Reference Guide for HP ProCurve MSM7xx Controllers CLI ProCurve MSM7xx 5400zl Switches ProCurve Controllers CLI Installation and Getting Started Guide Reference Guide
HP ProCurve MSM7xx Controllers CLI Reference Guide
Copyright and Disclaimer Notices © Copyright 2009 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. This document contains proprietary information, which is protected by copyright. No part of this document may be photocopied, reproduced, or translated into another language without the prior written consent of Hewlett-Packard.
Contents In this Contents section, new to 5.3.x contexts and commands are preceded with an asterisk “*” and formatted in green like this: * new context * new command 1 Introduction About this guide ...........................................................................................................1-2 Products covered...................................................................................................1-2 HP ProCurve Product Naming ........................................................
ping ..........................................................................................................................2-2 ps .............................................................................................................................2-3 quit...........................................................................................................................2-3 show license .........................................................................................................
Config context ..............................................................................................................2-9 * dhcp public ip default lease period..................................................................2-9 * dhcp public ip subnet.........................................................................................2-9 certificate................................................................................................................2-9 certificate binding..............
web access interface gre ....................................................................................2-15 web access lan .....................................................................................................2-15 web access vpn ....................................................................................................2-15 dhcp mode ............................................................................................................2-16 dhcp server ......................
snmp-server trap syslog-severity .......................................................................2-23 snmp-server ..........................................................................................................2-23 snmp-server access port-1..................................................................................2-23 snmp-server allow ...............................................................................................2-23 snmp-server chassis-id............................
soap-server ssl with client certificate ...............................................................2-30 soap-server access interface gre........................................................................2-30 soap-server access lan ........................................................................................2-30 soap-server access vpn .......................................................................................2-31 snmp-server trap vpn-connection.................................
service controller ap authentication refresh-rate............................................2-37 service controller ap authentication source file..............................................2-38 service controller ap authentication source local...........................................2-38 service controller ap authentication source radius ........................................2-38 service controller discovery...............................................................................
active-directory check attribute ........................................................................2-45 active-directory check user access ...................................................................2-45 active-directory device name .............................................................................2-45 active-directory domain......................................................................................2-45 active-directory group................................................
* authorize_net transaction key ........................................................................2-52 * ads presentation with frameset ......................................................................2-52 authentication http ..............................................................................................2-52 authentication https ............................................................................................2-52 noc access internet.......................................
Default Session profile context ................................................................................2-61 accounting interim update .................................................................................2-61 idle timeout ..........................................................................................................2-61 maximum input octets ........................................................................................2-61 maximum input packets .......................
access-controlled virtual ap ...............................................................................2-71 active .....................................................................................................................2-71 chargeable user identity .....................................................................................2-72 control method ....................................................................................................2-72 egress vlan .......................
pppoe unnumbered .............................................................................................2-81 ip nat outside source static ................................................................................2-81 ip rip authentication key-chain ..........................................................................2-82 ip rip authentication mode .................................................................................2-82 ip rip authentication string...............................
wpa-psk.................................................................................................................2-91 authentication server request radius cui ..........................................................2-91 dot1x session page ..............................................................................................2-91 wireless filters......................................................................................................2-91 wireless filters mac .....................
html redirection .................................................................................................2-100 local nas id..........................................................................................................2-100 bandwidth...........................................................................................................2-100 bandwidth default rates ....................................................................................
radius-server key 2 ............................................................................................2-108 radius-server message-authenticator ..............................................................2-108 radius-server name ............................................................................................2-108 radius-server nasid ............................................................................................2-109 radius-server timeout .................................
Syslog destination context ......................................................................................2-115 active ...................................................................................................................2-115 logging facility....................................................................................................2-115 logging host ........................................................................................................2-115 logging prefix .....
online time limit.................................................................................................2-123 online time limit.................................................................................................2-123 start time.............................................................................................................2-123 subscription plan name.....................................................................................2-123 * public ip reservation ..........
contact ................................................................................................................2-131 location ...............................................................................................................2-131 product type .......................................................................................................2-131 Controlled Network AP Group context.................................................................2-132 execute action..................
inherit untagged stp...........................................................................................2-138 bridge protocol ieee vlan ..................................................................................2-138 inherit vlan stp ...................................................................................................2-138 inherit local mesh qos .......................................................................................2-138 local mesh ip qos profile..................
provisioning local mesh port............................................................................2-145 provisioning local mesh security.....................................................................2-145 provisioning local mesh security.....................................................................2-145 provisioning local mesh type ...........................................................................2-146 country code .................................................................
end .......................................................................................................................2-153 inherit ..................................................................................................................2-153 RADIUS Profile context ..........................................................................................2-155 end .......................................................................................................................
* ingress traffic type..........................................................................................2-161 * mac authentication.........................................................................................2-162 * mac filter list ...................................................................................................2-162 * port name ........................................................................................................2-162 * port type ......................
Alphabetical list of commands In this alphabetical list, new to 5.3.
* dhcp public ip subnet 2-9 dhcp relay 2-101 dhcp relay 2-17 dhcp relay access centralized clients 2-18 dhcp relay access lan 2-18 dhcp relay active 2-102 dhcp relay circuit id 2-102 * dhcp relay circuit id 2-17 dhcp relay extend internet port 2-18 dhcp relay remote id 2-102 * dhcp relay remote id 2-18 dhcp relay subnet 2-102 dhcp server 2-102 dhcp server 2-16 dhcp server access centralized clients 2-17 dhcp server access lan 2-17 dhcp server controller 2-16 dhcp server controller discovery 2-16 dhcp server
inherit 2-159 inherit 8021x 2-137 inherit l3subnets 2-139 inherit local mesh qos 2-138 inherit sensor 2-136 inherit service availability 2-139 * inherit switch ports 2-139 inherit untagged stp 2-138 inherit vlan stp 2-138 initial discovery time 2-157 initial login time allocation 2-122 intercept traffic 2-67 interface 2-113 interface 2-144 interface ethernet 2-10 interface gre 2-11 interface ip 2-11 interface pptp client-default 2-11 interface provisioninig 2-144 interface vlan 2-75 interface vlan 2-77 * in
noc access interface vlan 2-54 noc access internet 2-52 noc access vpn 2-53 noc allow 2-53 noc authentication 2-53 noc ssl ca-certificate 2-59 noc ssl certificate 2-59 notify user location changes 2-60 nslookup 2-2 ntp protocol 2-19 ntp server 2-19 ntp server 2-21 ntp server failure trap 2-21 online time limit 2-123 online time limit 2-123 outgoing traffic network 2-113 passive-interface 2-119 passive-interface 2-82 passive-interface 2-84 * password 2-125 password 2-73 peer id 2-113 peer ip address 2-111 pe
service controller ap authentication credentials 2-37 service controller ap authentication enable 2-37 service controller ap authentication file 2-37 service controller ap authentication radius-server 2-37 service controller ap authentication refresh-rate 2-37 service controller ap authentication source file 2-38 service controller ap authentication source local 2-38 service controller ap authentication source radius 2-38 service controller discovery 2-38 service controller discovery interface internet-port
subscription plan name 2-123 * switch port 2-135 syslog 2-135 system accounting 2-51 termination action 2-68 top 2-3 traceroute 2-3 transmit key 2-90 transmit power 2-150 transport page 2-59 upstream diffserv tagging 2-99 use access-list 2-56 use access-list unauth 2-56 * user 2-126 user defined attribute 2-69 * user name 2-125 user profile 2-42 user tracking 2-46 user tracking destination 2-47 user tracking filter 2-47 user tracking port 2-47 username 2-10 username 2-74 * version 2-126 virtual ap 2-11 virt
Chapter 1: Introduction 1 Introduction Contents About this guide ...........................................................................................................1-2 Products covered...................................................................................................1-2 HP ProCurve Product Naming .............................................................................1-2 Important terms ............................................................................................
Introduction About this guide About this guide This guide explains how to work with the Command Line Interface (CLI) on HP ProCurve Networking MSM7xx Controllers.
Introduction About this guide Colubris name HP ProCurve name MAP-320R MultiService Access Point MSM310-R Access Point MAP-330 MultiService Access Point MSM320 Access Point MAP-330R MultiService Access Point MSM320-R Access Point MAP-330 AP+Sensor MultiService Access Point MSM325 Access Point with Sensor MAP-625 MultiService Access Point MSM422 Access Point MAP-630 AP+Sensor MultiService Access Point MSM335 Access Point with Sensor WCB-200 Wireless Client Bridge M111 Client Bridge Visitor Ma
Introduction HP ProCurve Networking support Example Description end [force] Items enclosed in square brackets are optional. You can either include them or not. Do not include the brackets. In this example you can either include “force” or omit it. firewall mode (high|low|none) Items enclosed in parenthesis and separated by a vertical line indicate a choice. Specify only one of the items. In this example, you must specify ’high’, ’low’, or ’none’.
Introduction Online documentation Online documentation For the latest documentation, visit the HP ProCurve Networking manuals Web page at: www.procurve.com/manuals. Configuring CLI support Using the service controller management tool, open the CLI configuration page. Select Service controller >> Management > CLI. Use this page to enable/disable CLI support via an SSH or serial connection. A maximum of three concurrent CLI sessions are supported regardless of the connection type.
Introduction Entering strings Note SSH connections to the CLI can be made on any active interface. Support for each interface must be explicitly enabled under Security. The login credentials for SSH connections are the same as those defined under Manager account. By default, both username and password are set to admin. SSH logins always use the local manager username and password, even if Administrative user authentication is set to use a RADIUS server.
Introduction Context hierarchy Context hierarchy CLI commands are grouped into functional contexts. The following table show the context hierarchy and the command used to switch from the parent context: Context hierarchy Command to switch from parent context View context (This is the first context. No command is needed.
Introduction Sample CLI session Sample CLI session This sample CLI session shows you how to set the WAN port to use a static IP address, disable NAT, and add an alternate IP address. (The CLI prompt is shown in bold.) CLI> enable CLI# config CLI(config)# interface ip wan CLI(config-if-ip)# ip address 192.168.66.1/24 CLI(config-if-ip)# ip address mode static CLI(config-if-ip)# no ip nat CLI(config-if-ip)# ip address alternate 192.168.23.
Chapter 2: CLI commands 2 CLI commands
CLI commands View context Path: View This is the root of the command tree. arping Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl arping [ -AbDfhqUV] [ -c ] [ -w ] [ -s ] -I Pings a destination on a device interface using ARP packets. enable Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl enable Switches to the enable context. iperf Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl iperf -c host [-t time] Runs a performance throughput test.
CLI commands ps Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl ps Displays all running processes. quit Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl quit Quits the CLI. show license Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl show license (eula | gpl | other) Displays license information. show logging filtered Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl show logging [filtered] Displays the system log.
CLI commands Enable context Path: View > Enable This context provides access to various utilities. reboot device Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl reboot device Restarts the system. show certificate Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl show certificate Display current certificates. show certificate binding Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl show certificate binding Display how the certificates are used.
CLI commands arping Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl arping [ -AbDfhqUV] [ -c ] [ -w ] [ -s ] -I Pings a destination on a device interface using ARP packets.
CLI commands show bridge forwarding Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl show bridge forwarding Show bridge forwarding information. show dns cache Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl show dns cache [] Show DNS cache entries. Specify a serial number to display detailed information. show interfaces Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl show interfaces Show networking interfaces.
CLI commands show web content Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl show web content Show all files inside the access points detected nearby. show client log Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl show client log [] Display client station log. Enter the MAC address to display more details for a specific client station. show radius statistics Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl show radius statistics Show RADIUS server statistics.
CLI commands controlled network Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl controlled network (ap | group | base) [] [] Create/use the controlled network entity. show controlled network config Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl show controlled network config Print configuration for all Controlled Network entities.
CLI commands Config context Path: View > Enable > Config This is the root context for all configuration commands. dhcp public ip default lease period Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dhcp public ip default lease period Sets the default lease time for the DHCP public IP subnet pool. dhcp public ip subnet Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dhcp public ip subnet Enable DHCP server IP Address pool for Access Controller public IP subnet functionality.
CLI commands factory settings Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl factory settings Resets the system configuration to factory default settings. interface ethernet Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl interface ethernet (port-1|port-2) Switches to the specified Ethernet interface context. reboot device Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl reboot device Restarts the system.
CLI commands interface ip Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl interface ip (lan | wan) Switches to the specified IP interface context. interface pptp client-default Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl interface pptp client-default Switches to the PPTP client interface context. interface gre Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl interface gre Switches to the specified GRE interface or creates a new GRE interface with the specified name.
CLI commands mac list Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl mac list Edit a MAC list. no mac list Delete a MAC list by name. show mac list Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl show mac list [] Display current MAC list, or one list in detail. ipsec policy Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl ipsec policy Switches to the specified IPSec policy or creates a new IPSec policy with the specified name.
CLI commands ip http port Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl ip http port Sets the port number to use for HTTP access to the service controller. Parameters Port number. Range: 1 - 65535. Description HTTP connections made to this port are met with a warning and the browser is redirected to the secure web server port. By default. this parameter is set to port 80.
CLI commands snmp-server trap web-login Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl snmp-server trap web-login Send a trap each time an administrator login is accepted. no snmp-server trap web-login Do not send a trap each time an administrator login is accepted. snmp-server trap web-logout Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl snmp-server trap web-logout Send a trap each time an administrator logs out.
CLI commands web access internet-port Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl web access internet-port Enables access to the management tool via the Internet port. no web access internet-port Blocks access to the management tool via the Internet port. web access lan-port Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl web access lan-port Enables access to the management tool via the LAN port. no web access lan-port Blocks access to the management tool via the LAN port.
CLI commands no web access vpn Blocks access to the management tool via a VPN connection. dhcp mode Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dhcp mode (server | relay | none) Sets whether the service controller operates as a DHCP server or DHCP relay agent. dhcp server Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dhcp server lan Switches to the DHCP server context.
CLI commands no dhcp server controller discovery Do not send the list of controller IP addresses with DHCP answers. dhcp server logout html user Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dhcp server logout html user Logout HTML user upon discover request. no dhcp server logout html user Do not logout HTML user upon discover request.
CLI commands dhcp relay remote id Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dhcp relay remote id Sets the Option 82 remote ID. no dhcp relay remote id Clears the Option 82 remote ID. dhcp relay access centralized clients Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dhcp relay access centralized clients Listen for DHCP requests from centralized access-controlled client stations.
CLI commands clock auto adjust dst Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl clock auto adjust dst Automatically adjust clock for daylight savings changes. no clock auto adjust dst Do not automatically adjust clock for daylight savings changes. clock timezone Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl clock timezone Sets the time zone the service controller is operating in. Parameters Offset from GMT as follows: +-HOUR:MIN.
CLI commands Parameters Day of the month. Range 1 - 31. Weekday. Valid values are: "sun", "mon", "tue", "wed", "thu", "fri", "sat". Month. Valid values are: "jan", "feb", "mar", "apr", "may", "jun", "jul", "aug", "sep", "oct", "nov", "dec".
CLI commands Rule of the form: The first [Weekday] on or after the [Day]th of [Month] at [Time]. Rule of the form: The first [Weekday] on or before the [Day]th of [Month] at [Time]. ntp server Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl ntp server Adds a network time server. Parameters Index of the time server in the list. Up to 20 time servers are supported. Time servers are checked in the order that they appear in the list.
CLI commands Parameters
CLI commands snmp-server trap syslog-severity Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl snmp-server trap syslog-severity Set the severity level of syslog messages that will trigger a trap. no snmp-server trap syslog-severity Do not send this trap. snmp-server Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl snmp-server Enables the SNMP agent. no snmp-server Disables the SNMP agent.
CLI commands snmp-server contact Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl snmp-server contact Specifies contact information. no snmp-server contact Deletes contact information. Parameters Email address. snmp-server heartbeat period Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl snmp-server heartbeat period Sets the interval between sending heartbeat traps. Parameters Heartbeat interval in seconds.
CLI commands snmp-server readwrite Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl snmp-server readwrite Sets the read-write community string. no snmp-server readwrite Deletes the read-write community string. snmp-server trap Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl snmp-server trap Enables support for SNMP traps. no snmp-server trap Disables support for SNMP traps.
CLI commands snmp-server trap link-state Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl snmp-server trap link-state Send a trap when the link state changes on any interface. no snmp-server trap link-state Do not send this trap. snmp-server trap snmp-authentication Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl snmp-server trap snmp-authentication Send a trap each time an SNMP request fails to supply the correct community name.
CLI commands Parameters Specifies the name of the VLAN. snmp-server access interface gre Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl snmp-server access interface gre Enables access to SNMP via the specified GRE tunnel. no snmp-server access interface gre Removes access to SNMP via the specified GRE tunnel. snmp-server access port-2 Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl snmp-server access port-2 Enables SNMP access on the upstream port.
CLI commands snmp-server trap satellite-unreachable Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl snmp-server trap satellite-unreachable Send a trap when a satellite cannot be reached. no snmp-server trap satellite-unreachable Ignore unreachable satellites. snmp-server user Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl snmp-server user Creates a new SNMP user or switches to the SNMP user context with the specified user name. no snmp-server user Deletes the specified SNMP user.
CLI commands soap-server access port-1 Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl soap-server access port-1 Enables SOAP access on the downstream port. no soap-server access port-1 Blocks SOAP access on the downstream port. soap-server access port-2 Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl soap-server access port-2 Enables SOAP access on the upstream port. no soap-server access port-2 Blocks SOAP access on the upstream port.
CLI commands soap-server http authentication username Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl soap-server http authentication username Set the SOAP server HTTP authentication username. soap-server port Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl soap-server port Sets the port the service controller will use to respond to SOAP requests. Parameters SOAP port number. Range 1 - 65535.
CLI commands soap-server access vpn Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl soap-server access vpn Enables access to the management tool via a VPN connection. no soap-server access vpn Blocks access to the management tool via a VPN connection. snmp-server trap vpn-connection Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl snmp-server trap vpn-connection Send a trap when a user establishes a VPN connection with the service controller.
CLI commands firmware-update automatic Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl firmware-update automatic Enables scheduled firmware upgrades. no firmware-update automatic Disables scheduled firmware upgrade. The service controller can automatically retrieve and install firmware from a local or remote URL at preset times. By placing service controller firmware on a web or ftp server, you can automate the update process for multiple units.
CLI commands firmware-update weekday Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl firmware-update weekday (everyday | monday | tuesday | wednesday | thursday | friday | saturday | sunday) Sets the day when the scheduled firmware upgrade will take place. snmp-server trap firmware-update Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl snmp-server trap firmware-update Send a trap on firmware update. no snmp-server trap firmware-update Do not send a trap on firmware update.
CLI commands no ip name-server dynamic Disables dynamic DNS assignment. ip name-server interception Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl ip name-server interception Intercepts all DNS requests from users and relays them to configured servers. no ip name-server interception Process DNS requests addressed to this device only.
CLI commands radius-server profile Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl radius-server profile Creates a new RADIUS profile or switches to the RADIUS context with the specified profile name. no radius-server profile Deletes the specified RADIUS profile. access controller Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl access controller Switches to the access controller context.
CLI commands ftp://host/path certificate ssl Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl certificate ssl Loads a new SSL certificate using the URI. session profile default Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl session profile default Switches to the session profile context. session profile Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl session profile Switches to the session profile context. no session profile Remove a session profile.
CLI commands discovery protocol device-id Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl discovery protocol device-id Overwrite the device-id field of information packets (the service controller serial number is not used). no discovery protocol device-id Do not overwrite the device-id field of information packets (use the service controller serial number).
CLI commands service controller ap authentication source file Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl service controller ap authentication source file Enables the use of a file authentication source. no service controller ap authentication source file Disables the use of a file authentication source.
CLI commands no service controller discovery interface lan-port Allow discovery on the LAN interface. service controller primary Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl service controller primary Become the Primary service controller. no service controller primary Become a secondary service controller.
CLI commands bandwidth control internet-port low Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl bandwidth control internet-port low Sets the bandwidth rates (Tx minimum, Tx maximum, Rx minimum, and Rx maximum) for traffic classed as Low.
CLI commands bandwidth control internet-port normal Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl bandwidth control internet-port normal Sets the bandwidth rates (Tx minimum, Tx maximum, Rx minimum, and Rx maximum) for traffic classed as Normal.
CLI commands show user profiles Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl show user profiles [] Display current local users. show user profiles details Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl show user profiles details Display detailed information about one user. user profile Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl user profile Adds or edits the specified username in the local user list.
CLI commands no dot1x reauth terminate Disabled this option to block client traffic during re-authentication and only activate traffic again if authentication succeeds. dot1x supplicant timeout Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl 802.1x supplicant time-out Sets the 802.1X supplicant time-out. Parameters time-out in seconds. dynamic key Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dynamic key Enables dynamic key support for 802.1X and WPA.
CLI commands radius-server client Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl radius-server client Enable radius clients list. no radius-server client Disable radius clients list. radius-server local eap-peap Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl radius-server local eap-peap Allow EAP-PEAP. no radius-server local eap-peap Disallow EAP-PEAP. radius-server local eap-tls Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl radius-server local eap-tls Allow EAP-TLS.
CLI commands no radius-server ssid detection nas-id Do not use NAS-ID for SSID detection. show radius-server Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl show radius-server Display current RADIUS server configuration. active-directory check attribute Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl active-directory check attribute Set the name of the AD attribute to check for. no active-directory check attribute Clear the name of the AD attribute to check for.
CLI commands active-directory group Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl active-directory group Create or go to an Active Directory group. no active-directory group Remove an Active Directory group. active-directory group order Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl active-directory group order Reorder an Active Directory group.
CLI commands no user tracking Disable capture of usage data. user tracking destination Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl user tracking destination Specify to where the detailed syslog packets should be sent. user tracking filter Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl user tracking filter A comma-separated list of filters (username or subnet).
CLI commands igmp proxy Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl igmp proxy Enable IGMP proxy. no igmp proxy Disable IGMP proxy. igmp proxy downstream interface Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl igmp proxy downstream interface Set the downstream IGMP port. igmp proxy upstream interface Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl igmp proxy upstream interface Set the upstream IGMP port.
CLI commands Access Controller context Path: View > Enable > Config > Access Controller All global access controller configuration takes place here. end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end Switches to parent context. ads presentation Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl ads presentation Enable advertisement display at regular intervals for authenticated users. no ads presentation Disable advertisement display for authenticated users.
CLI commands This option enables users to access the wireless network without reconfiguring their networking settings. For example, by default the service controller creates the wireless network on the subnet 192.168.1.0. If a client station is pre-configured with the address 10.10.4.99, it will still be able to connect to the service controller without changing its address, or its settings for DNS server and default gateway.
CLI commands system accounting Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl system accounting Enables RADIUS accounting support. no system accounting Disables RADIUS accounting support. remember delay Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl remember delay Length of time to remember users. Users who return later than this delay interval, are presented with the login page instead of being re-authenticated.
CLI commands authorize_net payment url Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl authorize_net payment url Set the payment URL for the Authorize.Net payment service. authorize_net transaction key Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl authorize_net transaction key Set the transaction key for the Authorize.Net payment service.
CLI commands noc access vpn Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl noc access vpn Accept authentication requests on VPN connections. no noc access vpn Do not accept authentication requests on VPN connections. noc allow Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl noc allow / Adds an IP address or subnet to the list of destinations that the service controller will accept user login authentication requests from when NOC authentication is active.
CLI commands noc access interface vlan Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl noc access interface vlan Adds the specified VLAN to the list of interfaces that authentication requests are accepted on. no noc access interface vlan Removes the specified VLAN from the list of interfaces that authentication requests are accepted on.
CLI commands wispr login url Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl wispr login url Specifies the WISPr login url assigned to the service controller. no wispr login url Deletes the WISPr login url assigned to the service controller. wispr logoff url Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl wispr logoff url Specifies the WISPr logoff url assigned to the service controller. no wispr logoff url Deletes the WISPr logoff url assigned to the service controller.
CLI commands IP address or domain name (up to 107 characters in length) Subnet address. Include the network mask as follows: address/subnet mask For example: 192.168.30.0/24 Use the keyword all to match any address. Use the keyword none if the protocol does not take an address range (ICMP for example). Specify a specific port to check or a port range as follows: none: Used with ICMP (since it has no ports). all: Check all ports.
CLI commands http proxy upstream Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl http proxy upstream Specifies the host:port of the HTTP Proxy Upstream server. no http proxy upstream Do not use an HTTP Proxy Upstream server. https ssl certificate Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl https ssl certificate Specifies the URL that points to an SSL certificate that will replace the default certificate on the service controller.
CLI commands ipass login url Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl ipass login url Specifies the URL of the IPass login page. The service controller will automatically redirect users with IPass client software to this page. no ipass login url No IPass login URL. login error url Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl login error url Specifies the URL of a login error page. no login error url No login error page.
CLI commands messages Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl messages Specifies the URL of a new message file. no messages No new messages file. Use default. noc ssl ca-certificate Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl noc ssl ca-certificate Specifies the URL of the certificate from the certificate authority (CA) that issued the NOC certificate. no noc ssl ca-certificate No CA certificate.
CLI commands welcome url Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl welcome url Specifies the URL of a welcome page. no welcome url No welcome page. notify user location changes Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl notify user location changes Notify RADIUS on location changes. no notify user location changes Do not notify RADIUS on location changes.
CLI commands Default Session profile context Path: View > Enable > Config > Default Session profile This context provides attributes that define settings for user sessions. Most of these attributes can be overridden by adding settings to a user RADIUS account. In this context, all commands add an attribute to the list, in some cases (access-list & mac address) several entries are added. The "no" form will remove the attributes.
CLI commands maximum output octets Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl maximum output octets Sets the maximum output limit in octets for all users that do not have a specific limit set in their profile. no maximum output octets Removes this attribute. maximum output packets Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl maximum output packets Sets the maximum output limit in packets for all users that do not have a specific limit set in their profile.
CLI commands session timeout Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl session timeout Sets the default session timeout for all users that do not have a specific limit set in their profile. no session timeout Removes this attribute. smtp redirection setup Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl [:t][,,] Sets basic SMTP redirection info: hostname[:port][,username,password]. no smtp redirection setup Clears basic SMTP redirection info.
CLI commands smtp redirection Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl smtp redirection Enables SMTP proxy support. no smtp redirection Disables SMTP proxy support.
CLI commands Session profile context Path: View > Enable > Config > Session profile end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end Switches to parent context. access controlled Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl access controlled Set profile as ’access controlled’. no access controlled Set profile as not ’access controlled’. access list Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl access list Set the access list. use access list Use this access list.
CLI commands use arp polling interval Use the ARP polling interval. no use arp polling interval Do not use the ARP polling interval. arp polling max count Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl arp polling max count Set the polling ARP count. use arp polling max count Use the polling ARP count. no use arp polling max count Do not use the polling ARP count.
CLI commands no use idle timeout Removes this attribute. intercept traffic Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl intercept traffic Turn on legal traffic interception. no intercept traffic Turn off legal traffic interception. use intercept traffic Use legal traffic interception. no use intercept traffic Do not use legal traffic interception. max input rate Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl max input rate Set the maximum input rate.
CLI commands use nat one-to-one Use this attribute. no use nat one-to-one Do not use this attribute. session profile Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl session profile Change this profile’s name. smtp redirection setup Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl smtp redirection setup [:t][,,] Sets basic SMTP redirection info: hostname[:port][,username,password]. no smtp redirection setup Clears basic SMTP redirection info.
CLI commands user defined attribute Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl user defined attribute ::::: Add a new user defined attribute. no user defined attribute Add a new user-defined attribute. Parameters Friendly name for this attribute. Numerical RADIUS type, 26 is Vendor-Specific. If RADIUS type is 26, contains the Vendor-Id. Put 0 if not.
CLI commands User Profile context View > Enable > Config > User Profile Use this context to modify settings for a specific user in the local user list.
CLI commands access controlled Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl access controlled Make this user access controlled. no access controlled Make this user not access controlled. access-controlled profile Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl access-controlled profile Use this session profile for this account. no access-controlled profile Do not use this session profile for this account. use access-controlled profile Use the Access Controlled profiles.
CLI commands chargeable user identity Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl chargeable user identity Set the CUI. use chargeable user identity Use the CUI. no use chargeable user identity Do not use the CUI. control method Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl control method (subscription | endtime | none) How is this account controlled? egress vlan Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl egress vlan Set the VLAN tunnel ID.
CLI commands no max user sessions This user doesn’t have a maximum concurrent sessions limit. password Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl password Change the password for this user. regular profile Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl regular profile Apply a non-ac profile. no regular profile Remove a non-ac profile. use regular profile Use the non-Access Controlled profiles. no use regular profile Do not use the non-Access Controlled profiles.
CLI commands no subscription plan Delete a subscription plan. username Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl username Change the name for this user.
CLI commands Internet interface context Path: View > Enable > Config > Internet interface This context provides commands for configuring Internet. end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end Switches to parent context. duplex Supported on: MSM710 MSM730 MSM750 MSM760 duplex (auto | half | full) Sets the duplex mode on Internet. Parameters auto Lets the service controller automatically set duplex mode based on the type of equipment it is connected to.
CLI commands ipsec vlan interface Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl ipsec vlan interface Specifies which VLAN is used by IPsec. no ipsec vlan interface Do not use a VLAN for IPsec.
CLI commands LAN interface context Path: View > Enable > Config > LAN interface This context provides commands for configuring LAN. end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end Switches to parent context. duplex Supported on: MSM710 MSM730 MSM750 MSM760 duplex (auto | half | full) Sets the duplex mode on LAN. Parameters auto Lets the service controller automatically set duplex mode based on the type of equipment it is connected to.
CLI commands ipsec vlan interface Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl ipsec vlan interface Specifies which VLAN is used by IPsec. no ipsec vlan interface Do not use a VLAN for IPsec.
CLI commands WAN IP interface context Path: View > Enable > Config > WAN IP interface This context provides commands for configuring various IP-networking related settings. pppoe client user Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl pppoe client user Sets the PPPoE username and password. no pppoe client user Deletes the PPPoE username. Parameters The username assigned to you by your ISP.
CLI commands ip nat Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl ip nat Enables Network Address Translation. no ip nat Disables Network Address Translation. nat limit port range Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl nat limit port range Reserves a range of TCP and UDP ports for each user starting at port 5000. no nat limit port range Use any port for NAT. All outgoing traffic for the user is mapped within the range.
CLI commands no pppoe auto-reconnect The service controller will not automatically attempt to reconnect if the connection is lost. pppoe mru Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl pppoe mru Specifies the maximum receive unit. Changes to this parameter should only be made according to the recommendations of your ISP. Incorrectly setting this parameter can reduce the throughput of your Internet connection. Parameters Maximum size (in bytes) of a PPPoE packet when receiving.
CLI commands IP address of the device on the internal network that traffic will be routed to. The protocol port number that the incoming traffic will be mapped to. ip rip authentication key-chain Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl ip rip authentication key-chain Specifies a keyed MD5 chain. no ip rip authentication key-chain Do not use this Keyed MD5 chain.
CLI commands ip address alternate Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl ip address alternate [] Assigns an alternate IP addresses to the Internet port. The address must be valid on the Internet. no ip address alternate [] Deletes the specified alternate IP address. The service controller uses these addresses to support its one-to-one NAT feature.
CLI commands LAN IP interface context Path: View > Enable > Config > LAN IP interface This context provides commands for configuring various IP-networking related settings for the LAN interface. end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end Switches to parent context. ip address Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl ip address / Sets a static IP address for the port. Parameters IP address. Subnet mask in CIDR format.
CLI commands no router rip Disable RIP.
CLI commands RADIUS remote configuration context Path: View > Enable > Config > RADIUS remote configuration end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end Switches to parent context. active Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl active Use a RADIUS server to fetch configuration information for the public access network. no active Do not use a RADIUS for remote configuration.
CLI commands Virtual AP context Path: View > Enable > Config > Virtual AP This context provides commands for configuring Virtual AP profiles (VAP (VSC)s). By default one profile exists with the name "". This is the default profile and cannot be deleted.
CLI commands force centralize data Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl force centralize data Force centralization of wireless client traffic when the AP is L2 connected to the LAN port of the service controller. no force centralize data Automatically determine if centralization of wireless client traffic is required. ingress interface Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl ingress vlan Sets the specified interface as the ingress interface traffic will be accepted on.
CLI commands max-association Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl max-association Sets the maximum number of clients stations that can associate with this VAP (VSC). Number of client stations. Range: 1 - 255. ssid name Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl ssid name Specifies the WLAN name (SSID) for the profile. vlan Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl vlan Assigns a VLAN ID to this VAP (VSC).
CLI commands ascii ASCII keys are much weaker than carefully chosen hex keys. You can include ASCII characters between 32 and 126, inclusive, in the key. However, note that not all client stations support non-alphanumeric characters such as spaces, punctuation, or special symbols in the key. transmit key Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl transmit key Sets the key the service controller will use to encrypt transmitted data. All four keys are used to decrypt received data.
CLI commands wpa-psk Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl wpa-psk Sets the WPA preshared key. no wpa-psk Deletes the WPA preshared key. Parameters Specify a key that is between 8 and 63 alphanumeric characters in length. It is recommended that the preshared key be at least 20 characters long, and be a mix of letters and numbers.
CLI commands wireless filters mac Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl wireless filters mac Sets the MAC address of the upstream device to send traffic to. no wireless filters mac Deletes the MAC address of the upstream device to send traffic to. wireless filters rule input Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl wireless filters rule input Adds a custom filter definition for incoming wireless traffic.
CLI commands wireless filters type Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl wireless filters type (mac | gateway | rules) Sets the type of wireless security filter to use. Parameters mac Traffic is forwarded to an upstream device with a specific MAC address. Wireless security filters use the default definitions. gateway Traffic is forwarded to the default gateway assigned to the service controller. Wireless security filters use the default definitions.
CLI commands mac authentication accounting Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl mac authentication accounting Enables RADIUS accounting for this VAP (VSC). no mac authentication accounting Disables RADIUS accounting for this VAP (VSC). mac authentication accounting radius profile Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl mac authentication accounting radius profile Sets RADIUS accounting to use the specified RADIUS profile.
CLI commands mac authentication local Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl mac authentication local Sets MAC-based authentication to use the local user list to validate the MAC addresses of client stations. no mac authentication local Do not use the local user list for MAC-based authentication. mac authentication Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl mac authentication Enables support for MAC-based authentication.
CLI commands html authentication active-directory Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl html authentication active-directory Use Active Directory (AD) to authenticate users. no html authentication active-directory Do not use Active Directory (AD) to authenticate users. html authentication local Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl html authentication local Validate HTML logins using the local user list.
CLI commands active Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl active Enable this VAP (VSC). no active Disable this VAP (VSC). beacon dtim count Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl beacon dtim count Defines the DTIM period in the beacon. Client stations use the DTIM to wake up from low-power mode to receive multicast traffic. The service controller transmits a beacon every 100 ms.
CLI commands no access lan stations Blocks traffic exchange between wireless and LAN stations. fast authentication Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl fast authentication Enables WPA2 opportunistic key caching. no fast authentication Disables WPA2 opportunistic key caching. layer3 mobility Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl layer3 mobility Enables Layer 3 mobility. no layer3 mobility Disables Layer 3 mobility.
CLI commands no qos Disables QoS for this profile. Four traffic queues are provided based on the WME standard. In order of priority, these queues are: 1: Voice traffic 2: Video traffic 3: Best effort data traffic 4: Background data traffic Each QoS priority mechanism maps traffic to one of the four traffic queues. Client stations that do not support the QoS mechanism for the profile they are connected to are always assigned to queue 3.
CLI commands wmm advertising Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl wmm advertising Enables WMM information element advertising. no wmm advertising Disables WMM information element advertising. html redirection Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl html redirection Enables support for HTML logins. no html redirection Disables support for HTML logins.
CLI commands radius accounting realms Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl radius accounting realms Use RADIUS accounting realms. no radius accounting realms Do not use RADIUS accounting realms. radius authentication realms Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl radius authentication realms Use RADIUS authentication realms. no radius authentication realms Do not use RADIUS authentication realms.
CLI commands dhcp relay active Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dhcp relay active The dhcp relay is enabled on the VAP (VSC). no dhcp relay active The dhcp relay is not enabled on the VAP (VSC). dhcp relay circuit id Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dhcp relay circuit id Sets the Option 82 circuit ID. no dhcp relay circuit id Clears the Option 82 circuit ID.
CLI commands no dhcp server dns Reset the domain name server provided to DHCP clients. dhcp server gateway Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dhcp server gateway Sets the default gateway provided to DHCP clients. no dhcp server gateway Reset the default gateway provided to DHCP clients. dhcp server range Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dhcp server range Specify the DHCP server IP address range.
CLI commands Parameters 2-104 none No wireless security. wep This option enables support for wireless users with WEP client software. 802.1x This option enables support for wireless users with 802.1X client software. The service controller supports 802.1x client software that uses EAP-TLS, EAP-TTLS, EAP-SIM, and PEAP. wep Enables the use of dynamic WEP keys for all 802.1X sessions. Dynamic key rotation occurs on key 1, which is the broadcast key. Key 0 is the pairwise key.
CLI commands VLAN interface context Path: View > Enable > Config > Internet interface > VLAN interface View > Enable > Config > LAN interface > VLAN interface This context provides commands for configuring Virtual LANs (VLANs). In this context, VLANs can be added or edited.
CLI commands vlan name Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl vlan name Change the name of this VLAN interface. ip default-gateway Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl ip default-gateway Sets the default gateway for this VLAN. no ip default-gateway Removes the default gateway for this VLAN. ip nat Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl ip nat Enable Network Address translation for this interface.
CLI commands RADIUS context Path: View > Enable > Config > RADIUS This context provides commands for configuring RADIUS profiles. end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end Switches to parent context. radius-server accounting port Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl radius-server accounting port Specifies the port to use for RADIUS accounting. Parameters Accounting port number. Range: 1 - 65535.
CLI commands radius-server deadtime Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl radius-server deadtime Sets the retry interval for access and accounting requests that time-out. If no reply is received within this interval, the service controller switches between the primary and secondary RADIUS servers (if defined). If a reply is received after the interval expires, it is ignored. Parameters Retry interval. Range: 2 - 60 seconds.
CLI commands radius-server nasid Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl radius-server nasid Sets the network access server ID you want to use for the service controller. By default, the serial number of the service controller is used. The service controller includes the NAS-ID attribute in all packets that it sends to the RADIUS server. radius-server timeout Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl radius-server timeout Activates RADIUS timeout.
CLI commands DHCP server context Path: View > Enable > Config > DHCP server This context lets you configure DHCP server settings. end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end Switches to parent context. active Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl active This range is enabled. no active This range is not enabled. gateway Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl gateway Sets the default gateway provided to DHCP clients.
CLI commands GRE interface context Path: View > Enable > Config > GRE interface Details of the GRE interface. end force Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end [force] Quits the GRE context. gre name Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl gre name Renames the current GRE interface. ip address Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl ip address / Set the local tunnel IP address and mask.
CLI commands IPsec policy context Path: View > Enable > Config > IPsec policy This context allows editing of IPSec configuration settings. end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end Switches to parent context. active Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl active Enables policy. no active Disables policy. authentication Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl authentication (x509 | psk) Selects between x509 and psk authentication.
CLI commands no dns server Resets the DNS server for this policy. incoming nat Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl incoming nat Enables NAT for incoming traffic. no incoming nat Disables NAT for incoming traffic. incoming traffic network Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl incoming traffic network / Sets the Phase 2 incoming network.
CLI commands peer ip address Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl peer ip address (| any ) Set the peer ip address for this policy. perfect forward secrecy Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl perfect forward secrecy Enable PFS. no perfect forward secrecy Disable PFS. preshared key Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl preshared key Sets the preshared key. no preshared key Removes the preshared key.
CLI commands Syslog destination context Path: View > Enable > Config > Syslog destination This context provides commands for configuring Syslog destinations. active Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl active Enables logging to the current destination. no active Disables logging to the current destination.
CLI commands end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end Switches to parent context. level Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl level Enables filtering of the log file by severity level. no level Disables filtering of the log file by severity level. level Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl level (lower | higher) (debug | info | notice | warning | error | critical | alert | emergency) Defines the severity of messages that will be logged.
CLI commands no message Disables filtering of the log file message field. message Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl message (matches | notmatches) Use this filter to include log messages. Use a regular expression to define the match criteria for the log file message field. no message Disables filtering of the log file message field. process Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl process Enables filtering of the log file by process name.
CLI commands PPTP client interface context Path: View > Enable > Config > PPTP client interface This is the PPTP client context. active Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl active Sets PPTP client connection to ’up’. no active Sets PPTP client connection to ’down’. pptp client credentials Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl pptp client credentials Sets the PPTP username and password.
CLI commands pptp client auto route discovery Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl pptp client auto route discovery Enables auto-route discovery. no pptp client auto route discovery Disables auto-route discovery. pptp client lcp echo Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl pptp client lcp echo Enables PPTP LCP echo. no pptp client lcp echo Disables PPTP LCP echo.
CLI commands Keychain context Path: View > Enable > Config > Keychain Manage a keychain: a collection of keys. end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end End current context. key Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl key Enter new key. no key Delete key with given ID. key chain name Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl key chain name Rename current keychain.
CLI commands Keys context Path: View > Enable > Config > Keychain > Keys Edit a key, as part of a keychain. end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end End current context. key-string Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl key-string Set the authentication string for this key. no key-string Remove the authentication string for this key.
CLI commands Subscription plan context Path: View > Enable > Config > Subscription plan Details about a subscription plan. end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end End current context. daily restriction Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl daily restriction Sets the daily restrictions hours. use daily restriction Enable daily restrictions. no use daily restriction Disable daily restrictions.
CLI commands online time limit Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl online time limit Use the online time limit. no online time limit Do not use the online time limit. online time limit Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl online time limit (minutes | hours | days) Sets the initial online time for an account. no online time limit Do not use the online time limit.
CLI commands no public ip subnet Removes this attribute. use public ip subnet Use this attribute. no use public ip subnet Do not use this attribute.
CLI commands SNMP user context Path: View > Enable > Config > SNMP user This context provides commands for configuring SNMP user. access level Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl access level (read-only | read-write) Specifies the access level for this SNMP user. end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end Returns to a previous context. password Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl password Specifies the password for this SNMP user.
CLI commands SNMP notification receiver context Path: View > Enable > Config > SNMP notification receiver This context provides commands for configuring SNMP notification receiver. community Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl community Specifies the community for this SNMP notification receiver. end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end Returns to a previous context.
CLI commands Active Directory Group context Path: View > Enable > Config > Active Directory Group Contains information about attributes to send when a user is related to an Active Directory group. end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end Switches to parent context. access controlled Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl access controlled Make this user access controlled. no access controlled Make this user not access controlled.
CLI commands active Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl active Enable this user account. no active Disable this user account. active-directory group name Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl active-directory group name Change the name for this user. egress vlan Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl egress vlan Set the VLAN tunnel ID. use egress vlan Use the VLAN tunnel ID. no use egress vlan Do not use the VLAN tunnel ID.
CLI commands use regular virtual ap Use only allowed Virtual APs (VSCs) for this profile. no use regular virtual ap Use any Virtual AP (VSC) for this profile.
CLI commands Controlled Network AP context Path: View > Enable > Controlled Network AP Contains commands for controlled network AP configuration. end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end Switches to parent context. execute action Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl execute action (synchronize | accept-suspicious | accept-product | rediscover) Execute an action on the entity’s devices.
CLI commands contact Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl contact Modify the contact. location Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl location Modify the location. product type Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl product type (map-320 | map-330 | map-625 | map-630 | msm410 | msm317 ) Set the product type of the AP that you are about to pre-configure. Some legacy product names are still used.
CLI commands Controlled Network AP Group context Path: View > Enable > Controlled Network AP Group Contains commands for controlled network AP Group configuration. execute action Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl execute action (synchronize | accept-suspicious | accept-product | rediscover) Execute an action on the entity’s devices. show config factory Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl show config [factory] Displays the current configuration as a list of CLI commands.
CLI commands Controlled Network Base Group context Path: View > Enable > Controlled Network Base Group Contains commands for controlled network Base Group configuration. execute action Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl execute action (synchronize | accept-suspicious | accept-product | rediscover) Execute an action on the entity’s devices.
CLI commands Controlled Network context Path: View > Enable > Controlled Network AP > Controlled Network View > Enable > Controlled Network AP Group > Controlled Network View > Enable > Controlled Network Base Group > Controlled Network Contains commands for controlled network configuration. end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end interface wireless Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl interface wireless [] Switch to the wireless interface context.
CLI commands switch port Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl switch port Switch to the ethernet port context. syslog Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl syslog Switch to syslog context. sensor server name Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl sensor server name Sets the IP address or hostname of the the RF Manager Server to connect to. Parameters Name Specify the IP address of the the RF Manager Server or its hostname.
CLI commands If there are any firewalls between the service controller and the RF Manager Server, then TCP and UDP ports 3851 must be open bidirectionally. If using the hostname option, an entry must be created on the network DNS server that points to the IP address of the RF Manager Server. If using the Server ID option, support for multicast traffic must be enabled on all routers and switches connected between the service controller and the RF Manager Server.
CLI commands dot1x reauth period Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dot1x reauth period (15m | 30m | 1h | 2h | 4h | 8h | 12h) Sets the 802.1X reauthentication interval. Client stations must reauthenticate when this interval expires. dot1x reauth terminate Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dot1x reauth terminate Enable this option to allow client stations to remain connected during re-authentication. Client traffic is blocked only when re-authentication fails.
CLI commands inherit untagged stp Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl inherit untagged stp Inherit untagged spanning tree protocol settings from parent. no inherit untagged stp Do not inherit untagged spanning tree protocol settings from parent. bridge protocol ieee vlan Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl bridge protocol ieee vlan Enable the bridge spanning tree protocol for VLANs. no bridge protocol ieee vlan Disable the bridge spanning tree protocol for VLANs.
CLI commands local mesh qos mechanism Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl local mesh qos mechanism (disabled | 802.1p | very_high | high | normal | low | diffsrv | tos | ip_qos) Set the QoS priority mechanism. enable vsc services Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl enable vsc services Enable wireless services when the service controller is unreachable. no enable vsc services Shutdown wireless services when the service controller is unreachable.
CLI commands no inherit switch ports Inherit settings from the switch ports.
CLI commands Virtual AP Binding context Path: View > Enable > Controlled Network AP Group > Virtual AP Binding Configuration for VAP Bindings dual radio binding Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dual radio binding (radio1 | radio2) Enables radio binding. no dual radio binding (radio1 | radio2) Disables radio binding. egress vlan Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl egress vlan Enable the egress vlan. no egress vlan Disable the egress vlan.
CLI commands Syslog context Path: View > Enable > Controlled Network AP > Controlled Network > Syslog View > Enable > Controlled Network AP Group > Controlled Network > Syslog View > Enable > Controlled Network Base Group > Controlled Network > Syslog Set basic configuration for entity’s logging. message Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl message (matches | notmatches) Use this filter to include log messages.
CLI commands no level Disables filtering of the log file by severity level. Parameters debug Debug-level messages. info Informational messages. notice Normal, but significant condition. warning Warning conditions. error Error conditions. critical Critical conditions. alert Action must be taken immediately. emergency System is unusable. level Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl level Enables filtering of the log file by severity level.
CLI commands Provisioning connectivity context Path: View > Enable > Controlled Network AP > Controlled Network > Provisioning connectivity View > Enable > Controlled Network AP Group > Controlled Network > Provisioning connectivity View > Enable > Controlled Network Base Group > Controlled Network > Provisioning connectivity Set basic configuration for entity’s provisioning connectivity. end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end Switch to parent context.
CLI commands vlan Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl vlan Set the provisioning vlan id. no vlan Disable use of the provisioning vlan. static ip Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl static ip Set the static IP address. provisioning local mesh group Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl provisioning local mesh group Set the local mesh group id.
CLI commands no provisioning local mesh security Disable the use of local mesh security. provisioning local mesh type Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl provisioning local mesh type (a | b | g | bg) Set the wireless mode for local mesh . country code Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl country code Set the country code for local mesh .
CLI commands Provisioning discovery context Path: View > Enable > Controlled Network AP > Controlled Network > Provisioning discovery View > Enable > Controlled Network AP Group > Controlled Network > Provisioning discovery View > Enable > Controlled Network Base Group > Controlled Network > Provisioning discovery Set basic configuration for entity’s provisioning discovery. end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end Switch to parent context.
CLI commands dns server Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dns server Add a DNS server to the list. no dns server Delete a DNS server from the list. discovery provisioning Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl discovery provisioning Enable discovery provisioning. no discovery provisioning Disable discovery provisioning. ip address Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl ip address Add an IP address to the list.
CLI commands CN Wireless interface context Path: View > Enable > Controlled Network AP > Controlled Network > CN Wireless interface View > Enable > Controlled Network AP Group > Controlled Network > CN Wireless interface View > Enable > Controlled Network Base Group > Controlled Network > CN Wireless interface Configuration for controlled-mode wireless interfaces.
CLI commands If you have installed multiple service controllers, reducing the receiver sensitivity of the service controller from its maximum will help to reduce the amount of crosstalk between the wireless stations to better support roaming clients. By reducing the receiver sensitivity, client stations will be more likely to connect with the nearest access point.
CLI commands dot11 automatic transmit-power Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dot11 automatic transmit-power Enables automatic transmit power selection. no dot11 automatic transmit-power Disables automatic transmit power selection.
CLI commands This is a global setting that is useful when creating wireless links to remote sites. However, it also applies to all wireless connection made with the radio, not just for wireless links. Therefore, if you are also using the radio to serve local wireless client stations, adjusting this setting may lower the performance for clients with marginal signal strength or when interference is present.
CLI commands no radio active Disables the radio. spectralink view Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl spectralink view Enable the use of spectralink view. no spectralink view Disable the use of spectralink view. dot11n guard interval Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dot11n guard interval (short | long) Select the 802.11n guard interval. dot11n channel width Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dot11n channel width (40 | 20 | auto) Select the 802.
CLI commands no inherit Do not inherit settings from parent.
CLI commands RADIUS Profile context Path: View > Enable > Controlled Network AP > Controlled Network > RADIUS Profile View > Enable > Controlled Network AP Group > Controlled Network > RADIUS Profile View > Enable > Controlled Network Base Group > Controlled Network > RADIUS Profile Basic per entity RADIUS Profile configuration. end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end Switch to parent context.
CLI commands Local mesh profile context Path: View > Enable > Controlled Network AP > Controlled Network > Local mesh profile View > Enable > Controlled Network AP Group > Controlled Network > Local mesh profile View > Enable > Controlled Network Base Group > Controlled Network > Local mesh profile Configuration for local mesh profiles. security Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl security Enables wireless security. no security Disables wireless security.
CLI commands mesh id Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl mesh id Set the local mesh group id. allowed downtime Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl allowed downtime Set the allowed downtime for a connection (or a link) to a peer. minimum snr Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl minimum snr Slave: Set the group’s minimum SNR.
CLI commands inherit Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl inherit Inherit settings from parent. no inherit Do not inherit settings from parent. name Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl name Renames the current local mesh group. radio active Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl radio active (radio1 | radio2) Enables the radio. no radio active (radio1 | radio2) Disables the radio.
CLI commands Local mesh provisioning profile context Path: View > Enable > Controlled Network AP > Controlled Network > Local mesh provisioning profile View > Enable > Controlled Network AP Group > Controlled Network > Local mesh provisioning profile View > Enable > Controlled Network Base Group > Controlled Network > Local mesh provisioning profile Configuration for local mesh provisioning profile.
CLI commands Switch port context Path: View > Enable > Controlled Network AP > Controlled Network > Switch port View > Enable > Controlled Network AP Group > Controlled Network > Switch port View > Enable > Controlled Network Base Group > Controlled Network > Switch port Switch port configuration. Note | The commands in this context are used to perform configuration of the Ethernet switch built into the MSM317 Access Device.
CLI commands no dot1x authentication Disable support for IEEE802.1X. dynamic vlan Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl dynamic vlan Enable dynamic VLAN. no dynamic vlan Disable dynamic VLAN. egress rate Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl egress rate <(128k|256k|512k|1m|2m|4m|8m|16m|32m)> Set the maximum rate at which this port will accept egress traffic. use egress rate Limit the egress data rate. no use egress rate Do not limit the egress data rate.
CLI commands mac authentication Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl mac authentication Enable support for MAC-based authentication. no mac authentication Disable support for MAC-based authentication. mac filter list Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl mac filter list Accept MAC addresses set in these lists. no mac filter list Remove this list of MAC ranges. port name Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl port name Change the port name.
CLI commands priority lookup Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl priority lookup (diffsrv | 802.1p | any) Choose the port priority lookup. use priority lookup Turn on priority lookup for this port. no use priority lookup Turn on priority lookup for this port. quarantine vlan Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl quarantine vlan Set the quarantine VLAN ID. no quarantine vlan Clear the quarantine VLAN. use quarantine vlan Use the quarantine VLAN setting.
CLI commands List of MAC addresses context Path: View > Enable > Config > List of MAC addresses Use to modify a list of MAC addresses. end Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl end Go to previous context. entry Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl entry Adds a new entry to the list. no entry Removes the entry from the list. list name Supported on: MSM710 MSM730 MSM750 MSM760 MSM765zl list name Change the current list name.
ProCurve 5400zl Switches Installation and Getting Startd Guide Technology for better business outcomes To learn more, visit www.hp.com/go/procurve/ © Copyright 2009 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty.