< Home

display vap-profile

Function

The display vap-profile command displays configuration and reference information about VAP profiles.

Format

display vap-profile { all | name profile-name }

Parameters

Parameter

Description

Value

all

Displays information about all VAP profiles.

-

name profile-name

Displays information about a specified VAP profile.

The VAP profile must exist.

Views

All views

Default Level

1: Monitoring level

Usage Guidelines

You can run the display vap-profile command to check configuration and reference information about VAP profiles.

Example

# Display information about all VAP profiles.

<HUAWEI> display vap-profile all
FMode   : Forward mode
STA U/D : Rate limit client up/down
VAP U/D : Rate limit VAP up/down
BR2G/5G : Beacon 2.4G/5G rate
------------------------------------------------------------------------------------------------------------
Name          FMode    Type      VLAN    AuthType  STA U/D(Kbps)  VAP U/D(Kbps)  BR2G/5G(Mbps)  Reference  SSID
------------------------------------------------------------------------------------------------------------
default       direct   service   VLAN 1  Open      -/-            -/-            1/6            0          HUAWEI-WLAN
vap-profile1  direct   service   VLAN 1  Open      -/-            -/-            1/6            0          HUAWEI-WLAN
------------------------------------------------------------------------------------------------------------
Total: 2
Table 1 Description of the display vap-profile all command output

Item

Description

Name

VAP profile name.

FMode

Service data forwarding mode.

Type

VAP profile type.
  • service
  • management AP
  • service-backup ap-offline
  • service-backup auth-server-down

VLAN

Service VLAN ID.

AuthType

User authentication mode.

STA U/D(Kbps)

Uplink/downlink rate limit of a single STA.

VAP U/D(Kbps)

Uplink/downlink rate limit of all STAs on a specified VAP.

BR2G/5G(Mbps)

Rate at which 2.4 GHz or 5 GHz Beacon frames are sent.

Reference

Number of times a VAP profile is referenced.

SSID

SSID profile referenced by a VAP profile.

# Display information about the VAP profile default.

<HUAWEI> display vap-profile name default
--------------------------------------------------------------------------------
Profile ID                                      : 0
Service mode                                    : enable
Type                                            : service
Forward mode                                    : direct-forward
Offline management                              : disable
Service VLAN ID                                 : 1
Service VLAN Pool                               : -
Permit VLAN ID                                  : 2 to 4
Auto off service switch                         : disable
Auto off starttime                              : -
Auto off endtime                                : -
STA access mode                                 : disable
STA blacklist profile                           :
STA whitelist profile                           :
Band steer                                      : enable
Sta network detect                              : enable
Learn client IPv4 address                       : enable
Learn client DHCP strict                        : disable
Learn client DHCP blacklist                     : disable
Learn client IPv6 address                       : enable 
Learn client DHCPv6 strict                      : disable
Learn client DHCPv6 blacklist                   : disable
IP source check                                 : disable
ARP anti-attack check                           : disable
DHCP option82 insert                            : disable
DHCP option82 remote id format                  : insert AP-MAC
  MAC format                                    : default
DHCP option82 circuit id format                 : insert AP-MAC
  MAC format                                    : default
ND trust port                                   : disable
SFN roam                                        : disable
Anti attack flood       
  ARP flood switch                              : enable                         
  ARP flood STA rate threshold                  : 4                              
  ARP flood blacklist                           : disable                        
  ND flood switch                               : enable                         
  ND flood STA rate threshold                   : 8                              
  ND flood blacklist                            : disable                        
  IGMP flood switch                             : enable                         
  IGMP flood STA rate threshold                 : 4                              
  IGMP flood blacklist                          : disable                        
  DHCP flood switch                             : enable
  DHCP flood STA rate threshold                 : 4 
  DHCP flood blacklist                          : disable 
  DHCPv6 flood switch                           : enable 
  DHCPv6 flood STA rate threshold               : 4                              
  DHCPv6 flood blacklist                        : disable                        
  mDNS flood switch                             : enable                         
  mDNS flood STA rate threshold                 : 4                              
  mDNS flood blacklist                          : disable                         
  Other broadcast flood switch                  : enable                         
  Other broadcast flood STA rate threshold      : 10                             
  Other broadcast flood blacklist               : disable                        
  Other multicast flood switch                  : enable                         
  Other multicast flood STA rate threshold      : 10                             
  Other multicast flood blacklist               : disable  
SSID profile                                    : default
Security profile                                : default
Traffic profile                                 : default
Authentication profile                          :
Hotspot2.0 profile                              :
Keep service                                    : disable
Keep service allow new access                   : disable
Keep service allow new access no auth           : disable
Service experience analysis                     : disable
SIP snooping port                               : 5060
mDNS Snooping switch                            : disable
--------------------------------------------------------------------------------
Table 2 Description of the display vap-profile name command output

Item

Description

Profile ID

VAP profile ID.

Service mode

Whether the VAP service is enabled.

To configure this parameter, run the service-mode disable command.

Type

VAP type.
  • service: service type
  • ap-management: management AP type
  • ap-offline: AP-offline backup service type

To configure this parameter, run the type (VAP profile view) command.

Forward mode

Service data forwarding mode.
  • direct-forward: direct forwarding
  • tunnel: tunnel forwarding
  • Soft-GRE: soft GRE forwarding

To configure this parameter, run the forward-mode command.

Offline management

Whether management VAP and antenna alignment VAP are enabled for offline APs.

To configure this parameter, run the temporary-management enable (VAP profile view) command.

Service VLAN ID

Service VLAN ID.

To configure this parameter, run the service-vlan (VAP profile view) command.

Service VLAN Pool

VLAN pool to which a service VLAN belongs.

To configure this parameter, run the service-vlan (VAP profile view) command.

Permit VLAN ID

VLAN from which packets are allowed to pass through when the authorization VLAN verification function is enabled.

Auto off service switch

Whether the scheduled VAP auto-off function is enabled.

To configure this parameter, run the auto-off service command.

Auto off starttime

Start time for scheduled VAP auto-off.

To configure this parameter, run the auto-off service command.

Auto off endtime

End time for scheduled VAP auto-off.

To configure this parameter, run the auto-off service command.

Auto off track link

Whether to automatically disable VAPs upon disconnection of the uplink of a cloud AP. After this function is enabled through the iMaster NCE-Campus, the SSID is automatically disabled when the uplink of the cloud AP is disconnected.

Only cloud APs support this parameter.

·STA access mode

STA access control mode.

To configure this parameter, run the sta-access-mode command.

STA blacklist profile

STA blacklist profile.

To configure this parameter, run the sta-access-mode command.

STA whitelist profile

STA whitelist profile.

To configure this parameter, run the sta-access-mode command.

Keep service

Whether service holding upon CAPWAP link disconnection is enabled.

To configure this parameter, run the keep-service enable (VAP profile view) command.

Keep service allow new access

Whether new STAs are allowed to go online when APs are offline.

To configure this parameter, run the keep-service enable (VAP profile view) command.

Keep service allow new access no auth

Whether offline APs allow Portal or MAC address authentication STAs to go online without authentication.

To configure this parameter, run the keep-service enable (VAP profile view) command.

Band steer

Whether the band steering function is enabled.

To configure this parameter, run the band-steer disable command.

Sta network detect

Whether to forcibly disconnect STAs without traffic.

To configure this parameter, run the sta-network-detect disable command.

Learn client IPv4 address

Whether STA IPv4 address learning is enabled.

To configure this parameter, run the learn-client-address disable (VAP profile view) command.

Learn client DHCP strict

Whether strict STA IP address learning through DHCP is enabled.

To configure this parameter, run the learn-client-address dhcp-strict command.

Learn client DHCP blacklist

Whether to add STAs with bogus IP addresses to a dynamic blacklist.

To configure this parameter, run the learn-client-address dhcp-strict command.

Learn client IPv6 address

Whether STA IPv6 address learning is enabled.

To configure this parameter, run the learn-client-address disable (VAP profile view) command.

Learn client DHCPv6 strict

Whether strict STA IP address learning through DHCPv6 is enabled.

To configure this parameter, run the learn-client-address dhcpv6-strict command.

Learn client DHCPv6 blacklist

Whether to add STAs with bogus IPv6 addresses to a dynamic blacklist.

To configure this parameter, run the learn-client-address dhcpv6-strict command.

IP source check

Whether IP source guard is enabled.

To configure this parameter, run the ip source check user-bind enable command.

ARP anti-attack check

Whether dynamic ARP probing is enabled.

To configure this parameter, run the arp anti-attack check user-bind enable command.

DHCP option82 insert

Whether to enable APs to add the Option 82 field to DHCP packets sent by STAs.

To configure this parameter, run the dhcp option82 insert enable command.

DHCP option82 remote id format

Format of the remote-ID in the Option 82 field added to DHCP packets sent by STAs.

To configure this parameter, run the dhcp option82 format (VAP profile view) command.

DHCP option82 circuit id format

Format of the circuit-ID in the Option 82 field dded to DHCP packets sent by STAs.

To configure this parameter, run the dhcp option82 format (VAP profile view) command.

MAC format

Format of the AP MAC address in the Option 82 field.

To configure this parameter, run the dhcp option82 format (VAP profile view) command.

ND trust port

Whether the ND trusted interface function is enabled.

To configure this parameter, run the nd trust port command.

SFN roam

Whether agile distributed SFN roaming is enabled.

To configure this parameter, run the sfn-roam enable command.

Anti attack flood

Flood detection and prevention.

ARP flood switch

Whether ARP flood detection is enabled.

  • enable
  • disable

To configure this parameter, run the anti-attack flood disable command.

ARP flood STA rate threshold

Rate threshold for ARP flood detection.

To configure this parameter, run the anti-attack flood sta-rate-threshold command.

ARP flood blacklist

Whether the ARP flood blacklist function is enabled.

  • enable
  • disable

To configure this parameter, run the anti-attack flood blacklist enable command.

ND flood switch

Whether ND flood detection is enabled.

  • enable
  • disable

To configure this parameter, run the anti-attack flood disable command.

ND flood STA rate threshold

Rate threshold for ND flood detection.

To configure this parameter, run the anti-attack flood sta-rate-threshold command.

ND flood blacklist

Whether the ND flood blacklist function is enabled.

  • enable
  • disable

To configure this parameter, run the anti-attack flood blacklist enable command.

IGMP flood switch

Whether IGMP flood detection is enabled.

  • enable
  • disable

To configure this parameter, run the anti-attack flood disable command.

IGMP flood STA rate threshold

Rate threshold for IGMP flood detection.

To configure this parameter, run the anti-attack flood sta-rate-threshold command.

IGMP flood blacklist

Whether the IGMP flood blacklist function is enabled.

  • enable
  • disable

To configure this parameter, run the anti-attack flood blacklist enable command.

DHCP flood switch

Whether DHCP flood detection is enabled.

  • enable
  • disable

To configure this parameter, run the anti-attack flood disable command.

DHCP flood STA rate threshold

Rate threshold for DHCP flood detection.

To configure this parameter, run the anti-attack flood sta-rate-threshold command.

DHCP flood blacklist

Whether the DHCP flood blacklist function is enabled.

  • enable
  • disable

To configure this parameter, run the anti-attack flood blacklist enable command.

DHCPv6 flood switch

Whether DHCPv6 flood detection is enabled.

  • enable
  • disable

To configure this parameter, run the anti-attack flood disable command.

DHCPv6 flood STA rate threshold

Rate threshold for DHCPv6 flood detection.

To configure this parameter, run the anti-attack flood sta-rate-threshold command.

DHCPv6 flood blacklist

Whether the DHCPv6 flood blacklist function is enabled.

  • enable
  • disable

To configure this parameter, run the anti-attack flood blacklist enable command.

mDNS flood switch

Whether mDNS flood detection is enabled.

  • enable
  • disable

To configure this parameter, run the anti-attack flood disable command.

mDNS flood STA rate threshold

Rate threshold for mDNS flood detection.

To configure this parameter, run the anti-attack flood sta-rate-threshold command.

mDNS flood blacklist

Whether the mDNS flood blacklist function is enabled.

  • enable
  • disable

To configure this parameter, run the anti-attack flood blacklist enable command.

Other broadcast flood switch

Whether the flood detection function is enabled for broadcast packets other than ARP, DHCP, DHCPv6, and ND packets.

  • enable
  • disable

To configure this parameter, run the anti-attack flood disable command.

Other broadcast flood STA rate threshold

Rate threshold for flood detection of broadcast packets other than ARP, DHCP, DHCPv6, and ND packets.

To configure this parameter, run the anti-attack flood sta-rate-threshold command.

Other broadcast flood blacklist

Whether the flood blacklist function is enabled for broadcast packets other than ARP, DHCP, DHCPv6, and ND packets.

  • enable
  • disable

To configure this parameter, run the anti-attack flood blacklist enable command.

Other multicast flood switch

Whether the flood detection function is enabled for multicast packets other than IGMP and mDNS packets.

  • enable
  • disable

To configure this parameter, run the anti-attack flood disable command.

Other multicast flood STA rate threshold

Rate threshold for flood detection of multicast packets other than IGMP and mDNS packets.

To configure this parameter, run the anti-attack flood sta-rate-threshold command.

Other multicast flood blacklist

Whether the flood detection function is enabled for multicast packets other than IGMP and mDNS packets.

  • enable
  • disable

To configure this parameter, run the anti-attack flood blacklist enable command.

SSID profile

Name of the SSID profile referenced by a VAP profile.

To configure this parameter, run the ssid-profile (VAP profile view) command.

Security profile

Name of the security profile referenced by a VAP profile.

To configure this parameter, run the security-profile (VAP profile view) command.

Traffic profile

Name of the traffic profile referenced by a VAP profile.

To configure this parameter, run the traffic-profile (VAP profile view) command.

Authentication profile

Name of the authentication profile referenced by a VAP profile.

Hotspot2.0 profile

Name of the Hotspot2.0 profile referenced by a VAP profile.

To configure this parameter, run the hotspot2-profile (VAP profile view) command.

SoftGRE profile

Name of the soft GRE profile referenced by a VAP profile.

To configure this parameter, run the forward-mode softgre profile-name command.

Service experience analysis

Whether the SEA function is enabled.

To configure this parameter, run the service-experience-analysis enable command.

SIP snooping port

SIP listening port number.

To configure this parameter, run the service-experience-analysis sip-snooping port command.

mDNS Snooping switch

Whether the mDNS snooping function is enabled.

To configure this parameter, run the mdns-snooping enable command.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >