H3C Shortcut Keys

Leave a comment

Like many things in the H3C world shortcut keys are not well documented here are the one I use every day. I will add more as I find them.

Ctrl-K display ip routing-table
Ctrl-O undo debugging all
Ctrl-G display current-configuration
Ctrl-A Beginning of Command Line
Ctrl-E End of Command Line
Ctrl-N Next Command in the history buffer
Ctrl-P Previous Command in the history buffer

WPA-WPA2 Radius setup for EAP using IAS with GUEST SSID on H3C Wireless Controller

Leave a comment

Since the even with the configuration guides I found and uploaded configuration of the Wireless Controller still has some details not in the guides. I thought I would upload my confguration of my wireless as an example. I am using EAP based WPA/WPA2 security to a Windows 2003 Radius Server specifically an internal PKI . This is based on an existing IAS Server infrastructure and just adding the Wireless Controller as a new Radius Client. I have two SSIDs one for guests called GUEST-WIFI on an internet access vlan (VLAN 80) and a SECURED-WIFI for end-users on VLAN 1 using WPA/WPA2.

On the controller the following needs to be configured:

 

#

domain default enable system

#

port-security enable

#

dot1x authentication-method eap

#

radius scheme ias

server-type extended

primary authentication IASSERVERIP

primary accounting IASSERVERIP

key authentication SHAREDKEY

key accounting SHAREDKEY

timer realtime-accounting 3

user-name-format keep-original

nas-ip ACCESSCONTROLLERIP

undo stop-accounting-buffer enable

accounting-on enable

#

#

domain ias

authentication default radius-scheme ias

authorization default radius-scheme ias

accounting default radius-scheme ias

access-limit disable

state active

idle-cut disable

self-service-url disable

#

wlan radio-policy rp

beacon-interval 500

#

wlan service-template 1 clear

ssid GUEST-WIFI

bind WLAN-ESS 0

user-isolation enable

service-template enable

#

wlan service-template 2 crypto

ssid SECURED-WIFI

bind WLAN-ESS 1

cipher-suite tkip

cipher-suite ccmp

security-ie rsn

security-ie wpa

service-template enable

#

#

interface WLAN-ESS0

port access vlan 80

#

interface WLAN-ESS1

port-security port-mode userlogin-secure-ext

port-security tx-key-type 11key

dot1x mandatory-domain ias

#

#

wlan ap autoap model 7760_2750 id 3

serial-id auto

radio 1

radio-policy rp

service-template 1

service-template 2

radio enable

On the IAS server a new radius client needs to be configured.

 

 

 

3CRUS2475 Discovery Process by H3C/3Com 7760 Access Point

7 Comments

One of the issues I found with having H3C/3Com now HP products over the last few years is the lack of support for senarios that are described but never documented. While desciption  of features exist configuration guides or FAQ seem non-existent. I recently purchased a S7500 controller blade at work for our new core to move over our existing 7760 series Access Points from 3CRUS2475 switches over to a more robust solution designed to handle our  70+ APs. I just wanted to take this time to document the way 7760 discovered the 3CRUS2475.

  1. 3Com Access Point sends a UDP port 42004 to broadcast searching for Wireless Switch with the model number of the  access point
  2. DNS Discovery for hostname 3ComUWS: 1 DNS request stops if no name found

Detailed H3C WX Access Controller Discovery from a HP/3Com 7760

1 Comment

One of the issues I found with having H3C/3Com now HP products over the last few years is the lack of support for scenarios that are described but never documented. While desciption  of features exist configuration guides or FAQ seem non-existent. I recently purchased a S7500 controller blade at work for our new core to move over our existing 7760 series Access Points from 3CRUS2475 switches over to a more robust solution designed to handle our  70+ APs. The first step is to update the managed firmware in the device from the firmware that ships meant for management by the Unified Wireless Switch 3CRUS2475 to the H3C fit managed mode. I just wanted to take this time to document the differnet ways it seem you can configure these to discover the Access Controller.

  1. IPv4 Broadcast Discovery 255.255.255.255 from/to port 12223:  3 packets detailing that it is a discovery packet and the model and serial number of the device.
  2. DNS Discovery for hostname 3ComWLC: 1 DNS request stops if no name found
  3. IPv6 Multicast Discovery FF02:1 from/to port 12223 : 3 Packets again detailing that it is a discovery packet and the model and serial number of the device.

This then repeats if  no controllers are found. The additional options for manually configuring the device exist:

Log in via the console port  or telnet in password is “h3capadmin”

<7760_2750> sys

[7760_2750] wlan ac ip “ip address”

or

[7760_2760] wlan ac ipv6 “ipv6 address”

[7760_2750] quit

<7760_2750> save

Hope this helps….

H3C WX Wireless Access Controllers Configuration Examples

Leave a comment

 

Here is a collection of WX Series Wireless Access Controller Configs:

H3C WX Series AC + Fit AP Configuration Examples is organized as follows:

            H3C Wireless Technical Overview

            Leave a comment

            A copy of the H3C Wireless Tech overview document helpful for a theory of operation on the WX series Wireless Access Controllers

            H3C_Wireless_Technical_Overview

            Supported HP / H3C / 3Com Access Points on WX6000 Access Controllers

            Leave a comment

            I recently purchased a H3C Wireless Controller for the HP A7500 switch. One of the issues I found out was with the HP consolidation of the product lines from Colubris/3Com/H3C I couldn’t get a answer on what was supported. Here is a list of access points that should be supported:

            JD446B - HP A-WA2110 Single Radio 802.11a/b/g Access Point

            JD451A - HP A-WA2220 Dual Radio 802.11a/b/g Access Point

            JD445A - HP A-WA2612 Single Radio 802.11n Access Point

            JD472A - HP A-WA2620 Dual Radio 802.11n Access Point

            JD452A - HP A-WA2610E Single Radio 802.11n Access Point

            JD453A - HP A-WA2620E Dual Radio 802.11n Plenum Access Point

            Ironically the following two are supported despite being some of the oldest and are not H3C. I anticipate these will soon be discontinued:

            JD015A - HP A7760 Single Radio 802.11a/b/g Access Point

            JD016A - HP A8760 Single Radio 802.11a/b/g Access Point

            Discontinued but still should work:
            3Com 3150

            I am anticipating that some of the nicer E-Series Wireless will be supported hopefully the MSM317 would be sweet.

            HP / H3C Hidden Commands

            Leave a comment

            There are hidden commands only to be used by developers within the H3C interface:

            The command to access this view is: _hidecmd

            Which gives you the following warning:
            Now you enter a hidden command view for developer’s testing, some commands may
            affect operation by wrong use, please carefully use it with our engineer’s
            direction.

            Depending on your device it will unlock different options :

            On the 7500 Switch:
            _bgp_display_debuginfo_detail Cancel current setting
            _debugging Specify the slot number
            _device Display device information
            _display Display current system information
            _exp_memfail_malloc Display current system information
            _fib Specify FIB configuration information
            _igmp-static-group Generate many group membership protocol
            specific static-group routes
            _ip-check-source IP
            _memory Memory operations
            _mld-static-group Generate many group membership protocol
            specific static-group routes
            _remove Display device program debugging
            information
            _reset Reset operation
            _terminal Settings of terminal
            _test Test trap send
            _write Write register

            On the 7500 Wireless Access Controller:
            _debugging Display device program debugging information
            _display Display current system information
            _fib Specify FIB configuration information
            _memory Memory operations
            _reset Reset operation
            _terminal Settings of terminal
            _test Test trap send
            _write Write register

            On the 5500-SI Switch:
            _debugging Display device program debugging information
            _display Display driver modules information
            _fib Specify FIB configuration information
            _memory Memory operations
            _reset Reset operation
            _terminal Settings of terminal
            _test Test trap send
            _write Write register

            Follow

            Get every new post delivered to your Inbox.