Cisco 3200 Series Wireless MIC Software Configuration Guide
Index

Table Of Contents

Numerics - A - B - C - D - E - F - G - H - I - K - L - M - N - O - P - Q - R - S - T - U - V - W -

Index

Numerics

12.2(15)T 18-4

2.4-GHz WMIC, contrasted with 4.9-GHz WMIC 1-8

4.9 GHz (US Only, Public Safety) 8-2

802.11d 3-6

802.11d (world mode) 3-11

802.11h 7-2

802.1x authentication 4-13

A

AAA

server group 4-25

aaa authentication login command 4-24

aaa authorization command 4-27

aaa new-model command 4-22, 4-25

access point 3-2

security settings, matching client devices 14-25

WDS 25-2

accounting

with RADIUS 4-28

with TACACS+ 4-32, 4-37

accounting command 10-2

Address Resolution Protocol (ARP) 3-7

administrator access 4-21

Advanced Encryption Standard (AES) 1-7

AES-CCMP 11-2

Aironet 802.11 extensions 4-40

Aironet Client Utility (ACU) 19-3

antenna gains 8-4

ARPANET 4-1

attributes, RADIUS

vendor-proprietary 4-30

vendor-specific 4-29

authentication

EAP server 4-20, 14-3

local mode with AAA 4-38

MAC address 14-6

NTP associations 4-47

RADIUS

key 4-22

login 4-24

server configuration for fast secure roaming 25-5

TACACS+

defined 4-32

key 4-34

login 4-34, 4-35

authentication network-eap command 25-10

authentication types

CCKM key management 14-6

EAP-FAST 14-5

EAP-TLS 14-5

EAP-TTLS 14-5

MAC address 14-6

matching on root devices and non-root bridges 14-25

Network-EAP 14-3

open 14-2

shared key 14-2

using WPA key management 14-6

authorization

with RADIUS 4-27

with TACACS+ 4-32, 4-36

autoinstall 10-2

B

bandwidth

bridges 3-4

banner login command 4-5

banner motd command 4-4

banners

configuring

login 4-5

message-of-the-day login 4-4

default configuration 4-4

when displayed 4-3

basic data rate 8-5

basic settings

checking 19-3

bootloader 19-7

BOOTP 4-2

BR350 interoperability 12-2

bridge

filters 3-3

bridge, wireless 3-2

bridge-group command 12-9

Bridge Group Virtual Interface (BVI) 2-3

bridge interoperability 12-2

bridge mode 3-3, 3-7, 3-8

bridge protocol data unit (BPDU) 12-1

BSSIDs 10-3

BVI

universal workgroup bridge 3-8

C

CCKM 3-9, 14-6

CCK modulation 8-2

CDMA 1-1

CDP

disabling for routing device 13-3

enabling and disabling 13-3

monitoring 13-4

Centralized Key Management (CCKM) 11-1

certificates

configuring 14-7

channel

default setting i-xiv, 5-1, 7-1

channels

allowed per country3-12to 3-16

cipher suites

enabling 11-5

with WPA 11-8

Cisco Centralized Key Management

See CCKM

Cisco Centralized Key Management (CCKM) 1-7

Cisco Compatible eXtensions (CCX) 3-9

Cisco Express Forwarding (CEF) 18-4

Cisco IOS image release 1-8

Cisco IOS version 12.4(6)T 7-1

Cisco TAC 19-1

CiscoWorks 2000 21-3

CKIP 1-7

CKIP (Cisco Key Integrity Protocol) 11-2

clock

See system clock

clock set command 4-44

clock timezone command 4-45

CMIC 1-7, 11-2

CMIC (Cisco Message Integrity Check)

See CMIC

commands

aaa authentication login 4-24

aaa authorization 4-27

aaa new-model 4-22, 4-25

accounting 10-2

authentication network-eap 25-10

banner login 4-5

banner motd 4-4

bridge-group 12-9, 16-4

cdp enable 13-3

cdp holdtime 13-2

cdp timer 13-2

clear cdp counters 13-4

clear cdp table 13-4

client profile multiple 9-5

clock set 4-44

clock timezone 4-45

crypto map local-address 18-4

del 19-5

dot11 interface speed 25-11

encapsulation 16-3

encapsulation dot1q 16-4

encryption 9-5

encryption mode cipher 11-1

hostname 4-1

infrastructure-client 3-7

infrastructure SSID 10-2

interface dot11radio 9-1

interface dot11radio0 16-3

interface fastEthernet0.x 16-4

ip domain-lookup 4-3

ip domain-name 4-2

ip multicast-routing 18-1, 18-2

ip name-server 4-3

ip pim 18-1, 18-2

login authentication 4-25

ntp authenticate 4-47

ntp peer 4-49

power 8-2

power client 8-3

prompt 4-1

radius-server host 4-23

router mobile 18-1, 18-2

set 19-6

set BOOT 19-6

set next hop loopback 18-4

setting privilege levels 4-10

show cdp 13-4

show cdp entry 13-4

show cdp interface 13-4

show cdp neighbors 13-4

show cdp traffic 13-4

show controller dot11radio 8-8

show controllers dot11Radio 5-2, 8-2

show crypto ipsec 18-5

show ip mobile router 18-5

show ip mobile tunnel 18-2

speed 8-6

ssid 9-1

tftp_init 19-5

vlan 10-2

world mode 3-6

community strings

configuring 21-4

overview 21-3

connections, secure remote 4-39

console cable 2-1

console port

cable 2-2

country code 3-11

country codes, supported??to 3-16

cryptographic message integrity 11-2

crypto map 18-4

crypto map local-address command 18-4

crypto pki CLI 14-7

crypto software image 4-39

D

data rate

basic 8-5

setting 8-6

throughput 8-5

date

See NTP and system clock

daylight saving time 4-46

default

configuration, resetting 19-3

default configuration

banners 4-4

DNS 4-2

NTP 4-47

password and privilege level 4-6

SNMP 21-4

system message logging 17-3

TACACS+ 4-33

del command 19-5

Delivery Traffic Indication Message (DTIM) 10-3

DFS

operating frequency 7-2

DHCP 2-3, 4-2

DNS

default configuration 4-2

display configuration 4-3

overview 4-2

setting up 4-2

domain names

DNS 4-2

Domain Name System

See DNS

dot11 interface speed command 25-11

Dynamic Frequency Selection (DFS) 7-1

dynamic frequency selection (DFS) 5-1

dynamic tunnel 18-1

E

EIRP 3-12, 8-1, 22-1

enable password 4-7

enable secret password 4-7

encrypted software image 4-39

encryption for passwords 4-7

encryption mode cipher command 11-1

Enhanced Distributed Channel Access (EDCA) 1-7

error messages

setting the display destination device 17-5

severity levels 17-7

system message format 17-2

Ethernet indicator 19-1

Ethertype protocols

protocols

Ethertype 24-2

Express Security page 2-4

Extensible Authentication Protocol

See EAP

extensions, Aironet 4-40

F

Fast Ethernet Switch mobile interface card (FESMIC) 2-1

Fast Secure Roaming 3-9

fast secure roaming 25-1

and WDS 25-4

authentication server 25-5

features 1-7

filters

configuring using CLI 20-2

protocol 24-1

forward-delay time 12-6

frequencies 6-1, 6-2, 6-3, 6-4

FTP

accessing MIB files 23-2

G

get-bulk-request operation 21-2

get-next-request operation 21-2, 21-3

get-request operation 21-2, 21-3

get-response operation 21-2

GPRS 1-4

group key updates 14-23

H

history table, level and number of syslog messages 17-8

home agent

tunnel template 18-1

host name, ARPANET rules 4-1

hostname command 4-1

I

IAPP messaging 3-6

IDS Mobile Networks 18-4

image, operating system 19-5

indicators 19-1

infrastructure-client command 3-7

infrastructure device 3-7

infrastructure SSID command 10-2

Interior Gateway Protocol (IGP) 1-4

IP address 2-3

release and renew 2-1

ip domain-lookup command 4-3

ip domain-name command 4-2

ip multicast-routing command 18-1, 18-2

ip name-server command 4-3

ip pim command 18-1, 18-2

IP port protocols 24-4

IP protocols

protocols

IP 24-3

IPSec

crypto map 18-4

tunnel template 18-4

ISO designators for protocols 24-1

K

KCK GL-4

KEK GL-4

key features 1-7

key management types 11-8

L

LEAP

setting on client and access point 14-25

LED indicators

Ethernet 19-1

radio traffic 19-1

status 19-1

Lightweight AP Protocol (LWAPP) 3-7

Load balancing 4-40

load balancing (wireless bridge) 3-5

login authentication

with RADIUS 4-24

with TACACS+ 4-34, 4-35

login authentication command 4-25

login banners 4-3

log messages

See system message logging

loopback

crypto map 18-4

M

MAC address

authentication 14-6

troubleshooting 19-3

Message Authentication Code GL-5

Message Integrity Check

See MIC

Message Integrity Code (MIC), definition GL-5

message-of-the-day (MOTD) 4-3

messages

to users through banners 4-3

method list 4-21

Metropolitan Mobile Networks (MMN) 3-3

MIBs

accessing files with FTP 23-2

location of files 23-2

overview 21-1

SNMP interaction with 21-3

MIC 4-40, 11-1, 19-3

Mobile IP

tunnel 3-8

modes

bridge 3-3, 3-7, 3-8

world 3-11

MoIP tunnel 1-5

monitoring, CDP 13-4

multicast 18-1

tunnel template 18-4

tunnel templates 18-1

multiple basic SSIDs (multiple BSSIDs)

description 10-3

requirements and guidelines 10-3

multiple client profiles

configuring WMIC 9-3, 9-5

N

name-to-address translation 4-3

Network-EAP 14-3

Network Time Protocol

See NTP

non-Cisco client 3-8

non-root access point 3-2

non-root bridge

infrastructure SSID 10-2

NTP

associations

authenticating 4-47

enabling broadcast messages 4-50

peer 4-49

server 4-49

default configuration 4-47

displaying the configuration 4-54

overview 4-41

restricting access

creating an access group 4-52

disabling NTP services per interface 4-53

source IP address, configuring 4-54

stratum 4-41

synchronizing devices 4-49

time

synchronizing 4-41

ntp authenticate command 4-47

ntp peer command 4-49

O

OFDM 1-8

OFDM modulation 8-2

P

pairwise GL-5

Pairwise Master Key (PMK) GL-5

password reset 19-3

passwords

default configuration 4-6

encrypting 4-7

setting

enable 4-6

enable secret 4-7

with usernames 4-9

per-VLAN Spanning Tree (PVST) 12-2

PKI

point-to-multipoint bridge 3-4

point-to-point bridging 3-3

power client command 8-3

power level, maximum 8-4

preferential treatment of traffic

See QoS

pre-shared key 14-23

primary intersection 1-3

privilege levels

exiting 4-11

logging into 4-11

overview 4-5, 4-10

setting a command with 4-10

prompt command 4-1

protocol filters 20-2, 24-1

protocols

IP port 24-4

public key infrastructure

See PKI

Q

QoS

configuration guidelines 15-4

impact on wireless LAN 15-2

overview 15-1

precedence 15-3

quality of service

See QoS

R

radar 7-1

Transmission Power Contro and Dynamic Frequency Selection 5-1, 7-1

radio

configuring transmit power 8-2, 8-3

indicator 19-1

radio channel

frequency 5-2

number 5-2

width 5-3

radio management 25-1

radio type 5-2, 8-2

RADIUS

administrator access 4-21

attributes

vendor-proprietary 4-30

vendor-specific 4-29

configuring

accounting 4-28

authentication 4-24

authorization 4-27

communication, global 4-22, 4-28

communication, per-server 4-21, 4-22

multiple UDP ports 4-22

default configuration 4-21

defining AAA server groups 4-25

displaying the configuration 4-31

identifying the server 4-21

limiting the services to the user 4-27

method list 4-21

operation of 4-20

overview 4-19

SSID 10-2

suggested network environments 4-19

tracking services accessed by user 4-28

radius-server host command 4-23

range 8-5

rate limit, logging 17-9

redundancy (wireless bridge) 3-5

regulatory

domains 6-2, 6-4

regulatory domains3-12to 3-16, 6-1, 6-3

regulatory limits 3-11

release and renew the IP address 2-1

reloading access point image 19-5

Remote Authentication Dial-In User Service

See RADIUS

restricting access

NTP services 4-52

passwords and privilege levels 4-5

TACACS+ 4-32

reverse tunneling

tunnel templates 18-1

RFC

1157, SNMPv1 21-2

1305, NTP 4-41

1901, SNMPv2C 21-2

1902 to 1907, SNMPv2 21-2

roaming, fast secure roaming using CCKM 25-2

role 3-1

station-role command 3-1

roles

access point 3-2

bridge 3-2

workgroup bridge 3-6

root access point 3-2

root port 12-1

router mobile command 18-1, 18-2

S

secondary intersection 1-3

secure remote connections 4-39

Secure Shell

See SSH

Secure Shell (SSH)

See SSH

security 2-4

protocol 4-21

root device and non-root bridge settings 14-25

synchronizing 14-25

troubleshooting 19-3

security settings, Express Security page 2-4

self-healing wireless LAN 25-4

sequence numbers in log messages 17-6

server group

AAA 4-25

service set identifier (SSID) 3-7, 10-1

set BOOT command 19-6

set command 19-6

set next hop loopback command 18-4

set-request operation 21-3

severity levels, defining in system messages 17-7

shared-key authentication 14-2

show controller dot11radio command 8-8

show controllers dot11Radio command 5-2, 8-2

show crypto ipsec command 18-5

show ip mobile router command 18-5

show ip mobile tunnel command 18-2

show vlan 16-6

Simple Network Management Protocol

See SNMP

SNMP

accessing MIB variables with 21-3

agent

described 21-3

disabling 21-4

community strings

configuring 21-4

overview 21-3

configuration examples 21-9

default configuration 21-4

limiting system log messages to NMS 17-8

manager functions 21-2

MIBs, location of 23-2

overview 21-1, 21-3

snmp-server view 21-9

status, displaying 21-10

system contact and location 21-9

trap manager, configuring 21-8

traps

described 21-2

enabling 21-6

overview 21-1, 21-3

types of 21-6

versions supported 21-2

software images

delete from Flash 19-5

spanning-tree

root port 12-1

Spanning Tree Protocol (STP) 12-1

Spanning Tree Protocol (wireless bridge)

See STP

speed command 8-6

SSH

crypto software image 4-39

described 4-39

description 2-2

displaying settings 4-40

SSH Communications Security, Ltd. 2-2

SSID

2.4-GHz radio 10-2

configuring 10-2

default (tsunami) 19-3

default configuration 10-2

disable 10-2

infrastructure SSID 10-2

RADIUS 10-2

troubleshooting 19-3

understanding 10-1

VLAN 2-4, 4-12, 10-3

without VLANs 4-11

static ARP 3-8

static WEP 4-11

with open authentication, setting on client and access point 14-25

with shared key authentication, setting on client and access point 14-25

station-role command 3-1

statistics

CDP 13-4

SNMP input and output 21-10

status indicators 19-1

STP

BPDU message exchange 12-2

designated port, defined 12-3

designated switch, defined 12-3

displaying status 12-14

inferior BPDU 12-3

interface states

blocking 12-6

disabled 12-7

forwarding 12-6, 12-7

learning 12-7

listening 12-7

overview 12-5

overview 12-1

redundant bridging 3-5

root port, defined 12-3

timers, described 12-4

stratum, NTP 4-41

summer time 4-46

syslog

See system message logging

system clock 4-41

configuring

daylight saving time 4-46

manually 4-44

summer time 4-46

time zones 4-45

displaying the time and date 4-44

overview 4-41

See also NTP

system message logging

default configuration 17-3

defining error message severity levels 17-7

disabling 17-4

displaying the configuration 17-11

enabling 17-4

facility keywords, described 17-11

level keywords, described 17-8

limiting messages 17-8

message format 17-2

overview 17-1

rate limit 17-9

sequence numbers, enabling and disabling 17-6

setting the display destination device 17-5

timestamps, enabling and disabling 17-6

UNIX syslog servers

configuring the daemon 17-10

configuring the logging facility 17-10

facilities supported 17-11

system name 4-1

manual configuration 4-1

T

TAC 19-1

TACACS+

accounting, defined 4-32

authentication, defined 4-32

authorization, defined 4-32

configuring

accounting 4-37

authentication key 4-34

authorization 4-36

login authentication 4-34, 4-35

default configuration 4-33

displaying the configuration 4-38

identifying the server 4-34

limiting the services to the user 4-36

operation of 4-33

overview 4-32

tracking services accessed by user 4-37

Telnet 2-1, 2-2

Temporal Key Integrity Protocol (TKIP) 11-1

Terminal Access Controller Access Control System Plus

See TACACS+

TFTP 19-5

tftp_init command 19-5

throughput 8-5

time

See NTP and system clock 4-41

timestamps in log messages 17-6

time zones 4-45

TKIP 4-40

Transmission Power Control (TPC) 5-1, 7-1

transmission power level 5-1, 7-1

transmit power 8-2, 8-3

client 8-3

regulatory limits 3-11

transmit power levels

supported by country3-11to 3-16

transmit speed 8-6

traps

configuring managers 21-6

defined 21-2

enabling 21-6

notification types 21-6

overview 21-1, 21-3

Tropos access point 3-8

troubleshooting 19-1

with CiscoWorks 21-3

with system message logging 17-1

tunnel 1-5

tunnel template

apply 18-2

dynamic tunnel 18-1

for multicast 18-1

IPSec 18-4

reverse tunneling 18-1

U

universal workgroup bridge 3-8

bridge

universal workgroup bridge 3-8

interoperability 3-6

multiple client profiles

multiple client profiles

description     1

world mode 3-6

universial workgroup bridge

static ARP 3-8

UNIX syslog servers

daemon configuration 17-10

facilities supported 17-11

message logging configuration 17-10

username-based authentication 4-9

V

VLAN

and bridges 16-2

configuring 16-3

overview 16-1

SSID 2-4, 4-11, 4-12, 10-3

with wireless bridges 16-3

vlan command 10-2

W

WDS

access point 25-2

and fast secure roaming 25-4

and WMIC 25-1

CLI commands 25-9

guidelines and requirements 25-4

universal workgroup bridge 3-9

web site

Cisco Software Center 19-7

WEP

configuring key 11-2

described 11-2

key example 11-5

key restrictions 11-4

keys 19-3

troubleshooting 19-3

with EAP 14-3

Wi-Fi Multimedia

See WMM

Wi-Fi Protected Access

See WPA

Wi-Fi Protected Access (WPA) 4-13

Wired Equivalent Privacy

See WEP

wireless bridges 16-3

Wireless Domain Services

See WDS

Wireless Domain Services (WDS) 25-1

WMIC

and WDS 25-1

multiple client profiles 9-3, 9-5

WMM

workgroup bridge 3-6

infrastructure-client 3-7

infrastructure SSID 10-2

world mode 3-11

802.11d 3-11

Cisco legacy 3-11

description 3-6

enabling and disabling 3-11

world-mode command 3-6

WPA 4-11

cipher suite 11-1

description 14-6

key management 14-6

WPA2 1-7