D-Link DWS-4026 Product Manual - Page 413

WLAN Switch, Disable Reason, IP Address, AP MAC Validation, Method, Require Authentication, Passphrase

Page 413 highlights

Software User Manual 12/10/09 D-Link Unified Access System Table 257: Basic Wireless Global Configuration Field Description WLAN Switch Disable Reason If the status is disabled, this field appears and one of the following reasons is listed: • None: The cause for the disabled status is unknown. • Administrator disabled: The Enable WLAN Switch check box has been cleared. • No IP Address: The WLAN interface does not have an IP address. • No SSL Files: The Unified Switch communicates with the APs it manages by using Secure Sockets Layer (SSL) connections. The first time you power on the Unified Switch, it automatically generates a server certificate that will be used to set up the SSL connections. The SSL certificate and key generation can take up to an hour to complete. If routing is enabled on the switch, the operational status might be disabled due to one of the following reasons: • No Loopback Interface: The switch does not have a loopback interface. • Global Routing Disabled: Even if the routing mode is enabled on the WLAN switch interface, it must also be enabled globally for the operational status to be enabled. IP Address This field shows the IP address of the WLAN interface on the switch. If the switch does not have the Routing Package installed, or if routing is disabled, the IP address is the network interface. If the routing package is installed and enabled, this is the IP address of the routing or loopback interface you configure for the Unified Switch features. If routing is enabled, it is strongly recommend that you define a loopback interface on the switch. By creating a loopback interface, you can control which routing interface the wireless function uses for its IP address when multiple routing interfaces exist. This can avoid discovery problems for the discovery modes where the AP knows the IP address of the Unified Switch. With the loopback interface, the IP address of the wireless function is always the same. In this context, the loopback interface does not refer to the loopback interface with the 127.0.0.1 IP address. When you configure a loopback interface for the wireless interface on the switch, it is essentially a permanent logical interface and cannot have an IP address of 127.0.0.1. You must create a dedicated subnet for the loopback interface, and other devices on the network must be able to contact the IP address of the loopback interface. AP Validation AP MAC Validation Method Require Authentication Passphrase For a Unified Switch to manage an AP, you must add the MAC address of the AP to the Valid AP database, which can be kept locally on the switch or in an external RADIUS server. When the switch discovers an AP that is not managed by another Unified Switch, it looks up the MAC address of the AP in the Valid AP database. If it finds the MAC address in the database, the switch validates the AP and assumes management. Select the database to use for AP validation and, optionally, for authentication if the Require Authentication Passphrase option is selected. • Local: If you select this option, you must add the MAC address of each AP to the local Valid AP database. • RADIUS: If you select this option, you must configure the MAC address of each AP in an external RADIUS server. Select this option to require APs to be authenticated before they can associate with the switch. If you select this option, you must configure the passphrase on the AP while it is in standalone mode as well as in the Valid AP database. To configure the pass phrase on a standalone AP, log onto the AP Administration Web UI and go to the Managed Access Point page, or log onto the AP CLI and use the set managed-ap pass-phrase command. To configure the passphrase for an AP in the local Valid AP database, click the Valid AP tab from the Basic Setup page. Then, click the MAC address of the AP and enter the passphrase in the Authentication Password field. If you enable authentication, it takes place immediately after the switch validates the AP. RADIUS Server Configuration Document 34CSFP6XXUWS-SWUM100-D7 Basic Setup Page 413

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518
  • 519
  • 520
  • 521
  • 522
  • 523
  • 524
  • 525
  • 526
  • 527
  • 528
  • 529
  • 530
  • 531
  • 532
  • 533
  • 534
  • 535
  • 536
  • 537
  • 538
  • 539
  • 540
  • 541
  • 542
  • 543
  • 544
  • 545
  • 546
  • 547
  • 548
  • 549
  • 550
  • 551
  • 552
  • 553
  • 554
  • 555
  • 556
  • 557
  • 558
  • 559
  • 560
  • 561
  • 562
  • 563
  • 564
  • 565
  • 566
  • 567
  • 568
  • 569
  • 570
  • 571
  • 572
  • 573
  • 574
  • 575
  • 576

Software User Manual
D-Link Unified Access System
12/10/09
Document
34CSFP6XXUWS-SWUM100-D7
Basic Setup
Page
413
WLAN Switch
Disable Reason
If the status is disabled, this field appears and one of the following reasons is listed:
None: The cause for the disabled status is unknown.
Administrator disabled: The Enable WLAN Switch check box has been cleared.
No IP Address: The WLAN interface does not have an IP address.
No SSL Files: The Unified Switch communicates with the APs it manages by using Secure
Sockets Layer (SSL) connections. The first time you power on the Unified Switch, it
automatically generates a server certificate that will be used to set up the SSL connections.
The SSL certificate and key generation can take up to an hour to complete.
If routing is enabled on the switch, the operational status might be disabled due to one of the
following reasons:
No Loopback Interface: The switch does not have a loopback interface.
Global Routing Disabled: Even if the routing mode is enabled on the WLAN switch interface,
it must also be enabled globally for the operational status to be enabled.
IP Address
This field shows the IP address of the WLAN interface on the switch. If the switch does not
have the Routing Package installed, or if routing is disabled, the IP address is the network
interface. If the routing package is installed and enabled, this is the IP address of the routing
or loopback interface you configure for the Unified Switch features.
If routing is enabled, it is strongly recommend that you define a loopback interface on the
switch. By creating a loopback interface, you can control which routing interface the wireless
function uses for its IP address when multiple routing interfaces exist. This can avoid
discovery problems for the discovery modes where the AP knows the IP address of the Unified
Switch. With the loopback interface, the IP address of the wireless function is always the
same.
In this context, the loopback interface does not refer to the loopback interface with the
127.0.0.1 IP address. When you configure a loopback interface for the wireless interface on
the switch, it is essentially a permanent logical interface and cannot have an IP address of
127.0.0.1. You must create a dedicated subnet for the loopback interface, and other devices
on the network must be able to contact the IP address of the loopback interface.
AP Validation
AP MAC Validation
Method
For a Unified Switch to manage an AP, you must add the MAC address of the AP to the Valid
AP database, which can be kept locally on the switch or in an external RADIUS server. When
the switch discovers an AP that is not managed by another Unified Switch, it looks up the MAC
address of the AP in the Valid AP database. If it finds the MAC address in the database, the
switch validates the AP and assumes management.
Select the database to use for AP validation and, optionally, for authentication if the Require
Authentication Passphrase option is selected.
Local: If you select this option, you must add the MAC address of each AP to the local Valid
AP database.
RADIUS: If you select this option, you must configure the MAC address of each AP in an
external RADIUS server.
Require Authentication
Passphrase
Select this option to require APs to be authenticated before they can associate with the switch.
If you select this option, you must configure the passphrase on the AP while it is in standalone
mode as well as in the Valid AP database. To configure the pass phrase on a standalone AP,
log onto the AP Administration Web UI and go to the
Managed Access Point
page, or log
onto the AP CLI and use the
set managed-ap pass-phrase
command.
To configure the passphrase for an AP in the local Valid AP database, click the
Valid AP
tab
from the
Basic Setup
page. Then, click the MAC address of the AP and enter the passphrase
in the Authentication Password field.
If you enable authentication, it takes place immediately after the switch validates the AP.
RADIUS Server Configuration
Table 257:
Basic Wireless Global Configuration
Field
Description