Wireless-ac/n dual band desktop access point with poe (14 pages)
Summary of Contents for Cisco WAP121
Page 1
ADMINISTRATION GUIDE Cisco Small Business WAP121 Wireless-N Access Point with PoE WAP321 Wireless-N Selectable-Band Access Point with PoE...
Page 2
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company.
TSPEC Client Associations TSPEC Status and Statistics TSPEC AP Statistics Radio Statistics Email Alert Status Chapter 3: Administration System Settings User Accounts Adding a User Changing a User Password Time Settings Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 4
Packet Capture Packet Capture Configuration Local Packet Capture Remote Packet Capture Packet Capture File Download Support Information Chapter 4: LAN Port Settings VLAN and IPv4 Address Settings IPv6 Addresses Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 5
Configuring a MAC Filter List Locally on the WAP Device Configuring MAC Authentication on the RADIUS Server WDS Bridge WEP on WDS Links WPA/PSK on WDS Links WorkGroup Bridge Quality of Service WPS Setup WPS Overview Usage Scenarios Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 6
Chapter 7: Client Quality of Service Client QoS Global Settings IPv4 and IPv6 ACLs MAC ACLs Configuring ACLs Class Map Adding a Class Map Defining a Class Map Policy Map Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 7
Operation of a WAP Device Dropped From a Single Point Setup Propagation of Configuration Settings and Parameters in Single Point Setup Access Points Configuring the WAP Device for Single Point Setup Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 8
Navigating to a WAP Device Using its IP Address in a URL Sessions Channel Management Viewing Channel Assignments and Setting Locks Current Channel Assignments Table Proposed Channel Assignments Table Configuring Advanced Settings Wireless Neighborhood Viewing Details for a Cluster Member Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Internet Explorer. Select Tools > Internet Options and then select the Security tab. Select Local Intranet and select Sites. Select Advanced and then select Add. Add the intranet address of the WAP device (http://<ip- Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Click Log In. The Access Point Setup Wizard page opens. STEP 3 If this is the first time that you logged on with the default user name (cisco) and the default password (cisco) or your password has expired, the Change Admin Password page opens.
(Optional) You can enter text in the AP Location field to note the physical location of the WAP device. Click Next. The Configure Device - Set System Date and Time window appears. STEP 5 Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 12
VLAN 1. Click Next. STEP 15 For the WAP121 device, the Wizard displays the Summary - Confirm Your Settings window. Skip to STEP For the WAP321 device, the Wizard displays the Enable Captive Portal - Create Your Guest Network window.
Page 13
If they are correct, click Submit. Your WAP setup settings are saved and a STEP 26 confirmation window appears. Click Finish. The Getting Started window appears. STEP 27 Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
A link to the Cisco WAP Resources support site. Forums A link to the Cisco Support Community site. Wireless Planning Tool A link to Fluke networks AirMagnet Planner for Cisco Small Business. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
You can then select on the desired submenu item to open the associated page. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Edits or modifies an existing entry. Select an entry first. Refresh Redisplays the current page with the latest data. Save Saves the settings or configuration. Update Updates the new information to the startup configuration. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Or, select System Summary under Device Status on the Getting Started page. The System Summary page shows this information: • PID VID—The WAP hardware model and version. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 18
WAP device and a client or server. The TCP states are: Listening—The service is listening for connection requests. Active—A connection session is established and packets are being transmitted and received. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
(active or inactive). The state indicates whether the VAP is exchanging data with a client. You can click Refresh to refresh the screen and show the most current information. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
WorkGroup Bridge. For information on configuring WorkGroup Bridges, see WorkGroup Bridge. To show the WorkGroup Bridge Transmit/Receive page, select Status and Statistics > WorkGroup Bridge in the navigation pane. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Total Number of Associated Clients—The total number of clients currently associated with the WAP device. • Network Interface—The VAP the client is associated with. • Station—The MAC address of the associated wireless client. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 22
• Up Time—The amount of time the client has been associated with the WAP device. You can click Refresh to refresh the screen and show the most current information. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
User Priority—User Priority (UP) for this TS. The UP is sent with each packet in the UP portion of the IP header. Typical values are as follows: 6 or 7 for voice 4 or 5 for video Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 24
Bytes—Number of bytes for which no TSPEC has been established when admission is required by the WAP device. You can click Refresh to refresh the screen and show the most current information. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
TS. • Medium Time Unallocated—Time of unused bandwidth for this Access Category. These statistics appear separately for the transmit and receive paths on the wireless radio interface: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
TSPEC Statistics Summary for Video ACM—The total number of accepted and the total number of rejected video traffic streams. You can click Refresh to refresh the screen and show the most current information. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Sequence Control field indicates it was a duplicate. • Failed Transmit Count—Number of times an MSDU was not transmitted successfully due to transmit attempts exceeding either the short retry limit or the long retry limit. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Number of Emails Failed—The total number of email failures. The range is an unsigned integer of 32 bits. The default is 0. • Time Last Email Sent—The day, date, and time when the last email was sent. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Description—A description of the event. You can click Refresh to refresh the screen and show the most current information. You can click Clear All to clear all entries from the log. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
One management user is configured on the WAP device by default: • User Name: cisco • Password: cisco You can use the User Accounts page to configure up to four additional users and to change a user password. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Select Administration > User Accounts in the navigation pane. STEP 1 The User Account Table shows the currently configured users. The user cisco is preconfigured in the system to have Read/Write privileges. All other users can have Read Only Access, but not Read/Write access.
Select Administration > User Accounts in the navigation pane. STEP 1 The User Account Table shows the currently configured users. The user cisco is preconfigured in the system to have Read/Write privileges. The password for the user cisco can be changed.
Page 34
Select Adjust Time for Daylight Savings if daylight savings time is applicable to STEP 3 your time zone. When selected, configure these fields: • Daylight Savings Start—Select the week, day, month, and time when daylight savings time starts. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Clear this field to save system logs to volatile memory. Logs in volatile memory are deleted when the system reboots. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Remote Log—Enables the WAP device to send log messages to a remote host. When disabled, all log messages are kept on the local system. • Server IPv4/IPv6 Address/Name—The IPv4 or IPv6 address, or the hostname of the remote log server. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Anyone with access to this email account has access to the sent messages. Review your email settings to ensure that they are appropriate for the privacy policy of your business. To configure the WAP device to send email alerts: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 38
Port—Enter the SMTP port number to use for outbound emails. The range is a valid port number from 0 to 65535. The default port is 465. The port generally depends on the mode used by the email provider. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Password: Your Windows Live account password Yahoo! Mail Yahoo requires using a paid account for this type of service. Yahoo recommends the following settings: Data Encryption: TLSv1 SMTP Server: plus.smtp.mail.yahoo.com Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Timeout expires. The range is from 1 to 10 sessions. The default is 5. If the maximum number of sessions is reached, the next user who attempts to log on to the configuration utility receives an error message about the session limit. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
In the Certificate File Status area, you can view whether a certificate currently exists on the WAP device, and view this information about it: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
WAP device username and password. If the management ACL is enabled, access through the web and SNMP is restricted to the specified IP hosts. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
When you upgrade the firmware, the access point retains the existing configuration NOTE information. TFTP Upgrade To upgrade the firmware on an access point using TFTP: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
The firmware upgrade file supplied must be a tar file. Do not attempt to use bin files or files of other formats for the upgrade; these types of files do not work. Click Upgrade to apply the new firmware image. STEP 3 Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Directly connect a PC to the LAN port. STEP 1 Configure the IP address and mask on the management PC to be in the same STEP 2 subnet as the switch. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 46
If the transfer is aborted because the network is unreachable, the session times out after 45 seconds. After the session times out, you can begin the recovery process again. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
The filename cannot contain the following characters: spaces, <, >, | , \, : , (, ), &, ; , #, ? , *, and two or more successive periods. For a TFTP backup only, enter the TFTP Server IPv4 Address. STEP 5 Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
? , *, and two or more successive periods. Select which configuration file on the WAP device that you want replaced with the STEP 5 downloaded file: the Startup Configuration or the Backup Configuration. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
For example, you can copy the Backup Configuration file to the Startup Configuration file type, so that it is used the next time you boot up the WAP device. To copy a file to another file type: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Any customized settings are lost. A window appears to enable you to confirm or cancel the reboot. The current management session might be terminated. Click OK to reboot. STEP 3 Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
• Local capture method— Captured packets are stored in a file on the WAP device. The WAP device can transfer the file to a TFTP server. The file is Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
WAP device. While the radio is operating in promiscuous mode, it continues serving associated clients. Packets not destined to the WAP device are not forwarded. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Capture Interface—Enter a capture interface type for packet capture: radio1—802. 1 1 traffic on the radio interface. eth0—802.3 traffic on the Ethernet port. VAP0—VAP0 traffic. VAP1 to VAP15, if configured—Traffic on the specified VAP. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
WAP device and sends the captured packets through a TCP connection to the Wireshark tool. Wireshark is an open source tool and is available for free; it can be downloaded from http://www.wireshark.org. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 55
At Port, enter the port number of the WAP. For example, enter 2002 if you used the STEP 5 default, or enter the port number if you used a port other than the default. Click OK. STEP 6 Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 56
Exclude beacons and ACK/RTS/CTS frames: !(wlan.fc.type_subtype == 8 | | wlan.fc.type == 1) • Data frames only: wlan.fc.type == 2 • Traffic on a specific BSSID: wlan.bssid == 00:02:bc:00:17:d0 Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Because the capture file is located in the RAM file system, it disappears if the WAP device is reset. To download a packet capture file using TFTP: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Information in the navigation pane. Click Download to generate the file based on current system settings. After a short pause, a window appears to enable you to save the file to your computer. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
When disabled, you can manually configure the port speed and duplex mode. If autonegotiation is disabled, select a Port Speed (10/100 Mb/s for the WAP121, STEP 3 and 10/100/1000 Mb/s for the WAP321) and the duplex mode (Half- or Full- duplex).
VLAN. If you want to segregate management traffic from the untagged VLAN traffic, configure the new VLAN ID at your router, and then use this new VLAN ID on your WAP device. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Configure these IPv4 settings: STEP 3 • Connection Type—By default, the DHCP client on the Cisco WAP121 and WAP321 automatically broadcasts requests for network information. If you want to use a static IP address, you must disable the DHCP client and manually configure the IP address and other network information.
Page 62
Blank (no value)—No IP address is assigned or the assigned address is not operational. • IPv6 Autoconfigured Global Addresses—If the WAP device has been assigned one or more IPv6 addresses automatically, the addresses are listed. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 63
When this happens, the WAP device may lose connectivity. We recommend that you change WAP device settings when a loss of connectivity will least affect your wireless clients. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Radio settings directly control the behavior of the radio in the WAP device and its interaction with the physical medium; that is, how and what type of signal the WAP device emits. To configure radio settings: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 65
By default, when the radio mode includes 802. 1 1n, the channel bandwidth is set to 20/40 MHz to enable both channel widths. Set the field to 20 MHz to restrict the use of the channel bandwidth to a 20 MHz channel. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 66
Select one of these options: Yes—The WAP device transmits data using a 400-nanosecond guard Interval when communicating with clients that also support the short guard interval. Yes is the default selection. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 67
If a packet exceeds the fragmentation threshold you set, the fragmentation function is activated and the packet is sent as multiple 802. 1 1 frames. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 68
A lower transmit power setting can also keep your network more secure because weaker wireless signals are less likely to propagate outside of the physical location of your network. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 69
The MCS settings can be configured only if the radio mode includes 802. 1 1n support. • Broadcast/Multicast Rate Limiting—Multicast and broadcast rate limiting can improve overall network performance by limiting the number of packets transmitted across the network. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 70
The default limit is 20 percent of total traffic. • TSPEC Video ACM Mode —Regulates mandatory admission control for the video access category. By default, TSPEC Video ACM mode is off. The options are: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
WAP device that can potentially allow unauthorized parties to access the network. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Radio page. NOTE • Type—The type of device: AP indicates the rogue device is an AP that supports the IEEE 802. 1 1 Wireless Networking Framework in Infrastructure Mode. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 73
Signal—The strength of the radio signal emitting from the rogue AP. If you hover the mouse pointer over the bars, a number representing the strength in decibels (dB) appears. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
To import an AP list from a file, use these steps: In the Download/Backup Trusted AP List area, select Download (PC to AP). STEP 1 Click Browse and choose the file to import. STEP 2 Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
WAP device. Up to four VAPs are supported on the WAP121 and up to eight VAPs are supported on the WAP321. Each VAP can be independently enabled or disabled, with the exception of VAP0.
Each VAP is associated with a VLAN, which is identified by a VLAN ID (VID). A VID can be any value from 1 to 4094, inclusive. The WAP121 supports five active VLANs (four for WLAN plus one management VLAN). The WAP321 supports nine active VLANs (eight for WLAN plus one management VLAN).
Page 77
• Security—The type of authentication required for access to the VAP: None Static WEP Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 78
When this happens, the WAP device may lose connectivity. We recommend that you change WAP device settings when a loss of connectivity will least affect your wireless clients. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
The Transfer Key Index indicates which WEP key the WAP device uses to encrypt the data it transmits. • Key Length—The length of the key. Select one: 64 bits 128 bits • Key Type—The key type. Select one: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 80
WEP key in order to associate with the WAP device. When the authentication algorithm is set to Shared Key, a station with an incorrect WEP key cannot associate with the WAP device. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
EAP Encapsulation Over LANs (EAPOL). IEEE 802. 1 X provides dynamically generated keys that are periodically refreshed. An RC4 stream cipher is used to encrypt the frame body and cyclic redundancy checking (CRC) of each 802. 1 1 frame. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 82
Server IP Address 2 to 4 or Server IPv6 Address 2 to 4—Up to three IPv4 or IPv6 backup RADIUS server addresses. If authentication fails with the primary server, each configured backup server is tried in sequence. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
This security mode is backwards-compatible for wireless clients that support the original WPA. These parameters configure WPA Personal: • WPA Versions—The types of client stations you want to support: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 84
VAP. The default is 300 seconds and the valid range is from 0 to 86400 seconds. A value of 0 indicates that the broadcast key is not refreshed. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
This option does not apply if you selected WPA for WPA Versions because the original WPA does not support this feature. • Cipher Suites—The cipher suite you want to use: TKIP CCMP (AES) TKIP and CCMP (AES) Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 86
Key 2 to Key 4—The RADIUS key associated with the configured backup RADIUS servers. The server at Server IP (IPv6) Address 2 uses Key 2, the server at Server IP (IPv6) Address 3 uses Key 3, and so on. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Adding Scheduler Profiles You can create up to 16 scheduler profile names. By default, no profiles are created. To view Scheduler status and add a Scheduler profile: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Select the profile from the Select a Profile Name list. STEP 1 Click Add Rule. STEP 2 The new rule shows in the rule table. Check the box next to the Profile Name and click Edit. STEP 3 Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
For the WLAN interface or a VAP, select the profile from the Profile Name list. STEP 2 The Interface Operational Status column shows whether the interface is currently enabled or disabled. Click Save. The changes are saved to the Startup Configuration. STEP 3 Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
VAPs that are enabled to use the local list. The filter can be configured to grant access only to the MAC addresses on the list, or to deny access only to addresses on the list. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
RADIUS server. The format for the list is described in this table: RADIUS Server Description Value Attribute User-Name (1) MAC address of the client station. Valid Ethernet MAC address. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Before you configure WDS on the WAP device, note these guidelines: • WDS only works with Cisco WAP121 and Cisco WAP321 devices. • All Cisco WAP devices participating in a WDS link must have the following identical settings: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 93
If you are unconcerned about security issues on the WDS link, you may decide not to set any type of encryption. Alternatively, if you have security concerns you can choose between Static WEP and WPA Personal. In WPA Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Key Type and Key Length fields. WPA/PSK on WDS Links These additional fields appear when you select WPA/PSK as the encryption type. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
WAP device. WDS is a better solution and is preferred over the WorkGroup Bridge solution. Use WDS if you are bridging Cisco WAP121 and WAP321 devices. If you are not, then consider WorkGroup Bridge. When the WorkGroup Bridge feature is enabled, the VAP configurations are not applied;...
Page 96
Select Wireless > WorkGroup Bridge in the navigation pane. STEP 1 Select Enable for the WorkGroup Bridge Mode. STEP 2 Configure these parameters for the Infrastructure Client Interface (upstream): STEP 3 • SSID—The SSID of the BSS. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 97
SSID Broadcast is enabled by default. • Security—The type of security to use for authenticating. Choices are: None Static WEP WPA Personal • MAC Filtering—Select one of these options: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
In normal use, the default values for the WAP device and station EDCA should not need to be changed. Changing these values affects the QoS provided. To configure WAP device and Station EDCA parameters: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 99
This value is the upper limit (in milliseconds) of a range from which the initial random backoff wait time is determined. The first random number generated is a number between 0 and the number specified here. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 100
Transmission Opportunity (TXOP) is an interval of time, in milliseconds, when a WME client station has the right to initiate transmissions onto the wireless medium (WM) towards the WAP device. The TXOP Limit maximum value is 65535. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Push button: The WPS button is either on the product or a clickable button on the user interface. • Personal Identification Number (PIN): The PIN can be viewed in the product user interface. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
• A wireless device that does not support WPS must join the WPS-enabled WLAN. The administrator, who cannot use WPS in this case, instead Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
WPS is operationally disabled on the VAP if any of these conditions are not met. Disabling WPS on a VAP does not cause disassociation of any clients previously NOTE authenticated through WPS on that VAP. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
WAP device with an enabled built-in registrar pushes a similar (hardware or software) button. This sequence begins the enrollment process, and the client device joins the network. Although the Cisco WAP devices do not support an actual hardware button, the administrator can initiate the enrollment for a particular VAP using a software button in the web- based configuration utility.
The WAP device has an additional security features for protecting its device PIN. After the WAP device has completed registration with an external registrar, and the resulting WPS transaction has concluded, the device PIN is automatically regenerated. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
IEs of its beacon frames or UPnP messages that it requires such configuration. The WAP device can serve as a proxy for up to three external registrars simultaneously. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
VAP on the network. The WAP device supports one instance only. Configure the global parameters: STEP 2 • Supported WPS Version—The WPS protocol version that the WAP device supports. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 108
The operational status of the instance and the reason for that status appears. See Enabling or Disabling WPS on a VAP for information about conditions that may cause the instance to be disabled. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
STEP 3 Within two minutes, enter the WAP pin on the software interface of the client STEP 4 device. The WAP pin is configured on the WPS Setup page. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
When the client is enrolled, either the built-in registrar of the WAP device or the external registrar on the network proceeds to configure the client with the SSID, encryption mode, and public shared key of a WPS-enabled BSS. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
If the field is set to Configured, then these values are configured by the administrator. You can click Refresh to update the page with the most recent status information. NOTE Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
In addition to using the global RADIUS servers, you can also configure each VAP to NOTE use a specific set of RADIUS servers. See the Networks page. To configure global RADIUS servers: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 113
If you enable RADIUS accounting, it is enabled for the primary RADIUS server and all backup servers. Click Save. The changes are saved to the Startup Configuration. STEP 3 Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
802. 1 X authenticator. The username can be 1 to 64 characters long. ASCII-printable characters are allowed, which includes uppercase and lowercase alphabetic letters, numeric digits, and all special characters except quotation marks. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 115
<, >, |, \, : , (, ), &, ; , #, ? , *, and two or more successive periods. Click Upload. STEP 3 A confirmation window appears, followed by a progress bar to indicate the status of the upload. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Password Aging Time—The number of days before a newly created password expires, from 1 to 365. The default is 180 days. Click Save. The changes are saved to the Startup Configuration. STEP 4 Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
8 to 16. The default is 8. Check the box to make the field editable and to activate this requirement. Click Save. The changes are saved to the Startup Configuration. STEP 4 Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
ACLs are a collection of permit and deny conditions, called rules, that provide security by blocking unauthorized users and allowing authorized users to access specific resources. ACLs can block any unwarranted attempts to reach network resources. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Select the type of ACL to add. STEP 3 Add the ACL. STEP 4 Add new rules to the ACL. STEP 5 Configure the match criteria for the rules. STEP 6 Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 120
When you select Permit, the rule allows all traffic that meets the rule criteria to enter or exit the WAP device (depending on the ACL direction you select). Traffic that does not meet the criteria is dropped. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 121
Source Port—Includes a source port in the match condition for the rule. The source port is identified in the datagram header. If you select Source Port, choose the port name or enter the port number. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 122
Match to Port—The IANA port number to match to the destination port identified in the datagram header. The port range is from 0 to 65535 and includes three different types of ports: 0 to 1023—Well-Known Ports 1024 to 49151—Registered Ports Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 123
Source IPv6 Address—Select this field to require a packet's source IPv6 address to match the address listed here. Enter an IPv6 address in the appropriate field to apply this criteria. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 124
Class of Service—Select this field and enter an 802. 1 p user priority to compare against an Ethernet frame. The valid range is from 0 to 7. This field is located in the first/only 802. 1 Q VLAN tag. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 125
Click Save. The changes are saved to the Startup Configuration. STEP 5 To delete an ACL, ensure that it is selected in the ACL Name-ACL Type list, select NOTE Delete ACL, and click Save. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
IPv4—The class map applies only to IPv4 traffic on the WAP device. • IPv6—The class map applies only to IPv6 traffic on the WAP device. The Class Map page appears with additional fields, depending on the Layer 3 protocol selected: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
The mask for DiffServ is a network-style bit mask in IP dotted decimal format indicating which part(s) of the destination IP address to use for matching against packet content. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 128
Match to Port—Matches the source port number in the datagram header to an IANA port number that you specify. The port range is from 0 to 65535 and includes three different types of ports: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 129
Source MAC Address—A source MAC address to compare against an Ethernet frame. • Source MAC Mask—The source MAC address mask specifying which bits in the destination MAC to compare against an Ethernet frame. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 130
To delete a class map, select it in the Class Map Name list and click Delete. The NOTE class map cannot be deleted if it is already attached to a policy. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
• Drop—Specifies that all packets for the associated traffic stream are to be dropped if the class map criteria is met. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Services (DiffServ). DiffServ policies are a useful tool for establishing general micro-flow definition and treatment characteristics that can be applied to each wireless client, both inbound and outbound, when it is authenticated on the network. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 133
MAC—The ACL examines Layer 2 frames for matches to ACL rules. • ACL Name Up—The name of the ACL applied to traffic entering the WAP device in the inbound direction. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
ACL Type Up—The type of ACL that is applied to traffic in the inbound (client-to-WAP) direction, which can be one of these options: IPv4: The ACL examines IPv4 packets for matches to ACL rules. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 135
WAP device in the inbound (client-to-WAP) direction. • DiffServ Policy Down—The name of the DiffServ policy applied to traffic from the WAP device in the outbound (WAP-to-client) direction. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Managed devices can be network nodes such as WAP devices, routers, switches, bridges, hubs, servers, or printers. The WAP device can function as an SNMP managed device for seamless integration into network management systems. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
NMS, IPv4 Address/Name—The IPv4 IP address, DNS hostname, or subnet of the network management system (NMS), or the set of machines that can execute get and set requests to the managed devices. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 138
Trap Community—A global community string associated with SNMP traps. Traps sent from the device provide this string as a community name. The valid range is from 1 to 60 alphanumeric and special characters. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
To add and configure an SNMP view: Select SNMP > Views in the navigation pane. STEP 1 Click Add to create a new row in the SNMPv3 Views table. STEP 2 Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Access to Management Information Bases (MIBs) for each group is controlled by associating a MIB view to a group for read or write access, separately. By default, the WAP device has two groups: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 141
MD5 key/password for authentication and a DES key/password for encryption. For groups that require authentication, encryption, or both, you must define the MD5 and DES key/passwords on the SNMP Users page. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Check the box in the new row and click Edit. STEP 3 Configure the parameters: STEP 4 • User Name—A name that identifies the SNMPv3 user. User names can contain up to 32 alphanumeric characters. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
SNMPv3 user name. SNMPv3 user configuration (see the Users page) should be completed before NOTE configuring SNMPv3 targets. The WAP device supports a maximum of eight targets. NOTE Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 144
Click Save. The user is added to the SNMPv3 Targets list and your changes are STEP 5 saved to the Startup Configuration. To remove an SMMP target, select the user in the list and click Delete. NOTE Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
You can configure CP verification to allow access for both guest and authenticated users. The Captive Portal feature is available only on the Cisco WAP321 device. NOTE Authenticated users must be validated against a database of authorized Captive Portal groups or users before access is granted.
User Count—The number of CP users currently configured on the WAP device. Up to 128 users can be configured. Click Save. The changes are saved to the Startup Configuration. STEP 3 Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Verification—The authentication method for CP to use to verify clients: Guest—The user does not need to be authenticated by a database. Local—The WAP device uses a local database to authenticated users. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 148
User Group to the CP instance. All users who belong to the group are permitted to access the network through this portal. • RADIUS IP Network—Choose if the WAP RADIUS client uses the configured IPv4 or IPv6 RADIUS server addresses. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 149
Locale Count—The number of locales associated with the instance. You can create and assign up to three different locales to each CP instance from the Web Customization page. • Delete Instance—Deletes the current instance. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
You can create up to three different authentication pages with different locales on your network. Enter a Web Locale Name to assign to the page. The name can be from 1 to 32 STEP 3 alphanumeric characters. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 151
Locale—An abbreviation for the locale, from 1 to 32 characters. The default is en. • Account Image—The image file to show above the login field to depict an authenticated login. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 152
Acceptance Use Policy check box. The range is from 1 to 128 characters. The default is Error: You must acknowledge the Acceptance Use Policy before connecting! Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Image Type Default Width by Height Background Shows as the page background. 10 by 800 pixels Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
The group facilitates managing the assignment of users to CP instances. The user group named Default is built-in and cannot be deleted. You can create up to two additional user groups. To add local user groups: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
AP. If the time specified in this field expires before the client attempts to reauthenticate, the client entry is removed from the authenticated client list. The range is from 0 to 1440 Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Verification—The method used to authenticate the user on the Captive Portal, which can be one of these values: Guest—The user does not need to be authenticated by a database. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Authentication Clients in the navigation pane. • MAC Address—The MAC address of the client. • IP Address—The IP address of the client. • User Name—The Captive Portal user name of the client. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 158
Failure Time—The time that the authentication failure occurred. A timestamp is included that shows the time of the failure. You can click Refresh to show the latest data from the WAP device. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Wireless Neighborhood Single Point Setup Overview The Cisco WAP121 and WAP321 devices support Single Point Setup. Single Point Setup provides a centralized method to administer and control wireless services across multiple devices. You use Single Point Setup to create a single group, or cluster, of wireless devices.
WAP devices in the same subnet of a network. A cluster supports only a group of configured WAP121 devices or a group of configured WAP321 devices. A single cluster does not support a mix of WAP121 and WAP321 devices in the same group.
(That is, if WAP1 has more changes, but WAP2 has the most recent change, WAP1 is selected. If they have an equal number of changes, but WAP2 has the most recent change, then WAP2 is selected.) Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Single Point Setup Captive Portal Password Complexity Client QoS User Accounts Email Alert HTTP/HTTPs Service (Except SSL Certificate Radio Settings Including Configuration) TSpec Settings (Some exceptions) Log Settings Rogue AP Detection Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 163
Broadcast or Multicast Rate Limiting Channel Bandwidth Short Guard Interval Supported Radio Configuration Settings and Parameters that are Not Propagated in Single Point Setup Channel Beacon Interval DTIM Period Maximum Stations Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
You can also click the IP address of a member to configure and view data on that device. Configuring the WAP Device for Single Point Setup To configure the location and name of an individual Single Point Setup cluster member: Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 165
Single Point Setup works only with devices using the same type of IP addressing. It does not work with a group of WAP devices where some have IPv4 addresses and some have IPv6 addresses. Click Enable Single Point Setup. STEP 3 Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Select Single Point Setup > Access Points in the navigation pane. STEP 2 Set the Cluster name to the same name that is configured for the cluster STEP 3 members. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
In this case, you can click the IP address in the table on the Access Points page to show the web-based configuration utility for the particular access point. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
The following data shows for each WLAN client session with a Single Point Setup. • AP Location—The location of the access point. The location is derived from the location specified on the Administration > System Settings page. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
WAP devices in a Single Point Setup cluster. Automatic channel assignment reduces mutual interference (or interference with other WAP devices outside of its cluster) and maximizes Wi-Fi bandwidth to help maintain efficient communication over the wireless network. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 170
Wireless > Radio page. See Viewing Channel Assignments and Setting Locks for information on the current and proposed channel assignments. To stop automatic channel assignment, click Stop. STEP 3 Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Click Save to update the locked setting. Locked devices show the same channel for the Current Channel Assignments table and the Proposed Channel Assignments table. Locked devices keep their current channels. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
• Determine if there is better set of channels every—The schedule for automated updates. A range of intervals is provided, from 30 minutes to six months Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
In cluster—Only neighbor WAP devices that are members of the cluster. Not in cluster—Only neighbor WAP devices that are not cluster members. Both—Shows all neighbor WAP devices (cluster members and nonmembers). Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 174
WAP device itself that corresponds to the IP address listed above it. A signal strength of zero is displayed because the device’s own signal strength is not measured. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
(dB). • Beacon Interval—The beacon interval used by the access point. • Beacon Age—The date and time of the last beacon received from this access point. Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 176
Disassociated because sending STA is leaving or has left Basic Service Set (BSS) STA requesting (re)association is not authenticated with responding STA Disassociated because the information in the Power Capability element is unacceptable Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Page 177
Request/Probe Response/Beacon frame Invalid group cipher Invalid pairwise cipher Invalid AKMP Unsupported RSNE version Invalid RSNE capabilities IEEE 802. 1 X authentication failed Cipher suite rejected because of the security policy Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...
Where to Go From Here Cisco provides a wide range of resources to help you and your customer obtain the full benefits of the Cisco WAP121 and WAP321 Access Point. Support Cisco Small Business www.cisco.com/go/smallbizsupport Support Community Cisco Small Business www.cisco.com/go/smallbizhelp...
Page 179
Where to Go From Here Cisco Small Business Cisco Partner Central for www.cisco.com/web/partners/sell/smb Small Business (Partner Login Required) Cisco Small Business www.cisco.com/smb Home Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE...