System®. Dell™, the DELL™ logo, and PowerConnect™ are trademarks of Dell Inc.
All rights reserved. Specifications in this manual are subject to change without notice.
Originated in the USA. All other trademarks are the property of their respective owners.
Open Source Code
Certain Aruba products include Open Source software code developed by third parties, including software code
subject to the GNU General Public License (GPL), GNU Lesser General Public License (LGPL), or other Open
Source Licenses. Includes software from Litech Systems Design. The IF-MAP client library copyright 2011 Infoblox,
Inc. All rights reserved. This product includes software developed by Lars Fenneberg, et al. The Open Source code
used can be found at this site:
http://www.arubanetworks.com/open_source
Legal Notice
The use of Aruba Networks, Inc. switching platforms and software, by all individuals or corporations, to terminate
other vendors’ VPN client devices constitutes complete acceptance of liability by that individual or corporation for
this action and indemnifies, in full, Aruba Networks, Inc. from any and all legal actions that might be taken against it
with respect to infringement of copyright on behalf of those vendors.
This document describes the Dell W-Instant command syntax and provides the following information for each
command:
l Command Syntax—The complete syntax of the command.
l Description—A brief description of the command.
l Syntax—A description of the command parameters, the applicable ranges and default values, if any.
l Usage Guidelines—Information to help you use the command, including prerequisites, prohibitions, and related
commands.
l Example—An example of how to use the command.
l Command History—The version of Dell W-Instant in which the command was first introduced.
l Command Information—This table describes command modes and platforms for which this command is
applicable.
The commands are listed in alphabetical order.
Intended Audience
This guide is intended for customers who configure and use Dell Networking W-Series Instant Access Point (WIAP).
Related Documents
In addition to this document, the Dell W-IAP product documentation includes the following:
l Dell Networking W-Series Instant Access Point Installation Guides
l Dell Networking W-Series Instant Access Point 6.3.1.1-4.0 Quick Start Guide
l Dell Networking W-Series Instant Access Point 6.3.1.1-4.0 User Guide
l Dell Networking W-Series Instant Access Point 6.3.1.1-4.0 MIB Reference Guide
l Dell Networking W-Series Instant Access Point 6.3.1.1-4.0 Syslog Messages Reference Guide
l Dell Networking W-Series Instant Access Point 6.3.1.1-4.0 Release Notes
Conventions
The following conventions are used throughout this document to emphasize important concepts:
Table 1:
Type StyleDescription
Typographical Conventions
Italics
Boldface
Commands
Dell Networking W-Series Instant 6.3.1.1-4.0 | CLI User GuideAbout this Guide | 4
This style is used for emphasizing important terms and to mark
the titles of books.
This style is used for command names and parameter options
when mentioned in the text.
This fixed-width font depicts command syntax and examples of
commands and command output.
Type StyleDescription
<angle brackets>In the command syntax, text within angle brackets represents
items that you should replace with information appropriate to
your specific situation.
For example, ping <ipaddr>
In this example, you would type “ping” at the system prompt
exactly as shown, followed by the IP address of the system to
which ICMP echo packets are to be sent. Do not type the angle
brackets.
[square brackets]In the command syntax, items enclosed in brackets are
optional. Do not type the brackets.
{Item_A|Item_B}In the command examples, single items within curled braces
and separated by a vertical bar represent the available
choices. Enter only one choice. Do not type the braces or bars.
{ap-name <ap-name>}|{ipaddr <ip-addr>}Two items within curled braces indicate that both parameters
must be entered together. If two or more sets of curled braces
are separated by a vertical bar, like in the example to the left,
enter only one choice. Do not type the braces or bars.
The following informational icons are used throughout this guide:
Indicates helpful suggestions, pertinent information, and important things to remember.
Indicates a risk of damage to your hardware or loss of data.
Indicates a risk of personal injury or death.
Contacting Dell
Table 2:
Support
Main Websitedell.com
Contact Informationdell.com/contactdell
Support Websitedell.com/support
Documentation Website
Support Information
dell.com/support/manuals
What is New in Dell W-Instant 6.3.1.1-4.0
This section lists the new and modified commands in the Dell W-Instant 6.3.1.1-4.0 release.
New Commands
The following commands are added in the Dell W-Instant 6.3.1.1-4.0 release:
5 | About this GuideDell Networking W-Series Instant 6.3.1.1-4.0 | CLI Reference Guide
Table 3:
New Commands in 6.3.1.1-4.0
CommandDescription
ale-serverConfigures Analytics and Location Engine (ALE) server details to enable W-IAP integration with
ALE.
ale-report-intervalConfigures the interval at which a W-IAP sends data to the Analytics and Location Engine
(ALE) server.
firewall-externalenforcement
iap-masterProvisions a W-IAP as a master W-IAP.
proxyConfigures a HTTP proxy on a W-IAP for cloud image download.
restrict-corp-accessConfigures restricted access to the corporate network.
restricted-mgmtaccess
show
airgroupservice-id
show aleDisplays the ALE configuration details.
show ap clientmatch-history
show ap clientmatch-live
show ap clientmatch-refused
Configures external firewall such as Palo Alto Networks(PAN) firewall to enable integration
with the W-IAP
Configures management subnets to enable restricted access to the corporate network.
Displays the AirGroup service IDs configured on a W-IAP for its AirGroup clients.
Displays a historical record of the client match events and actions for the clients associated with
a W-IAP.
Displays the current client match events and actions for clients associated with a W-IAP.
Displays the list of clients for which the channel allocation is refused as per the client match
configuration parameters.
show ap clientprobe-report
show ap client-viewDisplays information about the clients in the AP neighborhood.
show ap debug
client-match
show ap debug
spanning-tree
show ap pmkcacheDisplays the pairwise master key (PMK) cache table for clients associated with a W-IAP.
show ap virtualbeacon-report
show captiveportal-domains
show externalcaptive-portal
Displays the client probe report for a W-IAP.
Displays the information about the client match configuration status on an AP radio interface.
Displays the Spanning Tree Protocol (STP) information for a W-IAP if configured.
Displays a report with the MAC address details and RSSI information of a W-IAP.
Displays the internal and external Captive portal server domains.
Displays the external Captive portal configuration details.
show proxy configDisplays the HTTP proxy configuration details.
telnet-serverAllows Telnet access to the Dell W-Instant CLI.
vpn-gre-outsideConfigures an automatic GRE tunnel for Dell controller.
Displays the Link Aggregation Control Protocol (LACP) configuration status on a W-IAP.
Modified Commands
The following commands are modified in the Dell W-Instant 6.3.1.1-4.0 release:
Table 4:
CommandDescription
airgroupserviceThe airgroupservice allows you configure AirGroup services such as iTunes, Sharing, Chat,
ams-backup-ipThe ams-backup-ip command is enhanced to support a backup domain name along with
ams-ipThe ams-ip command is enhanced to support domain name along with the IP address.
armThe arm command is enhanced to support client match configuration.
Modified Commands in 6.3.1.1-4.0
and so on. You can configure all services at once.
the backup IP address.
commitThe commit command is enhanced to provide an option (commit apply no-save command)
for applying the configuration changes to the cluster without saving the configuration.
copyThe copy tftp command is enhanced to upload customized logo images to the W-IAP
database.
download-certThe download-cert command is enhanced to allow the downloading of Captive portal
server certificates from an FTP or TFTP server, or by using an HTTP URL.
ip dhcpThe ip dhcp command is modified to include centralized L3.
mgmt-userThe mgmt-user command now allows you to configure read-only users and users for the
guest management interface.
show airgroup
show airgroupserviceThe show airgroupservice command output is enhanced to display the configuration status
wired-port-profileThe wired-port-profile is modified to include the spanning-tree command parameter to
wlan access-rule
The show airgroup command is enhanced to include blocked-queries, blocked-service-id,
internal-state statistics, and swarm-info commands.
of all AirGroup services.
allow the administrators to enable Spanning Tree Protocol (STP) for the wired profile users.
The wlan access-rule command is enhanced to include the bandwidth-limit command to
allow the administrators to allocate bandwidth limit to the SSID users.
wlan auth-serverThe wlan auth-server command is enhanced to include the dynamic RADIUSproxy
configuration parameters.
7 | About this GuideDell Networking W-Series Instant 6.3.1.1-4.0 | CLI Reference Guide
Table 4:
Modified Commands in 6.3.1.1-4.0
CommandDescription
wlan external-captiveportal
The wlan external-captive-portal command is enhanced to allow the administrators to
create multiple profiles and assign the required profiles to a WLAN SSID or wired profile.
wlan ssid-profileThe wlan ssid-profile command is modified to include the following parameters:
l okc-disable — For Opportunistic Key Caching (OKC) roaming support
l dot11r — For 802.11r roaming support
l mac-authentication-delimiter — To allow the use of delimiters such as colon and dash in
MAC address string.
l mac-authentication-upper-case— To allow the use of uppercase letters in MAC address
Dell W-Instant supports the use of Command Line Interface (CLI) for scripting purposes. You can access the Dell
W-Instant CLI through a Secure Shell (SSH).
To enable the SSH access to the Dell W-Instant CLI:
1. From the Dell W-Instant UI, navigate to System > Show advanced options.
2. Select Enabled from the Terminal access drop-down list.
3. Click OK.
Connecting to a CLI Session
On connecting to a CLI session, the system displays its host name followed by the login prompt. Use the
administrator credentials to start a CLI session. For example:
If the login is successful, the privileged command mode is enabled and a command prompt is displayed. For
example:
(Instant Access Point)#
The privileged mode provides access to show, clear, ping, traceroute, and commit commands. The configuration
commands are available in the configuration (config) mode. To move from privileged mode to the configuration mode,
enter the following command at the command prompt:
(Instant Access Point)# configure terminal
The configure terminal command allows you to enter the basic configuration mode and the command prompt is
displayed as follows:
(Instant Access Point)(config)#
The Dell W-Instant CLI allows CLI scripting in several other sub-command modes to allow the users to configure
individual interfaces, SSIDs, access rules, and security settings.
You can use the question mark (?) to view the commands available in a privileged mode, configuration mode, or submode.
Although automatic completion is supported for some commands such as configure terminal, the complete exit
and end commands must be entered at command prompt for successful execution.
Applying Configuration Changes
Each command processed by the Virtual Controller is applied on all the slave W-IAPs in a cluster. When you make
configuration changes on a master W-IAP in the CLI, all associated W-IAPs in the cluster inherit these changes and
subsequently update their configurations. The changes configured in a CLI session are saved in the CLI context.
The CLI does not support the configuration data exceeding the 4K buffer size in a CLI session: therefore, it is
recommended that you configure fewer changes at a time and apply the changes at regular intervals.
To apply and save the configuration changes at regular intervals, use the following command in the privileged mode:
To apply the configuration changes to the cluster, without saving the configuration, use the following command in the
privileged mode:
(Instant Access Point)# commit apply no-save
To view the changes that are yet to be applied, use the following command in the privileged mode:
(Instant Access Point)# show uncommitted-config
To revert to the earlier configuration, use the following command in the privileged mode.
(Instant Access Point)# commit revert
Example:
(Instant Access Point)(config)# rf dot11a-radio-profile
(Instant Access Point)(RF dot11a Radio Profile)# beacon-interval 200
(Instant Access Point)(RF dot11a Radio Profile)# no legacy-mode
(Instant Access Point)(RF dot11a Radio Profile)# dot11h
(Instant Access Point)(RF dot11a Radio Profile)# interference-immunity 3
(Instant Access Point)(RF dot11a Radio Profile)# csa-count 2
(Instant Access Point)(RF dot11a Radio Profile)# spectrum-monitor
(Instant Access Point)(RF dot11a Radio Profile)# end
(Instant Access Point)# show uncommitted-config
rf dot11a-radio-profile
no legacy-mode
beacon-interval 200
no dot11h
interference-immunity 3
csa-count 1
no spectrum-monitor
Instant Access Point# commit apply
Configuration Sub-modes
Some commands in configuration mode allow you to enter into a sub-mode to configure the commands specific to
that mode. When you are in a configuration sub-mode, the command prompt changes to indicate the current submode.
You can exit a sub-command mode and return to the basic configuration mode or the privileged Exec (enable) mode
at any time by executing the exit or end command.
Deleting Configuration Settings
Use the no command to delete or negate previously-entered configurations or parameters.
l To view a list of no commands, type no at the prompt in the relevant mode or sub-mode followed by the question
mark. For example:
(Instant Access Point)(config) # no?
l To delete a configuration, use the no form of a configuration command. For example, the following command
removes a configured user role:
(Instant Access Point)(config) # no user <username>
l To negate a specific configured parameter, use the no parameter within the command. For example, the following
command deletes the PPPoE user configuration settings:
(Instant Access Point)(config) # pppoe-uplink-profile
(Instant Access Point)(pppoe_uplink_profile)# no pppoe-username
The Dell W-Instant CLI does not support positioning or precedence of sequence-sensitive commands. Therefore, it
is recommended that you remove the existing configuration before adding or modifying the configuration details for
sequence-sensitive commands. You can either delete an existing profile or remove a specific configuration by using
the no… commands.
The following table lists the sequence-sensitive commands and the corresponding no command to remove the
configuration.
Table 5:
Sequence-Sensitive Commands
Sequence-Sensitive CommandCorresponding no command
no rule <dest> <:mask> <match> <prot
ocol> <start-port> <end-port> {permi
t | deny | src-nat | dst-nat}
no mgmt-auth-server <auth-profile-na
me>
no set-role <attribute>{{equals|
not-equals| starts-with| ends-with|
contains} <operator>| value-of}
no set-role
no set-vlan <attribute>{{equals|
not-equals| starts-with| ends-with|
contains} <operator>| value-of}
no set-vlan
Saving Configuration Changes
The
running-config
To view the running-config of a W-IAP, use the following command:
(Instant Access Point) # show running-config
When you make configuration changes through the CLI, the changes affect the current running configuration only. To
save your configuration changes, use the following command in the privileged Exec mode:
(Instant Access Point)# write memory
Commands that Reset the W-IAP
If you use the CLI to modify a currently provisioned radio profile, the changes take place immediately. A reboot of the
W-IAP is not required to apply the configuration changes. Certain commands, however, automatically force W-IAP
to reboot. Verify the current network loads and conditions before executing the commands that enforce a reboot of
the W-IAP, as they may cause a momentary disruption in service as the unit resets.
holds the current W-IAP configuration, including all pending changes which are yet to be saved.
Command Line Editing
The system records your most recently entered commands. You can review the history of your actions, or reissue a
recent command easily, without having to retype it.
To view items in the command history, use theuparrow key to move back through the list and the
down
arrow key to
move forward. To reissue a specific command, press Enter when the command appears in the command history.
You can also use the command line editing feature to make changes to the command prior to entering it. The
command line editing feature allows you to make corrections or changes to a command without retyping. The
following table lists the editing controls. To use key shortcuts, press and hold the Ctrl button while you press a letter
key.
Table 6:
Line Editing Keys
KeyEffectDescription
Ctrl AHomeMove the cursor to the beginning of the line.
Ctrl B or the
left arrow
Ctrl DDelete RightDelete the character to the right of the cursor.
Ctrl EEndMove the cursor to the end of the line.
Ctrl F or the
right arrow
Ctrl KDelete RightDelete all characters to the right of the cursor.
BackMove the cursor one character left.
ForwardMove the cursor one character right.
Ctrl N or the
down arrow
Ctrl P or
up arrow
Ctrl TTransposeSwap the character to the left of the cursor with
Ctrl UClearClear the line.
Ctrl WDelete WordDelete the characters from the cursor up to and
Ctrl XDelete LeftDelete all characters to the left of the cursor.
NextDisplay the next command in the command
history.
PreviousDisplay the previous command in the command
history.
the character to the right of the cursor.
including the first space encountered.
Specifying Addresses and Identifiers in Commands
This section describes addresses and other identifiers that you can reference in CLI commands.
Table 7:
Address/IdentifierDescription
IP addressFor any command that requires entry of an IP address to specify a network entity,
Addresses and Identifiers
use IPv4 network address format in the conventional dotted decimal notation (for
example, 192.0.2.1).
Netmask addressFor subnet addresses, specify a subnet mask in dotted decimal notation (for
example, 255.255.255.0).
Media Access Control
(MAC) address
Service Set Identifier
(SSID)
Basic Service Set
Identifier (BSSID)
Extended Service Set
Identifier (ESSID)
For any command that requires entry of a device’s hardware address, use the
hexadecimal format (for example, 00:05:4e:50:14:aa).
A unique character string (sometimes referred to as a network name), consisting
of no more than 32 characters. The SSID is case-sensitive (for example, WLAN-
01).
This entry is the unique hard-wireless MAC address of the AP. A unique BSSID
applies to each frequency— 802.11a and 802.11g—used from the AP. Use the
same format as for a MAC address.
Typically the unique logical name of a wireless network. If the ESSID includes
spaces, enclose the name in quotation marks.
This command tests a configured authentication server.
Syntax
ParameterDescription
<servername>
<username>
Allows you to specify the authentication server for which the authentication test
is run.
Allows you to specify the user name for which the authentication test is run.
Usage Guidelines
Use this command to view the CPU load for application and system processes. This command allows you to verify
a configured RADIUS authentication server or the internal database. You can use this command to check for an “out
of service” RADIUS server.
Example
The following example shows the output of the aaa test-server command:
This command configures external antenna connectors for a W-IAP.
Syntax
ParameterDescriptionRange
<gain>
Configures the antenna gain. You can configure a gain value
in dBi for the following types of antenna:
l Dipole/Omni
l Panel
l Sector
Diploe/Omni - 6
Panel -14
Sector - 14
Usage Guidelines
If your W-IAP has external antenna connectors, you need to configure the transmit power of the system. The
configuration must ensure that the system’s Equivalent Isotropically Radiated Power (EIRP) is in compliance with
the limit specified by the regulatory authority of the country in which the W-IAP is deployed. You can also measure or
calculate additional attenuation between the device and antenna before configuring the antenna gain. To know if your
AP device supports external antenna connectors, see the
EIRP and Antenna Gain
The following formula can be used to calculate the EIRP limit related RF power based on selected antennas
(antenna gain) and feeder (Coaxial Cable loss):
EIRP = Tx RF Power (dBm)+GA (dB) - FL (dB)
The following table describes this formula:
Install Guide
that is shipped along with the AP device.
Table 8:
Formula Variable Definitions
Formula ElementDescription
EIRPLimit specific for each country of deployment
Tx RF PowerRF power measured at RF connector of the unit
GAAntenna gain
FLFeeder loss
For information on antenna gain recommended by the manufacturer, see dell.com/support.
Example
The following example configures external antenna connectors for the W-IAP with the 5 GHz radio band.
This command configures the Aeroscout Real-Time Asset Location Server (RTLS) settings for Dell W-Instant and
sends the Radio-frequency identification (RFID) tag information to an Aeroscout RTLS server.
Syntax
Command/ParameterDescriptionDefault
<IP-address>
<Port>
include-unassoc-stas
no
IP address of the Aeroscout RTLS server to which the
location reports are sent.
Port number of the Aeroscout RTLS server to which the
location reports are sent..
Includes the client stations not associated to any W-IAP
when mobile unit reports are sent to the Aeroscout
RTLS server.
Removes the Aeroscout RTLS configuration.—
—
—
Disabled
Usage Guidelines
This command allows you to integrate Aeroscout RTLS server with Dell W-Instant by specifying the IP address and
port number of the Aeroscout RTLS server. When enabled, the RFID tag information for the stations associated with
a W-IAP are sent to the AeroScout RTLS. You can also send the RFID tag information for the stations that are not
associated with any W-IAP.
Example
The following example configures the Aeroscout RTLS server:
This command configures the AirGroup settings for Dell W-Instant.
Syntax
ParameterDescriptionRangeDefault
cppm enforceregistration
cppm-query-interval
<interval>
cppm-server <server-nam
e>
disable
enable
enable-guest-multicast
Enforces the discovery of the CPPM
registered devices. When enabled, only
devices registered with CPPM will be
discovered by Bonjour® devices, based on
the CPPM policy configured.
Configures a time interval at which Dell WInstant sends a query to ClearPass Policy
Manager for mapping the access privileges of
each device to the available services.
Configures the ClearPass Policy Manager
server information for AirGroup policy.
Disables the AirGroup feature.——
Enables the AirGroup feature.——
Allows the users to use the Bonjour services
enabled in a guest VLAN. When enabled, the
Bonjour devices will be visible only in the
guest VLAN and AirGroup will not discover or
enforce policies in guest VLAN.
not share the Multicast DNS (mDNS)
database information with the other
clusters.
l In the Inter Cluster model, the W-IAP
shares the mDNS database information
with the other clusters. The mDNS records
in the Virtual Controller can be shared
with the all the Virtual Controllers
specified for L3 Mobility.
Removes the specified configuration
parameter.
—Disabled
——
Usage Guidelines
Use this command to configure the AirGroup, the availability of the AirGroup services, and ClearPass Policy
Manager (CPPM) servers.
Example
The following example configures an AirGroup profile:
Restricts the users assigned to these VLANs from
accessing the AirGroup service.
Enables the AirGroup service for the profile.—
Disables AirGroup services for the profile.—
Indicates the AirGroup service ID, which is the name of
a Bonjour service offered by a Bonjour-enabled device
or application.
NOTE: The service IDs cannot be added for the preconfigured services.
Removes the AirGroup service configuration.—
Disabled
—
Usage Guidelines
Use this command to enforce AirGroup service policies and define the availability of a Bonjour services such as
Apple® AirPrint and AirPlay for an AirGroup profile. When configuring Bonjour service for an AirGroup profile, you
can also restrict specific user roles and VLANs from availing the AirGroup services.
Example
The following example configures AirGroup services:
This command integrates W-AirWave Real-Time Asset Location Server (RTLS) settings for Dell W-Instant and
sends the Radio-frequency identification (RFID) tag information to an W-AirWave RTLS server with the RTLS feed
to accurately locate the wireless clients.
Syntax
Command/ParameterDescriptionDefault
<IP-address>
<Port>
<key>
<frequency>
include-unassoc-sta
no…
Configures the IP address of the W-AirWave RTLS
server.
Configures the port for the W-AirWave RTLS server.—
Configures key for service authorization.—
Configures the frequency at which packets are sent to
the RTLS server in seconds.
When enabled, this option sends mobile unit reports to
the W-AirWave RTLS server for the client stations that
are not associated to any W-IAP (unassociated
stations).
Removes the specified configuration parameter.—
—
5
Disabled
Usage Guidelines
Use this command to send the RFID tag information to W-AirWave RTLS. Specify the IP address and port number
of the W-AirWave server, to which the location reports must be sent. You can also send reports of the unassociated
clients to the RTLS server for tracking purposes.
This command allows you to modify the configuration settings for Application Layer Gateway (ALG) protocols
enabled on a W-IAP. An application-level gateway consists of a security component that augments a firewall or NAT
used in a network.
Syntax
Command/ParameterDescriptionDefault
sccp-disable
sip-disable
ua-disable
vocera-disable
no…
Disables the Skinny Call Control Protocol (SCCP).Enabled
Disables the Session Initiation Protocol (SIP) for VOIP
and other text and multimedia sessions.
Disables the Alcatel-Lucent NOE protocol.Enabled
Disables the VOCERA protocol.Enabled
Removes the specified configuration parameter.—
Usage Guidelines
Use this command to functions such as SIP, Vocera, and Cisco Skinny protocols for ALG.
Example
The following example configures the ALG protocols:
(Instant Access Point)(config)# alg
(Instant Access Point)(ALG)# sccp-disable
(Instant Access Point)(ALG)# no sip-disable
(Instant Access Point)(ALG)# no ua-disable
(Instant Access Point)(ALG)# no vocera-disable
(Instant Access Point)(ALG)# end
(Instant Access Point)# commit apply
Enabled
Command History
VersionDescription
Dell Networking W-Series Instant Access Point 6.2.1.0-3.3
This command adds the IP address or domain name of the backup W-AirWave Management server.
Syntax
ParameterDescription
<IP-address or domain
name>
no…
Configures the IP address or domain name of the secondary W-AirWave
Management Server.
Removes the specified configuration parameter.
Usage Guidelines
Use this command to add the IP address or domain name of the backup W-AirWave Management Server. The
backup server provides connectivity when the W-AirWave primary server is down. If the W-IAP cannot send data to
the primary server, the Virtual Controller switches to the backup server automatically.
Example
The following command configures an W-AirWave backup server.