This document contains proprietary information, which is
protected by copyright. No part of this document may be
photocopied, reproduced, or translated into another
language without the prior written consent of HewlettPackard.
Publication Number
5991-2193
December 2008
Applicable Products
ProCurve Wireless Access Point 530 NA (J8986A)
ProCurve Wireless Access Point 530 WW(J8987A)
Disclaimer
HEWLETT-PACKARD COMPANY MAKES NO WARRANTY
OF ANY KIND WITH REGARD TO THIS MATERIAL,
INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
WARRANTIES OF MERCHANTABILITY AND FITNESS
FOR A PARTICULAR PURPOSE. Hewlett-Packard shall not
be liable for errors contained herein or for incidental or
consequential damages in connection with the furnishing,
performance, or use of this material.
The only warranties for HP products and services are set
forth in the express warranty statements accompanying
such products and services. Nothing herein should be
construed as constituting an additional warranty. HP shall
not be liable for technical or editorial errors or omissions
contained herein.
Hewlett-Packard assumes no responsibility for the use or
reliability of its software on equipment that is not furnished
by Hewlett-Packard.
Trademark Credits
Windows NT®, Windows®, and MS Windows® are US
registered trademarks of Microsoft Corporation.
Warranty
See the Customer Support/Warranty booklet included with
the product.
A copy of the specific warranty terms applicable to your
Hewlett-Packard products and replacement parts can be
obtained from your HP Sales and Service Office or
authorized dealer.
Open Source Software Acknowledgement
Statement
This software incorporates open source components that
are governed by the GNU General Public License (GPL),
version 2. In accordance with this license, ProCurve
Networking will make available a complete, machinereadable copy of the source code components covered by
the GNU GPL upon receipt of a written request. Send a
request to:
Hewlett-Packard Company, L.P.
AP 530 Program
GNU GPL Source Code
Attn: ProCurve Networking Support
MS: 5551
Roseville, CA 95747 USA
Open source licenses pertaining to the open source software
included with the product can be found in Appendix C in this
guide.
■Curly brackets surrounding several sets of square brackets
({ [ ] | [ ] ..[ ] }) indicate that at least one choice is required from the group
of optional elements.
■Boldface indicates commands and option names, and also the exact words
that the user types. For example:
“Use the copy tftp command to download the key from a TFTP server.”
■Italics indicate arguments for which you must supply a variable value. For
example, the command syntax <username> indicates that you must
provide a username:
Syntax: radius-local <username>
1-3
Page 24
Getting Started
Overview
Command Prompts
In the default configuration, your access point displays the following CLI
prompt:
ProCurve Access Point 530#
Screen Examples
Figures containing examples of screen text and command output look like
this:
ProCurve Access Point 530# show version
Image Software Version WA.02.00.0412
Boot Software Version WAB.01.00
ProCurve Access Point 530#
Commands typed by the user are shown in boldface. In some cases, brief
command-output sequences appear outside a numbered figure. For example:
ProCurve Access Point 530(ethernet)# ip address 192.168.1.2
255.255.255.0 192.168.1.253
ProCurve Access Point 530(ethernet)# dns primary-server
192.168.1.55
Related Publications
Installation and Getting Started Guide. Use the Installation and
Getting Started Guide shipped with your access point to prepare for and
perform the physical installation. That guide also steps you through the
process of connecting the access point to your network and assigning IP
addressing, as well as describes the LED indications for correct operation and
trouble analysis.
The Installation and Getting Started Guide and the Management and Configuration Guide can be downloaded from the ProCurve Networking Web
site. (See “Getting Documentation from the Web” on page 1-5.)
Release Notes. Release notes are posted on the ProCurve Networking Web
site and provide information on new software updates:
■New features and how to configure and use them
■Software management, including downloading software to the access
point
■Software fixes addressed in current and previous releases
1-4
Page 25
Getting Started
Overview
To view and download a copy of the latest release notes for your access point,
see “Getting Documentation from the Web” on page 1-5.
Getting Documentation from the Web
1.Go to the ProCurve Networking Web site at
http://www.procurve.com/manuals
2.Click on the name of the product for which you want documentation.
3.On the resulting web page, double-click on a document you want.
4.Save the document to your hard disk.
Sources for More Information
■The AP530 Web browser interface provides online help, as described in
“Online Help for the ProCurve Web Browser Interface” on page 4-7.
■For more information on ProCurve technology, visit the ProCurve
Networking Web site at:
http://www.procurve.com
1-5
Page 26
Getting Started
Need Just a Quick Start?
Need Just a Quick Start?
IP Addressing
If you just want to give the access point an IP address so that it can communicate on your network, HP recommends that you use the CLI to quickly
configure IP addressing. To do so, do one of the following:
1.Log in to the CLI interface using the default username and password
(“admin and admin”).
ProCurve Access Point 530 login# admin
Password: admin
ProCurve Access Point 530#
2.Enter config for global configuration at the CLI level prompt.
ProCurve Access Point 530# config
3.Enter interface ethernet for global configuration at the CLI level prompt.
ProCurve Access Point 530(config)# interface
ethernet
4.Enter ip address, followed by the address and the subnet mask at the CLI
Ethernet Configuration level prompt.
ProCurve Access Point 530(ethernet)# ip address
<address> <subnet_mask>
5.(Optional) Enter an address for the default IP gateway at the CLI Ethernet
Configuration level prompt.
ProCurve Access Point 530(ethernet)# ip default-
gateway <gateway>
6.Save the current running configuration to the startup configuration.
ProCurve Access Point 530(ethernet)# write mem
For more on using the CLI, see Chapter 9, “Using the Command Line Interface (CLI)”.
1-6
Page 27
Getting Started
Need Just a Quick Start?
To Set Up and Install the Access Point in Your Network
Important!Use the Installation and Getting Started Guide shipped with your access
point for the following:
■Instructions for physically installing the access point in your network
■Quickly assigning an IP address, subnet mask, and gateway, setting a
Manager password, and (optionally) configuring other basic features
■Interpreting LED behavior
■Notes, cautions, and warnings related to installing and using the access
point
For the latest version of the Installation and Getting Started Guide and other
documentation for your access point, visit the ProCurve Networking Web site.
(See “Getting Documentation from the Web” on page 1-5.)
Advantages of Using the ProCurve Access Point 530 Browser Interface . 2-6
2-2
Page 31
Overview
This chapter describes the following:
■Access Point management interfaces
■Advantages of using each interface type
Selecting a Management Interface
Overview
2-3
Page 32
Selecting a Management Interface
Understanding Management Interfaces
Understanding Management Interfaces
The Access Point 530 management interfaces enable you to reconfigure the
access point and to monitor its status and performance. Interface types
include:
■CLI—a command line interface offering the full set of access point
commands through the VT-100/ANSI console built into the access point.
See “Advantages of Using the CLI” on page 2-5
■Web browser interface—an access point interface offering status infor-
mation and access point configuration, see“Advantages of Using the ProCurve
Access Point 530 Browser Interface” on page 2-6
■SNMP—a network management application such as the ProCurve
Manager to manage the access point via the Simple Network Management
Protocol (SNMP) from a network management station.
This manual describes how to use the CLI and the Web browser interface, and
how to use these interfaces to configure and monitor the access point.
NoteThis manual does describe how to configure SNMP functions on the AP530,
but does not describe how to manage the access point using SNMP. For further
information, see the documentation of your SNMP management application.
2-4
Page 33
Selecting a Management Interface
Advantages of Using the CLI
Advantages of Using the CLI
ProCurve Access Point
Manager Exec Level
530#
ProCurve Access Point
Global Configuration Level
530(config)#
ProCurve Access Point
530(<interface>)#
Interface Configuration Levels
Context-specific configurations, such as (ethernet, wds1, radio1,
radio1-wlan1).
Figure 2-1.Command Prompt Examples
■Provides access to the complete set of the access point configuration
features.
■Offers out-of-band access, through the RS-232 connection, or in-band
access using Telnet or Secure Shell.
■Enables quick, detailed system configuration and management access to
system operators and administrators experienced in command prompt
interfaces.
■Provides help at each level for determining available options and vari-
ables.
CLI Usage
■For information on how to use the CLI, refer to Chapter 3, "Using the Command
Line Interface (CLI)".
■To perform specific procedures (such as configuring IP addressing), use
the Table of Contents at the front of this manual to locate the information
you need.
■For information on individual CLI commands, refer to Chapter 9, "Command
Line Reference" or use the online Help provided in the CLI interface.
2-5
Page 34
Selecting a Management Interface
Advantages of Using the ProCurve Access Point 530 Browser Interface
Advantages of Using the ProCurve
Access Point 530 Browser Interface
Figure 2-2.Example of the ProCurve Access Point 530 Browser Interface
■Easy access to the access point from anywhere on the network.
■Familiar browser interface--locations of window objects consistent
with commonly used browsers, uses mouse clicking for navigation, no
terminal setup.
■Many features have all their fields in one screen so you can view all
values at once.
■More visual cues, using colors, status bars, device icons, and other
graphical objects instead of relying solely on alphanumeric values.
■Display of acceptable ranges of values available in configuration
The Command Line Interface (CLI) is a text-based command interface for
configuring and monitoring the access point. The CLI gives you access to the
access point’s full set of commands while providing the same password
protection that is used in the Web browser interface.
3-3
Page 38
Using the Command Line Interface (CLI)
Accessing the CLI
Accessing the CLI
The CLI is accessed through the access point console. You can access the
console out-of-band by directly connecting a terminal device to the access
point, or in-band by using Telnet or a Secure Shell (SSH) client.
NOTEOut-of-Band Requirements: To emulate the access point system console on
a serial port connection, terminal emulation software needs to be installed on
your PC (such as HyperTerminal or TeraTerm, which is available at http://
www.ayera.com/teraterm).
In-Band Requirements:
through an in-band connection, Telnet or SSH software needs to be installed
on your PC (such as PUTTY, which is available at http://
www.chiark.greenend.org.uk/~sgtatham/putty/).
To emulate the access point system console
Direct Console Access
To connect a console directly to the access point, use a null-modem cable or
an HP serial cable, part number 5184-1894 (shipped with many HP ProCurve
switches)
emulator and the access point’s Console port. Configure either one to operate
with these settings:
. Connect the serial cable between a VT-100 terminal or a PC terminal
•If using a PC terminal emulator, configure it as a DEC VT-100 (ANSI)
terminal.
•Port is COM1 (COM1 is the standard port, however, your PC might
use a different COM port (e.g. COM2)
•9600 baud (default is set to 9600)
•8 data bits, 1 stop bit, parity set to None, and flow control set to None.
•For the Windows Terminal program, also disable (uncheck) the “Use
Function, Arrow, and Ctrl Keys for Windows” option.
•For the HyperTerminal program, select the “Terminal keys” option for
the “Function, arrow, and ctrl keys act as” parameter.
HintTo clear unreadable console messages, change the Baud rate.
For example, on TeraTerm: (1) Access "Control" menu and select "Reset"
terminal, (2) Change Baud rate, and if necessary, (3) Access "Setup" menu ,
select "Window" and change the "Scroll buffer" value.
3-4
Page 39
Using the Command Line Interface (CLI)
Accessing the CLI
When correctly connected to the access point, press [Enter] to initiate the
console session.
For more information on connecting to the access point’s Console port, refer
to the Installation and Getting Started Guide.
NoteThe default Static IP address is 192.168.1.10. If there is no DHCP server on the
network, the access point retains this static IP address at first-time startup.
Telnet Access
To configure the access point through a Telnet session, make sure the access
point is configured with an IP address and that it is reachable from the PC that
is running the Telnet session (for example, use a ping command to the access
point’s IP address).
Start the Telnet program on the PC using the access point’s IP address (or DNS
name).
telnet 10.11.12.195
telnet AP530
[Enter]Example of an IP address.
[Enter]Example of a DNS-type name.
Secure Shell Access
Configuring the access point through an SSH client provides a secured connection as traffic is encrypted.
To configure the access point through an SSH session, make sure the access
point is configured with an IP address and that it is reachable from the PC that
is running the SSH session (for example, use a ping command to the access
point’s IP address).
Start the SSH program on the PC using the access point’s IP address (or DNS
name).
ssh 10.11.12.195
ssh AP530
After boot up, the SSH server needs about two minutes to generate host
encryption keys. The SSH server is disabled while the keys are being generated.
For more information on the Secure Shell, see “Setting Management Access Controls”
on page 5-9.
[Enter]Example of an IP address.
[Enter]Example of a DNS-type name.
3-5
Page 40
Using the Command Line Interface (CLI)
Using the CLI
Using the CLI
The CLI commands are organized into the following levels:
1.Manager EXEC
2.Global Configuration
3.Interface Configuration
4.Radio Configuration
5.WLAN Configuration
NoteExcept for most of the user-entered parameters (e.g. SSID strings, passwords,
etc.), CLI commands are not generally case-sensitive.
For the conventions used in this manual for CLI command syntax, see “Command
Syntax Statements” on page 1-3.
The access point supports one user account: the Manager account with full
privileges. The number of commands available are delineated by the configuration levels.
When you use the CLI to make a configuration change, you must save the
configuration to retain the changes upon rebooting the access point.
Password Security
By default, the access point defaults the Manager user name to ’admin’ for CLI
access with the password defaulted to ’admin’. To secure management access
to the access point, you must set the Manager password. Without a Manager
password configured, anyone having serial port or Telnet access to the access
point can reach all CLI command modes.
CautionHP strongly recommends that you configure a Manager password. If a
Manager password is not configured, the access point is not passwordprotected, and anyone having in-band or out-of-band access to the access
point may be able to compromise access point and network security.
For additional security, it is also possible to disable CLI management access
through the serial port, ssh, or Telnet. For more information, see “Web: Configuring
Access Controls” on page 5-10.
3-6
Page 41
Using the Command Line Interface (CLI)
Logging In
When you log onto the access point CLI, you will be prompted to enter an
account user name (the default is admin).
After entry of the user name, you will be prompted for the password. The
default password is admin.
For example:
ProCurve AP-530: admin
Password Prompt
Password:
Figure 3-1.Example of CLI Log-On Screen with Password
When you successfully log onto the CLI, you will see the following command
prompt:
Using the CLI
ProCurve Access Point 530#
3-7
Page 42
Using the Command Line Interface (CLI)
Using the CLI
Command Levels
Figure 3-2.Access Sequence for Command Levels
Configuration commands on the Access Point 530 are grouped into three
levels:
Manager Exec level allows you to examine the current configuration, perform
basic system-level actions, reset the access point, and move to the configuration access levels. The prompt for the Manager Exec level contains only the
system name and the "#" delimiter. For example:
ProCurve Acess Point 530 #
Global Configuration Level
Global Configuration level gives access to commands for configuring the
access point’s software features, plus all the commands available at the lower
Manager Exec level (except for the "configure [terminal]" command).
To enter this level, enter the configure command at the Exec prompt. The
prompt for this level adds the word "(config)" before the "#" delimiter. For
example:
ProCurve Acess Point 530# configure
ProCurve Acess Point 530(config)#
3-8
Page 43
Using the Command Line Interface (CLI)
Using the CLI
Context-Specific Configuration Levels
The Context Configuration level gives access to specific groups of commands
depending on whether you are configuring the Ethernet interface, a WDS
interface, a Radio, or a WLAN. Additionally, all the commands available at the
lower Manager Exec and Global Configuration levels are available.
The prompt changes according to the configuration context.
■Ethernet Configuration: To enter the Ethernet configuration context,
enter the interface ethernet command at the Exec prompt. For example:
ProCurve Acess Point 530(config)# interface ethernet
ProCurve Acess Point 530(ethernet)#
■WDS Configuration: To enter the WDS configuration context for WDS
2, for example, enter interface wds2 at the Exec prompt:
ProCurve Acess Point 530(config)# interface wds2
ProCurve Acess Point 530(wds2)#
■Radio Configuration: To enter the Radio context for radio 1, for
example, enter radio 1 at the Global Config prompt:
ProCurve Acess Point 530(config)# radio 1
ProCurve Acess Point 530(radio1)#
■WLAN Configuration: To enter the WLAN context for WLAN 1 on radio
1, enter wlan 1 at the "(radio 1)" prompt:
ProCurve Acess Point 530(radio1)# wlan 1
ProCurve Acess Point 530(radio1-wlan1)#
Table 3-1.Command Level Hierarchy
Command LevelExample of Prompt and Permitted Operations
Manager Exec
ProCurve Acess Point 530#Perform system-level actions
(Default)
Global
ProCurve Acess Point 530(config)#Execute configuration
Configuration
Interface
Configuration
ProCurve Acess Point 530(ethernet)#
ProCurve Acess Point 530(wds1)#
ProCurve Acess Point 530(radio1)#
ProCurve Acess Point 530
(radio1-wlan1)#
such as system control,
monitoring, and diagnostic
commands.
commands.
Execute context-specific
configuration commands, such
as a particular access point
interface. This is useful for
entering a series of commands
for the same context.
3-9
Page 44
Using the Command Line Interface (CLI)
Using the CLI
Moving Between Command Levels
Table 3-2.Moving Between Command Levels
Change in LevelsExample of Prompt, Command, and Result
Manager Exec
to
Global configuration
Global Configuration
to a
Context Configuration
Move from any level to the preceding level
ProCurve Acess Point 530# config
ProCurve Acess Point 530(config)#
ProCurve Acess Point 530(config)# interface
ethernet
ProCurve Acess Point 530(ethernet)#s
ProCurve Acess Point 530(ethernet)# exit
ProCurve Acess Point 530(config)# exit
ProCurve Acess Point 530#
Move from any level to Manager ExecProCurve Acess Point 530(ethernet)# end
ProCurve Acess Point 530#
—or—
ProCurve Acess Point 530(config)# end
ProCurve Acess Point 530#
When Changes are Applied
Regardless of which interface is used (CLI, or Web browser interface), the
most recently configured version of a parameter setting overrides any earlier
settings for that parameter. For example, if you use the Web interface to
configure an IP address of “X” for the Ethernet interface and later use the CLI
to configure a different IP address of “Y”, then “Y” replaces “X” as the IP
address for the Ethernet interface.
Changes made through the Web interface are immediately applied to the
startup configuration, whereas changes made through the CLI interface are
only made to the running configuration, and must be saved using the "copy"
or "write memory" command if they are to persist following a reboot.
To save the running configuration changes to the startup configuration using
the CLI Interface:
ProCurve Acess Point 530(ethernet)# write memory
3-10
Page 45
Using the Command Line Interface (CLI)
Using the CLI
Options for Getting Help in the CLI
At any command level in the AP530 CLI you can:
■Display all commands available at that level
■Display the completion of a command you have started to type
■Display the next options available for the command you are currently
entering.
Displaying All Available Commands
To display all commands available at the current command level, type "?" or
press the
NoteAt a given command level you can display the commands that level offers, plus
any relevant commands available at preceding levels. For example, at the
Global Configuration level, you can display Global Configuration commands
plus all the commands available at the lower Manager Exec level.
[Tab] key.
For example, typing "?" at the Manager Exec level produces this listing:
ProCurve Access Point 530# ?
configure Enter the Configuration context.
copy Copy data and configuration files to/from this device.
deauth-mac Enter MAC address to de-authenticate from this device.
end Return to the Manager level context.
erase Erase stored files.
exit Return to the previous context or terminate current cons
ole/telnet session if you are in the Manager context lev
el.
log Display all the entries in the event log.
logout Terminate this session.
page Toggle paging mode.
ping Send ICMP Ping requests to a device on the network.
reload Warm reboot of the device.
show Show operation information and parameters for this devic
e.
terminal Set the dimensions of the terminal window.
write View or save the running configuration of this device.
ProCurve Access Point 530#
Figure 3-3.Example of the Manager Exec Level Command Listing
3-11
Page 46
Using the Command Line Interface (CLI)
Using the CLI
Typing ? at the Global Configuration level produces this listing:
ProCurve Access Point 530(config)# ?
ap-authentication Configure username/password this access point uses to au
thenticate to the network.
buttons Enable/disable the ability to clear the password(s) and/
or configuration(s) via the buttons on this device.
cli-confirmation Enable/disable all confirmation dialogs for all CLI inte
rfaces on this device.
console Enable/disable the serial console on this device.
copy Copy data and configuration files to/from this device.
country Set the country code for the IEEE 802.11d regulatory dom
ain support.
deauth-mac Enter MAC address to de-authenticate from this device.
dns Configure DNS parameters.
domain Set the system domain name suffix to use when a domain n
ame suffix is not obtained through DHCP.
end Return to the Manager level context.
erase Erase stored files.
exit Return to the previous context or terminate current cons
ole/telnet session if you are in the Manager context lev
el.
group-config Add to a group, remove from a group, or re-configure gro
up-config settings.
hostname Set the system hostname.
inter-station-blockingEnable/disable blocking of direct communication between
wireless stations on this device.
interface Enter the Interface Configuration level context for the
specified interface.
lldp Enable/disable the Link Layer Discovery Protocol (LLDP)
service on this device.
lockout-mac Add or remove MAC addresses to be locked out of this dev
ice.
logging Configure logging/syslog-related settings for this devic
e.
logout Terminate this session.
mac-auth-local Add/remove local MAC address authentication control list
s entries on this device.
page Toggle paging mode.
password Configure local passwords.
ping Send ICMP Ping requests to a device on the network.
radio Enter the Radio Configuration level context for a specif
ic radio.
radius-local Configure user accounts for the internal RADIUS server o
n this device.
....
Figure 3-4.Example of the Configuration-Level Command Listing (Partial Listing)
3-12
Page 47
Using the Command Line Interface (CLI)
Using the CLI
Typing ? at the Context Configuration level produces similar results,
depending on the context.
If - - MORE - - appears below the help list, then there are more commands to be
displayed.
■To show the next page of commands, press the [Space] bar.
■To list the remaining commands one-by-one, repeatedly press [Enter].
■To quit the listing, type [Ctrl] [C].
Completing the Current Command
You can use [Tab] to quickly complete the current word in a command. To do
so, type the first few consecutive characters for a command and then press
[Tab] (with no spaces allowed). If you have typed enough of the word for the
CLI to distinguish it from other options, the CLI completes the current word,
otherwise it displays the available completions.
For example, at the Global Configuration level, if you press
[Tab] immediately
after typing "s", the CLI displays the command that begins with "s". For
example:
ProCurve Acess Point 530(config)# s[Tab]
show
snmp-server
snmpv3
sntp
ssh
stp
Use Shorthand Entries. The CLI accepts abbreviated commands and
options as long as they contain enough characters to be distinguished from
any other currently available commands or options. For example, both of the
following examples will switch to Global Configuration level:
ProCurve Acess Point 530# configure
ProCurve Acess Point 530(config)#
ProCurve Acess Point 530# config
ProCurve Acess Point 530(config)#
3-13
Page 48
Using the Command Line Interface (CLI)
Using the CLI
Displaying Available Command Options
You can display a reminder of the options available for the current command
by entering "?" or the [Tab] key in place of the next option. For example, to see
the command options for configuring SNMP:
ProCurve Access Point 530(config)# snmp-server ?
community Add/remove an SNMP community.
contact Specify a text string that identifies the main contact f
or this device.
host Add/remove an SNMP trap destination host/community.
location Specify a text string that identifies the location of th
is device.
port Specify the port to use for the SNMP server on this devi
ce.
trap Enable/disable specific SNMP traps.
enable Enable SNMPv1/v2c.
ProCurve Access Point 530(config)#
Figure 3-5.Example of How To List the Options for a Specific Command
3-14
Page 49
Using the Command Line Interface (CLI)
CLI Control and Editing
CLI Control and Editing
Keyst roke sFunction
[Ctrl] [A] Jumps to the first character of the command line.
[Ctrl] [B] or [<] Moves the cursor back (to the left) one character.
[Ctrl] [C] Terminates a task if one is running and displays the command line.
[Ctrl] [D] Deletes the character at the cursor.
[Ctrl] [E] Jumps to the end of the current command line (the character position after the
last character in the CLI command input buffer).
[Ctrl][F] or [>]Moves the cursor forward (to the right) one character if the cursor is not at the
end of the current command line.
[Ctrl] [H] Deletes the first character to the left of the command line.
[Ctrl] [K] Deletes from the cursor to the end of the command line.
[Ctrl] [L] or [Ctrl] [R] Repeats current command line on a new line.
[Ctrl] [N] or [v]Enters the next command line in the history buffer.
[Ctrl] [P] or [^]Enters the previous command line in the history buffer.
[Ctrl] [R] Repeats current command line on a new line.
[Ctrl] [U] or [Ctrl] [X] Deletes from the cursor to the beginning of the command line.
[Ctrl] [W] Deletes the last word typed.
[Ctrl] [Y] Recalls the most recent entry in the delete buffer.
[Ctrl] [Z] This character closes the current session, returning the operator to the previous
context (config).
[Esc] [B] Moves the cursor backward (to the left) one word.
[Esc] [D] Deletes from the cursor to the end of the word.
[Esc] [F] Moves the cursor forward (to the right) one word.
[Ctrl] [H], [Delete], or
[Backspace]
Tab or "?"Completes the current word of a command.
Deletes the first character to the left of the command line.
The Access Point 530 Web browser interface lets you easily access the access
point from a browser-based PC on your network.
This chapter covers the following:
■Starting a Web browser interface session
■Description of the Web browser interface
■An overview of the Web browser interface screens
■Tasks for your first Web browser interface session
4-3
Page 54
Using the ProCurve Web Browser Interface
Starting a Web Browser Interface Session with the Access Point
Starting a Web Browser Interface
Session with the Access Point
You can start a Web browser session using a standalone Web browser on a
network connection from a PC in the following ways:
•Directly connected to your network
•Connected through remote access to your network
This procedure assumes that you have a supported Web browser installed on
your PC or workstation, and that an IP address has been configured on the
access point. If you are using a Domain Name Server (DNS), your device may
have a name associated with it (for example, AP530) that you can type in the
Location or Address field instead of the IP address. Using DNS names typically
improves browser performance. See your network administrator for any name
associated with the access point. (For more information on assigning an IP
address, refer to “Configuring IP Parameters” on page 4-29.
Web browser support recommended to manage the access point include:
•Microsoft Internet Explorer version 5.5 or 6.x (with up-to-date patch
level for either major version) on Microsoft Windows XP or Microsoft
Windows 2000
•Netscape Mozilla 1.7.x on Redhat Linux version 2.4
•Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/
20070309 Firefox/2.0.0.3
4-4
The administration Web browser must have JavaScript enabled to support the
interactive features of the administration interface. It must also support HTTP
uploads to use the software upgrade feature.
Page 55
Using the ProCurve Web Browser Interface
Starting a Web Browser Interface Session with the Access Point
NoteAccess point management can be limited to access from the Ethernet inter-
face. For more on this feature, see “Setting Up Filter Control” on page 5-55.
Type the IP address (or DNS name) of the access point in the browser Location
or Address field and press
[Enter]. (It is not necessary to include http://.)
10.11.12.195
AP530
[Enter]Example of an IP address.
[Enter]Example of a DNS-type name.
Alternatively, the access point also supports a secure Web (HTTPS) browser
connection. In this case, type https:// followed by the IP address (or DNS name)
in the browser Location or Address field and press
https://10.11.12.195
https://AP530
[Enter]Example of an IP address.
[Enter]Example of a DNS-type name.
[Enter].
NoteInternet Explorer on Windows XP: To ensure proper screen refresh, be
sure that the browser options are configured as follows: Under the menu
“Tools / Internet Options / Temporary Internet Files / Settings,” the setting for
item “Check for newer versions of stored pages” should be set to “Automatically”. In Internet Explorer 7, this setting is found under the menu “Tools /
Internet Options / General / Browsing history / Settings”.
4-5
Page 56
Using the ProCurve Web Browser Interface
Description of the Web Interface
Description of the Web Interface
Subjects covered in this section include:
■The Home Page
■The Support Page
■Online Help
The Home Page
The home page is the entry point for the Web browser interface. The following
figure identifies the various parts of the screen.
Active Screen
Menu Sashes
Figure 4-1.The Home Page
4-6
Page 57
Using the ProCurve Web Browser Interface
Description of the Web Interface
Support Window
Clicking on the Support option in the upper-right corner of any of the Web
browser interface screens displays a pop-up window displaying links to online
support options.
The support page provides key information regarding your access point,
including links to white papers, software updates, and more.
Online Help for the ProCurve Web Browser Interface
Online Help is available for the Web browser interface. The help is context
sensitive and maps topics to the Web page you have accessed.
Figure 4-2.The Help and Support Options
The Help Option
The Support Option
4-7
Page 58
Using the ProCurve Web Browser Interface
Description of the Web Interface
Using the Help in the Browser Interface
Clicking on the Help option in the upper-right corner of any of the Web browser
interface screens displays a pop-up window displaying details about the page
you are viewing.
Click Help and open context-sensitive help page.
Figure 4-3.Viewing Online Help
At the top left of the Online Help page is a Topic and Menu bar display for easy
access to further information. Options include, Contents, Index, and Search,
as shown in Figure 4-4.
Figure 4-4.Example of the Online Help Panel
4-8
Page 59
Using the ProCurve Web Browser Interface
Web Interface Screens
Web Interface Screens
The four menu sashes at the left side of the Web interface contain the four
main screen groups:
■Device Information
■Network Setup
■Management
■Special Features.
Clicking on the group sash reveals a list of the screens in the group and
displays the summary screen for the group .
Clicking on the name of a screen below the group sash displays the corresponding screen.
Figure 4-5.The Main Web Interface Screen
4-9
Page 60
Using the ProCurve Web Browser Interface
Web Interface Screens
Device Information Group
The Device Information sash is the first logical group available on the Webinterface menu. This sash provides access to the following screens:
•Device Information (Access Point 530 Home Page)
•Wireless Stations
•AP/LAN Statistics
•Wireless Statistics
•Event log
These screens are primarily informational screens and are described in the
following pages.
Table 4-1.Index of Device Information Group Screens
Screen NamePage
Device Information summary screen4-11
Wireless Stations screen4-12
AP/LAN Statistics screen4-14
Wireless Statistics screen4-15
Event Log screen / Log tab4-17
Event Log screen / Settings tab5-45
4-10
Page 61
Using the ProCurve Web Browser Interface
Web Interface Screens
Device Information Summary
The Device Information summary screen is primarily informational, but also
serves as the configuration screen for basic system information (as described
in “Web: Setting the System Name, Location, and Contact” on page 5-15).
Figure 4-6.The Device Information Summary Screen
The Device Information screen displays the basic system configuration
settings:
■System Name: The name assigned to this access point. Modifiable field.
■Location: The access point’s assigned location. Modifiable field. Max
length of 255 characters.
■Contact: Administrator responsible for the system. Modifiable field. Max
length of 255 characters.
■IP Address: IP address of the management interface for this device.
■MAC Address: The physical layer address for the Ethernet port interface.
■Software Version: The version number for the runtime software.
■Serial Number: The serial number of the access point.
■Country Code: The access point’s current Country Code setting.
■System Up Time: Length of time the access point has been up (days,
hours, minutes, seconds).
■[Update]: Updates the access point with the modifiable parameters.
4-11
Page 62
Using the ProCurve Web Browser Interface
Web Interface Screens
Wireless Stations Screen
Accessed through the Wireless Stations option on the Device Information
sash, the Wireless Stations screen displays radio and network station status
details.
Figure 4-7.The Wireless Stations Screen
The Wireless Stations screen displays client stations associated with a particular access point. The associated stations are displayed along with information about packet traffic transmitted and received for each station.
■Radio: Indicates the access point radio.
■SSID: Indicates the Service Set Identifier (SSID) of the WLAN to which
the access point is connected.
■Station: The MAC address of the wireless client.
■Auth.: Shows if the station has been authenticated. The two basic
methods of authentication supported for 802.11 wireless networks are
“open system” and “shared key.” Open-system authentication accepts any
client attempting to connect to the access point without verifying its
identity. The shared-key approach uses Wired Equivalent Privacy (WEP)
to verify client identity by distributing a shared key to stations before
attempting authentication.
■Assoc.: Shows if the station has been successfully associated with the
access point. Once authentication is completed, stations can associate
with the current access point, or reassociate with a new access point.
The association procedure allows the wireless system to track the location of each mobile client, and ensures that frames destined for each client
are forwarded to the appropriate access point.
■Fwd: If 802.1X is used, this parameter indicates the station passed 802.1X
authentication and traffic can be forwarded to the access point. It also
indicates whether a wireless station has the correct WPA pre-shared key
4-12
Page 63
Using the ProCurve Web Browser Interface
Web Interface Screens
when the access point is using "wpa-psk" security on the WLAN. If the
WLAN is set to “static-wep” or “no-security”, this parameter displays “n/
a” as it does not apply.
■Received Packets: Indicates total packets received by this access point.
■Received Bytes: Indicates total bytes received by this access point.
■Sent Packets: Indicates total packets sent by this access point.
■Sent Bytes: Indicates total bytes sent by this access point.
■[Refresh]: Refreshes the Wireless station results.
4-13
Page 64
Using the ProCurve Web Browser Interface
Web Interface Screens
AP/LAN Statistics Screen
Accessed through the AP/LAN Statistics option on the Device Information
sash, the AP/LAN Statistics screen displays transmit/receive details.
Figure 4-8.The AP/LAN Statistics Screen
The AP/LAN Statistics screen displays the following information:
■IP Address: IP address of the management interface for this device.
■MAC Address: The physical layer address for the Ethernet port interface.
■Spanning Tree State: Indicates the spanning tree state if used. Possible
states include: disabled, listening, learning, forwarding, or blocking.
■Tran sm it Tot al P ac ke ts : Indicates total packets transmitted by this
access point.
■Receive Total Packets: Indicates total packets received by this access
point.
■Tran sm it Tot al B y t es : Indicates total bytes sent by this access point.
■Receive Total Bytes: Indicates total bytes received by this access point.
■Transmit Errors: Indicates the number of transmission errors.
■Receive Errors: Indicates the number of packet errors received.
■[Refresh]: Refreshes the AP/LAN statistics results.
4-14
Page 65
Using the ProCurve Web Browser Interface
Web Interface Screens
Wireless Statistics Screen
Accessed through the Wireless Statistics option on the Device Information
sash, the Wireless Statistics screen displays transmit/receive details.
Figure 4-9.The Wireless Statistics Screen
The Wireless Statistics screen displays dual radio information:
■Radio One / Two SSID: Indicates the Service Set Identifier (SSID) for
Radio 1 or Radio 2 .
■MAC Address: Indicates the physical layer address for the Ethernet port
interface.
■WDS LINK: Indicates the configured WDS link.
■Local MAC: Indicates the remote MAC address of the WDS link.
■Remote MAC: Indicates the remote MAC address of the WDS link.
■Spanning Tree Status: Indicates the spanning tree status if used.
■Tran sm it Tot al P ac ke ts : Indicates total packets transmitted over the
radio or WDS link.
4-15
Page 66
Using the ProCurve Web Browser Interface
Web Interface Screens
■Receive Total Packets: Indicates total packets received over the radio
or WDS link.
■Tran sm it Tot al B yt es : Indicates total bytes sent over the radio or WDS
link.
■Receive Total Bytes: Indicates total bytes received over the radio or
WDS link.
■Transmit Errors: Indicates total errors related to sending data.
■Receive Errors: Indicates total errors related to receiving data
■[Refresh]: Refreshes the Wireless Statistics results.
4-16
Page 67
Using the ProCurve Web Browser Interface
Web Interface Screens
Event Log Screen
Accessed through the Wireless Statistics option on the Device Information
sash, the Wireless Statistics screen displays transmit/receive details.
Figure 4-10. The Event Log Screen
The Event Log tab displays the following information:
■Time: Indicates the time the log message was generated.
■Ty pe: Indicates the logging (type) level associated with this message.
■Service: Indicates the service (type) associated with this message.
■Description: Indicates the content of the log message.
■[Refresh]: Refreshes the Event log results.
NoteThe Web user interface has a limited amount of memory for containing and
displaying the event log. When the size of the event log has grown larger than
the amount of memory allocated to the event log, all messages are purged from
the display. To view a complete list of events, use the CLI command show log.
4-17
Page 68
Using the ProCurve Web Browser Interface
Web Interface Screens
Network Setup Group
The Network Setup sash is the second logical group available on the Webinterface menu. Once accessed, it defaults to the Network Setup screen. This
group provides access to the following screens:
•Network Setup
•Ethernet
•Radio
•WLANs
The screens belonging to the Network Setup group are described in their
respective configuration sections.
Table 4-2.Index of Network Setup Group Screens
Screen NamePage
Network Setup summary screen 4-19
Ethernet screen5-19
Radio screen6-9, 6-12
Advanced Settings sub-screen6-14
WLANs screen6-37
Security sub-screen / Security tab7-18
Security sub-screen / RADIUS Servers tab7-33
Security sub-screen / Accounting Servers tab5-52
Security sub-screen / MAC Authentication tab7-46
Security sub-screen / Web Authentication tab / Login tab7-68
4-18
Page 69
Using the ProCurve Web Browser Interface
Web Interface Screens
Network Setup Summary
Accessed through the Network Setup sash, the Network Setup screen displays
the Ethernet and radio features within the network setup group.
Figure 4-11. The Network Setup Summary Screen
The Network Setup screen summarizes:
■Ethernet: details basic Ethernet parameters.
•Connection Type: Indicates the type of connection.
•MAC Address: The physical layer address for the Ethernet port
interface.
•IP Address: IP address of this device.
•Subnet: Subnet mask of this device.
•Gateway: Gateway address of this device.
■Radio One / Two: details basic Radio One & Two parameters.
•Status: Indicates if the radio is up or down.
•MAC Address: The physical layer address.
•Mode: Displays the radio mode for Radio One (IEEE 802.11b or IEEE
802.11g).
•Channel: Displays the channel on which the access point is currently
broadcasting.
•Max Tx Power: Displays the maximum radio power level for the
selected mode in dBm.
•WLAN: Indicates the WLAN identifier. There can be up to 16 WLANs.
•SSID: Indicates the Service Set Identifier (SSID) for the WLAN.
•VLAN ID: Indicates the VLAN the WLAN is operating on.
•Security: Indicates the configured security for the WLAN.
4-19
Page 70
Using the ProCurve Web Browser Interface
Web Interface Screens
Management Group
The Management sash is the third logical group available on the Web interface
menu. Once accessed, it defaults to the Management screen. This group
provides access to the following screens:
•Local MAC Authentication
•Web Authentication
•SNMP
•Group Configuration
•AP Authentication
•AP Access
•System Maintenance
The screens belonging to the Management group are described in their respective configuration sections.
Table 4-3.Index of Management Group Screens
Screen NamePage
Management summary screen 4-21
Local MAC Authentication screen7-45
Web Authentication screen / Address Pool tab7-64
Web Authentication screen / Guest Account tab7-66
SNMP screen / Settings tab5-26
SNMP screen / Traps tab5-32
SNMP screen / Trap Hosts tab5-32
SNMP screen / SNMPv3 Users tab5-40
Group Configuration screen5-65
AP Authentication screen7-54
AP Access screen / Access tab5-10
AP Access screen / Password tab5-6
System Maintenance screen / Reboot tabA-14
System Maintenance screen / Software tabA-5
System Maintenance screen / Configuration Files tabA-8
4-20
Page 71
Using the ProCurve Web Browser Interface
Web Interface Screens
Management Summary
Accessed through the Management sash, the Management screen displays a
summary of access point management settings.
Figure 4-12. The Management Summary Screen
The Management screen summarizes:
■Software Version: Displays the version of the running software.
■SNMP: Indicates if SNMP is enabled or disabled.
■SNMPv3: Indicates if SNMPv3 is enabled or disabled.
■SNMPv3 Users: Indicates the number of SNMPv3 users registered.
■CLI Access: Indicates the status (enable or disable) of CLI access inter-
faces: through the serial port, using Telnet ,or using SSH.
■Button Access: Indicates the status (enable or disable) for password,
factory, custom, and system resetting using the buttons on the back of the
access point.
■Web Access: Indicates the status (enable or disable) of support for Web
(HTTP) browser access and Secure Socket Layer (SSL) access, which
provides a secure encrypted connection to the access point’s Web interface.
4-21
Page 72
Using the ProCurve Web Browser Interface
Web Interface Screens
Special Features Group
The Special Features sash is the fourth logical group available on the Web
interface menu. Once accessed, it defaults to the Special Features screen. This
group provides access to the following screens:
•QoS
•WDS
•Local RADIUS
•MAC Lockout
•AP Detection
•Filters
•Time
The screens belonging to the Special Features group are described in their
respective configuration sections.
Screen NamePage
Special Features summary screen *4-23
QoS screen8-5
WDS screen8-19
Local RADIUS screen7-36
User Database screen7-39
MAC Lockout screen7-50
AP Detection screen / Settings tab8-30
AP Detection screen / AP List tab8-30
Filters screen5-55
Time screen5-48
4-22
Page 73
Using the ProCurve Web Browser Interface
Web Interface Screens
Special Features Summary
Accessed through the Special Features sash, the Special Features screen
displays a summary of special feature statistics.
Figure 4-13. The Special Features Summary Screen
The Special Features screen summarizes:
■QoS: Indicates if Quality of Service packet prioritization (also referred to
as WiFi Multimedia or WMM) is enabled or disabled.
■AP Detection: Indicates if AP Detection is enabled or disabled.
■SNTP Server: Indicates if the SNTP Server is enabled or disabled.
■Group Configuration: Indicates whether Group Configuration is
enabled or disabled for the access point.
■Local RADIUS: The number of accounts registered on the local RADIUS
server.
■WDS Link/Address: Indicates the WDS interface number and the config-
ured remote MAC address for each respective enabled WDS link.
4-23
Page 74
Using the ProCurve Web Browser Interface
Tasks for Your First ProCurve Web Browser Interface Session
Tasks for Your First ProCurve Web
Browser Interface Session
The ProCurve AP530 Installation and Getting Started Guide includes
instructions for a minimal initial configuration using the CLI on a console
attached to the access point. This configuration included:
■Setting the administrator password (which secures the access point
management interface from unauthorized access)
■Setting the IP address and subnet mask of the access point to be consistent
with your local network settings (which allows inband access to the Web
browser interface from the wired network)
■Setting the access point country code (which, if needed, can only be done
using the CLI)
■Optionally enabling one of the radios (which allows inband access to the
Web browser interface from the wireless network)
After performing the initial out-of-band configuration, it is usually more
convenient to continue the configuration process inband, using the Web
browser interface.
Some of important tasks that you may wish to be familiar with are described
below:
■Changing the management password
■Settings SNMP community names
■Setting the radio mode and channel
■Change TCP/IP settings
■Setting the WLAN SSID and security options
■Rebooting and resetting the access point
Changing the Management Password
You normally want to change the password to enhance access security for the
management interface on your access point. The password allows read and
write access to the Web browser interface.
4-24
Page 75
Using the ProCurve Web Browser Interface
Tasks for Your First ProCurve Web Browser Interface Session
NoteIf you want security beyond that achieved with user names and passwords,
you can disable access to the either the or the CLI and limit management
access to, for example, only the Web browser interface, only the CLI via the
console port, Telnet, or SSH. For more information, see “Web: Configuring Access
Controls” on page 5-10
Figure 4-14. Setting the Management Password
To Set the Management Password:
1.Click Management > AP Access and select the Password tab.
2.In the New Password field, enter a new password.
3.In the Confirm Password field, re-enter the new password.
4.Click [Update] to activate the new password.
Notes■The password is case sensitive and must be at least 1 character and at
most 32 characters long. However, only the first 8 characters of the
password are used; character number 9 and above are ignored at log in.
■The password you assign in the Web browser interface will overwrite the
previous settings assigned in either the Web browser interface or the
access point console. That is, the most recently assigned user password
is immediately effective for the access point, regardless of which interface
was used to assign these parameters.
4-25
Page 76
Using the ProCurve Web Browser Interface
Tasks for Your First ProCurve Web Browser Interface Session
The Manager user name and password control access to both the CLI and the
Web browser management interfaces for the access point. You are prompted
to supply the user name and password every time you try to access the access
point through either of these interfaces.
If You Lose the Password
If you lose the password, you can reset it by pressing the Clear button on the
back of the access point for more than one second. This action resets the
password to the factory default settings for all of the access point’s interfaces.
For details on resetting configuration files, see “File Uploads, Downloads, and Resets”
on page A-1.
Rebooting or Resetting the Access Point
You can also use the Web interface to:
•Reset the configuration file back to the factory default:
Click Management > System Maintenance and select the Configuration Files
tab. Then click the Reset to Factory Default [Reset] button in the
Reset Configuration area.
•Reboot the AP:
Click Management > System Maintenance and select the Reboot tab. Then
click the Reboot the Access Point [Reboot] button.
NOTEFor details on manual reset of the access point, reference the Installation and
Configuration Guide and see “File Uploads, Downloads, and Resets” on page A-1.
Setting SNMP Community Names
You can manage the access point from a network management station running
a Simple Network Management Protocol (SNMP) management application
such as ProCurve Manager.
The access point SNMP agent supports SNMP versions 1 and 2c. Management
access from SNMP v1 or v2c stations is controlled by community names. To
communicate with the access point, an SNMP v1 or v2c management station
must first submit a valid community name for authentication. The default
community names are “public” for read-only access and “private” for read/
write access. If you intend to support SNMP v1 or v2c managers, it is recommended that you change the default community names to prevent unauthorized access. For SNMP parameter details, see “Web: Setting Basic SNMP Parameters”
on page 5-26.
4-26
Page 77
Using the ProCurve Web Browser Interface
Tasks for Your First ProCurve Web Browser Interface Session
.
Figure 4-15. Setting SNMP Community Names
To Change A Default SNMP Community Name:
1.Click Management > SNMP and select the Settings tab.
2.To activate the SNMP feature on the access point, click SNMPv1/v2c Enabled.
3.To establish a public read-only SNMP community, type a name text string
to replace the default community name (public) in the Community Name
(RO) field.
4.To establish a private read-write SNMP community, type a name text string
to replace the default community name (private) in the Community Name
(R/W) field.
5.To activate SNMPv3 functions on the access point, click SNMPv3 Enabled.
6.Click [Update] to activate the new SNMP community name.
4-27
Page 78
Using the ProCurve Web Browser Interface
Tasks for Your First ProCurve Web Browser Interface Session
Setting the Radio Mode and Channel
The access point’s radio channel settings are limited by local regulations,
which determine the number of channels that are available. You can manually
set the access point’s radio channel or allow it to automatically select an
unoccupied channel.
Notes■Radio 1 operates in 802.11b/g mode, but Radio 2 operates in either 802.11b/
g or 802.11a modes. If radio 2 is to be configured in 802.11b or 802.11g
mode, it must be connected to an external antenna to ensure adequate
separation between the two radios operating in the same frequency. See
“Radio Configuration Summary Table” on page 6-6.
■If using the worldwide product, before configuring radio settings on the
access point, you must first use the CLI to set the Country Code so that
the radio channels used conform to your local regulations. It is your
responsibility to select a correct country setting, otherwise radio operation may fail to comply with legal requirements for use of the access point
in your country. See “Setting the Country Code” on page 6-4.
Adjacent access points operating in the same band should be configured to
use non-overlapping channels. See “Radio Configuration Summary Table” on page 6-6 and
“Web: Configuring Basic Radio Settings” on page 6-12.
.
Figure 4-16. Setting Radio Mode and Channel
4-28
Page 79
Using the ProCurve Web Browser Interface
Tasks for Your First ProCurve Web Browser Interface Session
To Set Radio Mode and Channel:
1.Select Radio.
2.Using the Radio drop-down, select the radio (1 or 2) you want to configure.
3.To enable the radio, click the Status On button.
4.Select the Mode (default is IEEE 802.11g).
5.Select the Channel
6.Click
[Update] to save the settings.
(auto is the default).
NoteIf you are configuring the worldwide product, the Radio screen is not available
for configuration until the Country Code is set using the CLI.
Configuring TCP/IP Settings
You can use the Web browser interface to manage the access point only if it
already has an IP address that is reachable through your network. You can set
an initial IP address for the access point by using the CLI interface.
After you have network access to the access point, you can then use the Web
browser interface to modify the initial IP configuration. For IP parameter
details, see “Web: Configuring IP Settings Statically or via DHCP” on page 5-19.
Figure 4-17. Configuring IP Parameters
4-29
Page 80
Using the ProCurve Web Browser Interface
Tasks for Your First ProCurve Web Browser Interface Session
To Set IP Parameters i:
1.Select Ethernet.
2.To set a dynamic connection, select DHCP in the Connection Type drop-
down.
3.To set a manual connection, select Static IP in the Connection Type drop-
down.
4.If you chose Static IP, enter the IP address and the subnet mask in the Static
IP Address and Subnet Mask fields. The defaults automatically populate.
5.If a management station exists on another network segment, in the Default
Gateway field enter the IP address of a gateway that can route traffic between
these segments.
6.Enter the IP address for the primary and secondary DNS servers to be used
for host-name to IP address resolution.
7.Optionally enter the domain suffix for hostname/domain-name lookups
in the Domain field.
8.Click
[Update] to save these IP settings.
NoteIf you change the IP address using the Web interface, you must log in again
using the new address.
4-30
Page 81
Using the ProCurve Web Browser Interface
Tasks for Your First ProCurve Web Browser Interface Session
Setting WLAN SSID and Security Settings
Wireless stations can read the SSIDs from the access point’s beacon frame. If
the “closed system” option is selected when configuring the access point, the
SSID is not broadcast in the beacon frame. For more secure data transmissions, the access point provides client authentication and data encryption
based on shared keys that are distributed to all stations.
Wired Equivalent Privacy (WEP) is implemented to provide a basic level of
security, preventing unauthorized access to the network and encrypting data
transmitted between wireless stations and the access point.
The access point allows configuration of up to 16 SSIDs . The Web interface
provides easy screens to configure SSID parameters, including: enabling, SSID
names, closed system, VLAN IDs, and security settings. For Security parameter details, see “Web: Setting Security Options” on page 7-18.
NOTEConfiguring WLAN security establishes WDS Link Security. For a summary of
the configuration relationship, see “Web: Setting Security Options” on page 7-18.
4-31
Page 82
Using the ProCurve Web Browser Interface
Tasks for Your First ProCurve Web Browser Interface Session
.
Figure 4-18. The WLANs Screen
4-32
Page 83
Tasks for Your First ProCurve Web Browser Interface Session
Figure 4-19. Configuring WLAN Security
Using the ProCurve Web Browser Interface
To Configure WEP Security:
1.Select WLANs.
2.Check the Radio 1 box, and the SSID name and VLAN ID fields populate
with defaults.
3.Enter a unique SSID name in the SSID name field and check the Closed System
box to prevent broadcasting of the SSID.
4.Click
5.Click the [
[Update] to save these IP settings.
Edit] button to open the Security pop-up window (see Figure 4-
19).
6.Select Static WEP in the Security Mode drop-down.
7.Check Shared for the Authentication option.
8.Select 1 in the Transfer Key Index drop-down to be used for the SSID
interface.
9.Select the key length to be used by all stations either 64 or 128 (default)
bits.
10. Select the Key Type, Hex (default) or ASCII.
11. Enter one WEP key conforming to the length and type already selected. You
can enter up to 4 WEP keys at a time.
4-33
Page 84
Using the ProCurve Web Browser Interface
Tasks for Your First ProCurve Web Browser Interface Session
12. Click [Update] to save these Security settings.
WEP is the security protocol initially specified in the IEEE 802.11 standard
for wireless communications. While WEP provides a margin of security for
environments with light network traffic, it is not sufficient for enterprise use
where highly-sensitive data is transmitted.
For more robust wireless security, you should consider implementing other
features supported by the access point. Wi-Fi Protected Access (WPA) and
IEEE 802.1X-2004 (Port-based network access control using the physical
access characteristics of IEEE 802® Local Area Networks (LAN) infrastructures to provide a means of authenticating and authorizing devices attached
to a LAN port that has point-to-point connection characteristics) provide
improved data encryption and user authentication. See “Wireless Security Configu-
■Configure IP, SNMP, SNTP, RADIUS Accounting, and VLAN parameters
■Set up filter control between wireless stations, between wireless stations
and the management interface, or for specified protocol types
5-4
Page 89
General System Configuration
AP Network Configuration Checklist
AP Network Configuration Checklist
In setting up your Access Point for network installation, this manual covers
many of the tasks that should be considered for proper security and management. Each of these tasks are detailed in their respective sections, however,
this summary is provided as an aid for establishing your network.
Restricting access between wireless client devices associated with the same access point. page 5-57
5-5
Page 90
General System Configuration
Modifying Management Passwords
Modifying Management Passwords
Management access to the access point’s CLI and Web interfaces is controlled
through an administrator password.
Additional in-band access security can also be gained by setting management
access controls (see “Setting Management Access Controls” on page 5-9) and using
traffic filters (see “Setting Up Filter Control” on page 5-55).
CautionHP strongly recommends that you configure a new Manager password and
not use the default. If a Manager password is not configured, then the access
point is not password-protected, and anyone having in-band or out-of-band
access to the access point may be able to compromise access point and
network security.
Pressing the Clear button on the back of the access point for more than two
seconds removes password protection.
Web: Setting the Management Password
The Password screen enables the access point’s password to be set.
The Web interface enables you to modify these parameters:
■New Password: New password to gain access to the administration of
the access point.
Note: The password is case sensitive and must be at least 1 character and
at most 32 characters long. However, only the first 8 characters of the
password are used; character number 9 and above are ignored at log in.
■Confirm New Password: Re-entered new password to gain access to the
administration of the access point.
■[Update]: Updates the new password.
5-6
Page 91
Figure 5-1.Creating a Password
To Create a Password:
General System Configuration
Modifying Management Passwords
1.Click Management > AP Access and select the Password tab.
2.In the Current Password field, enter the current password.
3.In the New Password field, enter a new password.
Note: The password is case sensitive and must be at least 1 character and
at most 32 characters long. However, only the first 8 characters of the
password are used; character number 9 and above are ignored at log in.
4.In the Confirm Password field, re-enter the new password.
5.Select [Update].
NoteThe password you assign in the Web browser interface will overwrite the
previous settings assigned in either the Web browser interface or the access
point console. That is, the most recently assigned user password is immediately effective for the access point, regardless of which interface was used to
assign these parameters.
5-7
Page 92
General System Configuration
Modifying Management Passwords
CLI: Setting the Management Password
CLI Commands Used in This Section
Command SyntaxCLI Reference Page
password manager <password> 9-21
This example shows how to create a manager password.
CautionIf you modify the password through CLI, you also modify the Web password.
NoteThe password is case sensitive and must be at least 1 character and at most
32 characters long. However, only the first 8 characters of the password are
used; character number 9 and above are ignored at log in.
ProCurve Access Point 530# configure
ProCurve Access Point 530(config)# password manager 9gY2dV7G
ProCurve Access Point 530(config)#
5-8
Page 93
General System Configuration
Setting Management Access Controls
Setting Management Access Controls
To provide more security for the access point, management interfaces that are
not required can be disabled. This includes the Web, Telnet, and Secure Shell
(SSH), as well as the serial console port and Reset button.
NoteThe access point’s serial port and Reset button cannot be disabled at the same
time. When the Reset button is disabled, it is not possible to disable the serial
port.
HTTP and HTTPS. The access point supports both a Web (HTTP) and
secure Web (HTTPS) browser interface. The secure hypertext transfer
protocol (HTTPS) over the Secure Socket Layer (SSL) provides a secure
encrypted connection to the access point’s Web interface. Both the HTTP and
HTTPS service can be enabled independently.
NoteThe HTTP and HTTPs services do not allow modification of the configured
port numbers.
Secure Shell (SSH). Telnet is a remote management tool that can be used
to configure the access point from anywhere in the network. However, Telnet
is not secure from hostile attacks. SSH can act as a secure replacement for
Telnet. The SSH protocol uses generated public keys to encrypt all data
transfers passing between the access point and SSH-enabled management
station stations and ensures that data traveling over the network arrives
unaltered. stations can then securely use the local user name and password
for access authentication.
Note that SSH client software needs to be installed on the management station
to access the access point for management via the SSH protocol.
NoteThe access point supports only SSH version 2.0.
After boot up, the SSH server needs about one minute to generate host
encryption keys. The SSH server is disabled while the keys are being generated.
5-9
Page 94
General System Configuration
Setting Management Access Controls
Web: Configuring Access Controls
The AP Access screen configures access to management interfaces and
button.
The Web interface enables you to modify these parameters:
CLI Access
■Serial Interface: Enables or disables management access through the
access point’s serial console port. (The default is Enabled.)
NOTEYou can not disable the serial interface, if you already have disabled the
Factory Reset option.
■Telnet Interface: Enables or disables management access through
Telnet. (The default is Enabled.)
■SSH Interface: Enables or disables management access through a
Secure Shell version 2.0 client. (The default is Enabled.)
Web Access
■HTTP Interface: Enables or disables management access through and
HTTP interface . (The default is Enabled.)
■SSL Interface: Enables or disables management access through an SSL
interface. (The default is Enabled.)
Button Access - For managing button access see, “Disabling the Access Point Push
Buttons” on page A-18.
■Factory Reset: Enables or disables button control access (back panel of
the access point) to a factory default file reset. (The default is Enabled.)
■Custom Reset: Enables or disables button control access (back panel of
the access point) to a custom config file reset. (The default is Enabled.)
■System Reset: Enables or disables button control access (back panel of
the access point) to a system reset. (The default is Enabled.)
5-10
Page 95
Figure 5-2.Configuring Access Controls
General System Configuration
Setting Management Access Controls
To Configure Access Control Settings:
1.Click Management > AP Access and select the Access tab.
2.As required, enable or disable the serial, Telnet, or SSH interfaces.
NoteIf using SSH for secure access to the CLI over a network connection, you may
want to disable the Telnet server.
3.As required, enable or disable the HTTP or SSL interfaces.
4.As required, enable or disable the manual push button options on the
access point.
NoteThe access point does not allow you to disable Factory Reset and the Serial
Interface at the same time.
5.Click [Update].
5-11
Page 96
General System Configuration
Setting Management Access Controls
CLI: Configuring Management Controls
CLI Commands Used in This Section
Command SyntaxCLI Reference Page
[no] console9-23
[no] ssh9-24
[no] telnet9-23
show console9-27
show system9-27
The following example shows how to enter management configuration context and control access to the Access Point device.
This example shows how to disable the console access to this device using
the no ssh command and display the current status of the access routes using
the show console command.
NoteEnter management commands, one per line.
ProCurve Access Point 530# configure
ProCurve Access Point 530(config)# no console
ProCurve Access Point 530(config)# show console
Web Access:
HTTP Interface Enabled
SSL Interface Enabled
ProCurve Access Point 530(config)#
5-12
Page 97
General System Configuration
Setting Management Access Controls
The following example demonstrates the no ssh command to disable the
serial SSH port, and the show ssh command to display the current status.
ProCurve Access Point 530# configure
ProCurve Access Point 530(config)# no ssh
ProCurve Access Point 530(config)# show ssh
SSH Status Disabled
ProCurve Access Point 530(config)#
The following example shows using the no telnet command to disable the
serial Telnet connection to this device.
CautionYou should use the no telnet command only when you are connected to the
access point through another method. Once you disable Telnet, the Telnet
connection is immediately lost.
ProCurve Access Point 530# configure
ProCurve Access Point 530(config)# no telnet
-----------------------------------------------------------C:connection is lost
5-13
Page 98
General System Configuration
Setting Management Access Controls
To display the current status for management access controls, use the show
system command.
ProCurve Access Point 530# show system
Serial Number TW633VV01D
System Name HP-AP-200
System Up Time 23 hours 17 mins 11 secs
System Location 2FS17
System Country Code us
Software Version WA.02.00.0412
Ethernet MAC Address 00:14:C2:A5:6A:B3
IP Address 192.168.15.200
Subnet Mask 255.255.255.0
Default Gateway 192.168.15.254
DHCP Client Disabled
Management VLAN ID 1
Untagged-VLAN ID 1
Radio 1 MAC Address 00:14:C2:A7:11:A0
Radio 1 Status Enabled (802.11g)
Radio 2 MAC Address 00:14:C2:A7:E1:20
Radio 2 Status Enabled (802.11g)
HTTP Interface Enabled
SSL Interface Enabled
SSH Interface Enabled
Telnet Interface Enabled
Serial Interface Enabled
ProCurve Access Point 530#
5-14
Page 99
General System Configuration
Modifying System Information
Modifying System Information
The access point’s system name can be left at its default setting. However,
modifying this parameter can help you to more easily distinguish one device
from another in your network.
NoteYou should also set the applicable WLANs (BSS/SSID) to identify the wireless
network service provided by the access point. See “Configuring the Radio” on page 6-
6.
Web: Setting the System Name, Location, and Contact
To modify the access point’s system parameters, use the Device Information
screen (the Home page or default screen).
The Web interface enables you to modify these parameters:
■System Name: An alias for the access point only, enabling the device to
be uniquely identified on the network. Setting must be at least 1 character
and a maximum of 63 characters long . (The default is ProCurve AP-530.)
■Location: The access point’s assigned location. (The default is not set.)
■Contact: The name of the Administrator responsible for the system. (The
default is not set.)
■[Update]: Updates the system information.
5-15
Page 100
General System Configuration
Modifying System Information
Figure 5-3.Configuring System Information
To Configure System Information:
1.Select Device Information in the navigation bar.
2.Type a name to uniquely identify the access point in the System Name
field.
3.Type a location to identify where the access point it located in the Location
field.
4.Type a name to identify the contact in the Contact field.
5.Select [Update] to modify the system information.
5-16
Loading...
+ hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.