System®. Dell™, the DELL™ logo, and PowerConnect™ are trademarks of Dell Inc.
All rights reserved. Specifications in this manual are subject to change without notice.
Originated in the USA. All other trademarks are the property of their respective owners.
Open Source Code
Certain Aruba products include Open Source software code developed by third parties, including software code
subject to the GNU General Public License (GPL), GNU Lesser General Public License (LGPL), or other Open
Source Licenses. Includes software from Litech Systems Design. The IF-MAP client library copyright 2011 Infoblox,
Inc. All rights reserved. This product includes software developed by Lars Fenneberg, et al. The Open Source code
used can be found at this site:
http://www.arubanetworks.com/open_source
Legal Notice
The use of Aruba Networks, Inc. switching platforms and software, by all individuals or corporations, to terminate
other vendors’ VPN client devices constitutes complete acceptance of liability by that individual or corporation for
this action and indemnifies, in full, Aruba Networks, Inc. from any and all legal actions that might be taken against it
with respect to infringement of copyright on behalf of those vendors.
This document describes the Dell W-Instant command syntax and provides the following information for each
command:
l Command Syntax—The complete syntax of the command.
l Description—A brief description of the command.
l Syntax—A description of the command parameters, the applicable ranges and default values, if any.
l Usage Guidelines—Information to help you use the command, including prerequisites, prohibitions, and related
commands.
l Example—An example of how to use the command.
l Command History—The version of Dell W-Instant in which the command was first introduced.
l Command Information—This table describes command modes and platforms for which this command is
applicable.
The commands are listed in alphabetical order.
Intended Audience
This guide is intended for customers who configure and use Dell Networking W-Series Instant Access Point (WIAP).
Related Documents
In addition to this document, the Dell W-IAP product documentation includes the following:
l Dell Networking W-Series Instant Access Point Installation Guides
l Dell Networking W-Series Instant Access Point 6.3.1.1-4.0 Quick Start Guide
l Dell Networking W-Series Instant Access Point 6.3.1.1-4.0 User Guide
l Dell Networking W-Series Instant Access Point 6.3.1.1-4.0 MIB Reference Guide
l Dell Networking W-Series Instant Access Point 6.3.1.1-4.0 Syslog Messages Reference Guide
l Dell Networking W-Series Instant Access Point 6.3.1.1-4.0 Release Notes
Conventions
The following conventions are used throughout this document to emphasize important concepts:
Table 1:
Type StyleDescription
Typographical Conventions
Italics
Boldface
Commands
Dell Networking W-Series Instant 6.3.1.1-4.0 | CLI User GuideAbout this Guide | 4
This style is used for emphasizing important terms and to mark
the titles of books.
This style is used for command names and parameter options
when mentioned in the text.
This fixed-width font depicts command syntax and examples of
commands and command output.
Page 5
Type StyleDescription
<angle brackets>In the command syntax, text within angle brackets represents
items that you should replace with information appropriate to
your specific situation.
For example, ping <ipaddr>
In this example, you would type “ping” at the system prompt
exactly as shown, followed by the IP address of the system to
which ICMP echo packets are to be sent. Do not type the angle
brackets.
[square brackets]In the command syntax, items enclosed in brackets are
optional. Do not type the brackets.
{Item_A|Item_B}In the command examples, single items within curled braces
and separated by a vertical bar represent the available
choices. Enter only one choice. Do not type the braces or bars.
{ap-name <ap-name>}|{ipaddr <ip-addr>}Two items within curled braces indicate that both parameters
must be entered together. If two or more sets of curled braces
are separated by a vertical bar, like in the example to the left,
enter only one choice. Do not type the braces or bars.
The following informational icons are used throughout this guide:
Indicates helpful suggestions, pertinent information, and important things to remember.
Indicates a risk of damage to your hardware or loss of data.
Indicates a risk of personal injury or death.
Contacting Dell
Table 2:
Support
Main Websitedell.com
Contact Informationdell.com/contactdell
Support Websitedell.com/support
Documentation Website
Support Information
dell.com/support/manuals
What is New in Dell W-Instant 6.3.1.1-4.0
This section lists the new and modified commands in the Dell W-Instant 6.3.1.1-4.0 release.
New Commands
The following commands are added in the Dell W-Instant 6.3.1.1-4.0 release:
5 | About this GuideDell Networking W-Series Instant 6.3.1.1-4.0 | CLI Reference Guide
Page 6
Table 3:
New Commands in 6.3.1.1-4.0
CommandDescription
ale-serverConfigures Analytics and Location Engine (ALE) server details to enable W-IAP integration with
ALE.
ale-report-intervalConfigures the interval at which a W-IAP sends data to the Analytics and Location Engine
(ALE) server.
firewall-externalenforcement
iap-masterProvisions a W-IAP as a master W-IAP.
proxyConfigures a HTTP proxy on a W-IAP for cloud image download.
restrict-corp-accessConfigures restricted access to the corporate network.
restricted-mgmtaccess
show
airgroupservice-id
show aleDisplays the ALE configuration details.
show ap clientmatch-history
show ap clientmatch-live
show ap clientmatch-refused
Configures external firewall such as Palo Alto Networks(PAN) firewall to enable integration
with the W-IAP
Configures management subnets to enable restricted access to the corporate network.
Displays the AirGroup service IDs configured on a W-IAP for its AirGroup clients.
Displays a historical record of the client match events and actions for the clients associated with
a W-IAP.
Displays the current client match events and actions for clients associated with a W-IAP.
Displays the list of clients for which the channel allocation is refused as per the client match
configuration parameters.
show ap clientprobe-report
show ap client-viewDisplays information about the clients in the AP neighborhood.
show ap debug
client-match
show ap debug
spanning-tree
show ap pmkcacheDisplays the pairwise master key (PMK) cache table for clients associated with a W-IAP.
show ap virtualbeacon-report
show captiveportal-domains
show externalcaptive-portal
Displays the client probe report for a W-IAP.
Displays the information about the client match configuration status on an AP radio interface.
Displays the Spanning Tree Protocol (STP) information for a W-IAP if configured.
Displays a report with the MAC address details and RSSI information of a W-IAP.
Displays the internal and external Captive portal server domains.
Displays the external Captive portal configuration details.
show proxy configDisplays the HTTP proxy configuration details.
telnet-serverAllows Telnet access to the Dell W-Instant CLI.
vpn-gre-outsideConfigures an automatic GRE tunnel for Dell controller.
Displays the Link Aggregation Control Protocol (LACP) configuration status on a W-IAP.
Modified Commands
The following commands are modified in the Dell W-Instant 6.3.1.1-4.0 release:
Table 4:
CommandDescription
airgroupserviceThe airgroupservice allows you configure AirGroup services such as iTunes, Sharing, Chat,
ams-backup-ipThe ams-backup-ip command is enhanced to support a backup domain name along with
ams-ipThe ams-ip command is enhanced to support domain name along with the IP address.
armThe arm command is enhanced to support client match configuration.
Modified Commands in 6.3.1.1-4.0
and so on. You can configure all services at once.
the backup IP address.
commitThe commit command is enhanced to provide an option (commit apply no-save command)
for applying the configuration changes to the cluster without saving the configuration.
copyThe copy tftp command is enhanced to upload customized logo images to the W-IAP
database.
download-certThe download-cert command is enhanced to allow the downloading of Captive portal
server certificates from an FTP or TFTP server, or by using an HTTP URL.
ip dhcpThe ip dhcp command is modified to include centralized L3.
mgmt-userThe mgmt-user command now allows you to configure read-only users and users for the
guest management interface.
show airgroup
show airgroupserviceThe show airgroupservice command output is enhanced to display the configuration status
wired-port-profileThe wired-port-profile is modified to include the spanning-tree command parameter to
wlan access-rule
The show airgroup command is enhanced to include blocked-queries, blocked-service-id,
internal-state statistics, and swarm-info commands.
of all AirGroup services.
allow the administrators to enable Spanning Tree Protocol (STP) for the wired profile users.
The wlan access-rule command is enhanced to include the bandwidth-limit command to
allow the administrators to allocate bandwidth limit to the SSID users.
wlan auth-serverThe wlan auth-server command is enhanced to include the dynamic RADIUSproxy
configuration parameters.
7 | About this GuideDell Networking W-Series Instant 6.3.1.1-4.0 | CLI Reference Guide
Page 8
Table 4:
Modified Commands in 6.3.1.1-4.0
CommandDescription
wlan external-captiveportal
The wlan external-captive-portal command is enhanced to allow the administrators to
create multiple profiles and assign the required profiles to a WLAN SSID or wired profile.
wlan ssid-profileThe wlan ssid-profile command is modified to include the following parameters:
l okc-disable — For Opportunistic Key Caching (OKC) roaming support
l dot11r — For 802.11r roaming support
l mac-authentication-delimiter — To allow the use of delimiters such as colon and dash in
MAC address string.
l mac-authentication-upper-case— To allow the use of uppercase letters in MAC address
Dell W-Instant supports the use of Command Line Interface (CLI) for scripting purposes. You can access the Dell
W-Instant CLI through a Secure Shell (SSH).
To enable the SSH access to the Dell W-Instant CLI:
1. From the Dell W-Instant UI, navigate to System > Show advanced options.
2. Select Enabled from the Terminal access drop-down list.
3. Click OK.
Connecting to a CLI Session
On connecting to a CLI session, the system displays its host name followed by the login prompt. Use the
administrator credentials to start a CLI session. For example:
If the login is successful, the privileged command mode is enabled and a command prompt is displayed. For
example:
(Instant Access Point)#
The privileged mode provides access to show, clear, ping, traceroute, and commit commands. The configuration
commands are available in the configuration (config) mode. To move from privileged mode to the configuration mode,
enter the following command at the command prompt:
(Instant Access Point)# configure terminal
The configure terminal command allows you to enter the basic configuration mode and the command prompt is
displayed as follows:
(Instant Access Point)(config)#
The Dell W-Instant CLI allows CLI scripting in several other sub-command modes to allow the users to configure
individual interfaces, SSIDs, access rules, and security settings.
You can use the question mark (?) to view the commands available in a privileged mode, configuration mode, or submode.
Although automatic completion is supported for some commands such as configure terminal, the complete exit
and end commands must be entered at command prompt for successful execution.
Applying Configuration Changes
Each command processed by the Virtual Controller is applied on all the slave W-IAPs in a cluster. When you make
configuration changes on a master W-IAP in the CLI, all associated W-IAPs in the cluster inherit these changes and
subsequently update their configurations. The changes configured in a CLI session are saved in the CLI context.
The CLI does not support the configuration data exceeding the 4K buffer size in a CLI session: therefore, it is
recommended that you configure fewer changes at a time and apply the changes at regular intervals.
To apply and save the configuration changes at regular intervals, use the following command in the privileged mode:
To apply the configuration changes to the cluster, without saving the configuration, use the following command in the
privileged mode:
(Instant Access Point)# commit apply no-save
To view the changes that are yet to be applied, use the following command in the privileged mode:
(Instant Access Point)# show uncommitted-config
To revert to the earlier configuration, use the following command in the privileged mode.
(Instant Access Point)# commit revert
Example:
(Instant Access Point)(config)# rf dot11a-radio-profile
(Instant Access Point)(RF dot11a Radio Profile)# beacon-interval 200
(Instant Access Point)(RF dot11a Radio Profile)# no legacy-mode
(Instant Access Point)(RF dot11a Radio Profile)# dot11h
(Instant Access Point)(RF dot11a Radio Profile)# interference-immunity 3
(Instant Access Point)(RF dot11a Radio Profile)# csa-count 2
(Instant Access Point)(RF dot11a Radio Profile)# spectrum-monitor
(Instant Access Point)(RF dot11a Radio Profile)# end
(Instant Access Point)# show uncommitted-config
rf dot11a-radio-profile
no legacy-mode
beacon-interval 200
no dot11h
interference-immunity 3
csa-count 1
no spectrum-monitor
Instant Access Point# commit apply
Configuration Sub-modes
Some commands in configuration mode allow you to enter into a sub-mode to configure the commands specific to
that mode. When you are in a configuration sub-mode, the command prompt changes to indicate the current submode.
You can exit a sub-command mode and return to the basic configuration mode or the privileged Exec (enable) mode
at any time by executing the exit or end command.
Deleting Configuration Settings
Use the no command to delete or negate previously-entered configurations or parameters.
l To view a list of no commands, type no at the prompt in the relevant mode or sub-mode followed by the question
mark. For example:
(Instant Access Point)(config) # no?
l To delete a configuration, use the no form of a configuration command. For example, the following command
removes a configured user role:
(Instant Access Point)(config) # no user <username>
l To negate a specific configured parameter, use the no parameter within the command. For example, the following
command deletes the PPPoE user configuration settings:
(Instant Access Point)(config) # pppoe-uplink-profile
(Instant Access Point)(pppoe_uplink_profile)# no pppoe-username
The Dell W-Instant CLI does not support positioning or precedence of sequence-sensitive commands. Therefore, it
is recommended that you remove the existing configuration before adding or modifying the configuration details for
sequence-sensitive commands. You can either delete an existing profile or remove a specific configuration by using
the no… commands.
The following table lists the sequence-sensitive commands and the corresponding no command to remove the
configuration.
Table 5:
Sequence-Sensitive Commands
Sequence-Sensitive CommandCorresponding no command
no rule <dest> <:mask> <match> <prot
ocol> <start-port> <end-port> {permi
t | deny | src-nat | dst-nat}
no mgmt-auth-server <auth-profile-na
me>
no set-role <attribute>{{equals|
not-equals| starts-with| ends-with|
contains} <operator>| value-of}
no set-role
no set-vlan <attribute>{{equals|
not-equals| starts-with| ends-with|
contains} <operator>| value-of}
no set-vlan
Saving Configuration Changes
The
running-config
To view the running-config of a W-IAP, use the following command:
(Instant Access Point) # show running-config
When you make configuration changes through the CLI, the changes affect the current running configuration only. To
save your configuration changes, use the following command in the privileged Exec mode:
(Instant Access Point)# write memory
Commands that Reset the W-IAP
If you use the CLI to modify a currently provisioned radio profile, the changes take place immediately. A reboot of the
W-IAP is not required to apply the configuration changes. Certain commands, however, automatically force W-IAP
to reboot. Verify the current network loads and conditions before executing the commands that enforce a reboot of
the W-IAP, as they may cause a momentary disruption in service as the unit resets.
holds the current W-IAP configuration, including all pending changes which are yet to be saved.
Page 13
Command Line Editing
The system records your most recently entered commands. You can review the history of your actions, or reissue a
recent command easily, without having to retype it.
To view items in the command history, use theuparrow key to move back through the list and the
down
arrow key to
move forward. To reissue a specific command, press Enter when the command appears in the command history.
You can also use the command line editing feature to make changes to the command prior to entering it. The
command line editing feature allows you to make corrections or changes to a command without retyping. The
following table lists the editing controls. To use key shortcuts, press and hold the Ctrl button while you press a letter
key.
Table 6:
Line Editing Keys
KeyEffectDescription
Ctrl AHomeMove the cursor to the beginning of the line.
Ctrl B or the
left arrow
Ctrl DDelete RightDelete the character to the right of the cursor.
Ctrl EEndMove the cursor to the end of the line.
Ctrl F or the
right arrow
Ctrl KDelete RightDelete all characters to the right of the cursor.
BackMove the cursor one character left.
ForwardMove the cursor one character right.
Ctrl N or the
down arrow
Ctrl P or
up arrow
Ctrl TTransposeSwap the character to the left of the cursor with
Ctrl UClearClear the line.
Ctrl WDelete WordDelete the characters from the cursor up to and
Ctrl XDelete LeftDelete all characters to the left of the cursor.
NextDisplay the next command in the command
history.
PreviousDisplay the previous command in the command
history.
the character to the right of the cursor.
including the first space encountered.
Specifying Addresses and Identifiers in Commands
This section describes addresses and other identifiers that you can reference in CLI commands.
Table 7:
Address/IdentifierDescription
IP addressFor any command that requires entry of an IP address to specify a network entity,
Addresses and Identifiers
use IPv4 network address format in the conventional dotted decimal notation (for
example, 192.0.2.1).
Netmask addressFor subnet addresses, specify a subnet mask in dotted decimal notation (for
example, 255.255.255.0).
Media Access Control
(MAC) address
Service Set Identifier
(SSID)
Basic Service Set
Identifier (BSSID)
Extended Service Set
Identifier (ESSID)
For any command that requires entry of a device’s hardware address, use the
hexadecimal format (for example, 00:05:4e:50:14:aa).
A unique character string (sometimes referred to as a network name), consisting
of no more than 32 characters. The SSID is case-sensitive (for example, WLAN-
01).
This entry is the unique hard-wireless MAC address of the AP. A unique BSSID
applies to each frequency— 802.11a and 802.11g—used from the AP. Use the
same format as for a MAC address.
Typically the unique logical name of a wireless network. If the ESSID includes
spaces, enclose the name in quotation marks.
This command tests a configured authentication server.
Syntax
ParameterDescription
<servername>
<username>
Allows you to specify the authentication server for which the authentication test
is run.
Allows you to specify the user name for which the authentication test is run.
Usage Guidelines
Use this command to view the CPU load for application and system processes. This command allows you to verify
a configured RADIUS authentication server or the internal database. You can use this command to check for an “out
of service” RADIUS server.
Example
The following example shows the output of the aaa test-server command:
This command configures external antenna connectors for a W-IAP.
Syntax
ParameterDescriptionRange
<gain>
Configures the antenna gain. You can configure a gain value
in dBi for the following types of antenna:
l Dipole/Omni
l Panel
l Sector
Diploe/Omni - 6
Panel -14
Sector - 14
Usage Guidelines
If your W-IAP has external antenna connectors, you need to configure the transmit power of the system. The
configuration must ensure that the system’s Equivalent Isotropically Radiated Power (EIRP) is in compliance with
the limit specified by the regulatory authority of the country in which the W-IAP is deployed. You can also measure or
calculate additional attenuation between the device and antenna before configuring the antenna gain. To know if your
AP device supports external antenna connectors, see the
EIRP and Antenna Gain
The following formula can be used to calculate the EIRP limit related RF power based on selected antennas
(antenna gain) and feeder (Coaxial Cable loss):
EIRP = Tx RF Power (dBm)+GA (dB) - FL (dB)
The following table describes this formula:
Install Guide
that is shipped along with the AP device.
Table 8:
Formula Variable Definitions
Formula ElementDescription
EIRPLimit specific for each country of deployment
Tx RF PowerRF power measured at RF connector of the unit
GAAntenna gain
FLFeeder loss
For information on antenna gain recommended by the manufacturer, see dell.com/support.
Example
The following example configures external antenna connectors for the W-IAP with the 5 GHz radio band.
This command configures the Aeroscout Real-Time Asset Location Server (RTLS) settings for Dell W-Instant and
sends the Radio-frequency identification (RFID) tag information to an Aeroscout RTLS server.
Syntax
Command/ParameterDescriptionDefault
<IP-address>
<Port>
include-unassoc-stas
no
IP address of the Aeroscout RTLS server to which the
location reports are sent.
Port number of the Aeroscout RTLS server to which the
location reports are sent..
Includes the client stations not associated to any W-IAP
when mobile unit reports are sent to the Aeroscout
RTLS server.
Removes the Aeroscout RTLS configuration.—
—
—
Disabled
Usage Guidelines
This command allows you to integrate Aeroscout RTLS server with Dell W-Instant by specifying the IP address and
port number of the Aeroscout RTLS server. When enabled, the RFID tag information for the stations associated with
a W-IAP are sent to the AeroScout RTLS. You can also send the RFID tag information for the stations that are not
associated with any W-IAP.
Example
The following example configures the Aeroscout RTLS server:
This command configures the AirGroup settings for Dell W-Instant.
Syntax
ParameterDescriptionRangeDefault
cppm enforceregistration
cppm-query-interval
<interval>
cppm-server <server-nam
e>
disable
enable
enable-guest-multicast
Enforces the discovery of the CPPM
registered devices. When enabled, only
devices registered with CPPM will be
discovered by Bonjour® devices, based on
the CPPM policy configured.
Configures a time interval at which Dell WInstant sends a query to ClearPass Policy
Manager for mapping the access privileges of
each device to the available services.
Configures the ClearPass Policy Manager
server information for AirGroup policy.
Disables the AirGroup feature.——
Enables the AirGroup feature.——
Allows the users to use the Bonjour services
enabled in a guest VLAN. When enabled, the
Bonjour devices will be visible only in the
guest VLAN and AirGroup will not discover or
enforce policies in guest VLAN.
not share the Multicast DNS (mDNS)
database information with the other
clusters.
l In the Inter Cluster model, the W-IAP
shares the mDNS database information
with the other clusters. The mDNS records
in the Virtual Controller can be shared
with the all the Virtual Controllers
specified for L3 Mobility.
Removes the specified configuration
parameter.
—Disabled
——
Page 21
Usage Guidelines
Use this command to configure the AirGroup, the availability of the AirGroup services, and ClearPass Policy
Manager (CPPM) servers.
Example
The following example configures an AirGroup profile:
Restricts the users assigned to these VLANs from
accessing the AirGroup service.
Enables the AirGroup service for the profile.—
Disables AirGroup services for the profile.—
Indicates the AirGroup service ID, which is the name of
a Bonjour service offered by a Bonjour-enabled device
or application.
NOTE: The service IDs cannot be added for the preconfigured services.
Removes the AirGroup service configuration.—
Disabled
—
Page 23
Usage Guidelines
Use this command to enforce AirGroup service policies and define the availability of a Bonjour services such as
Apple® AirPrint and AirPlay for an AirGroup profile. When configuring Bonjour service for an AirGroup profile, you
can also restrict specific user roles and VLANs from availing the AirGroup services.
Example
The following example configures AirGroup services:
This command integrates W-AirWave Real-Time Asset Location Server (RTLS) settings for Dell W-Instant and
sends the Radio-frequency identification (RFID) tag information to an W-AirWave RTLS server with the RTLS feed
to accurately locate the wireless clients.
Syntax
Command/ParameterDescriptionDefault
<IP-address>
<Port>
<key>
<frequency>
include-unassoc-sta
no…
Configures the IP address of the W-AirWave RTLS
server.
Configures the port for the W-AirWave RTLS server.—
Configures key for service authorization.—
Configures the frequency at which packets are sent to
the RTLS server in seconds.
When enabled, this option sends mobile unit reports to
the W-AirWave RTLS server for the client stations that
are not associated to any W-IAP (unassociated
stations).
Removes the specified configuration parameter.—
—
5
Disabled
Usage Guidelines
Use this command to send the RFID tag information to W-AirWave RTLS. Specify the IP address and port number
of the W-AirWave server, to which the location reports must be sent. You can also send reports of the unassociated
clients to the RTLS server for tracking purposes.
This command allows you to modify the configuration settings for Application Layer Gateway (ALG) protocols
enabled on a W-IAP. An application-level gateway consists of a security component that augments a firewall or NAT
used in a network.
Syntax
Command/ParameterDescriptionDefault
sccp-disable
sip-disable
ua-disable
vocera-disable
no…
Disables the Skinny Call Control Protocol (SCCP).Enabled
Disables the Session Initiation Protocol (SIP) for VOIP
and other text and multimedia sessions.
Disables the Alcatel-Lucent NOE protocol.Enabled
Disables the VOCERA protocol.Enabled
Removes the specified configuration parameter.—
Usage Guidelines
Use this command to functions such as SIP, Vocera, and Cisco Skinny protocols for ALG.
Example
The following example configures the ALG protocols:
(Instant Access Point)(config)# alg
(Instant Access Point)(ALG)# sccp-disable
(Instant Access Point)(ALG)# no sip-disable
(Instant Access Point)(ALG)# no ua-disable
(Instant Access Point)(ALG)# no vocera-disable
(Instant Access Point)(ALG)# end
(Instant Access Point)# commit apply
Enabled
Command History
VersionDescription
Dell Networking W-Series Instant Access Point 6.2.1.0-3.3
This command adds the IP address or domain name of the backup W-AirWave Management server.
Syntax
ParameterDescription
<IP-address or domain
name>
no…
Configures the IP address or domain name of the secondary W-AirWave
Management Server.
Removes the specified configuration parameter.
Usage Guidelines
Use this command to add the IP address or domain name of the backup W-AirWave Management Server. The
backup server provides connectivity when the W-AirWave primary server is down. If the W-IAP cannot send data to
the primary server, the Virtual Controller switches to the backup server automatically.
Example
The following command configures an W-AirWave backup server.
This command uniquely identifies the group of W-IAPs managed or monitored by the W-AirWave Management
console. The name can be a location, vendor, department, or any other identifier.
Syntax
ParameterDescription
ams-identity <Name>
Configures a name that uniquely identifies the W-IAP on the WAirWave Management server. The name defined for this command
will be displayed under the Groups tab in the W-AirWave user
interface.
Usage Guidelines
Use this command to assign an identity for the W-IAPs monitored or managed by the W-AirWave Management
Server.
Example
The following command configures an W-AirWave identifier:
(Instant Access Point)(config)# ams-identity dell
Command History
VersionDescription
Dell Networking W-Series Instant Access
Point 6.2.1.0-3.3
This command assigns an Adaptive Radio Management (ARM) profile for a W-IAP and configures ARM features
such as band steering, spectrum load balancing, airtime fairness mode, and access control features.
Syntax
Command/ParameterDescriptionRangeDefault
80mhz-support
a-channels <a-channel>
air-time-fairness-mode
{<default-access>| <fairaccess>|
<preferred-access>}
Enables the use of 80 MHz channels on
APs with 5GHz radios, which support a very
high throughput.
NOTE: Only the APs that support 802.11ac
can be configured with 80 MHz channels.
Configures 5 GHz channels.——
Allows equal access to all clients on the
wireless medium, regardless of client type,
capability, or operating system and
prevents the clients from monopolizing
resources. You can configure any of the
following modes:
l default-access — To provide access
based on client requests. When this
mode is configured, the per user and
per SSID bandwidth limits are not
enforced.
l fair-access — To allocate Airtime evenly
across all the clients.
l preferred-access — To set a preference
where 11n clients are assigned more
airtime than 11a/11g. The 11a/11g
clients get more airtime than 11b. The
ratio is 16:4:1.
Assigns the dual-band capable clients to
the 5 GHz band on dual-band. It reduces
co-channel interference and increases
available bandwidth for dual-band clients,
because there are more channels on the 5
balancebands,
prefer5ghz, force5ghz,
balancebands
Page 35
Command/ParameterDescriptionRangeDefault
client-aware
GHz band than on the 2.4 GHz band. You
can configure any of the following bandsteering modes:
l prefer-5ghz — To allow the W-IAP to
steer the client to 5 GHz band (if the
client is 5 GHz capable). However, the
W-IAP allows the client connection on
the 2.4 GHz band if the client
persistently attempts for 2.4 GHz
association.
l force-5ghz — To enforce 5 GHz band
steering mode on the W-IAPs, so that
the 5 GHz capable clients are allowed to
use only the 5GHz channels.
l balance-bands — To allow the W-IAPs to
balance the clients across the two 2.4
GHz and 5 GHz radio and to utilize the
available bandwidth.
l disable — To allow the clients to select
the bands.
Enables the client aware feature. When
enabled, the W-IAP will not change
channels for the Access Points when clients
are active, except for high priority events
such as radar or excessive noise. The client
aware feature must be enabled in most
deployments for a stable WLAN.
disable
—Enabled
client-match
calc-interval<seconds>
calc-threshold <threshold>
debug <level>
Enables enable the client match feature on
APs. When the client match feature is
enabled on a W-IAP, the W-IAP measures
the RF health of its associated clients.If
spectrum load balancing is triggered and a
client's Received Signal Strength Indication
(RSSI) is or less than 20 dB , clients are
moved from one AP to another for better
performance and client experience. In the
current release, the client match feature is
supported only within a W-IAP cluster.
Configures an interval at which client match
is calculated.
Configures a threshold that takes
acceptance client count difference among
all the channels of Client match into
account. When the client load on an AP
reaches or exceeds the threshold in
comparison, client match is enabled on that
AP.
Displays information requires for debugging
client match issues.
Configures the maximum number of
requests for client match.
Configures a percentage value to be
considered in the same virtual RF
neighborhood of Client match.
Configures a balancing strategy for client
match.
Configures 2.4 GHz channels.——
0-1005
0-1005
20-100%75%
1—3
1—Channelbased
2—Radiobased
3—Channel
and Radio
based
1
min-tx-power <power>
max-tx-power <power>
scanning
wide-bands {<none>| <all>|
<2.4>| <5>}
Sets the minimum transmission power. This
indicates the minimum Effective Isotropic
Radiated Power (EIRP). If the minimum
transmission EIRP setting configured on an
AP is not supported by the AP model, this
value is reduced to the highest supported
power setting.
Sets the highest transmit power levels for
the AP. If the maximum transmission EIRP
configured on an AP is not supported by the
AP model, the value is reduced to the
highest supported power setting.
NOTE: Higher power level settings may be
constrained by local regulatory
requirements and AP capabilities.
Allows the W-IAPs to scan other channels
for RF Management and Wireless Intrusion
Protection System enforcement.
Allows administrators to configure 40 MHz.
channels in the 2.4 GHz and 5.0 GHz
bands. 40 MHz channels are two 20 MHz
adjacent channels that are bonded
together. The 40 MHz channels double the
frequency bandwidth available for data
transmission. For high performance, enter
5GHz. If the AP density is low, enter
2.4GHz.
no…
Removes the current value for that
parameter and return it to its default setting
——
Usage Guidelines
Use this command to configure ARM features on a W-IAP. ARM ensures low-latency roaming, consistently high
performance, and maximum client compatibility in a multi-channel environment. By ensuring the fair distribution of
available Wi-Fi bandwidth to mobile devices, ARM ensures that data, voice, and video applications have sufficient
network resources at all times. ARM allows mixed 802.11ac, a, b, g, and n client types to inter-operate at the highest
performance levels.
This command enables firewall settings to protect the network against wired attacks, such as ARP attacks or
malformed DHCP packets, and notify the administrator when these attacks are detected.
Syntax
Command/ParameterDescription
drop-bad-arp-enable
fix-dhcp-enable
poison-check-enable
no…
Enables the W-IAP to block the bad ARP request.
Enables the W-IAP to fix the malformed DHCP packets.
Enables the W-IAP to trigger an alert notifying the user about the
ARP poisoning that may have been caused by the rogue APs.
Removes the specified configuration parameter.
Usage Guidelines
Use this command to block ARP attacks and to fix malformed DHCP packets.
Example
The following example configures firewall settings to protect the network from Wired attacks:
This command configures an interval after which the authenticated credentials of the clients stored in the cache
expire. When the cache expires, the clients are required to authenticate again.
Syntax
ParameterDescriptionRangeDefault
auth-survivability
cache-time-out
Indicates the duration after which the
authenticated credentials in the cache expire.
1-99 hours24 hours
Usage Guidelines
Use this command when the authentication survivability is enabled on a network profile, to set a duration after which
the authentication credentials stored in the cache expires. To enable the authentication survivability feature, use the
auth-survivability in WLAN SSID profile sub-mode.
encapsulation-type <gre>
ip <IP-address>
ip mtu <size>
gre-type <type>
no...
Description
This command creates a Communications Assistance for Law Enforcement Act (CALEA) profile to enable W-IAPs
for Lawful Intercept (LI) compliance and CALEA integration.
Syntax
Command/ParameterDescriptionRangeDefault
calea
encapsulation-type <gr
e>
ip <IP-address>
ip mtu <size>
gre-type
no…
Enables calea configuration sub-mode for
CALEA profile configuration.
Specifies the encapsulation type for
Generic Routing Encapsulation (GRE)
packets.
Configures the IP address of the CALEA
server on a W-IAP.
Configures the Maximum Transmission
Unit size to use.
Specifies GRE type.—25944
Removes the configuration——
——
GREGRE
——
68—15001500
Usage Guidelines
Use this command to configure a W-IAP to support Lawful Intercept (LI). LI allows the Law Enforcement Agencies
(LEA) to conduct an authorized electronic surveillance. Depending on the country of operation, the service providers
(SPs) are required to support LI in their respective networks.
In the United States, SPs are required to ensure LI compliance based on CALEA specifications. LI compliance in the
United States is specified by the CALEA.
For more information on configuring W-IAPs for CALEA integration, see
Point User Guide
.
Dell Networking W-Series Instant Access
Example
The following example configures a CALEA profile:
(Instant Access Point)(config)# calea
(Instant Access Point)(calea)# ip 192.0.8.29
(Instant Access Point)(calea)# ip mtu 1500
(Instant Access Point)(calea)# encapsulation-type gre
(Instant Access Point)(calea)# gre-type 25944
(Instant Access Point)(calea)# end
(Instant Access Point)# commit apply
This command provisions the cellular (3G/4G) uplink profiles on a W-IAP. Contact your IT administrator or the
manufacturer of your modem to obtain the parameter details for command execution.
Syntax
ParameterDescriptionRangeDefault
cellular-uplink-profile <profi
le>
4g-usb-type <4G-usb-type>
modem-isp <modem_isp>
modem-country <modem-country>
usb-auth-type <usb_
authentication_type>
usb-dev <usb-dev>
usb-dial <usb-dial>
usb-init <usb-init>
Configures a 3G or 4G cellular
profile for a W-IAP.
Configures the driver type for
the 4G modem.
Specifies the name of the ISP
to connect.
Specifies the country for the
deployment.
Specifies the authentication
type for USB.
Specifies the device ID of the
USB modem.
Specifies the parameter to dial
the cell tower.
Specifies the parameter name
to initialize the modem.
Specifies the password for the
account associated with the
subscriber of the selected ISP.
——
Page 46
ParameterDescriptionRangeDefault
usb-modeswitch <usb-modeswitc
h>
usb-type <usb-type>
usb-tty <usb-tty>
usb-user <usb-user>
no…
Specifies the parameter used
to switch modem from storage
mode to modem mode.
Configures the driver type for
the 3G modem.
Specifies the modem tty port.——
Specifies the username of
subscriber of the selected ISP.
Removes the specified
configuration parameter.
——
acm,
airprime, hso,
option,
pantech-3g,
sierra-evdo,
sierra-
gsm,none
——
——
—
Usage Guidelines
Use this command to configure a cellular uplink profile on a W-IAP and modem parameters 3G /4G uplink
provisioning. Dell W-Instant supports the use of 3G/4G USB modems to provide Internet backhaul to an Instant
network. The 3G/4G USB modems can be used to extend client connectivity to places where an Ethernet uplink
cannot be configured. This enables the IAP-VPNs to automatically choose the available network in a specific region.
The3G and 4G LTE USB modems can be provisioned on W-IAP3WN/3WNP and W-IAP155/155P.
Types of Modems
Dell W-Instant supports the following three types of 3G modems:
l True Auto Detect— Modems of this type can be used only in one country and for a specific ISP. The parameters
are configured automatically and hence no configuration is necessary.
l Auto-detect + ISP/country— Modems of this type require the user to specify the Country and ISP. The same
modem is used for different ISPs with different parameters configured for each of them.
l No Auto-detect— Modems of this type are used only if they share the same Device-ID, Country, and ISP details.
You need to configure different parameters for each of them. These modems work with Dell W-Instant when the
appropriate parameters are configured.
The following table lists the types of supported 3G modems:
Table 9:
Modem TypeSupported 3G Modems
True Auto Detectl USBConnect 881 (Sierra 881U)
List of Supported 3G Modems
l Quicksilver (Globetrotter ICON 322)
l UM100C (UTstarcom)
l Icon 452
l Aircard 250U (Sierra)
l USB 598 (Sierra)
l U300 (Franklin wireless)
l U301 (Franklin wireless)
l USB U760 for Virgin (Novatel)
l USB U720 (Novatel/Qualcomm)
l UM175 (Pantech)
l UM150 (Pantech)
l UMW190(Pantech)
l SXC-1080 (Qualcomm)
l Globetrotter ICON 225
l UMG181
l NTT DoCoMo L-05A (LG FOMA L05A)
l NTT DoCoMo L-02A
l ZTE WCDMA Technologies MSM (MF668?)
l Fivespot (ZTE)
l c-motech CNU-600
l ZTE AC2736
l SEC-8089 (EpiValley)
l Nokia CS-10
l NTT DoCoMo L-08C (LG)
l NTT DoCoMo L-02C (LG)
l Novatel MC545
l Huawei E220 for Movistar in Spain
l Huawei E180 for Movistar in Spain
l ZTE-MF820
l Huawei E173s-1
l Sierra 320
l Longcheer WM72
l U600 (3G mode)
Auto-detect + ISP/country
l Sierra USB-306 (HK CLS/1010 (HK))
l Sierra 306/308 (Telstra (Aus))
l Sierra 503 PCIe (Telstra (Aus))
l Sierra 312 (Telstra (Aus))
l Aircard USB 308 (AT&T's Shockwave)
l Compass 597(Sierra) (Sprint)
l U597 (Sierra) (Verizon)
l Tstick C597(Sierra) (Telecom(NZ))
l Ovation U727 (Novatel) (Sprint)
l USB U727 (Novatel) (Verizon)
l USB U760 (Novatel) (Sprint)
l USB U760 (Novatel) (Verizon)
l Novatel MiFi 2200 (Verizon Mifi 2200)
l Huawei E272, E170, E220 (ATT)
l Huawei E169, E180,E220,E272 (Vodafone/SmarTone (HK))
l Huawei E160 (O2(UK))
l Huawei E160 (SFR (France))
l Huawei E220 (NZ and JP)
l Huawei E176G (Telstra (Aus))
l Huawei E1553, E176 (3/HUTCH (Aus))
l Huawei K4505 (Vodafone/SmarTone (HK))
l Huawei K4505 (Vodafone (UK))
l ZTE MF656 (Netcom (norway))
l ZTE MF636 (HK CSL/1010)
l ZTE MF633/MF636 (Telstra (Aus))
l ZTE MF637 (Orange in Israel)
l Huawei E180, E1692,E1762 (Optus (Aus))
l Huawei E1731 (Airtel-3G (India))
l Huawei E3765 (Vodafone (Aus))
l Huawei E3765 (T-Mobile (Germany)
l Huawei E1552 (SingTel)
l Huawei E1750 (T-Mobile (Germany))
l UGM 1831 (TMobile)
l Huawei D33HW (EMOBILE(Japan))
l Huawei GD01 (EMOBILE(Japan))
l Huawei EC150 (Reliance NetConnect+ (India))
l KDDI DATA07(Huawei) (KDDI (Japan))
l Huawei E353 (China Unicom)
l Huawei EC167 (China Telecom)
l Huawei E367 (Vodafone (UK))
l Huawei E352s-5 (T-Mobile (Germany))
No auto-detectl Huawei D41HW
l ZTE AC2726
Table 10:
4G Supported Modem
Modem TypeSupported 4G Modem
True Auto Detectl Pantech UML290
l Ether-lte
When UML290 runs in auto detect mode, the modem can switch from 4G network to 3G network or vice-versa
based on the signal strength. To configure the UML290 for the 3G network only, manually set the USB type to
pantech-3g. To configure the UML290 for the 4G network only, manually set the 4G USB type to pantech-lte.
Example
The following example configures a cellular uplink profile:
(Instant Access Point)(config) # cellular-uplink-profile
(Instant Access Point)(cellular-uplink-profile)# 4g-usb-type pantech-lte
(Instant Access Point)(cellular-uplink-profile)# modem-country India
(Instant Access Point)(cellular-uplink-profile)# modem-isp example
(Instant Access Point)(cellular-uplink-profile)# usb-auth-type PAP
(Instant Access Point)(cellular-uplink-profile)# usb-user user1
(Instant Access Point)(cellular-uplink-profile)# usb-passwd user123
(Instant Access Point)(cellular-uplink-profile)# modem-country India
(Instant Access Point)(cellular-uplink-profile)# end
(Instant Access Point)# commit apply
This command configures daylight saving for the time zones that support daylight saving time.
Syntax
ParameterDescriptionRange
clock summer-time
<timezone>
recurring
<start-week>
<start-day>
<start-month>
<start-hour>
<eweek>
<eday>
<emonth>
Configures Daylight Saving time.Timezones
that support
daylight
saving
configuration
Indicates the recurrences.—
Indicates the week from which the daylight saving configuration is
effective.
Indicates the day from which the daylight saving configuration
applies.
Indicates the month from which the daylight saving configuration
applies.
Indicates the hour from which the daylight saving configuration
applies.
Indicates the week in which the daylight saving configuration ends.—
Indicates the day on which daylight saving configuration ends.—
Indicates the month in which daylight saving configuration ends.—
—
—
—
1-24
<ehour>
no…
Indicates the hour at which daylight saving configuration ends.1-24
Removes the configuration—
Usage Guidelines
Use this command to configure daylight saving for the timezones that support daylight saving. When enabled, the
daylight saving time ensures that the W-IAPs reflect the seasonal time changes in the region they serve.
Example
The following example configures daylight saving for a timezone:
(Instant Access Point)(config)# clock summer-time PST recurring 7 10 March 9PM 38 10 October 9
PM
(Instant Access Point)(config)# end
(Instant Access Point)# commit apply
This command allows you to commit configuration changes performed during a user session. You can also revert the
changes that are already committed.
Syntax
ParameterDescription
apply
no-save
revert
Applies and saves the W-IAP configuration changes.
Applies the configuration changes to the cluster, but does not save the
configuration. To save the configuration, run the write memory or commit apply
command.
Reverts the changes committed to the current configuration of a W-IAP.
Usage Guidelines
Each command processed by the Virtual Controller is applied on all the slave W-IAPs in a cluster. The changes
configured in a CLI session are saved in the CLI context. The CLI does not support the configuration data exceeding
the 4K buffer size in a CLI session: therefore, Dell recommends that you configure fewer changes at a time and
apply the changes at regular intervals.
To apply and save the configuration changes, use the commit apply command. To apply the configuration changes
without saving the configuration, use the commit apply no-save command.
Example
The following command allows you to commit the configuration changes:
(Instant Access Point) # commit apply
The following command reverts the already committed changes.
Command History
VersionDescription
Dell Networking W-Series Instant Access
Point 6.3.1.1-4.0
Dell Networking W-Series Instant Access
Point 6.2.1.0-3.3
This command enables content filtering feature. When content filtering is enabled on an SSID, all DNS requests to
non-corporate domains on this wireless network are sent to OpenDNS.
Syntax
Command/ParameterDescription
content-filtering
no
Enables content filtering.
Removes the configuration.
Usage Guidelines
Use this command to enable content filter. With content filter feature enabled, you can:
l Prevent known malware hosts from accessing your wireless network.
l Improve employee productivity by limiting access to certain Websites.
l Reduce bandwidth consumption significantly.
You can enable content filtering on an SSID. When enabled, all DNS requests to non-corporate domains on this
SSID are sent to the open DNS server.
This command allows you to provision a W-IAP as a Campus AP or Remote AP in a controller-based network, or as
a standalone AP.
Syntax
ParameterDescriptionRange
<mode>
<controller-IP>
Provisions the W-IAP as remote AP or campus AP in a
controller-based network or as a standalone AP.
Allows you to specify the IP address of the Controller to which
the Remote AP or Campus AP will be connected.
RAP, CAP,
StandaloneAP
—
Usage Guidelines
Before converting a W-IAP, ensure that both the W-IAP and controller are configured to operate in the same
regulatory domain. A W-IAP can be converted to a Campus AP and Remote AP only if the controller is running Dell
W-Instant 6.1.4 or later.
Example
The following command allows you to convert a W-IAP to a remote AP:
copy {config tftp <ip-address> <filename>|core-file tftp <ip-address>| flash tftp <ip-address>
<filename>| tftp <ip-address> <filename> {cpserver cert <password> format {p12|pem} | portal
logo | system {1xca [format {der|pem}]|1xcert <passsword>[format {p12|pem}]|config|flash}}
Description
This command copies files to and from the W-IAP.
Syntax
ParameterDescription
configCopies a configuration file to the TFTP server.
core-fileCopies a core file to the TFTP server.
flashCopies a file from flash to the TFTP server or to flash from a TFTP server.
tftpCopies files and certificates to the W-IAP database from a TFTP server.
<ip-address>Copies files to the specified TFTP server IP address.
<file-name>Indicates the name of the file to be copied.
cpserver
cert <password>
portal
logo
systemCopies the file to the system partition.
1xcaCopies the CA certificate used for 802.1X authentication from the TFTP server.
der
pem
1xcertCopies the server certificate used for 802.1X authentication from the TFTP
<passsword>Indicates the password for certificate authentication.
p12
pem
Copies internal Captive portal server certificate.
Copies customized logo for the internal Captive portal server.
Indicates the system partition file extensions.
server.
Indicates the certificate file extensions.
Usage Guidelines
Use this command to save backup copies of the configuration file to a TFTP server, or to load a certificate file and
customized logo from a TFTP server to the W-IAP database.
Example
The following example copies a configuration file to the TFTP server:
This command disables bridging traffic between two clients of a W-IAP on the same VLAN. Bridging traffic between
the clients will be sent to the upstream device to make the forwarding decision.
Syntax
ParameterDescription
deny-inter-user-bridging
no…
Prevents the inter-user bridging.
Removes the configuration.
Usage Guidelines
Use this command if you have security and traffic management policies defined for upstream devices.
Example
The following command disables inter-user bridging:
This command disables routing traffic between two clients of a W-IAP on different VLANs. Routing traffic between
the clients will be sent to the upstream device to make the forwarding decision.
Syntax
ParameterDescription
deny-local-routing
no…
Disables local routing of traffic.
Removes the configuration.
Usage Guidelines
Use this command to prevent the local routing of traffic if you have security and traffic management policies defined
for upstream devices.
This command allows you to download the client, authentication server, and Captive portal server certificates from
an FTP or TFTP server, or by using an HTTP URL.
Syntax
ParameterDescription
ca
cp
server
<url>
Downloads client certificates.
Downloads Captive portal server certificates.
Downloads Server certificates.
Allows you to specify the FTP, TFTP, or HTTP URL.
Usage Guidelines
Use this command to download certificates.
Example
The following command shows an example for downloading CAclient certificates:
(Instant Access Point)# download-cert ca ftp://192.0.2.7
This command enables or disables the dynamic CPU management feature, to manage resources across different
functions performed by a W-IAP.
Syntax
ParameterDescription
auto
disable
enable
Configures the W-IAP to automatically enable or disable CPU management feature
during run-time. When configured, the W-IAP determines the need for enabling or
disabling CPU management, based on the real-time load calculations taking into
account all different functions that the CPU needs to perform.
The aut o option is the default and recommended setting.
Disables CPU management on all APs, typically for small networks. This setting
protects the user experience.
Enables the CPU management feature. When configured, the client and network
management functions are protected. This setting helps in large networks with a
high client density.
Usage Guidelines
Use this command to enable or disable resource management across different functions performed by a W-IAP.
Example
The following example enables the automatic enabling or disabling of CPU management:
(Instant Access Point)(config)# dynamic-cpu-mgmt auto
(Instant Access Point)(config)# end
(Instant Access Point)# commit apply
Command History
VersionDescription
Dell Networking W-Series Instant 6.3.1.1-4.0This command is introduced.
This command enables the use of IP Address of the Virtual Controller for communication with external RADIUS
servers.
Syntax
Command/ParameterDescription
dynamic-radius-proxy
no…
Enables dynamic RADIUS proxy feature to allow the Virtual
Controller network to use the IPaddress of the Virtual Controller
when communicating with the external RADIUS servers.
Removes the configuration.
Usage Guidelines
Ensure that you set the Virtual Controller IP address as a NAS client in the RADIUS server when Dynamic RADIUS
proxy is enabled.
Example
The following example enables the dynamic RADIUS proxy feature:
This command allows you to use all ports on the APs as downlink ports.
Usage Guidelines
Use this command for W-IAP models that have only one Ethernet port enabled. When Eth0 bridging is configured,
ensure that the uplink for each W-IAP is mesh link, Wi-Fi, or 3G/4G.
Example
The following command enables Eth0 bridging:
(Instant Access Point)# enet0-bridging
Command History
VersionDescription
Dell Networking W-Series Instant Access
Point 6.2.1.0-3.3
This command enables the configuration of additional WLAN SSIDs.
Syntax
Command/ParameterDescription
extended-ssid
no…
Enables the users to configure additional SSIDs.
Removes the configuration.
Usage Guidelines
Use this command to create additional SSIDs. By default, you can create up to six WLAN SSIDs. With the
Extended SSID option enabled, you can create up to 16 WLANs. The following W-IAPs support 16 WLANs:
l W-IAP3WNP
l W-IAP93
l W-IAP134
l W-IAP135
The number of SSIDs that become active on each W-IAP depends on the W-IAP platform.
Example
The following example enables the configuration of extended SSIDs:
disable
enable
ip <address>
port <port>
user <name> <password>
no…
Description
This command configures external firewall details such as Palo Alto Networks(PAN) firewall to enable integration
with the W-IAP.
Syntax
ParameterDescriptionRangeDefault
firewall-external-enforcement
pan
disable
enable
ip <address>
port <port>
user <name> <password>
no…
PAN firewall configuration submode.
Disables PAN firewall.——
Enables PANfirewall.——
Configures PAN firewall IP
address on the W-IAP
Configures a port for the PAN
firewall
Configures administrator user
credentials of PAN firewall on a
W-IAP.
Removes the specified
configuration parameter.
——
——
1—65535443
——
——
Usage Guidelines
Use this command to enable external firewall integration with W-IAP. In Instant 6.3.1.1-4.0 release, W-IAPs can be
integrated with external firewall such as PAN firewall. The PAN firewall is based on user ID, which provides many
methods for connecting to sources of identity information and associating them with firewall policy rules. The
functionality provided by the PAN firewall based on user ID requires the collection of information from the network.
W-IAP maintains the network (such as mapping IP address) and user information for those clients in the network and
provides the required information for the user ID feature on PAN firewall.
To enable W-IAP integration with PAN firewall, a global profile configured on W-IAP with PAN firewall information
such as IP address, port, user name, password, firewall enabled or disabled status.
Example
The following example configures PAN firewall information on a W-IAP:
(Instant Access Point)(config)# firewall-external-enforcement pan
(Instant Access Point)(firewall-external-enforcement pan)# enable
(Instant Access Point)(firewall-external-enforcement pan)# ip 192.0.2.11
(Instant Access Point)(firewall-external-enforcement pan)# port 443
This command configures external antenna connectors for a W-IAP.
Syntax
ParameterDescriptionRangeDefault
<gain>
Configures the antenna gain. You can configure gain
value in dBi for the following types of antenna:
l Dipole/Omni
l Panel
l Sector
Diploe/Omni - 6
Panel -12
Sector - 12
—
Usage Guidelines
If your W-IAP has external antenna connectors, you need to configure the transmit power of the system. The
configuration must ensure that the system’s Equivalent Isotropically Radiated Power (EIRP) is in compliance with
the limit specified by the regulatory authority of the country in which the W-IAP is deployed. You can also measure or
calculate additional attenuation between the device and antenna before configuring the antenna gain. To know if your
AP device supports external antenna connectors, see the
EIRP and Antenna Gain
The following formula can be used to calculate the EIRP limit related RF power based on selected antennas
(antenna gain) and feeder (Coaxial Cable loss):
EIRP = Tx RF Power (dBm)+GA (dB) - FL (dB)
The following table describes this formula:
Install Guide
that is shipped along with the AP device.
Table 11:
Formula Variable Definitions
Formula ElementDescription
EIRPLimit specific for each country of deployment
Tx RF PowerRF power measured at RF connector of the unit
GAAntenna gain
FLFeeder loss
For information on antenna gain recommended by the manufacturer, see dell.com/support.
Example
The following example configures external antenna connectors for the W-IAP with the 2.4 GHz radio band.
This command configures a generic routing encapsulation (GRE) tunnel from each W-IAP to the VPN/GRE Endpoint
rather than the tunnels created just from the Virtual Controller.
Syntax
ParameterDescription
gre per-ap-tunnel
no…
Creates a GRE tunnel from the W-IAP to the VPN/GRE endpoint.
Removes the configuration.
Usage Guidelines
Use this command to allow the traffic to be sent to the corporate network through a Layer-2 GRE tunnel from the WIAP itself. When a GRE tunnel per W-IAP is created, the traffic need not be forwarded through the Virtual Controller.
Example
The following example creates a GRE tunnel for the W-IAP:
(Instant Access Point)(config)# gre per-ap-tunnel
(Instant Access Point)(config)# end
(Instant Access Point)# commit apply
Command History
VersionDescription
Dell Networking W-Series Instant Access
Point 6.2.1.0-3.3
This command configures a GREprotocol number as GRE type.
Syntax
ParameterDescriptionRangeDefault
gre type <type>
Configures the protocol number or IP address for
GRE type
16-bit
protocol
number
0
Usage Guidelines
Use this command to specify GRE type. The 16-bit protocol number uniquely identifies a Layer-2 tunnel. The WIAPs or controllers at both endpoints of the tunnel must be configured with the same protocol number.
Example
The following example configures the GRE type:
(Instant Access Point)(config)# gre type 0
(Instant Access Point)(config)# end
(Instant Access Point)# commit apply
Command History
VersionDescription
Dell Networking W-Series Instant Access
Point 6.2.1.0-3.3
This command displays keyboard editing commands that allow you to make corrections or changes to the command
without retyping.
You can also enter the question mark (?) to get various types of command help:
l When typed at the beginning of a line, the question mark lists all commands available in the current mode.
l When typed at the end of a command or abbreviation, the question mark lists possible commands that match.
l When typed in place of a parameter, the question mark lists available options.
Example
The following example shows the output of the help command.
HELP:
Special keys:
BS.... delete previous character
Ctrl-A.... go to beginning of line
Ctrl-E.... go to end of line
Ctrl-F.... go forward one character
Ctrl-B.... go backward one character
Ctrl-D.... delete current character
Ctrl-U, X .. delete to beginning of line
Ctrl-K.... delete to end of line
Ctrl-W.... delete previous word
Ctrl-T.... transpose previous character
Ctrl-P.... go to previous line in history buffer
Ctrl-N.... go to next line in history buffer
Ctrl-Z.... return to root command prompt
Tab.... command-line completion
exit.... go to next lower command prompt
?.... list choices
Help may be requested at any point in a command by entering
a question mark '?'. If nothing matches, the help list will
be empty and you must back up until entering a '?' shows the
available options.
Two styles of help are provided:
1. Full help is available when you are ready to enter a
command argument (e.g. 'show ?') and describes each possible
argument.
2. Partial help is provided when an abbreviated argument is entered
and you want to know what arguments match the input
(e.g. 'show w?'.)
This command changes the hostname of the Virtual Controller.
Syntax
ParameterDescription
<name>
Configures a hostname for the Virtual Controller.
Usage Guidelines
The hostname is used as the default prompt. You can use any alphanumeric character, punctuation, or symbol
characters. When spaces, plus symbols (+), question marks (?), or asterisks (*) are used, enclose the text in quotes.
Example
The following example configures host name for a W-IAP.
This command configures a 3rd Generation Partnership Project (3GPP) Cellular Network for hotspots that have
roaming relationships with cellular operators.
Syntax
ParameterDescription
hotspot anqp-3gpp-profile
<profile-name>
3gpp-plmn1…3gpp-plmn6 <PLMN-ID>
enable
no…
Creates a 3GPP profile.
Configures the Public Land Mobile Networks (PLMN) value of the
network. The PLMN value can be specified for first, second, third,
fourth, fifth, and sixth highest priority network.
The PLMN ID consists of a 12-bit Mobile Country Code (MCC) and
the 12-bit Mobile Network Code (MNC).
Activates the configuration profile.
Removes the configuration
Usage Guidelines
Use this command to configure a 3GPP Cellular Network hotspot profile that defines the ANQP information element
(IE) for 3G Cellular Network for hotspots. The IE defined in this profile will be sent in a Generic Advertisement
Service (GAS) query response from a W-IAP in a cellular network hotspot. The 3GPP Mobile Country Code (MCC)
and the 12-bit Mobile Network Code data in the IE can help the client select a 3GPP network when associated with a
hotspot profile and enabled on a WLAN SSID profile.
This command defines the domain name to be sent in an Access Network Query Protocol (ANQP) information
element in a Generic Advertisement Service (GAS) query response.
Syntax
ParameterDescription
hotspot anqp-domain-name-profile
<profile-name>
domain-name <domain-name>
enable
no…
Creates a domain profile.
Configures a domain name of the hotspot operator.
Enables the configuration profile.
Removes the existing configuration
Usage Guidelines
Use this command to configure a domain name in the ANQP Domain Name profile. If a client uses the Generic
Advertisement Service (GAS) to post an ANQP query to a W-IAP, the W-IAP will return an ANQP Information
Element with the domain name when this profile is associated with a hotspot profile and enabled on a WLAN SSID
profile.
Example
The following command defines a domain name for the ANQP domain name profile:
Configuration mode and the ANQP domain profile configuration
sub-mode
Page 93
hotspot anqp-ip-addr-avail-profile
hotspot anqp-ip-addr-avail-profile <profile-name>
enable
ipv4-addr-avail
ipv6-addr-avail
no…
Description
This command defines the available IP address types to be sent in an Access network Query Protocol (ANQP)
information element in a Generic Advertisement Service (GAS) query response.
Syntax
ParameterDescription
hotspot anqp-ip-addr-avail-profile <profilename>
enable
ipv4-addr-avail
ipv6-addr-avail
no…
Creates an ANQP IP Address availability profile.
Enables the IP address availability profile.
Indicates the availability of an IPv4 network.
Indicates the availability of an IPv6 network.
Removes the existing configuration.
Usage Guidelines
Use this command to configure the IP Address availability information and IP address types which could be
allocated to the clients after they associate to the hotspot W-IAP.
Example
The following command configures an AP using this profile to advertise a public IPv4 network.
This command defines a Network Access Identifier (NAI) realm information that can be sent as an Access network
Query Protocol (ANQP) information element in a Generic Advertisement Service (GAS) query response.
Syntax
ParameterDescriptionRange
hotspot anqp-nairealm-profile
<profile-name>
enable
nai-home-realm
nai-realm-auth-id-1
nai-realm-auth-id-2
<auth-id>
Configures a NAI realm hotspot profile.—
Enables the NAI realm profile.
Sets the realm in this profile as the NAI Home Realm.—
Configures the NAI realm authentication ID.
Use the nai-realm-auth-id-1 command to send the one of the
following authentication methods for the primary NAI realm ID.
Use the nai-realm-auth-id-2 command to send the one of the
following authentication methods for the secondary NAI realm
ID.
Configures any of the following types of authentication ID:
l credential— Uses credential authentication.
l eap-inner-auth—Uses EAP inner authentication type.
l exp-inner-eap— Uses the expanded inner EAP
authentication method.
l expanded-eap—Uses the expanded EAP authentication
method.
l non-eap-inner-auth—Uses non-EAP inner authentication
type.
l reserved—Uses the reserved authentication method.
Configures a value for NAI realm authentication. Use the nairealm-auth-value-1 command to select an authentication
value for the authentication method specified by nai-realmauth-id-1. Use thenai-realm-auth-value-2 command to select
the authentication value for the authentication method
specified bynai-realm-auth-id-2.
—
Page 95
ParameterDescriptionRange
<auth-value>
Configures any of following types of authentication values for
the specified <auth-id>:
l For credential <auth-ID>, specify the following values:
l sim
l usim
l nfc-secure
l hw-token
l softoken
l certificate
l uname-passward
l none
l reserved
l vendor-specific
l For eap-inner-auth <aut- ID>, specify the following values:
l reserved
l pap
l chap
l mschap
l mschapv2
l For exp-inner-eap <auth-ID>, specify exp-inner-eap as the
authentication value.
l For expanded-eap<auth-ID>, specify expanded-eap as the
authentication value
l For non-eap-inner-auth<auth-ID> specify any of the
l crypto-card— Crypto card authentication
l eap-aka—EAP for UMTS Authentication and Key
Agreement
l eap-sim—EAP for GSM Subscriber Identity Modules
l eap-tls—EAP-Transport Layer Security
l eap-ttls—EAP-Tunneled Transport Layer Security
l generic-token-card—EAP Generic Token Card (EAP-GTC)
l identity— EAP Identity type
l notification—The hotspot realm uses EAP Notification
messages for authentication.
l one-time-password—Authentication with a single-use
password
l peap—Protected Extensible Authentication Protocol
l peapmschapv2— Protected Extensible Authentication
Protocol with Microsoft Challenge Handshake
Authentication Protocol version 2
Configures a UTF-8 or rfc4282 formatted character string for
NAI realm encoding.
rfc4282,
utf8
Page 96
ParameterDescriptionRange
nai-realm-name
<nai-realm-name>
no…
Configures a name for the NAI realm. The realm name is often
the domain name of the service provider.
Removes any existing configuration.
—
—
Usage Guidelines
Use this command to configure an NAI Realm profile that identifies and describes a NAI realm accessible to the WIAP, and the method used for NAI realm authentication. The settings configured in this profile determine the NAI
realm elements that are included as part of a GAS Response frame.
Example
The following example creates an NAI realm profile:
Configures URL, IP address, or FQDN used by
the hotspot network for the accept-term-andcond or dns-redirect network authentication
types.
Removes any existing configuration.
—
—
Usage Guidelines
When the asra option is enabled in the hotspot profile associated with a WLANSSID, the settings configured for the
network authentication profile are sent in the GAS response to the client.
Example
The following command configures a network authentication profile for DNS redirection.
This command configures the Roaming Consortium Organization Identifier (OI) information to be sent in an Access
network Query Protocol (ANQP) information element in a Generic Advertisement Service (GAS) query response.
Syntax
ParameterDescriptionRange
hotspot anqp-roam-cons-profile
<profile-name>
enable
roam-cons-oi
<roam-cons-oi>
roam-cons-oi-len
<roam-cons-oi-len>
no…
Creates roaming consortium profile.
Enables the roaming consortium profile.—
Sends the specified roaming consortium OI in
a GAS query response. The OI must be a
hexadecimal number 3-5 octets in length.
Indicates the length of the OI. The value of the
roam-cons-oi-len parameter must equal upon
the number of octets of the roam-cons-oi field.
l 0: 0 Octets in the OI (Null)
l 3: OI length is 24-bit (3 Octets)
l 5: OI length is 36-bit (5 Octets)
Removes any existing configuration.
—
Hexadecimal
number 3-5
octets in length
—
—
Usage Guidelines
Use this command to configure the roaming consortium OIs assigned to service providers when they register with
the IEEE registration authority. The Roaming Consortium Information Elements (IEs) contain information about the
network and service provider, whose security credentials can be used to authenticate with the W-IAP transmitting
this IE.
Example
The following command defines the roaming consortium OI and OI length in the ANQP roaming consortium profile: