Specifications

Configuring RBT-Switch to RBT-Switch Security
RoamAbout Mobility System Software Configuration Guide 7-5
Clearing a Mobility Domain Member from a Seed
YoucanremoveindividualmembersfromtheMobilityDomainontheseedRoamAboutSwitch.
ToremoveaspecificmemberoftheMobilityDomain,typethefollowingcommand:
clear mobility-domain member ip-addr
ThiscommandhasnoeffectiftheRoamAboutSwitchmemberisnotconfiguredaspartofa
MobilityDomainorthecurrentRoamAboutSwitchisnottheseed.
Configuring RBT-Switch to RBT-Switch Security
YoucanenhancesecurityonyournetworkbyenablingRoamAboutSwitchtoRoamAboutSwitch
security.RoamAbou tSwitchtoRoamAboutSwitchsecurityencryptsmanagementtraffic
exchangedbyRoamAboutSwitchesinaMobilityDomain.
WhenRoamAboutSwitchtoRoamAboutSwitchsecurityisenabled,managementtrafficamong
RoamAboutSwitchesintheMobilityDomainis
encryptedusingAES.Thekeyingmaterialis
dynamicallygeneratedforeachsessionandpassedamongswitchesusingpublickeysthatyou
configure.
ToconfigureRoamAboutSwitchtoRoamAboutSwitchsecurity:
•SetMobilityDomainsecurityoneachswitchtorequired.Thedefaultsettingisnone.
RoamAboutSwitchtoRoamAboutSwitchsecuritycan
bedisabledorenabledonaMobilit y
Domainbasis.Thefeaturemusthavethesamesetting(requiredornone)onallswitchesin
theMobilityDomain.Usethefollowingcommandontheseedandoneachmembertoenable
RoamAboutSwitchtoRoamAboutSwitchsecurity:
set domain security required
Thiscommandalsocreatesacertificate.
•OntheMobilityDomainseed,specifythepublickeyforeachmember.Usethefollowing
command:
set mobility-domain member ip-addr key hex-bytes
Specifythekeyas16hexadecimalbytes,separatedbycolons.Hereisanexample:
00:11:22:33:44:55:66:77:88:99:aa:bb:cc:dd:ee:ff
•Oneachmemberswitch,specifytheseed’sIPaddressanditspublickey.Usethefollowing
command:
set mobility-domain mode member seed-ip ip-addr key hex-bytes
Thiscommanddoesnotneedtobeenteredontheseedswitch.
•Ontheseedandoneachmember,generateaprivatekey.Usethefollowingcommand:
crypto generate key domain 128
Monitoring the VLANs and Tunnels in a Mobility Domain
TunnelsconnectRoamAboutswitches.TunnelsareformedautomaticallyinaMobilityDomainto
extendaVLANtotheRoamAboutSwitchthat aroamingstationisassociatedwith.Asingle
tunnelcancarrytrafficformanyusersandmanyVLANs.Thetunnelportcancarrytrafficfor
multipleVLANsbymeansof
multiplevirtualports.