Nortel Networks NN47250-500 Switch User Manual


 
Configuring and managing ports and VLANs 105
Nortel WLAN—Security Switch 2300 Series Configuration Guide
The ap-num parameter identifies the AP connection for the AP. The range of valid connection ID numbers depends on
the WSS model. Table 3 lists the ranges of valid ap-num values for each model.
For the serial-id parameter, specify the serial ID of the AP. The serial ID is listed on the AP case. To display the serial
ID using the CLI, use the show version details command.
The model and radiotype parameters have the same options as they do with the set port type ap command. Because the
WSS does not supply power to an indirectly connected AP, the set ap command does not use the poe parameter.
To configure AP connection 1 for AP model 2330 with serial-ID 0322199999, type the following command:
WSS# set ap 1 serial-id 0322199999 model 2330
success: change accepted.
Setting a port for a wired authentication user
To set a port for a wired authentication user, use the following command:
set port type wired-auth port-list [tag tag-list] [max-sessions num]
[auth-fall-thru {last-resort | none | web-portal}]
You must specify a port list. Optionally, you also can specify a tag-list to subdivide the port into virtual ports, set the
maximum number of simultaneous user sessions that can be active on the port, and change the fallthru authentication
type.
By default, one user session can be active on the port at a time.
The fallthru authentication type is used if the user does not support 802.1X and is not authenticated by MAC authentica-
tion. The default is none, which means the user is automatically denied access if neither 802.1X authentication or MAC
authentication is successful.
To set port 17 as a wired authentication port, type the following command:
WSS# set port type wired-auth 17
success: change accepted
This command configures port 17 as a wired authentication port supporting one interface and one simultaneous user
session.
For 802.1X clients, wired authentication works only if the clients are directly attached to the wired authentication port,
or are attached through a hub that does not block forwarding of packets from the client to the PAE group address
(01:80:c2:00:00:03). Wired authentication works in accordance with the 802.1X specification, which prohibits a client
Table 3: Valid ap-num Values
Switch Model Valid Range
MX-2800 1 to 2048
2382 1 to 320
2380 1 to 300
2360/2361 1 to 30
2350 1 to 8