIntop1x" status enable remotable disable auto-enable disable interwlan-roaming enable egress-filtering disable aplist "13151013915L0000" both aplist "WS-AP3715I" both aplist "14252471085C0000" both aplist "1548Y-1286800000" both ssid "ExtremeIntop1x" timeout-pre 5 timeout-post 30 timeout-session 0 direct-client-traffic disable default-cos "No CoS" default-traffic-mirror prohibited netflow disable appl-visibility disable auth mac disable mode 8021x vsa-ap disable vsa-ssid disable vsa-vns disable vsa-policy disable vsa-topology disable vsa-ingress disable vsa-egress disable interim 0 cdr disable aaa-redir disable use-zone disable radius-namespace DISABLED include-cui-type disable config "FreeRadius" role auth nasid vnsname nasip vnsip config exit config "FreeRadius" role acct nasid vnsname nasip vnsip config exit priv mode wpa wpa-broadcast-rekey 3600 wpa-v2 aes wpa-v2-key-mgmt okc group-key-ps disable fast-transition disable mfp disable qos-policy legacy disable wmm enable dot11e disable turbo-voice disable uapsd enable voice-admission-control disable video-admission-control disable beffort-admission-control disable bground-admission-control disable uplink do-nothing downlink do-nothing flex-client-access disable priority-override disable priority-map import 02000000000000000000020002000200010003000300030003000400040004000400050005000500050000000000060006000000000000000700000000000000 priority-override-up 1 rf process-client-ie disable 11h-support disable 11h-power-reduction disable ssid-suppress disable energy-save-mode disable 11k-support disable 11k-quiet-ie disable unauth-behavior discard-unauth-traffic## rolerole create "Voice" snmpid 1 0 "Voice" filter-status enable ulfilterap enable apcustom disable name "Voice" default-cos no-change access-control allow traffic-mirror none acfilters## AP post configurationap defaults assign wlan-foreign-ap enable load-groups logs collection disable frequency 1 destination local## VNSvnsmode create "ExtremIntop" wlans "ExtremeIntop" pol "Voice" "ExtremIntop" wlans-name "ExtremeIntop" non-auth "Voice" auth non-auth status enable name "ExtremIntop"vnsmode create "ExtremeIntopPSK" wlans "ExtremeIntopPSK" pol "Voice" "ExtremeIntopPSK" wlans-name "ExtremeIntopPSK" non-auth "Voice" auth non-auth status enable name "ExtremeIntopPSK"vnsmode create "ExtremeIntop1x" wlans "ExtremeIntop1x" pol "Voice" "ExtremeIntop1x" wlans-name "ExtremeIntop1x" non-auth "Voice" auth non-auth status enable name "ExtremeIntop1x"## site## Threat definition## RF Locationlocation location-engine disable auto-tracking none area-tracking disable default-height 300 default-env-mode 2 publish push disable push-client-reporting disable interval 60 unit 0 floor-plan## System Maintenanceloglevel ac 3 stationlog disable send_station_trap disable send2wm enableloglevel ap 2healthpoll enable## maintenance cyclemaintain_cycle freq never starttime 00:00 duration 3## SNMP COS REF MAPPINGsnmp-cos-mapping 3 0 0snmp-cos-mapping 3 1 0snmp-cos-mapping 3 2 1snmp-cos-mapping 3 3 1snmp-cos-mapping 3 4 2snmp-cos-mapping 3 5 2snmp-cos-mapping 3 6 3snmp-cos-mapping 3 7 3snmp-cos-mapping 3 8 4snmp-cos-mapping 3 9 4snmp-cos-mapping 3 10 5snmp-cos-mapping 3 11 5snmp-cos-mapping 3 12 6snmp-cos-mapping 3 13 6snmp-cos-mapping 3 14 7snmp-cos-mapping 3 15 7EWC.extremenetworks.com# EWC.extremenetworks.com#