User Manual
Page 1
...WS2000 Wireless Switch is a robust layered security approach than enables enterprises to manage and deploy The WS2000 offers a level of access ports. rogue access port/point (AP) detection and containment; URL filtering; IP routing; SPECIFICATION Sheet WS2000 All-in-one solution that simplifies and helps reduce the costs of managing wired and wireless (802.11a/b/g) networks...deployment/management, investment protection; For larger corporations deploying the WS2000 in branch offices, secure remote management capabilities (with extension Application Layer Gateway (ALG) support; ...
...WS2000 Wireless Switch is a robust layered security approach than enables enterprises to manage and deploy The WS2000 offers a level of access ports. rogue access port/point (AP) detection and containment; URL filtering; IP routing; SPECIFICATION Sheet WS2000 All-in-one solution that simplifies and helps reduce the costs of managing wired and wireless (802.11a/b/g) networks...deployment/management, investment protection; For larger corporations deploying the WS2000 in branch offices, secure remote management capabilities (with extension Application Layer Gateway (ALG) support; ...
User Manual
Page 2
...network operations or data center to easily control and manage devices anywhere in the main office greatly simplifies hotspot enablement for authentication and Radius accounting enables organizations and service providers to offer secure wireless public access, either as a complimentary service or as a wireless...WS2000 enable the easy extension of ownership (TCO). Superior network performance...and resiliency The WS2000 is packed with native support... Motorola Enterprise Mobility Services provide the comprehensive support and technical expertise you need to purchase and manage additional...
...network operations or data center to easily control and manage devices anywhere in the main office greatly simplifies hotspot enablement for authentication and Radius accounting enables organizations and service providers to offer secure wireless public access, either as a complimentary service or as a wireless...WS2000 enable the easy extension of ownership (TCO). Superior network performance...and resiliency The WS2000 is packed with native support... Motorola Enterprise Mobility Services provide the comprehensive support and technical expertise you need to purchase and manage additional...
User Manual
Page 3
... and other distributed locations. SNMPv3; WS2000 Network Architecture The WS2000 brings enterprise mobility and secure wired and wireless networking to power access ports and points Java™ web-based graphical user interface; trusted host provisioning; easy-to enable public hot spots Provides secure public access - URL Whitelist; Motorola RF Management Suite (RFMS); supports URL Blacklist; Active/standby configuration...
... and other distributed locations. SNMPv3; WS2000 Network Architecture The WS2000 brings enterprise mobility and secure wired and wireless networking to power access ports and points Java™ web-based graphical user interface; trusted host provisioning; easy-to enable public hot spots Provides secure public access - URL Whitelist; Motorola RF Management Suite (RFMS); supports URL Blacklist; Active/standby configuration...
User Manual
Page 4
...(MIB-II, Ping MIB, Trace Route MIB, Motorola MIB High Availability Active/standby configuration support; DHCP (client/server/relay), switch auto-configuration and firmware updates with Admission Control; CCMP; (802.11i WPA2) Key Exchange Management: Extensible Authentication Protocol (EAP); excessive crypto IV ...: 1.75 in. excessive probes; MOTOROLA and the Stylized M Logo are registered in . SPECIFICATION Sheet ws2000 All-in-one or all zero addresses Premium Wireless IPS: Via RF Management Suite for forensics and reporting VPN gateway: Supports DES, 3DES and AES-128 and...
...(MIB-II, Ping MIB, Trace Route MIB, Motorola MIB High Availability Active/standby configuration support; DHCP (client/server/relay), switch auto-configuration and firmware updates with Admission Control; CCMP; (802.11i WPA2) Key Exchange Management: Extensible Authentication Protocol (EAP); excessive crypto IV ...: 1.75 in. excessive probes; MOTOROLA and the Stylized M Logo are registered in . SPECIFICATION Sheet ws2000 All-in-one or all zero addresses Premium Wireless IPS: Via RF Management Suite for forensics and reporting VPN gateway: Supports DES, 3DES and AES-128 and...
Quick Start Guide
Page 1
.... (2) Introduction The WS2000 Wireless Switch provides centralized management of the equipment. ...switch to the upright position in the facility's network and run your network and devices (see the WS2000 Wireless Switch System Reference available on the Motorola website). (4) WS2000 Wireless Switch Box • WS2000 Wireless Switch • Clear snap-on the front of this device (see the site-specific documentation derived from the switch...device to your facility's Technical or Systems Support. Configure the product for installation of the switch. 2. This wireless switch...
.... (2) Introduction The WS2000 Wireless Switch provides centralized management of the equipment. ...switch to the upright position in the facility's network and run your network and devices (see the WS2000 Wireless Switch System Reference available on the Motorola website). (4) WS2000 Wireless Switch Box • WS2000 Wireless Switch • Clear snap-on the front of this device (see the site-specific documentation derived from the switch...device to your facility's Technical or Systems Support. Configure the product for installation of the switch. 2. This wireless switch...
Quick Start Guide
Page 2
...faulty device is designed to which can be Listed to any Layer 2/3 network device Standard Ethernet Ports 802.3af LAN Ports (PoE) WAN Port Power LED Plug devices into place on , the user is encouraged to try to WAN and LAN (RJ-45) Ports The WS2000 Wireless Switch ...locations they are sold and will invalidate any technical problem, question or support issue involving Motorola products. If a non-power device is off . Lock Port Back Power Connector Using the CompactFlash® Slot The WS2000 wireless switch has a CompactFlash® slot which you plug in the slot. These...
...faulty device is designed to which can be Listed to any Layer 2/3 network device Standard Ethernet Ports 802.3af LAN Ports (PoE) WAN Port Power LED Plug devices into place on , the user is encouraged to try to WAN and LAN (RJ-45) Ports The WS2000 Wireless Switch ...locations they are sold and will invalidate any technical problem, question or support issue involving Motorola products. If a non-power device is off . Lock Port Back Power Connector Using the CompactFlash® Slot The WS2000 wireless switch has a CompactFlash® slot which you plug in the slot. These...
Reference Guide
Page 6
TOC-4 WS2000 Wireless Switch System Reference Guide 6.2.1 Configuring the RADIUS Server 6-5 6.2.2 Configuring Lightweight Directory Access Protocol (LDAP) Authentication 6-7 6.2.3 Setting Up a Proxy RADIUS Server 6-8 6.2.4 Managing the Local User Database 6-9 6.2.5 Adding New Guest Users Quickly 6-11 6.2.6 Setting the User Access Policy 6-12 6.3 Managing Digital Certificates 6-13 6.3.1 Importing CA Certificates 6-13 6.3.2 Creating Self Certificates 6-15 Chapter 7: Switch Administration 7.1 Overview of...
TOC-4 WS2000 Wireless Switch System Reference Guide 6.2.1 Configuring the RADIUS Server 6-5 6.2.2 Configuring Lightweight Directory Access Protocol (LDAP) Authentication 6-7 6.2.3 Setting Up a Proxy RADIUS Server 6-8 6.2.4 Managing the Local User Database 6-9 6.2.5 Adding New Guest Users Quickly 6-11 6.2.6 Setting the User Access Policy 6-12 6.3 Managing Digital Certificates 6-13 6.3.1 Importing CA Certificates 6-13 6.3.2 Creating Self Certificates 6-15 Chapter 7: Switch Administration 7.1 Overview of...
Reference Guide
Page 20
...WARNING! Viewing this online system reference guide with Internet Explorer 5.0 and higher or Netscape Navigator 4.7 or higher on the network. It also serves as a reference guide for the administrator to use while updating or maintaining the system. 1.1.1 About ... user interface accessed from any web browser on a Microsoft Windows based PC. 1-2 WS2000 Wireless Switch System Reference Guide 1.1 WS2000 Wireless Switch System Reference Guide This guide is intended to support administrators responsible for the system administrator to use during the initial setup and configuration of...
...WARNING! Viewing this online system reference guide with Internet Explorer 5.0 and higher or Netscape Navigator 4.7 or higher on the network. It also serves as a reference guide for the administrator to use while updating or maintaining the system. 1.1.1 About ... user interface accessed from any web browser on a Microsoft Windows based PC. 1-2 WS2000 Wireless Switch System Reference Guide 1.1 WS2000 Wireless Switch System Reference Guide This guide is intended to support administrators responsible for the system administrator to use during the initial setup and configuration of...
Reference Guide
Page 21
... the network. When an MU contacts the switch, the switch cell controller services attempt to authenticate the device for access to and from one of these ports provide IEEE 802.3af-compliant Power over Ethernet (PoE) support for devices that provides stateful packet inspection. The WS 2000 Wireless Switch acts as a WAN/LAN gateway and a wired/wireless switch. 1.2.1 Management of security...
... the network. When an MU contacts the switch, the switch cell controller services attempt to authenticate the device for access to and from one of these ports provide IEEE 802.3af-compliant Power over Ethernet (PoE) support for devices that provides stateful packet inspection. The WS 2000 Wireless Switch acts as a WAN/LAN gateway and a wired/wireless switch. 1.2.1 Management of security...
Reference Guide
Page 22
..."Power over the line to a power device (such as a switch or router). 1-4 WS2000 Wireless Switch System Reference Guide 1.3 Hardware Overview The WS 2000 Wireless Switch provides a fully integrated solution for managing every aspect of connecting wireless LANs (WLANs) to the command-line ...networks through a Layer 2/3 device (such as an Access Port). (See the WS 2000 Wireless Switch LED explanation for more information on the meaning of the different state of the transmission (10 or 100 Mbit/sec.), the other indicating whether there is being delivered over Ethernet" (PoE) support...
..."Power over the line to a power device (such as a switch or router). 1-4 WS2000 Wireless Switch System Reference Guide 1.3 Hardware Overview The WS 2000 Wireless Switch provides a fully integrated solution for managing every aspect of connecting wireless LANs (WLANs) to the command-line ...networks through a Layer 2/3 device (such as an Access Port). (See the WS 2000 Wireless Switch LED explanation for more information on the meaning of the different state of the transmission (10 or 100 Mbit/sec.), the other indicating whether there is being delivered over Ethernet" (PoE) support...
Reference Guide
Page 23
Ports 1-4, which supply 802.3af Power over Ethernet (PoE) support to the port. Location Upper left LED Upper right LED Lower LED Function This LED is present on Ports 1-4. The light is off when the ... of the port. no device) is made to devices (such as Access Ports). GREEN-The switch is delivering 48 volts to the power device connected to a device is connected; This LED indicates activity on . The light flashes when traffic is being transferred over the line. Product Overview 1-5 1.3.2 WS 2000 Wireless Switch LED Functions The switch has a large blue...
Ports 1-4, which supply 802.3af Power over Ethernet (PoE) support to the port. Location Upper left LED Upper right LED Lower LED Function This LED is present on Ports 1-4. The light is off when the ... of the port. no device) is made to devices (such as Access Ports). GREEN-The switch is delivering 48 volts to the power device connected to a device is connected; This LED indicates activity on . The light flashes when traffic is being transferred over the line. Product Overview 1-5 1.3.2 WS 2000 Wireless Switch LED Functions The switch has a large blue...
Reference Guide
Page 29
... to enable access to the device(s) connected to only one subnet. Getting Started 2-5 Step 4: Configure the LAN Interface The first step of network configuration process is collected from other...screen to view a summary of the Subnet1 line is enabled. Network Network (subnet) name is summary information; The WS2000 Wireless Switch allows the administrator to consolidate the LAN's communications on this ...with the four supported subnets, and to the left column of the information on fewer subnets. The rest of the configuration screens. The WS 2000 Network Management System uses ...
... to enable access to the device(s) connected to only one subnet. Getting Started 2-5 Step 4: Configure the LAN Interface The first step of network configuration process is collected from other...screen to view a summary of the Subnet1 line is enabled. Network Network (subnet) name is summary information; The WS2000 Wireless Switch allows the administrator to consolidate the LAN's communications on this ...with the four supported subnets, and to the left column of the information on fewer subnets. The rest of the configuration screens. The WS 2000 Network Management System uses ...
Reference Guide
Page 33
...its support of wireless networks. To start the WLAN configuration process, select the Network Configuration --> Wireless item from the left menu. The following Wireless summary screen appears. Wireless Summary Area The top portion of the window displays a summary of the switch, ...device. In order to use the wireless features of the WLANs that WLAN1 is shown in number. Verify that is printed on this area) can adopt up to six Access Ports at a time, but the list of the switch is 00:09:5B:45:9B:07. Getting Started 2-9 Step 7: Enable Wireless LANs (WLANs) The WS2000 Wireless Switch...
...its support of wireless networks. To start the WLAN configuration process, select the Network Configuration --> Wireless item from the left menu. The following Wireless summary screen appears. Wireless Summary Area The top portion of the window displays a summary of the switch, ...device. In order to use the wireless features of the WLANs that WLAN1 is shown in number. Verify that is printed on this area) can adopt up to six Access Ports at a time, but the list of the switch is 00:09:5B:45:9B:07. Getting Started 2-9 Step 7: Enable Wireless LANs (WLANs) The WS2000 Wireless Switch...
Reference Guide
Page 38
... the communications of physical-port addresses and Wireless LANs (WLANs) associated with the four supported subnets, and to enable or disable each configured subnet. 1. The rest of the switch-managed LAN. 3-2 WS2000 Wireless Switch System Reference Guide 3.1 Enabling Subnets for the LAN Interface Subnets are used to maximize the available network addresses and to save changes. Each enabled...
... the communications of physical-port addresses and Wireless LANs (WLANs) associated with the four supported subnets, and to enable or disable each configured subnet. 1. The rest of the switch-managed LAN. 3-2 WS2000 Wireless Switch System Reference Guide 3.1 Enabling Subnets for the LAN Interface Subnets are used to maximize the available network addresses and to save changes. Each enabled...
Reference Guide
Page 42
... WIAP enabled switch, a switch that may prefer or require such access. 3.3 Configuring Subnet Access The WS 2000 Network Management System allows the administrator to set up access rules for subnet-tosubnet and subnet-to provide the IP address of specified devices provides corresponding static...it remains in WIAP mode. 3-6 WS2000 Wireless Switch System Reference Guide 7. Only port 24576 is supported. 13.Option 43 is used to associate static (or fixed) IP addresses with this subnet are members of specific wireless devices. This address is the device's hard-coded hardware number (shown ...
... WIAP enabled switch, a switch that may prefer or require such access. 3.3 Configuring Subnet Access The WS 2000 Network Management System allows the administrator to set up access rules for subnet-tosubnet and subnet-to provide the IP address of specified devices provides corresponding static...it remains in WIAP mode. 3-6 WS2000 Wireless Switch System Reference Guide 7. Only port 24576 is supported. 13.Option 43 is used to associate static (or fixed) IP addresses with this subnet are members of specific wireless devices. This address is the device's hard-coded hardware number (shown ...
Reference Guide
Page 45
... the sender, and the data really is tightly integrated with IP. GRE General Routing Encapsulation (GRE) supports VPNs across an Internet that of Internet Protocol (IP) networks. The screen consists of ports. 6. The Settings area enables or disables the data found on receiving ... Subnet Access screen allows the administrator to be used for broadcasting data over any other key component is a mechanism for encapsulating network layer protocols over the Internet. The Firewall Rules area displays the currently defined and active firewall rules. Because ICMP uses IP...
... the sender, and the data really is tightly integrated with IP. GRE General Routing Encapsulation (GRE) supports VPNs across an Internet that of Internet Protocol (IP) networks. The screen consists of ports. 6. The Settings area enables or disables the data found on receiving ... Subnet Access screen allows the administrator to be used for broadcasting data over any other key component is a mechanism for encapsulating network layer protocols over the Internet. The Firewall Rules area displays the currently defined and active firewall rules. Because ICMP uses IP...
Reference Guide
Page 47
...ICMP Internet Control Message Protocol (ICMP) is a set of rules used for the firewall rule. GRE General Routing Encapsulation (GRE) supports VPNs across an Internet that of -band messages related to directly connect, and then send and receive datagrams over the Internet. ... mode, providing security between two end points. Also, AH can be used in IP packets, are divided into packets for encapsulating network layer protocols over the Internet. ESP Encapsulating Security Protocol (ESP) is Encapsulating Security Protocol (ESP), described below . An IP address...
...ICMP Internet Control Message Protocol (ICMP) is a set of rules used for the firewall rule. GRE General Routing Encapsulation (GRE) supports VPNs across an Internet that of -band messages related to directly connect, and then send and receive datagrams over the Internet. ... mode, providing security between two end points. Also, AH can be used in IP packets, are divided into packets for encapsulating network layer protocols over the Internet. ESP Encapsulating Security Protocol (ESP) is Encapsulating Security Protocol (ESP), described below . An IP address...
Reference Guide
Page 49
The Hello Time is a switched network that must be invoked. It is discarded when it exceeds the value set for a port, and to be set to a value less than a standard LAN, ... each bridge protocol data unit sent. Also provide the IDs of the VLAN which is equal to the network infrastructure without physically disconnecting network equipment. The WS 2000 Wireless Switch supports assigning one or more VLANs, select Network Configuration --> VLAN from the navigation menu on physical location. Set the Forward Delay. The 802.1d specification recommends...
The Hello Time is a switched network that must be invoked. It is discarded when it exceeds the value set for a port, and to be set to a value less than a standard LAN, ... each bridge protocol data unit sent. Also provide the IDs of the VLAN which is equal to the network infrastructure without physically disconnecting network equipment. The WS 2000 Wireless Switch supports assigning one or more VLANs, select Network Configuration --> VLAN from the navigation menu on physical location. Set the Forward Delay. The 802.1d specification recommends...
Reference Guide
Page 52
... immediate neighbor multicast agents to support the creation of transient groups, the addition and deletion of members of a group, and the periodic confirmation of -band messages related to replace the current version Internet Protocol, IP Version 4 ("IPv4"). 3-16 WS2000 Wireless Switch System Reference Guide Transport ICMP ...two main PIM protocols, PIM Sparse Mode and PIM Dense Mode. Also, ESP can be used by the IETF to network operation. The Internet Group Management Protocol (IGMP) is the data sent. GRE is also used in each optimized for out-of group membership. ESP ...
... immediate neighbor multicast agents to support the creation of transient groups, the addition and deletion of members of a group, and the periodic confirmation of -band messages related to replace the current version Internet Protocol, IP Version 4 ("IPv4"). 3-16 WS2000 Wireless Switch System Reference Guide Transport ICMP ...two main PIM protocols, PIM Sparse Mode and PIM Dense Mode. Also, ESP can be used by the IETF to network operation. The Internet Group Management Protocol (IGMP) is the data sent. GRE is also used in each optimized for out-of group membership. ESP ...
Reference Guide
Page 66
... selected RIP type, the RIP v2 Authentication area of a more sophisticated protocol. More importantly, RIP version 2 supports subnet masks, a critical feature that do not have enough redundant paths to warrant the overhead of the screen becomes...the use in stub networks and in small autonomous systems that is selected, specify a password of the following values. Select the type of RIP v1's capabilities, but it is well suited for example, if the switch manages a private LAN.... file must be appropriate to secure table updates. 4-12 WS2000 Wireless Switch System Reference Guide 1.
... selected RIP type, the RIP v2 Authentication area of a more sophisticated protocol. More importantly, RIP version 2 supports subnet masks, a critical feature that do not have enough redundant paths to warrant the overhead of the screen becomes...the use in stub networks and in small autonomous systems that is selected, specify a password of the following values. Select the type of RIP v1's capabilities, but it is well suited for example, if the switch manages a private LAN.... file must be appropriate to secure table updates. 4-12 WS2000 Wireless Switch System Reference Guide 1.