Home
Netgear PROSAFE WG302 User's Manual
Contents
1. 2 From the Security menu click the Access Control link to display the Access Control List menu shown below Access Control List Turn Access Control On Select Access Control Database Local MAC Address Database v Trusted Wireless Stations Local MAC Address Database MAC Address C 00 09 5b a0 00 04 Available Wireless Stations Station iMac Address ID Add Add New Station Manually MAC Address k Add Figure 3 10 Access Control List menu 3 Select the Turn Access Control On check box 3 20 Basic Installation and Configuration July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 4 Choose to use the local MAC address database stored on the access point or use the RADIUS MAC address database stored on a RADIUS server If you choose the RADIUS MAC Address Database you must configure the RADIUS Server Settings first 5 Then either select from the list of available wireless cards the WG302 has found in your area or enter the MAC address and device name for a device you plan to use You can usually find the MAC address printed on the wireless adapter 6 Click Add to add the wireless device to the access list Repeat these steps for each additional device you want to add to the list 7 Be sure to click Apply to save your wireless access control list settings Now only devices on this list will be allowed to wirelessly connect to the WG302 How to Configu
2. 6 Choose WPA with Radius from the list 7 Click Apply to save your settings How to Configure WPA PSK Note Not all wireless adapters support WPA Furthermore client software is required on the client Windows XP and Windows 2000 with Service Pack 3 do include the client software that supports WPA Nevertheless the wireless adapter hardware and driver must also support WPA Consult the product document for your wireless adapter and WPA client software for instructions on configuring WPA settings To configure WPA PSK follow these steps 1 Log in at the default LAN address of http 192 168 0 228 with the default user name of admin and default password of password or using whatever LAN address and password you have set up 2 Click WEP WPA Settings in the Security menu of the WG302 WEP WPA Settings Wireless LAN Network Authentication Open System Data Encryption Open System Shared Key Passphrase Legacy 802 1 WPA with Radius Key1 WPA2 with Radius WPA amp WPA with Radius Key 2 IWPA PSK D eae Pork Key 3 WPA PSK amp WPA2 PSK Key 4 Enable Wireless Client Security Separator No Yes Cancel Figure 3 14 WEP WPA Settings menu 3 Choose WPA PSK from the list 4 Enter the pre shared key passphrase 5 Click Apply to save your settings Basic Installation and Configuration 3 25 July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Poin
3. Port Number Port number of the Radius Server The default is 1813 e Shared Secret This is shared between the Wireless Access Point and the Radius Server while authenticating the supplicant 4 Click Apply to save your settings Basic Installation and Configuration 3 27 July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 5 Click WEP WPA Settings in the Security menu WEP WPA Settings Wireless LAN Network Authentication Open System gt Data Encryption Enable Wireless Client Security Separator No Yes Cancel Figure 3 16 WEP WPA Settings menu 6 Choose WPA2 with Radius from the list 7 Click Apply to save your settings How to Configure WPA2 PSK Note Not all wireless adapters support WPA2 Furthermore client software is required on the client Make sure your client card supports WPA2 Consult the product document for your wireless adapter and WPA2 client software for instructions on configuring WPA2 settings To configure WPA2 PSK follow these steps 1 Log in at the default LAN address of http 192 168 0 229 with the default user name of admin and default password of password or using whatever LAN address and password you have set up 3 28 Basic Installation and Configuration July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 2 Click WEP WPA Settings in the Security menu
4. 168 0 x and a Subnet Mask of 255 255 255 0 Open a Web browser such as Internet Explorer or Netscape Navigator Connect to the WG302 by entering its default address of http 192 168 0 228 into your browser A login window like the one shown below opens gt t NETGEAR ProSafe Wireless Access Point 0507 p x J Name admin Password eeccccce Figure 3 6 Login window Log in use the default user name of admin and default password of password Once you have entered your access point name your Web browser should automatically find the WG302 Access Point and display the home page as shown in Login result WG302 home page on page 3 7 Using the Basic IP Settings Options The Basic IP Settings menu is under the Basic heading of the main menu Use this menu to configure DHCP static IP and access point access point name settings Basic Installation and Configuration 3 11 July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 Basic Settings Access Point Name Inetgear 4F35E IP Address DHCP Client OE Enable Disable IP Address 192 168 Jo 228 IP Subnet Mask 255 J255 255 o Default Gateway lo jo jo Ijo Primary DNS Server o o 0 jo Secondary DNS Server o Ja 3 0 lo Spanning Tree Protocol Enable Disable Time Zone GMT 08 00 Pacific Time US amp Canada Tijuana J C Adjust for Daylight Saving Time Current Time Fri Dec
5. If you are configuring the WG302 from a wireless computer and you change the click Apply You must then change the wireless settings of your computer to match the new Settings Configure and test your PCs for wireless connectivity Program the wireless adapter of your PCs to have the same SSID and channel that you configured in the WG302 Check that they have a wireless link and are able to obtain an IP address by DHCP from the WG302 Once your PCs have basic wireless connectivity to the WG302 you can configure the advanced wireless security functions Basic Installation and Configuration 3 19 July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 How to Restrict Wireless Access by MAC Address To restrict access based on MAC addresses follow these steps 1 Log in to the WG302 using its default address of hitp 192 168 0 228 or at whatever IP address the unit is currently configured Use the default user name of admin and default password of password or whatever LAN address and password you have set up Note When configuring the WG302 from a wireless computer whose MAC address is es not in the access control list if you select Turn Access Control On you will lose your wireless connection when you click Apply You must then access the wireless access point from a wired computer or from a wireless computer which is on the access control list to make any further changes
6. M fo fo fo Port Number fisiz Shared Secret o Reauthentication Time E 600 Seconds I Global Key Update every 3600 Seconds C every fiooo x1000 Packets I Update if any station disassociates Accounting Radius Server Login Primary IP Address fo k fo i p fo Port Number is13 Shared Secret e e Secondary P Address jo 5 fo i p n p Port Number s13 Shared Secret D Cancel Figure 3 12 Radius Server Settings 3 Enter the Radius settings e Authentication Access Control Radius Server Configuration This configuration is required for authentication using Radius IP Address Port No and Shared Secret is required for communication with Radius Server A Secondary Radius Server can be configured which is used on failure on Primary Radius Server e IP Address The IP address of the Radius Server The default is 0 0 0 0 Port Number Port number of the Radius Server The default is 1812 Basic Installation and Configuration 3 23 July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 e Shared Secret This is shared between the Wireless Access Point and the Radius Server while authenticating the supplicant e Re authentication Time The time interval in seconds after which the supplicant will be authenticated again with the Radius Server The default is 3600 seconds e Global key Re Key Time Check on this option to enable Re keying of Global Key The Glob
7. WPA Settings in the Security menu WEP WPA Settings Wireless LAN Network Authentication Open System v Data Encryption Open System WPA with Radius WP h Radiy HWPA amp WPA2 with Radius D WAP Key 1 Key 2 Key 3 WPA2 PSK Key 4 Enable Wireless Client Security Separator No Yes Cancel Figure 3 19 WEP WPA Settings menu 6 Choose WAP and WPA2 with Radius from the list 7 Click Apply to save your settings How to Configure WPA2 PSK and WPA2 PSK Note Not all wireless adapters support WPA Furthermore client software is required on the client Windows XP and Windows 2000 with Service Pack 3 do include the client software that supports WPA Nevertheless the wireless adapter hardware and driver must also support WPA Consult the product document for your wireless adapter and WPA client software for instructions on configuring WPA settings Note Not all wireless adapters support WPA2 Furthermore client software is required on the client Make sure your client card supports WPA2 Consult the product document for your wireless adapter and WPA2 client software for instructions on configuring WPA2 settings To configure WPA PSK and WPA2 PSK follow these steps 1 Log in at the default LAN address of http 192 168 0 229 with the default user name of admin and default password of password or using whatever LAN address and password you have set up 3 32 Basic Installatio
8. access point is the SSID you configure in the wireless adapter card All wireless nodes in the same network must be configured with the same SSID Authentication Circle one Open System or Shared Key Choose Shared Key for more security Note If you select shared key the other devices in the network will not connect unless they are set to Shared Key and have the same keys in the same positions as those in the WG302 WEP Encryption Keys For all four 802 11b keys choose the Key Size Circle one 64 128 or 152 bits Key 1 Key 2 Key 3 Key 4 WPA PSK Pre Shared Key WPA2 PSK Pre Shared Key Record the WPA PSK key Record the WPA2 PSK key Key Key WPA RADIUS Settings For WPA record the following settings for the primary and secondary RADIUS servers Server Name IP Address Primary Secondary Port Shared Secret WPA2 RADIUS Settings For WPA2 record the following settings for the primary and secondary RADIUS servers Server Name IP Address Primary Secondary Port Shared Secret Use the procedures described in the following sections to configure the WG302 3 18 Basic Installation and Configuration July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 How to Set Up and Test Basic Wireless Connectivity Follow the instructions below to set up and test basic wireless connectivity Once you have established basic wireless connectivity you can enable security sett
9. can take slightly longer to establish Also WEP encryption can consume more battery power on a notebook computer Cabling Requirements The WG302 Access Point connects to your LAN via twisted pair Category 5 Ethernet cable with RJ 45 connectors 3 2 Basic Installation and Configuration July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 Default Factory Settings When you first receive your WG302 the default factory settings will be set as shown below You can restore these defaults with the Factory Default Restore switch on the rear panel see WG302 front panel on page 2 6 FEATURE FACTORY DEFAULT SETTINGS User Name case sensitive admin Password case sensitive password Operating Mode Access Point Access Point Name netgearxxxxxx where xxxxxx are the last six digits of the wireless access point s MAC address Built in DHCP client DHCP client disabled Built in DHCP server DHCP server disabled IP Configuration IP Address 192 168 0 228 if DHCP server is unavailable Subnet Mask 255 255 255 0 Gateway 0 0 0 0 Network Name SSID NETGEAR Broadcast Network Name SSID Enabled 802 11g Radio Frequency Channel 11 AutoCell RF Management Enabled AutoCell Enhanced RF Security stealth mode Disabled WEP WPA Disabled Restricting connectivity based on MAC Access Disabled Control List Spanning Tree Protocol Enabled Time Zo
10. if all clients support WPA2 If selected you must use AES encryption and configure the Radius Server Settings Screen WPA and WPA2 with Radius This selection allows clients to use either WPA with TKIP or WPA2 with AES If selected encryption must be TKIP AES and you must also configure the Radius Server Settings Screen Note All options are available if using Access Point mode In other modes e g Repeater or Bridge some options may be unavailable Data Encryption Select the desired option The available options depend on the Network Authentication setting above otherwise the default is None The supported options are None No encryption is used 64 bits WEP Standard WEP encryption using 40 64 bit encryption 128 bits WEP Standard WEP encryption using 104 128 bit encryption 152 bits WEP Proprietary mode that will only work with other wireless devices that support this mode TKIP This is the standard encryption method used with WPA AES This is the standard encryption method for WPA2 Some clients may support AES with WPA but this is not supported by this Access Point TKIP AES This setting allows both WPA and WPA2 to be supported Broadcast packets use TKIP For unicast point to point transmissions WPA clients use TKIP and WPA2 clients use AES Passphrase To use the passphrase to generate the WEP keys enter a passphrase and click Generate Keys You can also enter the k
11. is NETGEAR A group of Wireless Stations and a single access point all using the same ID SSID form a Basic Service Set BSS Using the same SSID is essential Devices with different SSIDs are unable to communicate with each other However some access points allow connections from wireless stations which have their SSID set to any or whose SSID is blank null A group of wireless stations and multiple access points all using the same ID ESSID form an Extended Service Set ESS Different access points within an ESS can use different channels To reduce interference it is recommended that adjacent access points should use different channels As wireless stations physically move through the area covered by an ESS they will automatically change to the access point which has the least interference or best performance This capability is called roaming Note The AutoCell feature enhances the roaming interference and channel selection of an extended wireless network e Broadcast Wireless Network Name SSID This field lets you turn off the SSID broadcast If you turn off the SSID broadcast only stations that know the SSID will connect Disabling SSID broadcast somewhat hampers the wireless network discovery feature of some products The default is to enable SSID broadcast Note Broadcast Wireless Network Name SSID is automatically turned off when you select the AutoCell Enhanced RF Security
12. option in the advanced wireless settings page gt e Operating Mode Select the desired wireless operating mode The options are Auto 11g b Both 802 11g and 802 11b wireless stations can be used This is the default 11g Only Only 802 11g wireless stations can be used This is required for 108 Mbps data rate operation 3 14 Basic Installation and Configuration July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 11b Only All 802 11b wireless stations can be used 802 11g wireless stations can still be used if they can operate in 802 11b mode e Channel This field identifies which operating frequency will be used It should not be necessary to change the wireless channel unless you notice interference problems or setting up the WG302 near another access point See Wireless Channels on page B 7 for more information on wireless channels Note Channel selection is automatically adjusted by AutoCell when the Auto RF Ca Management option is enabled The default setting is for the AutoCell Auto RF Management option to be enabled Access points use a fixed channel You can select the channel used This allows you to choose a channel which provides the least interference and best performance In the USA and Canada 11 channels are available Note Channel 6 is required for 108 Mbps data rate fusing multiple access points it is
13. 31 21 58 09 1999 Figure 3 7 IP Settings menu e Access Point Name NetBIOS Enter a new name for the wireless access point and click Apply to save your changes e The IP Address The wireless access point is shipped preconfigured with its DHCP client disabled and with the following private static IP addresses IP Address 192 168 0 228 IP Subnet Mask 255 255 255 0 Gateway 0 0 0 0 Primary and Secondary DNS Servers 0 0 0 0 If your network has a requirement to use a different IP addressing scheme you can make those changes in this menu These settings are only required if the Use this IP address radio button is chosen Remember to click Apply to save your changes 3 12 Basic Installation and Configuration July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 e Spanning Tree Protocol Spanning Tree Protocol in enabled by default for the wireless access point This provides network traffic optimization in settings with multiple WG302 Access Points e Time Zone Select the time zone location for your setting Note You must have an Internet connection to get the current time Understanding Basic Wireless Settings To configure the wireless settings of your wireless access point click the Wireless Settings link in the Basic section of the main menu of the browser interface The Basic Wireless Settings menu will appear as shown below Wireless Se
14. B 5 for a full explanation of each of these options as defined by the IEEE 802 11 wireless communication standard 6 Click Apply to save your settings Note If you use a wireless computer to configure WEP settings you will be es disconnected when you click Apply Reconfigure your wireless adapter to match the new settings or access the wireless access point from a wired computer to make any further changes How to Configure WPA with Radius Note Not all wireless adapters support WPA Furthermore client software is required on the client Windows XP and Windows 2000 with Service Pack 3 do include the client software that supports WPA Nevertheless the wireless adapter hardware and driver must also support WPA Consult the product document for your wireless adapter and WPA client software for instructions on configuring WPA settings To configure WPA follow these steps 1 Log in at the default LAN address of http 192 168 0 228 with the default user name of admin and default password of password or using whatever LAN address and password you have set up 3 22 Basic Installation and Configuration July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 2 Click Radius Server Settings in the Security menu Radius Server Settings Authentication Access Control Radius Server Login Primary IP Address ob fb b n p Port Number fisiz Shared Secret E Secondary IP Address p
15. CONFIGURE LAN AND WIRELESS ACCESS Configure the WG302 Ethernet port for LAN access Name Connect to the WG302 by opening your browser and entering hitp 192 168 0 228 in the address field A login window like the one shown below opens z NETGEAR ProSafe Wireless Access Point W302 admin Password Figure 3 2 Login window in lower case letters When prompted enter admin for the user name and password for the password both July 2005 v3 0 Basic Installation and Configuration Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 e The Web browser will then display the WG302 settings page General Basic Settings Wireless Settings WEPANPA Settings Radius Server Settings Access Control Change Password Remote Management Upgrade Firmware BackupRestore Settings Reboot AP Activity Log Available Wireless Station List Statistics Rogue AP Detection IP Settings Hotspot Settings Wireless Settings Access Point Settings Knowledge Base Documentation Logout NETGEAR ProSafe Wireless Access Point 050 settings General Access Point Information Access Point Name netgear 4f35e MAC Address 00 09 5b 74 3 5e Country Region United States Firmware Version 4 1 2 Access Point Mode Access Point Current IP Settings IP Address 192 168 0 228 Subnet Mask 255 255 255 0 Default Gateway 0 0 0 0 DHCP Client Enable Current Wireless Setti
16. Chapter 3 Basic Installation and Configuration This chapter describes how to set up your NETGEAR ProSafe Wireless Access Point 802 11g WG302 for wireless connectivity to your LAN This basic configuration will enable computers with 802 11b or 802 11g wireless adapters to do such things as connect to the Internet or access printers and files on your LAN Note Indoors computers can connect over 802 11g wireless networks at ranges E of several hundred feet or more This distance can allow for others outside your area to access your network It is important to take appropriate steps to secure your network from unauthorized access The WG302 Access Point provides highly effective security features which are covered in detail in Understanding WEP WPA Security Options on page 3 15 Deploy the security features appropriate to your needs You need to prepare these three things before you can establish a connection through your wireless access point e A location for the WG302 that conforms to the Observing Placement and Range Guidelines below e The wireless access point connected to your LAN through a device such as a hub switch router or Cable DSL gateway e One or more computers with properly configured 802 11b or 802 11g wireless adapters Observing Placement and Range Guidelines The operating distance or range of your wireless connection can vary significantly based on the physical placement of the wireless acc
17. WEPIWPA Settings Wireless LAN Network Authentication Open System i Data Encryption None Passphrase Key 1 Key 2 Key 3 Key 4 Enable Wireless Client Security Separator No O Yes Figure 3 9 Wireless Security Settings The WEP WPA settings are explained as follows e Network Authentication Specifies the Authentication type used The default is Open System Select the desired option Open System If selected you have the option of using WEP encryption or no encryption Shared Key If selected you must use WEP at least one shared key must be entered Legacy 802 1x If selected you must configure the Radius Server Settings Screen WPA PSK If selected you must use TKIP encryption and enter the WPA passphrase Network key WPA with Radius If selected you must configure the Radius Server Settings Screen WPA2 PSK WPA2 is a later version of WPA Only select this if all clients support WPA2 If selected you must use AES encryption and enter the WPA passphrase Network key 3 16 Basic Installation and Configuration July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 WPA PSK and WPA2 PSK This selection allows clients to use either WPA with TKIP or WPA2 with AES If selected encryption must be TKIP AES The WPA passphrase Network key must also be entered WPA2 with Radius WPA2 is a later version of WPA Only select this
18. al Key Re Key can be done based on time interval in seconds or number of packets exchanged using the global key The default is 3600 seconds e Update if any station disassociates Check on this option to refresh global key when any stations disassociated with wireless Access Point e Accounting Radius Server Configuration This configuration is required for accounting using Radius Server IP Address Port No and Shared Secret is required for communication with Radius Server A Secondary Radius Server can be configured which is used on failure on Primary Radius Server e JP Address The IP address of the Radius Server The default is 0 0 0 0 Port Number Port number of the Radius Server The default is 1813 e Shared Secret This is shared between the Wireless Access Point and the Radius Server while authenticating the supplicant 4 Click Apply to save your settings 5 Click WEP WPA Settings in the Security menu Shared Key Passphrase Lega Key 1 q RER Ry ie with Radius Key 2 WPA PSK Key 3 WPA2 PSK yee WPA PSK amp WPA2 PSK Key 4 Enable Wireless Client Security Separator No Cyes Cancel Figure 3 13 Wireless Settings menu WEP WPA Settings Wireless LAN Network Authentication opan System z Data Encryption atom q we Radus D 3 24 July 2005 v3 0 Basic Installation and Configuration Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302
19. better if adjacent access points use different channels to reduce interference The recommended channel spacing between adjacent access points is 5 channels for example use channels 1 and 6 or 6 and 11 In Infrastructure mode wireless stations normally scan all channels looking for an access point If more than one access point can be used the one with the strongest signal is used This can only happen when the various access points are using the same SSID e Data Rate Shows the available transmit data rate of the wireless network 108 Mbps is only available when the operating mode is 802 11g only and the channel is 6 The default is Best e Output Power Set the transmit signal strength of the access point The options are full half quarter eighth and min Decrease the transmit power if more than one AP is colocated using the same channel frequency The default is Full Note Output power is automatically adjusted by AutoCell when the Auto RF Management option is enabled The default setting is for the AutoCell Auto RF Management option to be enabled Basic Installation and Configuration 3 15 July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 Understanding WEP WPA Security Options The table below identifies the various WEP WPA security options A full explanation of these standards is available in Appendix B Wireless Networking Basics
20. ccess Control Radius Server Configuration This configuration is required for authentication using Radius IP Address Port No and Shared Secret is required for communication with Radius Server A Secondary Radius Server can be configured which is used on failure on Primary Radius Server e IP Address The IP address of the Radius Server The default is 0 0 0 0 Port Number Port number of the Radius Server The default is 1812 e Shared Secret This is shared between the Wireless Access Point and the Radius Server while authenticating the supplicant e Re authentication Time The time interval in seconds after which the supplicant will be authenticated again with the Radius Server The default is 3600 seconds e Global key Re Key Time Check on this option to enable Re keying of Global Key The Global Key Re Key can be done based on time interval in seconds or number of packets exchanged using the global key The default is 3600 seconds e Update if any station disassociates Check on this option to refresh global key when any stations disassociated with wireless Access Point e Accounting Radius Server Configuration This configuration is required for accounting using Radius Server IP Address Port No and Shared Secret is required for communication with Radius Server A Secondary Radius Server can be configured which is used on failure on Primary Radius Server IP Address The IP address of the Radius Server The default is 0 0 0 0
21. eless Network Name SSID If you disable broadcast of the SSID only devices that have the correct SSID can connect This nullifies the wireless network discovery feature of some products such as Windows XP but the data is still fully exposed to a determined snoop using specialized test equipment like wireless sniffers e Use WEP Wired Equivalent Privacy WEP data encryption provides data security WEP Shared Key authentication and WEP data encryption will block all but the most determined eavesdropper 3 4 Basic Installation and Configuration July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 Use WPA WPA PSK WPA2 or WPA2 PSK Wi Fi Protected Access WPA and WPA2 data encryption provides data security The very strong authentication along with dynamic per frame rekeying of WPA make it virtually impossible to compromise Because this is a new standard wireless device driver and software availability may be limited Use AutoCell Enhanced RF Security Stealth Mode In addition to standard encryption and security mechanisms such as WEP and WPA the WG302 AutoCell feature provides self organizing micro cells for an additional level of privacy for enterprises In this mode AutoCell shrinks the size of coverage to the minimum to reach clients but also shrinks the size of the beacons that access points use to announce their presence This mode makes an enterprise wireless LAN nearly inv
22. ess Point 802 11g WG302 b Click the Wireless Settings link in the Setup section of the main menu to view the Wireless Settings menu Wireless Settings Country Region Select Wireless LAN M Turn Radio On Wireless Network Name SSID NETGEAR Broadcast Wireless Network Name SSID ves CNo Operating Mode Auto 11g 11b Channel Frequency 4 2 427C Data Rate Output Power Apply Cancel Figure 3 5 Basic Wireless Settings menu c Configure the wireless interface for wireless access See the online help or the Understanding Basic Wireless Settings topic of this Reference Manual for full instructions Note You must set the Regulatory Domain It may not be legal to operate the wireless access point in a region other than one of those identified in this field Now that you have finished the setup steps you are ready to deploy the WG302 in your network If needed you can now reconfigure the computer you used in step 1 back to its original TCP IP settings 3 DEPLOY THE WG302 ACCESS POINT a Disconnect the WG302 and position it where you will deploy it The best location is elevated such as wall mounted or on the top of a cubicle at the center of your wireless coverage area and within line of sight of all the mobile devices b Lift the antenna on either side so that they are vertical Note Consult the antenna positioning and wireless mode configuration information in the Advanced Configuration cha
23. ess point The latency data throughput performance and notebook power consumption of wireless adapters also vary depending on your configuration choices Basic Installation and Configuration 3 1 July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 Note Failure to follow these guidelines can result in significant performance C J degradation or inability to wirelessly connect to the WG302 For complete performance specifications see Appendix A Specifications For best results place your wireless access point e Near the center of the area in which your PCs will operate e Inan elevated location such as a high shelf where the wirelessly connected PCs have line of sight access even if through walls e Away from sources of interference such as PCs microwaves and 2 4 GHz cordless phones e Away from large metal surfaces e Putting the antenna in a vertical position provides best side to side coverage Putting the antenna in a horizontal position provides best up and down coverage e Ifusing multiple access points it is better if adjacent access points use different radio frequency Channels to reduce interference The recommended Channel spacing between adjacent access points is 5 Channels for example use Channels 1 and 6 or 6 and 11 The time it takes to establish a wireless connection can vary depending on both your security settings and placement WEP connections
24. eys directly These keys must match the other wireless stations Key 1 Key 2 Key 3 Key 4 If using WEP select the key to be used as the default key Data transmissions are always encrypted using the default key The other keys can only be used to decrypt received data WPA Passphrase Network Key If using WPA PSK enter the passphrase here All wireless stations must use the same passphrase network key The network key must be from 8 to 63 characters in length Wireless Client Security Separation If enabled the associated wireless clients will not be able to communicate with each other This feature is intended for hotspots and other public access situations The default is Disabled Basic Installation and Configuration 3 17 July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 Before You Change the SSID and WEP Settings For a new wireless network print this form and fill in the parameters For an existing wireless network get the settings from the person who set up or is responsible for the network Be sure to set the Regulatory Domain correctly as the first step Store this information in a safe place SSID The Service Set Identification SSID identifies the wireless local area network NETGEAR is the default WG302 SSID However you may customize it by using up to 32 alphanumeric characters Write your customized SSID on the line below SSID Note The SSID in the wireless
25. he Radius Server The default is 1812 e Shared Secret This is shared between the Wireless Access Point and the Radius Server while authenticating the supplicant e Re authentication Time The time interval in seconds after which the supplicant will be authenticated again with the Radius Server The default is 3600 seconds e Global key Re Key Time Check on this option to enable Re keying of Global Key The Global Key Re Key can be done based on time interval in seconds or number of packets exchanged using the global key The default is 3600 seconds e Update if any station disassociates Check on this option to refresh global key when any stations disassociated with wireless Access Point e Accounting Radius Server Configuration This configuration is required for accounting using Radius Server IP Address Port No and Shared Secret is required for communication with Radius Server A Secondary Radius Server can be configured which is used on failure on Primary Radius Server IP Address The IP address of the Radius Server The default is 0 0 0 0 Port Number Port number of the Radius Server The default is 1813 e Shared Secret This is shared between the Wireless Access Point and the Radius Server while authenticating the supplicant 4 Click Apply to save your settings Basic Installation and Configuration 3 31 July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 5 Click WEP
26. ings appropriate to your needs 1 Log in to the WG302 using its default address of hitp 192 168 0 228 or at whatever IP address the unit is currently configured Use the default user name of admin and default password of password or whatever password you set up Click the Wireless Settings link in the main menu of the WG302 Choose a suitable descriptive name for the wireless network name SSID In the SSID box enter a value of up to 32 alphanumeric characters The default SSID is NETGEAR Note The SSID of any wireless access adapters must match the SSID you configure in the NETGEAR ProSafe Wireless Access Point 802 11g WG302 If they do not match you will not get a wireless connection to the WG302 Select the Country Region in which the wireless interface will operate Set the Channel It should not be necessary to change the wireless channel unless you notice interference problems or are near another wireless access point Select a channel that is not being used by any other wireless networks within several hundred feet of your wireless access point For more information on the wireless channel frequencies see Wireless Channels on page B 7 For initial configuration and testing leave the Wireless Card Access List set to Everyone and the Encryption Strength set to Disabled Click Apply to save your changes A SSID channel or security settings you will lose your wireless connection when you Note
27. isible to users outside an office building AutoCell clients such as the NETGEAR WAGS11 are highly recommended for Enhanced RF Security Installing the WG302 Access Point Before installing the NETGEAR ProSafe Wireless Access Point 802 11g WG302 you should make sure that your Ethernet network is up and working You will be connecting the access point to the Ethernet network so that computers with 802 11b or 802 11g wireless adapters will be able to communicate with computers on the Ethernet network In order for this to work correctly verify that you have met all of the system requirements shown on page 2 5 1 SET UP THE WG302 ACCESS POINT Tip Before mounting the WG302 in a high location first set up and test the WG302 to verify wireless network connectivity a Prepare a computer with an Ethernet adapter If this computer is already part of your network record its TCP IP configuration settings b Configure the computer with a static IP address of 192 168 0 210 and 255 255 255 0 for the Subnet Mask c Connect an Ethernet cable from the WG302 to the computer d Turn on your computer connect the power adapter to the WG302 and verify the following The PWR power light goes on The LAN light of the wireless access point is lit when connected to a powered on computer Basic Installation and Configuration 3 5 July 2005 v3 0 3 6 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 a 2
28. n and Configuration July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 2 Click WEP WPA Settings in the Security menu of the WG302 WEPAWPA Settings Wireless LAN Network Authentication Open System gt Data Enc ion mi _ Shared Key Passphrase Legacy 802 1 WPA with Radius WPA2 with Radius WPA amp WPA2 with Radius WPA PSK WPA PSK WPA PSK amp WPA2 PSK D Open System Enable Wireless Client Security Separator No Cyes Cancel Figure 3 20 WEP WPA Settings menu 3 Choose WPA PSK and WPA2 PSK from the list 4 Enter the pre shared key passphrase 5 Click Apply to save your settings Basic Installation and Configuration 3 33 July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 3 34 Basic Installation and Configuration July 2005 v3 0
29. n at the default LAN address of http 192 168 0 229 with the default user name of admin and default password of password or using whatever LAN address and password you have set up 2 Click Radius Server Settings in the Security menu Radius Server Settings Authentication Access Control Radius Server Login Primary IP Address b e p Port Number jis12 Shared Secret E Secondary IP Address o l e e e Port Number s12 Shared Secret OCS Reauthentication Time E 600 Seconds I Global Key Update C every 3600 Seconds C every fiooo x1000 Packets I Update if any station disassociates Accounting Radius Server Login Primary IP Address fo fo fo fo PortNumber 1813 _ Shared Secret Secondary IP Address fo k fo fo k p PortNumber 1613 _ Shared Secret sz Cancel Figure 3 18 Radius Server Settings menu 3 30 July 2005 v3 0 Basic Installation and Configuration Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 3 Enter the Radius settings e Authentication Access Control Radius Server Configuration This configuration is required for authentication using Radius IP Address Port No and Shared Secret is required for communication with Radius Server A Secondary Radius Server can be configured which is used on failure on Primary Radius Server e IP Address The IP address of the Radius Server The default is 0 0 0 0 Port Number Port number of t
30. ne GMT Time Zone Adjust for Daylight Saving Time Disabled SNMP Enabled but Trap forwarding is disabled Secure Telnet Enabled SugerG Mode Disabled WMM Mode Disabled Basic Installation and Configuration 3 3 July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 Understanding WG302 Wireless Security Options Your wireless data transmissions can be received well beyond your walls by anyone with a compatible adapter For this reason use the security features of your wireless equipment The WG302 Access Point provides highly effective security features which are covered in detail in this chapter Deploy the security features appropriate to your needs Wireless Data Security Options Range Up to 500 Foot Radius MMMM a 1 No Security Easy but no security 1 Me 2 MAC Access List No data security 3 WEP Security but vulnerable 4 WPA or WPA PSK Very strong security 5 AutoCell RF stealth mode Figure 3 1 WG302 wireless data security options There are several ways you can enhance the security of your wireless network e Restrict Access Based on MAC address You can restrict access to only trusted PCs so that unknown PCs cannot wirelessly connect to the WG302 MAC address filtering adds an obstacle against unwanted access to your network but the data broadcast over the wireless link is fully exposed e Turn Off the Broadcast of the Wir
31. ngs Operating Mode Auto 1 1g 11b Wireless Network Name SSID NETGEAR Channel Frequency 6 2 442GHz WEP WPA Disable AutoCell Enable Rogue AP Detection Disable Figure 3 3 Login result WG302 home page Basic Installation and Configuration 3 7 July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 When the wireless access point is connected to the Internet click the Knowledge Base or the Documentation link under the Web Support menu to view support information or the documentation for the wireless access point Ifyou do not click Logout the wireless access point will wait 5 minutes after there is no activity before it automatically logs you out e Click the Basic Settings link to view the Basic Settings menu Basic Settings Access Point Name netgear 4F35E IP Address DHCP Client OEnable Disable IP Address 192 Jiss Jo 228 IP Subnet Mask 255 2ss 25s o Default Gateway o lo b lo Secondary DNS Server o o a Jo Primary DNS Server jo jjo jjo Spanning Tree Protocol Enable Disable Time Zone GMT 08 00 Pacific Time US amp Canada Tijuana vi Cl Adjust for Daylight Saving Time Current Time Fri Dec 31 21 58 09 1999 Figure 3 4 Basic Settings menu e Configure the settings appropriate for your network 3 8 Basic Installation and Configuration July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Acc
32. of the WG302 WEP WPA Settings Wireless LAN Network Authentication l Open System gt Data Encryption Open System Shared Key Passphrase Legacy 802 1 WPA with Radius WPA2 with Radius WPA amp WPA2 with Radius Key1 Key 2 WPA PSK FiWPAZPSK D WrATORE WrACroR Key 4 Enable Wireless Client Security Separator No Yes Cancel Figure 3 17 WEP WPA Settings menu 3 Choose WPA2 PSK from the list 4 Enter the pre shared key passphrase 5 Click Apply to save your settings How to Configure WPA and WPA2 with Radius Note Not all wireless adapters support WPA Furthermore client software is required on the client Windows XP and Windows 2000 with Service Pack 3 do include the client software that supports WPA Nevertheless the wireless adapter hardware and driver must also support WPA Consult the product document for your wireless adapter and WPA client software for instructions on configuring WPA settings Note Not all wireless adapters support WPA2 Furthermore client software is required on the client Make sure your client card supports WPA2 Consult the product document for your wireless adapter and WPA2 client software for instructions on configuring WPA2 settings Basic Installation and Configuration 3 29 July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 To configure WPA and WPA2 follow these steps 1 Log i
33. pter of the Reference Manual c Connect an Ethernet cable from your WG302 Access Point to a LAN port on your router switch or hub Basic Installation and Configuration 3 9 July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 Note By default WG302 is set to with the DHCP client disabled If your network uses dynamic IP addresses you will need to change this setting d Connect the power adapter to the wireless access point and plug the power adapter in to a power outlet The PWR LAN and Wireless LAN lights and should light up 4 VERIFY WIRELESS CONNECTIVITY Using a computer with an 802 11b or 802 11g wireless adapter with the correct wireless settings needed to connect to the WG302 SSID WEP WPA MAC ACL etc verify connectivity by using a browser such as Netscape or Internet Explorer to browse the Internet or check for file and printer access on your network Note If you are unable to connect see Chapter 6 Troubleshooting 3 10 Basic Installation and Configuration July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 How to Log In to the WG302 Using Its Default IP Address 1 192 168 0 228 is the default IP address of your access point The WG302 is set by default with the DHCP client disabled Note The computer you are using to connect to the WG302 should be configured with an IP address that starts with 192
34. re WEP To configure WEP data encryption follow these steps 1 Log in to the WG302 using its default address of hitp 192 168 0 228 or at whatever IP address the unit is currently configured Use the default user name of admin and default password of password or whatever LAN address and password you have set up 2 Click the WEP WPA Settings link in the main menu of the WG302 WEP WPA Settings Wireless LAN Network Authentication Open System z Data Encryption Ope Passphrase Key 1 WPA amp WPA2 with Radius Key 2 WPA PSK Cie WPA2 PSK ye WPA PSK amp WPA2 PSK Key 4 Enable Wireless Client Security Separator No Yes Cancel Figure 3 11 Wireless Settings menu 3 Choose Open System or Shared Key authentication Basic Installation and Configuration 3 21 July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 4 Select encryption strength 5 You can manually or automatically program the four data encryption keys These values must be identical on all PCs and Access Points in your network e Automatic enter a word or group of printable characters in the Passphrase box and click the Generate button The four key boxes will be automatically populated with key values e Manual enter ten hexadecimal digits any combination of 0 9 a f or A F Select which of the four keys will be the default See Overview of WEP Parameters on page
35. t 802 11g WG302 How to Configure WPA2 with Radius Note Not all wireless adapters support WPA2 Furthermore client software is required on the client Make sure your client card supports WPA2 Consult the product document for your wireless adapter and WPA2 client software for instructions on configuring WPA2 settings To configure WPA2 follow these steps Log in at the default LAN address of http 192 168 0 229 with the default user name of admin and default password of password or using whatever LAN address and password you 1 have set up Radius Server Settings Click Radius Server Settings in the Security menu Authentication Access Control Radius Server Login Primary IP Address bl b e e Port Number fisiz Shared Secret f Secondary IP Address fo fo fo fo Port Number fisiz Shared Secret ti i C O Y Reauthentication Time jso Seconds I Global Key Update C every 3600 Seconds C every fioo x1000 Packets I Update if any station disassociates Accounting Radius Server Login Primary IP Address Port Number Shared Secret Secondary IP Address Port Number Shared Secret Po Po Po eo 1813 I B eo Po BO 1813 w ao Cancel Figure 3 15 Radius Server Settings menu 3 26 July 2005 v3 0 Basic Installation and Configuration Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 3 Enter the Radius settings e Authentication A
36. ttings Country Region Select H Wireless LAN M Turn Radio On Wireless Network Name SSID NETGEAR Broadcast Wireless Network Name SSID ves CNo Operating Mode Auto 11g 11b E Channel Frequency 27G 4 Data Rate Bet H Output Power Fa z Apply Cancel Figure 3 8 Basic Wireless Settings menu The Basic Wireless Settings menu options are discussed below e Country Region This field identifies the region where the WG302 can be used It may not be legal to operate the wireless features of the wireless access point in a region other than one of those identified in this field There is no default country domain and the channel is set to 11 Unless a country domain is selected the channel cannot be changed Basic Installation and Configuration 3 13 July 2005 v3 0 Reference Manual for the NETGEAR ProSafe Wireless Access Point 802 11g WG302 e Turn Radio On On by default you can also turn off the radio to disable access through this device This can be helpful for configuration network tuning or troubleshooting activities e Wireless Network Name SSID The SSID is also known as the wireless network name Enter a value of up to 32 alphanumeric characters In a setting where there is more than one wireless network different wireless network names provide a means for separating the traffic Any device you want to participate in a particular wireless network will need to use the SSID The WG302 default SSID
Download Pdf Manuals
Related Search
Related Contents
ASUS P4B533-X User's Manual Samsung Galaxy Xcover 3 Manuel de l'utilisateur VPC3+C User Manual Revision 1.04 TriScrollTM Série 300 Pompe sèche de vide de rouleau Copyright © All rights reserved.
Failed to retrieve file