An HP PrCurve Netwrking Applicatin Nte Interperability between PrCurve WESM zl and HP ipaq Vice Messenger smartphne Cntents 1. Intrductin... 3 2. Prerequisites... 3 3. Netwrk architecture... 3 4. Secure wireless encryptin... 3 4.1 Cnfigure the PrCurve WESM... 4 4.2 Cnfigure the HP ipaq Vice Messenger... 6 5. Fast raming... 8 5.1 Fast raming ptins... 9 5.2 Cnfigure self-healing... 9 5.3 Test raming time... 10
6. Firmware versins and phne upgrades... 10 6.1 PrCurve switch and WESM firmware... 10 6.2 HP ipaq firmware... 10 6.3 Upgrading firmware in the HP ipaq Vice Messenger... 10 7. Reference dcuments... 11 HP PrCurve Netwrking 2
1. Intrductin This dcument describes the interperability f a PrCurve wireless services slutin cupled with the HP ipaq Vice Messenger t prvide a secure Vice ver WLAN (VWLAN) slutin with the fllwing services: Secure wireless encryptin with 802.1X Fast raming 2. Prerequisites Yu will need the fllwing equipment: PrCurve Switch 5406zl r 8212zl with the latest firmware versin Wireless Edge Services Mdule zl (WESM zl) plugged int a slt f the 5406zl Tw PrCurve radi prts (RP210 r RP230) HP ipaq Vice Messenger smartphne The wireless services mdule and radi prts are installed in the 5406zl r 8212zl. The radi prts have been discvered. Fr mre infrmatin n this cnfiguratin please refer t PrCurve Applicatin Nte AN-M1, Hw t extend yur wired netwrk t wireless. 3. Netwrk architecture Figure 1 details the cnfiguratin referenced in this applicatin nte. Figure 1. Cnfiguratin fr PrCurve-HP ipaq Vice Messenger interperability 4. Secure wireless encryptin The HP ipaq 514 Vice Messenger smartphne supprts the fllwing ptins: Fr authenticatin, the HP ipaq 514 supprts pen authenticatin, shared, WPA, WPA-PSK, WPA2, and WPA2-PSK. Fr encryptin, the device supprts n encryptin (disabled), as well as WEP, TKIP, and AES. Fr the 802.1X EAP type, the device supprts PEAP, as well as Smart Card r Certificate. This applicatin nte describes the cnfiguratin f WPA2 802.1X authenticatin with AES encryptin and PEAP. HP PrCurve Netwrking 3
4.1 Cnfigure the PrCurve WESM T cnfigure the PrCurve WESM fr secure wireless encryptin via WPA2-PSK: 1. On the wireless edge services mdule, g t Netwrk Setup > WLAN Setup and create a new WLAN called vice2. 2. Cnfigure this WLAN as fllws: SSID: vice2 VLAN ID: The VLAN yu want t be assigned t the phne. This VLAN must be tagged n the WESM uplink frm the switch menu. (Fr details, refer t Applicatin Nte AN-M1, r t the Wireless Services Mdule Administratr Guide). Authenticatin: 802.1X EAP. Encryptin: Enable bth WPA/WPA2 TKIP and WPA2 AES. 3. In the main windw Advanced Optins panel, click t enable Use Vice Priritizatin and select Vice as the Access Categry. 4. Click the Cnfig buttn, and in the WPA/WPA2 windw enable all three Fast Raming ptins (PMK Caching, Opprtunistic Key Caching, Pre-Authenticatin). Then click OK t return t the main Edit windw. 5. In the main Edit windw, click the Radius Cnfig buttn at the bttm t display the Radius Cnfiguratin windw. HP PrCurve Netwrking 4
6. In the Radius Cnfiguratin windw supply the RADIUS Server Address and the RADIUS Shared Secret fr 802.1X authenticatin, then click OK: HP PrCurve Netwrking 5
7. Finally, t enable the new WLAN, highlight the vice2 WLAN, then click the Enable buttn at the bttm f the WLAN list windw: 4.2 Cnfigure the HP ipaq Vice Messenger T cnfigure the HP ipaq 514 Vice Messenger smartphne: 1. Frm the main screen f the phne chse Start > Settings. Yu see a list f ptins: 1. Phne 2. Sunds 3. Prfiles 4. Hme Screen 5. Clck & Alarm 6. Cnnectins 7. Security 8. Remve Prgrams 9. Mre.. HP PrCurve Netwrking 6
2. Type 6 t select Cnnectins. The fllwing list appears: Wireless Manager Beam Bluetth Dial-up GPRS Prxy VPN Wi-Fi Mre 3. Select Wireless Manager. This menu enables yu t activate r deactivate the Wi-Fi, Bluetth and phne. 4. Ensure Wi-Fi is enabled, r else turn it n. (Use the arrws t mve frm ne line t anther in the display and the central buttn t select.) Then click Dne t exit the Wireless Manager. 5. Frm the Cnnectins menu chse 8 fr Wi-Fi. Yu see the list f all available wireless netwrks. 6. Select the vice2 netwrk. Yu see the first screen, with the netwrk name (vice2) and a request fr the Netwrk Type. 7. Chse Private/Wrk netwrk, then click Next. Yu see the Netwrk Key screen. 8. On the Netwrk Key screen, cnfigure the settings as fllws: Authenticatin: WPA2 Data Encryptin: AES Select the check bx fr The key is autmatically prvided. Then click Next. 9. On the 802.1X screen, check Use IEEE 802.1X netwrk access cntrl, and fr EAP type select PEAP. Then click Finish. 10. After a few secnds yu are prmpted t enter the 802.1X credentials. Enter credentials in the screen; fr example: User name: jhn Passwrd: hp Dmain: practive HP PrCurve Netwrking 7
The HP ipaq smartphne authenticates using these credentials, and yu can see the authenticatin success in IAS and IDM: 5. Fast raming Layer 2 raming ccurs when a phne that was assciated t a radi prt mves t anther radi prt adpted by the same WESM. The phne remains in the same VLAN. Layer 3 raming happens when a phne mves between tw radi prts assciated t different WESM mdules. The vice WLAN is assciated with different VLANs (and subnets) n the tw mdules. In this case, the phne keeps its riginating IP address but the vice flw is tunneled by the current mdule t the hme mdule. HP PrCurve Netwrking 8
Fr mre infrmatin n L2/L3 raming cnfiguratins, please refer t PrCurve Applicatin Nte AN-M3, Hw t cnfigure L2 and L3 wireless raming. 5.1 Fast raming ptins T enable a phne t transitin faster between tw radi prts and reduce the raming time, yu can cnfigure these ptins: PMK caching Opprtunistic key caching Pre-authenticatin These ptins are available with 802.1X authenticatin. The HP ipaq 540 Vice Messenger supprts PEAP, as well as Smart Card r Certificate. This applicatin nte utilizes PEAP. 5.2 Cnfigure self-healing The self-healing feature enables assciating neighbrs t each radi prt. In case f failure f a radi prt, the neighbrs increase their transmit pwer t prvide cverage and cmpensate fr the failed RP. Yu can als enable interference avidance, which causes radis t change their channel settings t avid interfering with surrunding radis. T enable self-healing: 1. In the WESM, frm the Special Features > Self Healing > Cnfiguratin tab, check the Enable Neighbr Recvery bx, then click Apply. 2. Then frm the Neighbr Details tab click Detect Neighbrs. 3. Yu can nw edit an RP radi t check that the ther radis with same 802.11 mde (a r b/g) have been listed as neighbrs. HP PrCurve Netwrking 9
5.3 Test raming time Yu can determine the raming time by first using the WESM t determine the radi prt t which the phne is assciated. T test raming time: 1. Frm Device Assciatin > Wireless Statins, nte the radi s Statin Index. 2. G t Device Assciatin > Radi Adptin Statistics and determine the MAC address f the crrespnding radi prt. 3. T determine the switch prt assciated with this MAC address, use PrCurve Manager s Find Nde tl. Use the cmmand shw lldp inf remte all n the switch if the radi prts are cnnected at layer 2. Or use shw arp if the radi prts have IP addresses. 4. If the phne is cnnected t a SIP PBX, initiate a call. Otherwise, frm a machine n the netwrk launch a cntinuus ping t the phne IP address, which yu can see in the Wireless Statins list. 5. Frm the switch CLI r Web agent disable the prt f the RP t which the phne is assciated. The phne shuld lse ne r tw pings, then subsequent pings shuld be successful again, indicating the phne has assciated t a different RP: 6. Firmware versins and phne upgrades This sectin prvides versin numbers f firmware used fr this applicatin nte, and explains hw t upgrade the HP ipaq Vice Messenger smartphne. 6.1 PrCurve switch and WESM firmware Firmware versins f the switches used fr this applicatin nte are as fllws: K.13.09 fr the PrCurve Switch 5406zl WT.01.15 fr the PrCurve WESM zl 6.2 HP ipaq firmware Firmware used n the HP ipaq 512 Vice Messenger firmware is as fllws: Btrm versin 2.05.00, available frm: http://h20000.www2.hp.cm/bizsupprt/techsupprt/sftwaredescriptin.jsp?lang=en&cc=us&prdtypeid=2 15348&prdSeriesId=3375716&prdNameId=3360097&swEnvOID=4014&swLang=8&mde=2&taskId=135& switem=hh-57038-1 6.3 Upgrading firmware in the HP ipaq Vice Messenger T upgrade the phne s firmware: 1. Back up the smartphne s cnfiguratin befre the firmware upgrade. Upgrading firmware resets the HP ipaq Vice Messenger t the factry default settings. 2. Cnnect a PC t the smartphne via a USB cable and ActiveSync. (Refer t the phne dcumentatin fr details f ActiveSync.) 3. Open the btrm package n the PC, and fllw the instructins n the PC and smartphne screens. 4. The phne then rebts and is reset t the factry default settings, with the new firmware installed. HP PrCurve Netwrking 10
7. Reference dcuments This cncludes the prcedures fr interperating PrCurve switches with the HP ipaq 514 Vice Messenger. Fr further infrmatin abut hw t cnfigure PrCurve switches and the HP ipaq Vice Messenger t supprt cnvergence, please refer t the fllwing links: Fr user manuals fr PrCurve 3500yl-5400zl-8212zl switches: http://www.hp.cm/rnd/supprt/manuals/3500-6200-5400-chapterfiles.htm Fr PrCurve WESM zl manuals: http://www.hp.cm/rnd/supprt/manuals/wireless_zl.htm Fr PCM+ and IDM manuals: http://www.hp.cm/rnd/supprt/manuals/prcurve-manager.htm http://www.hp.cm/rnd/supprt/manuals/idm.htm Fr HP ipaq Vice Messenger manuals: http://h20000.www2.hp.cm/bizsupprt/techsupprt/dcumentindex.jsp?lang=en&cc=us&taskid=101&prdc lassid=-1&cntenttype=supprtmanual&dcindexid=64179&prdtypeid=215348&prdseriesid=3375716 Fr further infrmatin, please visit www.prcurve.eu 2008 Hewlett-Packard Develpment Cmpany, L.P. The infrmatin cntained herein is subject t change withut ntice. The nly warranties fr HP prducts and services are set frth in the express warranty statements accmpanying such prducts and services. Nthing herein shuld be cnstrued as cnstituting an additinal warranty. HP shall nt be liable fr technical r editrial errrs r missins cntained herein. 4AA2-2302EEE HP PrCurve Netwrking 11