beautypg.com

Verifying the configuration – H3C Technologies H3C WX3000E Series Wireless Switches User Manual

Page 252

background image

238

[AC-isp-sun] accounting default radius-scheme 2000

[AC-isp-sun] quit

# Create interface WLAN-ESS 1.

[AC] interface WLAN-ESS 1

# Set the port security mode to userLoginSecureExt.

[AC-WLAN-ESS1] port-security port-mode userlogin-secure-ext

# Enable key negotiation of the 11key type.

[AC-WLAN-ESS1] port-security tx-key-type 11key

# Disable the 802.1X multicast trigger and online user handshake functions.

[AC-WLAN-ESS1] undo dot1x multicast-trigger

[AC-WLAN-ESS1] undo dot1x handshake

# Specify the mandatory 802.1X authentication domain as the domain sun for the interface
WLAN-ESS 1.

[AC-WLAN-ESS1] dot1x mandatory-domain sun

[AC-WLAN-ESS1] quit

# Set the 802.1X authentication mode to EAP.

[AC] dot1x authentication-method eap

3.

Configure the WLAN service template, and the AP:
# Create a WLAN service template of the crypto type, enter its view, and set an SSID.

[AC] wlan service-template 1 crypto

[AC-wlan-st-1] ssid sectest

# Bind the interface to the service template.

[AC-wlan-st-1] bind WLAN-ESS 1

# Enable open system authentication, the TKIP cipher suite, and the WPA-IE in the beacon and

probe responses.

[AC-wlan-st-1] authentication-method open-system

[AC-wlan-st-1] cipher-suite tkip

[AC-wlan-st-1] security-ie wpa

# Enable the service template function.

[AC-wlan-st-1] service-template enable

[AC-wlan-st-1] quit

# Create an AP template named ap1 and its model is WA2100, and set a serial ID for the AP.

[AC] wlan ap ap1 model WA2100

[AC-wlan-ap-ap1] serial-id 210235A29G007C000020

# Bind the service template 1 to the port radio 1, and enable the raido.

[AC-wlan-ap-ap1] radio 1 type dot11g

[AC-wlan-ap-ap1-radio-1] service-template 1

[AC-wlan-ap-ap1-radio-1] radio enable

[AC-wlan-ap-ap1-radio-1] return

Verifying the configuration

# Display the port security configuration information.

display port-security interface WLAN-ESS1

Equipment port-security is enabled

Trap is disabled

Disableport Timeout: 20s