20
Interoperability Report Ascom i62 Fortinet MC/WLC WLC controller platform Fortinet MC/WLC v. 8.4-0-7 Ascom i62 v. 6.0.6 Morrisville, NC, USA May 2018

Ascom Interoperability Report Fortinet WLC 8 4 R1 · 2018-05-29 · Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 3 / 20 Introduction This document describes

  • Upload
    others

  • View
    10

  • Download
    0

Embed Size (px)

Citation preview

  • Interoperability Report

    Ascom i62 Fortinet MC/WLC

    WLC controller platform

    Fortinet MC/WLC v. 8.4-0-7

    Ascom i62 v. 6.0.6

    Morrisville, NC, USA

    May 2018

  • Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 2 / 20

    Contents

    Introduction ......................................................................................................................................... 3

    About Ascom ..................................................................................................................................... 3

    About Fortinet .................................................................................................................................... 3

    Site Information ................................................................................................................................... 4

    Verification site .................................................................................................................................. 4

    Participants ........................................................................................................................................ 4

    Verification topology .......................................................................................................................... 4

    Summary .............................................................................................................................................. 5

    General conclusions .......................................................................................................................... 5

    Verification overview .......................................................................................................................... 6

    Known limitations ............................................................................................................................... 7

    Appendix A: Verification Configurations ......................................................................................... 8

    Fortinet MC1550 WLAN Controller version 8.4-0-7 .......................................................................... 8

    Ascom i62 ........................................................................................................................................ 17

    Appendix B: Interoperability Verification Records ....................................................................... 20

    Document History ............................................................................................................................. 20

  • Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 3 / 20

    Introduction This document describes a summary of the interoperability verification results of the Ascom’s and Fortinets platform, necessary steps and guidelines to optimally configure the platforms and support contact details. The report should be used in conjunction with both Fortinets and Ascom’s platform configuration guides.

    About Ascom Ascom is a global solutions provider focused on healthcare ICT and mobile workflow solutions. The vision of Ascom is to close digital information gaps allowing for the best possible decisions – anytime and anywhere. Ascom’s mission is to provide mission-critical, real-time solutions for highly mobile, ad hoc, and time-sensitive environments. Ascom uses its unique product and solutions portfolio and software architecture capabilities to devise integration and mobilization solutions that provide truly smooth, complete and efficient workflows for healthcare as well as for industry, security and retail sectors.

    Ascom is headquartered in Baar (Switzerland), has subsidiaries in 15 countries and employs around 1,300 people worldwide. Ascom registered shares (ASCN) are listed on the SIX Swiss Exchange in Zurich.

    About Fortinet Fortinet (NASDAQ: FTNT) secures the largest enterprise, service provider, and government organizations around the world. Fortinet empowers its customers with intelligent, seamless protection across the expanding attack surface and the power to take on ever-increasing performance requirements of the borderless network - today and into the future. Only the Fortinet Security Fabric architecture can deliver security features without compromise to address the most critical security challenges, whether in networked, application, cloud or mobile environments. Fortinet ranks #1 in the most security appliances shipped worldwide and more than 330,000 customers trust Fortinet to protect their businesses. Learn more at https://www.fortinet.com, the Fortinet Blog, or FortiGuard Labs.

  • Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 4 / 20

    Site Information

    Verification site Ascom US 300 Perimeter park drive Morrisville, NC, US-27560 USA

    Participants Karl-Magnus Olsson, Ascom, Morrisville

    Verification topology

  • Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 5 / 20

    Summary

    General conclusions

    The result of the verified test areas, such as authentication, association, handover and call stability tests, produced in general very good test result. Due to Fortinets single channel architecture, no traditional roaming is made which makes the roaming seamless.

    Note. Unless the parameter “Expedited Forwarding Override” is used the i62 have to mark voice packets with DSCP 48 in order for appropriate mapping in the “air” (Access Category 6). Refer to handset configuration on page 17.

    Please refer to Fortinet’s documentation for information regarding co-existence and between different access point models within the same wireless network.

    Supported Partner Access Points with SW version 8.4-0.7:

    AP 332 (i/e variants)

    AP 822 and AP832 (i/e variants)

    AP 1010/1014/1020 (i/e variants)

    AP U421EV, U423EV

    Supported Partner Controller Platforms with SW version 8.4-0-7:

    MC3200, MC3200-VE

    MC1550, MC1550-VE

    MC6000

    MC4200

    MC4200-VE

    FortiWLC-50D ,200D, 500D, 1000D, 3000D

    FWC- VM-50, 200, 500, 1000,3000

  • Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 6 / 20

    Verification overview

    WLAN Compatibility and Performance

    High Level Functionality Result Comments

    Association, Open with No Encryption OK

    Association, WPA2-PSK / AES Encryption OK

    Association, PEAP-MSCHAPv2 Auth, AES Encryption OK

    Association with EAP-TLS authentication OK

    Association, Multiple ESSIDs OK

    Beacon Interval and DTIM Period OK

    PMKSA Caching OK

    WPA2-opportunistic/proactive Key Caching OK

    WMM Prioritization OK

    802.11 Power-save mode OK

    802.11e U-APSD OK

    802.11e U-APSD (load test) OK

    Roaming, WPA2-PSK, AES Encryption OK Roam transparent to handset*

    Roaming, PEAP-MSCHAPv2 Auth, AES Encryption OK Roam transparent to handset*

    *) RF Mode: Virtual Cell. See Known issues section for limitations regarding Native Cell mode.

  • Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 7 / 20

    Known limitations Description and Symptoms Workaround Ticket(s)

    raised i62 might lose SIP registration and experience voice disturbances when associated in .11n mode. Affects AP 332, 8xx and 10xx.

    Associate in legacy/non 11n mode by setting Ascom i62 “802.11 Protocol” to 802.11a or 802.11b/g. (see chapter Ascom i62 network settings for details)

    Ascom ticket WX-3948

    RF Virtulization Mode: “Native Cell” considerations. When using PSK Authentication AP U421EV show longer roaming times than expected due to delayed EAPOL keys from AP. Measuerd roaming times are typically 120-170ms and data loss can be clearly noticed in a call. Fortinet does not support OKC (oppurtunistic key caching) resulting in unacceptable (for VoIP) roaming times when utlizing .1X authentication together with Native Cell.

    Virtual Cell mode is recomended for all access points.

    For additional information regarding the known limitations please contact [email protected] or [email protected]. For detailed verification results, refer to Appendix B: Interoperability Verification Records.

  • Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 8 / 20

    Appendix A: Verification Configurations

    Fortinet MC1550 WLAN Controller version 8.4-0-7 In the following chapter you will find screenshots and explanations of basic settings in order to get a Fortinet WLAN system to operate with an Ascom i62. Please note that security settings were modified according to requirements in individual test cases.

    The configuration file is found at the bottom of this chapter.

    System overview

  • Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 9 / 20

    Security settings

    Security profiles.

    Security profile WPA2-PSK, AES/CCMP encryption.

  • Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 10 / 20

    Security profile WPA2-Enterprise, AES-CCMP encryption Primary RADIUS Profile Name “FreeRadius” refers to the RADIUS profile set up in the controller. See radius profile below for additional details.

    Configuration of Radius profile.

  • Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 11 / 20

    Radius profile configuration. Note that the profile “FreeRadius”, the RADIUS IP and the secret must correspond to the authentication server running in the network.

  • Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 12 / 20

    ESS, Radio and QoS settings

    Ascom recommended settings for 802.11b/g/n are to only use channel 1, 6 or 11. For 802.11a/n/ac, use channels according to the infrastructure manufacturer and country regulations.

    Note that power level was adjusted for test purpose

    Make sure that all non-DFS channel are taken before resorting to DFS channels. The handset can cope in mixed non-DFS and DFS environments; however, due to “unpredictability” introduced by radar detection protocols, voice quality may become distorted and roaming delayed. Hence Ascom recommends if possible avoiding the use of DFS channels in VoWIFI deployments.

  • Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 13 / 20

    ESS settings. Since multicast applications are usually not expected in WLANs, where Ascom VoWIFI handsets are deployed, the “Allow Multicast Flag” should be set to “OFF”.

    Make sure 802.11r and 802.11k is disabled.

  • Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 14 / 20

    ESS settings (continued).

    Make sure APSD support is enabled. Utilizing U-APSD will dramatically improve the i62s talk time.

    Note. Ascom and Fortinet recommend Virtual Cell for AP332/822/832/10xx and U421. See section Known Issues for further details.

  • Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 15 / 20

    ESS advanced settings

    - Select Voice Client Type - ascom

    - Set DTIM Period of 5 and a DTIM interval of 100ms. These values are recommended in order to allow maximum battery conservation without impacting the quality. Lower DTIM values are possible but will decrease the standby time.

    - Expedited Forwarding Override will map DSCP 46 (EF) to the AC_VO. If turned off, IP DSCP for Voice has to be set to 0x30 (48) in the Phone. See i62 settings further down.

    In a Fortinet environment, we recommended that the data rates are advertised within the ESS per above for 802.11a/n/ac.

  • Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 16 / 20

    In a Fortinet environment, it is recommended that the data rates are advertised within the ESS per above (802.11b/g/n). To further optimize performance it is recommended to disallow 802.11b clients to associate by setting 12Mbps rate to mandatory in the 802.11bgn data rate set.

  • Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 17 / 20

    Ascom i62

    Network settings for WPA2-PSK

    Note. Make sure that the enabled channels in the i62 handset match the channel plan used in the system.

    Note. FCC is no longer allowing 802.11d to determine regulatory domain. Devices deployed in USA must set Regulatory domain to “USA”.

  • Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 18 / 20

    Network settings for .1X authentication (PEAP-MSCHAPv2)

  • Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 19 / 20

    802.1X Authentication requires a CA certificate to be uploaded to the phone by “right clicking” - > Edit certificates. EAP-TLS will require both a CA and a client certificate.

    Note that both a CA and a client certificate are needed for TLS. Otherwise only a CA certificate is needed. Server certificate validation can be overridden in version 4.1.12 and above per handset setting.

  • Interoperability Report Date Page Ascom i62 – Fortinet WLC 04-May-2018 20 / 20

    Appendix B: Interoperability Verification Records Pass Fail Comments Not verified

    14 3 0 3

    Total 20

    Refer to the attached file for detailed verification results.

    Refer to the verification specification for explicit information regarding each verification case. The specification can be found here (requires login): https://www.ascom-ws.com/AscomPartnerWeb/en/startpage/Sales-tools/Interoperability/Templates/

    Document History

    Rev Date Author Description P1 4-May-18 SEKMO Draft R1 15-May-18 SEKMO Updates after review. Revision R1

    =~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2018.05.15 14:57:47 =~=~=~=~=~=~=~=~=~=~=~=sh running-config Building configuration. Please wait ...configure terminalno rogue-ap detectionaudit period 60controller-index 2auto-ap-upgrade enabletopo-update disableaeroscout disableaeroscout ip-address 0.0.0.0aeroscout port 12092fastpath onclient-handoff-logic onbonding none10gig-module disable1gig-sfp disableigmp-snoop state disableigmp-snoop age-time 300roaming-domain stoproaming-domain roam-time-out 60snmp-filter-config ap-discovered onsnmp-filter-config ap-assigned offsnmp-filter-config ap-neighbor offsnmp-filter-config ap-neighbor-detail offstation-aging-out-interval 2optimization noneassociated-station-max-idle-period 2000adequate-signal-threshold -45zeronet-packet disableap-keepalive-timeout 60hostname mc1550ip dhcp-server 192.168.0.10ip dhcp-passthroughip udp-broadcast upstream all-ports selectedip udp-broadcast downstream all-ports selectedip udp-broadcast upstream-bridged all-ports selectedip udp-broadcast downstream-bridged all-ports selectedipv6-neighbor-discovery-optimization enableload-balance-vcell load-threshold 100load-balance-vcell rssi-threshold -65load-balance-vcell disablemanagement wirelessqosvars admission admitallqosvars ttl 0qosvars udpttl 0qosvars tcpttl 0qosvars enableqosvars bwscaling 100qosvars drop-policy headqosvars max-stations-per-radio 256qosvars max-stations-per-bssid 0qosvars load-balance-overflow offqosvars calls-per-ap 0qosvars calls-per-interference 0qosvars calls-per-bssid 0qosvars cac-deauth offqosvars station-assign-age 30qosvars sip-idle-timeout 120air-shield daily-out-of-service noneair-shield start-time 00:00air-shield end-time 00:00rogue-ap mitigation nonerogue-ap assigned-aps 3rogue-ap aging 600rogue-ap scanning-time 100rogue-ap operational-time 400rogue-ap mitigation-frames 10rogue-ap scanning-channels 1,2,3,4,5,6,7,8,9,10,11,12,13,14,36,40,44,48,52,56,60,64,100,104,108,112,116,120,124,128,132,136,140,149,153,157,161,165rogue-ap min-rssi -100spectrum-band 00000000000000000000000000001011snmp-server description controllerforce-dhcp-retry count 4statistics period 60frame-report-suppression disablelocation-server project-name Project-Exonnlocation-server disablelocation-server source alllocation-server report-format legacylocation-server ip-address 0.0.0.0location-server port 10000location-server report-interval 5location-server relay-multicast 00:00:00:00:00:00radius-profile FreeRadius description "" ip-address 192.168.0.2 coa on radius-timeout 2 radius-retries 3 radius-version 0 key secret port 1812 remote-radius-server off radius-relay-apid 0 mac-delimiter hyphen password-type shared-secret called-station-id-type default owner controller exitauthentication-mode global authentication-type local primary-radius-ip 0.0.0.0 primary-radius-port 1812 primary-radius-secret "" secondary-radius-ip 0.0.0.0 secondary-radius-port 1812 secondary-radius-secret "" primary-tacacs-ip 0.0.0.0 primary-tacacs-port 49 primary-tacacs-secret "" secondary-tacacs-ip 0.0.0.0 secondary-tacacs-port 49 secondary-tacacs-secret "" exitaccess-list auto-authentication-expiry-period 20ap 14 boot-script "" description AP-14 contact "" building "" floor "" led Normal location "" dataplane-encryption off link-probing-duration 120 mac-address 00:0c:e6:37:8d:e0 model FAP-U423EV power-supply 802.3-at indoor-outdoor indoor keepalive-timeout 60 mca-status unplanned ap-group-id 0 feature-group-id 0 exitap 15 boot-script "" description AP-15 contact "" building "" floor "" led Normal location "" dataplane-encryption off link-probing-duration 120 mac-address 00:0c:e6:12:ff:a1 model AP832i power-supply 802.3-af indoor-outdoor indoor keepalive-timeout 60 mca-status unplanned ap-group-id 0 feature-group-id 0 exitdefaultsettings 1 channel 6 channel-width 20-mhz rf-mode 802.11bgn exitdefaultsettings 2 channel 36 channel-width 40-mhz-extension-channel-above rf-mode 802.11an exitdefaultsettings 3 channel 149 channel-width 40-mhz-extension-channel-above rf-mode 802.11an exitarrp 0 disable radio1-channel-planning channel 6 radio1-channel-planning channel-width 20-mhz radio2-channel-planning channel 36 radio2-channel-planning channel-width 40-mhz-extension-channel-above auto-power Off timer-state Off dfs Off freeze No timer-value 15 rssi-threshold -65 exitsecurity-profile default security-version 0 key-rotation disabled management-frame-protection-11w disable allowed-l2-modes open online-sign-up not-configured captive-portal disabled captive-portal-profile "" captive-portal-auth-method internal psk key "" firewall-capability none passthrough-firewall-filter-id "" firewall-filter-id "" security-logging off owner controller static-wep key "" static-wep key-index 1 mac-filter-radius-server primary "" mac-filter-radius-server secondary "" mac-filter-acct-radius-server primary "" mac-filter-acct-radius-server secondary "" mac-filter-state disabled rekey period 0 group-rekey interval 0 bksa-caching-period 43200 radius-server primary "" radius-server secondary "" auth-supplicant-timeout 30 auth-server-timeout 30 auth-max-request 4 pae-max-reauth 4 pae-txperiod 30 eapol-key-retries no kddi no captive-portal no shared-authentication no rekey period no 8021x-network-initiation no pmk-caching no reauth no captive-portal-bypass-mac no macfiltering exitsecurity-profile WPA2PSK security-version 0 key-rotation disabled management-frame-protection-11w disable allowed-l2-modes wpa2-psk online-sign-up not-configured captive-portal disabled captive-portal-profile "" captive-portal-auth-method internal encryption-modes ccmp psk key comptest firewall-capability none passthrough-firewall-filter-id "" firewall-filter-id "" security-logging off owner controller static-wep key "" static-wep key-index 1 mac-filter-radius-server primary "" mac-filter-radius-server secondary "" mac-filter-acct-radius-server primary "" mac-filter-acct-radius-server secondary "" mac-filter-state disabled rekey period 0 group-rekey interval 0 bksa-caching-period 0 radius-server primary "" radius-server secondary "" auth-supplicant-timeout 30 auth-server-timeout 30 auth-max-request 4 pae-max-reauth 4 pae-txperiod 30 eapol-key-retries no kddi no captive-portal no shared-authentication no rekey period no 8021x-network-initiation no pmk-caching no reauth no captive-portal-bypass-mac no macfiltering exitsecurity-profile WPA2dot1x security-version 0 key-rotation disabled management-frame-protection-11w disable allowed-l2-modes wpa2 online-sign-up not-configured captive-portal disabled captive-portal-profile "" captive-portal-auth-method internal encryption-modes ccmp psk key "" firewall-capability none passthrough-firewall-filter-id "" firewall-filter-id "" security-logging off owner controller static-wep key "" static-wep key-index 1 reauth mac-filter-radius-server primary "" mac-filter-radius-server secondary "" mac-filter-acct-radius-server primary "" mac-filter-acct-radius-server secondary "" mac-filter-state disabled rekey period 0 group-rekey interval 0 bksa-caching-period 0 8021x-network-initiation pmk-caching radius-server primary FreeRadius radius-server secondary "" auth-supplicant-timeout 30 auth-server-timeout 30 auth-max-request 4 pae-max-reauth 4 pae-txperiod 30 eapol-key-retries no kddi no captive-portal no shared-authentication no rekey period no captive-portal-bypass-mac no macfiltering exitinterface Dot11Radio 14 1 fg-id 0 override off channel 6 rf-mode 802.11bgn localpower 24 preamble-short admin-mode Up bg-protection-mode auto ht-protection-mode off channel-width 20-mhz rf-virtual-mode NativeCell transmit-beamforming-support off stbc-support off probe-response-threshold 15 dfs-fallback-option disable vht-support disable dfs-fallback-channel 6 dfs-channe-revertive 30 no n-only-mode default protection-mode mesh disable mode service antenna-property 4 fg-id 0 rfband dual link Point-To-Multi-Point override off antenna-gain 2.4GHz 3 antenna-gain 5GHz 3 exit antenna-property 2 fg-id 0 rfband dual link Point-To-Multi-Point override off antenna-gain 2.4GHz 3 antenna-gain 5GHz 3 exit antenna-property 3 fg-id 0 rfband dual link Point-To-Multi-Point override off antenna-gain 2.4GHz 3 antenna-gain 5GHz 3 exit antenna-property 1 fg-id 0 rfband dual link Point-To-Multi-Point override off antenna-gain 2.4GHz 3 antenna-gain 5GHz 3 exit exitinterface Dot11Radio 14 2 fg-id 0 override off channel 36 rf-mode 802.11ac localpower 23 admin-mode Up bg-protection-mode auto ht-protection-mode off channel-width 20-mhz mimo-mode 3x3 rf-virtual-mode NativeCell transmit-beamforming-support on_mu_mimo stbc-support off probe-response-threshold 15 dfs-fallback-option disable vht-support disable dfs-fallback-channel 36 dfs-channe-revertive 30 no preamble-short no n-only-mode default protection-mode mesh disable mode service antenna-property 2 fg-id 0 rfband dual link Point-To-Multi-Point override off antenna-gain 2.4GHz 3 antenna-gain 5GHz 3 exit antenna-property 3 fg-id 0 rfband dual link Point-To-Multi-Point override off antenna-gain 2.4GHz 3 antenna-gain 5GHz 3 exit antenna-property 1 fg-id 0 rfband dual link Point-To-Multi-Point override off antenna-gain 2.4GHz 3 antenna-gain 5GHz 3 exit antenna-property 4 fg-id 0 rfband dual link Point-To-Multi-Point override off antenna-gain 2.4GHz 3 antenna-gain 5GHz 3 exit exitinterface Dot11Radio 15 1 fg-id 0 override off channel 6 rf-mode 802.11bgn localpower 24 preamble-short admin-mode Up bg-protection-mode auto ht-protection-mode off channel-width 20-mhz mimo-mode 3x3 rf-virtual-mode NativeCell transmit-beamforming-support off stbc-support off probe-response-threshold 15 dfs-fallback-option disable vht-support disable dfs-fallback-channel 6 dfs-channe-revertive 30 no n-only-mode default protection-mode mesh disable mode service antenna-property 2 fg-id 0 rfband dual link Point-To-Multi-Point override off antenna-gain 2.4GHz 3 antenna-gain 5GHz 4 exit antenna-property 1 fg-id 0 rfband dual link Point-To-Multi-Point override off antenna-gain 2.4GHz 3 antenna-gain 5GHz 4 exit antenna-property 3 fg-id 0 rfband dual link Point-To-Multi-Point override off antenna-gain 2.4GHz 3 antenna-gain 5GHz 4 exit exitinterface Dot11Radio 15 2 fg-id 0 override off channel 36 rf-mode 802.11ac localpower 23 admin-mode Up bg-protection-mode auto ht-protection-mode off channel-width 80-mhz mimo-mode 3x3 rf-virtual-mode NativeCell transmit-beamforming-support off stbc-support off probe-response-threshold 15 dfs-fallback-option disable vht-support disable dfs-fallback-channel 36 dfs-channe-revertive 30 no preamble-short no n-only-mode default protection-mode mesh disable mode service antenna-property 1 fg-id 0 rfband dual link Point-To-Multi-Point override off antenna-gain 2.4GHz 3 antenna-gain 5GHz 4 exit antenna-property 3 fg-id 0 rfband dual link Point-To-Multi-Point override off antenna-gain 2.4GHz 3 antenna-gain 5GHz 4 exit antenna-property 2 fg-id 0 rfband dual link Point-To-Multi-Point override off antenna-gain 2.4GHz 3 antenna-gain 5GHz 4 exit exitinterface ap 14 1 enable exitinterface ap 14 2 enable exitinterface ap 15 1 enable exitinterface ap 15 2 enable exitport-profile default disable vlan name "" vlantrunk disable reconnect-primary-server 10 dataplane tunneled port-ap-vlan-policy none port-ap-vlan-tag 0 owner controller security-profile "" accounting interim-interval 3600 accounting primary-radius "" accounting secondary-radius "" no multicast-enable no ip-prefix-validation no ipv6-bridging exitqoscodec 22 codec h263 qosprotocol sip tokenbucketrate 34500 maxdatagramsize 1400 minpolicedunit 0 samplerate 30 tokenbucketsize 6000 peakrate 41400 rspecrate 34500 rspecslack 33000 owner controller exitqoscodec 21 codec h261 qosprotocol sip tokenbucketrate 9600 maxdatagramsize 1400 minpolicedunit 0 samplerate 30 tokenbucketsize 1600 peakrate 11520 rspecrate 9600 rspecslack 33000 owner controller exitqoscodec 20 codec siren qosprotocol sip tokenbucketrate 4000 maxdatagramsize 80 minpolicedunit 0 samplerate 50 tokenbucketsize 160 peakrate 4800 rspecrate 4000 rspecslack 20000 owner controller exitqoscodec 19 codec g729 qosprotocol sip tokenbucketrate 3000 maxdatagramsize 60 minpolicedunit 0 samplerate 50 tokenbucketsize 120 peakrate 3300 rspecrate 3000 rspecslack 20000 owner controller exitqoscodec 18 codec g7221-32 qosprotocol sip tokenbucketrate 6000 maxdatagramsize 120 minpolicedunit 0 samplerate 50 tokenbucketsize 240 peakrate 7200 rspecrate 6000 rspecslack 20000 owner controller exitqoscodec 17 codec g7221 qosprotocol sip tokenbucketrate 5000 maxdatagramsize 100 minpolicedunit 0 samplerate 50 tokenbucketsize 200 peakrate 6000 rspecrate 5000 rspecslack 20000 owner controller exitqoscodec 16 codec g711a qosprotocol sip tokenbucketrate 10000 maxdatagramsize 200 minpolicedunit 0 samplerate 50 tokenbucketsize 400 peakrate 11000 rspecrate 10000 rspecslack 20000 owner controller exitqoscodec 15 codec g723.1 qosprotocol sip tokenbucketrate 2100 maxdatagramsize 64 minpolicedunit 0 samplerate 33 tokenbucketsize 128 peakrate 2500 rspecrate 2100 rspecslack 10000 owner controller exitqoscodec 14 codec gsm qosprotocol sip tokenbucketrate 3650 maxdatagramsize 75 minpolicedunit 0 samplerate 50 tokenbucketsize 150 peakrate 4380 rspecrate 3650 rspecslack 20000 owner controller exitqoscodec 13 codec g711u qosprotocol sip tokenbucketrate 10000 maxdatagramsize 200 minpolicedunit 0 samplerate 50 tokenbucketsize 400 peakrate 11000 rspecrate 10000 rspecslack 20000 owner controller exitqoscodec 12 codec default qosprotocol sip tokenbucketrate 10000 maxdatagramsize 200 minpolicedunit 0 samplerate 50 tokenbucketsize 400 peakrate 11000 rspecrate 10000 rspecslack 20000 owner controller exitqoscodec 11 codec h263 qosprotocol h323 tokenbucketrate 34500 maxdatagramsize 1400 minpolicedunit 0 samplerate 30 tokenbucketsize 6000 peakrate 41400 rspecrate 34500 rspecslack 33000 owner controller exitqoscodec 10 codec h261 qosprotocol h323 tokenbucketrate 9600 maxdatagramsize 1400 minpolicedunit 0 samplerate 30 tokenbucketsize 1600 peakrate 11520 rspecrate 9600 rspecslack 33000 owner controller exitqoscodec 9 codec siren qosprotocol h323 tokenbucketrate 4000 maxdatagramsize 80 minpolicedunit 0 samplerate 50 tokenbucketsize 160 peakrate 4800 rspecrate 4000 rspecslack 20000 owner controller exitqoscodec 8 codec g729 qosprotocol h323 tokenbucketrate 3000 maxdatagramsize 60 minpolicedunit 0 samplerate 50 tokenbucketsize 120 peakrate 3300 rspecrate 3000 rspecslack 20000 owner controller exitqoscodec 7 codec g7221-32 qosprotocol h323 tokenbucketrate 6000 maxdatagramsize 120 minpolicedunit 0 samplerate 50 tokenbucketsize 240 peakrate 7200 rspecrate 6000 rspecslack 20000 owner controller exitqoscodec 6 codec g7221 qosprotocol h323 tokenbucketrate 5000 maxdatagramsize 100 minpolicedunit 0 samplerate 50 tokenbucketsize 200 peakrate 6000 rspecrate 5000 rspecslack 20000 owner controller exitqoscodec 5 codec g711a qosprotocol h323 tokenbucketrate 10000 maxdatagramsize 200 minpolicedunit 0 samplerate 50 tokenbucketsize 400 peakrate 11000 rspecrate 10000 rspecslack 20000 owner controller exitqoscodec 4 codec g723.1 qosprotocol h323 tokenbucketrate 2100 maxdatagramsize 64 minpolicedunit 0 samplerate 33 tokenbucketsize 128 peakrate 2500 rspecrate 2100 rspecslack 10000 owner controller exitqoscodec 3 codec gsm qosprotocol h323 tokenbucketrate 3650 maxdatagramsize 75 minpolicedunit 0 samplerate 50 tokenbucketsize 150 peakrate 4380 rspecrate 3650 rspecslack 20000 owner controller exitqoscodec 2 codec g711u qosprotocol h323 tokenbucketrate 10000 maxdatagramsize 200 minpolicedunit 0 samplerate 50 tokenbucketsize 400 peakrate 11000 rspecrate 10000 rspecslack 20000 owner controller exitqoscodec 1 codec default qosprotocol h323 tokenbucketrate 10000 maxdatagramsize 200 minpolicedunit 0 samplerate 50 tokenbucketsize 400 peakrate 11000 rspecrate 10000 rspecslack 20000 owner controller exitqosrule 1 netprotocol 6 qosprotocol h323 firewall-filter-id "" dstip 0.0.0.0 dstmask 0.0.0.0 dstport 1720 dstport-match on srcip 0.0.0.0 srcmask 0.0.0.0 srcport 0 netprotocol-match on action capture priority 0 avgpacketrate 0 tokenbucketrate 0 dscp disabled qosrulelogging off qosrule-logging-frequency 60 packet-min-length 0 packet-max-length 0 no trafficcontrol owner controller exitqosrule 2 netprotocol 6 qosprotocol h323 firewall-filter-id "" dstip 0.0.0.0 dstmask 0.0.0.0 dstport 0 srcip 0.0.0.0 srcmask 0.0.0.0 srcport 1720 srcport-match on netprotocol-match on action capture priority 0 avgpacketrate 0 tokenbucketrate 0 dscp disabled qosrulelogging off qosrule-logging-frequency 60 packet-min-length 0 packet-max-length 0 no trafficcontrol owner controller exitqosrule 3 netprotocol 17 qosprotocol sip firewall-filter-id "" dstip 0.0.0.0 dstmask 0.0.0.0 dstport 5060 dstport-match on srcip 0.0.0.0 srcmask 0.0.0.0 srcport 0 netprotocol-match on action capture priority 0 avgpacketrate 0 tokenbucketrate 0 dscp disabled qosrulelogging off qosrule-logging-frequency 60 packet-min-length 0 packet-max-length 0 no trafficcontrol owner controller exitqosrule 5 netprotocol 6 qosprotocol sip firewall-filter-id "" dstip 0.0.0.0 dstmask 0.0.0.0 dstport 5060 dstport-match on srcip 0.0.0.0 srcmask 0.0.0.0 srcport 0 netprotocol-match on action capture priority 0 avgpacketrate 0 tokenbucketrate 0 dscp disabled qosrulelogging off qosrule-logging-frequency 60 packet-min-length 0 packet-max-length 0 no trafficcontrol owner controller exitqosrule 7 netprotocol 17 qosprotocol other firewall-filter-id "" dstip 0.0.0.0 dstmask 0.0.0.0 dstport 5200 dstport-match on srcip 0.0.0.0 srcmask 0.0.0.0 srcport 0 netprotocol-match on action forward priority 0 avgpacketrate 27 tokenbucketrate 9100 dscp disabled qosrulelogging off qosrule-logging-frequency 60 packet-min-length 0 packet-max-length 0 no trafficcontrol owner controller exitqosrule 8 netprotocol 17 qosprotocol other firewall-filter-id "" dstip 0.0.0.0 dstmask 0.0.0.0 dstport 0 srcip 0.0.0.0 srcmask 0.0.0.0 srcport 5200 srcport-match on netprotocol-match on action forward priority 0 avgpacketrate 27 tokenbucketrate 9100 dscp disabled qosrulelogging off qosrule-logging-frequency 60 packet-min-length 0 packet-max-length 0 no trafficcontrol owner controller exitessid MeruIntop enable security-profile default hotspot-profile "" backup-ess-profile "" timer-profile "" virtual-interface-profile name "" ess-version 0 tunnel-type none vlan name "" vlan-pool name "" gre name "" ip-prefix-validation-enable multicast-to-unicast-conversion rf-virtual-mode VirtualCell s1-vht-base-mcs mcs0-9 s2-vht-base-mcs mcs0-9 s3-vht-base-mcs mcs0-9 s4-vht-base-mcs mcs0-9 s1-vht-support-mcs mcs0-9 s2-vht-support-mcs mcs0-9 s3-vht-support-mcs mcs0-9 s4-vht-support-mcs mcs0-9 voice-client-type none countermeasure ap-vlan-policy none ap-vlan-tag 0 band-steering-mode disable band-steering-timeout 5 expedited-forward-override dataplane tunneled ssid MeruIntop owner controller ap-discovery join-ess publish-essid on publish-essid-vport disabled apsd-support l2bridge none beacon dtim-period 5 beacon period 100 supported-tx-rates 802.11b 1 supported-tx-rates 802.11b 2 supported-tx-rates 802.11b 5.5 supported-tx-rates 802.11b 11 supported-tx-rates 802.11a 6 supported-tx-rates 802.11a 9 supported-tx-rates 802.11a 12 supported-tx-rates 802.11a 18 supported-tx-rates 802.11a 24 supported-tx-rates 802.11a 36 supported-tx-rates 802.11a 48 supported-tx-rates 802.11a 54 supported-tx-rates 802.11an 6 supported-tx-rates 802.11an 9 supported-tx-rates 802.11an 12 supported-tx-rates 802.11an 18 supported-tx-rates 802.11an 24 supported-tx-rates 802.11an 36 supported-tx-rates 802.11an 48 supported-tx-rates 802.11an 54 supported-tx-rates 802.11an-mcs 0 supported-tx-rates 802.11an-mcs 1 supported-tx-rates 802.11an-mcs 2 supported-tx-rates 802.11an-mcs 3 supported-tx-rates 802.11an-mcs 4 supported-tx-rates 802.11an-mcs 5 supported-tx-rates 802.11an-mcs 6 supported-tx-rates 802.11an-mcs 7 supported-tx-rates 802.11an-mcs 8 supported-tx-rates 802.11an-mcs 9 supported-tx-rates 802.11an-mcs 10 supported-tx-rates 802.11an-mcs 11 supported-tx-rates 802.11an-mcs 12 supported-tx-rates 802.11an-mcs 13 supported-tx-rates 802.11an-mcs 14 supported-tx-rates 802.11an-mcs 15 supported-tx-rates 802.11an-mcs 16 supported-tx-rates 802.11an-mcs 17 supported-tx-rates 802.11an-mcs 18 supported-tx-rates 802.11an-mcs 19 supported-tx-rates 802.11an-mcs 20 supported-tx-rates 802.11an-mcs 21 supported-tx-rates 802.11an-mcs 22 supported-tx-rates 802.11an-mcs 23 supported-tx-rates 802.11g 6 supported-tx-rates 802.11g 9 supported-tx-rates 802.11g 12 supported-tx-rates 802.11g 18 supported-tx-rates 802.11g 24 supported-tx-rates 802.11g 36 supported-tx-rates 802.11g 48 supported-tx-rates 802.11g 54 supported-tx-rates 802.11bg 1 supported-tx-rates 802.11bg 2 supported-tx-rates 802.11bg 5.5 supported-tx-rates 802.11bg 11 supported-tx-rates 802.11bg 6 supported-tx-rates 802.11bg 9 supported-tx-rates 802.11bg 12 supported-tx-rates 802.11bg 18 supported-tx-rates 802.11bg 24 supported-tx-rates 802.11bg 36 supported-tx-rates 802.11bg 48 supported-tx-rates 802.11bg 54 supported-tx-rates 802.11bgn 11 supported-tx-rates 802.11bgn 12 supported-tx-rates 802.11bgn 18 supported-tx-rates 802.11bgn 24 supported-tx-rates 802.11bgn 36 supported-tx-rates 802.11bgn 48 supported-tx-rates 802.11bgn 54 supported-tx-rates 802.11bgn-mcs 0 supported-tx-rates 802.11bgn-mcs 1 supported-tx-rates 802.11bgn-mcs 2 supported-tx-rates 802.11bgn-mcs 3 supported-tx-rates 802.11bgn-mcs 4 supported-tx-rates 802.11bgn-mcs 5 supported-tx-rates 802.11bgn-mcs 6 supported-tx-rates 802.11bgn-mcs 7 supported-tx-rates 802.11bgn-mcs 8 supported-tx-rates 802.11bgn-mcs 9 supported-tx-rates 802.11bgn-mcs 10 supported-tx-rates 802.11bgn-mcs 11 supported-tx-rates 802.11bgn-mcs 12 supported-tx-rates 802.11bgn-mcs 13 supported-tx-rates 802.11bgn-mcs 14 supported-tx-rates 802.11bgn-mcs 15 supported-tx-rates 802.11bgn-mcs 16 supported-tx-rates 802.11bgn-mcs 17 supported-tx-rates 802.11bgn-mcs 18 supported-tx-rates 802.11bgn-mcs 19 supported-tx-rates 802.11bgn-mcs 20 supported-tx-rates 802.11bgn-mcs 21 supported-tx-rates 802.11bgn-mcs 22 supported-tx-rates 802.11bgn-mcs 23 base-tx-rates 802.11b 11 base-tx-rates 802.11a 6 base-tx-rates 802.11a 12 base-tx-rates 802.11a 24 base-tx-rates 802.11an 6 base-tx-rates 802.11an 12 base-tx-rates 802.11an 24 base-tx-rates 802.11an-mcs none base-tx-rates 802.11g 6 base-tx-rates 802.11g 9 base-tx-rates 802.11g 12 base-tx-rates 802.11g 18 base-tx-rates 802.11g 24 base-tx-rates 802.11g 36 base-tx-rates 802.11g 48 base-tx-rates 802.11g 54 base-tx-rates 802.11bg 11 base-tx-rates 802.11bgn 11 base-tx-rates 802.11bgn-mcs none accounting interim-interval 3600 reconnect-primary-server 10 accounting primary-radius "" accounting secondary-radius "" no backup-ess-profile no timer-profile no accounting-radius all no multicast-enable no force-dhcp no wireless-to-wireless-isolation no acm-support all no multicast-mac-transparency no ap-vlan-priority no vlan ess-ap 15 2 calls-per-bss 0 exit ess-ap 15 1 calls-per-bss 0 exit ess-ap 14 2 calls-per-bss 0 exit ess-ap 14 1 calls-per-bss 0 exit exitessid MeruIntopPSK enable security-profile WPA2PSK hotspot-profile "" backup-ess-profile "" timer-profile "" virtual-interface-profile name "" ess-version 0 tunnel-type none vlan name "" vlan-pool name "" gre name "" ip-prefix-validation-enable multicast-to-unicast-conversion rf-virtual-mode VirtualCell s1-vht-base-mcs mcs0-9 s2-vht-base-mcs mcs0-9 s3-vht-base-mcs mcs0-9 s4-vht-base-mcs mcs0-9 s1-vht-support-mcs mcs0-9 s2-vht-support-mcs mcs0-9 s3-vht-support-mcs mcs0-9 s4-vht-support-mcs mcs0-9 voice-client-type ascom ap-vlan-policy none ap-vlan-tag 0 band-steering-mode disable band-steering-timeout 5 expedited-forward-override dataplane tunneled ssid MeruIntopPSK owner controller ap-discovery join-ess publish-essid on publish-essid-vport disabled apsd-support l2bridge none beacon dtim-period 5 beacon period 100 supported-tx-rates 802.11b 1 supported-tx-rates 802.11b 2 supported-tx-rates 802.11b 5.5 supported-tx-rates 802.11b 11 supported-tx-rates 802.11a 6 supported-tx-rates 802.11a 9 supported-tx-rates 802.11a 12 supported-tx-rates 802.11a 18 supported-tx-rates 802.11a 24 supported-tx-rates 802.11a 36 supported-tx-rates 802.11a 48 supported-tx-rates 802.11a 54 supported-tx-rates 802.11an 12 supported-tx-rates 802.11an 18 supported-tx-rates 802.11an 24 supported-tx-rates 802.11an 36 supported-tx-rates 802.11an 48 supported-tx-rates 802.11an 54 supported-tx-rates 802.11an-mcs 0 supported-tx-rates 802.11an-mcs 1 supported-tx-rates 802.11an-mcs 2 supported-tx-rates 802.11an-mcs 3 supported-tx-rates 802.11an-mcs 4 supported-tx-rates 802.11an-mcs 5 supported-tx-rates 802.11an-mcs 6 supported-tx-rates 802.11an-mcs 7 supported-tx-rates 802.11an-mcs 8 supported-tx-rates 802.11an-mcs 9 supported-tx-rates 802.11an-mcs 10 supported-tx-rates 802.11an-mcs 11 supported-tx-rates 802.11an-mcs 12 supported-tx-rates 802.11an-mcs 13 supported-tx-rates 802.11an-mcs 14 supported-tx-rates 802.11an-mcs 15 supported-tx-rates 802.11an-mcs 16 supported-tx-rates 802.11an-mcs 17 supported-tx-rates 802.11an-mcs 18 supported-tx-rates 802.11an-mcs 19 supported-tx-rates 802.11an-mcs 20 supported-tx-rates 802.11an-mcs 21 supported-tx-rates 802.11an-mcs 22 supported-tx-rates 802.11an-mcs 23 supported-tx-rates 802.11g 6 supported-tx-rates 802.11g 9 supported-tx-rates 802.11g 12 supported-tx-rates 802.11g 18 supported-tx-rates 802.11g 24 supported-tx-rates 802.11g 36 supported-tx-rates 802.11g 48 supported-tx-rates 802.11g 54 supported-tx-rates 802.11bg 1 supported-tx-rates 802.11bg 2 supported-tx-rates 802.11bg 5.5 supported-tx-rates 802.11bg 11 supported-tx-rates 802.11bg 6 supported-tx-rates 802.11bg 9 supported-tx-rates 802.11bg 12 supported-tx-rates 802.11bg 18 supported-tx-rates 802.11bg 24 supported-tx-rates 802.11bg 36 supported-tx-rates 802.11bg 48 supported-tx-rates 802.11bg 54 supported-tx-rates 802.11bgn 12 supported-tx-rates 802.11bgn 18 supported-tx-rates 802.11bgn 24 supported-tx-rates 802.11bgn 36 supported-tx-rates 802.11bgn 48 supported-tx-rates 802.11bgn 54 supported-tx-rates 802.11bgn-mcs 0 supported-tx-rates 802.11bgn-mcs 1 supported-tx-rates 802.11bgn-mcs 2 supported-tx-rates 802.11bgn-mcs 3 supported-tx-rates 802.11bgn-mcs 4 supported-tx-rates 802.11bgn-mcs 5 supported-tx-rates 802.11bgn-mcs 6 supported-tx-rates 802.11bgn-mcs 7 supported-tx-rates 802.11bgn-mcs 8 supported-tx-rates 802.11bgn-mcs 9 supported-tx-rates 802.11bgn-mcs 10 supported-tx-rates 802.11bgn-mcs 11 supported-tx-rates 802.11bgn-mcs 12 supported-tx-rates 802.11bgn-mcs 13 supported-tx-rates 802.11bgn-mcs 14 supported-tx-rates 802.11bgn-mcs 15 supported-tx-rates 802.11bgn-mcs 16 supported-tx-rates 802.11bgn-mcs 17 supported-tx-rates 802.11bgn-mcs 18 supported-tx-rates 802.11bgn-mcs 19 supported-tx-rates 802.11bgn-mcs 20 supported-tx-rates 802.11bgn-mcs 21 supported-tx-rates 802.11bgn-mcs 22 supported-tx-rates 802.11bgn-mcs 23 base-tx-rates 802.11b 11 base-tx-rates 802.11a 6 base-tx-rates 802.11a 12 base-tx-rates 802.11a 24 base-tx-rates 802.11an 12 base-tx-rates 802.11an 24 base-tx-rates 802.11an-mcs none base-tx-rates 802.11g 6 base-tx-rates 802.11g 9 base-tx-rates 802.11g 12 base-tx-rates 802.11g 18 base-tx-rates 802.11g 24 base-tx-rates 802.11g 36 base-tx-rates 802.11g 48 base-tx-rates 802.11g 54 base-tx-rates 802.11bg 11 base-tx-rates 802.11bgn 12 base-tx-rates 802.11bgn-mcs none accounting interim-interval 3600 reconnect-primary-server 10 accounting primary-radius "" accounting secondary-radius "" no backup-ess-profile no timer-profile no accounting-radius all no multicast-enable no force-dhcp no wireless-to-wireless-isolation no acm-support all no countermeasure no multicast-mac-transparency no ap-vlan-priority no vlan ess-ap 15 2 calls-per-bss 0 exit ess-ap 15 1 calls-per-bss 0 exit ess-ap 14 2 calls-per-bss 0 exit ess-ap 14 1 calls-per-bss 0 exit exitessid MeruIntop1x enable security-profile WPA2dot1x hotspot-profile "" backup-ess-profile "" timer-profile "" virtual-interface-profile name "" ess-version 0 tunnel-type none vlan name "" vlan-pool name "" gre name "" ip-prefix-validation-enable multicast-to-unicast-conversion rf-virtual-mode NativeCell s1-vht-base-mcs mcs0-9 s2-vht-base-mcs mcs0-9 s3-vht-base-mcs mcs0-9 s4-vht-base-mcs mcs0-9 s1-vht-support-mcs mcs0-9 s2-vht-support-mcs mcs0-9 s3-vht-support-mcs mcs0-9 s4-vht-support-mcs mcs0-9 voice-client-type none countermeasure ap-vlan-policy none ap-vlan-tag 0 band-steering-mode disable band-steering-timeout 5 expedited-forward-override dataplane tunneled ssid MeruIntop1x owner controller ap-discovery join-ess publish-essid on publish-essid-vport disabled apsd-support l2bridge none beacon dtim-period 5 beacon period 100 supported-tx-rates 802.11b 1 supported-tx-rates 802.11b 2 supported-tx-rates 802.11b 5.5 supported-tx-rates 802.11b 11 supported-tx-rates 802.11a 6 supported-tx-rates 802.11a 9 supported-tx-rates 802.11a 12 supported-tx-rates 802.11a 18 supported-tx-rates 802.11a 24 supported-tx-rates 802.11a 36 supported-tx-rates 802.11a 48 supported-tx-rates 802.11a 54 supported-tx-rates 802.11an 12 supported-tx-rates 802.11an 18 supported-tx-rates 802.11an 24 supported-tx-rates 802.11an 36 supported-tx-rates 802.11an 48 supported-tx-rates 802.11an 54 supported-tx-rates 802.11an-mcs 0 supported-tx-rates 802.11an-mcs 1 supported-tx-rates 802.11an-mcs 2 supported-tx-rates 802.11an-mcs 3 supported-tx-rates 802.11an-mcs 4 supported-tx-rates 802.11an-mcs 5 supported-tx-rates 802.11an-mcs 6 supported-tx-rates 802.11an-mcs 7 supported-tx-rates 802.11an-mcs 8 supported-tx-rates 802.11an-mcs 9 supported-tx-rates 802.11an-mcs 10 supported-tx-rates 802.11an-mcs 11 supported-tx-rates 802.11an-mcs 12 supported-tx-rates 802.11an-mcs 13 supported-tx-rates 802.11an-mcs 14 supported-tx-rates 802.11an-mcs 15 supported-tx-rates 802.11an-mcs 16 supported-tx-rates 802.11an-mcs 17 supported-tx-rates 802.11an-mcs 18 supported-tx-rates 802.11an-mcs 19 supported-tx-rates 802.11an-mcs 20 supported-tx-rates 802.11an-mcs 21 supported-tx-rates 802.11an-mcs 22 supported-tx-rates 802.11an-mcs 23 supported-tx-rates 802.11g 6 supported-tx-rates 802.11g 9 supported-tx-rates 802.11g 12 supported-tx-rates 802.11g 18 supported-tx-rates 802.11g 24 supported-tx-rates 802.11g 36 supported-tx-rates 802.11g 48 supported-tx-rates 802.11g 54 supported-tx-rates 802.11bg 1 supported-tx-rates 802.11bg 2 supported-tx-rates 802.11bg 5.5 supported-tx-rates 802.11bg 11 supported-tx-rates 802.11bg 6 supported-tx-rates 802.11bg 9 supported-tx-rates 802.11bg 12 supported-tx-rates 802.11bg 18 supported-tx-rates 802.11bg 24 supported-tx-rates 802.11bg 36 supported-tx-rates 802.11bg 48 supported-tx-rates 802.11bg 54 supported-tx-rates 802.11bgn 12 supported-tx-rates 802.11bgn 18 supported-tx-rates 802.11bgn 24 supported-tx-rates 802.11bgn 36 supported-tx-rates 802.11bgn 48 supported-tx-rates 802.11bgn 54 supported-tx-rates 802.11bgn-mcs 0 supported-tx-rates 802.11bgn-mcs 1 supported-tx-rates 802.11bgn-mcs 2 supported-tx-rates 802.11bgn-mcs 3 supported-tx-rates 802.11bgn-mcs 4 supported-tx-rates 802.11bgn-mcs 5 supported-tx-rates 802.11bgn-mcs 6 supported-tx-rates 802.11bgn-mcs 7 supported-tx-rates 802.11bgn-mcs 8 supported-tx-rates 802.11bgn-mcs 9 supported-tx-rates 802.11bgn-mcs 10 supported-tx-rates 802.11bgn-mcs 11 supported-tx-rates 802.11bgn-mcs 12 supported-tx-rates 802.11bgn-mcs 13 supported-tx-rates 802.11bgn-mcs 14 supported-tx-rates 802.11bgn-mcs 15 supported-tx-rates 802.11bgn-mcs 16 supported-tx-rates 802.11bgn-mcs 17 supported-tx-rates 802.11bgn-mcs 18 supported-tx-rates 802.11bgn-mcs 19 supported-tx-rates 802.11bgn-mcs 20 supported-tx-rates 802.11bgn-mcs 21 supported-tx-rates 802.11bgn-mcs 22 supported-tx-rates 802.11bgn-mcs 23 base-tx-rates 802.11b 11 base-tx-rates 802.11a 6 base-tx-rates 802.11a 12 base-tx-rates 802.11a 24 base-tx-rates 802.11an 12 base-tx-rates 802.11an 24 base-tx-rates 802.11an-mcs none base-tx-rates 802.11g 6 base-tx-rates 802.11g 9 base-tx-rates 802.11g 12 base-tx-rates 802.11g 18 base-tx-rates 802.11g 24 base-tx-rates 802.11g 36 base-tx-rates 802.11g 48 base-tx-rates 802.11g 54 base-tx-rates 802.11bg 11 base-tx-rates 802.11bgn 12 base-tx-rates 802.11bgn-mcs none accounting interim-interval 3600 reconnect-primary-server 10 accounting primary-radius FreeRadius accounting secondary-radius "" no backup-ess-profile no timer-profile no accounting-radius secondary no multicast-enable no force-dhcp no wireless-to-wireless-isolation no acm-support all no multicast-mac-transparency no ap-vlan-priority no vlan ess-ap 15 2 calls-per-bss 0 exit ess-ap 15 1 calls-per-bss 0 exit ess-ap 14 1 calls-per-bss 0 exit ess-ap 14 2 calls-per-bss 0 exit exitvpn server vpn-server-ip 192.168.0.23 vpn-server-hostname "" port 1194 ip-pool 192.168.0.0 subnet-mask 255.255.0.0 exitevent "Admin Login Failure" state enable severity Critical syslog enable snmp enable threshold 1 exitevent "User 802.1x Authentication Failure" state enable severity Major syslog enable snmp enable threshold 0 exitevent "User TKIP Message Integrity Check Failure" state enable severity Major syslog enable snmp enable threshold 0 exitevent "MIC Counter Measure Activation" state enable severity Major syslog enable snmp enable threshold 0 exitevent "CAC limit reached" state enable severity Major syslog enable snmp enable threshold 0 exitevent "Controller IP Address Change" state enable severity Major syslog enable snmp enable threshold 0 exitevent "DFS Channel Update" state enable severity Major syslog enable snmp enable threshold 0 exitevent "Certificate Error" state enable severity Info syslog enable snmp enable threshold 0 exitevent "Certificate Installed" state enable severity Info syslog enable snmp enable threshold 0 exitevent "Radius Server Switchover" state enable severity Info syslog enable snmp enable threshold 0 exitevent "Radius Server Switchover Failure" state enable severity Major syslog enable snmp enable threshold 0 exitevent "Alarm History Reaches Threshold" state enable severity Major syslog enable snmp enable threshold 90 exitevent "Event Log Reaches Threshold" state enable severity Major syslog enable snmp enable threshold 90 exitevent "Radius Server Restored" state enable severity Info syslog enable snmp enable threshold 0 exitevent "System ID Changed" state enable severity Info syslog enable snmp enable threshold 0 exitevent "Interference Detected" state enable severity Major syslog enable snmp enable threshold 0 exitevent "High Channel Utilization" state enable severity Minor syslog enable snmp enable threshold 0 exitevent "Low Channel Quality" state enable severity Minor syslog enable snmp enable threshold 0 exitevent "No License Enforcement on Active Slave will be expired" state enable severity Minor syslog enable snmp enable threshold 0 exitevent "Power is not AT. Disabling lacp." state enable severity Major syslog enable snmp enable threshold 0 exitevent "Switch doesnot support LACP. Disabling lacp." state enable severity Major syslog enable snmp enable threshold 0 exitevent "Reinitialization of Database" state enable severity Info syslog enable snmp enable threshold 0 exitevent "AP model not supported" state enable severity Critical syslog enable snmp enable threshold 0 exitevent "Service Down" state enable severity Info syslog enable snmp enable threshold 0 exitevent "Planning channel not good" state enable severity Critical syslog enable snmp enable threshold 0 exitevent "RF positioning of AP is not proper" state enable severity Info syslog enable snmp enable threshold 0 exitevent "Channel changed due to dynamic update from ARRP" state enable severity Info syslog enable snmp enable threshold 0 exitevent "AP Power Supply Change Notification" state enable severity Info syslog enable snmp enable threshold 0 exitevent "AP Low Power Supply Notification" state enable severity Info syslog enable snmp enable threshold 0 exitevent "ESS Exceed Limit" state enable severity Info syslog enable snmp enable threshold 0 exitevent "Process Core" state enable severity Major syslog enable snmp enable threshold 0 exitalarm "Link Down" state enable severity Critical syslog enable snmp enable threshold 0 exitalarm "AP Down" state enable severity Critical syslog enable snmp enable threshold 0 exitalarm "AP Wireless Interface Down" state enable severity Critical syslog enable snmp enable threshold 0 exitalarm "AP Software Version Mismatch" state enable severity Critical syslog enable snmp enable threshold 0 exitalarm "Software License Expired" state enable severity Critical syslog enable snmp enable threshold 0 exitalarm "Software License Violated" state enable severity Critical syslog enable snmp enable threshold 0 exitalarm "Master Down" state enable severity Critical syslog enable snmp enable threshold 0 exitalarm "AP Wireless Interface Station Capacity Full" state enable severity Critical syslog enable snmp enable threshold 0 exitalarm "Controller Memory Usage High" state enable severity Major syslog enable snmp enable threshold 70 exitalarm "Controller CPU Usage High" state enable severity Major syslog enable snmp enable threshold 80 exitalarm "AP Memory Usage High" state enable severity Major syslog enable snmp enable threshold 70 exitalarm "AP CPU Usage High" state enable severity Major syslog enable snmp enable threshold 80 exitalarm "DHCP Address Pool Exhausted" state enable severity Critical syslog enable snmp enable threshold 90 exitalarm "Watchdog Failure" state enable severity Critical syslog enable snmp enable threshold 0 exitalarm "AP Radio Card Failure" state enable severity Critical syslog enable snmp enable threshold 0 exitalarm "Radius Server Failed" state enable severity Critical syslog enable snmp enable threshold 0 exitalarm "Rogue AP Detected" state enable severity Major syslog enable snmp enable threshold 600 exitalarm "AP Runtime Error" state enable severity Minor syslog enable snmp enable threshold 0 exitalarm "Alarm History Full" state enable severity Critical syslog enable snmp enable threshold 99 exitalarm "Event Log Full" state enable severity Critical syslog enable snmp enable threshold 99 exitalarm "Power Module Failure" state enable severity Critical syslog enable snmp enable threshold 0 exitalarm "Fan Module Failure" state enable severity Critical syslog enable snmp enable threshold 0 exitalarm "AP Wireless Interface Down due to fallback channel not found" state enable severity Critical syslog enable snmp enable threshold 0 exitalarm "AP License Exceeded" state enable severity Critical syslog enable snmp enable threshold 0 exitalarm "New AP in the network after channel planning" state enable severity Major syslog enable snmp enable threshold 0 exitalarm "AP822 HW Rev Not Supported" state enable severity Critical syslog enable snmp enable threshold 0 exitalarm "AP power not supported" state enable severity Critical syslog enable snmp enable threshold 0 exitservice-type AppleTV value _airplay._tcp.local.,_raop._tcp.local. description "Apple TV" owner controller version 0 exitservice-type Chromecast value _googlecast._tcp.local. description Chromecast owner controller version 0 exitservice-type Printer value _ipp._tcp.local.,_ipps._tcp.local.,_universal._sub._ipp._tcp.local.,_universal._sub._ipps._tcp.local.,_printer._tcp.local.,_scanner._tcp.local. description Printer owner controller version 0 exitservice-control-config state disableservice-control-config service-types *service-control-config locations *service-control-config vlans 0service-control-config essids *service-control-config gateways 0app-visibility-config state disableapp-visibility-config report-interval 90app-visibility-config export-state disableapp-visibility-config export-ip 0.0.0.0app-visibility-config export-port 4739app-visibility-config controller-dscp-marking-state disablecaptive-portal-global-settings captive-portal-certificate defaultcaptive-portal-global-settings redirection-protocol httpsqos-dscp-mgmt-pkts DscpControllerToEzrf efqos-dscp-mgmt-pkts DscpControllerToAp efqos-dscp-mgmt-pkts DscpApToController efwapi-server ip-address 0.0.0.0 port 3810ap-l3-discovery-method capwapexitmc1550(15)#

    WLAN TR

    WLAN Interoperability Test ReportWLAN configuration:

    Beacon Interval: 100ms

    Test object - Handset:DTIM Interval: 5

    Ascom i62 sw version 6.0.6802.11d Regulatory Domain: world

    Test object - WLAN system:WMM Enabled (Auto/WMM)

    Fortinet, MC 1550 version 8.4-0 build 7No Auto-tune

    AP 332, 832, 1010, 421AP332AP832AP1000AP421Single Voice VLAN

    2.4Ghz5.0Ghz2.4Ghz5.0Ghz2.4Ghz5.0Ghz2.4Ghz5.0Ghz

    Test CaseDescriptionVerdictVerdictVerdictVerdictVerdictVerdictVerdictVerdictComment

    TEST AREA ASSOCIATION / AUTHENTICATION

    #101Association with open authentication, no encryptionNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDPASSPASS

    #107Association with WPA2-PSK authentication, AES-CCMP encryptionPASSPASSPASSPASSPASSPASSPASSPASS

    #110Association with PEAP-MSCHAPv2 auth, AES-CCMP encryptionPASSPASSPASSPASSPASSPASSPASSPASSFreeRADIUS; Server side certificate loaded to Device.FAIL

    #116Association with EAP-TLS authenticationPASSPASSPASSPASSPASSPASSPASSPASSFreeRADIUS; Server and client side certificate loaded to Device.

    TEST AREA POWER-SAVE AND QOSPASS

    #150802.11 Power-save modePASSPASSPASSPASSPASSPASSPASSPASSFAIL

    #151Beacon period and DTIM intervalNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDPASSPASSDTIM 1,3,5 testedNOT TESTED

    #152802.11e U-APSDPASSPASSPASSPASSPASSPASSPASSPASSSee Comment

    #202WMM prioritizationNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDPASSPASSLoad generated with iPerf. No degradation of voice noticed.

    TEST AREA "PERFORMANCE"

    #308Power-save mode U-APSD – WPA2-PSKNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDPASSPASS12 handset in call on 1 radio verified ok

    TEST AREA ROAMING AND HANDOVER TIMES

    #401Handover with open authentication and no encryptionNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNot tested

    #404Handover with WPA2-PSK auth and AES-CCMP encryptionPASSPASSSee CommentSee CommentPASSPASSSee CommentSee CommentVirtual Cell: OK. Client roaming not applicable due to virtual cell architecture. Native cell: Tested with AP421 and AP832 only. AP421 roaming times 120-170ms due to delayed keys from AP. Noticable voice gap. AP832 roaming times 90-100ms

    #408Handover with PEAP-MSCHAPv2 authentication and AES-CCMP encryptionPASSPASSSee CommentSee CommentPASSPASSSee CommentSee CommentVirtual Cell: OK. Client roaming not applicable due to virtual cell architecture. Native cell: Tested with AP421 and AP832 only.OKC not supported. Initial roam to AP takes 1s+. Noticable voice gap.

    #411Handover using PMKSA and opportunistic/proactive key cachingPASSPASSSee CommentSee CommentPASSPASSSee CommentSee CommentVirtual Cell: OK. Client roaming not applicable due to virtual cell architecture. Native cell: See #408

    TEST AREA BATTERY LIFETIME

    #501Battery lifetime in idleNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDPASSPASS80h+ battery in idle.

    #504Battery lifetime in call with power save mode U-APSDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDPASSPASS10h+ during call measured.

    TEST AREA STABILITY

    #602Duration of call – U-APSD modePASSPASSPASSPASSPASSPASSPASSPASS1h call ok

    TEST AREA 802.11n

    #801Frame aggregation A-MSDUNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTED

    #802Frame aggregation A-MPDUNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTEDNOT TESTED

    #80440Mhz channelsNOT TESTEDPASSNOT TESTEDPASSNOT TESTEDPASSNOT TESTEDPASS

    #805802.11n ratesSee CommentSee CommentSee CommentSee CommentSee CommentSee CommentPASSPASSUsage of 11n not recomended due to known issues. OK with AP421.