06-WLAN access

HomeSupportConfigure & DeployConfiguration ExamplesH3C Access Controllers Configuration Examples(V7)-6W10506-WLAN access
02-Example for Configuring PSK Encryption
Title Size Download
02-Example for Configuring PSK Encryption 120.93 KB

Example: Configuring PSK encryption

Introduction

The following information provides an example for configuring PSK encryption.

Network configuration

As shown in Figure 1, the switch acts as a DHCP server to assign IP addresses to the AP and the client. Perform the following tasks:

·     Configure PSK on the AC to enable the client to use PSK for encryption.

·     Configure open system authentication and bypass authentication so that the client can access the WLAN without being authenticated.

·     Configure PSK as the authentication and key management (AKM) mode.

·     Set the cipher suite to CCMP.

·     Set the security IE to RSN.

Figure 1 Network diagram

 

Restrictions and guidelines

When you configure PSK encryption, follow these restrictions and guidelines:

·     Use the serial ID labeled on the AP's rear panel to specify an AP.

·     Configure a pre-shared key if the AKM mode is PSK.

Procedures

Configuring the AC

1.     Configure AC interfaces:

# Create VLAN 100 and VLAN-interface 100, and assign an IP address to the VLAN interface. The AC will use this IP address to establish a CAPWAP tunnel with the AP.

<AC> system-view

[AC] vlan 100

[AC-vlan100] quit

[AC] interface vlan-interface 100

[AC-Vlan-interface100] ip address 192.1.1.1 16

[AC-Vlan-interface100] quit

# Create VLAN 200 and VLAN-interface 200, and assign an IP address to the VLAN interface. The client will use this VLAN to access the WLAN.

[AC] vlan 200

[AC-vlan200] quit

[AC] interface vlan-interface 200

[AC-Vlan-interface200] ip address 192.2.1.1 24

[AC-Vlan-interface200] quit

# Configure GigabitEthernet 1/0/1 that connects the AC to the switch as a trunk port, remove the port from VLAN 1, and assign the port to VLANs 100 and 200.

[AC] interface gigabitethernet 1/0/1

[AC-GigabitEthernet1/0/1] port link-type trunk

[AC-GigabitEthernet1/0/1] undo port trunk permit vlan 1

[AC-GigabitEthernet1/0/1] port trunk permit vlan 100 200

[AC-GigabitEthernet1/0/1] quit

2.     Configure wireless services:

# Create service template 1 and enter its view.

[AC] wlan service-template 1

# Configure the SSID as service.

[AC-wlan-st-1] ssid service

# Specify VLAN 200 for clients to access the WLAN defined by the service template.

[AC-wlan-st-1] vlan 200

# Set the AKM mode to PSK, and configure simple character string of 12345678 as the PSK.

[AC-wlan-st-1] akm mode psk

[AC-wlan-st-1] preshared-key pass-phrase simple 12345678

# Set the cipher suite to CCMP and set the security IE to RSN.

[AC-wlan-st-1] cipher-suite ccmp

[AC-wlan-st-1] security-ie rsn

# Configure the AC to forward client data traffic. You can skip this step if the AC is the client traffic forwarder by default.

[AC-wlan-st-1] client forwarding-location ac

# Enable the service template.

[AC-wlan-st-1] service-template enable

[AC-wlan-st-1] quit

3.     Configure the AP:

 

 

NOTE:

In a large-scale network, configure AP groups instead of single APs as a best practice.

 

# Create manual AP officeap, and specify the AP model and serial ID.

[AC] wlan ap officeap model WA6320

[AC-wlan-ap-officeap] serial-id 219801A28N819CE0002T

[AC-wlan-ap-officeap] quit

# Create AP group group1, and add the AP to the AP group.

[AC] wlan ap-group group1

[AC-wlan-ap-group-group1] ap officeap

# Bind service template 1 to radio 2.

[AC-wlan-ap-group-group1] ap-model WA6320

[AC-wlan-ap-group-group1-ap-model-WA6320] radio 2

[AC-wlan-ap-group-group1-ap-model-WA6320-radio-2] service-template 1

# Enable radio 2.

[AC-wlan-ap-group-group1-ap-model-WA6320-radio-2] radio enable

[AC-wlan-ap-group-group1-ap-model-WA6320-radio-2] quit

[AC-wlan-ap-group-group1-ap-model-WA6320] quit

[AC-wlan-ap-group-group1] quit

Configuring the switch

1.     Configure switch interfaces:

# Create VLAN 100 and VLAN-interface 100, and assign an IP address to the VLAN interface. The switch will use VLAN 100 to forward packets between the AC and the AP.

<Switch> system-view

[Switch] vlan 100

[Switch-vlan100] quit

[Switch] interface vlan-interface 100

[Switch-Vlan-interface100] ip address 192.1.1.2 16

[Switch-Vlan-interface100] quit

# Create VLAN 200 and VLAN-interface 200, and assign an IP address to the VLAN interface. The switch will use VLAN 200 to forward client traffic.

[Switch] vlan 200

[Switch-vlan200] quit

[Switch] interface vlan-interface 200

[Switch-Vlan-interface200] ip address 192.2.1.2 24

[Switch-Vlan-interface200] quit

# Configure GigabitEthernet 1/0/1 that connects the switch to the AC as a trunk port, remove the port from VLAN 1, and assign the port to VLANs 100 and 200.

[Switch] interface gigabitethernet 1/0/1

[Switch-GigabitEthernet1/0/1] port link-type trunk

[Switch-GigabitEthernet1/0/1] undo port trunk permit vlan 1

[Switch-GigabitEthernet1/0/1] port trunk permit vlan 100 200

[Switch-GigabitEthernet1/0/1] quit

# Configure GigabitEthernet 1/0/2 that connects the switch to the AP as a trunk port, remove the port from VLAN 1, set the PVID to VLAN 100, and assign the port to VLAN 100.

[Switch] interface gigabitethernet 1/0/2

[Switch-GigabitEthernet1/0/2] port link-type trunk

[Switch-GigabitEthernet1/0/2] undo port trunk permit vlan 1

[Switch-GigabitEthernet1/0/2] port trunk permit vlan 100

[Switch-GigabitEthernet1/0/2] port trunk pvid vlan 100

# Enable PoE on GigabitEthernet 1/0/2.

[Switch-GigabitEthernet1/0/2] poe enable

[Switch-GigabitEthernet1/0/2] quit

2.     Configure DHCP:

# Enable DHCP.

[Switch] dhcp enable

# Create DHCP address pool vlan100 to assign an IP address to the AP, and specify subnet 192.1.0.0/16 in the DHCP address pool.

[Switch] dhcp server ip-pool vlan100

[Switch-dhcp-pool-vlan100] network 192.1.0.0 mask 255.255.0.0

# Exclude IP address 192.1.1.1 from dynamic allocation in the address pool.

[Switch-dhcp-pool-vlan100] forbidden-ip 192.1.1.1

# Specify the gateway address as 192.1.1.2 in the DHCP address pool.

[Switch-dhcp-pool-vlan100] gateway-list 192.1.1.2

[Switch-dhcp-pool-vlan100] quit

# Create DHCP address pool vlan200 to assign an IP address to the client, and specify subnet 192.2.1.0/24 in the DHCP address pool.

[Switch] dhcp server ip-pool vlan200

[Switch-dhcp-pool-vlan200] network 192.2.1.0 mask 255.255.255.0

# Exclude IP address 192.2.1.1 from dynamic allocation in the address pool.

[Switch-dhcp-pool-vlan200] forbidden-ip 192.2.1.1

# Specify the gateway address as 192.2.1.2 and specify the DNS server address in the DHCP address pool. In this example, the gateway also acts as a DNS server.

[Switch-dhcp-pool-vlan200] gateway-list 192.2.1.2

[Switch-dhcp-pool-vlan200] dns-list 192.2.1.2

[Switch-dhcp-pool-vlan200] quit

Verifying the configuration

# Verify that the client has been associated with the WLAN and the AKM mode is PSK.

[AC] display wlan client verbose

Total number of clients: 1

 

MAC address                       : 0024-d705-c608

IPv4 address                      : 192.2.1.3

 IPv6 address                      : N/A

 Username                          : N/A

 AID                               : 1

 AP ID                             : 2

 AP name                           : officeap

 Radio ID                          : 2

 SSID                              : service

 BSSID                             : 80f6-2eaf-5190

 VLAN ID                           : 200

 Sleep count                       : 137

 Wireless mode                     : 802.11g

 Supported rates                   : 1, 2, 5.5, 6, 9, 11,

                                     12, 18, 24, 36, 48, 54 Mbps

QoS mode                          : WMM

 Listen interval                   : 100

 RSSI                              : 20

 Rx/Tx rate                        : 2/1

 Authentication method             : Open system

 Security mode                     : PRE-RSNA

 AKM mode                          : N/A

 Security mode                     : RSN

 AKM mode                          : PSK

 Cipher suite                      : CCMP

 User authentication mode          : Bypass

 Authorization ACL ID              : N/A

 Authorization user profile        : N/A

 Roam status                       : N/A

 Key derivation                    : N/A

 PMF status                        : N/A

 Forwarding policy name            : N/A

 Online time                       : 0days 0hours 21minutes 55seconds

 FT status                         : Inactive

Configuration files

·     AC:

#

vlan 100

#

vlan 200

#

wlan service-template 1

 ssid service

client forwarding-location ac

vlan 200

akm mode psk

 preshared-key pass-phrase cipher $c$3$N//5BVbsOqdBTxi+7MJZKT6Zqh5MAmYs2ZzM

 cipher-suite ccmp

 security-ie rsn

service-template enable

#

interface Vlan-interface100

 ip address 192.1.1.1 255.255.0.0

#

interface Vlan-interface200

 ip address 192.2.1.1 255.255.255.0

#

interface GigabitEthernet1/0/1

 port link-type trunk

 undo port trunk permit vlan 1

 port trunk permit vlan 100 200

#                                                                              

wlan ap-group group1                                                           

 ap officeap                                                                        

 ap-model WA6320                                                               

  radio 2                                                                      

   radio enable                                                                

   service-template 1

#

wlan ap officeap model WA6320

 serial-id 219801A28N819CE0002T

#

·     Switch:

#

 dhcp enable

#

vlan 100

#

vlan 200

#

dhcp server ip-pool vlan100

 gateway-list 192.1.1.2

 network 192.1.0.0 mask 255.255.0.0

 forbidden-ip 192.1.1.1

#

dhcp server ip-pool vlan200

 gateway-list 192.2.1.2

 network 192.2.1.0 mask 255.255.255.0

 dns-list 192.2.1.2

 forbidden-ip 192.2.1.1

#

interface GigabitEthernet1/0/1

port link-type trunk

undo port trunk permit vlan 1

 port trunk permit vlan 100 200

#

interface GigabitEthernet1/0/2

port link-type trunk

undo port trunk permit vlan 1

 port trunk permit vlan 100

 port trunk pvid vlan 100

poe enable

#

Related documentation

·     WLAN Access Command Reference in H3C Access Controllers Command References

·     WLAN Access Configuration Guide in H3C Access Controllers Configuration Guides

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Intelligent Storage
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
  • Technical Blogs
All Support
  • Become A Partner
  • Partner Policy & Program
  • Global Learning
  • Partner Sales Resources
  • Partner Business Management
  • Service Business
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us