User guide

OmniPCX Enterprise / OmniPCX Office
TECHNICAL RELEASE NOTE OF VoWLAN
R4.2.1
TC1308 8 Ed. 01 / 03 March 2010
VoIP TSPEC Enforcement parameter in QoS profile must be disabled (or set to 100 (to avoid
"Service unavailable" message and reboot)).
4.5.2 Restrictions on 310 & 610 WLAN handsets
AOS 3.4.1.1 (min) with PEF license is mandatory for 120.023 version deployment otherwise
WMM-AC feature cannot be used and there is an upgrading problem.
Updating the WLAN handsets with the version 120.023 from a previous release needs first
an intervention on OAW for the management of QoS WMM-AC. That involves the upgrade
of OAW switch in 3.4.1, the PEF license installation and administration of the ACM-
mandatory in OAW. Otherwise, the handset upgrade would not be complete, with a "No
Net Found, No WMM APs" error displayed.
When downgrading from 120.023 to previous version that does not include some of the new
security types, a default restoration is recommended (to avoid "No Net Found, No APs" and
MIPTs stopped during the downgrade).
WPA2-Enterprise 802.1X authentication in PEAP requires an on site intervention. The certificate
installation on MIPT is done with the HAT and dual charger and must be done on each phone.
The use of 512 or 1024 bit certificates is recommended for optimal performance.
4.5.3 Restriction in multi-switches mode
The use of default PSK key for IPSec tunneling will not work after an upgrade of OAWS to 3.4.1.x
releases: Change the default value of PSK key by another value before the 3.4.1.x upgrade.
4.5.4 Restrictions with Cisco CCXv4
Cisco CCX mode requires WPA2-Enterprise 802.1X (RADIUS).
The support of CCXv4 mode for topologies with 310 & 610 WLAN handsets requires Cisco AP
which supports this mode.
AP does not respond to U-APSD Trigger Frame.
Re-authentication fails with Cisco Autonomous AP when using CCKM.
4.5.5 Restrictions on Remote AP
When AP125 acts as Remote AP, Enet1 cannot be used if PoE is running on Enet0.
D-LINK DIR-100 is not compatible with OAW in Remote AP environment.
4.5.6 Restrictions on 802.1x security
The OKC mode for Fast AP roaming is not supported in level 3 configurations (multi-switches).
If the forwarding mode on an OAW-AP120 series is changed from tunnel to split-tunnel, the
switch has to be rebooted for wireless 802.1x clients to complete the EAP exchange.
WPA2-Enterprise 802.1X authentication types require the use of a RADIUS authentication server
to validate user specific credentials.
Microsoft IAS RADIUS does not support EAP-FAST authentication.