background image

 

 

V3.0 

 

Private IP Address: 

Enter corresponding IP address for internal. 

 

Private Port:

 Enter internal service port No. for private. 

 

Schedule :

 Administrator can select to used rule of 

“Time Policy”

 

 

Click 

“Save” 

button to save your set function. Then click “Reboot” button to activate your 

changes.

 

 
 

5.5.5

 

Access Control 

The Access Control function administrator can to block or allow specific kinds of TCP/UDP/ICMP 
protocol, such as Internet access, designated services, and websites. The Access Control function 
can set 20 profiles. 
Please click on 

Advance -> Access Control

 and follow the below setting. 

 

 

#

Display access control list. 

 

Active

Display Active or InActive for the access control rule. 

 

Comment: 

Display information for the rule.

 

 

Protocol

Display information for the protocol.

 

 

Edit

Administrator can click the button to set

 

Access Control rule.

 

Summary of Contents for OW-200 A1

Page 1: ...V3 0 CERIO Corporation CenOS 5 0 User Manual for OW 200 A1 OW 218 A1...

Page 2: ...AP Mode 14 CAP mode Centralizes Access Point 15 2 System Configuration 16 2 1 Management 16 2 2 Configure Time Server 19 2 3 SNMP 21 2 4 Configure Time Policy 22 3 Access Point mode 24 3 1 VLAN Setup...

Page 3: ...Walled Garden 48 Privilege Address 48 Profile 49 3 3 RADIUS Server 50 3 4 RADIUS Account Setup 50 3 5 Wireless Configuration 51 3 5 1 Radio 0 Basic Setup 51 3 5 2 Advanced Setup 53 3 5 3 WMM Setup 55...

Page 4: ...nfigure DHCP Server 79 5 4 Wireless General Setup 81 5 4 1 Radio 0 Basic Setup 82 5 4 2 Advanced Setup 84 5 4 3 WMM Setup 86 5 4 4 Station Setup 89 5 4 5 Repeater AP Setup 90 5 4 6 MAC Filter Setup 92...

Page 5: ...2 6 Authentication Profile 110 6 2 7 Status 110 7 Utilities 111 7 1 Profile Setting 111 7 2 System Upgrade 112 7 3 Network Utility 114 7 4 Reboot 114 8 Status 115 8 1 Overview 115 8 2 Wireless Client...

Page 6: ...1 Radio 0 Basic Setup 2 The device don t add the hardware return factory value button if software want to reset to default then must use RJ 45 reset function kit Accessories under working of the devic...

Page 7: ...f AP Please PC link to Device used cat5 6 Ethernet cable The following setup uses a Windows PC user OS may vary Step 1 Please click on the computer icon in the bottom right window and click Open Netwo...

Page 8: ...ck left side Ethernet function click on the right side Change adapter options again Step 3 In Change adapter options Page Please find Ethernet Local LAN and Click the right button on the mouse and Cli...

Page 9: ...Internet Protocol Version 4 TCP IPv4 and double click or click OK button Step 5 Select Use the following IP address and fix in IP Address 192 168 2 ex The is any number by 1 to 253 Subnet mask 255 255...

Page 10: ...Launch as web browser to access the web management interface of system by entering the default IP Address http 192 168 2 254 in the URL field and then press Enter System Login Default login Username i...

Page 11: ...Point It allow wireless clients or Stations STA to access Supports DHCP Service allowing for automated assigning of IP addresses to clients connecting to the network WDS Setup includes AES Advanced E...

Page 12: ...V3 0 Client Bridge Repeater Mode Please click on System Mode Setup and choose Client Bridge Mode...

Page 13: ...and Internet service to new residential and business customers In this mode the AP is enabled with DHCP Server functions The wired clients of the AP are in the same subnet from Main Base Station and i...

Page 14: ...ile application helping WISPs deliver wireless broadband Internet service to residents and business customers In the WISP CPE mode the CenOS 5 0 AP is a gateway enabled with NAT and DHCP Server functi...

Page 15: ...nt Please click on System Mode Setup and choose CAP Mode Control Management of CenOS5 0 APs AP Management support 802 1Q VLAN infrastructure Centralized setting Access Point function and firmware upgr...

Page 16: ...s in this page and modify system login password and select use system login protocol by 80 443 23 22 Port The management page adds LED control on off and system auto reboot function There are common f...

Page 17: ...rval of time Delay After system start the set time value starts execution Ping watchdog Times of faults After the error exceeds the set value system will auto reboot Login Methods Administrator can se...

Page 18: ...red client network basis on VLAN0 When disable this function system can use 8 VLAN and 8 ESSID Auto Reboot The functions can Auto reboot the system by Date time management Daily Setting time to system...

Page 19: ...tor can select manual or via a NTP server to modify system time for the right local time If select update the system time for manual when administrator reboot system the system time will reply default...

Page 20: ...rver Administrator can select NTP Server NTP Server Administrator can setting as NTP Server Time Zone Administrator can select a desired time zone from the drop down list Daylight saving Time Enable o...

Page 21: ...username Set a community string to authorize read only access Ro password Set a password to authorize read only access RW username Set a community string to authorize read write access RW password Se...

Page 22: ...ct Enable or Disable the service Community Set a community string required by the remote host computer that will receive trap messages or notices send by the system IP 1 4 Enter the IP addresses of th...

Page 23: ...dule or Out of schedule to execution the rules Create New Policy button Administrator can set time for week start time and end time Click Save button to add schedule to policy There are 10 schedule ma...

Page 24: ...y master VLAN and VLAN Tag No information IP Address Display IP Address for VLAN Network NetMask Display IP netmask Radio 0 Display radio 5G SSID name Action The button can set VLAN network functions...

Page 25: ...or Disable 5G Radio 802 1d Spanning Tree The spanning tree network protocol provides a loop free topology for a bridged LAN between LAN interface and 8 WDS interfaces from wds0 to wds7 The Spanning T...

Page 26: ...ty for the access point and set 802 11r fast roaming Please click pull down button 3 1 1 DHCP Server Administrator can select enable disable the function Start IP Set Start IP for DHCP Service End IP...

Page 27: ...introduce potential conflicts Lowering the lease time will avoid potential address conflicts but might cause more interruptions to the client while it will acquire new IP addresses from the DHCP serv...

Page 28: ...t bandwidth limit by IP MASK IP Range Port Service SIP RTP RTSP WEB protocol each VLAN can set 10 bandwidth management rule Click Save button to save your changes Then click Reboot button to activate...

Page 29: ...select Enable or Disable WiFi connection Limit User Limit If select enable of the connection Limit function administrator can set users connection limit Recommended limit 60 Wi Fi Users Security Type...

Page 30: ...et of reverse rounds are applied to transform ciphertext back into the original plaintext using the same encryption key TKIP is short for Temporal Key Integrity Protocol TKIP scrambles the keys using...

Page 31: ...ion RADIUS server Support 1 to 64 characters After the above function is setup please click Save button and reboot system will apply new profile and working normally 3 1 4 MAC Filter 1 Only Deny List...

Page 32: ...aged MAC address list Click Save button to save your changes Then click Reboot button to activate your changes 3 1 5 802 11r Fast Roaming Setup The dual band Access Point supports 802 11r 802 11k func...

Page 33: ...g IEEE 802 11r nas_identifier must be set and must be between 1 and 48 octets long R1 Identifier PMK R1 Key Holder identifier 6 octet identifier as a hex string R1 Push Administrator can select Enable...

Page 34: ...apply new profile and working normally 3 2 Authentication This function used to operate in Access Point mode the function is for Web Authentication It supports authentication for local users RADIUS Se...

Page 35: ...administrator can enable or disable this function Authentication Administrator can enable or disable authentication function Multiple Login Administrator can set one account to multiple users simulta...

Page 36: ...unction Account session log will copy to syslog server Local User Administrator can enable authentication for local user Create user account can to reference 3 2 2 Local User setup RADIUS Authenticati...

Page 37: ...n set guest Count Limit login time and type and flow control Service Administrator can select enable or disable this function Login Type One Time Login to start counting until the end of time Multiple...

Page 38: ...User Name Administrator can create users account Password Set account password OAuth2 0 The OAuth2 0 function supports Facebook and Google by default Users can add additional OAuth2 0 servers through...

Page 39: ...website to receive an account ID and password follow the steps below Step 1 Please go to the Google Developers Console page and create a project Reference https developers google com identity protocol...

Page 40: ...horized redirect URLs important Administrator must set login URL in the device function After complete set of login URL go to the Restrictions function in web page Follow the steps below to set login...

Page 41: ...is http domain0 login com same as Login URL Google Authorized redirect URLs is http domain0 login com login index cgi cgi CALLBACK Step 5 After completing the Restrictions setup click the create butto...

Page 42: ...plete the application on the Facebook website to receive an account ID and password follow the steps below Step 1 Please to Facebook developer s page and add a New App Step 2 Select WWW function Step...

Page 43: ...ndex cgi cgi CALLBACK Administrator must set login URL in the device function After complete set of login URL go to the Facebook Site URL function in web page Follow the steps below to set login URLs...

Page 44: ...m display into the Site URL page on the Facebook website Step 7 Click Advanced function to enable the Native or desktop app and Is App Secret embedded in the client Step 8 After completing the Faceboo...

Page 45: ...se Enable or Disable the PoP3 authentication Display Name Set the Display Name based on the appropriate POP3 user or client Client ID and Client Secret setup by third parties such as Facebook and Goog...

Page 46: ...or None POP3 Server Test Use this tool to test if the POP3 server is operating correctly with your selected email Customize Page This function is to customize the user Login Page This supports Multip...

Page 47: ...ng sample login page html code templates are available on Cerio website The following function uses the enabled Template Multiple Language Administrator can select enable or disable multiple language...

Page 48: ...n and authentication User without the network access right can still have a chance to experience the actual network service free of charge in Walled Garden URL list Display Name Set name of Website IP...

Page 49: ...ers PC After the above function is setup please click Save button and reboot system will apply new profile and working normally Profile Administrator can backup current authentication configuration an...

Page 50: ...erver use Key Click Save button to save your changes Then click Reboot button to activate your changes 3 4 RADIUS Account Setup When enabled RADIUS Server administrator can add RADIUS account and pass...

Page 51: ...unt list in RADIUS Server Import From PC Administrator can import account list to the RADIUS Server Click Save button to save your set function Then click Reboot button to activate your changes 3 5 Wi...

Page 52: ...below Channel Bandwidth The 20 40 and 802 11ac 80 MHz option is usually the best The other option is available for special circumstances Shout GI Short Guard Interval is Enabled by default to increase...

Page 53: ...available access points may miss the beacons You can decrease the beacon interval which increases the rate of beacons This will make the association and roaming process very responsive however the ne...

Page 54: ...rmal environment supports non jumbo frames Short Preamble By default this function is Enabled Disabling will automatically use the Long 128 bit Preamble Synchronization field The preamble is used to s...

Page 55: ...ts of the media being sent Queues automatically provide minimum transmission delay for Voice Video multimedia and mission critical applications and rely on best effort parameters for traditional IP da...

Page 56: ...tion Window size is reached Once the Maximum Contention Window size is reached retries will continue until a maximum number of retries allowed is reached Valid values for the cwmax are 1 3 7 15 31 63...

Page 57: ...is used the recipient acknowledges each received uncast packet Click Save button to save your set function Then click Reboot button to activate your changes 3 5 4 WDS Setup Please click on Wireless WD...

Page 58: ...g VALN Click Save button to save your set function Then click Reboot button to activate your changes 3 5 5 WDS Status Displays 5G radio WDS link status through MAC and Date TX RX Please click on Wirel...

Page 59: ...Mode and Repeater AP function with help of illustrations 4 1 Configure LAN Setup Here are the instructions for how to setup the local IP Address and Netmask Please click on System LAN and follow the...

Page 60: ...to as STP is defined in the IEEE Standard 802 1d DHCP Forward When the AP Mode device and Client Bridge AP are linked and DHCP Service is Enabled the Client Bridge AP must also enable DHCP Forward to...

Page 61: ...this is optional WINS IP Enter IP address of the Windows Internet Name Service WINS server this is optional Domain Enter the domain name for this network Lease Time The IP addresses given out by the...

Page 62: ...button Static Lease IP Setup Administrator can set as static IP address for users Comment Enter description for the information IP Address Set static IP address for users MAC Address Set MAC address...

Page 63: ...and Taiwan Band Mode If Client Bridge want to use 5G link to Access Point then administrator can enable the function radio 1 Auto Channel Administrator can Enable or Disable the function If select dis...

Page 64: ...uency reflections Select the option that works best for your installation Aggregation By default it s Enable To Disable to deactivated Aggregation A part of the 802 11n standard or draft standard It a...

Page 65: ...available access points may miss the beacons You can decrease the beacon interval which increases the rate of beacons This will make the association and roaming process very responsive however the ne...

Page 66: ...old value By default RTS is disabled in a normal environment supports non jumbo frames Short Preamble By default it s Enable To Disable is to use Long 128 bit Preamble Synchronization field The preamb...

Page 67: ...he transmission of packets in each queue based on the requirements of the media being sent Queues automatically provide minimum transmission delay for Voice Video multimedia and mission critical appli...

Page 68: ...doubling of the random backoff value This doubling continues until either the data frame is sent or the Maximum Contention Window size is reached Once the Maximum Contention Window size is reached re...

Page 69: ...icy is used the recipient acknowledges each received uncast packet Click Save button to save your set function Then click Reboot button to activate your changes 4 3 4 Station Setup The functions setti...

Page 70: ...tor can limit Wi Fi users the Quantity Authentication Select the desired security type from the drop down list the options are WPA PSK WPA2 PSK WPA WPA2 Enterprise and WEP 802 1X Open System Data are...

Page 71: ...he encryption key A set of reverse rounds are applied to transform ciphertext back into the original plaintext using the same encryption key TKIP is short for Temporal Key Integrity Protocol TKIP scra...

Page 72: ...ess Point while the access will be denied for all the remaining clients Action Type is set to Only Allow List MAC Only Deny List MAC Define certain wireless clients in the list which will have denied...

Page 73: ...000 administrator can setting 1 65535 Reassoc deadline Reassociation deadline in time units TUs 1 024 ms range 1000 65535 The default is 1000 R0 NAS Identifier PMK R0 Key Holder identifier When using...

Page 74: ...ion will appear in list R1 Key Holder List Enter a unified set of R1 Key Holder identification certification MAC Address Enter the main roaming device MAC address R1 Identifier Enter Shared identifier...

Page 75: ...for correct wireless settings to associate with WISP AP before a dynamic IP along with related IP settings If IP Address is not assigned please double check with your wireless settings and ensure succ...

Page 76: ...for Maximum Transmission Unit Consult with WISP for a correct MTU setting Reconnect Mode Administrator can select three function for Always On On Demand Manual Always on A connection to Internet is al...

Page 77: ...MTU setting MPPE40 128 Microsoft Point to Point Encryption MPPE encrypts data in Point to Point Protocol PPP based dial up connections or Point to Point Tunneling Protocol PPTP virtual private networ...

Page 78: ...clone MAC from a PC Default MAC Address Keep the default MAC address of WAN port on the system Manual MAN Address Enter the MAC address registered with your ISP DNS Check No Default DNS Server or Spe...

Page 79: ...802 1d Spanning Tree The spanning tree network protocol provides a loop free topology for a bridged LAN between LAN interface and 8 WDS interfaces from wds0 to wds7 The Spanning Tree Protocol which is...

Page 80: ...DHCP server will only be valid for the duration specified by the lease time Increasing the time ensure client operation without interruptions but could introduce potential conflicts Lowering the leas...

Page 81: ...ers list of static IP address Click Save button to save your set function Then click Reboot button to activate your changes 5 4 Wireless General Setup The main setup Client Bridge connection to AP Sta...

Page 82: ...dministrator can select 5G Band for 802 11a n or 802 11ac The default is 802 11ac Auto Channel Administrator can Enable or Disable the function If select disable function the WiFi channel can be fixed...

Page 83: ...lections Select the option that works best for your installation Aggregation By default it s Enable To Disable to deactivated Aggregation A part of the 802 11n standard or draft standard It allows sen...

Page 84: ...available access points may miss the beacons You can decrease the beacon interval which increases the rate of beacons This will make the association and roaming process very responsive however the ne...

Page 85: ...old value By default RTS is disabled in a normal environment supports non jumbo frames Short Preamble By default it s Enable To Disable is to use Long 128 bit Preamble Synchronization field The preamb...

Page 86: ...he transmission of packets in each queue based on the requirements of the media being sent Queues automatically provide minimum transmission delay for Voice Video multimedia and mission critical appli...

Page 87: ...time window for retry of a transmission The value specified here in the Minimum Contention Window is the upper limit in milliseconds of a range from which the initial random backoff wait time is deter...

Page 88: ...wledgment Policy WMM defines two ACK policies Normal ACK and No ACK Click Checkbox indicates No ACK When the no acknowledgement No ACK policy is used the recipient does not acknowledge received packet...

Page 89: ...survey button Security After site survey AP station complete will list all AP station when click AP station setup button then AP station information ESSID Security type will display on page PassPhras...

Page 90: ...tor can limit Wi Fi users the Quantity Authentication Select the desired security type from the drop down list the options are WPA PSK WPA2 PSK WPA WPA2 Enterprise and WEP 802 1X Open System Data are...

Page 91: ...he encryption key A set of reverse rounds are applied to transform ciphertext back into the original plaintext using the same encryption key TKIP is short for Temporal Key Integrity Protocol TKIP scra...

Page 92: ...ess Point while the access will be denied for all the remaining clients Action Type is set to Only Allow List MAC Only Deny List MAC Define certain wireless clients in the list which will have denied...

Page 93: ...000 administrator can setting 1 65535 Reassoc deadline Reassociation deadline in time units TUs 1 024 ms range 1000 65535 The default is 1000 R0 NAS Identifier PMK R0 Key Holder identifier When using...

Page 94: ...ion will appear in list R1 Key Holder List Enter a unified set of R1 Key Holder identification certification MAC Address Enter the main roaming device MAC address R1 Identifier Enter Shared identifier...

Page 95: ...nce over the DMZ rule In order to use a range of ports available to access to different internal hosts Virtual Server rules are needed Automatic Assignment Enter Internal IP address of DMZ host and on...

Page 96: ...an select Enable or Disable the service Comment Enter the description of IP filter rule Policy Administrator can select the IP flow rule of Deny or Pass In Out Administrator can select the IP flow rul...

Page 97: ...r Allow Deny The MAC Filter List will be denied to access LAN to WAN Others will be allowed Allow The MAC Filter List will be allowed to access LAN to WAN Others will be denied Comment Enter the descr...

Page 98: ...nt to assign ports 21 25 to one FTP Telnet and SMTP server A in the example and port 80 to another B in the example You assign the LAN IP addresses and the ISP assigns the WAN IP address The NAT netwo...

Page 99: ...Control function administrator can to block or allow specific kinds of TCP UDP ICMP protocol such as Internet access designated services and websites The Access Control function can set 20 profiles P...

Page 100: ...al IP IP range go to destination IP IP range and use protocol TCP Deny TCP Protocol Administrator can set TCP protocol and assign IP IP range UDP Deny UDP Protocol Administrator can set UDP protocol a...

Page 101: ...of LAN or VLAN IP Address Gateway DNS and Ethernet Tag etc Please click on System VLAN Setup Display VLAN No VLAN Mode Display on off line status for the VLAN mode IP Address Display IP address for th...

Page 102: ...Tag Administrator can set Tag ID for the Ethernet port Set Gateway DNS address functions Gateway The default Gateway IP Address is 192 168 2 1 Please check your Gateway IP and change DNS Check either...

Page 103: ...managed APs function administrator must reboot all managed APs 6 2 1 Scan Device This management page can discover all managed APs in the network Administrator can set IP address Password and VLAN tag...

Page 104: ...managed APs When the setting managed APs is completed please click Apply Reboot button to complete the setup process 6 2 2 Batch Setup The AP control function supports centralized configuration of man...

Page 105: ...enable or disable 2 4G radio of the managed APs Access Point1 Administrator can enable or disable 5G radio of the managed APs 802 1d Spanning Tree Administrator can enable or disable the function ple...

Page 106: ...stem login port and system log server service for managed APs Please refer to 2 1 system management Wireless Batch Setup Setting Wi Fi configurations for managed APs Please refer to 3 5 1 Wireless Bas...

Page 107: ...login passwords and web login port for managed APs If administrator has change AP devices administrator can modify MAC address of the new managed AP 6 2 4 Group Setup Administrator can create Groups...

Page 108: ...e New Map Click the button to create map Map Name Enter map name Image URL Paste Map image url Description Enter the description for the map After the Map URL setup confirmation please reboot the syst...

Page 109: ...V3 0 View Once complete administrators can click the View button to monitor AP statuses and locations...

Page 110: ...le or Disable authentication function For more details refer to 3 2 1 Authentication Click Dropdown to set authentication functions Refer to 3 2 2 Authentication dropdown functions Action The button c...

Page 111: ...or reboot system 7 1 Profile Setting This Functions purpose is to backup current configuration restore prior configuration or reset back to factory default configurations Please click on Utilities Pro...

Page 112: ...ot button to activate 7 2 System Upgrade Firmware is the main software image that system needs to respond to requests and to manage real time operations Firmware upgrades are sometimes required to inc...

Page 113: ...FTP Server The upgrade firmware will support via local PC and TFTP Server and HTTP URL to upgrade system 1 To prevent data loss during firmware upgrade please back up current settings before proceedin...

Page 114: ...ill be shown in the Result field Count By default its 5 and the range is from 1 to 50 It indicates number of connectivity test Traceroute Allows tracing the hops from the CenOS 5 0 AP device to a sele...

Page 115: ...iled information on System Network can be reviewed via this page The status mainly displays system related information including system network information wireless base station information and wirele...

Page 116: ...and account type for the authentication account This page only used AP mode VLAN Display VLAN number Authentication Display Captive Portal authentication function is on off in the VLANs Users Count D...

Page 117: ...tor can select dates VLAN Administrator can select VLANs Detall Administrator can clicl button to open detall information 8 5 System Log The system log displays system events when system is up and run...

Page 118: ...etmask 128 0 0 0 255 255 255 252 IP Gateway IP Format 1 254 Primary DNS IP Format 1 254 Secondary DNS IP Format 1 254 Hostname Length 32 0 9 A Z a z _ DHCP Server Start IP IP Format 1 254 End IP IP Fo...

Page 119: ...ity Length 32 0 9 A Z a z _ RO RW user Length 31 0 9 A Z a z _ RO RW password Length 8 32 0 9 A Z a z _ Community Length 32 0 9 A Z a z _ IP IP Format 1 254 General Setup Tx Power 1 100 Wireless Profi...

Page 120: ...us Server IP IP Format 1 254 Radius Port 1 65535 Shared Secret 8 64 characters Session Timeout 60 seconds 0 is disable WDS Setup AES Key 8 63 ASCII chars 64 HEX chars Peer s MAC Address 12 HEX chars D...

Reviews: