Wireless Networks®, the registered Aruba the Mobile Edge Company logo, and Aruba Mobility Management System®.
Dell™, the DELL™ logo, and PowerConnect™ are trademarks of Dell Inc.
All rights reserved. Specifications in this manual are subject to change without notice.
Originated in the USA. All other trademarks are the property of their respective owners.
Open Source Code
Certain Aruba products include Open Source software code developed by third parties, including software code subject
to the GNU General Public License (GPL), GNU Lesser General Public License (LGPL), or other Open Source Licenses.
Includes software from Litech Systems Design. The IF-MAP client library copyright 2011
Infoblox, Inc. All rights reserved. This product includes software developed by Lars Fenneberg, et al. The Open Source
code used can be found at this site:
http://www.arubanetworks.com/open_source
Legal Notice
The use of Aruba Networks, Inc. switching platforms and software, by all individuals or corporations, to terminate other
vendors’ VPN client devices constitutes complete acceptance of liability by that individual or corporation for this action
and indemnifies, in full, Aruba Networks, Inc. from any and all legal actions that might be taken against it with respect
to infringement of copyright on behalf of those vendors.
June 2014 | 0510897-18Dell Networking W-AirWave 8.0 | User Guide
Integrating AirWave into the Network and Organizational Hierarchy15
Administrative Roles16
Configuring AirWave17
Before You Begin17
Formatting the Top Header17
Customizing Columns in Lists19
Resetting Pagination Records20
Using the Pagination Widget21
Using Export CSV for Lists and Reports21
Defining Graph Display Preferences21
Customizing the Dashboard22
Adding Widgets23
Available Widgets23
Search Preferences26
Setting Severe Alert Warning Behavior27
Defining General AirWave Server Settings28
AMP Setup > General28
General Settings29
Automatic Authorization Settings30
Top Header Settings31
Search Method31
Home Overview Preferences31
Display Settings31
Device Configuration Settings32
AMP Features33
External Logging Settings33
Historical Data Retention Settings34
Firmware Upgrade Defaults36
Additional AMP Services36
Performance Settings38
Static Routes41
Creating AirWave Users41
AirWave User Roles43
Dell Network ing W-AirWave 8.0 | User GuideContents | 3
Page 4
User Roles and VisualRF43
Creating AirWave User Roles43
Configuring Login Message, TACACS+, RADIUS, and LDAP Authentication48
Setting Up Login Configuration Options49
Configuring Whitelists49
Setting Up Certificate Authentication50
Setting Up Single Sign-On50
Specifying the Authentication Priority51
Configuring RADIUS Authentication and Authorization51
Integrating a RADIUS Accounting Server52
Configuring TACACS+ Authentication53
Configuring LDAP Authentication and Authorization55
Enabling AirWave to Manage Your Devices58
Configuring Communication Settings for Discovered Devices58
Loading Device Firmware Onto AirWave (optional)61
Setting Up Device Types64
Configuring Cisco WLSE and WLSE Rogue Scanning65
Introduction to Cisco WLSE65
Initial WLSE Configuration66
Adding an ACS Server for WLSE66
Enabling Rogue Alerts for Cisco WLSE66
Configuring WLSE to Communicate with APs66
Discovering Devices66
Managing Devices67
Inventory Reporting67
Defining Access67
Grouping67
Configuring IOS APs for WDS Participation67
WDS Participation68
Primary or Secondary WDS68
Configuring ACS for WDS Authentication68
Configuring Cisco WLSE Rogue Scanning68
Configuring ACS Servers70
Integrating AirWave with an Existing Network Management Solution (NMS)71
Auditing PCI Compliance on the Network73
Introduction to PCI Requirements73
PCI Auditing73
Enabling or Disabling PCI Auditing75
Deploying WMS Offload76
Overview of WMS Offload in AirWave76
General Configuration Tasks Supporting WMS Offload in AirWave76
Additional Information Supporting WMS Offload77
Configuring and Using Device Groups78
AirWave Groups Overview80
Viewing All Defined Device Groups81
Configuring Basic Group Settings82
Adding and Configuring Group AAA Servers91
Configuring Group Security Settings92
Configuring Group SSIDs and VLANs96
Configuring Radio Settings for Device Groups100
4 | ContentsDell Network ing W-AirWave 8.0 | User Guide
Page 5
Cisco WLC Group Configuration104
Accessing Cisco WLC Configuration104
Navigating Cisco WLC Configuration104
Configuring WLANs for Cisco WLC Devices105
Defining and Configuring LWAPP AP Groups for Cisco Devices108
Viewing and Creating Cisco AP Groups108
Configuring Cisco Controller Settings108
Configuring Wireless Parameters for Cisco Controllers109
Configuring Cisco WLC Security Parameters and Functions109
Configuring Management Settings for Cisco WLC Controllers110
Configuring Group PTMP Settings110
Configuring Proxim Mesh Radio Settings111
Configuring Group MAC Access Control Lists113
Specifying Minimum Firmware Versions for APs in a Group114
Comparing Device Groups115
Deleting a Group116
Changing Multiple Group Configurations117
Modifying Multiple Devices118
Using Global Groups for Group Configuration120
Discovering, Adding, and Managing Devices124
Device Discovery Overview124
Discovering and Adding Devices124
SNMP/HTTP Scanning124
Adding Networks for SNMP/HTTP Scanning125
Adding Credentials for Scanning125
Defining a Scan Set126
Running a Scan Set127
The Cisco Discovery Protocol (CDP)129
Authorizing Devices to AirWave from APs/Devices > New Page129
Manually Adding Individual Devices129
Adding Devices with the Device Setup > Add Page130
Adding Multiple Devices from a CSV File133
Adding Universal Devices134
Assigning Devices to the Ignored Page134
Unignoring a Device135
Monitoring Devices136
Viewing Device Monitoring Statistics136
Creating CustomFiltered Views137
Understanding the APs/Devices > Monitor Pages for All Device Types138
Monitoring Data Specific to Wireless Devices139
Evaluating Radio Statistics for an AP146
Overview of the Radio Statistics Page146
Viewing Real-Time ARM Statistics146
Issues Summary section147
802.11 Radio Counters Summary147
Radio Statistics Interactive Graphs148
Recent ARM Events Log149
Detected Interfering Devices Table150
Active BSSIDs Table151
Monitoring Data for Mesh Devices151
Dell Network ing W-AirWave 8.0 | User GuideContents | 5
Page 6
Monitoring Data for Wired Devices (Routers and Switches)152
Understanding the APs/Devices > Interfaces Page154
Auditing Device Configuration155
Using Device Folders (Optional)156
Configuring and Managing Devices157
Moving a Device from Monitor Only to Manage Read/Write Mode157
Configuring AP Settings158
Setting a Maintenance Window for a Device165
Configuring Device Interfaces for Switches166
Individual Device Support and Firmware Upgrades169
Troubleshooting a Newly Discovered Down Device172
Using AirWave to Set up Spectrum Analysis174
Spectrum Configurations and Prerequisites174
Setting up a Permanent Spectrum Dell AP Group175
Configuring an Individual AP to run in Spectrum Mode176
Configuring a Controller to use the Spectrum Profile177
Viewing and Adding Templates180
Configuring General Template Files and Variables183
Configuring General Templates183
IOS Configuration File Template184
Device Configuration File on APs/Devices > Audit Configuration Page184
Using Template Syntax185
Using AP-Specific Variables185
Using Directives to Eliminate Reporting of Configuration Mismatches185
Ignore_and_do_not_push Command186
Push_and_exclude Command186
Using Conditional Variables in Templates186
Using Substitution Variables in Templates187
Configuring Templates for Dell Networking W-Instant188
Configuring Templates for AirMesh189
Configuring Cisco IOS Templates190
Applying Startup-config Files190
WDS Settings in Templates190
SCP Required Settings in Templates191
Supporting Multiple Radio Types via a Single IOS Template191
Configuring Single and Dual-Radio APs via a Single IOS Template191
Configuring Cisco Catalyst Switch Templates192
Configuring Symbol Controller / HP WESM Templates192
Configuring a Global Template194
Using RAPIDS and Rogue Classification198
Introduction to RAPIDS198
Viewing Overall Network Health on RAPIDS > Overview198
Setting Up RAPIDS200
RAPIDS Setup200
Basic Configuration200
Classification Options201
6 | ContentsDell Network ing W-AirWave 8.0 | User Guide
Page 7
Containment Options201
Filtering Options202
Additional Settings202
Defining RAPIDS Rules203
Controller Classification with WMS Offload203
Device OUI Score204
Rogue Device Threat Level204
Viewing and Configuring RAPIDS Rules204
Deleting or Editing a Rule207
Recommended RAPIDS Rules207
Using RAPIDS Rules with Additional AirWave Functions208
Viewing Rogues on the RAPIDS > List Page208
Overview of the RAPIDS > Detail Page211
Viewing Ignored Rogue Devices212
Using RAPIDS Workflow to Process Rogue Devices212
Score Override212
Using the Audit Log214
Additional Resources214
Performing Daily Administration in AirWave216
Monitoring and Supporting AirWave with the System Pages216
Using the System > Status Page217
Viewing Device Events in System > Syslog & Traps218
Using the System > Event Log Page219
Triggers and Alerts220
Creating New Triggers220
Viewing, Delivering, and Responding to Triggers and Alerts228
Backing Up AirWave231
Viewing and Downloading Backups231
Running Backup on Demand231
Restoring from a Backup231
Using the System > Configuration Change Jobs Page232
Using the System > Firmware Upgrade Jobs Page232
Using the System > Performance Page233
Monitoring and Supporting WLAN Clients236
Overview of the Clients Pages237
Monitoring Your Network with the Clients > Overview Page238
Monitoring WLAN Users in the Clients > Connected and Clients > All Pages239
Monitoring Rogue Clients With the Clients > Rogue Clients Page243
Supporting Guest WLAN Users With the Clients > Guest Users Page244
Supporting VPN Users with the Clients > VPN Sessions Page247
Supporting RFID Tags With the Clients > Tags Page248
Evaluating and Diagnosing User Status and Issues249
Evaluating User Status with the Clients > Client Detail Page249
Mobile Device Access Control in Clients > Client Detail and Clients > Connected250
Classifying Dell Devices in Client Detail251
Quick Links for Clients on Dell Devices251
Using the Deauthenticate Client Feature252
Viewing a Client’s Association History252
Viewing the Rogue Association History for a Client253
Evaluating Client Status with the Clients > Diagnostics Page253
Dell Network ing W-AirWave 8.0 | User GuideContents | 7
Page 8
Managing Mobile Devices with SOTI MobiControl and AirWave254
Overview of SOTI MobiControl254
Prerequisites for Using MobiControl with AirWave254
Adding a Mobile Device Management Server for MobiControl254
Accessing MobiControl from the Clients > Client Detail Page255
Monitoring and Supporting AirWave with the Home Pages255
Monitoring AirWave with the Home > Overview Page256
Using the Home >AppRF Page258
Using the Home >UCC Page259
Call Quality260
Quality Correlation260
Call Volume260
Devices260
UCC Chart Details260
Viewing the Home >RF Performance Page261
Viewing the Home >RFCapacity Page262
Viewing the Home > Network Deviations Page264
How Standard Deviation is Calculated265
The Home > Search Page266
Accessing AirWave Documentation267
Viewing and Updating License Information267
Configuring Your Own User Information with the Home > User Info Page269
Supporting AirWave Servers with the Master Console271
Using the Public Portal on Master Console272
Adding a Managed AMP with the Master Console273
Using Global Groups with Master Console274
Controller Backups and Restoration274
Using AirWave Failover for Backup275
Navigation Section of AirWave Failover275
Adding Watched AirWave Stations275
Viewing Generated Reports288
Using Custom Reports288
Using the Dell Networking W License Report289
Using the Capacity Planning Report290
Example290
Using the Client Inventory Report292
Example292
Using the Client Session Report294
Using the Configuration Audit Report296
Using the Device Summary Report297
Using the Device Uptime Report299
Using the IDS Events Report300
Using the Inventory Report302
8 | ContentsDell Network ing W-AirWave 8.0 | User Guide
Page 9
Example302
Using the Match Event Report304
Using the Memory and CPU Utilization Report305
Using the Network Usage Report306
Using the New Clients Report308
Using the New Rogue Devices Report309
Using the PCI Compliance Report311
Using the Port Usage Report312
Using the RADIUS Authentication Issues Report314
Using the RF Health Report315
Using the Rogue Clients Report316
Using the Rogue Containment Audit Report318
Using the VPN Session Report318
Emailing and Exporting Reports319
Emailing Reports in General Email Applications319
Emailing Reports to Smarthost320
Exporting Reports to XML, CSV, or PDF320
Floorplan Features327
Mesh View Navigation327
Configuring Flash UI Personal Preferences329
General Flash UI Preferences329
AP Flash UI Preferences330
Clients Flash UI Preferences331
Overlays Flash UI Preferences331
Grid Lines Flash UI Preferences332
Navigation Flash UI Preferences332
Advanced Settings in VisualRF > Setup333
Server Settings334
Location Settings335
Location Calculation Timer Settings336
Attenuation Settings338
Adding a New Attenuation339
VisualRF Resource Utilization339
Planning and Provisioning340
Creating a New Campus340
Creating a New Building340
Creating a Floor Plan342
Editing a Floor Plan Image342
Cropping the Floor Plan Image342
Sizing a Non-CAD Floor Plan343
Dell Network ing W-AirWave 8.0 | User GuideContents | 9
Page 10
Defining Floor Plan Boundaries344
Legacy VisualRF Floor Plan Configuration Options344
Defining Floor Plan Regions345
Adding Region to a New Floor using the Floor Upload Wizard345
Adding a Region to an Existing Floor Plan345
Legacy Region Configuration Settings346
Editing a Planning Region349
Floor Plan Properties349
Adding Deployed Access Points onto the Floor Plan349
Adding Planned APs onto the Floor Plan350
Auto-Matching Planned Devices351
Printing a Bill of Materials Report351
Increasing Location Accuracy352
Adding Exterior Walls353
Defining Stationary Devices354
Fine-Tuning Location Service in VisualRF > Setup355
Decreasing Grid Size355
Enabling Dynamic Attenuation355
Configuring Infrastructure355
Deploying APs for Client Location Accuracy356
Adding Client Surveys357
Using VisualRF to Assess RF Environments359
Viewing a Wireless User’s RF Environment359
Tracking Location History360
Checking Signal Strength to Client Location361
Viewing an AP’s Wireless RF Environment361
Viewing a Floor Plan’s RF Environment362
Viewing a Network, Campus, Building’s RF Environment363
Viewing Campuses, Buildings, or Floors from a List View363
Viewing Campuses, Buildings, or Floors from a Tree View364
Importing and Exporting in VisualRF365
Exporting a campus365
Importing from CAD365
Batch Importing CAD Files365
Requirements365
Pre Processing Steps366
Upload Processing Steps366
Post Processing Steps366
Sample Upload Instruction XML File366
Common Importation Problems367
Importing from a Dell Networking W-Series Controller367
Pre-Conversion Checklist367
Process on Controller367
Process on AirWave367
VisualRF Location APIs368
Sample Device Location Response368
Sample Site Inventory Response368
About VisualRF Plan369
Overview369
Minimum requirements369
10 | ContentsDell Networki ng W-Ai rWav e 8.0 | User Guide
Page 11
VisualRF Plan Installation369
Differences between VisualRF and VisualRF Plan369
Index371
Dell Network ing W-AirWave 8.0 | User GuideContents | 11
Page 12
12 | ContentsDell Networki ng W-Ai rWav e 8.0 | User Guide
Page 13
Chapter 1
Introduction
Thank you for choosing Dell Networking W-AirWave 8.0.AirWave makes it easy and efficient to manage your wireless
network by combining industry-leading functionality with an intuitive user interface, enabling network administrators
and helpdesk staff to support and control even the largest wireless networks in the world.
The User Guide provides instructions for the configuration and operation of Dell Networking W-AirWave. This section
includes the following topics:
l "A Unified Wireless Network Command Center" on page 13
l "Integrating AirWave into the Network and Organizational Hierarchy " on page 15
Refer to the
Dell Networking W-AirWave 8.0 Installation Guide
for information on installing and upgrading AirWave.
A Unified Wireless Network Command Center
Dell Networking W-AirWave 8.0 is the only network management software that offers you a single intelligent console
from which to monitor, analyze, and configure wireless networks in automatic fashion. Whether your wireless network is
simple or a large, complex, multi-vendor installation, AirWave manages it all.
AirWave supports hardware from leading wireless vendors including the following:
l Dell Networking W-Series
l Aruba Networks®
l Avaya™
l Cisco® (Aironet and WLC)
l Enterasys®
l Juniper Networks®
l LANCOM Systems
l Meru Networks®
l Nortel Networks™
l ProCurve™ by HP®
l Proxim®
l Symbol™
l Trapeze™
l Tropos™
and many others.
The components of AirWave are described in the next section.
AirWave Management Platform
The AirWave Management Platform (AirWave) is the centerpiece of AirWave, offering the following functions and
benefits:
l Core network management functionality:
n Network discovery
Dell Network ing W-AirWave 8.0 | User GuideIntroduction | 13
Page 14
n Configuration of APs & controllers
n Automated compliance audits
n Firmware distribution
n Monitoring of every device and user connected to the network
n Real-time and historical trend reports
l Granular administrative access
n Role-based (for example, Administrator contrasted with Help Desk)
n Network segment (for example, Retail Store network contrasted with Corporate HQ network)
l Flexible device support
n Thin, thick, mesh network architecture
n Multi-vendor support
n Current and legacy hardware support
Controller Configuration
AirWave supports global and group-level configuration of Dell Networking W-Series ArubaOS (AOS), the operating
system, software suite, and application engine that operates mobility and centralizes control over the entire mobile
environment. For a complete description of Dell Networking W-Series ArubaOS, refer to the Dell Networking W-SeriesArubaOS User Guide for your specific version.
AirWave consolidates and pushes global controller configurations from within AirWave.
Two pages in AirWave support controller configuration:
l Device Setup > Dell Configuration for global Dell Configuration. This page is available if Use Global Dell
Configuration is set to Yes in AMP Setup > General.
l Groups > Controller Config for group-level configuration.
For additional information that includes a comprehensive inventory of all pages and settings that support Dell
Networking W Configuration, refer to the Dell Networking W-AirWave 8.0 Controller Configuration Guide.
Instant Configuration
Dell Networking W-Instant (Instant) is a system of access points in a Layer 2 subnet. The IAPs are controlled by a single
IAP that serves a dual role as an W-IAP and primary Virtual Controller (VC), eliminating the need for dedicated
controller hardware. This system can be deployed through a simplified setup process appropriate for smaller
organizations, or for multiple geographically dispersed locations without an on-site administrator.
With AirWave, IT can centrally configure, monitor, and troubleshoot Aruba Instant WLANs, upload new software
images, track devices, generate reports, and perform other vital management tasks, all from a remote location.
Starting with AirWave 8.0, a Virtual Controller or Instant AP can authenticate to the AirWave server using a pre-shared
key, or using two-way certificate-based authentication using an SSL certificate sent from AirWave to the Instant device.
Virtual Controllers push data to AirWave via HTTPS. If your enterprise has a security policy that restricts the use of port
443 for inbound communication, you can change the port AirWave uses to communicate with Instant devices.
For additional information that includes a comprehensive inventory of all pages and settings that support Instant
Configuration, refer to the Dell Networking W-Instant in Dell Networking W-AirWave 8.0 Deployment Guide.
VisualRF
VisualRF is a powerful tool for monitoring and managing radio frequency (RF) dynamics within your wireless network,
to include the following functions and benefits:
l Accurate location information for all wireless users and devices
14 | IntroductionDel l Networki ng W-Ai rWav e 8.0 | User Guide
Page 15
l Up-to-date heat maps and channel maps for RF diagnostics
n Adjusts for building materials
n Supports multiple antenna types
l Floor plan, building, and campus views
l Visual display of errors and alerts
l Easy import of existing floor plans and building maps
l Planning of new floor plans and AP placement recommendations
RAPIDS
RAPIDS is a powerful and easy-to-use tool for monitoring and managing security on your wireless network, to include
the following features and benefits:
l Automatic detection of unauthorized wireless devices
l Rogue device classification that supports multiple methods of rogue detection
l Wireless detection:
n Uses authorized wireless APs to report other devices within range.
n Calculates and displays rogue location on VisualRF map.
l Wired network detection:
n Discovers rogue APs located beyond the range of authorized APs/sensors.
n Queries routers and switches.
n Ranks devices according to the likelihood they are rogues.
n Multiple tests to eliminate false positive results.
n Provides rogue discovery that identifies the switch and port to which a rogue device is connected.
Master Console and Failover
The Dell Networking W-AirWave Master Console and Failover tools enable network-wide information in easy-tounderstand presentation, to entail operational information and high-availability for failover scenarios. The benefits of
these tools include the following:
l Provides network-wide visibility, even when the WLAN grows to 50,000+ devices
l Executive Portal allows executives to view high-level usage and performance data
l Aggregated alerts
l Failover
n Many-to-one failover
n One-to-one failover
The Master Console and Failover servers can be configured with a Device Down trigger that generates an alert if
communication is lost. In addition to generating an alert, the Master Console or Failover server can also send email or
NMS notifications about the event.
Integrating AirWave into the Network and Organizational Hierarchy
AirWave generally resides in the NOC and communicates with various components of your WLAN infrastructure. In
basic deployments, AirWave communicates solely with indoor wireless access points (and WLAN controllers over the
wired network. In more complex deployments, AirWave seamlessly integrates and communicates with authentication
servers, accounting servers, TACACS+ servers, LDAP servers, routers, switches, network management servers, wireless
IDS solutions, helpdesk systems, indoor wireless access points, mesh devices. AirWave has the flexibility to manage
Dell Network ing W-AirWave 8.0 | User GuideIntroduction | 15
Page 16
devices on local networks, remote networks, and networks using Network Address Translation (NAT). AirWave
communicates over-the-air or over-the-wire using a variety of protocols.
The power, performance, and usability of AirWave become more apparent when considering the diverse components
within a WLAN. Table 1 itemizes some example network components.
Table 1:
Components of a WLAN
ComponentDescription
Autonomous APStandalone device which performs radio and authentication functions
Thin APRadio-only device coupled with WLAN controller to perform authentication
WLAN ControllerUsed in conjunction with thin APs to coordinate authentication and roaming
NMSNetwork Management Systems and Event Correlation (OpenView, Tivoli, and so forth)
RADIUS
Authentication
RADIUS AccountingAirWave itself serves as a RADIUS accounting client
Wireless GatewaysProvide HTML redirect and/or wireless VPNs
TACACS+ and LDAPUsed to authenticate AirWave administrative users
Routers/SwitchesProvide AirWave with data for user information and AP and Rogue discovery
Help Desk SystemsRemedy EPICOR
Rogue APsUnauthorized APs not registered in the AirWave database of managed APs
RADIUS authentication servers (Funk, FreeRADIUS, ACS, or IAS)
Administrative Roles
The flexibility of AirWave enables it to integrate seamlessly into your business hierarchy as well as your network
topology. AirWave facilitates various administrative roles to match each individual user's role and responsibility:
l A Help Desk user can be given read-only access to monitoring data without being permitted to make configuration
changes.
l A U.S.-based network engineer can be given read-write access to manage device configurations in North America,
but not to control devices in the rest of the world.
l A security auditor can be given read-write access to configure security policies across the entire WLAN.
l NOC personnel can be given read-only access to monitoring all devices from the Master Console.
16 | IntroductionDel l Networki ng W-Ai rWav e 8.0 | User Guide
Page 17
Configuring AirWave
This section contains the following procedures to deploy initial AirWave configuration:
l "Formatting the Top Header" on page 17
l "Customizing Columns in Lists" on page 19
l "Resetting Pagination Records" on page 20
l "Using the Pagination Widget" on page 21
l "Using Export CSV for Lists and Reports" on page 21
l "Defining Graph Display Preferences" on page 21
l "Customizing the Dashboard" on page 22
l "Setting Severe Alert Warning Behavior" on page 27
l "Defining General AirWave Server Settings" on page 28
l "Defining AirWave Network Settings" on page 39
l "Creating AirWave User Roles" on page 43
l "Creating AirWave Users" on page 41
l "Configuring Login Message, TACACS+, RADIUS, and LDAP Authentication" on page 48
l "Enabling AirWave to Manage Your Devices" on page 58
l "Setting Up Device Types" on page 64
l "Configuring Cisco WLSE and WLSE Rogue Scanning" on page 65
l "Configuring ACS Servers" on page 70
l "Integrating AirWave with an Existing Network Management Solution (NMS) " on page 71
l "Auditing PCI Compliance on the Network" on page 73
l "Deploying WMS Offload" on page 76
Chapter 2
Additional configurations are available after basic configuration is complete.
Before You Begin
Remember to complete the required configurations in this chapter before proceeding. Dell support remains available to
you for any phase of AirWave installation.
Formatting the Top Header
The Dell Networking W-AirWave interface centers around a horizontal row of tabs with nested subtabs.
A row of statistics hyperlinks called Top Header Stats above the tabs represents commonly used subtabs. These
hyperlinks provide the ability to view certain key statistics by mousing over, such as number and type of Down devices,
and serve as shortcuts to frequently viewed subtabs. Figure 1 illustrates the navigation bar. More information on
hyperlinks, tabs, and subtabs is a available in the Dell Networking W-AirWave 8.0 Installation Guide.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 17
Page 18
Figure 1:Navigation Bar Displaying Down Device Statistics
You can control the Top Header Stats links that appear from the AMP Setup > General page, as described in "Defining
General AirWave Server Settings" on page 28. Top Header Stats can also be customized for individual users on the
Home > User Info page. There you can select the statistics to display for certain device types and override the AMP
Setup page.
All possible display options for users are show in Figure 2.
A confirmation message does not appear when you make modifications to the Top Header Stats.
Refer to "Configuring Your Own User Information with the Home > User Info Page" on page 269 for more information.
Figure 2:Home > User Info Top Header Stats Display Options
You can also set the severity level of critical alerts displayed for a user role. For details including a description of what
constitutes a severe alert, see "Setting Severe Alert Warning Behavior" on page 27.
18 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 19
Customizing Columns in Lists
Customize the columns for any list table selecting Choose Columns, as shown in the figure below. Use the up/down
arrows to change the order in which the column heads appear.
Figure 3:Choose Columns Drop down List
More information about the universal list elements is available in "Common List Settings" in the Dell Networking WAirWave 8.0 Installation Guide.
You can also control which column heads appear for each user role. Navigate to the Home > User Info page, and then
select Yes in the Customize Columns for Other Roles field. This exposes the Choose Columns for Roles drop down
menu in all tables shown in Figure 4.
The first column shows the user roles that were customized, if any. The second column allows you to establish left-toright columns and order them using the arrows.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 19
Page 20
Figure 4:Table with Choose Columns for Roles Menu Selected
Resetting Pagination Records
To control the number of records in any individual list, select the link with Records Per Page mouseover text at the top
left of the table, as shown in Figure 5. AirWave remembers each list’s pagination preferences.
Figure 5:Records Per Page Drop Down Menu
To reset all Records Per Page preferences, click the Reset reset button in the Display Preferences section of the Home >
User Info page, as shown in Figure 6.
Figure 6:Home > User Info > Display Preferences section
20 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 21
Using the Pagination Widget
The pagination widget is located at the top and bottom of every list table, as shown in Figure 7.
Figure 7:Pagination Widget
Use the down arrow next to Page 1 to see all the page numbers for that table in a drop down menu. From here, you can
jump to any portion of the table. Select the > symbol to jump to the next page, and >| to jump to the last page.
Using Export CSV for Lists and Reports
Some tables have a Export CSV setting you can use export the data as a spreadsheet. See Figure 8 for an example of a
list with the Export CSV option selected.
Figure 8:List with CSV Export Selected
AirWave also enables CSV exporting of all report types. For more information, see "Exporting Reports to XML, CSV, or
PDF" on page 320.
Defining Graph Display Preferences
Many of the graphs in AirWave are Highcharts, which allow you to adjust the graph settings attributes as shown in
Figure 9.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 21
Page 22
Figure 9:Interactive Graphs on the Home > Overview Page
Highcharts are built with JavaScript, so the graphs can run directly through your browser without the need for additional
client-side plugins. This makes it possible to view your AirWave charts on a mobile device.
These charts can be used and customized as follows.
l A Time Range selector in the upper right portion of the charts (including pop-up charts) allows you to select a
common or a custom date range for your data. The preconfigured ranges for AirWave charts are current 2 hours, 1
day, 1 week, and 1 year.
l Drop-down menus are available for viewing client and usage for specific SSIDs and/or all SSIDs. A search field is
available to help you quickly find a specific WLAN.
You can select up to six options from each drop-down menu. Once selected, each option will appear in the colorcoded legend below the chart. Clicking on an option in this legend will disable or enable that information in the
graph. Note that even if an option is disabled from viewing in the graph, that option will still remain in the legend
until you deselect it from the drop-down menu.
l Max and Avg options allow you to change the chart view to show the maximum or average client and usage
information.
l Plot points display within the chart at varying intervals, depending on the selected time range. Tooltips and a plot
line appear as you hover over each plot point, showing you the detailed information for that specific time.
l Click on any chart to view a pop-up version. In this version, you can easily zoom in on a range of data by using your
mouse to drag a rectangle in the chart. While you are zoomed in, a Reset zoom button appears, enabling you to
return to the original view. The pop-up charts also include a legend that displays the Last, Min, Max, and Avg values
for the selected graph.
l Some charts include a drop-down option next to the graph title. For example, on the APs/Devices > Monitor page
for Radio Statistics, you can select the drop-down beside the graph title to view a graph for Client, Usage, Radio
Channel, Radio Noise, Radio Power, Radio Errors, and 802.11 Counters information. In prior versions of AirWave,
these graphs appeared as separate tabs.
Customizing the Dashboard
You can rearrange or remove widgets appearing on the Home > Overview dashboard by selecting the Customize link to
the right of this window, as shown in Figure 10.
Figure 10:Customize Button on the Home > Overview Page
22 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 23
The Customize workspace that appears is shown in Figure 11.
Figure 11:Customize Overview Page
Adding Widgets
The Home > Overview page displays the currently selected widgets (charts/graphs). You can change the widgets on this
page by selecting the Customize link in the upper-right corner.
The Available Widgets section on the left holds all available graphical elements (widgets). Select any blue widget tile
with a verbal description enclosed, and it immediately turns into a graphical element with a description.
Drag the widgets you want to appear on the Home > Overview dashboard across to the gridlines and arrange them in
the right section, within the gridlines. A widget snaps back to the nearest available gridline if you drop it across two or
more lines and turns red if you attempt to place it over gridlines already occupied by widgets. Widgets with a green top
banner are properly placed and set to appear when you select Save. Widgets that remain in the left section will not
appear; although they can be reinstated by selecting Restore Defaults.
Available Widgets
Table 2 describes the list of available widgets along with a description for each. Note that when a widget is enabled, the
information that displays can vary based on the user’s permission level. Certain roles, for example, limit the top folder
that a user can view.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 23
Page 24
Table 2:
Available Widgets
WidgetDescription
The Client graph is enabled by default and, by default, shows the maximum
number of attached clients over the last two hours. Select the Show All link to
view more specific client information on the graph, such as the total and
average clients for a specific SSID, the maximum VPN sessions, etc. The
available check boxes within this graph are determined by the SSIDs that
AirWave is aware of from polling the device.
Client/Usage Graphs
Monitoring and Config Pie
The Usage graph is enabled by default and, by default, shows the average
bits-per-second in/out information and average VPN in/out information.
Select the Show All link to view usage information for specific SSIDs. The
available checkboxes within this graph are determined by by the SSIDs that
AirWave is aware of from polling the device.
The information in these graphs is color coded to match the selected check
boxes.
The Monitoring Status pie shows the percentage of total devices that are up
and the number and percentage of devices that are currently down. Clicking
within this pie chart takes you to the APs/ Devices > Down page.
The Configuration Compliance pie shows the percentage of devices that are
mismatched, good, unknown, and those with auditing disabled. It also
provides a summary of the total number of devices that are mismatched.
Clicking within this pie chart takes you to the APs/Devices > Mismatch page.
These pie charts are enabled by default.
Alert Summary
Quick Links
RAPIDS: Acknowledged
RAPIDS: Classification Pie
The Alert Summary table is enabeld by default and provides the number of
AirWave alerts, IDS events, and RADIUS authentication issues over the last 2
hours, the last 24 hours, and the total since the last AirWavereboot.
l Click on AirWave Alerts to drill down to more detailed alert information.
This information displays in the current page. You can return to the Alert
Summary graph by selecting the Home Overview link.
l Click on IDS Events to drill to more detailed event information. This link
takes you to the RAPIDS > IDS Events page.
l Click on RADIUS Authentication Issues to drill to more detailed RADIUS
authentication information. This information displays in the current page.
You can return to the Alert Summary graph by selecting the Home
Overview link.
The Quick Links section is enabled by default. This section provides the user
with easy navigation to a specific folder, group, report, or common task.
The Acknowledged RAPIDS Devices pie chart shows the percentage of
acknowledged and unacknowledged RAPIDS that the user has visibility into.
The RAPIDS information appears from the moment a rogue is discovered
until it is deleted. Ignored rogues, however, are not included in this chart.
This chart also displays on the RAPI DS > Overview page.
The RAPIDS: Classification Pie shows the percentage of devices classified
as Valid, Suspected Neighbor, Suspected Valid, Suspected Rogue, Rogue,
and Neighbor that are attached to AirWave. The RAPIDS information appears
from the moment a rogue is discovered until it is deleted. Ignored rogues,
however, are not included in this chart.
This pie chart can also be viewed on the RAPIDS > Overview page.
24 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 25
Table 2:
Available Widgets (Continued)
WidgetDescription
The RAPIDS: Classification Summary table shows the number of devices
classified as Valid, Suspected Valid, Neighbor, Suspected Neighbor,
Suspected Rogue, Rogue, and Unclassified that are attached to AirWave. In
RAPIDS: Classification
Summary
IDS Events
RAPIDS: OS Pie
RAPIDS: OS Summary
addition, contained rogue information will appear if Manage rogue AP
containment is set to Yes on the RAPIDS > Setup page.
The RAPIDS information appears from the moment a rogue is discovered
until it is deleted. Note that ignored rogues are not included in this chart.
This table can also be viewed on the RAPIDS > Overview page.
The IDS Event s table shows the number and type of attacks logged by the
intrusion detection system over the last 2 hours, the last 24 hours, and the
total since the last AirWave reboot. This is the same table that displays on the
RAPIDS > Overview page.
The RAPIDS: OS Pie chart shows the top 9 rogue devices by OS, Others,
Unknown, and Not Scanned. The RAPIDS information appears from the
moment a rogue is discovered until it is deleted. Note that ignored rogues are
not included in this chart.
This pie chart can also be viewed on the RAPIDS > Overview page.
The RAPIDS: OS Summary table shows the top 9 rogue devices by OS,
Others, Unknown, and Not Scanned. The RAPIDS information appears from
the moment a rogue is discovered until it is deleted. Note that ignored rogues
are not included in this chart.
This table can also be viewed on the RAPIDS > Overview page.
Top Folders By AP Usage
Top Folders By A Radio
Channel Usage
Top Folders By BG Radio
Channel Usage
This chart lists the folders and the number of APs in each folder whose usage
is greater than the cutoff (or usage threshold). The cutoff represents 75% of
the maximum usage, where the maximum usage is the AP with the highest
usage regardless of the folder in which it resides. The cutoff value is
displayed within the title, and this value can vary. The chart takes into
account approved APs with radios based on the last 24 hours. In addition,
this chart is updated every hour.
This chart shows the folders and the number of A radios (5GHz) in each
folder whose channel usage is greater than the cutoff (or usage threshold) as
measured by Mbps. This cutoff is on the on the AMP Set up > General page
using the Configure Channel Busy Threshold option. If this option is not
configured, then the cutoff is 75% of the ‘maximum,’ where the ‘maximum’
refers to the AP that has the highest usage regardless of the folder in which it
resides. The cutoff value is displayed within the title, and this value can vary.
This chart takes into account approved APs with ‘A’ radios based on the last
24 hours. In addition, this chart is updated every hour.
This chart shows the folders and the number of BG radios (2.4GHz) in each
folder whose channel usage is greater than the cutoff (or usage threshold) as
measured by Mbps. This cutoff is on the on the AMP Set up > General page
using the Configure Channel Busy Threshold option. If this option is not
configured, then the cutoff is 75% of the ‘maximum,’ where the ‘maximum’
refers to the AP that has the highest usage regardless of the folder in which it
resides. The cutoff value is displayed within the title, and this value can vary.
This chart takes into account approved APs with ‘BG’ radios based on the last
24 hours. In addition, this chart is updated every hour.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 25
Page 26
Table 2:
Available Widgets (Continued)
WidgetDescription
This chart shows the folders and the number of A radios (5GHz) in each
folder whose client count is greater than the cutoff. The cutoff represents 75%
Top Folders By A Radio Client
Count
Top Folders By BG Radio
Client Count
Top Clients By Total Traffic
of the ‘maximum,’ where the ‘maximum’ is the radio that has the highest client
count regardless of the folder. The cutoff value is displayed within the title
and can vary. This chart takes into account approved APs with A radios
based on the last 24 hours. In addition, this chart is updated every hour.
This chart shows the folders and the number of BG radios (2.4GHz) in each
folder whose client count is greater than the cutoff. The cutoff represents 75%
of the ‘maximum,’ where the ‘maximum’ is the radio that has the highest client
count regardless of the folder. The cutoff value is displayed within the title
and can vary. This chart takes into account approved APs with BG radios
based on the last 24 hours. In addition, this chart is updated every hour.
The widget looks at currently connected clients as well has client historical
information over the past 24 hours and then displays the top 10 clients with
the must usage. You can click on a MAC address to view more information
about any of the clients that display on this table. This table is updated every
hour.
Clients By AOS Device Type
Clients By Device Type
Clients By Device Mfgr
Clients By Device Model
Clients By Mfgr & Model
Clients By Device OS
Clients By Device OS Detail
Clients By Network Vendor
This pie chart shows the percentage of clients that have attached to AirWave
over the last 24 hours based on the AOS device type.
This pie chart shows the percentage of clients that have attached to AirWave
over the last 24 hours based on the device type (such as a specific operating
system or smart phone type).
This pie chart shows the percentage of clients that have attached to AirWave
over the last 24 hours based on the client manufacturer.
This pie chart shows the percentage of clients that have attached to AirWave
over the last 24 hours based on the device model (such as the smart phone
type).
This pie chart shows the percentage of clients that have attached to AirWave
over the last 24 hours based on the client manufacturer and model.
This pie chart shows the percentage of clients that have attached to AirWave
over the last 24 hours based on the device operating system (such as
Windows or Android).
This pie chart shows the percentage of clients that have attached to AirWave
over the last 24 hours based on the device operating system version (such as
Windows NT 6.1).
This pie chart shows the percentage of clients that have attached to AirWave
over the last 24 hours based on each device’s network interface vendor.
Client Signal Distribution
The Client Signal Distribution chart shows the number of attached devices
that have a signal quality within a set of ranges.
Search Preferences
For each user, you can customize the search results to display only desired categories of matches on the Home > User
Info page. Go to the Search Preferences section and select the desired search type from the Search Method drop down.
26 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 27
This search type will be used when a user types an entry in the Search field and then clicks Enter without selecting a
specific search type.
l Use System Defaults: The Search Method will be based on the system-wide configuration setting. This method is
configured on the AMP Setup > General page.
l Active clients + historical clients (exact match) + all devices: Commonly referred to as Quick Search, this looks at all
active and historical clients and all devices. This search is not case-sensitive. The results of this search display in a
popup window rather than on the Home > Search page. This popup window includes top-level navigation that
allows you to filter the results based on Clients, APs, Controllers, and Switches.
l Active clients + all categories: This looks at all active clients (not historical) and all categories. This search is not
case-sensitive. This search returns results on partial matches for usernames if that username is included in either the
beginning or the end of a user name string
l Active clients + all categories (exact match): This looks at all active clients (not historical) and all categories. This
search returns only matches that are exactly as typed (IP, username, device name, etc). This search is case-sensitive for
all searched fields.
l Active + historical clients + all categories: This looks at all active and historical clients and all categories. This
search is not case-sensitive.
l Active + historical clients + all categories (exact match): This looks at all active and historical clients and all
categories. This search returns only matches that are exactly as typed (IP, username, device name, etc). This search is
case-sensitive for all searched fields.
A confirmation message does not appear after you make modifications to Search Preferences.
Figure 12:Home > User Info Search Preferences
Setting Severe Alert Warning Behavior
You can control the alert levels you can see on the Alerts top header stats link from the Home > User Info page. The
Severe Alert Threshold determines the severity level that results in a Severe Alert. Specify either Normal, Warning,
Minor, Major, or Critical as the severity alert threshold value. These threshold values are tied to triggers that are created
on the System > Triggers page. For example, if a trigger is defined to result in a Critical alert, and if the Severe Alert
Threshold here is defined as Major, then the list of Severe Alerts will include all Major and Critical alerts. Similarly, if
this value is set to Normal, which is the lowest threshold, then the list of Severe Alerts will include all alerts.
When a Severe Alert exists, a new component named Severe Alerts will appear at the right of the Status field in bold
red font. This field is hidden if there are no Severe Alerts. In addition, only users who are enabled for viewing Severe
Alerts on the Home > User Info page can see severe alerts.
The Severe Alert Threshold drop down menu, located in the Top Header Stats section of the Home > User Info page
is shown in Figure 13.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 27
Page 28
Figure 13:Home > User Info > Severe Alert Threshold Drop Down Menu
Defining General AirWave Server Settings
This section describes all pages accessed from the AMP Setup tab. It also describes two pages in the Device Setup tab:
the Communication and Upload Files pages. After required and optional configuration tasks in this chapter are
complete, continue to later chapters in this document to create and deploy device groups and device configuration and
discovery on the network.
Refer to the following topics for configuration information:
l "AMP Setup > General" on page 28
l "Defining AirWave Network Settings" on page 39
l "AirWave User Roles" on page 43
l "Creating AirWave Users" on page 41
l "Configuring Login Message, TACACS+, RADIUS, and LDAP Authentication" on page 48
l "Enabling AirWave to Manage Your Devices" on page 58
l "Setting Up Device Types" on page 64
AMP Setup > General
The first step in configuring AirWave is to specify the general settings for the AirWave server. Figure 14 illustrates the
AMP Setup > General page. Select Save when the General Server settings are complete and whenever making
subsequent changes. These settings are applied globally across the product (for all users).
28 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 29
Refer to the following sections for information about the available settings:
l "General Settings" on page 29
l "Automatic Authorization Settings" on page 30
l "Top Header Settings" on page 31
l "Search Method" on page 31
l "Home Overview Preferences" on page 31
l "Display Settings" on page 31
l "Device Configuration Settings" on page 32
l "AMP Features" on page 33
l "External Logging Settings" on page 33
l "Historical Data Retention Settings" on page 34
l "Firmware Upgrade Defaults" on page 36
l "Additional AMP Services" on page 36
l "Performance Settings" on page 38
Figure 14:AMP Setup > General Page Illustration (Partial View)
General Settings
Browse to the AMP Setup > General page, locate the General section, and enter the information described in Table 3:
Table 3:
SettingDefaultDescription
System Name
Default Group
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 29
AMP Setup >General > General Section Fields and Default Values
Defines your name for your AirWave server, with a maximum limit of 20
alphanumeric characters.
Sets the device group that this AirWave server uses as the default for
Access
Points
device-level configuration. Select a device group from the drop-down
menu. A group must first be defined on the Groups > List page to appear
in this drop-down menu. For additional information, refer to "Configuring
and Using Device Groups" on page 78.
Page 30
Table 3:
AMP Setup >General > General Section Fields and Default Values (Continued)
SettingDefaultDescription
This setting defines the interval of queries which compares actual device
settings to the Group configuration policies stored in the AirWave
Device
Configuration
Audit Interval
Daily
database. If the settings do not match, the AP is flagged as mismatched
and AirWave sends an alert via email, log, or SNMP.
NOTE: Enabling this feature with a frequency of Daily or more frequently
is recommended to ensure that your AP configurations comply with your
established policies. Specifying Never is not recommended.
Automatically
repair
misconfigured
devices
Send debugging
messages
Nightly
Maintenance Time
(00:00 - 23:59)
Disabled
Enabled
04:15
If enabled, this setting automatically reconfigures the settings on the
device when the device is in Manage mode and AirWave detects a
variance between actual device settings and the Group configuration
policy in the AirWave database.
If enabled, AirWave automatically emails any system errors to Dell
support at dell.com/support to assist in debugging.
Specifies the local time of day AirWave should perform daily
maintenance. During maintenance, AirWave cleans the database,
performs backups, and completes a few other housekeeping tasks. Such
processes should not be performed during peak hours of demand.
Automatic Authorization Settings
On the AMP Setup > General page, locate the Automatic Authorization section. These settings allow you to control
the conditions by which devices are automatically authorized into AP groups and folders. AirWave validates the Folder
and Group to ensure that both settings have been set to valid drop down options. Table 4 describes the settings and
default values in this section.
Table 4:
SettingDefaultDescription
Add New
Controllers and
Autonomous
Devices Location
AMP Setup > General > Automatic Authorization Fields and Default Values
Globally add new controllers and autonomous devices to:
l The New Device List (located in APs/Devices > New).
l The same folder and group as the discovering device.
New Device List
l The same group and folder of their closest IP neighbor on the
same subnet.
l Choose a group and folder. If you select this option, enter the
folder/group in the Auto Authorization G roup and Auto
Authorization F older fields that display.
NOTE: This setting can be overridden in Groups > Basic.
Globally add new thin APs to:
l The New Devices list.
l The same folder and group as the discovering device.
Add New Thin APs
Location
New Device List
l The same group and folder of their closest IP neighbor on the
same subnet.
l Choose a group and folder. If you select this option, enter the
folder/group in the Auto Authorization G roup and Auto
Authorization F older fields that display.
NOTE: This setting can be overridden in Groups > Basic.
Automatically
Authorized Virtual
Controller Mode
30 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Manage
Read/Write
Specify whether Virtual Controller mode for Instant APs will be in
Manage Read/Write mode or Monitor Only mode.
Page 31
Top Header Settings
On the AMP Setup > General page, locate the Top Header section to select the Top Header Stats to be displayed at the
top of the interface.
Search Method
On the AMP Setup > General page, locate the Search Method section. Select one of the following drop down options
as the system-wide default search method. This default search type will be used when a user types an entry in the Search
field and then clicks Enter without selecting a specific search type.
l Active clients + historical clients (exact match) + all devices: Commonly referred to as Quick Search, this looks at all
active and historical clients and all devices. This search is not case-sensitive. The results of this search display in a
popup window rather than on the Home > Search page. This popup window includes top-level navigation that
allows you to filter the results based on Clients, APs, Controllers, and Switches.
l Active clients + all categories: This looks at all active clients (not historical) and all categories. This search is not
case-sensitive.
l Active clients + all categories (exact match): This looks at all active clients (not historical) and all categories. This
search returns only matches that are exactly as typed (IP, username, device name, etc). This search is case-sensitive for
all searched fields.
l Active + historical clients + all categories: This looks at all active and historical clients and all categories. This
search is not case-sensitive.
l Active + historical clients + all categories (exact match): This looks at all active and historical clients and all
categories. This search returns only matches that are exactly as typed (IP, username, device name, etc). This search is
case-sensitive for all searched fields.
Per-user search preferences can be set in the Home > User Info page; refer to "Search Preferences" on page 26.
Home Overview Preferences
On the AMP Setup > General page, locate the Home Overview Preferences section. Table 5 describes the settings and
default values in this section.
Table 5:
AMP Setup > General > Home Overview Preferences Fields and Default Values
SettingDefaultDescription
Configure Channel
Busy Threshold
Channel Busy
Threshold (%)
Yes
n/a
Whether you want to configure the threshold at which a channel is
considered to be busy at the Top Folders By Radio Channel Usage
Overview widget.
The threshold percent at which the radio channel is considered busier than
normal. This field is only available if the Configure Channel Busy Threshold
setting is Yes.
Display Settings
On the AMP Setup > General page, locate the Display section and select the options to appear by default in new
device groups.
Changes to this section apply across all of AirWave. These changes affect all users and all new device groups.
Table 6 describes the settings and default values in this section.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 31
Page 32
Table 6:
AMP Setup > General > Display Fields and Default Values
SettingDefaultDescription
Sets AirWave to use fully qualified domain names for APs instead of the AP
name. For example, ‘testap.yourdomain.com; would be used instead of
‘testap.’ Select one of the following options:
l Don’t use FQDN - This default value specifies that the fully qualified
APFully Qualified
Domain Name
Options
Show vendorspecific device
settings for
No
All Devices
domain name will not be used.
l Use AP Name with FQDN - The AP name will prepend the FQDN, for
example “somehostname (my.hostname.com).” Note that if the AP name
is not present, then the FQDN will still appear in parenthesis.
l Use only FQDN - Only the fully qualified domain name will be used.
NOTE: This option is supported only for Cisco IOS, Dell Networking WSeries, Aruba Networks, and Alcatel-Lucent devices.
Displays a drop-down menu that determines which Group tabs and options
are viewable by default in new groups, and selects the device types that
use fully qualified domain names. This field has three options, as follows:
l All devices—When selected, AirWave displays all Group tabs and setting
options.
l Only devices on this AMP—When selected, AirWave hides all options
and tabs that do not apply to the APs and devices currently on AirWave.
l Selected device type—When selected, a new field appears listing many
device types. This option allows you to specify the device types for
which AirWave displays group settings. You can override this setting.
Look up device
and wireless user
hostnames
Yes
Enables AirWave to look up the DNS for new user hostnames. This setting
can be turned off to troubleshoot performance issues.
Defines the length of time, in hours, for which a DNS server hostname
remains valid on AirWave, after which AirWave refreshes DNS lookup:
DNS Hostname
Lifetime
Device
Troubleshooting
Hint
24 hours
N/A
l 1 hour
l 2 hours
l 4 hours
l 12 hours
l 24 hours
The message included in this field is displayed along with the Down if a
device’s upstream device is up. This applies to all APs and controllers but
not to routers and switches.
Device Configuration Settings
Locate the Device Configuration section and adjust the settings. Table 7 describes the settings and default values of this
section.
Table 7:
SettingDefaultDescription
Guest User
Configuration
AMP Setup > General > Device Configuration Section Fields and Default Values
Enables or prevents guest users to/from pushing configurations to
Disabled
devices. Options are Disabled (default), Enabled for Devices in
Manage(Read/W rit e), Enabled for all Devices.
32 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 33
Table 7:
AMP Setup > General > Device Configuration Section Fields and Default Values (Continued)
SettingDefaultDescription
When Yes is selected, you can enable the ArubaOS WMS offload
Allow WMS Offload
configuration in
monitor-only mode
No
feature on the Groups > Basic page for WLAN switches in Monitor Only
mode. Enabling WMS offload does not cause a controller to reboot.
This option is supported only for Aruba and Dell Networking W-Series
devices.
Allow disconnecting
users while in
monitor-only mode
Use Global Dell
Configuration
No
No
Sets whether you can deauthenticate a user for a device in monitor-
only mode. If set to No, the Deauthenticate Client button for in a Clients
> Client Detail page is enabled only for Managed devices.
Enables Dell Networking W configuration profile settings to be globally
configured and then assigned to device groups. If disabled, settings
can be defined entirely within Groups > Controller Configinstead of
globally.
NOTE: Changing this setting may require importing configuration on
your devices. When an existing Dell Networking W configuration setup
is to be converted from global to group, follow these steps:
1. Set all the devices to Monitor Only mode before setting the flag.
2. Each device Group will need to have an import performed from the
Audit page of a controller in the AMP group.
3. All of the thin APs need to have their settings imported after the
device group settings have finished importing.
4. If the devices were set to Monitor Only mode, set them back to
Managed mode.
AMP Features
Locate the AMPFeatures section and adjust settings to enable or disable VisualRF and RAPIDS. Table 8 describes these
settings and default values.
Table 8:
AMP Setup Setup > General > AMP Features Fields and Default Values
SettingDefaultDescription
Display VisualRFNoEnable or disable the VisualRF navigation tab.
Display RAPIDSNoEnable or disable the RAPI DS navigation tab.
Restrict access to following pages to users with the AMP Administration role
only:
Hide setup pages
from non-admin
users
Allow role based
report visibility
Yes
Yes
l VisualRF > Setup
l AMP Setup > NMS
l RAPIDS > Score Override
l RAPIDS > Rules
l RAPIDS > Setup
l System > Triggers
Enable or disable role-based reporting in AMP. When disabled, reports can
only be generated with by-subject visibility.
External Logging Settings
Locate the External Logging section and adjust settings to send audit and system events to an external syslog server.
Table 9 describes these settings and default values. You can also send a test message using the Send Test Message
button after enabling any of the logging options.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 33
Page 34
Table 9:
AMP Setup > General > External Logging Section Fields and Default Values
SettingDefaultDescription
Enter the IP address of the syslog server. Note that this field is hidden if both
Syslog ServerN/A
Syslog Port514
"Include event log messages" and "Include audit log messages" are set to
No.
Enter the port of the syslog server. Note that this field is hidden if both
"Include event log messages" and "Include audit log messages" are set to
No.
Include event log
messages
Event log facilitylocal1
Include audit log
messages
Audit log facilitylocal1
Send Test MessageN/A
NoSelect Yes to send event log messages to an external syslog server.
Select the facility for the event log from the drop-down menu. This field is only
available if the "Include event log messages" setting is Yes.
NoSelect Yes to send audit log messages to an external syslog server.
Select the facility for the audit log from the drop-down menu. This field is only
available if the "Include audit log messages" setting is Yes
If messaging is enabled and a server and port are configured, click this
button to send a test message. Upon completion, a message will appear at
the top of this page indicating that the message was sent successfully.
Historical Data Retention Settings
Locate the Historical Data Retention section and specify the number of days you want to keep client session records
and rogue discovery events. Table 10 describes the settings and default values of this section. Many settings can be set
to have no expiration date.
Table 10:
SettingDefaultDescription
AMP Setup > General > Historical Data Retention Fields and Default Values
Inactive Client and
VPN User Data (01500 days, zero
disables)
Client Association
and VPN Session
History (0-550 days,
zero disables)
Tag History (0-550
days, zero disables)
Rogue AP
Discovery Events
(14-550 days, zero
disables)
Reports (0-550
days, zero disables)
34 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
60
14
14Sets the number of days AirWave retains location history for Wi-Fi tags.
14
60
Defines the number of days AirWave stores basic information about inactive
clients and VPN users. A shorter setting of 60 days is recommended for
customers with high user turnover such as hotels. The longer you store
inactive user data, the more hard disk space you require.
Defines the number of days AirWave stores client and VPN session records.
The longer you store client session records, the more hard disk space you
require.
Defines the number of days AirWave stores Rogue Discovery Events. The
longer you store discovery event records, the more hard disk space you
require.
Defines the number of days AirWave stores Reports. Large numbers of
reports, over 1000, can cause the Reports > Generated page to be slow to
respond.
Page 35
Table 10:
AMP Setup > General > Historical Data Retention Fields and Default Values (Continued)
SettingDefaultDescription
Automatically
Acknowledge Alerts
(0-550 days, zero
disables)
Acknowledged
Alerts(0-550 days,
zero disables)
Radius/ARM/IDS
Events(0-550 days,
zero disables)
Archived Device
Configurations (0100, zero disables)
Archive device
configs even if they
only have rogue
classifications
Guest Users (0-550
days, zero disables)
Inactive SSIDs (0550 days, zero
disables)
14
60
14
10
No
30
425
Defines automatically acknowledged alerts as the number of days AirWave
retains alerts that have been automatically acknowledged. Setting this value to
0 disables this function, and alerts will never expire or be deleted from the
database.
Defines the number of days AirWave retains information about acknowledged
alerts. Large numbers of Alerts, over 2000, can cause the System > Alerts
page to be slow to respond.
Defines the number of days AirWave retains information about RADIUS, ARM,
and IDS events. Setting this value to 0 disables this function, and the
information will never expire or be deleted from the database.
Defines the number of configurations that will be retained for archived
devices.. Whether rogue information is included depends on the setting of the
Archive device configs even if they only have rogue classificat ions setting.
Sets whether to archive device configurations even if the device only has
rogue classifications.
Sets the number of days that AirWave is to support any guest user. A value of 0
disables this function, and guest users will never expire or be deleted from the
AirWave database.
Sets the number of days AirWave retains historical information after AirWave
last saw a client on a specific SSID. Setting this value to 0 disables this
function, and inactive SSIDs will never expire or be deleted from the database.
Inactive Interfaces
(0-550 days, zero
disables)
Interface Status
History (0-550 days,
zero disables)
Interfering Devices
(0-550 days, zero
disables)
Device Events
(Syslog, Traps)(131 days)
Mesh Link History
(0-550 days)
Sets the number of days AirWave retains inactive interface information after
425
425
14
2
30Sets the number of days AirWave retains historical information for mesh links.
the interface has been removed or deleted from the device. Setting this value
to 0 disables this function, and inactive interface information will never expire
or be deleted from the database.
Sets the number of days AirWave retains historical information on interface
status. Setting this value to 0 disables this function.
Sets the number of days AirWave retains historical information on interfering
devices. Setting this value to 0 disables this function.
Sets the number of days AirWave retains historical information on device
events such as syslog entries and SNMP traps. Setting this value to 0 disables
this function. Refer to "Viewing Device Events in System > Syslog & Traps" on
page 218.
NOTE: If your data table has more than 5 million rows, AirWavewill truncate
the device event retention data. In this case, the "number of days" setting
becomes "number of hours."
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 35
Page 36
Table 10:
AMP Setup > General > Historical Data Retention Fields and Default Values (Continued)
SettingDefaultDescription
Device Uptime (0120 months, zero
disables)
Client Data
Retention Interval
(1-425 days)
60
425Sets the number of days AirWave retains historical information for clients.
Sets the number of months AirWave retains historical information on device
uptime. Setting this value to 0 disables this function.
Firmware Upgrade Defaults
Locate the Firmware Upgrade Defaults section and adjust settings as required. This section allows you to configure the
default firmware upgrade behavior for AirWaveTable 11 describes the settings and default values of this section.
Table 11:
SettingDefaultDescription
Allow firmware
upgrades in
monitor-only mode
Maximum
Interleaved Jobs (1-
20)
AMP Setup > General > Firmware Upgrade Defaults Fields and Default Values
If Yes is selected, AirWave upgrades the firmware for APs in Monitor Only
mode. When AirWave upgrades the firmware in this mode, the desired
No
20
configuration are not be pushed to AirWave. Only the firmware is applied.
The firmware upgrade may result in configuration changes AirWave does
not correct those changes when the AP is in Monitor Only mode.
Defines the number of jobs AirWave runs at the same time. A job can
include multiple APs. When jobs are started by multiple users, AirWave will
interleave upgrades so that one user's job does not completely block
another’s.
Maximum
Interleaved Devices
Per Job (1-1000)
Failures before
stopping (0-20, zero
disables)
20
1
Defines the number of devices that can be in the process of upgrading at the
same time. Within a single job, AirWave may start the upgrade process for
up to this number of devices at the same time. However, only one device will
be actively downloading a firmware file at any given time.
Sets the default number of upgrade failures before AirWave pauses the
upgrade process. User intervention is required to resume the upgrade
process. Setting this value to 0 disables this function.
Additional AMP Services
Locate the AdditionalAMP Services section, and adjust settings as required. Table 12 describes the settings and default
values of this section.
Table 12:
SettingDefaultDescription
Enable FTP ServerNo
AMP Setup > General > Additional AMP Services Fields and Default Values
Enables or disables the FTP server on AirWave. The FTP server is only
used to manage Aruba AirMesh and Cisco Aironet 4800 APs. Best practice
is to disable the FTP server if you do not have any supported devices in the
network.
36 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 37
Table 12:
AMP Setup > General > Additional AMP Services Fields and Default Values (Continued)
SettingDefaultDescription
Enables or disables the RTLS Collector, which is used to allow
ArubaOScontrollers to send signed and encrypted RTLS (real time locating
system) packets to VisualRF-- in other words, AirWave becomes the acting
RTLS server. The RTLS server IP address must be configured on each
controller. This function is used for VisualRF to improve location accuracy
and to locate chirping asset tags. This function is supported only for Dell
Networking W-Series, Alcatel-Lucent, and Aruba Networks devices.
Enable RTLS
Collector
Use embedded Mail
Server
No
Yes
If Yes is specified, the following additional fields appear. These
configuration settings should match the settings configured on the
controller:
l RTLS Port—Specify the port for the AirWave RTLS server.
l RTLS Username—Enter the user name used by the controller to decode
RTLS messages.
l RTLS Password—Enter the RTLS server password that matches the
controller’s value.
l Confirm RTLS Password—Re-enter the RTLS server password.
Enables or disables the embedded mail server that is included with
AirWave. If Yes is specified, then enter information for an optional mail relay
server.
This field supports a Send T est Email button for testing server functionality.
Clicking this button prompts you with To and F rom fields in which you must
enter valid email addresses.
Process user
roaming traps from
Cisco WLC
Enable AMON data
collection
Enable AppRF Data
Collection
AppRF Storage
GibaBytes Allocated
(Greater than or
equal to 2 GiB)
Yes
Yes
Yes
50
Whether AirWave should parse client association and authentication traps
from Cisco WLC controllers to give real time information on users connected
to the wireless network.
Allows AirWave to collect enhanced data from Dell Networking W devices
on certain firmware versions. See the
Practices Guide
on dell. com/ support/manuals for more details.
Dell Networking W-AirWave Best
If AMON is enabled for a controller, you can enable this flag to instruct
AirWave to collect AppRF data from the controller. If this is enabled, then the
Home > AppRF page will display.
If AppRF Data Collection is enabled, specify the amount of storage to
allocate.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 37
Page 38
Table 12:
AMP Setup > General > Additional AMP Services Fields and Default Values (Continued)
SettingDefaultDescription
Prefer AMON is a configuration setting which causes AirWave to use an
AMON feed to obtain client monitioring information from a controller rather
than polling it via SNMP. When you enable this setting, values such as AP
lists and rogue AP lists are still polled via SNMP, but the bulk of client client
monitoring information is delivered via AMON.
Before enabling the Prefer AMON setting, please note the following:
Prefer AMONvs
SNMP Polling
Enable Syslog and
SNMP Trap
Collection
SNMP
Polling
Yes
l When Prefer AMON is enabled, the controller must be configured to
send AMON to AirWave.
l The network path from the controller to the AirWave server must allow
traffic on UDP port 8211.
l The controller routinely sends AMON in large UDP packets, (up to 30K
bytes). Before enabling this setting, ensure the network path from the
controller to AirWave can pass such large packets intact.
l This setting should only be used in a network environment with low
levels of UDPpacket loss, as the loss of a single Ethernet frame will
potentially result in the loss of up to 30K bytes worth of data.
This option specifies whether traps used to detect roaming events, auth
failures, AP up/down status, and IDS events will still be collected if they are
sent by managed devices.
Performance Settings
Locate the Performance section. Performance tuning is unlikely to be necessary for many AirWave implementations,
and likely provides the most improvements for customers with extremely large Pro or Enterprise installations. Please
contact Dell support at dell.com/support if you think you might need to change any of these settings. Table 13 describes
the settings and default values of this section.
Table 13:
SettingDefaultDescription
AMP Setup> General > Performance Fields and Default Values
Monitoring
Processes
Maximum number
of configuration
processes
Maximum number
of audit processes
SNMP Fetcher
Count (2-6)
Optional setting configures the throughput of monitoring data.
Based on the
number of
cores for
your server
5
3
2Specify the number of SNMPv2 fetchers.
Increasing this setting allows AirWave to process more data per
second, but it can take resources away from other AirWave
processes. Contact Dell support at dell.com/support if you think you
might need to increase this setting for your network. Also note that the
value range varies based on the number of available process cores.
Increases the number of processes that are pushing configurations to
your devices, as an option. The optimal setting for your network
depends on the resources available, especially RAM. Contact Dell
support at dell.com/support if you think you might need to increase
this setting for your network.
Increases the number of processes that audit configurations for your
devices, as an option. The optimal setting for your network depends
on the resources available, especially RAM. Contact Dell support at
dell.com/supportif you are considering increasing this setting for your
network.
38 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 39
Table 13:
AMP Setup> General > Performance Fields and Default Values (Continued)
SettingDefaultDescription
Verbose Logging
of SNMP
Configuration
SNMP Rate
Limiting for
Monitored Devices
RAPIDS
Processing Priority
RAPIDS custom
process limit (1-
16)
No
No
Low
1 when
Custom is
specified for
the RAPIDS
Processing
Priority.
Enables or disables logging detailed records of SNMP configuration
information.
When enabled, AirWave fetches SNMP data more slowly, potentially
reducing device CPU load.
This setting is used for networks containing legacy controllers not
available through Dell. Dell recommends not enabling this setting.
Defines the processing and system resource priority for RAPIDS in
relation to AirWave as a whole.
When AirWave is processing data at or near its maximum capacity,
reducing the priority of RAPIDS can ensure that processing of other
data (such as client connections and bandwidth usage) is not
adversely impacted.
The default priority is Low. You can also tune your system
performance by changing group poll periods.
If you select Custom for the priority, then also specify the RAPIDS
custom process limit.
Sets the maximum number of monitoring process assigned to
RAPIDS work. Note that this option is only available if Custom is
specified for the RAPIDS Processing Priority.
Defining AirWave Network Settings
The next step in configuring AirWave is to confirm the AirWave network settings. Define these settings by navigating
to the AMP Setup > Network page. Figure 15 illustrates the contents of this page.
Figure 15:AMP Setup > Network page illustration
Specify the network configuration options described in the sections that follow to define the AirWave network settings.
Select Save when you have completed all changes on the AMP Setup > Network page, or select Revert to return to the
last settings. Save restarts any affected services and may temporarily disrupt your network connection.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 39
Page 40
Primary Network Interface Settings
Locate the Primary Network Interface section. The information in this sections should match what you defined during
initial network configuration and should not require changes. Table 14 describes the settings and default values.
Table 14:
Primary Network Interface Fields and Default Values
SettingDefaultDescription
IP AddressNone
HostnameNoneSets the DNS name assigned to the AirWave server.
Subnet MaskNoneSets the subnet mask for the primary network interface.
GatewayNoneSets the default gateway for the network interface.
Primary DNS IPNoneSets the primary DNS IP address for the network interface.
Secondary DNS IPNoneSets the secondary DNS IP address for the network interface.
Sets the IP address of the AirWave network interface.
NOTE: This address must be a static IP address.
Secondary Network Interface Settings
Locate the Secondary Network Interface section. The information in this section should match what you defined during
initial network configuration and should not require changes. Table 15 describes the settings and default values.
Table 15:
SettingDefaultDescription
Secondary Network Interface Fields and Default Values
EnabledNo
IP AddressNone
Subnet MaskNoneSpecify the subnet mask for the secondary network interface.
Select Yes to enable a secondary network interface. You will be promted
to define the IP address and subnet mask.
Specify the IP address of the AirWave secondary network.
NOTE: This address must be a static IP address.
Network Time Protocol (NTP) Settings
On the AMP Setup > Network page, locate the Network Time Protocol (NTP) section. The Network Time Protocol is
used to synchronize the time between AirWave and your network’s NTP server. NTP servers synchronize with external
reference time sources, such as satellites, radios, or modems.
Specifying NTP servers is optional. NTP servers synchronize the time on the AirWave server, not on individual access
points.
To disable NTP services, clear both the Primary and Secondary NTP server fields. Any problem related to
communication between AirWave and the NTP servers creates an entry in the event log. Table 16 describes the settings
and default values in more detail. For more information on ensuring that AirWave servers have the correct time, please
see http://support.ntp.org/bin/view/Servers/NTPPoolServers.
40 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Primaryntp1.yourdomain.comSets the IP address or DNS name for the primary NTP server.
Secondaryntp2.yourdomain.comSets the IP address or DNS name for the secondary NTP server.
Static Routes
On the AMP Setup > Network page, locate the Static Routes area. This section displays network, subnet mask, and
gateway settings that you have defined elsewhere from a command-line interface.
This section does not enable you to configure new routes or remove existing routes.
What Next?
l Go to additional tabs in the AMP Setup section to continue additional setup configurations. The next section
describes AirWave roles.
l Complete the required configurations in this chapter before proceeding. Dell support remains available to you for any
phase of AirWave configuration.
Creating AirWave Users
AirWave installs with only one user—the admin, who is authorized to perform the following functions:
l Define additional users with varying levels of privilege, be it manage read/write or monitoring.
l Limit the viewable devices as well as the level of access a user has to the devices.
Each general user that you add must have a user name, a password, and a role. Use unique and meaningful user names as
they are recorded in the log files when you or other users make changes in AirWave.
Username and password are not required if you configure AirWave to use RADIUS, TACACS, or LDAP authentication. You
do not need to add individual users to the AirWave server if you use RADIUS, TACACS, or LDAP authentication.
The user role defines the user type, access level, and the top folder for that user. User roles are defined on the AMP
Setup > Roles page. Refer to the previous procedure in this chapter for additional information, "Creating AirWave User
Roles" on page 43.
The admin user can provide optional additional information about the user, including the user's real name, email address,
phone number, and so forth.
Perform the following steps to display, add, edit, or delete AirWave users of any privilege level. You must be an admin
user to complete these steps.
1. Go to the AMP Setup > Users page. This page displays all users currently configured in AirWave. Figure 16
illustrates the contents and layout of this page.
Figure 16:AMP Setup > Users Page Illustration
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 41
Page 42
2. Select Add to create a new user, select the pencil icon to edit an existing user, or select a user and select Delete to
remove that user from AirWave. When you select Add or the edit icon, the Add User page appears, illustrated in
Figure 17.
A current user cannot change his/her own role. The Role drop-down field is disabled to prevent this.
3. Enter or edit the settings on this page. Table 17 describes these settings in additional detail.
Table 17:
AMP Setup > Users > Add/Edit User Fields and Default Values
SettingDefaultDescription
UsernameNone
RoleNone
PasswordNone
NameNone
Sets the username as an alphanumeric string. The Username is used when logging
in to AirWave and appears in AirWave log files.
Specifies the user’s Role, which defines the Top viewable folder as well as the type
and access level of the user specified in the previous field.
The admin user defines user roles on the AMP Setup > Roles page, and each user
in the system is assigned to a role.
Sets the password for the user being created or edited. Enter an alphanumeric
string without spaces, and enter the password again in the Confirm Password field.
NOTE: Because the default user's password is identical to the name, it is strongly
recommended that you change this password. Changing your password will log
you out.
Allows you to define an optional and alphanumeric text field that takes note of the
user's actual name.
42 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 43
Table 17:
AMP Setup > Users > Add/Edit User Fields and Default Values (Continued)
SettingDefaultDescription
Email
Address
PhoneNoneAllows you to enter an optional phone number for the user.
NotesNone
None
Allows you to specify a specific email address that will propagate throughout many
additional pages in AirWave for that user, including reports, triggers, and alerts.
Enables you to cite any additional notes about the user, including the reason they
were granted access, the user's department, or job title.
4. Select Add to create the new user, Save to retain changes to an existing user, or Cancel to cancel out of this screen.
The user information you have configured appears on the AMP Setup > Users page, and the user propagates to all
other AirWave pages and relevant functions.
AirWave enables user roles to be created with access to folders within multiple branches of the overall hierarchy. This
feature assists non-administrator users who support a subset of accounts or sites within a single AirWave deployment,
such as help desk or IT staff.
What Next?
l Go to additional tabs in the AMP Setup section to continue additional setup configurations.
l Complete the required configurations in this chapter before proceeding. Dell support remains available to you for any
phase of AirWave installation.
AirWave User Roles
The AMP Setup > Roles page defines the viewable devices, the operations that can be performed on devices, and
general AirWave access. User roles can be created that provide users with access to folders within multiple branches of
the overall hierarchy. This feature assists non-administrative users, such as help desk or IT staff, who support a subset of
accounts or sites within a single AirWave deployment. You can restrict user roles to multiple folders within the overall
hierarchy even if they do not share the same top-level folder. Non-admin users are only able to see data and users for
devices within their assigned subset of folders.
User Roles and VisualRF
VisualRF uses the same user roles as defined for AirWave. Users can see floor plans that contain an AP to which they
have access in AirWave, although only visible APs appear on the floor plan. VisualRF users can also see any building
that contains a visible floor plan and any campus that contains a visible building.
In VisualRF > Setup > Server Settings, a flag added in AirWave 7.2 allows you to restrict the visibility of empty floor plans
to the role of the user who created them. In previous versions, a floor plan without APs could be visible to all users. By
default, this setting is set to No.
When a new role is added to AirWave, VisualRF must be restarted for the new user to be enabled.
Creating AirWave User Roles
Perform the following steps to view, add, edit, or delete user roles:
1. Go to the AMP Setup > Roles page. This page displays all roles currently configured in AirWave. Figure 18
illustrates the contents and layout of this page.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 43
Page 44
Figure 18:AMP Setup > Roles Page Illustration
2. Select Add to create a new role, select the pencil icon to edit an existing role, or select a checkbox and select Delete
to remove that role from AirWave. When you select Add or the edit icon, the Add/Edit Role page appears, illustrated
in Figure 19.
Figure 19:AMP Setup > Roles > Add/Edit Role Page Illustration
3. Enter or edit the settings on this page. As explained earlier in this section, Roles define the type of user-level access,
the user-level privileges, and the view available to the user for device groups and devices in AirWave. The available
configuration options differ for each role type.
Most users will see two sections on this page: Role and Guest User Preferences. The Guest User Preferences section will
not appear, however, if Guest User Configuration is disabled in AMP Setup > General.
The following tables describe the available settings and default values for each role type.
44 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 45
Table 18:
AMP Setup > Roles > Add/Edit Roles Fields and Default Values for AirWave Administrator Role
SettingDefaultDescription
Sets the administrator-definable string that names the role. The role name
NameNone
should indicate the devices and groups that are viewable, as well as the
privileges granted to that role.
EnabledYes
Disables or enables the role. Disabling a role prevents all users of that
role from logging in to AirWave.
Defines the type of role.
AirWave Administrator—The AirWave Administrator has full access to
AirWave and all of the devices. Only theAirWave Administrator can create
new users or access the AMP Setup page, the VisualRF > Setup page,
Type
AP/Device
Manager
VisualRF > Audit Log page, System > Event Log, and System >
Performance.
Enables or disables Single Sign-On for the role. If enabled, allows the role
Dell Networking W
Controller Role
Disabled
to directly access Dell controller UIs from the Quick Links or IP Address
hypertext throughout AirWave without having to enter credentials for the
controller.
Allow user to disable
timeout
NoWhether a user can disable AirWave’s timeout feature.
Custom MessagenoneA custom message can also be included.
Table 19:
AMP Setup > Roles > Add/Edit Roles Fields and Default Values for AP/Device Manager Role
SettingDefaultDescription
NameNone
EnabledYes
Type
AP/Device
Access Level
AP/Device
Manager
Monitor
(Read Only)
Sets the administrator-definable string that names the role. The role name should
indicate the devices and groups that are viewable, as well as the privileges
granted to that role.
Disables or enables the role. Disabling a role prevents all users of that role from
logging in to AirWave.
Defines the type of role.
AP/Device Manager—AP/Device Managers have access to a limited number of
devices and groups based on the Top folder and varying levels of control based
on the Access Level.
Defines the privileges the role has over the viewable APs. AirWave supports
three privilege levels, as follows:
l Manage (Read/Write)—Manage users can view and modify devices and
Groups. Selecting this option causes a new field, Allow authorization of
APs/Devices, to appear on the page, and is enabled by default.
l Audit (Read O nly)—Audit users have read only access to the viewable
devices and Groups. Audit users have access to the APs/Devices > Audit
page, which may contain sensitive information including AP passwords.
l Monitor (Read Only)—Monitor users have read-only access to devices and
groups and VisualRF. Monitor users cannot view the APs/Devices > Audit
page which may contain sensitive information, including passwords.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 45
Page 46
Table 19:
AMP Setup > Roles > Add/Edit Roles Fields and Default Values for AP/Device Manager Role
(Continued)
SettingDefaultDescription
Defines the highest viewable folder for the role. The role is able to view all
devices and groups contained by the specified top folder. The top folder and its
subfolders must contain all of the devices in any of the groups it can view.
NOTE: AirWave enables user roles to be created with access to folders within
Top FolderTop
multiple branches of the overall hierarchy. This feature assists non-administrator
users who support
deployment, such as help desk or IT staff.
User roles can be restricted to multiple folders within the overall hierarchy, even if
they do not share the same top-level folder. Non-administrator users are only
able to see data and users for devices within their assigned subset of folders.
a subset of accounts or sites
within a single AirWave
Allow
authorization
of
Yes
APs/Devices
RAPIDSNone
VisualRFRead Only
Dell
Networking
W Controller
Disabled
Role
NOTE: This option is only available when the AP/Device Access Level is
specified as Manage (Read/Write).
Sets the RAPIDS privileges, which are set separately from the APs/Devices. This
field specifies the RAPIDS privileges for the role, and options are as follows:
l None— Cannot view the RAPIDS tab or any Rogue APs.
l Read Only—The user can view the RAPIDS pages but cannot make any
changes to rogue APs or perform OS scans.
l Read/Write—The user may edit individual rogues, classification, threat levels
and notes, and perform OS scans.
l Administrator—Has the same privileges as the Read/Write user, but can also
set up RAPIDS rules, override scores and is the only user who can access the
RAPIDS > Setup page.
Sets the VisualRF privileges, which are set separately from the APs/Devices.
Options are as follows:
l Read Only—The user can view the VisualRF pages but cannot make any
changes to floor plans.
l Read/Write—The user may edit individual floor plans, buildings, and
campuses.
Enables or disables Single Sign-On for the role. If enabled, allows the role to
directly access Dell Networking W controller UIs from the Quick Links or IP
Address hypertext throughout AirWave without having to enter credentials for the
controller
Display client
diagnostics
screens by
No
Sets the role to support helpdesk users with parameters that are specific to the
needs of helpdesk personnel supporting users on a wireless network.
default
Allow user to
disable
NoWhether a user can disable AirWave’s timeout feature.
timeout
If this option is enabled, users with an assigned role of Monitoring or Audit can be
Allow
creation of
Guest Users
Yes
given access to guest user account creation along with the option to allow a
sponsor to change its username.
NOTE: This option is not available if the AP/Device Access Level is specified as
Manage (Read/Write).
46 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 47
Table 19:
AMP Setup > Roles > Add/Edit Roles Fields and Default Values for AP/Device Manager Role
(Continued)
SettingDefaultDescription
Allow
accounts with
no expiration
Allow
sponsor to
change
sponsorship
username
Custom
Message
Table 20:
Yes
NoSpecifies whether a sponsor can change the sponsorship user name.
noneA custom message can also be included.
AMP Setup > Roles > Add/Edit Roles Fields and Default Values for AirWave Management Client
Specifies whether to allow accounts that have no expiration set. If this is set to
No, then enter the amount of time that can elapse before the access expires.
Role
SettingDefaultDescription
Sets the administrator-definable string that names the role. The role name should
NameNone
EnabledYes
Type
AP/Device
Manager
indicate the devices and groups that are viewable, as well as the privileges
granted to that role.
Disables or enables the role. Disabling a role prevents all users of that role from
logging in to AirWave.
Defines the type of role.
AirWave Management Client—The AirWave Management Client (AMC) software
allows WiFi-enabled devices to serve as additional sensors to gather data for
RAPIDS. Use this role type to set up a client to be treated as a user with the AMC
role. The user information defined in AMC must match the user with the AirWave
Management Client type.
Allow user
to disable
timeout
.
Table 21:
NoWhether a user can disable AirWave’s timeout feature.
AMP Setup > Roles > Add/Edit Roles Fields and Default Values for Guest Access Sponsor Role
SettingDefaultDescription
Sets the administrator-definable string that names the role. The role name should
NameNone
EnabledYes
Type
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 47
AP/Device
Manager
indicate the devices and groups that are viewable, as well as the privileges
granted to that role.
Disables or enables the role. Disabling a role prevents all users of that role from
logging in to AirWave.
Defines the type of role.
Guest Access Sponsor—Limited-functionality role to allow helpdesk or reception
desk staff to grant wireless access to temporary personnel. This role only has
access to the defined top folder of APs.
Page 48
Table 21:
AMP Setup > Roles > Add/Edit Roles Fields and Default Values for Guest Access Sponsor Role
(Continued)
SettingDefaultDescription
Defines the Top viewable folder for the role. The role is able to view all devices
and groups contained by the Top folder. The top folder and its subfolders must
contain all of the devices in any of the groups it can view.
NOTE: AirWave enables user roles to be created with access to folders within
Top FolderTop
Allow user
to disable
NoWhether a user can disable AirWave’s timeout feature.
timeout
Allow
accounts
with no
Yes
expiration
Allow
sponsor to
change
NoSpecifies whether a sponsor can change the sponsorship user name.
sponsorship
username
multiple branches of the overall hierarchy. This feature assists non-administrator
users who support
deployment, such as help desk or IT staff.
User roles can be restricted to multiple folders within the overall hierarchy, even if
they do not share the same top-level folder. Non-administrator users are only able
to see data and users for devices within their assigned subset of folders.
Specifies whether to allow accounts that have no expiration set. If this is set to No,
then enter the amount of time that can elapse before the access expires.
a subset of accounts or sites
within a single AirWave
Custom
Message
noneA custom message can also be included.
What Next?
l Go to additional tabs in the AMP Setup section to continue additional setup configurations. The next section
describes how to set up AirWave users.
l Complete the required configurations in this chapter before proceeding. Dell support remains available to you for any
phase of AirWave configuration.
Configuring Login Message, TACACS+, RADIUS, and LDAP Authentication
AirWave uses session-based authentication with a configurable login message and idle timeout. As an option, you can
set AirWave to use an external user database to simplify password management for AirWave administrators and users.
This section contains the following procedures to be followed in AMP Setup > Authentication:
l "Setting Up Login Configuration Options" on page 49
l "Configuring Whitelists" on page 49
l "Setting Up Certificate Authentication" on page 50
l "Setting Up Single Sign-On" on page 50
l "Specifying the Authentication Priority" on page 51
l "Configuring RADIUS Authentication and Authorization" on page 51
l "Integrating a RADIUS Accounting Server" on page 52
l "Configuring TACACS+ Authentication" on page 53
l "Configuring LDAP Authentication and Authorization" on page 55
48 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 49
Setting Up Login Configuration Options
On the AMP Setup > Authentication page, administrators can optionally configure the AirWave user's idle timeout or a
message-of-the-day that appears when a user first logs in, as shown in Figure 20:
Figure 20:Login configuration field and results in the AirWave Login page
1. Go to AMP Setup > Authentication.
2. Complete the fields described on Table 22:
Table 22:
Login Configuration section of AMP Setup > Authentication
FieldDefaultDescription
Max AMP User Idle
Timeout
Login messagenone
240
Number of minutes of idle time until AirWave automatically ends the user
session. Affects all users of this AirWave. The range is 5-240 minutes.
A persistent message that will appear for all of this AirWave's users after they
log in.
3. Select Save when you are finished or follow the next procedure to configure Whitelists, Certificate Authentication,
Single Sign-On, TACACS+, LDAP, and RADIUS Authentication options.
Configuring Whitelists
On the AMP Setup >Authentication page, you can now include a list of subnets that are able to log in to AirWave. If
this option is enabled, then by default, the current client network will appear as the first entry in the list of subnets.
Additional entries can be added, one per line, in the text entry box.
For Instant devices that are managed by AirWave, this option must be enabled if Certificate Authentication is also
enabled.
Do not delete the current client network line from the AirWave whitelist. Doing so can result in the loss of access to the
AirWave user interface.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 49
Page 50
Figure 21:Enabling AirWave Whitelists
Setting Up Certificate Authentication
On the AMP Setup > Authentication page, administrators can specify whether to require a certificate during
authentication and whether to use two-factor authentication. A PEM-encoded certificate bundle is required for this
feature.
This feature must be enabled per role in AMP Setup > Roles.
Perform the following steps to enable this feature for this AMP.
1. Locate the Certificate Authentication section in AMP Setup > Authentication.
2. In the Enable Certificate Authentication field, select Yes.
3. Specify whether to require a certificate in order to authenticate. If Yes, then you can also specify whether to use twofactor authentication.
4. Enter the PEM-encoded CA certificate bundle.
5. Select Save if you are finished or follow the next procedure to specify the authentication priority.
Setting Up Single Sign-On
On the AMP Setup > Authentication page, administrators can set up single sign-on (SSO) for users that have access to
AirWave controllers. This allows users to log in to AirWave and use the IP Address or Quick Links hypertext links
across AirWave to access the controller’s UI without having to enter credentials again. The links the user can select to
access a controller can be found on the APs/Devices > Monitor page in the Device Info section, and on device list
pages.
Perform the following steps to enable this feature for this AirWave.
1. Locate the Single Sign-On section in AMP Setup > Authentication.
2. In the Enable Single Sign-On field, select Yes.
3. Select Save if you are finished or follow the next procedure to specify the authentication priority.
50 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 51
Specifying the Authentication Priority
To specify the authentication priority for this AirWave, locate the Authentication Priority section in AMP Setup >
Authentication, and select either Local or Remote as the priority.
If Local is selected, then remote will be attempted if a user is not available. If Remote is selected, then the local
database is searched if remote authentication fails. The order of remote authentication is RADIUS first, followed by
TACACS, and finally LDAP.
Select Save if you are finished or follow the next procedure to configure RADIUS, TACACS+, and LDAP
Authentication options.
Configuring RADIUS Authentication and Authorization
For RADIUS capability, you must configure the IP/Hostname of the RADIUS server, the TCP port, and the server shared
secret. Perform these steps to configure RADIUS authentication:
1. Go to the AMP Setup > Authentication page. This page displays current status of RADIUS. Figure 22 illustrates this
page.
Figure 22:AMP Setup > Authentication Page Illustration for RADIUS
2. Select No to disable or Yes to enable RADIUS authentication. If you select Yes, several new fields appear. Complete
the fields described in Table 23.
Table 23:
AMP Setup > Authentication Fields and Default Values for RADIUS Authentication
FieldDefaultDescription
Primary Server
Hostname/IP Address
Primary Server Port (1-
65535)
Primary Server SecretN/A
Confirm Primary Server
Secret
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 51
N/AEnter the IP address or the hostname of the primary RADIUS server.
1812Enter the TCP port for the primary RADIUS server.
Specify and confirm the primary shared secret for the primary RADIUS
server.
N/ARe-enter the primary server secret.
Page 52
Table 23:
AMP Setup > Authentication Fields and Default Values for RADIUS Authentication (Continued)
FieldDefaultDescription
Secondary Server
Hostname/IP Address
Secondary Server Port
(1-65535)
Secondary Server
Secret
Confirm Secondary
Server Secret
N/AEnter the IP address or the hostname of the secondary RADIUS server.
1812Enter the TCP port for the secondary RADIUS server.
N/AEnter the shared secret for the secondary RADIUS server.
N/ARe-enter the secondary server secret.
3. Select Save to retain these configurations, and continue with additional steps in the next procedure.
Integrating a RADIUS Accounting Server
AirWave checks the local username and password before checking with the RADIUS server. If the user is found locally, the
local password and role apply. When using RADIUS, it’s not necessary or recommended to define users on the AirWave
server. The only recommended user is the backup admin, in case the RADIUS server goes down.
Optionally, you can configure RADIUS server accounting on AMP Setup > RADIUS Accounting. This capability is not
required for basic AirWave operation, but can increase the user-friendliness of AirWave administration in large networks.
Figure 23 illustrates the settings of this optional configuration interface.
Perform the following steps and configurations to enable AirWave to receive accounting records from a separate
RADIUS server. Figure 23 illustrates the display of RADIUS accounting clients already configured, and Figure 24
illustrates the Add RADIUS Accounting Client page.
1. To specify the RADIUS authentication server or network, browse to the AMP Setup > RADIUS Accounting page,
select Add, illustrated in Figure 24, and provide the information in Table 24.
2. Complete the following fields:
Table 24:
AMP Setup > Radius Accounting Fields and Default Values for LDAP Authentication
SettingDefaultDescription
Specify the IP address for the authentication server if you only want to accept
IP/NetworkNone
NicknameNoneSets a user-defined name for the authentication server.
Shared Secret
(Confirm)
None
packets from one device. To accept packets from an entire network enter the
IP/Netmask of the network (for example, 10.51.0.0/24).
Sets the Shared Secret that is used to establish communication between AirWave
and the RADIUS authentication server.
Configuring TACACS+ Authentication
For TACACS+ capability, you must configure the IP/Hostname of the TACACS+ server, the TCP port, and the server
shared secret. This TACACS+ configuration is for AirWave users and does not affect APs or users logging into APs.
1. Go to the AMP Setup > Authentication page. This page displays current status of TACACS+. Figure 25 illustrates
this page when neither TACACS+, LDAP, nor RADIUS authentication is enabled in AirWave.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 53
Page 54
Figure 25:AMP Setup > Authentication Page Illustration for TACACS+
2. Select No to disable or Yes to enable TACACS+ authentication. If you select Yes, several new fields appear.
Complete the fields described in Table 25.
Table 25:
AMP Setup > Authentication Fields and Default Values for TACACS+ Authentication
FieldDefaultDescription
Primary Server Hostname/IP
Address
Primary Server Port (1-65535)49Enter the port for the primary TACACS+ server.
Primary Server SecretN/A
Confirm Primary Server SecretN/ARe-enter the primary server secret.
Secondary Server
Hostname/IP Address
Secondary Server Port (1-
65535)
Secondary Server SecretN/AEnter the shared secret for the secondary TACACS+ server.
Confirm Secondary Server
Secret
N/A
N/A
49Enter the port for the secondary TACACS+ server.
N/ARe-enter the secondary server secret.
Enter the IP address or the hostname of the primary TACACS+
server.
Specify and confirm the primary shared secret for the primary
TACACS+ server.
Enter the IP address or hostname of the secondary TACACS+
server.
3. Select Save and continue with additional steps.
Configuring Cisco ACS to Work with AirWave
To configure Cisco ACS to work with AirWave, you must define a new service named AMP that uses https on the ACS
server.
1. The AMP https service is added to the TACACS+ (Cisco) interface under the Interface Configuration tab.
2. Select a checkbox for a new service.
3. Enter AMP in the service column and https in the protocol column.
54 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 55
4. Select Save.
5. Edit the existing groups or users in TACACS to use the AMP service and define a role for the group or user.
l The role defined on the Group Setup page in ACS must match the exact name of the role defined on the AMP
Setup > Roles page.
n The defined role should use the following format: role=<name_of_AMP_role>. One example is as follows:
role=DormMonitoring
As with routers and switches, AirWave does not need to know usernames.
6. AirWave also needs to be configured as an AAA client.
l On the Network Configuration page, select Add Entry.
l Enter the IP address of AirWave as the AAA Client IP Address.
l The secret should be the same value that was entered on the AMP Setup > TACACS+ page.
7. Select TACACS+ (Cisco IOS) in the Authenticate Using drop down menu and select submit + restart.
AirWave checks the local username and password store before checking with the TACACS+ server. If the user is found
locally, the local password and local role apply. When using TACAS+, it is not necessary or recommended to define users
on the AirWave server. The only recommended user is the backup administrator, in the event that the TACAS+ server goes
down.
Configuring LDAP Authentication and Authorization
LDAP (Lightweight Directory Access Protocol) provides users with a way of accessing and maintaining distributed
directory information services over a network. When LDAP is enabled, a client can begin a session by authenticating
against an LDAP server which by default is on TCP port 389.
Perform these steps to configure LDAP authentication:
1. Go to the AMP Setup> Authentication page.
2. Select the Yes radio button to enable LDAP authentication and authorization. Once enabled, the available LDAP
configuration options will display. Figure 26 illustrates this page.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 55
Page 56
Figure 26: AMP Setup > Authentication Page Illustration for LDAP
3. Complete the fields described in Table 26.
Table 26:
AMP Setup > Authentication Fields and Default Values for LDAP Authentication
FieldDefaultDescription
Primary Server
Hostname/IP Address
Primary Server Port (1-
65535)
Secondary Server
Hostname/IP Address
Secondary Server Port
(1-65535)
none
389
none
389
Connection Typeclear-text
Enter the IP address or the hostname of the primary LDAP
server.
Enter the port where the LDAP server is listening. The default
port is 389.
Optionally enter the IP address or hostname of the secondary
LDAP server. This server will be contacted in the event that the
primary LDAP server is not reachable.
Enter the port where the LDAP service is listening on the
secondary LDAP server. The default port is 389.
Specify one of the following connection types AirWave and the
LDAP server:
l clear-text results in unencrypted communication.
l ldap-s results in communication over SSL.
l start-tls uses certificates to initiate encrypted
communication.
56 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 57
Table 26:
AMP Setup > Authentication Fields and Default Values for LDAP Authentication (Continued)
FieldDefaultDescription
If Connection Type is configured as start-t ls, then also specify
whether the start-tls connection type uses a certificate.
l none - The server may provide a certificate, but it will not
be verified. This may mean that you are connected to the
wrong server.
l optional - Verifies only when the servers offers a valid
View Server Certificatenone
LDAP Server CA
Certificate
none
certificate.
l require - The server must provide a valid certificate.
A valid LDAP Server CA Certif icate must be provided in case
of optional or require. Certificates uploaded on the Device
Setup > Certificates page with a type of Intermediate CA or
Trusted CA are listed in the drop down for LDAP Server CA
Certificate.
Specify the LDAP server certificate to use to initiate encrypted
communication. Only certificates that have been uploaded with
a type of Intermediate CA or Trusted CA will appear in this
drop down.
NOTE: This LDAP Server CA Certificate drop down menu oly
appears if View Server Certificat e is specified as optional or
require.
Specify the Distinguished Name (DN) of the administrator
account, such as
Bind DNnone
‘cn=admin01,cn=admin,dn=domain,dn=com’. Note that for the
Active directory, the bind DN can also be in the
administrator@domain format (for example,
administrator@acme.com).
Bind PasswordnoneSpecify the bind DN account password.
Confirm Bind
Password
noneRe-enter the bind password.
The DN of the node in your directory tree from which to start
Base DNnone
searching for records. Generally, this would be the node that
contains all the users who may access AirWave, for example
cn=users,dc=domain,dc=com.
Key AttributesAMAccountName
The LDAP attribute that identifies the user, such as
‘sAMAccountName’ for Active Directory
The LDAP attribute that contains the AirWave role. Users who
Role Attributenone
log in to AirWave using this LDAP authentication will be
granted permissions based on this role. Refer to AirWave User
Roles for more information about AirWave User Roles.
Filter(objectclass=*)
This option limits the object classes in which the key,role
attributes would be searched.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 57
Page 58
Table 26:
AMP Setup > Authentication Fields and Default Values for LDAP Authentication (Continued)
FieldDefaultDescription
The LDAP rule parameters are Position, Role Attribute,
Operation, Value, and AirWave role. If you create multiple
LDAP rules, rules are processed in order based on the rule
position value, so the position you assign to the LDAP rule
Add New LDAP Rulenone
represents the order in which the LDAP rule is applied to
determine the AirWave role. LDAP rules can only be
configured and applied after LDAP authentication is enabled.
The LDAP rules are similar to the rules used by the controller
to derive the AirWave role.
4. Select Save to retain these configurations, and continue with additional steps in the next procedure.
What Next?
l Go to additional subtabs in AMP Setup to continue additional setup configurations.
l Complete the required configurations in this chapter before proceeding. Dell support remains available to you for
any phase of AirWave configuration.
Enabling AirWave to Manage Your Devices
Once AirWave is installed and active on the network, the next task is to define the basic settings that allow AirWave to
communicate with and manage your devices. Device-specific firmware files are often required or are highly desirable.
Furthermore, the use of Web Auth bundles is advantageous for deployment of Cisco WLC wireless LAN controllers
when they are present on the network.
This section contains the following procedures:
l "Configuring Communication Settings for Discovered Devices" on page 58
l "Loading Device Firmware Onto AirWave (optional)" on page 61
Configuring Communication Settings for Discovered Devices
To configure AirWave to communicate with your devices, to define the default shared secrets, and to set SNMP polling
information, navigate to the Device Setup > Communication page, illustrated in Figure 27.
58 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 59
Figure 27:Device Setup > Communication Page Illustration
Perform the following steps to define the default credentials and SNMP settings for the wireless network.
1. On the Device Setup > Communication page, locate the Default Credentials area. Enter the credentials for each
device model on your network. The default credentials are assigned to all newly discovered APs.
The Edit button edits the default credentials for newly discovered devices. To modify the credentials for existing
devices, use the APs/Devices > Manage page or the Modify Devices link on the APs/Devices > List page.
Community strings and shared secrets must have read-write access for AirWave to configure the devices. Without read-
write access, AirWave may be able to monitor the devices but cannot apply any configuration changes.
2. Browse to the Device Setup > Communication page, locate the SNMP Settings section, and enter or revise the
following information. Table 27 lists the settings and default values.
Table 27:
Device Setup > Communication > SNMP Settings Fields and Default Values
SettingDefaultDescription
SNMP Timeout
(3-60 sec)
SNMP Retries
(1-40)
3
3
Sets the time, in seconds, that AirWave waits for a response from a device after
sending an SNMP request.
Sets the number of times AirWave tries to poll a device when it does not receive
a response within the SNMP Timeout Period or the Group's Missed SNMP Poll
Threshold setting (1-100). If AirWave does not receive an SNMP response from
the device after the specified number of retries, AirWave classifies that device as
Down.
NOTE: Although the upper limit for this value is 40, some SNMP libraries still
have a hard limit of 20 retries. In these cases, any retry value that is set above 20
will still stop at 20.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 59
Page 60
3. Locate the SNMPv3 Informs section. Select the Add button to reveal configuration options. AirWave users will
need to configure all v3 users that are configured on the controller. The SNMP Inform receiver in the AirWave will
be restarted when users are changed or added to the controller.
l Username - Username of the SNMP v3 user as configured on the controller.
l Auth Protocol - Can be MD5 or SHA. The default setting is SHA.
l Auth and Priv Protocol Passphrases - Enter the authentication and privilege protocol passphrases for the user as
configured on the controller.
l Priv Protocol - Can be DES or AES. The default setting is DES..
This form allows you to edit existing SNMPv3 users by selecting the pencil icon next to the desired user. It also allows you
to remove existing users by selecting the user’s checkbox and then clicking Delete.
4. Locate the Telnet/SSH Settings section, and complete or adjust the default value for the field. Table 28 shows the
setting and default value.
Table 28:
Device Setup > Communication > Telnet/SSH Settings Fields and Default Values
SettingDefaultDescription
Telnet/SSH Timeout
(3-120 sec)
10
Sets the timeout period in seconds used when performing Telnet and SSH
commands.
5. Locate the HTTP Discovery Settings section and adjust the default value. Table 29 shows the setting and default
value.
Table 29:
Device Setup > Communication > HTTP Discovery Settings Fields and Default Values
SettingDefaultDescription
HTTP Timeout
(3-120 sec)
5Sets the timeout period in seconds used when running an HTTP discovery scan.
6. Locate the ICMP Settings section and adjust the default value as required. Table 30 shows the setting and default
value.
Table 30:
Device Setup > Communication > ICMP Settings Fields and Default Values
SettingDefaultDescription
Attempt to
ping devices
that were
unreachable
via SNMP
Yes
l When Yes is selected, AirWave attempts to ping the AP device.
l Select No if performance is affected in negative fashion by this function. If a
large number of APs are unreachable by ICMP, likely to occur where there is in
excess of 100 APs, the timeouts start to impede network performance.
NOTE: If ICMP is disabled on the network, select No to avoid the performance
penalty caused by numerous ping requests.
7. Locate the Symbol 4131 and Cisco Aironet IOS SNMP Initialization area. Select one of the options listed. Table 31
describes the settings and default values
60 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 61
Table 31:
Device Setup > Communication > Symbol 4131 and Cisco Aironet IOS SNMP Initialization Fields
and Default Values
SettingDefaultDescription
Do Not Modify
SNMP Settings
Enable readwrite SNMP
Yes
No
When selected, specifies that AirWave will not modify any SNMP settings. If
SNMP is not already initialized on the Symbol, Nomadix, and Cisco IOS APs,
AirWave is not able to manage them.
When selected, and when on networks where the Symbol, Nomadix, and Cisco
IOS APs do not have SNMP initialized, this setting enables SNMP so the
devices can be managed by AirWave.
Loading Device Firmware Onto AirWave (optional)
AirWave enables automated firmware distribution to the devices on your network. Once you have downloaded the
firmware files from the vendor, you can upload this firmware to AirWave for distribution to devices via the Device Setup> Upload Firmware & Files page.
This page lists all firmware files on AirWave with file information. This page also enables you to add new firmware
files, to delete firmware files, and to add New Web Auth Bundle files.
The following additional pages support firmware file information:
l Firmware files uploaded to AirWave appear as an option in the drop-down menu on the Groups > Firmware page
and as a label on individual APs/Devices > Manage pages.
l Use the AMP Setup page to configure AirWave-wide default firmware options.
Table 32 below itemizes the contents, settings, and default values for the Upload Firmware & Files page.
DescriptionNoneDisplays a user-configurable text description of the firmware file.
Server ProtocolNone
Use Group File
Server
Firmware
Filename
Firmware MD5
Checksum
Firmware File
Size
Dell Controller(any
model)
None
None
None
NoneDisplays the size of the firmware file in bytes.
Displays a drop-down list of the primary AP makes and models
that AirWave supports with automated firmware distribution.
Displays the user role that uploaded the firmware file. This is the
role that has access to the file when an upgrade is attempted.
Displays the file transfer protocol by which the firmware file was
obtained from the server. This can be FTP, TFTP, HTTP, or
HTTPS.
If enabled, displays the name of the file server supporting the
group.
Displays the name of the file that was uploaded to AirWave and
to be transferred to an AP when the file is used in an upgrade.
Displays the MD5 checksum of the file after it was uploaded to
AirWave. The MD5 checksum is used to verify that the file was
uploaded to AirWave without issue. The checksum should
match the checksum of the file before it was uploaded.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 61
HTML File SizeNoneSupporting HTML, displays the size of the file in bytes.
HTML VersionNone
Desired
Firmware File for
Specified Groups
None
None
None
Displays the firmware version number. This is a userconfigurable field.
Supporting HTML, displays the name of the file that was
uploaded to AirWave and to be transferred to an AP when the
file is used in an upgrade.
Supporting HTML, displays the MD5 checksum of the file after it
was uploaded to AirWave. The MD5 checksum is used to verify
that the file was uploaded to AirWave without issue. The
checksum should match the checksum of the file before it was
uploaded.
Supporting HTML, displays the version of HTML used for file
transfer.
The firmware file is set as the desired firmware version on the
Groups > Firmware Files page of the specified groups. You
cannot delete a firmware file that is set as the desired firmware
version for a group.
Loading Firmware Files onto AirWave
Perform the following steps to load a device firmware file onto AirWave:
1. Go to the Device Setup > Upload Firmware & Files page.
2. Select Add. The Add Firmware File page appears. Figure 28 illustrates this page.
3. Select the Supported Firmware Versions and Features link to view supported firmware versions.
Unsupported and untested firmware may cause device mismatches and other problems. Please contact Dell support at
dell.com/support before installing non-certified firmware.
62 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 63
4. Enter the appropriate information and select Add. The file uploads to AirWave and once complete, this file appears
on the Device Setup > Upload Firmware & Files page. This file also appears on additional pages that display
firmware files (such as the Group > Firmware page and on individual APs/Devices > Manage pages).
5. You can also import a CSV list of groups and their external TFTP firmware servers. Table 33 itemizes the settings of
this page.
Table 33:
Supported Firmware Versions and Features Fields and Default Values
SettingDefaultDescription
Indicates the firmware file is used with the specified type.
TypeDell controller
Firmware VersionNone
DescriptionNone
Upload firmware
files (and use
built-in firmware)
Use an external
firmware file
server
Server ProtocolTFTP
Enabled
N/A
With selection of some types, particularly Cisco controllers,
you can specify the boot software version.
Provides a user-configurable field to specify the firmware
version number. This open appears if Use an external
firmware f ile server is enabled.
Provides a user-configurable text description of the
firmware file.
Allows you to select a firmware from your local machine
and upload it via TFTP or FTP.
You can also choose to assign the external TFTP server on
a per-group basis. If you select this option, you must enter
the IP address on the G roups > Firmware page. Complete
the Firmware File Server IP Address field.
Specify whether to use a built-in TFTP server or FTP, HTTP,
or HTTPS to upload a firmware file. TFTP is recommended.
If you select FTP, AirWave uses an anonymous user for file
upload.
Use Group File
Server
Firmware File
Server IP Address
Firmware
Filename
HTMLFilenameNone
Patch FilenameNone
Boot Software
Version
Disabled
None
None
None
If you opt to use an external firmware file server, this
additional option appears. This setting instructs AirWave to
use the server that is associated with the group instead of
defining a server.
Provides the IP address of the External TFTP Server (like
SolarWinds) used for the firmware upgrade. This option
displays when the user selects the Use an external
firmware f ile option.
Enter the name of the firmware file that needs to be
uploaded. Ensure that the firmware file is in the TFTP root
directory. If you are using a non-external server, you select
Choose File to find your local copy of the file.
Browse to the HTMLfile that will accompany the firmware
upload. Note that this field is only available for certain
Firmware File Types (for example, Symbol 4121).
If you selected Symbol WS5100 as the Firmware File Type,
and you are upgrading from version 3.0 to 3.1, then browse
to the path where the patch file is located.
If you specified a Cisco WLC device as the Firmware File
Type, then also enter the boot software version.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 63
Page 64
Additional fields may appear for multiple device types. AirWave prompts you for additional firmware information as
required. For example, Intel and Symbol distribute their firmware in two separate files: an image file and an HTML file. Both
files must be uploaded to AirWave for the firmware to be distributed successfully via AirWave.
6. Select Add to import the firmware file.
To delete a firmware file that has already been uploaded to AirWave, return to the Device Setup > Upload Firmware &Files page, select the checkbox for the firmware file and select Delete.
A firmware file may not be deleted if it is the desired version for a group. Use the Group > Firmware page to investigate this
potential setting and status.
Using Web Auth Bundles in AirWave
Web authentication bundles are configuration files that support Cisco WLC wireless LAN controllers. This procedure
requires that you have local or network access to a Web Auth configuration file for Cisco WLC devices.
Perform these steps to add or edit Web Auth bundles in AirWave.
1. Go to the Device Setup > Upload Firmware & Files page. This page displays any existing Web Auth bundles that
are currently configured in AirWave, and allows you to add or delete Web Auth bundles.
2. Scroll to the bottom of the page. Select the Add New Web Auth Bundle button to create a new Web Auth bundle
(see Figure 29), or select the pencil icon next to an existing bundle to edit. You may also delete Web Auth bundles
by selecting that bundle with the checkbox, and selecting Delete.
Figure 29:Add Web Auth Bundle Page Illustration
3. Enter a descriptive label in the description field. This is the label used to identify and track Web Auth bundles on
the page.
4. Enter the path and filename of the Web Auth configuration file in the Web Auth Bundle field or select Choose File
to locate the file.
5. Select Add to complete the Web Auth bundle creation, or Save if replacing a previous Web Auth configuration file,
or Cancel to abort the Web Auth integration.
For additional information and a case study that illustrates the use of Web Auth bundles with Cisco WLC controllers,
refer to the following document on Cisco’s Web site:
l Wireless LAN controller Web Authentication Configuration Example, Document ID: 69340
On AMP Setup > Device Type Setup, you can define how the Device Type displayed for users on your network is
calculated from available data. The first matching property is used. These rules cannot be edited or deleted, but only
reordered or enabled.
You can change the priority order of rules by dragging and dropping rows, as shown in Figure 30.
64 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 65
Check or uncheck the checkbox under the Enabled column to turn device setup rules on or off.
Refer to "Monitoring and Supporting WLAN Clients" on page 236 for more information on the Device Type column
that appears in Clients list tables.
Figure 30:AMP Setup > Device Type Setup Page Illustration
Configuring Cisco WLSE and WLSE Rogue Scanning
The Cisco Wireless LAN Solution Engine (WLSE) includes rogue scanning functions that AirWave supports. This
section contains the following topics and procedures, and several of these sections have additional sub-procedures:
l "Introduction to Cisco WLSE" on page 65
l "Initial WLSE Configuration" on page 66
l "Configuring IOS APs for WDS Participation" on page 67
l "Configuring ACS for WDS Authentication" on page 68
l "Configuring Cisco WLSE Rogue Scanning" on page 68
You must enter one or more CiscoWorks WLSE hosts to be polled for discovery of Cisco devices and rogue AP
information.
Introduction to Cisco WLSE
Cisco WLSE functions as an integral part of the Cisco Structured Wireless-Aware Network (SWAN) architecture, which
includes IOS Access Points, a Wireless Domain Service, an Access Control Server, and a WLSE. In order for AirWave to
obtain Rogue AP information from the WLSE, all SWAN components must be properly configured. Table 34 describes
these components.
Table 34:
SWAN ComponentRequirements
WDS (Wireless Domain
Services)
Cisco SWAN Architecture Components
l WDS Name
l Primary and backup IP address for WDS devices (IOS AP or WLSM)
l WDS Credentials APs within WDS Group
NOTE: WDS can be either a WLSM or an IOS AP. WLSM (WDS) can control up to 250
access points. AP (WDS) can control up to 30 access points.
WLSE (Wireless LAN
Solution Engine)
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 65
l IP Address
l Login
Page 66
Table 34:
Cisco SWAN Architecture Components (Continued)
SWAN ComponentRequirements
ACS (Access Control
Server)
APs
l IP Address
l Login
l APs within WDS Group
Initial WLSE Configuration
Use the following general procedures to configure and deploy a WLSE device in AirWave:
l "Adding an ACS Server for WLSE" on page 66
l "Enabling Rogue Alerts for Cisco WLSE" on page 66
l "Configuring WLSE to Communicate with APs" on page 66
l "Discovering Devices" on page 66
l "Managing Devices" on page 67
l "Inventory Reporting" on page 67
l "Defining Access" on page 67
l "Grouping" on page 67
Adding an ACS Server for WLSE
1. Go to the Devices > Discover > AAA Server page.
2. Select New from the drop-down list.
3. Enter the Server Name, Server Port (default 2002), Username, Password, and Secret.
4. Select Save.
Enabling Rogue Alerts for Cisco WLSE
1. Go to the Faults > Network Wide Settings > Rogue AP Detection page.
2. Select the Enable.
3. Select Apply.
Additional information about rogue device detection is available in "Configuring Cisco WLSE Rogue Scanning" on
page 68.
Configuring WLSE to Communicate with APs
1. Go to the Device Setup > Discover page.
2. Configure SNMP Information.
3. Configure HTTP Information.
4. Configure Telnet/SSH Credentials
5. Configure HTTP ports for IOS access points.
6. Configure WLCCP credentials.
7. Configure AAA information.
Discovering Devices
The following three methods can be used to discover access points within WLSE:
l Using Cisco Discovery Protocol (CDP)
66 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 67
l Importing from a file
l Importing from CiscoWorks
Perform these steps to discover access points.
1. Go to the Device > Managed Devices > Discovery Wizard page.
2. Import devices from a file.
3. Import devices from Cisco Works.
4. Import using CDP.
Managing Devices
Prior to enabling radio resource management on IOS access points, the access points must be under WLSE management.
AirWave becomes the primary management/monitoring vehicle for IOS access points, but for AirWave to gather Rogue
information, the WLSE must be an NMS manager to the APs.
Use these pages to make such configurations:
1. Go to Device > Discover > Advanced Options.
2. Select the method to bring APs into management Auto, or specify via filter.
Inventory Reporting
When new devices are managed, the WLSE generates an inventory report detailing the new APs. AirWave accesses the
inventory report via the SOAP API to auto-discover access points. This is an optional step to enable another form of AP
discovery in addition to AirWave, CDP, SNMP scanning, and HTTP scanning discovery for Cisco IOS access points.
Perform these steps for inventory reporting.
1. Go to Devices > Inventory > Run Inventory.
2. Run Inventory executes immediately between WLSE polling cycles.
Defining Access
AirWave requires System Admin access to WLSE. Use these pages to make these configurations.
1. Go to Administration > User Admin.
2. Configure Role and User.
Grouping
It’s much easier to generate reports or faults if APs are grouped in WLSE. Use these pages to make such configurations.
1. Go to Devices > Group Management.
2. Configure Role and User.
Configuring IOS APs for WDS Participation
IOS APs (1100, 1200) can function in three roles within SWAN:
l Primary WDS
l Backup WDS
l WDS Member
AirWave monitors AP WDS role and displays this information on AP Monitoring page.
APs functioning as WDS Master or Primary WDS will no longer show up as Down is the radios are enabled.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 67
Page 68
WDS Participation
Perform these steps to configure WDS participation.
1. Log in to the AP.
2. Go to the Wireless Services > AP page.
3. Select Enable participation in SWAN Infrastructure.
4. Select Specified Discovery, and enter the IP address of the Primary WDS device (AP or WLSM).
5. Enter the Username and Password for the WLSE server.
Primary or Secondary WDS
Perform these steps to configure primary or secondary functions for WDS.
1. Go to the Wireless Services > WDS > General Setup page.
2. If the AP is the Primary or Backup WDS, select Use the AP as Wireless Domain Services.
n Select Priority (set 200 for Primary, 100 for Secondary).
n Configure the Wireless Network Manager (configure the IP address of WLSE).
3. If the AP is Member Only, leave all options unchecked.
4. Go to the Security > Server Manager page.
5. Enter the IP address and Shared Secret for the ACS server and select Apply.
6. Go to the Wireless Services > WDS > Server Group page.
7. Enter the WDS Group of the AP.
8. Select the ACS server in the Priority 1 drop-down menu and select Apply.
Configuring ACS for WDS Authentication
ACS authenticates all components of the WDS and must be configured first. Perform these steps to make this
configuration.
1. Login to the ACS.
2. Go to the System Configuration > ACS Certificate Setup page.
3. Install a New Certificate by selecting the Install New Certificate button, or skip to the next step if the certificate was
previously installed.
4. Select User Setup in the left frame.
5. Enter the Username that will be used to authenticate into the WDS and select Add/Edit.
6. Enter the Password that will be used to authenticate into the WDS and select Submit.
7. Go to the Network Configuration > Add AAA Client page.
8. Add AP Hostname, AP IP Address, and Community String (for the key).
9. Enter the Password that will be used to authenticate into the WDS and select Submit.
For additional and more general information about ACS, refer to "Configuring ACS Servers" on page 70.
Configuring Cisco WLSE Rogue Scanning
The AMP Setup > WLSE page allows AirWave to integrate with the Cisco Wireless LAN Solution Engine (WLSE).
AirWave can discover APs and gather rogue scanning data from the Cisco WLSE.
Figure 31 illustrates and itemizes the AirWave settings for communication that is enabled between AirWaveand WLSE.
68 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Perform the following steps for optional configuration of AirWave for support of Cisco WLSE rogue scanning.
1. To add a Cisco WLSE server to AirWave , navigate to the AMP Setup > WLSE page and select Add. Complete the
fields in this page. Table 35 describes the settings and default values.
Table 35:
AMP Setup > WLSE Fields and Default Values
SettingDefaultDescription
Hostname/IP AddressNone
ProtocolHTTPSpecify whether to use HTTP or HTTPS when polling the WLSE.
Port1741Defines the port AirWave uses to communicate with the WLSE server.
UsernameNone
PasswordNone
Designates the IP address or DNS Hostname for the WLSE server,
which must already be configured on the Cisco WLSE server.
Defines the username AirWave uses to communicate with the WLSE
server. The username and password must be configured the same
way on the WLSE server and on AirWave.
The user needs permission to display faults to discover rogues and
inventory API (XML API) to discover manageable APs. As derived from
a Cisco limitation, only credentials with alphanumeric characters (that
have only letters and numbers, not other symbols) allow AirWave to
pull the necessary XML APIs.
Defines the password AirWave uses to communicate with the WLSE
server. The username and password must be configured the same
way on the WLSE server and on AirWave.
As derived from a Cisco limitation, only credentials with alphanumeric
characters (that have only letters and numbers, not other symbols)
allow AirWave to pull the necessary XML APIs.
Poll for AP Discovery; Poll
for Rogue Discovery
Polling Period
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 69
Yes
10
minutes
Sets the method by which AirWave uses WLSE to poll for discovery of
new APs and/or new rogue devices on the network.
Determines how frequently AirWave polls WLSE to gather rogue
scanning data.
Page 70
2. After you have completed all fields, select Save. AirWave is now configured to gather rogue information from WLSE
rogue scans. As a result of this configuration, any rogues found by WLSE appear on the RAPIDS > List page.
What Next?
l Go to additional tabs in the AMP Setup section to continue additional setup configurations.
l Complete the required configurations in this chapter before proceeding. Dell support remains available to you for any
phase of AirWave installation.
Configuring ACS Servers
This is an optional configuration. The AMP Setup > ACS page allows AirWave to poll one or more Cisco ACS servers
for wireless username information. When you specify an ACS server, AirWave gathers information about your wireless
users. Refer to "Setting Up Device Types" on page 64 if you want to use your ACS server to manage your AirWave
users.
Perform these steps to configure ACS servers:
1. Go to the AMP Setup > ACS page. This page displays current ACS setup, as illustrated in Figure 32.
Figure 32:AMP Setup > ACS Page Illustration
2. Select Add to create a new ACS server, or select a pencil icon to edit an existing server. To delete an ACS server,
select that server and select Delete. When selecting Add or edit, the Details page appears, as illustrated in Figure 33.
IP/HostnameNoneSets the DNS name or the IP address of the ACS Server.
ProtocolHTTP
Port2002
UsernameNoneSets the Username of the account AirWave uses to poll the ACS server.
PasswordNoneSets the password of the account AirWave uses to poll the ACS server.
Polling Period10 min
Launches a drop-down menu specifying the protocol AirWave uses when it polls the
ACS server.
Sets the port through which AirWave communicates with the ACS. AirWave
generally communicates over port 2002.
Launches a drop-down menu that specifies how frequently AirWave polls the ACS
server for username information.
4. Select Add to finish creating the new ACS server, or Save to finish editing an existing ACS server.
5. The ACS server must have logging enabled for passed authentications. Enable the Log to CSV PassedAuthentications report option, as follows:
n Log in to the ACS server, select System Configuration, then in the Select frame, select Logging.
n Under Enable Logging, select CSV Passed Authentications. The default logging options function and support
AirWave. These include the two columns AirWave requires: User-Name and Caller-ID.
What Next?
l Go to additional tabs in the AMP Setup section to continue additional setup configurations.
l Complete the required configurations in this chapter before proceeding. Dell support remains available to you for any
phase of AirWave installation.
Integrating AirWave with an Existing Network Management Solution
(NMS)
This is an optional configuration. The AMP Setup > NMS configuration page allows AirWave to integrate with other
Network Management Solution (NMS) consoles. This configuration enables advanced and interoperable functionality as
follows:
l AirWave can forward WLAN-related SNMP traps to the NMS, or AirWave can send SNMPv1 or SNMPv2 traps to
the NMS.
l AirWave can be used in conjunction with Hewlett-Packard’s ProCurve Manager.
l The necessary AMP MIB files for either type of NMS interoperability are downloaded from the AMP Setup > NMS
page. For additional information, contact support at dell.com/support.
Perform these steps to configure NMS support in AirWave:
1. Go to AMP Setup > NMS, illustrated in Figure 34.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 71
Page 72
Figure 34:AMP Setup >NMS Page Illustration
2. Select Add to integrate a new NMS server, or select the pencil icon to edit an existing server. Provide the information
described in Table 37:
Table 37:
AMP Setup >NMS Integration Add/Edit Fields and Default Values
SettingDefaultDescription
HostnameNoneCites the DNS name or the IP address of the NMS.
Sets the port AirWave uses to communicate with the NMS.
Port162
Community StringNoneSets the community string used to communicate with the NMS.
SNMP Version2CSets the SNMP version of the traps sent to the Host.
EnabledYesEnables or disables trap logging to the specified NMS.
Send Configuration TrapsYesEnables NMS servers to transmit SNMP configuration traps.
NOTE: AirWave generally communicates via SNMP traps on port
162.
3. The NMS Integration Add/Edit page includes the Netcool/OMNIbus Integration link to information and
instructions. The IBM Tivoli Netcool/OMNIbus operations management software enables automated event correlation
and additional features resulting in optimized network uptime.
4. The NMS Integration Add/Edit page includes the HP ProCurve Manager Integration link. Select this link for
additional information, zip file download, and brief instructions for installation with AirWave. Select Add to finish
creating the NMS server or Save to configure an existing NMS server.
What Next?
l Go to additional tabs in the AMP Setup section to continue additional setup configurations.
72 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 73
l Complete the required configurations in this chapter before proceeding. Dell support remains available to you for any
phase of AirWave installation.
Auditing PCI Compliance on the Network
This section describes PCI requirements and auditing functions in AirWave. It includes the following topics:
l "Introduction to PCI Requirements" on page 73
l "PCI Auditing" on page 73
l "Enabling or Disabling PCI Auditing" on page 75
Introduction to PCI Requirements
AirWave supports wide security standards and functions in the wireless network. One component of network security is
the optional deployment of Payment Card Industry (PCI) Auditing.
The Payment Card Industry (PCI) Data Security Standard (DSS) establishes multiple levels in which payment cardholder
data is protected in a wireless network.AirWave supports PCI requirements according to the standards and specifications
set forth by the following authority:
l Payment Card Industry (PCI) Data Security Standard (DSS)
n PCI Security Standards Council Web site
https://www.pcisecuritystandards.org
n PCI Quick Reference Guide, Version 1.2 (October 2008)
PCI Auditing in AirWave allows you to monitor, audit, and demonstrate PCI compliance on the network. There are five
primary pages in which you establish, monitor, and access PCI auditing, as follows:
l The AMP Setup > PCI Compliance page enables or disables PCI Compliance monitoring on the network, and
displays the current compliance status on the network. See "Enabling or Disabling PCI Auditing" on page 75.
l The Reports > Definitions page allows you to create custom-configured and custom-scheduled PCI Compliance
reports. See "Reports > Definitions Page Overview" on page 278.
l The Reports > Generated page lists PCI Compliance reports currently available, and allows you to generate the
latest daily version of the PCI Compliance Report with a single select. Refer to "Reports > Generated Page
Overview" on page 280.
l The APs/Devices > PCI Compliance page enables you to analyze PCI Compliance for any specific device on the
network. This page is accessible when you select a specific device from the APs/Devices > Monitor page. First, you
must enable this function through AMP Setup. See "Enabling or Disabling PCI Auditing" on page 75.
l The PCI Compliance Report offers additional information. Refer to "Using the PCI Compliance Report" on page
311. This report not only contains Pass or Fail status for each PCI requirement, but cites the action required to
resolve a Fail status when sufficient information is available.
When any PCI requirement is enabled on AirWave, AirWave grades the network as pass or fail for the respective PCI
requirement. Whenever a PCI requirement is not enabled in AirWave, AirWave does not monitor the network’s status in
relation to that requirement, and cannot designate Pass or Fail network status. AirWave users without RAPIDS visibility
enabled will not see the 11.1 PCI requirements in the PCI Compliance Report.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 73
Page 74
Table 38:
PCI Requirements and Support in AirWave
RequirementDescription
Monitoring configuration standards for network firewall devices
When Enabled: PCI Requirement 1.1 establishes firewall and router configuration
standards.
1.1
1.2.3
2.1
A device fails Requirement 1.1 if there are mismatches between the desired
configuration and the configuration on the device.
When Disabled: firewall router and device configurations are not checked for PCI
compliance, and Pass or Fail status is not reported or monitored.
Monitoring firewall installation between any wireless networks and the cardholder data
environment
When Enabled: A device passes requirement 1.2.3 if it can function as a stateful
firewall.
When Disabled: firewall router and device installation are not checked for PCI
compliance.
Monitoring the presence of vendor-supplied default security settings
When Enabled: PCI Requirement 2 establishes the standard in which all vendorsupplied default passwords are changed prior to a device’s presence and operation in
the network.
A device fails requirement 2.1 if the username, passwords or SNMP credentials being
used by AirWave to communicate with the device are on a list of forbidden default
credentials. The list includes common vendor default passwords, for example.
When Disabled: device passwords and other vendor default settings are not checked
for PCI compliance.
2.1.1
4.1.1
11.1
Changing vendor-supplied defaults for wireless environments
When Enabled: A device fails requirement 2.1.1 if the passwords, SSIDs, or other
security-related settings are on a list of forbidden values that AirWave establishes and
tracks. The list includes common vendor default passwords. The user can input new
values to achieve compliance.
When Disabled: network devices are not checked for forbidden information and PCI
Compliance is not established.
Using strong encryption in wireless networks
When Enabled: PCI Requirement 4 establishes the standard by which payment
cardholder data is encrypted prior to transmission across open public networks. PCI
disallows WEP encryption as an approved encryption method after June 20, 2010. A
device fails requirement 4.1.1 if the desired or actual configuration reflect that WEP is
enabled on the network, or if associated users can connect with WEP.
When Disabled: AirWave cannot establish a pass or fail status with regard to PCI
encryption requirements on the network.
Identifying unauthorized wireless devices.
When enabled, a report will indicate a failure if there are unacknowledged rogue APs
present in RAPIDS or there are no wireless rogues discovered in the last three months.
74 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 75
Table 38:
PCI Requirements and Support in AirWave (Continued)
RequirementDescription
Using intrusion-detection or intrusion-prevention systems to monitor all traffic
When Enabled: AirWave reports pass or fail status when monitoring devices capable of
reporting IDS events. Recent IDS events are summarized in the PCI Compliance report
11.4
or the IDS Report.
When Disabled: AirWave does not monitor the presence of PCI-compliant intrusion
detection or prevention systems, nor can it report Pass or Fail status with regard to IDS
events.
Enabling or Disabling PCI Auditing
Perform these steps to verify status and to enable or disable AirWave support for PCI 1.2 requirements. enabling one or
all PCI standards on AirWave enables real-time information and generated reports that advise on Pass or Fail status. The
PCI auditing supported in AirWave is reported in Table 1 in the "PCI Auditing" on page 73 section.
1. To determine what PCI Compliance standards are enabled or disabled on AirWave, navigate to the AMP Setup >PCI Compliance page, illustrated in Figure 35.
2. To enable, disable, or edit any category of PCI Compliance monitoring in AirWave, select the pencil icon next to the
category. The Default Credential Compliance page displays for the respective PCI standard.
3. Create changes as required. The edit pages will vary based on the PCIRequirement that you select. Figure 36 shows
an example of how to edit the PCI 2.1 requirement.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 75
Page 76
Figure 36:Default Credential Compliance for PCI Requirements
4. Select Save.
5. To view and monitor PCI auditing on the network, use generated or daily reports. See "Creating, Running, and
Emailing Reports" on page 278. In addition, you can view the real-time PCI auditing of any given device online.
Perform these steps:
a. Go to the APs/Devices > List page.
b. Select a specific device. The Monitor page for that device displays. The APs/Devices page also displays a
Compliance subtab in the menu bar.
c. Select Compliance to view complete PCI compliance auditing for that specific device.
Deploying WMS Offload
Overview of WMS Offload in AirWave
This section describes the Dell Networking W-Series Wireless LAN Management Server (WMS) offload infrastructure.
WMS Offload is supported with the following two requirements:
l ArubaOS Version 2.5.4 or later
l AirWave Version 6.0 or later
The Dell Networking W WMS feature is an enterprise-level hardware device and server architecture with managing
software for security and network policy. There are three primary components of the WMS deployment:
l Air Monitor AP devices establish and monitor RF activity on the network.
l The WMS server manages devices and network activity to include rogue AP detection and enforcement of network
policy.
l The AirWave graphical user interface (GUI) allows users to access and use the WMS functionality.
WMS Offload is the ability to place the burden of the WMS server data and GUI functions on AirWave. WMS master
controllers provide this data so that AirWave can support rigorous network monitoring capabilities.
General Configuration Tasks Supporting WMS Offload in AirWave
WMS Offload must be enabled with a six-fold process and related configuration tasks as follows:
1. Configure WLAN switches for optimal AirWave monitoring.
76 | Configuring AirWaveDell Network ing W-AirWave 8.0 | User Guide
Page 77
a. Disable debugging.
b. Ensure the AirWave server is a trap receiver host.
c. Ensure proper traps are enabled.
2. Configure AirWave to optimally monitor the AirWave infrastructure.
a. Enable WMS offload on the AMP Setup > General page.
b. Configure SNMP communication.
c. Create a proper policy for monitoring the AirWave infrastructure.
d. Discover the infrastructure.
3. Configure device classification.
a. Set up rogue classification.
b. Set up rogue classification override.
c. Establish user classification override devices.
4. Deploy ArubaOS-specific monitoring features.
a. Enable remote AP and wired network monitoring.
b. View controller license information.
5. Convert existing floor plans to VisualRF to include the following elements:
l Dell Networking W-Series ArubaOS
l RF Plan
6. Use RTLS for increasing location accuracy (optional).
a. Enable RTLS service on the AirWave server.
b. Enable RTLS on ArubaOS infrastructure.
Additional Information Supporting WMS Offload
Refer to the Dell Networking W-AirWave8.0 Best Practices Guide at dell.com/support/manuals for additional
information, including detailed concepts, configuration procedures, restrictions, ArubaOS infrastructure, and AirWave
version differences in support of WMS Offload.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring AirWave | 77
Page 78
Chapter 3
Configuring and Using Device Groups
This section describes the deployment of device groups within AirWave. The section below describes the pages or
focused subtabs available on the Groups tab. Note that the available subtabs can vary significantly from one device
group to another. One or more subtabs may not appear, depending on the Default Group display option selected on the
AMP SetupSetup > General page and the types of devices you add to AirWave.
Figure 37:Subtabs under the Group tab
Table 39:
Menu
Item
List
Monitor
Basic
Templates
Groups pages
DescriptionRefer to
"Viewing All
This page is the default page in the Groups section of AirWave. It lists all groups currently
configured in AirWave and provides the foundation for all group-level configurations.
This page displays client and bandwidth usage information, lists devices in a given group,
provides an Alert Summary table for monitoring alerts for the group, and provides a detailed
Audit Log for group-level activity.
This page appears when you create a new group on the Groups > List page. Once you
define a group name, AirWave displays the Basic page from which you configure many
group-level settings. This page remains available for any device group configured in
AirWave.
This page manages templates for any device group. Templates allow you to manage the
configuration of Dell Networking W-Series, 3Com, Alcatel-Lucent, Aruba Networks, Cisco
Aironet IOS, Cisco Catalyst switches, Enterasys, HP, Nortel, Symbol and Trapeze devices in
a given group using a configuration file. Variables in such templates configure devicespecific properties, such as name, IP address and channel. Variables also define grouplevel properties.
Defined
Device
Groups" on
page 81
"Viewing
Device
Monitoring
Statistics" on
page 136
"Configuring
Basic Group
Settings" on
page 82
"Creating and
Using
Templates" on
page 178
"Configuring
Security
SSIDThis page sets SSIDs, VLANs, and related parameters in device groups.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring and Using Device Groups | 78
This page defines general security settings for device groups, to include RADIUS,
encryption, and additional security settings on devices.
Group
Security
Settings" on
page 92
"Configuring
Group SSIDs
and VLANs"
on page 96
Page 79
Table 39:
Groups pages (Continued)
Menu
Item
AAA
Servers
RadioThis page defines general 802.11 radio settings for device groups.
Controller
Config
Instant
Config
DescriptionRefer to
This page configures authentication, authorization, and accounting settings in support of
RADIUS servers for device groups.
This page manages ArubaOS Device Groups, AP Overrides, and other profiles specific to
Dell Networking W-Series devices on the network. Use this page as an alternative to the
Device Setup > Dell Networking W >Configuration page. The appearance of this page
varies depending on whether AirWave is configured for global configuration or group
configuration.
This page manages Dell Networking W-Instant devices on the network.
"Adding and
Configuring
Group AAA
Servers" on
page 91
"Configuring
Radio
Settings for
Device
Groups" on
page 100
This page consolidates controller-level settings from the Group Radio, Security, SSIDs,
Cisco WLC Radio and AAA Server pages into one navigation tree that is easier to navigate,
and has familiar layout and terminology. Bulk configuration for per-thin AP settings,
previously configured on the Group LWAPP APs tab, can now be performed from Modify
Devices on the APs/Devices > List page.
This page defines settings specific to Proxim MP devices when present. As such, this page
is only available when a Proxim MP device is added to this group.
This page defines mesh AP settings specific to Proxim devices when present.
This page defines MAC-specific settings that apply to Proxim, Symbol, and ProCurve 520
devices when present.
"Cisco WLC
Group
Configuration"
on page 104
"Configuring
Group PTMP
Settings" on
page 110.
"Configuring
Proxim Mesh
Radio
Settings" on
page 111
"Configuring
Group MAC
Access
Control Lists"
on page 113
79 | Configuring and Using Device GroupsDel l Networki ng W-Ai rWav e 8.0 | User Guide
Page 80
Table 39:
Groups pages (Continued)
Menu
Item
FirmwareThis page manages firmware files for many devices.
Compare
DescriptionRefer to
This page allows you to compare line item-settings between two device groups. On the
Groups > List page, select the Compare two groups link, select the two groups from the
drop-down menus, and then select Compare. Refer to
This section also provides the following additional procedures for group-level configurations:
l "Deleting a Group" on page 116
l "Changing Multiple Group Configurations " on page 117
l "Modifying Multiple Devices" on page 118
l "Using Global Groups for Group Configuration" on page 120
AirWave Groups Overview
"Specifying
Minimum
Firmware
Versions for
APs in a
Group" on
page 114
"Comparing
Device
Groups" on
page 115
Enterprise APs, controllers, routers, and switches have hundreds of variable settings that must be configured precisely in
order to achieve optimal performance and network security. Configuring all settings on each device individually is time
consuming and error prone. AirWave addresses this challenge by automating the processes of device configuration and
compliance auditing. At the core of this approach is the concept of Device Groups, which have the following functions
and benefits:
l AirWave allows certain settings to be managed efficiently at the Group level, while others are managed at an
individual device level.
l AirWave defines a Group as a subset of the devices on the wireless LAN, ranging in size from one device to
hundreds of devices that share certain common configuration settings.
l Groups can be defined based on geography (such as 5th Floor APs), usage or security policies (such as Guest Access
APs), function (such as Manufacturing APs), or any other appropriate variable.
l Devices within a group may originate from different vendors or hardware models, but all devices within a Group
share certain basic configuration settings.
Typical group configuration variables include the following settings:
l Basic settings - SSID, SNMP polling interval, and so forth
l Security settings - VLANs, WEP, 802.1x, ACLs, and so forth
l Radio settings - data rates, fragmentation threshold, RTS threshold, DTIM, preamble, and so forth.
When configuration changes are applied at a group level, they are assigned automatically to every device within that
group. Such changes must be applied with every device in Managed mode. Monitor mode is the more common mode.
Always review the Audit page before pushing configurations to a device or group.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring and Using Device Groups | 80
Page 81
Individual device settings—such as device name, RF channel selection, RF transmission power, antenna settings, and so
forth—typically should not be managed at a group level and must be individually configured for optimal performance.
Individual AP settings are configured on the APs/Devices > Manage page.
You can create as many different groups as required. Administrators usually establish groups that range in size from five
to 100 wireless devices.
Group configuration can be enhanced with the AirWave Global Groups feature, which lets you create Global Groups
with configurations that are pushed to individual Subscriber Groups.
The columns in the default view of the Groups > Monitor page is defined in Dell Networking W-AirWave and cannot
be modified. However, you can create a new view of this page that returns custom information based on the filter
parameters and data columns you selected when creating that new view. For more information, see "Creating
CustomFiltered Views" on page 137.
Viewing All Defined Device Groups
To display a list of all defined groups, browse to the Groups > List page, illustrated in Figure 38.
Figure 38:Groups > List Page Illustration (partial view)
Table 40 describes the columns in the Groups > List page.
Table 40:
Groups > List Columns
ColumnDescription
Add New
Group
Manage
(wrench icon)
Name
Up/Down
Status Polling
Period
Total DevicesTotal number of devices contained in the group including APs, controllers, routers, or switches.
ChangesDisplays when a group has unapplied changes.
Launches a page that enables you to add a new group by name and to define group
parameters for devices in that group. For additional information, refer to "Configuring Basic
Group Settings" on page 82.
Goes to the Groups > Basic configuration page for that group. Hover your mouse over the icon
to see a list of shortcuts to group-specific subtabs that would appear across the navigation
section if this group is selected. (See Figure 39 in "Configuring Basic Group Settings" on page
82.)
Uniquely identifies the group by location, vendor, department or any other identifier (such as
‘Accounting APs,’ ‘Floor 1 APs,’ ‘Cisco devices,’ ‘802.1x APs,’ and so forth).
The time between Up/Down SNMP polling periods for each device in the group. Detailed
SNMP polling period information is available on the Groups > Basic configuration page. Note
that by default, most polling intervals do not match the up/down period.
81 | Configuring and Using Device GroupsDel l Networki ng W-Ai rWav e 8.0 | User Guide
Page 82
Table 40:
Groups > List Columns (Continued)
ColumnDescription
If a group is designated as global, it may not contain APs but it may be used as a template for
Is Global Group
Global GroupSpecifies which group this Subscriber Group is using as its template.
SSIDThe SSID assigned to supported device types within the group.
Down
MismatchedThe number of devices within the group that are in a mismatched state.
IgnoredThe number of ignored devices in that group.
Clients
UsageA running average of the sum of bytes in and bytes out for the managed radio page.
other groups. This column may also indicate Yes if this group has been pushed to AirWave
from a Master Console.
The number of access points within the group that are not reachable via SNMP or are no
longer associated to a controller. Note that thin APs are not directly polled with SNMP, but are
polled through the controller. That controller may report that the thin AP is down or is no longer
on the controller. At this point, AirWave classifies the device as down.
The number of mobile users associated with all access points within the group. To avoid
double counting of clients, clients are only listed in the group of the AP with which they are
associated. Note that device groups with only controllers in them report no clients.
VPN SessionsNumber of active (connected) VPN sessions under this group.
Duplicate
When you first configure AirWave, there is only one default group labeled Access Points. If you have no other groups
configured, refer to "Configuring Basic Group Settings" on page 82.
Creates a new group with the name Copy of <Group Name> with identical configuration
settings. (Dell configuration settings will have to be manually added back.)
Configuring Basic Group Settings
The first default device group that AirWave sets up is the Access Points group, but you can use this procedure to add
and configure any device group. Perform these steps to configure basic group settings, then continue to additional
procedures to define additional settings as required.
l To create a new group, select Add on the Groups > List page. Enter a group name and select Add. The Groups >
Basic page appears.
l To edit an existing device group, select the manage (wrench) icon next to the group. The Groups > Basic page
appears. If you mouse over an existing group’s wrench, a popup menu displays, allowing you to select options such
as Basic, Templates, Security, SSIDs, AAA Servers, Radio, Controller Config, Instant Config, and Cisco WLCConfig. See Figure 39.
The mouse-over list can vary based on a group's settings.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring and Using Device Groups | 82
Page 83
Figure 39:Pop-up When Hovering over Wrench Icon in Groups > List
Figure 40 illustrates one example of the Groups > Basic page.
83 | Configuring and Using Device GroupsDel l Networki ng W-Ai rWav e 8.0 | User Guide
Page 84
Figure 40:Groups > Basic Page Illustration
1. Define the settings in the Basic and Global Group sections. Table 41 describes several typical settings and default
values of this Basic section.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring and Using Device Groups | 84
Page 85
Table 41:
Basic and Global Groups Fields and Default Values
SettingDefaultDescription
Name
Missed SNMP
Poll Threshold
(1-100)
Regulatory
Domain
Timezone
Allow One-toOne NAT
Audit
Configuration
on Devices
Is Global
Group
Defined
when first
adding the
group
1
United States
AMP System
Time
No
Yes
No
Displays or changes the group name. As desired, use this field to set the name
to uniquely identify the group by location, vendor, department, or any other
identifier (such as Accounting APs, Cisco devices, 802.1x APs, and so forth).
Sets the number of Up/Down SNMP polls that must be missed before AirWave
considers a device to be down. The number of SNMP retries and the SNMP
timeout of a poll can be set on the Device Setup > Communication page.
Sets the regulatory domain in AirWave, limiting the selectable channels for APs
in the group.
Allows group configuration changes to be scheduled relative to the time zone in
which the devices are located. This setting is used for scheduling group-level
configuration changes.
Allows AirWave to talk to the devices on a different IP address than the one
configured on the device.
NOTE: If enabled, the LAN IP Address listed on the AP/Devices > Manage
configuration page under the Settings area is different than the IP Address
under the Device Communication area.
Auditing and pushing of configuration to devices can be disabled on all the
devices in the group. Once disabled, all the devices in the groups will not be
counted towards mismatched devices.
If specified as Yes, then this group can be selected in the Use Global Group
drop down menu for future group configurations.
Use Global
Group
No
When enabled, this field allows you to define the device group to be a Global
Group. Refer to "Using Global Groups for Group Configuration" on page 120.
2. Complete the SNMP Polling Periods section. The information in this section overrides default settings. Table 42
describes the SNMP polling settings.
Table 42:
SNMP Polling Periods Fields and Default Values
SettingDefaultDescription
Sets time between Up/Down SNMP polling for each device in the
Up/Down Status Polling
Period
Override Polling Period
for Other Services
AP Interface Polling
Period
5 minutes
No
10
minutes
group.
The Group SNMP Polling Interval overrides the global parameter
configured on the Device Setup > Communication page. An initial
polling interval of 5 minutes is best for most networks.
Enables or disables overriding the base SNMP Polling Period. If you
select Yes, the other settings in the SNMP Polling Periods section are
activated, and you can override default values.
Sets the interval at which AirWave polls for radio monitoring and
bandwidth being used by a device.
85 | Configuring and Using Device GroupsDel l Networki ng W-Ai rWav e 8.0 | User Guide
Page 86
Table 42:
SNMP Polling Periods Fields and Default Values (Continued)
SettingDefaultDescription
Client Data Polling Period
Thin AP Discovery Polling
Period
Device-to-Device link
Polling Period
802.11 Counters Polling
Period
Rogue AP and Device
Location Data Polling
Period
CDP Neighbor Data
Polling Period
Mesh Discovery Polling
Period
10
minutes
15
minutes
5 minutes
15
minutes
30
minutes
30
minutes
15
minutes
Sets time between SNMP polls for client data for devices in the group.
Sets time between SNMP polls for Thin AP Device Discovery.
Controllers are the only devices affected by this polling interval.
Sets time between SNMP polls for Device-to-Device link polling. Mesh
APs are the only devices affected by this polling interval.
Sets time between SNMP polls for 802.11 Counter information.
Sets time between SNMP polls for Rogue AP and Device Location
Data polling.
Sets the frequency in which this group polls the network for Cisco
Discovery Protocol (CDP) neighbors.
Sets time between SNMP polls for Mesh Device Discovery.
3. To configure support for routers and switches in the group, locate the Routers and Switches section and adjust these
settings as required. This section defines the frequency in which all devices in the group polled. These settings can
be disabled entirely as desired. Table 43 describes the SNMP polling settings.
Table 43:
Routers and Switches Fields and Default Values
SettingDefaultDescription
Sets the frequency in which devices poll routers and switches for
Read ARP Table4 hours
Read CDP Table for
Device Discovery
Read Bridge Forwarding
Table
Interface Up/Down Polling
Period
Interface Bandwidth
Polling Period
4 hours
4 hours
5 minutes
15
minutes
Address Resolution Protocol (ARP) table information. This setting can
be disabled, or set to poll for ARP information in a range from every 15
seconds to 12 hours.
For Cisco devices, sets the frequency in which devices poll routers
and switches for Cisco Discovery Protocol (CDP) information. This
setting can be disabled, or set to poll for CDP neighbor information in
a range from every 15 seconds to 12 hours.
Sets the frequency in which devices poll the network for bridge
forwarding information. This setting can be disabled, or set to poll
bridge forwarding tables from switches in a range from every 15
seconds to 12 hours.
Sets the frequency in which network interfaces are polled for up/down
status. This setting can be disabled, or set to poll from switches in a
range from every 15 seconds to 30 minutes.
Sets the frequency in which network interfaces are polled for
bandwidth usage. This setting can be disabled, or set to poll from
switches in a range from every 5 minutes to 30 minutes.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring and Using Device Groups | 86
Page 87
Table 43:
Routers and Switches Fields and Default Values (Continued)
SettingDefaultDescription
Interface Error Counter
Polling Period
Poll 802.3 error countersNoSets whether 802.3 error counters should be polled.
Poll Cisco interface error
counters
30
minutes
No
Sets the frequency in which network interfaces are polled for up/down
status. This setting can be disabled, or set to poll bridge forwarding
tables from switches in a range from every 5 minutes to 30 minutes.
Sets whether the interface error counters for Cisco devices should be
polled.
4. Record additional information and comments about the group in the Notes section.
5. To configure which options and tabs are visible for the group, complete the settings in the Group Display Options
section. Table 44 describes the settings and default values.
Table 44:
Group Display Options Fields and Default Values
SettingDefaultDescription
Drop-down menu determines which Group tabs and options are to be viewable by
default in new groups. Settings include the following:
l All Devices—AirWave displays all Group tabs and setting options.
l Only devices in t his group—AirWave hides all options and tabs that do not
apply to the devices in the group. If you use this setting, then to get the group
list to display the correct SSIDs for the group, you must Save and Apply on the
group.
l Only devices on this AMP— hides all options and tabs that do not apply to the
APs and devices currently on AirWave.
l Use system default s—Use the default settings on AMP Setup > General
l Selected device types—Allows you to specify the device types for which
AirWave displays Group settings.
Show device
settings for
Only
devices
on this
AMP
Selected
Device Types
N/A
This option appears if you chose to display selected device types, allowing you to
select the device types to display group settings. Use Select devices in this group
to display only devices in the group being configured.
6. To assign dynamically a range of static IP addresses to new devices as they are added into the group, locate the
Automatic Static IP Assignment section on the Groups > Basic configuration page. If you select Yes in this section,
additional fields appear. Complete these fields as required. Table 45 describes the settings and default values This
section is only relevant for a small number of device types, and will appear when they are present.
Table 45:
Automatic Static IP Assignment Fields and Default Values
SettingDefaultDescription
Assign Static
IP Addresses
to Devices
Start IP
Address
Number of
Addresses
No
noneSets the first address AirWave assigns to the devices in the Group.
none
Specify whether to enable AirWave to statically assign IP addresses from a
specified range to all devices in the Group. If this value is set to Yes, then the
additional configuration fields described in this table will become available.
Sets the number of addresses in the pool from which AirWave can assign IP
addresses.
87 | Configuring and Using Device GroupsDel l Networki ng W-Ai rWav e 8.0 | User Guide
Page 88
Table 45:
Automatic Static IP Assignment Fields and Default Values (Continued)
SettingDefaultDescription
Subnet MasknoneSets the subnet mask to be assigned to the devices in the Group.
Subnet
Gateway
Next IP
Address
noneSets the gateway to be assigned to the devices in the Group.
none
Defines the next IP address queued for assignment. This field is disabled for the
initial Access Points group.
7. To configure Spanning Tree Protocol on WLC devices and Proxim APs, locate the Spanning Tree Protocol section
on the Groups > Basic configuration page. Adjust these settings as required. Table 46 describes the settings and
default values.
Table 46:
Spanning Tree Protocol Fields and Default Values
SettingDefaultDescription
Spanning Tree
Protocol
Bridge Priority32768
Bridge
Maximum Age
No
20
Specify wehther to enable or disables Spanning Tree Protocol on Proxim APs.If
this value is set to Yes, then the additional configuration fields described in this
table will become available.
Sets the priority for the AP. Values range from 0 to 65535. Lower values have
higher priority. The lowest value is the root of the spanning tree. If all devices are
at default the device with the lowest MAC address will become the root.
Sets the maximum time, in seconds, that the device stores protocol information.
The supported range is from 6 to 40.
Bridge Hello
Time
Bridge
Forward Delay
2Sets the time, in seconds, between Hello message broadcasts.
15
Sets the time, in seconds, that the port spends in listening and learning mode if
the spanning tree has changed.
8. To configure Network Time Protocol (NTP) settings locate the NTP section and adjust these settings as required.
Table 47 describes the settings and default values.
Table 47:
NTP Fields and Default Values
SettingDefaultDescription
NTP Server
#1,2,3
UTC Time
Zone
Daylight
Saving Time
NoneSets the IP address of the NTP servers to be configured on the AP.
0
No
Sets the hour offset from UTC time to local time for the AP. Times displayed in
AirWave graphs and logs use the time set on the AirWave server.
Enables or disables the advanced daylight saving time settings in the Proxim
section of the Groups > Basic configuration page.
9. To configure settings specific to Cisco IOS/Catalyst, locate the Cisco IOS/Catalyst section and adjust these settings
as required. Table 48 describes the settings and default values.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring and Using Device Groups | 88
Page 89
Table 48:
Cisco IOS/Catalyst Fields and Default Values
SettingDefaultDescription
SNMP Version2cThe version of SNMP used by AirWave to communicate to the AP.
The protocol AirWave uses to communicate with Cisco IOS devices.
Cisco IOS CLI
Communication
Cisco IOS Config
File
Communication
Telnet
TFTP
Selecting SSH uses the secure shell for command line page (CLI)
communication and displays an SSH Version option. Selecting Telnet
sends the data in clear text via Telnet.
The protocol AirWave uses to communicate with Cisco IOS devices.
Selecting SCP uses the secure copy protocol for file transfers and displays
an SCP Version option. Selecting TFTP will use the insecure trivial file
transfer protocol. The SCP login and password should be entered in the
Telnet username and password fields.
10. To configure settings specific to Cisco WLC, locate the Cisco WLC section and adjust these settings as required.
Table 49 describes the settings and default values.
Table 49:
Cisco WLC Fields and Default Values
SettingDefaultDescription
SNMP Version2c
CLI CommunicationSSH
When configuring Cisco WLC controllers, refer to "Configuring Wireless Parameters for Cisco Controllers" on page 109.
Sets the version of SNMP used by AirWave to communicate to WLC
controllers.
Sets the protocol AirWave uses to communicate with Cisco IOS devices.
Selecting SSH uses the secure shell for command line page (CLI)
communication. Selecting Telnet sends the data in clear text via Telnet.
11. To configure settings specific to Dell locate the Aruba/Dell Networking W section and adjust these settings as
required. Table 50 describes the settings and default values of this section.
Table 50:
Aruba Fields and Default Values
SettingDefaultDescription
SNMP Version2cThe version of SNMP used by AirWave to communicate to the AP.
Configures commands previously documented in the Dell Networking W-
Offload WMS
Database
No
AirWave 8.0
to display historical information for WLAN switches.
Changing the setting to Yes pushes commands via SSH to all WLAN switches
in Monitor Only mode without rebooting the controller. The command can be
pushed to controllers in manage mode (also without rebooting the controller) if
the Allow WMS Offload setting on AMP Setup > G eneral is changed to Yes.
Best Practices Guide
. When enabled, this feature allows AirWave
Dell Networking
W-Series GUI
Config
89 | Configuring and Using Device GroupsDel l Networki ng W-Ai rWav e 8.0 | User Guide
Yes
This setting selects whether you'd like to configure your devices using the
Groups > Controller method (either global or group) or using Templates.
Page 90
Table 50:
Aruba Fields and Default Values (Continued)
SettingDefaultDescription
Ignore Rogues
Discovered by
Remote APs
Delete
Certificates On
Controller
No
NoSpecifies whether to delete the current certificates on an ArubaOS controller.
Configures whether to turn off RAPIDS rogue classification and rogue
reporting for RAPs in this group.
12. To configure settings for 3Com, Enterasys, Nortel, or Trapeze devices, locate the 3Com/Enterasys/Nortel/Trapeze
section and define the version of SNMP to be supported.
13. To configure settings for universal devices on the network, including routers and switches that support both wired
and wireless networks, locate the Universal Devices, Routers and Switches section of the Groups > Basic page and
define the version of SNMP to be supported.
14. To control the conditions by which devices are automatically authorized into this group, locate the AutomaticAuthorization settings section and adjust these settings as required. Table 51 describes the settings and default
values.
Table 51:
Automatic Authorization Fields and Default Values
SettingDefaultDescription
Whether to auto authorize new controllers to the New Devices List, the same
Add New Controllers
and Autonomous
Devices Location
Use
Global
Setting
Group/Folder as the discovering devices, the same Group/Folder as the
closest IP neighbor, and/or a specified auto-authorization group and folder.
The Current Global Setting set in AMP Setup > General is shown below this
field. Selecting a different option overrides the global setting.
Whether to auto authorize new thin APs to the New Devices List, the same
Add New Thin APs
Location
Use
Global
Setting
Group/Folder as the discovering devices, the same Group/Folder as the
closest IP neighbor, and/or a specified auto-authorization group and folder.
The Current Global Setting set in AMP Setup > General is shown below.
Selecting a different option overrides the global setting for this group.
15. The specify the Virtual Controller Certificates to be applied to this group, locate the Virtual Controller Certificates
settings section and adjust these settings as desired. Table 52 describes the settings and default values.
Table 52:
Virtual Controller Certificate Fields and Default Values
SettingDefaultDescription
Specify a CA certificate for the virtual controller. The fields in this drop down
CA CertNone
Server CertNone
will populate when a certificate of type Intermediate CA or Trusted CA is
added in the Device Setup > Certificates page.
Specify a server certificate for the virtual controller. The fields in this drop
down will populate when a certificate of type Server Cert is added in the
Device Setup > Certificates page.
16. To automate putting multiple devices in this group into Manage mode at once so that changes can be applied and
have the devices revert to Monitor-Only mode after the maintenance period is over, locate the MaintenanceWindows option and define a new AP Group Maintenance Window.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring and Using Device Groups | 90
Page 91
17. Select Save when the configurations of the Groups > Basic configuration page are complete to retain these settings
without pushing these settings to all devices in the group. Save is a good option if you intend to make additional
device changes in the group, and you want to wait until all configurations are complete before you push all
configurations at one time. Select Save and Apply to make the changes permanent, or select Revert to discard all
unapplied changes.
What Next?
l Continue to additional sections in this chapter to create new groups or to edit existing groups.
l Once general group-level configurations are complete, continue to later chapters in this document to add or edit
additional device-level configurations and to use several additional AirWave functions.
Adding and Configuring Group AAA Servers
Configure RADIUS servers on the Groups > AAA Servers page.
Once defined on this page, RADIUS servers are selectable in the drop-down menus on the Groups > Security andGroups > SSIDs configuration pages. Perform these steps to create RADIUS servers.
TACACS+ servers are configurable only for Cisco WLC devices. Refer to "Configuring Cisco WLC Security Parameters
and Functions" on page 109.
1. Go to the Groups > List page and select the group for which to define AAA servers by selecting the group name.
The Monitor page appears.
2. Select the AAA Servers page. The AAA Servers page appears, enabling you to add a RADIUS server. Figure 41
illustrate this page for AAA RADIUS Servers:
Figure 41:Groups > AAA Servers Page Illustration
3. To add a RADIUS server or edit an existing server, select Add New RADIUS Server or the corresponding pencil
icon to edit an existing server. Table 53 describes the settings and default values of the Add/Edit page.
Table 53:
Adding a RADIUS Server Fields and Default Values
SettingDefaultDescription
Hostname/IP
Address
None
Sets the IP Address or DNS name for RADIUS Server.
NOTE: IP Address is required for Proxim/ORiNOCO and Cisco Aironet IOS
APs.
91 | Configuring and Using Device GroupsDel l Networki ng W-Ai rWav e 8.0 | User Guide
Page 92
Table 53:
Adding a RADIUS Server Fields and Default Values (Continued)
SettingDefaultDescription
Sets the shared secret that is used to establish communication between
Secret and Confirm
Secret
None
AirWave and the RADIUS server.
NOTE: The shared secret entered in AirWave must match the shared secret on
the server.
AuthenticationNo
Authentication Port
(1-65535)
AccountingNo
Accounting Port (1-
65535)
Timeout (0-86400)None
Max Retries
(0-20)
1812
1813
None
Sets the RADIUS server to perform authentication when this setting is enabled
with Yes.
Appears when Aut hentication is enabled. Sets the port used for communication
between the AP and the RADIUS server.
Sets the RADIUS server to perform accounting functions when enabled with
Yes.
Appears when Accounting is enabled.Sets the port used for communication
between the AP and the RADIUS server.
Sets the time (in seconds) that the access point waits for a response from the
RADIUS server.
Sets the number of times a RADIUS request is resent to a RADIUS server
before failing.
NOTE: If a RADIUS server is not responding or appears to be responding
slowly, consider increasing the number of retries.
4. Select Add to complete the creation of the RADIUS server, or select Save if editing an existing RADIUS server. The
Groups > AAA Servers page displays this new or edited server. You can now reference this server on the Groups >
Security page.
AirWave supports reports for subsequent RADIUS Authentication. These are viewable by selecting Reports >
Generated, scrolling to the bottom of the page, and selecting Latest RADIUS Authentication Issues Report.
5. To make additional RADIUS configurations for device groups, use the Groups > Security page and continue to the
next topic.
Configuring Group Security Settings
The Groups > Security page allows you to set security policies for APs in a device group:
1. Select the device group for which to define security settings from the Groups > List page.
2. Go to Groups > Security. Some controls on this page interact with additional AirWave pages. Figure 42 illustrates
this page and Table 54 explains the fields and default values.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring and Using Device Groups | 92
Page 93
Figure 42:Groups > Security Page Illustration
Table 54:
Groups > Security Page Fields and Default Values
SettingDefaultDescription
VLANs Section
This field enables support for VLANs and multiple SSIDs on the wireless
network. If this setting is enabled, define additional VLANs and SSIDs on
VLAN Tagging and
Multiple SSIDs
Enabled
Management VLAN IDUntagged
General Section
Create Closed NetworkNo
the Groups > SSIDs page. Refer to "Configuring Group SSIDs and
VLANs" on page 96. If this setting is disabled, then you can specify the
Encryption Mode in the Encryption section that displays. Refer to
"Groups > Security Encryption Mode settings" on page 95 for information
on configuring Encryption.
This setting sets the ID for the management VLAN when VLANs are
enabled in AirWave . This setting is supported only for the following
devices:
l Proxim AP-600, AP-700, AP-2000, AP-4000
l Avaya AP-3, Avaya AP-7, AP-4/5/6, AP-8
l ProCurve520WL
If enabled, the APs in the Group do not broadcast their SSIDs.
NOTE: Creating a closed network will make it more difficult for intruders
to detect your wireless network.
If enabled, this setting blocks client devices associated with an AP from
Block All Inter-client
Communication
No
communicating with other client devices on the wireless network.
NOTE: This option may also be identified as PSPF (Publicly Secure
Packet Forwarding), which can be useful for enhanced security on public
wireless networks.
EAP Options Sect ion
93 | Configuring and Using Device GroupsDel l Networki ng W-Ai rWav e 8.0 | User Guide
Page 94
Table 54:
Groups > Security Page Fields and Default Values (Continued)
SettingDefaultDescription
WEP Key Rotation
Interval
300
RADIUS Authentication Servers Section
RADIUS Authentication
Server #1 - #4
Authentication Profile
Name
Authentication Profile
Index
Not
selected
AirWaveDefined
Server #1
1
RADIUS Accounting Servers Section
RADIUS Accounting
Server #1 - #4
Not
selected
Authentication Profile
Name
Authentication Profile
Index
3
Sets the frequency at which the Wired Equivalent Privacy (WEP) keys
are rotated in the device group being configured. The supported range is
from 0 to 10,000,000 seconds.
Defines one or more RADIUS Authentication servers to be supported in
this device group. Select up to four RADIUS authentication servers from
the four drop-down menus.
For Proxim devices only, this field sets the name of the authentication
profile to be supported in this device group.
For Proxim devices only, this field sets the name of the authentication
profile index to be supported in this device group.
Defines one or more RADIUS Accounting servers to be supported in this
device group. Select up to four RADIUS accounting servers from the four
drop-down menus.
For Proxim devices only, this field sets the name of the accounting profile
to be supported in this device group.
For Proxim devices only, this field sets the name of the accounting profile
index to be supported in this device group.
MAC Address Authentication Section
MAC Address
Authentication
No
If enabled, only MAC addresses known to the RADIUS server are
permitted to associate to APs in the Group.
Allows selection of the format for MAC addresses used in RADIUS
authentication and accounting requests:
l Dash Delimited: xx-xx-xx-xx-xx-xx (default)
MAC Address Format
Single
Dash
l Colon Delimited: xx:xx:xx:xx:xx:xx
l Single-Dash: xxxxxx-xxxxxx
l No Delimiter: xxxxxxxxxxxx
This option is supported only for Proxim AP-600, AP-700, AP-2000, AP4000, Avaya AP3/4/5/6/7/8, HP ProCurve 520WL
Authorization Lifetime1800
Primary RADIUS Server
Reattempt Period
0
Sets the amount of time a user can be connected before reauthorization
is required. The supported range is from 900 to 43,200 seconds.
Specifies the time (in minutes) that the AP awaits responses from the
primary RADIUS server before communicating with the secondary
RADIUS server, and so forth
The Encryption options display on the Groups > Security page when the VLAN Tagging and Multiple SSIDs option
is set to Disabled. This setting defaults to No Encryption. Refer to Table 55 for information regarding configuring
encryption.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring and Using Device Groups | 94
CKIP MMH ModeNoSpecify whether to use Multi-Module Has (MMH)mode.
Encryption Mode WPA
Require
802.1X
Select the Transmit Key value. This can be a value from 1 through 4. Note
that 802.1X + WEP mode sets this key value to 1.
Enter 40/64-bit Keys in 5 alphanumeric or 10 hexadecimal digits, or enter
104/128-bit Keys in 13 alphanumeric or 26 hexadecimal digits.
None
NoSpecify whether to use Key Permutation.
Enter and confirm the Cisco Key Integrity Protocol (CKIP) static key,
specified in hexadecimal digits.
Select the CKIP Key Index value. This can be a value from 1 through 4.
Unicast Cipher
(Cisco only)
Encryption Mode WPA/ PSK
Unicast Cipher
(Cisco only)
WPA Preshared
Key
(Alphanumeric)
Encryption Mode WPA2
WPA2 WPA
Compatibility Mode
WPA1 Cipher
(Cisco WLC Only)
Unicast Cipher
(Cisco Only)
AESSpecify the Unicast Cipher. Values include AES, TKIP, and AES/TKIP.
AES/TKIPSpecify the Unicast Cipher. Values include AES, TKIP, and AES/TKIP.
NoneEnter an alphanumeric value for the preshared key.
YesSpecify whether to enable WPA2 WPA Compatibility Mode.
TKIP
AES/TKIPSpecify the Unicast Cipher. Values include AES, TKIP, and AES/TKIP.
Specify the WPA1 Cipher. Values include AES, TKIP, and AES/TKIP.
NOTE: This drop down is only available if WPA2 WPA Compatibility Mode is
Yes.
95 | Configuring and Using Device GroupsDel l Networki ng W-Ai rWav e 8.0 | User Guide
Page 96
Table 55:
Groups > Security Encryption Mode settings (Continued)
SettingDefaultDescription
Encryption Mode WPA2/PSK
WPA2 WPA
Compatibility Mode
WPA1 Cipher
(Cisco WLC Only)
Unicast Cipher
(Cisco Only)
WPA Preshared
Key
(Alphanumeric)
Encryption Mode xSec
This indicates to use xSec encryption. No other configuration options are available.
Yes
TKIP
AES/TKIPSpecify the Unicast Cipher. Values include AES, TKIP, and AES/TKIP.
NoneEnter an alphanumeric value for the preshared key.
Specify whether to enable WPA2 WPA Compatibility Mode.
Specify the WPA1 Cipher. Values include AES, TKIP, and AES/TKIP.
NOTE: This drop down is only available if WPA2 WPA Compatibility Mode is
Yes.
3. Select Save to retain these security configurations for the group, select Save and Apply to make the changes
permanent, or select Revert to discard all unapplied changes.
4. Continue with additional security-related procedures in this document for additional RADIUS and SSID settings for
device groups, as required.
Configuring Group SSIDs and VLANs
The Groups > SSIDs configuration page allows you to create and edit SSIDs and VLANs that apply to a device group.
Perform these steps to create or edit VLANs and to set SSIDs.
WLANs that are supported from one or more Cisco WLC controllers can be configured on the Groups > Cisco WLC Config
page.
Figure 43 illustrates an example of the Groups > SSIDs page.
Figure 43:Groups > SSIDs Page Illustration
AirWave reports users by radio and by SSID. Graphs on the AP and controller monitoring pages display bandwidth in and
out based on SSID. AirWave reports can also be run and filtered by SSID. An option on the AMP Setup > General page
can age out inactive SSIDs and their associated graphical data.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring and Using Device Groups | 96
Page 97
1. Go to Groups > List and select the group name for which to define SSIDs/VLANs.
2. Select the Groups > SSIDs configuration page. Table 56 describes the information that appears for SSIDs and
VLANs that are currently configured for the device group.
Table 56:
Groups > SSIDs Fields and Descriptions
FieldDescription
SSIDDisplays the SSID associated with the VLAN.
VLAN ID
NameDisplays the name of the VLAN.
Encryption ModeDisplays the encryption on the VLAN.
First or Second Radio
Enabled
First or Second Radio
Primary
Native VLAN
Identifies the number of the primary VLAN SSID on which encrypted or unencrypted
packets can pass between the AP and the switch.
Enables the VLAN, SSID and Encryption Mode on the radio control.
Specifies which VLAN to be used as the primary VLAN. A primary VLAN is required.
NOTE: If you create an open network (see the Create Closed Network setting below)
in which the APs broadcast an SSID, the primary SSID is broadcast.
Sets this VLAN to be the native VLAN. Native VLANs are untagged and typically used
for management traffic only. AirWave requires a Native VLAN to be set. For AP types
do not require a native VLAN, create a dummy VLAN, disable it on both radio controls,
and ensure that it has the highest VLAN ID.
3. Select Add to create a new SSID or VLAN, or select the pencil icon next to an existing SSID/VLAN to edit that
existing SSID or VLAN. The Add SSID/VLAN configuration page appears as illustrated in Figure 44 and explained
in Table 57.
Figure 44:Add SSID/VLAN Page Illustration
4. Locate the SSID/VLAN section on the Groups > SSIDs configuration page and adjust these settings as required.
This section encompasses the basic VLAN configuration. Table 57 describes the settings and default values. Note
that the displayed settings can vary.
97 | Configuring and Using Device GroupsDel l Networki ng W-Ai rWav e 8.0 | User Guide
Page 98
Table 57:
SSID/VLAN Section Fields and Default Values
SettingDefaultDescription
Enables or disables an interface name for the VLAN interface.
Specify Interface NameYes
Selecting No for this option displays the Enable VLAN Tagging and
VLAN ID options.
Enable VLAN Tagging
(Cisco WLC, Proxim,
Symbol only)
VLAN ID (1-4094)None
InterfacemanagementSets the interface to support the SSID/VLAN combination.
SSIDNone
NameNone
Maximum Allowed
Associations (0-2007)
Broadcast SSID (Cisco
WLC, Proxim and
Symbol 4131 only)
255
No
Enables or disables VLAN tagging. Displays if Specify Interface
Name is set to No.
Indicates the number of the VLAN designated as the Native VLAN,
typically for management purposes. Displays if Specify Interface
Name is set to No and Enable VLAN Tagging is set to Yes.
Sets the Service Set Identifier (SSID), which is a 32-character userdefined identifier attached to the header of packets sent over a
WLAN. It acts as a password when a mobile device tries to connect
to the network through the AP, and a device is not permitted to join
the network unless it can provide the unique SSID.
Sets a user-definable name associated with SSID/VLAN
combination.
Indicates the maximum number of mobile users which can
associate with the specified VLAN/SSID.
NOTE: 0 means unlimited for Cisco.
For specific devices as cited, this setting enables the AP to
broadcast the SSID for the specified VLAN/SSID. This setting works
in conjunction with the Create Closed Network setting on the
Groups > Security configuration page. Proxim devices support a
maximum of four SSIDs.
NOTE: This option should be enabled to ensure support of legacy
users.
Partial Closed System
(Proxim only)
Unique Beacon
(Proxim only)
Block All Inter-Client
Communication
No
No
Yes
For Proxim only, this setting enables to AP to send its SSID in every
beacon, but it does not respond to any probe requests.
For Proxim only, if more than one SSID is enabled, this option
enables them to be sent in separate beacons.
This setting blocks communication between client devices based
on SSID.
5. Locate the Encryption area on the Groups > SSIDs page and adjust these settings as required. Table 58 describes the
available encryption modes. Table 55 in "Configuring Group Security Settings" on page 92 describes configuration
settings for each mode.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring and Using Device Groups | 98
Page 99
Table 58:
Encryption Section Field and Default Values
SettingDefaultDescription
Drop-down menu determines the level of encryption required for devices to
associate to the APs. The drop-down menu options are as follows. Each
option displays additional encryption settings that must be defined.
Complete the associated settings for any encryption type chosen:
l No Encryption
l Optional WEP—Wired Equivalent Privacy, not PCI compliant as of 2010
l Require W EP—Wired Equivalent Privacy, not PCI compliant as of 2010
l Require 802. 1x—Based on the WEP algorithm
Encryption Mode
No
Encryption
l Require LEAP—Lightweight Extensible Authentication Protocol
l 802.1x+WEP—Combines the two encryption types shown
l 802.1x+LEAP—Combines the two encryption types shown
l LEAP+WEP—Combines the two encryption types shown
l Static CKIP—Cisco Key Integrity Protocol
l WPA—Wi-Fi Protected Access protocol
l WPA/PSK—Combines WPA with Pre-Shared Key encryption
l WPA2—Wi-Fi Protected Access 2 encryption
l WPA2/PSK—Combines the two encryption methods shown
l xSec—FIPS-compliant encryption including Layer 2 header info
6. Locate the EAP Options area on the Groups > SSIDs page, and complete the settings. Table 59 describes the settings
and default values.
Table 59:
EAP Options Section Field and Default Value
SettingDefaultDescription
WEP Key Rotation
Interval (0-10000000
120Time (in seconds) between WEP key rotation on the AP.
sec)
7. Locate the RADIUS Authentication Servers area on the Groups > SSIDs configuration page and define the settings.
Table 60 describes the settings and default values.
Table 60:
RADIUS Authentication Servers Fields and Default Values
SettingDefaultDescription
RADIUS Authentication
Server 1-3
(Cisco WLC, Proxim only)
Authentication Profile
Name (Proxim Only)
Authentication Profile
Index (Proxim Only)
None
None
None
Drop-down menu to select RADIUS Authentication servers previously
entered on the Groups > RADIUS configuration page. These RADIUS
servers dictate how wireless clients authenticate onto the network.
Sets the Authentication Profile Name for Proxim AP-600, AP-700, AP2000, AP-4000.
Sets the Authentication Profile Index for Proxim AP-600, AP-700, AP2000, AP-4000.
8. Select Save when the security settings and configurations in this procedure are complete.
You may need to return to the G roups > Security configuration page to configure or reconfigure RADIUS servers.
99 | Configuring and Using Device GroupsDel l Networki ng W-Ai rWav e 8.0 | User Guide
Page 100
9. Locate the RADIUS Accounting Servers area on the Groups > SSIDs configuration page and define the settings.
Table 61 describes the settings and default values.
Table 61:
Radius Accounting Servers Fields and Default Values
SettingDefaultDescription
RADIUS Accounting
Server 1-3 (Cisco WLC,
Proxim Only)
Accounting Profile
Name (Proxim Only)
Accounting Profile
Index (Proxim Only)
None
None
None
Pull-down menu selects RADIUS Accounting servers previously entered on
the Groups > RADIUS configuration page. These RADIUS servers dictate
where the AP sends RADIUS Accounting packets for this SSID/VLAN.
Sets the Accounting Profile Name for Proxim AP-600, AP-700, AP-2000,
AP-4000.
Sets the Accounting Profile Index for Proxim AP-600, AP-700, AP-2000, AP-
4000.
10. Select Add when you have completed all sections. This returns you to the Groups > SSIDs page.
11. Select Save to retain these SSID configurations for the group, select Save and Apply to make the changes permanent,
or select Revert to discard all unapplied changes.
What Next?
l Continue with additional Group procedures in this document as required.
Configuring Radio Settings for Device Groups
The Groups > Radio configuration page allows you to specify detailed RF-related settings for devices in a particular
group.
Ifyou have existing deployed devices, you may want to use the current RF settings on those devices as a guide for
configuring the settings in your default Group.
Perform the following steps to define RF-related radio settings for groups.
1. Go to the Groups > List page and select the group for which to define radio settings by selecting the group name.
Alternatively, select Add from the Groups > List page to create a new group, define a group name. In either case, the
Monitor page appears.
2. Go to the Groups > Radio page. Figure 45 illustrates this page.
Dell Network ing W-AirWave 8.0 | User GuideConfiguring and Using Device Groups | 100
Loading...
+ hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.