Home
User Manual 4ipnet EAP200
Contents
1. Radio Status System Name Enterprise Access Paint MAC Address 00 1F D4 33 96 02 Firmware Version Band 802 11g 1 Build Number Channel 1 Location TX Power 19 dBm Site EN A Device Time 1970 01 01 08 00 30 System Up Time 0 days 0 00 30 z E LAN Interface 4 AP Status MAC Address 00 1F D4 83 96 01 groe BSSID ESSID eae lene GRE IP Address VAP 1 00 1F D4 83 96 02 EAP 1 None a v Subnet Mask 255 255 0 0 VAP 2 06 1F D4 83 96 02 EAP 2 None 0 a Gateway VAP 3 OA 1F D4 83 96 02 EAP 3 Nane co Q GRE Tunnel Status Connected Remote IP 192 168 3 3 Key 12345 The Web Management Interface System Overview Page 14 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH e To logout simply click on the Logout button at the upper right hand corner of the interface to return to the Administrator Login Page Click OK to logout fi Home Logout Help Logout Message from webpage EJ 2 re vou sure to logoff Logout Prompt For security reasons it is strongly recommended to change the administrator s password upon the completion of all configuration settings 15 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH Please follow the following steps to change the administrator s password Q LA g System Wireless Firewall Utilities Status Change Password Backup amp Restore System
2. V u ov i G i NY A x A 5 ar a ie Gi TOG E F o U Y st od v Ay TY ms il 4 Mi N M 1 FN a OA Aa for your IP network User s Manual EAP200 V2 00 Enterprise Access Point 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH Copyright amp Disclaimer Copyright The contents of this publication may not be reproduced in any part or as a whole stored transcribed in an information retrieval system translated into any language or transmitted in any form or by any means mechanical magnetic electronic optical photocopying manual or otherwise without the prior written permission of 4IPNET INC Disclaimer AIPNET INC does not assume any liability arising out the application or use of any products or software described herein Neither does it convey any license under its parent rights not the parent rights of others 4IPNET further reserves the right to make changes in any products described herein without notice The publication is subject to change without notice Trademarks AIPNET 4ipnet is a registered trademark of 4IPNET INC Other trademarks mentioned in this publication are used for identification purposes only and may be properties of their respective Owners Copyright 4IPNET INC 4ipnet 1 NAME Y User s Manual EAP200 Enterprise Access Point ENGLISH Table of Contents PN MA 4 PT 4 DN 0 8 bf 119 6 Cc een E E E E EN N
3. Overview General Y var Config Security y Repeater Advanced Access Control Site Survey h 1 T r r Home gt Wireless gt VAP Config VAP Configuration Profile Name VAP Disable Enable Profile Name VAP 1 ESSID EAP200 1 VLAN ID Disable Enable VLAN ID 1 4094 VAP State Page e Security Type The hyperlink showing the security type connects to the Security Settings Page VAP Overview General h VAP Config N Secu rity k Repeater Advanced Access Control Site Survey k Home gt Wireless gt Security Security Settings Profile Name Security Type None k VAP Security Type Page 47 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH e MAC ACL The hyperlink showing Allow or Disable connects to the Access Control Settings Page VAP Overview ki General 5 VAP Config A Security Repeater Advanced k Access Control 4 Bite Survey 1 z i a T 3 Home gt Wireless gt Access Control Access Control Settings Profile Name VAP 1 Maximum Number of Clients 32 Range 1 32 1 Access Control Type Disable Access Control VAP MAC ACL Page e Advanced Settings The advanced settings hyperlink connects to the Advanced Wireless Settings Page ATE AT 1 m k Fn Y A VAP Overview General VAP Config Security epeater 4dvanced Control 1 M 1 Site S
4. 4ipnet 7 3 2 Service User s Manual EAP200 Enterprise Access Point ENGLISH The administrator can add or delete firewall service here the services in this list will become options to choose in firewall rule when EtherType is IPv4 EAP200 provides a list of rules to block or pass traffics of layer 3 or above protocols These services are available to choose from drop down list of layer2 firewall rule edit page with Ether Type to be IPv4 The first 28 entries are default services and the administrator can add delete any extra desired services There are 28 firewall services available in default settings these default services cannot be deleted but can be disabled If changes are made please click SAVE to save the settings before leaving this page Firewall List Service I Advanced Home gt Firewall gt Service Config No Name 1 ALL 2 ALL TCP 3 ALL UDP 4 ALL ICMP 5 FTP 5 HTTP 7 HTTPS POPS g SMTP 10 DHCP Firewall Service Description ALL TCP Source Port 0 65535 Destination Port 0 65535 UDP Source Port 0 65535 Destination Port 0 65535 ICMP TCP UDP Destination Port 20 21 TCP UDP Destination Port 80 TCP UDP Destination Port 443 TCP Destination Part 110 TCP Destination Port 25 UDP Destination Port 67 68 First Prev Next Last total 28 Add Firewall Service Page 70 Copyright 4IPNET INC PN ss as Mana EAP200 Enterprise Access Point ENGLISH 7 3 3 Adv
5. Home gt Wireless gt VAP Config VAP Configuration Profile Name VAP Disable Enable Profile Name VAP 1 ESSID EAP200 1 VLAN ID Disable Enable VLAN ID 1 4094 VAP Configuration Page To enable specific VAP select the VAP from the drop down list of Profile Name The basic settings of each VAP are collected in the profile as follows e VAP Enable or Disable this VAP e Profile Name he profile name of specific VAP for identity management purposes e ESSID ESSID Extended Service Set ID serves as an identifier for clients to associate with the specific VAP It can be coupled with different service level like a variety of wireless security types e VLAN ID EAP200 supports tagged VLANs virtual LANs To enable VLAN function each VAP shall be given a unique VLAN ID with valid values ranging from 1 to 4094 5l Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 2 4 Security EAP200 supports various wireless authentication and data encryption methods in each VAP profile With this the administrator can provide different service levels to clients The security type includes None WEP 802 1X WPA PSK and WPA RADIUS e None Authentication is not required and data is not encrypted during transmission when this option is selected This is the default setting as shown in the following figure VAP Overview General VAP Contig 4 Security Repea
6. The management services e g VLAN for Management SNMP and System log can be configured here General Network Interface A Management GRE Tunnel CAPWAP Home gt System gt Management Services Management Services VLAN for Management Disable Enable VLAN ID me 1 4094 SNMP Configuration G Disable Enable Community String Trap Disable Enable severIP System Log Disable Enable SYSLOG Server IP Server Port 514 SYSLOG Level Management Services Page e VLAN for Management When it is enabled management traffics from the system will be tagged with a VLAN ID In other words administrator who wants to access the WMI must send management traffics with the same VLAN ID such as connecting to a specific VAP with the same VLAN ID Enter a value between 1 and 4094 for the VLAN ID if the option is enabled 41 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH e SNMP Configuration By enabling SNMP function the administrator can obtain the system information remotely SNMP Configuration Disable Enable Community String Trap Disable Enable SNMP Configuration Fields Enable Disable Enable or Disable this function Community String The community string is required when accessing the Management Information Base MIB of the system o Read Enter the community string to access the MIB with Read privilege
7. access the system gt MAC ACL Allow List When selecting MAC ACL Allow List only the client devices identified by their MAC addresses listed in the Allow List allowed MAC addresses are granted with access to the system The administrator can temporarily block any allowed MAC address by checking Disable until the administrator re Enables the listed MAC Security Repeater Advanced Y Access Control Site Survey VAP Overview 1 General VAP Config 4 Home gt Wireless gt Access Control Access Control Settings Profile Name VAP 1 Maximum Number of Clients f Range 1 32 Access Control Type MAC ACL Allow List w No MAC Address State 1 Disable O Enable 2 Disable O Enable MAC Allow List Note An empty Allow List means that there is no allowed MAC address Make sure at least the MAC of the management system is included e g network administrator s computer 6 Copyright 4IPNET INC 41pnet User s Manual EAP200 Enterprise Access Point ENGLISH gt MAC ACL Deny List When selecting MAC ACL Deny List all client devices are granted with access to the system except those listed in the Deny List denied MAC addresses The administrator can allow any denied MAC address to connect to the system temporarily by checking Disable VAP Overview y General V VAP Config V Security A Repeater V Adva nced Access Control Site Survey A Home gt Wireless gt
8. PN ras Mana EAP200 Enterprise Access Point ENGLISH Notelll If you set WEP security for Universal Repeater the security of AP will also change to WEP and use the same settings WEP Key Type Open Shared Auto WEP Key Length 64 bits 128 bits 152 bits WEP Key Format ASCII Hex WEP Key Index WEP Keys 1 2 WPA PSK Click Setup to configure the WPA PSK setting for associating with the target AP Cip psk DA 1F D4 39 10 74 11 54 52 WPA PSK The following configuration box will then appear at the bottom of the screen Information provided here must be consistent with the security settings of the target AP Pre shared Cipher TKIP Pre shared Key Type 3 psk Hex 64 chars Passphrase amp 63 chars 65 Copyright 4IPNET INC m 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 3 Firewall The system provides an added security feature Layer2 Firewall in addition to typical AP security Layer2 Firewall offers a firewall function that is tallored specifically for Layer2 traffics providing another choice of shield against possible security threats coming from going to WLAN AP interfaces hence besides firewall policies configured on gateways this extra security feature will assist to mitigate possible security breach This section provides information in the following functions Firewall Settings Service and
9. o Write Enter the community string to access the MIB with Write privilege Trap When enabled events on Cold Start Interface UP amp Down and Association amp Disassociation can be reported to an assigned server o Enable Disable Enable or Disable this function o Server IP Address Enter the IP address of the assigned server for receiving the trap report e System Log By enabling this function specify an external SYSLOG server to accept SYSLOG messages from the system remotely V V V WV System Log Disable Enable SYSLOG Server IP Server Port SYSLOG Level System Log Fields Enable Disable Enable or Disable this function Server IP The IP address of the Syslog server that will receive the reported events Server Port The port number of the Syslog server Syslog Level Select the desired level of received events from the drop down menu 42 Copyright 4IPNET INC PN ers Mana EAP200 Enterprise Access Point ENGLISH 7 1 4 GRE Tunnel When GRE tunnel is created between EAP200 and the controller EAP200 can be logically deployed into the Controller s managed network regardless of its physical location If the tunnel is created from WHG series controllers all of the configuration should be performed on the Controller side It is meaningless to configure GRE tunnel settings from the EAP200 side Once the settings are applied from the Controller side the applied settings such as Key string will b
10. 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 2 5 Repeater To extend wireless network coverage EAP200 supports 3 options of Repeater type None WDS or Universal Repeater selecting None will turn off this function gt Universal Repeater lf Universal Repeater is selected please provide the SSID of upper bound AP for uplink connection Security Type None WEP or WPA PSK can be configured for this Repeater connection Please note the security type configured here shall follow upper bound AP s for intended connection VAP Overview General VAP Config Security Repeater ray I Access Control Site Survey Home gt Wireless gt Repeater Config Repeater Settings The SSID of Upper Bound AP Current wireless channel of the system is set at 1 Repeater connection may fall if the system is set to connect to upper AP with different channels Security Type Repeater Settings Universal Repeater o The SSID of Upper Bound AP Specify the SSID of the upper bound AP that the system is used to extend that AP s wireless service coverage o Security Type None WEP or WPA PSK 56 Copyright 4IPNET INC 41pnet User s Manual EAP200 Enterprise Access Point ENGLISH gt WDS If WDS is selected EAP200 can support up to 4 WDS links to its peer APs Security Type None WEP or WPA PSK can be configured to decide which encryption to be used for WDS connections respectively Please fill in
11. Unit 4 micro seconds Beacon Interval 1100 100 500ms Wireless General Settings Page On this page select the Band with which the AP is to broadcast its signal The rest of the fields are optional and can be configured at another time Click SAVE if any changes have been made 20 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH Step 4 Configuring Wireless Coverage VAP 1 To setup the AP s wireless access refer to the following VAP 1 configuration other VAP configuration can refer to the same setup steps as done for VAP 1 Click on the Overview tab to proceed gt J a System Wireless Firewall Utilities Status PA Overview General j VAP Config Security Repeater Advanced Access Control Site Survey A Home gt Wireless gt VAP Overview VAP Overview VAP No ESSID State Security Type MAC ACL Advanced Settings 1 EAP200 1 Enabled None Disabled Edit 2 EAP200 2 Disabled None Disabled Edit 3 EAP200 3 Disabled None Disabled Edit 4 EAP200 4 Disabled None Disabled Edit 5 EAP200 5 Disabled None Disabled Edit 6 EAP200 6 Disabled None Disabled Edit 7 EAP200 7 Disabled None Disabled Edit 8 EAP200 8 None Disabled Edit Disabled AL A x VAP Overview General WAP Config Home gt Wireless gt Virtual AP Overview Page On this page click the hyperlink in the row and column that corresponds with VAP 1 s State This will bring up the following
12. o Accounting Service Enabling this option allows accounting of login and logouts through the RADIUS server o Accounting Port The port number used by the RADIUS server for accounting purposes Specify a port number or use the default 1813 o Accounting Interim Update Interval The system will update accounting information to the RADIUS server every interval period e WPA PSK WPA PSK Wi Fi Protected Access Pre shared Key is a pre shared key authentication method a special mode of WPA VAP Overview General Y VAP Config Y Security Repeater 1 Advanced Access Control Site Survey Home gt AP gt Security Security Settings Profile Name Security Type Cipher Suite Pre shared Key Type PSK Hex 64 chars Passphrase 8 63 chars Group Key Update Period 600 second s Security Settings WPA PSK gt Cipher Suite Select an encryption method from TKIP WPA AES WPA TKIP WAP2 AES WAP2 or Mixed gt Pre shared Key Type Select a pre shared key type PSK Hex or Passphrase gt Pre shared Key Enter the key value for the pre shared key the format of the key value depends on the key type selected gt Group Key Update Period The time interval for the Group Key to be renewed the time unit is in seconds 54 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH gt WPA RADIUS If this option is selected the RADIUS authentication and data
13. AP 3 e Three EAP200 systems construct a network comprising of wired and wireless segments e ApP 2 plays the role of a wireless bridge e All devices share the same DHCP server 192 168 1 1 Copyright 4IPNET INC m 41pnet User s Manual EAP200 Enterprise Access Point ENGLISH 2 3 Hardware Description This section depicts the hardware information including all panel description Connector Panel 7 6 3 4 3 1 EAP200 Connector Panel dam mu mm vom mm ma mm vo er v a Attach the power adapter here Antenna Panel EAP200 Antenna Panel Antenna Connector Attach the antennas here The system supports one RF interface with two SMA connectors Copyright 4IPNET INC e 7 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH LED Panel Aipnet EAP200 Enterprise Access Point EAP200 LED Panel 1 Power LED LED ON indicates power on OFF indicates power off LAN LED LED ON indicates LAN cable connected OFF indicates no connection BLINKING indicates transmitting data 3 WLAN LED LED ON indicates wireless ready WDS LED LED ON indicates WDS ready WES LED poreca MES siaus indicate WES status WES Start LED Green OFF and then LED Red OFF and then AN SLOWLY BLINKING SLOWLY j aan jej WES Negotiate Timeout WES Negotiate Timeout Timeout Tr Te ON Fr Ta LED RedON WES Success LED Red 10 Green ON LED Green ON WES Fail LED Green ON LE
14. Control This means that there is no restriction for client devices to access the system 2 MAC ACL Allow List This means that only the client devices identified by their MAC addresses listed in the Allow List allowed MAG addresses is granted with access to the system The administrator can temporarily block any allowed MAG address by checking Disable until the administrator renews the listed MAC VAP Overview General VAP Config Security Repeater Advanced Access Control Site Survey Home gt Wireless gt Access Control Access Control Settings Profile Name VAP 1 Maximum Number of Clients Range 1 32 Access Control Type MAC ACL Allow List v No MAC Address MAC ACL Allow List State An empty Allow List means that there are no allowed MAC addresses Make sure at least the MAC of the modifying system is included e g network administrator s computer 31 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 3 MAC ACL Deny List This means that all client devices are granted with access to the system except those listed in the Deny List denied MAC addresses The administrator can allow any denied MAG address to connect to the system temporarily by checking Enable 1 iT MAP Overview General Y VAP Config y Security 1 Repeater Adva nced Access Control Site Survey A Home gt Wireless gt Access Control Access Contr
15. List Service Y Advanced Home gt Firewall gt Firewall List Layer 2 Firewall Settings Remove rule 1 gt gt To edit a specific rule Ed in Setting column of firewall list will lead to the following page for detail configuration From this page the rule can be edited from scratch or an existing rule for revision Firewall List Service 1 Advanced Home gt Firewall List gt Rule Config Layer 2 Firewall Configuration Rule ID Rule name EtherType IEEE802 3 Interface VAPI H T a O a DSAP SSAP Type 2000 fie IPv4 0800 Source macaddress Masks mask I Destination MAC Address 01 00 0C CC CC CC Action Block Pass Remark gt Rule ID The numbering of this specific rule will decide its priority among available firewall rules in the table Rule name The rule name can be specified here EtherType he drop down list will provide the available types of traffics subject to this rule Interface It can indicate inbound outbound direction with desired interfaces V V VY v Service when EtherType is IPv4 Select the available upper layer protocols services from the drop down list gt DSAP SSAP when EtherType is IEEE 802 3 The value can be further specified for the fields in 802 2 LLC frame header 6 Copyright 4IPNET INC 4ipnet gt gt User s Manual EAP200 Enterprise Access Point ENGLISH Ty
16. encryption will be both enabled VAP Overview General WAP Config Security Repeater 4 Advanced 4 Access Control Site Survey Home gt Wireless gt Security Security Settings Profile Name Security Type Cipher Suite Group Key Update Period 600 second s Per RAINIS Sanner Host Domain Name IP Address Authentication Port 1812 Secret Key rs Accounting Service Disable Enable Accounting Interim Update Interval so second s Security Settings WPA RADIUS gt WPA Settings o Cipher Suite Select an encryption method from TKIP WPA AES WPA TKIP WAP2 AES WAP2 or Mixed o Group Key Update Period The time interval for the Group Key to be renewed the time unit is in seconds gt RADIUS Server Settings Primary Secondary o Host Enter the IP address or domain name of the RADIUS server o Authentication Port The port number used by the RADIUS server Specify a port number or use the default 1812 o Secret Key The secret key for the system to communicate with the RADIUS server o Accounting Service Enabling this option allows accounting of login and logouts through the RADIUS server o Accounting Port The port number used by the RADIUS server for accounting purposes Specify a port number or use the default 1813 o Accounting Interim Update Interval The system will update accounting information to the RADIUS server every interval period 99 Copyright 4IPNET INC
17. page gt System Wireless r 5 Firewall Utilities Status mn Se h A i A 1 O ZA Tr Security Repeater Advanced y Access Control y Site Survey 1 VAP Config VAP Configuration Profile Name VAP 1 VAP Disable Enable Profile Name VAP 1 ESSID EAP200 1 VLAN ID Disable U Enable VLAN ID ie 1 4004 VAP Configuration Page VAP 1 shown 21 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH The desired VAP profile can be selected from the drop down menu of Profile Name and VAP 1 configuration will serve as an example for all other VAPs Before proceeding further please make sure that the VAP field is Enable afterwards enter an ESSID to represent the WLAN associated with AP s VAP 1 It is suggested that Profile Name is used to describe what this particular VAP will be used for otherwise leave it as default VLAN ID can be chosen at another time Click SAVE to save all changes up to this point and Reboot the system to apply these revised settings Congratulations After reboot the AP can start to work with these revised settings 22 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 4 Adding Virtual Access Points EAP200 possesses the feature of multi ESSID namely it can behave as multiple virtual access points provid
18. provides Certificate security for CAPWAP to ensures the safety between Access Controller and WAP gt Use Default Certificate Click Use Default Certificate to use the default certificate and key 76 Copyright 4IPNET INC ia 41pnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 5 Status This page is used to view the current condition and state of the system and includes the following functions Overview Associated Clients Repeater and Event Log 7 5 1 Overview The System Overview page provides an overview of the system status for the administrator man M yp oa a a 1 awen Associated Clients y Repeater Event Log Home gt Status gt System Overview System Overview P System gt Radio Status System Name Enterprise Access Point MAC Address 00 1F D4 33 96 02 Firmware Version Band 802 119 n Build Number Channel 1 Location TX Power 19 dBm Site EN A Device Time 1970 01 01 08 00 30 System Up Time 0 days 0 00 30 LAN Interface 4 AP Status MAC Address 00 1F D4 83 96 01 Hang BSSID ESSID av one GRE IP Address VAP 1 00 1F D4 83 96 02 EAP 1 None 0 v Subnet Mask 255 255 0 0 VAP 2 06 1F D4 83 96 02 EAP 2 None 0 Gateway VAP 3 0A 1F D4 83 96 02 EAP 3 None 0 vw Q GRE Tunnel Status Connected Remote IP 192 168 3 3 Key 12345 System Overview Page 7 Copyright 4IPNET INC
19. remote peer s MAG address and click SAVE to proceed if setting revision is necessary CLEAR button is used to clear the contents in the above WDS connection list VAP Overview General VAP Config Security Repeater Advanced Access Control Site Survey Home gt Wireless gt Repeater Config Repeater Settings Repeater Type IWES WDS Profile WDS MAC Address Security type Repeater Settings WDS o WES Enable WES o MAC Address To remote peer s MAC address o WDS Click on Enable to enable the respective WDS links click on Delete to remove them o Security Type None WEP or WPA PSK 9 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 2 6 Advanced The advanced wireless settings for tne EAP200 s VAP Virtual Access Point profiles allow customization of data transmission settings The administrator can tune the following parameters to improve network communication performance if a poor connection occurs VAP Overview General 4 VAP Config Security Repeater Advanced Access Control Y Site Survey Home gt Wireless gt advanced Advanced Wireless Settings Profile Name VAP 1 RTS Threshold 2346 1 2346 Fragment Threshold 2346 256 2346 DTIM period 1 1 15 Broadcast SSID Disable Enable Wireless Station Isolation 9 Disable Enable WMM Disable Enable IAPP Disable Enable Multicast Broa
20. stations associated with the system are isolated and can only communicate with the system 58 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH WMM The default is Disable Wi Fi Multimedia WMM is a Quality of Service QoS feature that prioritizes wireless data packets based on four access categories voice video best effort and background Applications without WMM and applications that do not require QoS are assigned to the best effort category which receives a lower priority than that of voice and video Therefore WMM decides which data streams are more important and assigns them a higher traffic priority This option works with WMM capable clients only lt To receive the benefits of WMM QoS gt The application must support WMM WMM shall be enabled on EAP200 WMM shall be enabled in the wireless adapter on clients computer IAPP IAPP Inter Access Point Protocol is a protocol by which access points share information about the stations that are connected to them By enabling this function the system will automatically broadcast information of associated wireless stations to its peer access points This will help wireless stations roam smoothly among IAPP enabled access points in the same wireless LAN Multicast Broadcast Rate Bandwidth configuration for multicast broadcast packets If your wireless clients require larger or smaller bandwidth for sending multicast broadcast
21. 4 1 3 Package Content cccccccccssssccsssscesssscessescesscscssscscssesccsssecessescessescessescessescsssescsnsesesseesessescessescessess 5 System Overview and Getting Started sernrnrennrnronvrnrrnvrnrrnvrnrrnrrnrrnrrsennrrssrnresernrnsernresenvrnsenvrsssnvsenn 6 TT I 6 Deplovnieni OPO LOS EE ET EN 7 S S EGEN DET 2 0 OR 8 2 4 Hardware Installation ooovoonnroooornnnnnnrnnnnnsssnnnnnnnnnnnnnnnsssnnnnnnnrsnnnnssssnnnnnnnesnnnessssennnnevsenenessseennnnn 10 2 5 Console Interface rrnvrrnnnrnrrnvrnnnnnsnnnvrrnnnsssnnvvrnnnsssenvnrrnnesssnnnvrsnnessennvvennessenvvrsnesssenvvvrenesssnvvrsnnseen 11 2 6 Access Web Management Interface ooosoronnvonnnvonn non ono 13 Connect your AP to your Network oooonnooonnnonnnnonnn non non 17 Adding Virtual Access Points oooonoooonnoonn noone on non nn 23 NNM s b r bv 25 Create a WDS Bridge between two APS nrrnrnrernrnrernrnsennrnsennnnsennnnssnnenesnvnnesnrnnennrnsesnrnssnnnnsennensvnne 34 Web Management Interface Configuration rsrrrrsnrrronvrrrenvrnrenvrnnenvrerrnvrnnrnrrnernrrsernrnsenvrnsennnssen 36 TE EVE NE 38 7 1 1 GENCTAL sesisicodsarsvssdaosenenednnanousuiswopedesioasaudsnabwenntsewainsussnenancbnotshuendeaneoseustienasbunseducenatseanadwenntowmeuceundus 38 TT NNN 40 7 GE 0 5 ere E E E E N A S E EE 41 LAGRE TO ee E EE ho ro 43 MON 44 ALANAIS CSS 46 TALVA cae OV 2 e E A E EE ET en 46 7 2 2 Gen
22. 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH Table 3 Status Page s Organizational Layout Description The system name of the EAP200 System Name Firmware Version The present firmware version of the EAP200 The present firmware build number of the EAP200 The location of the EAP200 The site of the EAP200 The system time of the EAP200 The time that the system has been rebooted in Build Number System Location Device Time System Up Time operation The MAG address of the LAN Interface The IP address of the LAN Interface The Subnet Mask of the LAN Interface The Gateway of the LAN Interface The MAC address of the RF Card The RF band in use The channel specified MAC Address LAN Interface IP Address Gateway MAC Address Band Channel Radio Status Tx Power Transmit Power level of RF card Profile Name The profile name of AP Basic Service Set ID Extended Service Set ID Security Type Security type of the Virtual AP The number of online clients The status of GRE Tunnel The status of connection or Disabled The IP Address of AC Key The password for the connection Online Clients 78 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 5 2 Associated Clients The administrator can remotely oversee the status of all associated clients on this page When a low SNR is found here the administrator can tune the corresponding parameters
23. Access Control Access Control Settings Profile Name VAP 1 Maximum Number of Clients Range 1 32 Access Control Type MAC ACL Deny List w No MAC Address State 1 Disable O Enable es Disable O Enable Deny List 62 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH gt RADIUS ACL Authenticate incoming MAG addresses by an external RADIUS When RADIUS ACL is selected all incoming MAC addresses will be authenticated by an external RADIUS Please note that each VAP s MAC ACL and its security type Shown on the Security Settings page share the same RADIUS configuration VAP Overview General VAP Config Security Repeater Adva nced Access Control Site Survey Home gt Wireless gt Access Control Access Control Settings Profile Name Maximum Number of Clients Range 1 32 Access Control Type Primary RADIUS Server Notell These settings will also apply to security settings which use RADIUS Server for this VAP Host Domain Name IP Address Authentication Port 1 65535 Secret Key mr et RADIUS ACL 63 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 2 8 Site Survey Sit Survey is a useful tool to provide information about the surrounding wireless environment available APs are shown with their respective SSID MAG Address Channel Rate setting Signal reading a
24. Advanced Firewall Settings 7 3 1 Firewall List It provides an overview of firewall rules in the system 6 default rules with up to total 20 firewall rules are available for configuration Firewall List Service 4 Advanced Home gt Firewall gt Firewall List Layer 2 Firewall Settings Enable Layer 2 Firewall Disable Enable No State Action Name EtherType Remark Setting 1 LI DROP CDP IEEE 8023 Del Ed In My 2 LI DROP STP IEEE 8023 Del Ed In My 3 DROP GARP IEEE 8023 Del Ed In My Firewall List Page From the overview table each rule is designated with the following field No The numbering will decide the priority to let system carry out the available firewall rules in the tables e State The check marks will enable the respective rules Action DROP denotes a block rule ACCEPT denotes a pass rule Name It shows the name of rule EtherType It denotes the type of traffics subject to this rule Remark It shows the note of this rule Setting 4 actions are available Del denotes to delete the rule Ed denotes to edit the rule In denotes to insert a rule and Mv denotes to move the rule 66 Copyright 4IPNET INC PN ras Mana EAP200 Enterprise Access Point ENGLISH gt gt To delete a specific rule Del in Setting column of firewall list will lead to the following page for removal confirmation After SAVE button Is clicked and system reboot the rule will be removed Firewall
25. Alternate DNS Server Layer STP Disable Enable Network Settings Page Mode Determine the way to obtain the IP address by DHCP or Static gt Static The administrator can manually set up the static LAN IP address All required fields are marked with a red asterisk O O O O O IP Address The IP address of the LAN port Netmask The Subnet mask of the LAN port Default Gateway The Gateway IP address of the LAN port Primary DNS Server The IP address of the primary DNS Domain Name System server Alternate DNS Server The IP address of the substitute DNS server gt DHCP This configuration type is applicable when the system is connected to a network with the presence of a DHCP server all related IP information required will be provided by the DHCP server automatically Layer 2 STP If the EAP200 is set up to bridge other network components this option can be enabled to prevent undesired loops because broadcasting storm may occur in a multi switch environment where broadcast packets are forwarded in an endless loop between switches Moreover a broadcast storm may consume most of available system resources in addition to available bandwidth Thus enabling the Layer 2 STP can lower such undesired occurrence and derive the best available data path for network Communication 40 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 1 3 Management
26. D Red ON 6 USB LED Disabled for future usage only Copyright 4IPNET INC PN ras Mana EAP200 Enterprise Access Point ENGLISH 2 4 Hardware Installation Please follow the steps mentioned below to install the hardware of EAP200 1 Place the EAP200 at the best location The best location for EAP200 is usually at the center of your intended wireless network 2 Connect the EAP200 to your network device Connect one end of the Ethernet cable to LAN port of EAP200 and the other end of the cable to a switch a router or a hub EAP200 is then connected to your existing wired LAN network 3 There are two ways to supply power over to EAP200 a Connect the DC power adapter to the EAP200 power socket b EAP200 LAN port is capable of transmitting DC currents Connect an IEEE 802 3af compliant PSE device e g a PoE switch to the LAN port of EAP200 with the Ethernet cable Now the Hardware Installation is complete Please only use the power adapter supplied with the EAP200 package Using a different power adapter may damage this system To double verify the wired connection between EAP200 and you switch router hub please also check the LED status indicator of the respective network devices 10 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 2 5 Console Interface Via this port to enter the console interface for the administrator to check the IP address of EAP200 and reset th
27. DIUS server Specify a port number or use the default 1812 o Secret Key The secret key for the system to communicate with the RADIUS server o Accounting Service Enabling this option allows accounting of login and logouts through the RADIUS server o Accounting Port The port number used by the RADIUS server for accounting purposes Specify a port number or use the default 1813 o Accounting Interim Update Interval The system will update accounting information to the RADIUS server every interval period When these configurations are finished and MAC restriction is not needed click SAVE and then Reboot the system Otherwise click on the Overview tab and proceed with the next step 30 Copyright 4IPNET INC 41pnet User s Manual EAP200 Enterprise Access Point ENGLISH Step 3 Configuring MAC ACL Access Control List Clicking on the hyperlink corresponding with intended VAP in the MAC ACL column the user will be brought to the Access Control Settings page i a j 1 A 1 f A j N VAP Overview General VAP Config Security Repeater Adva nced Access Control Site Survey Home gt Wireless gt Access Control Access Control Settings Profile Name VAP 1 Maximum Number of Clients f Range 1 32 1 Access Control Type Disable Access Control Access Control Settings Page Please choose among Disable Allow Deny and RADIUS ACL from the drop down menu of Access Control Type 1 Disable Access
28. EN Indicates that clicking this button will save the changes you made but you must reboot the system upon the completion of all configuration settings for the changes to take effect ER Indicates that clicking this button will clear what you have set before the settings are x applied Copyright 4IPNET INC 4ipnet 1 3 Package Content The standard package of EAP200 includes 4ipnet EAP200 Quick Installation Guide QIG CD ROM with User s Manual and QIG Console Cable Ethernet Cable Power Adapter DC 12V Antenna Screw Pack Ground Gable x1 x1 x1 x1 x1 x1 x2 x1 x1 User s Manual EAP200 Enterprise Access Point ENGLISH lt is recommended to keep the original packing materials for possible future shipment when repair or maintenance is required Any returned product should be packed in its original packaging to prevent damage during delivery Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 2 System Overview and Getting Started 2 1 Introduction of 4ipnet EAP200 The 4ipnet EAP200 Enterprise Access Point embedded with 802 11 n b g 2 4GHz MIMO radio in dust proof metal housing Is designed for wireless connectivity In enterprise or industrial environments of all dimensions EAP200 makes the wireless communication fast secure and easy It supports business grade security such as 802 1X and Wi Fi Protected Access WPA and WPA2 By pushing a purposely built butt
29. For regular indoor deployments please keep the default setting e Beacon Interval ms The entered amount of time indicates how often the beacon signal will be sent from the access point Due to RF regulation in different nations available values in the above table will differ Table 2 RF Configurations under normal circumstances in certain countries me omme me 36 40 44 48 52 56 60 6M 9M 12M 18M 24M na 64 100 104 108 112 116 120 124 128 132 36M 48M 54M 136 140 802 11b 1 2 3 4 3 6 1 8 9 10 471 2M 5 5M 11M 11 12 13 802 119 1 2 3 4 5 6 7 8 9 10 6M 9M 12M 18M 24M 11 12 13 36M 48M 54M Auto Lowest Low 12345678 9 10 EO ZA Medium High Highest J J J J J J J J J J e IU 5 J es 802 11b 802 119 11M 12M 18M 24M g g 11 12 13 36M 48M 54M 36 40 44 48 52 56 60 6M 9M 12M 18M 24M 64 100 104 108 112 802 11a 802 11n 36M 48M 54M 116 120 124 128 132 136 140 MC S0 15 123456789 10 1M 2M 5 5M 11M 12M 802 11n 802 119 o V Ty Js J L D J 18M 24M 36M 48M 11 12 13 54M MCSO 15 50 Copyright 4IPNET INC 41pnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 2 3 VAP Configuration This section provides configuration of each Virtual Access Point with settings such as Profile Name ESSID and VLAN ID Security 1 Repeater V Advanced Access Control 4 Site Survey VAP Overview General WAF Config
30. Key Index WEP Keys Security Settings WEP 802 11 Authentication Select from Open System Shared Key or Auto WEP Key Length Select from 64 bit 128 bit 152 bit key length WEP Key Format Select from ASCII or Hex format for the WEP key WEP Key Index Select a key index from 1 through 4 The WEP key index is a number that V V V WV specifies which WEP key is used for the encryption of wireless frames during data transmission gt WEP Keys Provide the pre defined WEP key value the system supports up to 4 sets of WEP keys 27 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH e 802 1X When 802 1X Authentication is selected RADIUS authentication and enhanced dynamic WEP are provided SE HE A Al JE VAP Overview General 4 VAP Config smie Repeater Advanced Access Control 1 Site Survey gt Home gt Wireless gt Securit ET oS mrd i gm Security SETTINGS Profile Name VAP 1 W Security Type 802 1X A ER Disable Enable WEP Key Length 64 bits 128 bits Rekeying Period 300 second s Primary RADIUS Server Host I et Domain Name IP Address Authentication Port 1812 Je Secret Key 4 Accounting Service Disable Enable Accounting Part Accounting Interim Update Interval secondis Security Settings 802 1X Authentication gt Dynamic WEP Settings o Dynamic WEP For 802 1X security type Dyna
31. List gt Rule Config Layer 2 Firewall Configuration Rule ID 1 EtherType Interface From To Service ALL w IP Address a Mask 0 0 0 0 0 Ww a eT J Action Block Pass 60 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH gt gt To move a specific rule Mv in Setting column of firewall list will lead to the following page for reordering confirmation After SAVE button is clicked and system reboot the order of rules will be updated Firewall List Service Advanced A Home gt Firewall gt Move rule Move Rule ID 1 Move to Before O After ID t1 2 0 Please make sure all desired rules state of rule are checked and saved in overview page the rule will be enforced upon system reboot Firewall List Service Advanced Home gt Firewall gt Firevall List Layer 2 Firewall Settings Enable Layer 2 Firewall Disable Enable No State Action Name EtherType Remark 1 DROP CDP and VTP IEEE 8023 2 O DROP STP BPDU IEEE_8023 3 L DROP GARP IEEE 8023 4 O DROP RIP IPv4 5 O DROP HSRP IPv4 6 d DROP OSPF IPv4 7 8 9 10 First Prev Next Last total 20 69 Del Del Del Del Del Del Del Del Del Del Setting Ed Ed Ed Ed Ed Ed Ed Ed Ed Ed In In In In Mv Mv My My My My My My My My Copyright 4IPNET INC
32. Overview General VAP Config Security Repeater Advanced Access Control Y Site Survey Home gt Wireless gt Security Security Settings Profile Name VAP 1 Security Type Security Settings Page VAP 1 as shown for example Select the desired Security Type from the drop down menu which includes None WEP 802 1X WPA PSK and WPA RADIUS 26 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH e None Authentication is not required and data is not encrypted during transmission when this option is selected This is the default setting as shown in the following figure VAP Overview 1 General VAP Config Security Repeater 1 Advanced y Access Control I Site Survey Home gt Wireless gt Security Security Settings Profile Name VAP 1 w Security Type Security Settings None e WEP WEP Wired Equivalent Privacy is a data encryption mechanism with key length selected from 64 bit 128 bit or 152 bit VAP Overview General VAP Config Security 4 Repeater Advanced Access Control Site Survey Home gt Wireless gt Security Security Settings Profile Name Security Type WEP Note The WEP keys are global setting for all virtual APs The key value will apply to all VAPs 302 11 Authentication Open System Shared Key Auto WEP Key Length 64 bits 128 bits 152 bits WEP Key Format ASCII Hex WEP
33. P 7 1 1 General General Network Interface Management 4 GRE Tunnel 4 CAPWAP Home gt System gt General System Information Name EAP200 Description o O Time Device Time 1970 01 01 01 39 09 Time Zone GMT 08 00 Taipei Time O Enable NTP Manually set up Set Date Wear Month M Day Set Time Hour M Min sec System Information Page e System Information For maintenance purpose it is highly recommended to have the following information stated as clearly as possible gt Name The system name used to identify this system gt Description Further information about the system e g device model firmware version and active date gt Location The information on geographical location of the system for the administrator to locate the system easily Time gt Device Time Display the current time of the system gt Time Zone Select an appropriate time zone from the drop down list box gt Time Synchronize the system time by NTP server or manual setup 38 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 1 Enable NTP By selecting Enabled NTP EAP200 can synchronize its system time with the NTP server automatically While this method is chosen at least one NTP server s IP address or domain name must be provided Time Device Time 2000 01 03 04 32 49 Time Zone GMT 08 00 Taipei Time Ena
34. Suite Select an encryption method from TKIP WPA AES WPA TKIP WAP2 AES WAP2 or Mixed gt Pre shared Key Type Select a pre shared key type PSK Hex or Passphrase gt Pre shared Key Enter the key value for the pre shared key the format of the key value depends on the key type selected gt Group Key Update Period The time interval for the Group Key to be renewed the time unit is In Seconds 29 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH e WPA RADIUS Authenticate users by RADIUS and provide WPA data encryption VAP Overview General Y VAP Config Y Security Repeater Advanced Access Control Site Su rvey Home gt Wireless gt Security Security Settings Profile Name Security Type Cipher Suite Group Key Update Period 600 second s Primary RADIUS Server Host OA Domain Name IP Address Authentication Port 1812 F Secret Key a Accounting Service Disable Enable Accounting Interim Update Interval so seconds Security Settings WPA RADIUS gt WPA Settings o Cipher Suite Select an encryption method from TKIP WPA AES WPA TKIP WAP2 AES WAP2 or Mixed o Group Key Update Period The time interval for the Group Key to be renewed the time unit is in seconds gt RADIUS Server Settings o Host Enter the IP address or domain name of the RADIUS server o Authentication Port The port number used by the RA
35. Upgrade Reboot Upload Certificate Liema fbeltiac i Home gt Utilities gt Change Password Change Password Name admin Old Password New Password UP to 32 characters Re enter New Password Change Password Page gt Click on the Utilities main menu button and then select the Change Password tab gt Enter the old password and then a new password with a length of up to 32 characters and retype it in the Re enter New Password field Congratulation Now 4ipnet s EAP200 is installed and configured successfully lt is strongly recommended to make a backup copy of configuration settings After the EAP200 s network configuration is completed please remember to change the IP Address of your PC Connection Properties back to its original settings in order to ensure that your PC functions properly in its real network environments 16 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 3 Connect your AP to your Network The following instructions depict how to establish the wireless coverage of your network The AP will connect to the network through its LAN port and provide wireless access to your network After having prepared the EAP200 s hardware for configuration set the TCP IP settings of administrator s computer to have a static IP Address of 192 168 1 10 and Subnet Mask of 255 255 255 0 Step 1 Configuring the AP s Syste
36. able VLAN ID Fy 1 4084 VAP Configuration Page VAP 1 shown 23 Copyright 4IPNET INC PN ii IT Mana EAP200 Enterprise Access Point ENGLISH Please select the desired VAP profile from the drop down menu of Profile Name Choose Enable for the VAP field Pick a descriptive Profile Name and an appropriate ES SID for clients to associate to A VLAN ID can be provided to indicate the traffics through this particular VAP It may allow further management control e g access rights and Internet usage etc of each VAP with a management gateway Click SAVE and then Reboot for the changes to take effect 24 Copyright 4IPNET INC 4ipnet 5 Secure Your AP Different VAP may require different level of security These instructions will guide the user through setting User s Manual EAP200 Enterprise Access Point ENGLISH up different types of security for a particular VAP Simply repeat the following steps for other VAP with security requirement Step 1 Ensure the intended VAP is Enabled gt system MINER Firewall AP Overview General M VAP Config Security Repeater N Advanced Access Control Home gt Wireless AP VAP Overview VAP No ESSID state Security Type 1 EAP200 1 Enabled None 2 EAP200 2 Disabled None 3 EAP200 3 Disabled Nonea 4 EAP200 4 Disabled None 5 EAP200 5 Disabled None 6 EAP200 6 Disabled None 7 EAP200 7 Disabled None a EAP200 8 Disabled None VAP Overview Page go Uti
37. al 4 Network Interface Management GRE Tunnel VCAFVW A CAPWAP Configuration CAPWAP Disable Enable Certificate Date Check O Disable O Enable Manage Certificates DNS SRV Discovery Disable Enable Domain Name Suffix DHCP Option Discovery U Disable Enable Broadcast Discovery O Disable Enable Multicast Discovery Disable O Enable Pri AC Address Remark 2 e Certificate Date Check To enable this item select Enable and click Manage Certificates to enter the page of Upload Certificate Please refer to the section 7 4 4 Upload Certificate e DNS SRV Discovery The way of using DNS SRV to discover acess controller gt Domain Name Suffix Enter the suffix of the access controller such as example com DHCP Option Discovery The way of using DHCP option to discover access controller Broadcast Discovery The way of using Broadcast to discover access controller e Multicast Discovery The way of using muticast to discover access controller e Static Discovery The way of using Static approach to discover access controller gt AC Address The IP address of access controller If it can not discover the first AC it will try to discover the second AC 44 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH Upload Certificate Manage Certificates A5 Copyright 4IPNET INC e 4ipnet User s Manual EAP200 Enterprise Access P
38. anced Advanced firewall settings are used to supplement the firewall rules providing extra security enhancement against DHCP and ARP traffics traversing the available interfaces of system Firewall List Y Service Advanced Home gt Firewall gt Advanced Advanced Firewall Settings Trust Interface O c O O O O O O VAP1 VAP2 VAP3 VAP4 VAP5 VAPS VAP VAPS AEE Disable Enable ARP Inspection Disable Enable Force DHCP Disable Enable Trust List Broadcast Disable Enable Static Trust List Disable Enable Trust Interface Each VAP interface can be checked individually to mark as trusted interfaces security enforcements on DHCP ARP like DHCP snooping and ARP inspection will be carried out on non trusted interfaces DHCP Snooping When enabled DHCP packets will be validated against possible threats like DHCP starvation attack in addition the trusted DHCP server IP MAC can be specified to prevent rouge DHCP server ARP Inspection When enabled ARP packets will be validated against ARP spoofing o Force DHCP option when enabled the AP only learns MAC IP pair information through DHCP packets Since devices configured with static IP address does not send DHCP traffic therefore any clients with static IP address will be blocked from internet access unless its MAC IP pair is listed and enabled on the Static Trust List o Trust List Broadcast can be enabled to let other AP with L2 firewall feature learn th
39. ble NTP O Manually set up NTP Time Configuration Fields Generally networks would have a common NTP server internal or external If there is use that one otherwise locate a nearby NTP server on the web 2 Manually set up By selecting Manually set up the administrator can manually set the system date and time Time Device Time 2000 01 03 04 32 49 Time Zone GMT 08 00 Taipei Time O Enable NTP Manually set up set Time hour Min Mlsec Manual Time Configuration Fields Set Date Select the appropriate Year Month and Day from the drop down menu Set Time Select the appropriate Hour Min and Sec from the drop down menu Unless either Internet connection or NTP server may become unavailable it is recommended to use NTP server for time synchronization because system time needs to be reconfigured upon reboot 39 Copyright 4IPNET INC PN ras Mana EAP200 Enterprise Access Point ENGLISH 7 1 2 Network Interface General On this page the network settings of the device can be configured fields with a red asterisk i e IP Address Netmask Default Gateway and Primary DNS Server are mandatory Network Interface I Management V GRE Tunnel 4 CAPWAP Home gt System gt Network Interface Network Settings Mode Static DHCP IP Address 197 168 1 1 Netmask 255 255 0 0 Default Gateway 192 168 1 2 sa Primary DNS Server 192 168 1 2 j
40. ch occurrence please make sure Layer 2 STP is enabled To turn on this feature please click on the System and then Network Interface tab F f A l A General Network Interface Management GRE Tunnel CAPWAP 1 Home gt System gt Network Interfare Network Settings Mode static DHCP IP Address 19 168 1 1 Netmask 255 255 0 0 j Default Gateway 192 168 1 2 j Primary DNS Server 197 168 1 2 j Alternate DNS Server Layer STP Disable Enable Network Settings Page Please select Enable in the field labeled Layer2 STP This will prevent data from looping or a broadcast storm Click SAVE when completed and then Reboot to allow updated settings to take effect 39 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 Web Management Interface Configuration This chapter will guide the user through the EAP200 s detailed settings The following table shows all the User Interface Ul functions of 4ipne s EAP200 Enterprise Access Point The Web Management Interface WMI is the page where the status is displayed control is issued and parameters are configured In the Web Management Interface there are two main interface areas Main Menu and Working Area The Working Area occupies the major area of the WMI displayed in the center of the interface ltis also referred to as the configuration page The Main Menu on the top of the WMI allows t
41. ckup file and then click Upload to restore the settings The backup file will replace the active configuration file currently running on the system After network parameters have been reset restored the network settings of the administrator PC may need to be changed to ensure that the IP address of the administrator PC is on the same subnet mask as the EAP200 73 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 4 3 System Upgrade The EAP200 provides a web firmware upload upgrade feature The administrator can download the latest firmware from the website and save it on the administrator s PC To upgrade the system firmware click Browse to choose the new firmware file you downloaded onto your PC and then click Upload to execute the process here will be a prompt confirmation message appearing to notify the administrator to restart the system after a successful firmware upgrade Please restart the system after upgrading the firmware Change Password Backup amp Restore System Upgrade Reboot Home gt Utilities gt System Upgrade System Upgrade Current Version Current Build Number System Upgrade Page e Itis recommended to check the firmware version number before proceeding further Please make sure you have the correct firmware file Note e Firmware upgrade may sometimes result in the loss of some data Please ensure that all necessary settings are writ
42. d lnterval available when Band is 802 119 802 11n The guard interval is the space between symbols characters being transmitted to eliminate inter symbol interference In order to further boost throughput with 802 11n short guard interval is half of what it used to be please select Enable to use Short Guard Interval or Disable to use normal Guard Interval e Channel Width available when Band is 802 119 802 11n Double channel bandwidth to 40 MHz is supported to enhance throughput e Channel Select the appropriate channel from the drop down menu to correspond with your network settings for example Channel 1 11 is available in North American and Channel 1 13 in Europe or choose the default Auto e Max Transmit Rate The maximum wireless transmit rate can be selected from the drop down menu The system will use the highest possible rate when Auto is selected e Transmit Power The signal strength transmitted from the system can be selected among Auto Highest High Medium Low and Lowest from the drop down menu e ACK Timeout lt indicates a period of time that the system waits for an Acknowledgement frame sent back from a station without retransmission In other words upon timeout if the Acknowledgement frame Is still not received the frames will be retransmitted This option can be used to tune network 49 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH performance for extended coverage
43. dcast Rate 11M Advanced Wireless Settings Page e RTS Threshold Enter a value between 1 and 2346 RTS Request to Send Threshold determines the packet size at which the system issues a request to send RTS before sending the fragment to prevent the hidden node problem The RTS mechanism will be activated if the data size exceeds the value provided A lower RTS Threshold setting can be useful in areas where many client devices are associating with EAP200 or in areas where the clients are far apart and can detect only EAP200 but not each other e Fragmentation Threshold Enter a value between 256 and 2346 The default is 2346 A packet size larger than this threshold will be fragmented sent with several pieces instead of one chunk before transmission smaller value results in smaller frames but allows a larger number of frames in transmission lower Fragment Threshold setting can be useful in areas where communication is poor or disturbed by a serious amount of radio interference e DTIM Period Input the DTIM Interval that is generated within the periodic beacon at a specified frequency Higher DTIM will let the wireless client save energy more but the throughput will be lowered e Broadcast SSID Disabling this function will prevent the system from broadcasting its SSID If broadcast of the SSID is disabled only devices that have the correct SSID can connect to the system e Wireless Station Isolation By enabling this function all
44. e trusted MAC IP pairs to issue ARP requests o Static Trust List can be used to add MAC or MAC IP pairs of devices that are trusted to issue ARP request Other network nodes can still send their ARP requests however if their IP appears in the static list with different MAC their ARP requests will be dropped to prevent eavesdropping If any settings are made please click SAVE to save the configuration before leaving this page Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 4 Utilities The administrator can maintain the system on this page Change Password Backup amp Restore System Upgrade Reboot and Upload Certificate 7 4 1 Change Password To protect the Web Management Interface from unauthorized access it is highly recommended to change the administrator s password to a secure password Only alpha numeric characters are allowed and it is also recommended to make use of a combination of both numeric and alphabetic characters Change Password Backup Restore 1 System Upgrade Reboot Home gt Utilities gt Change Password Change Password Name admin New Password up to 32 characters Re enter New Password Change Password Page The administrator can change password on this page Enter the original password admin and new password and then re enter the new password in the Re enter New Password field Click SAVE to save the new password 72 C
45. e device to default if the admin password is forgotten 1 In order to connect to the console port of EAP200 a console modem cable and a terminal simulation program such as the Hyper Terminal are needed 2 Ifa Hyper Terminal is used please set the parameters as 115200 8 None 1 None LOM Properties ajx Por Settings Br der second pe Dats bir 6 Panty Woe ss 5100 btn 5 Plone corlied Han Herpe Dest suits EIK mar nph m The console interface looks like the screenshot below displaying the current LAN IP address and the instructions to reset device to default 2 COM4 PuTTY SYSTEM IP 255 0 0 5 E Enter reset2def twice to r t login to the factory default 11 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH When resetting the device to default from the console interface key in reset2def for login and password Confirm yes and EAP200 will begin the reset process COMA PuTTY SYSTEM IP 192 168 10 17 Enter reset def twice to r login Password Do you really want to VE l ctOry default ctory default and reboot yes When the login prompt reappears the device has completed the reset to default process and the LAN IP is reset to 192 168 1 1 COMA PuTTY Copying Feature Control Profile Check customized objects Check customized pages Configuration
46. e passed to the corresponding EAP200 and its WMI page will automatically open to confirm the changes Click Restart link and EAP200 will restart to activate the tunnel A new window will automatically open and display the tunnel settings from the AP side which is passed from the Controller Click the Reboot link to apply and activate the settings to AP Please refer to your WHG manual for more information regarding AP management with tunnels General ekwork Interface I Management GRE Tunnel CAPWAP Home gt System gt Management Services GRE Tunnel Configuration GRE Tunnel Disable 6 amp Enable Remote Pi key o Interface Myapi Mvap2 VAP3 7 VAPA V VAPS Z VAP6 V VAP7 7 VAPS WDS1 WDS2 WDS3 WDS4 e GRE Tunnel To enable click Enable of GRE Tunnel gt Remote IP Enter the IP address of the Controller gt Key Set up a password for the connection e Interface Select a VAP or WDS that its traffic will pass through the GRE Tunnel between APs and controller For how to enable VAP items please refer the section 7 2 3 VAP Configuration for reference 43 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 1 5 CAPWAP CAPWAP is a standard interoperable protocol that enables a controller to manage a collection of wireless access points There are 5 ways of discovery DNS SRV DHCP option Broadcast Multicast and Static V Lj 1 sg ER Gener
47. eral oooo ooooonnnn o ooonn non 49 7 2 3 VAP Configuration EN 51 DN a E E EAE EAE E EN A E A E E 52 ERE EEE EE E E 56 TER SG GE 0 EEE EN 58 7 2 7 Access Or 60 GR STU VOY A O E EE EE EN 64 va TN CV ML 66 7 3 1 Firewall LIst oooonnnnnv ooo nn 66 g ARE EEE EN 70 TN 71 7 MUU SEERE EE 72 2 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH EGO EC EE 72 ni Ba ka NESE A ino E E 73 7 4 3 System Upgrade kos ono 74 AA RD 75 7 4 4 Upload Certificate ooooonnnnonn non non nn 76 FN 71 AD TOVE O e E secs dese esas dessa duced tesseatesecos 77 7 5 2 NS EA Soe nscess sec tccasececicsicasddeeusasvonciasanssacas sionetscetsiaceapioscassaeneidiesdsestened seacse sioussodenoseesee 79 TT RD 80 AG DE RER 81 TNT 82 3 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 1 Before You Start 1 1 Preface This manual is intended for system integrators field engineers and network administrators to set up 4ipnet s EAP200 802 11n b g 2 4GHz MIMO Access Point in their network environments It contains step by step procedures and visual examples to guide MIS staff or individuals with basic network system knowledge to complete the installation 1 2 Document Conventions a Represents essential steps actions or messages that should not be ignored Contains related information that corresponds to a topic
48. file tmp can t open tmp status L syslogd ad athOapo og en No such file or directory CHH osif vap Stop stopping OSIF VAP bro port iort1l1 IEEESOZ11 IOCTL J athl apO entering disabled st SETHMLMEJ Invalid Could not connect to kernel driver ioctl IEEESOZ1L IOCTL _SETMLME Invalid argument Using interface athUapU with hwaddr 00 11 dz 65 33 5313 and ssid EAP200 1 bro port la packet receive r rR m m l packet receive 7 l F m F Hi Warning No source rm UL rm ma T Sent 3 probe s5 3 br eceived O reply 0 Start WES Hi Hi m ii O Fh starting pid 546 ct A bg SYSTEM IF 192 168 Enter login afathOapO entering forwarding state cyfrom from Network is down Network is down dev null Terne Tri assages they ll go to 0 broadcast 3 shin getty U apper sh L tty U 115200 vt 100 actory default 12 Copyright 4IPNET INC 41pnet User s Manual EAP200 Enterprise Access Point ENGLISH 2 6 Access Web Management Interface 4ipnet EAP200 supports web based configuration Upon the completion of hardware installation EAP200 can be configured through a PC by using its web browser such as Mozilla Firefox 2 0 and higher or Internet Explorer version 6 0 and higher The default values of the EAP200 s LAN IP Address and Subnet Mask are IP Address 192 168 1 1 Subnet Mask 255 255 255 0 E Enterpri
49. he administrator to traverse to various management functions of the system The management functions are grouped into branches System Wireless Firewall Utilities and Status Table 1 EAP200 s Function Organization OPTION FUNCTION General Network Interface Management GRE Tunnel CAPWAP VAP Overview General VAP Configuration Wireless Seel Repeater Advanced Access Control Site Survey Firewall List set Le 00 et Base amp Restore Sr ge Upgrade EE te erte Certificate Geer a aa Associated Clients Repeater Event Log 36 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH On each configuration page the user may Click SAVE to save the changes but the user must reboot the system upon the completion of all configurations for the changes to take effect Upon clicking SAVE the following message will appear Some modification has been saved and will take effect after Reboot All online users will be disconnected during reboot or restart Note 37 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 1 System Upon clicking on the System button users can work on this section for general configurations of the devices e g Time Setup Network Configurations and System Logs This section includes the following functions General Network Interface Management GRE Tunnel and CAPWA
50. ing different levels of services from the same physical AP device Please click on the Wireless icon to review the VAP Overview page g gt System Home gt Wireless VAP Overview VAP No ESSID 1 EAP200 1 2 EAP200 2 3 EAP200 3 4 EAP200 4 5 EAP200 5 6 EAP200 6 7 EAP200 7 EAP200 8 VAP Overview General VAP Config Y Security WITeless f 1 1 State Enabled Disabled Disabled Disabled Disabled Disabled Disabled Disabled S status gt Firewall Utilities Repeater A Advanced A Access Control y Site Survey gt VAP Overview Security Type MAC ACL Advanced Settings None Disabled Edit None Disabled Edit None Disabled Edit None Disabled Edit None Disabled Edit None Disabled Edit None Disabled Edit None Disabled Edit VAP Overview Page To proceed with specific VAP configuration click on the corresponding cell in the State column and the row of the VAP the particular VAP s Configuration page will then appear for further configuration g gt System f M P f VAP Overview General 4 AP Config 4 Security Repeater Wireless A Home gt Wireless gt var Canfig VAP Profile Name VAP 1 ESSID EAP200 1 VLAN ID 5 i EF i i 1 Advanced Access Control V Site Survey G status Firewall Utilities VAP Configuration Profile Name VAP 1 Disable Enable Disable En
51. ion is selected RADIUS authentication and Dynamic WEP are provided VAP Overview General Y VAP Config Y Security Repeater Y Advanced Access Control Y Site Survey Home gt AP gt Security O KONE oc Oe Ee eee Security Settings Profile Name VAP 1 x Security Type 802 1X Dynamic WEP Disable Enable WEP Key Length 64 bits 128 bits Rekeying Period 300 serondis Primary RADIUS Server joer t Domain Name IP Address Authentication Port 1812 Secret Key Accounting Service Disable Enable Accounting Port l Accounting Interim Update Interval E second s Secondary RADIUS Server gt I Domain Name IP Address Security Settings 802 1X Authentication gt Dynamic WEP Settings o Dynamic WEP For 802 1X security type Dynamic WEP is always enabled to automatically generate WEP keys for encryption o WEP Key Length Select from 64 bit or 128 bit key length o Re keying Period he time interval for the dynamic WEP key to be updated the time unit is in second gt RADIUS Server Settings Primary Secondary o Host Enter the IP address or domain name of the RADIUS server o Authentication Port The port number used by the RADIUS server Specify a port number or use the default 1812 o Secret Key The secret key for the system to communicate with the RADIUS server 53 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH
52. l Network Interface Management GRE Tunnel CAPWAP 1 Home gt System gt Network Interface Network Settings Mode Static O DHCP IP Address 192 168 1 1 ja Default Gateway Primary DNS Server j Alternate DNS Server nm Layer STP Disable Enable Network Settings Page If the deployment decides the AP will be getting dynamic IP Addresses from the connected network set Mode to DHCP otherwise set Mode to Static and fill in the required fields marked with a red asterisk IP Address Netmask Gateway and Primary DNS Server with the appropriate values for the network Click SAVE when you are finished to save changes that have been made 19 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH Step 3 Configure the AP s Wireless General Settings Click on the Wireless icon followed by the General tab On this page we only need to choose the Band and Channel that we wish to use AJ s amp System Wireless Firewall Utilities Status i VAP Overview General VAP Contig Security Repeater Advanced Acces Control A Site Survey Home gt Wireless gt General General Settings Band 802 119 802 1in M Pure tin Short Preamble Disable Enable Short Guard Interval Disable Enable Channel Width 20 MHz vi Channel 1 Max Transmit Rate Auto M Transmit Power Auto ka ACK Timeout 0 eto 255 0 4 uto
53. lities Site Survey MAC ACL Disabled Disabled Disabled Disabled Disabled Disabled Disabled Disabled S Status Advanced Settings Edit Edit Edit Edit Edit Edit Edit Edit On the VAP Overview page check the table to confirm the VAP State If it is Enabled skip to Step 2 If not click on to proceed with VAP Configuration for that particular VAP 25 Copyright 4IPNET INC m 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH A 5 A 1 1 VAP Overview General 4 VAP Config Security Repeater Advanced Access Control Site Survey Home gt Wireless gt VAP Config VAP Configuration Profile Name VAP Disable Enable Profile Name VAP 1 ESSID EAP200 1 VLAN ID Disable Enable VLAN ID f 1 40941 VAP Configuration Page VAP 1 as shown for example Select Enable for the VAP field and click SAVE Click the Overview tab to return to the previous table to begin the next step Step 2 Configure Security Settings for your VAP The following instructions will guide the user to set up wireless security with a specific VAP If only restricted access of certain MAG addresses is desired skip to the Step3 MAC restriction can be coupled with wireless security to provide extra protection First click on the corresponding cell in the column labeled Security Type This hyperlink will direct the user to the following Security Settings page VAP
54. m Information gt Enter the AP s default IP Address 192 168 1 1 into the URL of a web browser gt Login via using Username admin and Password admin The WMI appears as shown below gt Y gt 3 System Wireless Firewall Utilities EWE Y N Overview Associated Clients V Repeater Event Log Home gt Status gt System Overvie System Overview g gt System Radio Status System Name Enterprise Access Point MAC Address 60 1F B4 83 96 02 Firmware Version Band 802 11g n Build Number Channel 1 Location TX Power 19 dBm Site EN A Device Time 1970 01 01 08 00 30 System Up Time Odays 0 00 30 LAN Interface 4 AP Status Profile SE ERS Security Online MAC Address 00 1F D4 83 96 01 Kva BSSID ESSID Type Clients SRE IP Address VAP 1 00 1F D4 83 96 02 EAP 1 None 0 S Subnet Mask 255 255 0 0 VAP 2 06 1F D4 83 96 02 EAP 2 None 0 3 Gateway VAP 3 OA 1F D4 83 96 02 EAP 3 None g v Q GRE Tunnel Status Connected Remote IP 192 108 3 3 Key 12345 Web Management Interface Main Page System Overview 17 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH From here click on the System icon to arrive at the following page On this Page you can make entries to the Name Description and Location fields as well as set the device s time gt A g AN Wireless Firewall Utilities Status T A 5 f i NI General Network Interface 1 Management GRE T
55. mic WEP is always enabled to automatically generate WEP keys for encryption o WEP Key Length Select from 64 bits or 128 bits key length o Rekeying Period The time interval for the dynamic WEP key to be updated the time unit is in second gt RADIUS Server Settings o Host Enter the IP address or domain name of the RADIUS server o Authentication Port The port number used by the RADIUS server Specify a port number or use the default 1812 o Secret Key The secret key for the system to communicate with the RADIUS server o Accounting Service Enabling this option allows accounting of login and logouts through the RADIUS server o Accounting Port The port number used by the RADIUS server for accounting purposes Specify a port number or use the default 1813 o Accounting Interim Update Interval The system will update accounting information to the RADIUS server every interval period 28 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH e WPA PSK Provide shared key authenticaiton in WPA data ee VAP Overview A ad VAP dan Security Repeater A bie A Access Control Site oe Home gt Wireless gt Security Security Settings Profile Name VAP 1 Security Type WPA PSK w Cipher Suite TKIP WPA Pre shared Key Type O PSK Hex 64 chars Passphrase 8 63 chars Group Key Update Period second s Security Settings WPA PSK gt Cipher
56. nd Security type The administrator can click Setup or Connect to configure the wireless connection according to the mentioned readings when Repeater Type is Universal Repeater Scan Again 0 1 00 1F 04 00 26 56 54 43 None Connect o 00 5 N8 1F D4 00 26 56 1 54 9 None Connect Site Survery Page lf Universal Repeater function is enabled the system can scan and display all surrounding available access points APs The administrator can then select an AP to for connection to extend its wireless service coverage on this page SSID The SSID Service Set ID of the AP found in this system s coverage area MAC Address The MAC address of the respective AP Channel The channel number currently used by the respective AP or repeater Rate The transmitting rate of the respective AP Signal The encryption type used by the respective AP V V V V v v Setup Connect o Connect Click Connect to associate with the respective AP directly no further configuration is required Cip 893 00 0E 2E 7C AA 6E 1 54 4 None o Setup Click Setup to configure security settings for associating with the respective AP WEP Click Setup to configure the WEP setting for associating with the target AP Cip wep 00 11 43 08 09 56 5 54 40 WEP The following configuration box will then appear at the bottom of the screen Security settings configured here must be the same as the target AP 64 Copyright 4IPNET INC
57. og The Event Log provides the records of system activities The administrator can monitor the system status by checking this log Overview Associated Clients Repeater Event Log Home Status gt Event Log Event Log Jan 1 00 00 14 syslogd started BusyBox v1 12 4 Jan 1 00 00 14 syslog athOap0 IEEE 802 11 Fetching hardware channel rate support not supported Event Log Page In the log each line represents an event record in each line there are 4 fields Date Time The time amp date when the event happened Hostname Indicates which host recorded this event Note that all events on this page are local events so the hostname in this field is always the same However in remote SYSLOG service this field will help the administrator identify which event is from this EAP200 Process name Indicate the event generated by the running instance Description Description of the event To save the file locally click SAVE LOG to clear all of the records click CLEAR 8 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 6 Online Help The Help button is at the upper right corner of the display screen Click Help for the Online Help window and then click the hyperlink of the relevant information needed fi Home SLogout 7 Help Online Help Corner P N V20020110306 82 Copyright 4IPNET INC
58. oint ENGLISH 7 2 Wireless This section includes the following functions VAP Overview General VAP Configuration Security Repeater Advanced Access Control and Site Survey EAP200 supports up to eight Virtual Access Points VAPs Each VAP can have its own settings e g ESSID VLAN ID security settings etc With such VAP capabilities different levels of service can be configured to meet network requirements 7 2 1 VAP Overview An overall status is collected on this page including ESSID State Security Type MAC ACL and Advanced Settings where EAP200 features 8 VAPs with respective settings In this table please click on the hyperlink to further configure each individual VAP l a a a VSP Overview I General VAP Config Security 1 Repeater Advanced Y Access Control Y Site Survey Home gt Wireless gt VAP Overview VAP Overview VAP Mo ESSID State Security Type MAC ACL Advanced Settings 1 EAP200 1 Enabled None Disabled Edit 2 EAP200 2 Disabled None Disabled Edit 3 EAP200 3 Disabled None Disabled Edit 4 EAP200 4 Disabled None Disabled Edit 5 EAP200 5 Disabled None Disabled Edit 6 EAP200 6 Disabled None Disabled Edit 7 EAP200 7 Disabled None Disabled Edit 8 EAP200 8 Disabled None Disabled Edit VAP Overview Page 46 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH e State The hyperlink showing Enable or Disable connects to the VAP Configuration page i
59. ol Settings Profile Name VAP 1 Maximum Number of Clients Range 1 32 Access Control Type MAC ACL Deny List v No MAC Address State MAC ACL Deny List 32 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 4 RADIUS ACL Authenticate incoming MAG addresses by an external RADIUS server When RADIUS ACL is selected all incoming MAC addresses will be authenticated by an external RADIUS server Please note that each VAP MAC ACL and its security type shown on the Security Settings page share the same RADIUS configuration VAP Overview Y General Y VAP Config Security Repeater N Adwa nced Access Control Site Survey A Home gt Wireless gt Access Control Access Control Settings Profile Name VAP 1 Y Maximum Number of Clients Range 1 32 Access Control Type RADIUS ACL s ee NE JE Ke Notelll These settings will also apply to security settings which use RADIUS Server for this VAP Host as A Domain Name IP Address Authentication Port 1 65535 Secret Key 051 5 ja Secondary RADIUS Server Hl si mm Authentication Port RADIUS ACL Click SAVE and Reboot upon completing the related configurations to take effect 33 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 6 Create a WDS Bridge between two APs WDS link creation will assist to extend network coverage where r
60. on the 4ipWES Press n Connect feature makes it easy to bridge wireless links of multiple EAP200s for forming wider wireless network coverage EAP200 also features multiple ESSIDs with VLAN tags and multiple Virtual APs great for enterprise applications such as separating the traffics of different departments using different ESSIDs The PoE LAN port can receive power from Power over Ethernet PoE sourcing device ts metal case is IP50 anti dust compliant which means that EAP200 is well suited to WLAN deployment in industrial environments Internet NY WHG Controller E55ID 2 AY a EE Switch fa fe yp fl X Public Wireless Network N IJH Internal Wired Network Wired and Wireless Network Layout with EAP200s Internal Wireless Network Copyright 4IPNET INC m 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 2 2 Deployment Topology DHCP Server 192 148 1 1 192 148 1 14 Aroles Laptop II Au hertc ston Serves 192 168 1 19 a 1 M Laptop WDS Link a R gt l k A S gt a u a Sy 1 7 la 14 197744 1 14 rhain tissi Wired Detktops Wied Deskiens 192 TERT Wireles laclop f NL e ly b a j i SA 102 148 1 12 72168100 Wired Dotkicpi Common Network Layout with EAP200s This above deployment scenario illustrates a deployment example using three access points AP 1 AP 2 and
61. opyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 4 2 Backup amp Restore This function is used to backup and restore the EAP200 settings The EAP200 can also be restored to factory defaults using this function It can be used to duplicate settings to other access points backup settings of this system and then restore on another AP Change Password i Backup amp Restore System Upgrade N Reboot Upload Certificate i Home gt Utilities gt Config Save amp Restore Configuration Backup amp Restore Reset to Default Backup System Settings Backup amp Restore Page e Reset to Default gt Click Reset to load the factory default settings of EAP200 A pop up Page will appear to reconfirm the request to reboot the system Click OK to proceed or click Cancel to cancel the reboot request Message from webpage 2 This action will reboot the system Do you want to continue Reboot Confirmation Prompt gt A warning message as displayed below will appear during the reboot period The system power must be kept turn on before the completion of the reboot process gt The System Overview page will appear upon the completion of reboot e Backup System Settings Click Backup to save the current system settings to a local disk such as the hard disk drive HDD of a local computer or a compact disc CD e Restore System Settings Click Browse to search for a previously saved ba
62. or investigate the settings of associated clients to improve network communication performance Overview Associated Clients Repeater Event Log Home gt Status gt Wireless Clients Associated Client Status Client List Associated VAP ESSID MAC Address SNR dB Idle Time secs Disconnect Associated Client Status Page e Associated VAP The name of a VAP Virtual Access Point that the client is associated with e ESSID The Extended Service Set ID which the client is associated with e MAC Address The MAC address of associated clients e SNR The Signal to Noise Ratio of respective client s association e Idle Time Time period that the associated client is inactive the time unit is in second e Disconnect Upon clicking Kick the client will be disconnected with the system 79 Copyright 4IPNET INC o Hal 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 5 3 Repeater The administrator can review detailed information of the repeater function on this page Information of repeater s status mode and encryption is provided Overview I Clients Repeater Event Log Home gt Status gt Repeater Information Repeater Information Universal Repeater 551D Cip AP Status Enabled TX Rate 48 Mbits SNR 16 TX Count 69 Bytes TX Error 0 Packets Encryption None Repeater Status Page 80 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 5 4 Event L
63. packets the administrator can customize the EAP700 s multicast broadcast bandwidth here 59 Copyright 4IPNET INC PN ras Mana EAP200 Enterprise Access Point ENGLISH 7 2 7 Access Control On this page the network administrator can restrict the total number of clients connected to the EAP200 as well as specify particular MAC addresses that can or cannot access the device VAP Overview General VAP Config Security Repeater I Advanced Per Control Site Survey Home gt AP gt Access Control Access Control Settings Profile Name VAP 1 Maximum Number of Clients Range 1 32 Access Control Type Disable Access Control Access Control Settings Page e Maximum Number of Clients EAP200 supports various methods of authenticating clients for wireless LAN access The default policy is unlimited access without any authentication required To restrict the station number of wireless connections simply change the Maximum Number of Stations to a desired number For example while the number of stations is set to 20 only 20 stations are allowed to connect to the specified VAP 60 Copyright 4IPNET INC e 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH e Access Control Type The administrator can restrict the wireless access of client devices based on their MAC addresses gt Disable Access Control When Disable is selected there is no restriction for client devices to
64. pe when EtherType is IEEE802 3 The field can be used to indicate the type of encapsulated traffics VLAN ID when EtherType is 802 1 Q The VLAN ID is provided to associate with certain VLAN tagging traffics Priority when EtherType is 802 1 Q It denotes the priority level with associated VLAN traffics Encapsulated Type when EtherType is 802 1 Q It can be used to indicate the type of encapsulated traffics Opcode when EtherType is ARP RARP This list can be used to specify the ARP Opcode in ARP header Source MAC Address Mask indicates the source MAC IP Address Mask indicates the source IP address when EtherType is IPv4 ARP IP MAC amp MASK indicate the ARP payload fields Destination MAC Address Mask indicates the destination MAC IP Address Mask indicates the destination IP address when EtherType is IPv4 ARP IP MAC amp MASK indicate the ARP payload fields Action The rule can be chosen to be Block or Pass Remark The note of this rule can be specified here When the configuration for firewall rule is provided please click SAVE and Reboot system to let the firewall rule take effort gt gt To insert a specific rule In in Setting column of firewall list will lead to the following page for detail configuration with rule ID for the current inserted rule From this page the rule can be edited form scratch or from an existing rule for revision Firewall List Service 4 Advanced Home gt Firewall
65. se Access Point Windows Internet Explore E yov http t192 165 1 1 File Edit View Favorites Tools Help amp Enterprise Access Point Example of entering EAP200 s default IP Address into a web browser e To access the web management interface WMI connect the administrator PC to the LAN port of EAP200 via an Ethernet cable Then set a static IP Address on the same subnet mask as the EAP200 in TCP IP settings of your PC such as the following example IP Address 192 168 1 100 Subnet Mask 255 255 255 0 Please note that the IP Address used should not overlap with the IP Addresses of any other device within the same network Note e Launch the web browser on your PC and enter the IP Address of the EAP200 192 168 1 1 at the address field and then press Enter The following Administrator Login Page will then appear Enter admin for both the Username and Password fields and then click Login tj Username admin Password 200 0 Administrator Login Page 13 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH e After a successful login into EAP200 a System Overview page of the Web Management Interface WMI will appear 4 AJ s B System Wireless Firewall Utilities Status Overview Associated Cliente Repeater Event Log Home gt Status gt System Overview System Overview P System
66. ten down before upgrading the firmware e During firmware upgrade please do not turn off the power This may permanently damage the system 74 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 4 4 Reboot This function allows the administrator to restart the EAP200 safely The process shall take about three minutes Click Reboot to restart the system Please wait for the blinking timer to complete its countdown before accessing the system s Web Management Interface again The System Overview page will appear after reboot successfully Occasionally it is necessary to reboot the EAP200 to ensure that parameter changes are submitted Change Fassword Backup amp Restore System Upgrade Reboot Upload Certificate Home gt Utilities gt Reboot Reboot the System Reboot may take several minutes to complete The Admin Login Page will be shown after system boots up Reboot Page ge Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 7 4 4 Upload Certificate This function is used to setup the advanced configuration for the CAPWAP to manage Certificates Change Password Backup amp Restore System Upg GE Reboot Upload Certificate Home gt Utilities gt Upload Certificate Upload Certificate Upload Private Key Upload Certificate Upload Trusted Certificate File Name eg Use Default Certificate gt Certificate It
67. ter Advanced Access Control Site Survey Home gt Wireless gt Security Security Settings Profile Name VAP 1 Security Type Security Settings None e WEP WEP Wired Equivalent Privacy is a data encryption mechanism based on a 64 bit 128 bit or 152 bit shared key algorithm i A S 4 di 4 E A 1 i A VAP Overview General VAP Config security Repeater 41 Advanced Access Control Y Site Survey Home gt Wireless gt Security Security Settings Profile Name security Type WEP v Note The WEP keys are global setting for all virtual APs The key value will apply to all VAPSs 02 11 Authentication Open System Shared Key Auto WEP Key Length 64 bits 128 bits 152 bits WEP Key Format ASCII U Hex WEP Key Index WEP Keys Security Settings WEP 92 Copyright 4IPNET INC 4ipnet User s Manual EAP200 Enterprise Access Point ENGLISH 802 11 Authentication Select from Open System Shared Key or Auto WEP Key Length Select from 64 bit 128 bit 152 bit key length WEP Key Format Select from ASCII or Hex format for the WEP key WEP Key Index Select a key index from 1 4 The WEP key index is a number that specifies V V V WV which WEP key will be used for the encryption of wireless frames during data transmission gt WEP Keys Provide the pre defined WEP key value the system supports up to 4 sets of WEP keys e 802 1X When 802 1X Authenticat
68. unnel Y CAPWAP Home gt System gt General System Information Name EAP200 Description Location Ime Device Time 1970 01 01 00 47 28 Time Zone GMT 08 00 Taipei v Time Enable NTP Manually set up NTP Server 1 NIP Server 2 System Information Page There are two methods of setting up the time Manual indicated by the option Set Date amp Time and NTP The default is Manual and requires individual setup every time the system starts up Simply choose a time zone and set the time accordingly When finished click SAVE Time Zone GMT 08 00 Taipei M Time O Enable NTP Manually set up Set Date year Month pay Set TIME kour Min mec Manually Time Setup The alternative is NTP Upon selecting NTP under the Time field the configuration changes to allow up to two NTP servers Simply enter a local NTP server s IP Address if available or search online for an NTP server nearest you Set the time zone and click SAVE 18 Copyright 4IPNET INC 41pnet User s Manual EAP200 Enterprise Access Point ENGLISH Time Zone GMT 08 001Taipei v Time Enable NTP O Manually set up NTP Setup Step 2 Configuring the AP s Network Settings While still on this Page click on the Network Interface tab to begin configuration of the network settings Genera
69. unning wires is not an option effectively transferring the traffics to the other end of WLAN LAN through the EAP200 Since this is a peer to peer connection both EAP200s will be configured by the same way Step 1 Make sure the Band and Channel are matched between the WDS peers In order to create a valid WDS link the two EAP200s must be configured to use the same channel and band for their wireless settings Click the Wireless icon and then General tab to go to the following page gt U gt a System Mireless Firewall Utilities Status WAP Overview General VAP Config Security Repeater Advanced Access Control Site Survey A Home gt Wireless gt General General Settings Band 802 119 602 111 Pure 11n Short Preamble Disable Enable Short Guard Interval Disable Enable Channel Width 20 MHz Channel 1 Max Transmit Rate Auto Transmit Power Auto w ACK Timeout o o 255 0 4 uto Unit 4 micro seconds Beacon Interval 100 200 500ms Wireless General Settings Page Please make sure both APs are using the same Band and Channel in order to establish a successful WDS link Click SAVE if any changes have been made 34 Copyright 4IPNET INC 41pnet User s Manual EAP200 Enterprise Access Point ENGLISH Step 2 Prevent Loops if Connecting Many APs When many APs are linked in this manner undesired loops may form to lower overall WLAN performance To prevent su
70. urvey Home gt Wireless gt Advanced Advanced Wireless Settings Profile Name RTS Threshold 1 2346 Fragment Threshold 256 2346 DTIM period f1 15 Broadcast SSID Disable Enable Wireless Station Isolation Disable Enable WMM Disable Enable IAPP Disable Enable Multicast Broadcast Rate VAP Advanced Settings Page 48 Copyright 4IPNET INC PN ras Mana EAP200 Enterprise Access Point ENGLISH 7 2 2 General AP s general wireless settings can be configured here VAP Overview General WAP Config Security 4 Repeater Y Advanced 1 Access Control Site Survey Home gt Wireless gt Genera General Settings Band 802 119 802 11n Pure iin Short Preamble Disable Enable Short Guard Interval Disable Enable Channel Width Channel Max Transmit Rate Transmit Power ACK Timeout 0 255 G A uto Unit 4 micro seconds ML Beacon Interval 00 F100 500ms AP General Settings Page e Band Select an appropriate wireless band 802 11b 802 119 802 11b 802 119 802 119 802 11n or select Disable if the wireless function is not required gt Pure 11n Enable 802 11n network only e Short Preamble The short preamble with a 56 bit synchronization field can improve WLAN transmission efficiency Select Enable to use Short Preamble or Disable to use Long Preamble with a 128 bit synchronization field e Short Guar
Download Pdf Manuals
Related Search
Related Contents
Bem-vindo! Sobre este manual Manuale - Hanna Instruments レンジフードファン取付説明書 Black Box C18 headphone Speaker - AV-iQ CGA CADEV - Conditions générales d`achat V1.0 Copyright © All rights reserved.
Failed to retrieve file