Summary of the content on the page No. 1
Cisco Wireless LAN Controller
Configuration Guide
Software Release 3.2
March 2006
Corporate Headquarters
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA 95134-1706
USA
http://www.cisco.com
Tel: 408 526-4000
800 553-NETS (6387)
Fax: 408 526-4100
Text Part Number: OL-8335-02
Summary of the content on the page No. 2
THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS. THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT SHIPPED WITH THE PRODUCT AND ARE
Summary of the content on the page No. 3
CONTENTS Preface xiii Audience xiv Purpose xiv Organization xiv Conventions xv Related Publications xvii Obtaining Documentation xvii Cisco.com xvii Product Documentation DVD xviii Ordering Documentation xviii Documentation Feedback xviii Cisco Product Security Overview xix Reporting Security Problems in Cisco Products xix Obtaining Technical Assistance xx Cisco Technical Support & Documentation Website xx Submitting a Service Request xx Definitions of Service Request Severity xxi Obtaining Ad
Summary of the content on the page No. 4
Contents Client Roaming 1-8 Same-Subnet (Layer 2) Roaming 1-8 Inter-Controller (Layer 2) Roaming 1-8 Inter-Subnet (Layer 3) Roaming 1-9 Special Case: Voice Over IP Telephone Roaming 1-9 Client Location 1-9 External DHCP Servers 1-10 Per-Wireless LAN Assignment 1-10 Per-Interface Assignment 1-10 Security Considerations 1-10 Cisco WLAN Solution Wired Connections 1-11 Cisco WLAN Solution Wireless LANs 1-11 Access Control Lists 1-12 Identity Networking 1-12 Enhanced Integration with Cisco Secure A
Summary of the content on the page No. 5
Contents Web User Interface and the CLI 1-25 Web User Interface 1-25 Command Line Interface 1-26 CHAPTER 2 Using the Web-Browser and CLI Interfaces 2-1 Using the Web-Browser Interface 2-2 Guidelines for Using the GUI 2-2 Opening the GUI 2-2 Enabling Web and Secure Web Modes 2-2 Configuring the GUI for HTTPS 2-2 Loading an Externally Generated HTTPS Certificate 2-3 Disabling the GUI 2-5 Using Online Help 2-5 Using the CLI 2-5 Logging into the CLI 2-5 Using a Local Serial Connection 2-6 Using a
Summary of the content on the page No. 6
Contents Using the CLI to Configure the Virtual Interface 3-13 Using the CLI to Configure the Service-Port Interface 3-14 Configuring Dynamic Interfaces 3-14 Using the GUI to Configure Dynamic Interfaces 3-14 Using the CLI to Configure Dynamic Interfaces 3-16 Configuring Ports 3-17 Configuring Port Mirroring 3-20 Configuring Spanning Tree Protocol 3-21 Using the GUI to Configure Spanning Tree Protocol 3-22 Using the CLI to Configure Spanning Tree Protocol 3-26 Enabling Link Aggregation 3-27 Li
Summary of the content on the page No. 7
Contents Configuring Multicast Mode 4-9 Understanding Multicast Mode 4-9 Guidelines for Using Multicast Mode 4-9 Enabling Multicast Mode 4-10 Configuring the Supervisor 720 to Support the WiSM 4-10 General WiSM Guidelines 4-10 Configuring the Supervisor 4-11 Using the Wireless LAN Controller Network Module 4-12 CHAPTER 5 Configuring Security Solutions 5-1 Cisco WLAN Solution Security 5-2 Security Overview 5-2 Layer 1 Solutions 5-2 Layer 2 Solutions 5-2 Layer 3 Solutions 5-3 Rogue Access Point
Summary of the content on the page No. 8
Contents Configuring Identity Networking 5-16 Identity Networking Overview 5-16 RADIUS Attributes Used in Identity Networking 5-17 QoS-Level 5-17 ACL-Name 5-17 Interface-Name 5-18 VLAN-Tag 5-18 Tunnel Attributes 5-19 CHAPTER 6 Configuring WLANs 6-1 Wireless LAN Overview 6-2 Configuring Wireless LANs 6-2 Displaying, Creating, Disabling, and Deleting Wireless LANs 6-2 Activating Wireless LANs 6-3 Assigning a Wireless LAN to a DHCP Server 6-3 Configuring MAC Filtering for Wireless LANs 6-3 Enabli
Summary of the content on the page No. 9
Contents CHAPTER 7 Controlling Lightweight Access Points 7-1 Lightweight Access Point Overview 7-2 Cisco 1000 Series IEEE 802.11a/b/g Lightweight Access Points 7-2 Cisco 1030 Remote Edge Lightweight Access Points 7-3 Cisco 1000 Series Lightweight Access Point Part Numbers 7-4 Cisco 1000 Series Lightweight Access Point External and Internal Antennas 7-4 External Antenna Connectors 7-5 Antenna Sectorization 7-5 Cisco 1000 Series Lightweight Access Point LEDs 7-5 Cisco 1000 Series Lightweight Acc
Summary of the content on the page No. 10
Contents Erasing the Controller Configuration 8-4 Resetting the Controller 8-5 CHAPTER 9 Configuring Radio Resource Management 9-1 Overview of Radio Resource Management 9-2 Radio Resource Monitoring 9-2 Dynamic Channel Assignment 9-3 Dynamic Transmit Power Control 9-4 Coverage Hole Detection and Correction 9-4 Client and Network Load Balancing 9-4 RRM Benefits 9-5 Overview of RF Groups 9-5 RF Group Leader 9-5 RF Group Name 9-6 Configuring an RF Group 9-6 Using the GUI to Configure an RF Group
Summary of the content on the page No. 11
Contents CHAPTER 10 Configuring Mobility Groups 10-1 Overview of Mobility 10-2 Overview of Mobility Groups 10-5 Determining When to Include Controllers in a Mobility Group 10-7 Configuring Mobility Groups 10-7 Prerequisites 10-7 Using the GUI to Configure Mobility Groups 10-8 Using the CLI to Configure Mobility Groups 10-11 Configuring Auto-Anchor Mobility 10-11 Guidelines for Using Auto-Anchor Mobility 10-12 Using the GUI to Configure Auto-Anchor Mobility 10-12 Using the CLI to Configure Auto
Summary of the content on the page No. 12
Contents FCC Statements for Cisco 2000 Series Wireless LAN Controllers B-8 FCC Statements for Cisco 4100 Series Wireless LAN Controllers and Cisco 4400 Series Wireless LAN Controllers B-9 APPENDIX C End User License and Warranty C-1 End User License Agreement C-2 Limited Warranty C-4 Disclaimer of Warranty C-6 General Terms Applicable to the Limited Warranty Statement and End User License Agreement C-6 Additional Open Source Terms C-7 APPENDIX D System Messages and Access Point LED Patterns D
Summary of the content on the page No. 13
Preface This preface provides an overview of the Cisco Wireless LAN Controller Configuration Guide (OL-8335-02), references related publications, and explains how to obtain other documentation and technical assistance, if necessary. It contains these sections: • Audience, page xiv Purpose, page xiv Organization, page xiv Conventions, page xv Related Publications, page xvii Obtaining Documentation, page xvii Documentation Feedback, page xviii Cisco Product Security Overview, pag
Summary of the content on the page No. 14
Preface Audience Audience This guide describes Cisco Wireless LAN Controllers and Cisco Lightweight Access Points. This guide is for the networking professional who installs and manages these devices. To use this guide, you should be familiar with the concepts and terminology of wireless LANs. Purpose This guide provides the information you need to set up and configure wireless LAN controllers. Organization This guide is organized into these chapters: Chapter 1, “Overview,” provides an over
Summary of the content on the page No. 15
Preface Conventions Conventions This publication uses these conventions to convey instructions and information: Command descriptions use these conventions: Commands and keywords are in boldface text. Arguments for which you supply values are in italic. Square brackets ([ ]) mean optional elements. Braces ({ }) group required choices, and vertical bars ( | ) separate the alternative elements. Braces and vertical bars within square brackets ([{ | }]) mean a required choice within an op
Summary of the content on the page No. 16
Preface Conventions Varoitus Tämä varoitusmerkki merkitsee vaaraa. Olet tilanteessa, joka voi johtaa ruumiinvammaan. Ennen kuin työskentelet minkään laitteiston parissa, ota selvää sähkökytkentöihin liittyvistä vaaroista ja tavanomaisista onnettomuuksien ehkäisykeinoista. (Tässä julkaisussa esiintyvien varoitusten käännökset löydät liitteestä "Translated Safety Warnings" (käännetyt turvallisuutta koskevat varoitukset).) Attention Ce symbole d’avertissement indique un danger. Vous vous trou
Summary of the content on the page No. 17
Preface Related Publications Related Publications These documents provide complete information about the Cisco Unified Wireless Network Solution: Cisco Wireless LAN Controller Command Reference Quick Start Guide: Cisco 2000 Series Wireless LAN Controllers Quick Start Guide: Cisco 4100 Series Wireless LAN Controllers Quick Start Guide: Cisco 4400 Series Wireless LAN Controllers Quick Start Guide: VPN Termination Module for Cisco 4400 Series Wireless LAN Controllers Quick Start Gui
Summary of the content on the page No. 18
Preface Documentation Feedback Product Documentation DVD The Product Documentation DVD is a comprehensive library of technical product documentation on a portable medium. The DVD enables you to access multiple versions of installation, configuration, and command guides for Cisco hardware and software products. With the DVD, you have access to the same HTML documentation that is found on the Cisco website without being connected to the Internet. Certain products also have .PDF versions of t
Summary of the content on the page No. 19
Preface Cisco Product Security Overview Cisco Product Security Overview Cisco provides a free online Security Vulnerability Policy portal at this URL: http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html From this site, you will find information about how to: Report security vulnerabilities in Cisco products. Obtain assistance with security incidents that involve Cisco products. Register to receive security information from Cisco. A current list of security adv
Summary of the content on the page No. 20
Preface Obtaining Technical Assistance Obtaining Technical Assistance Cisco Technical Support provides 24-hour-a-day award-winning technical assistance. The Cisco Technical Support & Documentation website on Cisco.com features extensive online support resources. In addition, if you have a valid Cisco service contract, Cisco Technical Assistance Center (TAC) engineers provide telephone support. If you do not have a valid Cisco service contract, contact your reseller. Cisco Technical Support