Page 1
HP MSM313 / MSM323 Integrated Services Access Points Deployment Guide ProCurve 5400zl Switches HP MSM313/MSM323 Integrated Services Access Points Installation and Getting Started Guide Deployment Guide...
Page 3
HP MSM313/MSM323 Integrated Services Access Points Deployment Guide...
Page 4
License (GPL), version 2. In accordance with this license, Hewlett-Packard will make available a complete, machine-readable copy of the source code components covered by the GNU GPL upon receipt of a written request. Send a request to: Hewlett-Packard Company, L.P. GNU GPL Source Code Attn: HP Support Roseville, CA 95747 USA www.hp.com...
HP MSM313/MSM323 Deployment Guide Contents Contents Chapter 1 Scenario 2c: Hotspot with satellites and roaming (via RADIUS server) Introduction How it works................30 About this guide................8 Configuration road map ............30 Products covered................8 A. Install the APs..............30 Important terms................8 B. Switch the APs to autonomous mode......30 Conventions ................8...
Page 6
HP MSM313/MSM323 Deployment Guide Contents A. Configure the wireless network ........49 A. Configure addressing............70 B. Configure the location-aware group name ......49 B. Configure the radios ............71 C. Configure the connection to the service controller on the C. Configure the local mesh links........71 APs ..................49...
1 Introduction About this guide This guide contains detailed scenarios for using HP MSM313/MSM323 Integrated Services Access Points and HP MSM Access Points in a wide range of applications. Although detailed configuration steps are provided for each scenario, this guide does not cover the basic procedures for operating and configuring HP ProCurve mobility devices.
The HP Web site, www.hp.com/networking/support provides up-to-date support information. Additionally, your HP-authorized network reseller can provide you with assistance, both with services that they offer and with services offered by HP. Online documentation The latest documentation is available on the HP Support Web page at:...
Page 10
HP MSM313/MSM323 Deployment Guide 1 Introduction...
Introduction This chapter presents a variety of scenarios for public/guest network access deployments using MSM313/MSM323 Integrated Services Access Points operating alone or with one or more MSM Access Points. In this chapter, the MSM313 and MSM323 Integrated Services Access Points are Note: often referred to as "service controller"...
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks Scenario 1a: Hotspot in a box This scenario shows you how to quickly deploy and test the service controller without installing a RADIUS server. Instead, user authentication is handled locally. How it works In this scenario, a single service controller is installed to provide a wireless network and access to the Internet.
By default the service controller is configured to: • automatically choose the best operating channel (frequency) • support 802.11b/g clients • create a wireless network named HP ProCurve There is no need to change these settings for this scenario. C. Configure the Internet connection 1.
Page 15
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks 3. Specify a valid user name and password and click Go. 4. The Session page should open and you are automatically redirected to the web site you originally requested. The session page may not appear if your web browser has a popup blocker.
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks Scenario 1b: Hotspot with custom interface This scenario adds custom settings to the default public access interface used in Scenario 1a. This scenario illustrates how to customize the operation of the public access interface by defining custom web pages on a third-party web server and loading them onto the service controller.
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks Examples Sample public access files are referenced in this document. To get these files, go to the HP support Website at: www.hp.com/networking/support and select the option needed to get to the MSM product documentation page (ProCurve).
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks 7. Determine if the pages were successfully loaded by selecting: Tools > System log. If the pages were loaded successfully, the log will contain the message: LOGINFO("%d update(s) to internal HTML pages/logo.\n", updates);...
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks Scenario 1c: Hotspot with satellites and roaming This scenario adds two APs to extend the wireless network in Scenario 1b. This scenario adds two autonomous APs to extend the reach of the public access network created by a service controller.
Each AP will use the service controller to authenticate user logins. Do the following on each AP. 1. Select VSC > Profiles. 2. Click the HP ProCurve profile to edit it. 3. In the General box, select the Use HP ProCurve MSM controller check box. 4. Click Save. 5. Select Security > Access controller 6.
Follow this procedure to create three virtual service communities on all APs. 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the HP ProCurve profile to edit it. 3. On the Add/Edit Virtual Service Community page: •...
VSC you configured on the APs: 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the HP ProCurve profile to edit it. 3. On the Add/Edit Virtual Service Community page: • Under General, set Name to None.
Page 23
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks 5. On the Add/Edit Virtual Service Community page: • Under General, set Name to WEP. • Under Virtual AP, set WLAN name (SSID) to WEP. • Under Wireless protection: • Select the checkbox and choose WEP.
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks Scenario 2a: Hotspot with RADIUS authentication This installation shows you how to create a public access network using an AAA (authentication, administration, accounting) RADIUS server to handle user authentication. How it works In this scenario a single service controller is installed to provide a wireless network and access to the Internet.
F. Enable RADIUS authentication of users 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the HP ProCurve profile to edit it. 3. On the Add/Edit Virtual Service Community page: • Under HTML-based user logins,: •...
Page 26
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks 2. The service controller will intercept the URL and display the Login page. (Depending on the type of certificate that is installed on the service controller, you may see a security warning first.
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks Scenario 2b: Hotspot with custom interface (via RADIUS server) This scenario adds custom settings to the default public access interface used in Scenario 2a. This scenario illustrates how to customize the operation of the public access interface when using a AAA RADIUS server.
The pages must be changed as a group. So even if you did not change all the pages, Note: you must still supply new files for all the pages and define all attributes as shown. For more information on these attributes, consult the HP MSM313/MSM323 Network Note: Access Configuration Guide.
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks 5. Click Retrieve Now. The service controller will login and retrieve the attributes. 6. Click Save. 7. Determine if the pages were successfully loaded by selecting: Tools > System log. If the pages were loaded successfully, the log will contain the message: LOGINFO("%d update(s) to internal HTML pages/logo.\n", updates);...
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks Scenario 2c: Hotspot with satellites and roaming (via RADIUS server) This scenario adds multiple APs to extend the wireless network in Scenario 2b. AP devices can be used to extend the reach of the public access network created by a service controller.
Configure the following on each AP. 1. Select VSC > Profiles. 2. Click the HP ProCurve profile to edit it. 3. In the General box, select the Use HP ProCurve MSM controller check box. 4. Click Save. 5. Select Security > Access controller.
Start with the configuration defined in Scenario 2c. Note: A. Create VSCs on the APs Follow this procedure to create three virtual service communities on all APs. 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the HP ProCurve profile to edit it.
Follow this procedure to create virtual service communities on the service controller that match each VSC you configured on the APs: 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the HP ProCurve profile to edit it.
Page 34
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks 3. On the Add/Edit Virtual Service Community page: • Under General, set Name to None. • Under Virtual AP, set WLAN name (SSID) to None. • Under HTML-based user logins: • Enable RADIUS authentication.
This scenario adds support for 802.11a wireless clients to Scenario 2d. HP multi-radio access points can be configured to support the same SSID on two different radios. This enables a single device to support wireless clients regardless of the type of radio they have: 802.11a, b, or g.
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks Scenario 3: Shared hotspot for public and private traffic In this scenario VLANs and multiple SSIDs are used to enable public and private users to share the same infrastructure with complete security. How it works This scenario shows you how to deploy a wireless network so that it can be shared between company employees and guests.
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks Configuration road map A. Define settings on the RADIUS servers 1. On the ISP RADIUS server create accounts for public users. 2. On the corporate RADIUS server create accounts for employees. B. Install the service controller and AP 1.
LAN port is always sent to the first VSC profile. 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the HP ProCurve profile to edit it. 3. On the Add/Edit Virtual Service Community page: • Under General, set Name to Private.
Configure the AP A. Create VSCs 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the HP ProCurve profile to edit it. 3. On the Add/Edit Virtual Service Community page: • Under General, enter the Name as Public.
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks • Under Virtual AP, enter the WLAN name (SSID) as Private. • Click Save. B. Configure the connection to the service controller 1. Select Security > Access controller. 2. Set the Access controller shared secret to match the secret set on the service controller.
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks Scenario 4: Delivering custom HTML pages using VLANs This scenario shows you how to split users onto different VLANs and take advantage of this to deliver a customized user experience. How it works In this scenario a hotel assigns user traffic to a different VLAN based on an AP’s location within the...
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks In this scenario the service controller is used to provide access control functions only Note: and is not configured to support wireless clients. Configuration road map A. On the RADIUS server Define accounts for all users and the service controller on the RADIUS server.
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks B. Create a RADIUS profile 1. Select Security > RADIUS profiles. 2. Click Add New Profile. • In the Profile name box, assign RADIUS1 to the new profile. • In the Settings box, use the defaults except for Authentication method which must match the method supported by the RADIUS server.
• Public: Used for APs installed in public spaces. Forwards public traffic on VLAN 50. 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the HP ProCurve profile to edit it. 3. On the Add/Edit Virtual Service Community page: •...
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks 5. On the Add/Edit Virtual Service Community page: • Under General, set Name to Public. • Under VSC ingress mapping, clear the SSID checkbox. • Under VSC egress mapping, select VLAN and then select Public.
2 Public/guest networks C. Configure a VSC 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the HP ProCurve profile. 3. On the Add/Edit Virtual Service Community page: • Under General, set Name to Hotspot. • Under General, select the Use HP ProCurve MSM controller check box.
This feature, which is enabled by default, permits the service controller to determine the physical location where users are logging into the network (as well as other information which can used for user tracking). See the HP MSM313/MSM323 Network Access Configuration Guide for more information on this feature.
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks Configuration road map A. Install the service controller and the APs 1. Install the devices as described in the appropriate Quickstart guide. 2. Before you connect each unit to the LAN, start the management tool and configure each unit as described in the sections that follow.
1. Select VSC > Profiles. 2. Click the HP ProCurve profile to edit it. 3. Under General, make sure that the Use HP ProCurve MSM controller checkbox is selected. 4. Under Location aware: • For AP 1, set Group name to Complex_1.
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks Configure the service controller A. Configure the Internet port 1. Select Network > Ports > Internet port. 2. Select the addressing option required by your ISP. 3. Click Configure and define all settings as required.
F. Using the public access interface To use the condo internet service, tenants do the following: • Connect to the SSID HP ProCurve using 80211.b or g. • Start their web browser and specify the URL wireless.colubris.com which is the URL assigned to the service controller.
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks Scenario 6: Multi-site installation (distributed architecture) This scenario shows you how to create a multi-site installation using multiple service controllers. How it works In this scenario, multiple series 3x3 service controllers are installed to offer public access networking at a number of different physical locations.
• In the Primary RADIUS server box, specify the address of the RADIUS server at the NOC and the secret the service controller will use. • Click Save. F. Configure the VSC 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the HP ProCurve profile.
H. Define attributes on the RADIUS server On the RADIUS server, define an account for the service controller and add the following entries to login-page=web_server_URL/newpages/login.html transport-page=web_server_URL/newpages/transport.html session-page=web_server_URL/newpages/session.html fail-page=web_server_URL/newpages/fail.html logo=web_server_URL/newpages/logo.gif For more information on these attributes, consult the HP MSM313/MSM323 Network Access Configuration Guide.
J. Using the public access interface To use the internet service, users do the following: • Connect to the SSID HP ProCurve using 80211.b or g. • Start their web browser and specify the URL wireless.colubris.com which is the URL assigned to the service controller.
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks Scenario 7: Multi-site installation (centralized architecture) This scenario shows you how to create a multi-site installation using multiple service controllers to tunnel traffic back to a central location. How it works In this scenario, multiple series 3x3 service controllers are installed to offer public access networking at a number of different physical locations.
4. Click Save. E. Configure the VSC 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the HP ProCurve profile. 3. On the Add/Edit Virtual Service Community page: • Under General, select the Provide access control checkbox.
Page 58
HP MSM313/MSM323 Deployment Guide 2 Public/guest networks...
This scenario makes use of a service controller, several autonomous APs, and dynamic local mesh links. The HP local mesh implementation features dynamic links which can be used to automatically configure setups. In this chapter, the MSM313 and MSM323 Integrated Services Access Points are Note: referred to as "service controllers"...
HP MSM313/MSM323 Deployment Guide 3 Local mesh deployment Three virtual service communities (VSCs) are defined on each device. Each VSC provides support for a different security option: WEP, WPA (with preshared key), and none. To connect with the wireless network, users must select the SSID of the VSC that matches the option that they want to use and then login using the public access interface created by the service controller.
HP MSM313/MSM323 Deployment Guide 3 Local mesh deployment B. Configure the radios For optimum performance, the wireless channel used for the wireless bridge should be different and non-overlapping with the channel used to support wireless client stations. One effective way to meet this challenge is to use 802.11b/g mode to support wireless clients and 802.11a mode to create the bridge.
Follow this procedure to create three virtual service communities on all APs. 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the HP ProCurve profile to edit it. 3. On the Add/Edit Virtual Service Community page: •...
Follow this procedure to create virtual service communities on the service controller that match each VSC you configured on the APs: 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the HP ProCurve profile to edit it.
Page 65
HP MSM313/MSM323 Deployment Guide 3 Local mesh deployment 3. On the Add/Edit Virtual Service Community page: • Under General, set Name to None. • Under Virtual AP, set WLAN name (SSID) to None. • Under HTML-based user logins: • Enable RADIUS authentication.
HP MSM313/MSM323 Deployment Guide 3 Local mesh deployment E. Configure the radios 1. Select Wireless > Radios. 2. Under Radio 1: • Set Operating mode to Local mesh only. • Set Wireless mode to 802.11a. • Set Channel to Automatic.
HP MSM313/MSM323 Deployment Guide 3 Local mesh deployment Scenario 1b: Dynamic local mesh with load balancing This scenario adds an additional service controller and autonomous APs to extend the network in Scenario 1a. This scenario illustrates how to use local mesh links to split traffic.
HP MSM313/MSM323 Deployment Guide 3 Local mesh deployment Configuration road map Start with the configuration defined in Scenario 1a. Note: A. Install and configure the AP D and AP E Install and configure AP D and AP E with the same settings used for the APs in scenario 1a with the following difference: when configuring the local mesh links, change the Mesh ID from its default setting of 1 to 2.
HP MSM313/MSM323 Deployment Guide 3 Local mesh deployment Scenario 2: Creating a self-healing network This scenario makes use of a service controller, several autonomous APs, and dynamic local mesh links. This scenario illustrates how to use local mesh links to deploy a wireless infrastructure that can automatically adjust to network changes.
HP MSM313/MSM323 Deployment Guide 3 Local mesh deployment For optimum performance, the APs use 802.11b/g mode on radio 1 to support wireless clients and 802.11a mode on radio 2 to create the links. Configuration road map A. Install the APs Install the AP as described in the Quickstart guide.
• For Mesh ID, leave the default setting of 1. 7. Click Save. D. Configure the connection to the service controller on the APs Configure the following on each AP. 1. Select VSC > Profiles. 2. Click the HP ProCurve profile to edit it.
Follow this procedure to create three virtual service communities on all APs. 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the HP ProCurve profile to edit it. 3. On the Add/Edit Virtual Service Community page: •...
Follow this procedure to create virtual service communities on the service controller that match each VSC you configured on the APs: 1. Select VSC > Profiles. 2. On the Virtual Service Communities page, click the HP ProCurve profile to edit it.
Page 74
HP MSM313/MSM323 Deployment Guide 3 Local mesh deployment 3. On the Add/Edit Virtual Service Community page: • Under General, set Name to None. • Under Virtual AP, set WLAN name (SSID) to None. • Under HTML-based user logins: • Enable RADIUS authentication.
HP MSM313/MSM323 Deployment Guide 3 Local mesh deployment E. Configure the radios 1. Select Wireless > Radios. 2. Under Radio 1: • Set Operating mode to Access point only. • Set Wireless mode to 802.11a. • Set Channel to Automatic.
Page 76
HP MSM313/MSM323 Deployment Guide 3 Local mesh deployment...