background image

|

  

Auto-configuration

69

|

 devolo dLAN 200 DSpro Manual 

|

12.13.1

RADIUS Client 

The RADIUS client implemented in the Wisconsin nodes is configured through 
the autoconfiguration file with three parameters: 

RADIUS server IP address 

RADIUS server UDP port 

Shared secret password between client and server 

It also sends two RADIUS standard attributes within a RADIUS request: 

MAC address of the slave trying to join the network as 

User name

MAC address of the master as 

NAS-Identifier

12.13.2

RADIUS Server 

12.13.2.1 Installing Freeradius Server (v0.8.1) 

Any RADIUS server is suitable to work with the Wisconsin RADIUS clients.  The 
following is an example with the Linux freeradius server. 

Extract the freeradius tar file, compile, and install the RADIUS server: 

tar zxvf freeradius 0.8.1.tar.gz

cd freeradius 0.8.1

./configure

make

make install

The configuration RADIUS files are then installed in /usr/local/etc/raddb/ and the 
log file can be seen in /usr/local/var/log/radius/radius.log. 

IMPORTANT: Each time a configuration file is changed, the RADIUS server 
daemon must be restarted: 

killall radiusd 

radiusd 

12.13.2.2 Configuring Freeradius Server with DS2 Options 

The RADIUS server must be configured to respond to client queries in the correct 
way.  It must supply the client with the following information: 

Access-Accept or Access-Reject message; 

Profile number. Attribute DS2-profile. 

Summary of Contents for dLAN 200 DSpro

Page 1: ...dLAN 200 DSpro Manual...

Page 2: ...technical development You can find all declarations and certifications of compliance for the products as long as they were available at the time of publication in the appendix of this documentation T...

Page 3: ...pro Adapter Configuration 10 5 Starting Up the dLAN 200 DSpro Adapter 11 6 Providing an IP Address 11 7 Telnet to the dLAN 200 DSpro Adapter 13 8 Writing an Autoconfiguration File 16 9 Configuring the...

Page 4: ...7 12 7 3 OVLAN Configuration and Root Interface 38 12 8 Autoconfiguration File 40 12 8 1 Introduction 40 12 8 2 Parameter Types 40 12 8 3 Parameter Format 40 12 8 4 Supported Parameters in the Autocon...

Page 5: ...o dLAN 200 DSpro Manual 13 Appendix 76 13 1 Technical data 76 13 2 Important safety instructions 77 13 3 CE conformity 78 13 4 Declaration of conformity 79 13 5 Warranty conditions 80 13 6 Troubleshoo...

Page 6: ...on with maximum data security 1 2 About this manual This document describes the basic steps required to setup a small demonstration network with dLAN 200 DSpro adapters It also explains the procedure...

Page 7: ...http www winpcap org Wireshark is the graphical packet capture tool used to inspect the traffic generated by the dLAN 200 DSpro adapter It can be downloaded from http www wireshark org Hane Win DHCP T...

Page 8: ...Service Pack 2 is installed on the PC running Windows XP disable the DHCP server service and the firewall service All of the tools and examples described in this document have been tested on a compute...

Page 9: ...shes when data is being transmitted ETH Col Flashes at a faster rate if the network is experiencing increasing use ETH This is the connection point on the dLAN 200 DSpro for connec ting it to a comput...

Page 10: ...t It is recommended to use a high pass filter not part of the standard accessory to decouple the dLAN 200 DSpro signals from the transfer point of the TV signal A filter should be used when you want t...

Page 11: ...o adap ter will issue a DHCP discover packet as shown in Figure 1 Figure 1 Packet Trace of the Startup of the Adapter If you cannot see the DHCP packets coming from the dLAN 200 DSpro adapter the caus...

Page 12: ...your computer s subnet mask In the lid Other select option 120 Then select type Binary and in the Value field type 0 0 0 0 putting spaces between the zeroes Finally click Add Figure2 Configuration of...

Page 13: ...checked The console can provide useful information about the status of the dLAN 200 DSpro adapter and the connectivity to its neighbours To open a telnet session to the dLAN 200 DSpro adapter we must...

Page 14: ...d click on Open to connect to the dLAN 200 DSpro adapter A window will come up with the welcome message from the dLAN 200 DSpro adapter as shown in Figure 5 To obtain information from the dLAN 200 DSp...

Page 15: ...G 1 DSNR_MODE_MONITORING 1 DWRONG_ACKS 1 DCOEX_ESCALABLE 1 DNEW_BCAST DUSE_ARC_TIMER 0 O2 Type h for help OK user i Slave Access MAC 00 50 C2 12 6E 13 IP 192 168 1 2 SYNC MODE 5 AGC RX enabled RXG 0 A...

Page 16: ...er nodes physical Tx and Rx speeds and status of the bridge Number of boots since the last factory reset Additional instructions concerning dLAN 200 DSpro adapter configuration through the console are...

Page 17: ...e one level network can be built File master conf General parameters GENERAL_USE_AUTOCONF yes GENERAL_MAC_MODE ACCESS Configure the node as Master HE GENERAL_TYPE HE GENERAL_FW_TYPE LV GENERAL_AUTHENT...

Page 18: ...y this directory in the DHCP application under Options Preferences Then go to the TFTP lid and set TFTP Root Directory to the direc tory where the configuration files are as shown in Figure 9 The next...

Page 19: ...gn a profile to each of your dLAN 200 DSpro adapters The assignment is done based on the MAC address Choose one of your dLAN 200 DSpro adapters to be the master and the rest will be slaves In the main...

Page 20: ...they will search for a connection to the DHCP server through Ethernet or PLC and they will finally be configured one as master and the rest as slaves If everything is properly configured the master wi...

Page 21: ...g the dLAN 200 DSpro adapter will report KO The commands are typed at the command prompt which looks like user To enter a menu you must type the name of the menu or the short alias and then press ENTE...

Page 22: ...ll ask for a password Type maxibon and press ENTER When using Putty the password fails the first time Using SecureCRT there is not such a problem Line editing is not allowed at the dLAN 200 DSpro adap...

Page 23: ...ange the transmission gain to 0 default is 1 To change the transmission gain type a txg 0 If you are experiencing satu ration between any two dLAN 200 DSpro adapters you must reduce the trans mission...

Page 24: ...st known autoconfiguration file and TFTP server from which it was downloaded If you want to set a static configuration in the dLAN 200 DSpro adapter you must issue the command ac bm NVRAM You must als...

Page 25: ...ble modes until it finds a master To change the PLC mode you must type for example s m 6 to switch to mode 6 To change the PLC mode and make it permanent type s m w 6 This will store the mode in the f...

Page 26: ...installation in the field When not available a default con figuration will be utilized The Management VLAN of all PLC equipment of a transformer station may be different for each transformer station e...

Page 27: ...starts with the same default factory configuration Access CPE Using IFCP explained in Section 12 4 the dLAN 200 DSpro adapter disco vers if it is booting in a network with VLANs or not If a network h...

Page 28: ...LAN if needed Once this para meter is obtained the IFCP protocol finishes Using TFTP protocol the nodes download the autoconfiguration file and configure the firmware accordingly 12 3 1 Autoconfigurat...

Page 29: ...nent 12 4 IFCP Protocol The IFCP Inter Firmware Communication Protocol is used to transfer the trans lation table between dLAN 200 DSpro adapters at booting Although the translation table is comprised...

Page 30: ...o change the entire network to use VLANs A dLAN 200 DSpro adapter must not perform IFCP Autoconfiguration noIFCP Boot in the NVRAM in the following two cases If it is the first node of the network dir...

Page 31: ...that with the new FW version the slave always makes IFCP requests during booting and because of that LV nodes always start their IFCP servers whether using VLANs or not A master with a pre vious FW v...

Page 32: ...Node D and Node F is DATA VLAN OPERA TOR 2 but the translation table that Node D gets from Node B indicates that DATA VLAN OPERATOR 2 is VLAN 34 and the translation table Node F gets indi cates that i...

Page 33: ...the dLAN 200 DSpro adapter configures itself to use the Management VLAN included in the translation table Parameter TRANSLATION_ROOTPATH_OVLAN explained later NOTE VLAN 1 is reserved in a Wisconsin PL...

Page 34: ...solve this situation where a dLAN 200 DSpro adapter gets IFCP from a different master than should be the case if the auto configuration file downloaded by the dLAN 200 DSpro adapter includes the tran...

Page 35: ...VLAN 1 21 TRANSLATION_DATA_VLAN 3 19 TRANSLATION_DATA_VLAN 4 1333 TRANSLATION_DATA_VLAN 16 22 TRANSLATION_ROOTPATH_OVLAN 666 The translation table that the dLAN 200 DSpro adapter will then use and the...

Page 36: ...acted by the customer The configuration will be GENERAL_FW_TYPE equal to EU The main differences between configuring a dLAN 200 DSpro adapter as EU or LV are the following Local VLAN Configuration The...

Page 37: ...IP VLAN per LV cell It is possible to add private VLANs between specific customers that do not belong to any ISP or voice operator In this case VLAN trunks must be defi ned in the intermediary equipme...

Page 38: ...5 in equipment that is connected to the backbone and no tag is allowed in this path However packets with the ALL_VLAN tag are not filtered An example of the basic OVLAN configuration is shown in Figur...

Page 39: ...e 14 Basic OVLAN Configuration Example The following configuration must be set therefore in all end users OVLAN_ENABLE yes OVLAN_DATA_TAG ROOTPATH The node that connects to the backbone must have GENE...

Page 40: ...ce or VLAN OVLAN configuration could use the same autoconfiguration file Thus LV nodes with no specific QoS or VLAN OVLAN parameters should receive a dif ferent generic file The network operator can u...

Page 41: ...ameters in the file are stored in the NVRAM when the file is downloaded and the node boots in NVRAM mode the next time Default value yes WARNING When the dLAN 200 DSpro adapter boots in NVRAM mode IFC...

Page 42: ...ut for EXTB GENERAL_IP_ADDRESS ddd ddd ddd ddd IP address of the dLAN 200 DSpro adapter for the next boot if DHCP is disabled GENERAL_IP_NETMASK ddd ddd ddd ddd IP netmask of the dLAN 200 DSpro adapte...

Page 43: ...ur notches are stored in the NVRAM GENERAL_IFACE_ROOT EXTA EXTB Root interface assignment The root interface is the interface where the autoconfiguration file is received The system automatically obta...

Page 44: ...these settings are related to a SIGNAL_MODE Correct settings in one mode do not mean it is correct in others Reception Gain Parameters Automatic Gain Control parameters AGC_RX_ENABLE 0 1 Disables enab...

Page 45: ...WARNING The power control is only allowed in CPEs It must never be used in a HE or TD repeater 12 8 4 3 RADIUS Parameters RADIUS_SERVER_IP ddd ddd ddd ddd RADIUS server IP address RADIUS_SERVER_PORT...

Page 46: ...ority that is the priority assigned to packets that do not match a criterion Default value 2 12 8 4 5 Quality of Service QoS Parameters QOS_ENABLE YES NO This parameter enables disables the quality of...

Page 47: ...it will be imposed by the slave when transmitting data back to its master Master Node Parameters HE or REPEATER QOS_LATENCY_STEP 20 400 in ms Configures the minimum latency step for the different slav...

Page 48: ...bled the user will receive tokens constantly Every time the master node has transmitted all required tokens to all the slaves with upstream bandwidth limited then it will transmit tokens to the slaves...

Page 49: ...dden for the user with profile i When the list is ALLOWED the tags are added to the base confi guration when the list is FORBIDDEN the list is reset and only tags defined with PROFILE_VLAN_ADD_TAG wil...

Page 50: ...to 16 tags TRANSLATION_ROOTPATH_OVLAN 2 4094 Translation table rootpath OVLAN WARNING When the dLAN 200 DSpro adapter is going to boot in NVRAM mode IFCP is not performed so the translation table is...

Page 51: ...t be allowed in the node interfaces It is necessary to configure these trunks for private VLANs between EUs in all intermediary equipment VLAN_RETAG_EXTA_SRC 0 2 4095 VLAN retagging External Ethernet...

Page 52: ...sent by the dLAN 200 DSpro adapter are tagged with the ROOTPATH ovlan tag This prevents Forwarding Tables of LV equip ments becoming filled with MAC addresses and overflow in very large net works hund...

Page 53: ...egardless of the number of hops reception gain or values of the other autoconfiguration parameters If AP_PREFER_MASTER is configured and AP_FIX_MASTER is not used the best master selected will be the...

Page 54: ...erformed A value of 1 255 means that the RADIUS update is performed with this period in hours Default value 24 ACCESSP_AUTHLIST_MAC i 0xXXXXXXXXXXXX List of allowed MAC addresses The length of the lis...

Page 55: ...t to use a number greaterthan 200000000 so as not to exceed the accumulated maxi mum of 4294967296 Default values ETHA 2000000 ETHB 2000000 PLC 4000000 STP_HELLO_TIME 10 100 Hello time expressed in de...

Page 56: ...SC MAC to be in the FW this is done automatically Default value 4 MAC_INGRESS_FILTERING_MODE FIXED AUTO If FIXED Enables the INGRESS MAC FILTERING and registers the list of MAC_INGRESS_FILTERING_FIXED...

Page 57: ...200 DSpro adap ters As a general rule this configuration overrides the basic VLAN OVLAN con figuration In order to decrease the risk of loosing the connection the VLAN OVLAN filtering follows these ru...

Page 58: ...rnet interface A Default value yes VLAN_OUTFORMAT_TAG_IFACE_EXTB yes no Sends packets with a VLAN tag to external Ethernet interface B Default value yes VLAN_OUTFORMAT_TAG_IFACE_OTHER yes no Sends pac...

Page 59: ...o 0 VLAN_IS_ALLOWED_IFACE_ROOT yes no Private VLANs list Root interface IFACE_ROOT list is an allowed tag list if YES or forbidden if NO Default value yes VLAN_LIST_IFACE_ROOT i 2 4095 Private VLANs l...

Page 60: ...nterfaces If set to NO drops packets with an OVLAN tag entering external Ethernet interface A If set to YES accepts tagged packets with an OVLAN tag Default value no OVLAN_TAGGED_ONLY_IFACE_EXTB yes n...

Page 61: ...U the default value is equal to OVLAN_DATA_TAG If LV or MV the default value is 0 OVLAN_PVID_FW 2 4095 OVLAN tag for tagging untagged packets from the firmware interface FW Default value 0 OVLAN_IS_AL...

Page 62: ...so the autoconfiguration of those parameters does not imply the use of that configuration The values of those parameters are stored in the NVRAM and will be used in the next boot 12 8 4 16 SNMP Param...

Page 63: ...dapter 12 9 NVRAM The NVRAM contains the following information necessary before the autocon figuration file is received Its own MAC address If required the PLC signal bandwidth and the central frequen...

Page 64: ...AN that this node uses to get the IP through DHCP Also the IFCP client has to be disabled otherwise the Management VLAN will not be used Note that this tag is only mandatory when there is no other nod...

Page 65: ...peater node has to look for slaves When a new slave is found it can be authenticated using RADIUS protocol or automatically added to the system if the authentication is disabled The master should also...

Page 66: ...o RADIUS authentication two ways of operation are possible The first one is NO AUTHENTICATION The master will configure a default QoS and VLAN OVLAN configuration the invited profile for the slave The...

Page 67: ...e the ifcp code option option extensions path name code 18 string option ifcp code code 120 unsigned integer 32 It is also necessary to define the phone number in the header of the dhcpd conf file if...

Page 68: ...hardware ethernet 00 50 C2 00 00 15 fixed address 10 10 1 15 option tftp server name 10 10 1 28 option extensions path name he txt option ifcp code 35 host node3 hardware ethernet 00 50 C2 12 6b b3 fi...

Page 69: ...ith the Wisconsin RADIUS clients The following is an example with the Linux freeradius server Extract the freeradius tar file compile and install the RADIUS server tar zxvf freeradius 0 8 1 tar gz cd...

Page 70: ...he Linux RADIUS server INCLUDE dictionary ds2 All possible clients must then be defined in the clients conf file of the RADIUS server A set of clients in the same sub network can be included in the sa...

Page 71: ...ile 2 0050C2000011 Auth Type Local User Password anonymous DS2 profile 2 DEFAULT Auth Type Reject 12 14 Autoconfiguration Console 12 14 1 Configuring Boot Mode from the Console The boot mode can be ob...

Page 72: ...VLAN taken from the NVRAM or the IFCP if the management VLAN was obtained through IFCP To change the VLAN working mode use the vconf command vconf 0 1 mnmt_vlan_msb mnmt_vlan_lsb The first argument e...

Page 73: ...NVRAM ac ifcpmode set 1 enables IFCP in the next boot writing in the NVRAM ac ifcpmode get Checks the IFCP state for the next boot reading the NVRAM NOTE DHCP should be used if possible to disable IFC...

Page 74: ...Time domain Multiplier parameter set To get the running configuration for STP parameters execute the csh run stp command Showing running configuration Spanning Tree Protocol Parameters Set STP_PRIO 7...

Page 75: ...rocess is performed They are the following they are in general set csh nvram general Showing NVRAM stored configuration General Configuration Parameters Set GENERAL_USE_AUTOCONF YES GENERAL_TYPE HE GE...

Page 76: ...ual LAN QoS Quality of Service Supported protocols IEEE 802 1 p Q Type of Service ToS Service Classifier CoS Bridging 32 active connections at the same time MAC table with 64 entries Packets from MAC...

Page 77: ...DSpro must not be set up in close proximity to a radiator The dLAN 200 DSpro should only be set up in locations where adequate ventilation is assured in accordance with the manufacturer s instruction...

Page 78: ...lowed properly if the case of the dLAN 200 DSpro has been damaged 13 3 CE conformity The product conforms to the basic requirements of Directive 1999 5 EC R TTE and the other relevant provisions of th...

Page 79: ...erungen und Bestimmungen der folgenden Normen und Methoden The product complies with the essential requirements and provisions of following standards and methods Sicherheitsanforderungen EN 60950 1 20...

Page 80: ...they initiate a new warranty period The warranty period for installed replacement parts ends with the warranty period of the device as a whole 3 Warranty procedure a If defects appear during the warr...

Page 81: ...y of data where periodic secu rity data back ups have been made f The warranty is valid only for the first purchaser and is not transferable g The court of jurisdiction is located in Aachen Germany in...

Page 82: ...short coaxial cable to carry out a quick connectivity test The Ethernet LED does not light up Make sure that the dLAN 200 DSpro is connected to a device with an Ethernet port by an RJ 45 cable and th...

Reviews: