background image

 

 35

3.6. Advanced Settings 

3.6.1. Packet Filters 

The HD24613 Web-Based Network Management provides layer 2 (Ethernet Type Filters), layer 3 (IP 
Protocol Filters), and layer 4 (TCP/UDP Port Filters) filtering capabilities. The configuration 
processes for the filters are similar. 

Functionality

: Sets the filtering as 

enabled

 or 

disabled

Policy for matched packets

: Choose to 

discard

 or to 

pass 

a matched packet. 

To enable a filtering rule

: Select the check box to the left of the rule to enable. 

3.6.1.1. Ethernet Type Filters 

When this feature is enabled, the 

Ethernet type

 field of the MAC (Media Access Control) header of a 

packet incoming from the WLAN or Ethernet interface is inspected for filtering. To set a rule, specify 
the hex-decimal Ethernet type number and give the rule a name. 

 

Fig. 46. Ethernet type filters settings 

3.6.1.2. IP Protocol Filters 

When this feature is enabled, the protocol, source address, and destination address fields of a packet 
incoming from the WLAN or Ethernet interface is inspected for filtering. To set a rule, specify the 
hex-decimal protocol number, source IP address range (Source IP Address AND Source Subnet 
Mask), and destination IP address range (Destination IP Address AND Destination Subnet Mask). 

Summary of Contents for HD24613

Page 1: ...i 802 11g In wall WLAN Access Point Model No HD24613 User Guide HD24613_UG_001 ...

Page 2: ...en the equipment and receiver z Connect the equipment into an outlet on a circuit different from that to which the receiver is connected z Consult the dealer or an experienced radio TV technician for help FCC Caution To assure continued compliance example use only shielded interface cables when connecting to computer or peripheral devices Any changes or modifications not expressly approved by the ...

Page 3: ...those who install and use it Howev er special attention must be paid to the dangers of electric shock and static electricity when working with electrical equipment All guidelines of this and of the computer manufacture must therefore be allowed at all times to ensure the safe use of the equipment EU Countries Intended for Use The ETSI version of this device is intended for home and office use in A...

Page 4: ...and Cancel Commands 13 3 1 3 Home and Refresh Commands 14 3 2 Viewing Status 15 3 2 1 Associated Wireless Clients 15 3 2 2 Current DHCP Mappings 15 3 2 3 System Log 15 3 2 4 Link Monitor 16 3 3 General Operations 16 3 3 1 Specifying Operational Mode 16 3 3 2 Changing Password 18 3 3 3 Managing Firmware 18 3 3 3 1 Upgrading Firmware by HTTP 18 3 3 3 2 Backing up and Restoring Configuration Settings...

Page 5: ...et Filters 35 3 6 1 1 Ethernet Type Filters 35 3 6 1 2 IP Protocol Filters 35 3 6 1 3 TCP UDP Port Filters 36 3 6 2 Management 36 3 6 2 1 UPnP 36 3 6 2 2 System Log 37 3 6 2 3 SNMP 37 Appendix A Default Settings 39 Appendix B Troubleshooting 40 B 1 Wireless Settings Problems 40 B 2 TCP IP Settings Problems 41 ...

Page 6: ... 128 bit WEP Wired Equivalent Privacy For authentication and data encryption Enabling Disabling SSID Broadcasts When the HD24613 is in AP Bridge mode the administrator can enable or disable the SSID broadcasts functionality for security reasons When the SSID broadcast functionality is disabled a client computer cannot connect to the HD24613 with blank network name SSID Service Set ID the correct S...

Page 7: ... Association Control When the HD24613 is in AP Bridge mode it can be configured to deny association requests when it has served too many wireless clients or traffic load is too heavy Associated Wireless Clients Status When the HD24613 is in AP Bridge mode it can show the status of all wireless clients that are currently associated or connected Auto Channel Selection The auto channel selection feat...

Page 8: ... it System Log For system operational status monitoring Local log System events are logged to the on board RAM of the HD24613 and can be viewed using a Web browser Remote log by SNMP trap Systems events are sent in the form of SNMP traps to a remote SNMP management server z Power over Ethernet Power is supplied to the HD24613 via an Ethernet cable using an 802 3af compliant power injector z Hardwa...

Page 9: ...the HD24613 2 Place the HD24613 in desired location upon the desk or flat surface 3 Using the single port PoE Injector connect one end of an Ethernet LAN cable from a LAN port on the network router or switch and the opposite end to the port marked Data In Use another Ethernet LAN cable to connect the port marked Data Out to the WAN port on rear of the HD24613 4 Plug the single port PoE power cord ...

Page 10: ...iguration management protocol is HTTP based make sure that the IP address of the managing computer and the IP address of the managed AP are in the same IP subnet the default IP address of the HD24613 is 192 168 100 1 and the default subnet mask is 255 255 255 0 To connect the Ethernet managing computer and the managed HD24613 for first time configuration you have two choices as illustrated in Fig ...

Page 11: ...nter the user name and password to gain the right to access the Web based Network Manager For first time configuration use the default user name root and default password root respectively Fig 2 The Login page NOTE It is strongly recommended that the password be changed for security reasons On the start page click the General Password link to change the value of the password see Section 3 3 1 for ...

Page 12: ...supported through Wireless Distribution System WDS AP Client This mode is for Dynamic LAN to LAN Bridging The AP Client automati cally establishes bridge links with APs from any vendors Fig 4 Operational mode settings 1 Click on General from the side menu and then select Operational Mode 2 Select an operational mode and click Save to apply the setting In either mode the HD24613 forwards packets be...

Page 13: ...13 and an AP Client both devices have to be con figured with the same SSID and WEP settings The AP Client automatically scans for any HD24613 that is using the matched SSID and establishes a bridge link with the scanned HD24613 NOTE Although it s more convenient to use dynamic bridging it has a limitation the AP Client only can forward TCP IP packets between its wireless interface and Ethernet int...

Page 14: ...e RF channels depends on local regulations therefore you have to choose an appropriate regulatory domain to comply with local regulations The SSID of a wireless client com puter and the SSID of the HD24613 must be identical for them to communicate with each other NOTE Put a check in the Auto Channel Selection checkbox to allow the Frequency Channel of the HD24613 to be automatically set Fig 6 IEEE...

Page 15: ...lient Computers The TCP IP and IEEE 802 11b related settings of wireless client computers must match those of the HD24613 in order for a wireless link to be established 2 5 1 Configure IEEE 802 11 Settings Before the TCP IP networking system of a wireless client computer can communicate with other hosts the underlying wireless link must be established between a wireless enabled computer and the HD...

Page 16: ...is a DHCP server on the network NOTE For some versions of Windows the computer needs to be restarted for the changes of TCP IP settings to take effect 2 6 Confirm Settings of the HD24613 and Client Computers After configuring the HD24613 and setting up client computers it is recommended that all settings are checked and confirmed 2 6 1 Checking if the IEEE 802 11b Related Settings Work To check if...

Page 17: ...r troubleshooting 5 Type ping 2nd_dns_server where 2nd_dns_server is a placeholder for the IP address of the secondary DNS server of the wireless client computer Then press Enter If this DNS server responds the client should have no problem with TCP IP networking else see Appendix B 2 TCP IP Settings Problems for troubleshooting 3 Advanced Network Management This section covers the options and set...

Page 18: ...ss settings of the HD24613 DHCP Server Modify settings for the DHCP Dynamic Host Configuration Protocol server z IEEE 802 11 Click this tab to access the following settings Communication Modify basic IEEE 802 11b g settings of the HD24613 to work prop erly with wireless clients Security Modify security settings for authenticating wireless users and encrypting wire less data IEEE 802 1x RADIUS Modi...

Page 19: ...wo buttons Restart and Cancel In addition changes are highlighted in red Clicking Cancel discards all the changes Clicking Restart restarts the HD24613 for the settings changes to take effect Fig 10 Settings have been changed 3 1 3 Home and Refresh Commands At the bottom of a status page there are two buttons Home and Refresh Clicking Home brings you back to the Summary page Clicking Refresh updat...

Page 20: ... device that obtains the IP address A computer or device that acts as a DHCP client is identified by its MAC address Fig 13 Current DHCP mappings A static mapping indicates that the DHCP client always obtains the specified IP address from the DHCP server You can set static DHCP mappings in the Static DHCP Mappings section of the DHCP Server configuration page see Section 3 4 2 A dynamic mapping in...

Page 21: ...wireless connectivity to the Access Point Fig 15 Link monitor NOTE The values are updated every 20 seconds 3 3 General Operations 3 3 1 Specifying Operational Mode Fig 16 Operational mode settings The HD24613 supports two operational modes AP Bridge This mode provides both Access Point and Static LAN to LAN Bridging functionality The static LAN to LAN bridging function is supported through Wireles...

Page 22: ... are shown in the following table AP Bridge AP Client AP Bridge WDS STA AP AP Client STA AP Table 2 Operational modes vs wireless link types To establish a static bridge link based on WDS the AP bridges at both end of the WDS link must be manually configured with each other s MAC addresses see Section 3 5 1 5 for more information To establish a dynamic bridge link between a HD24613 and an AP Clien...

Page 23: ...agement protocol setting The HTTP method is suggested since it is more user friendly However due to different behavior of various Web browsers HTTP based firmware management operations may not work properly with some Web browsers If you cannot successfully perform HTTP based firmware management opera tions with your Web browser try the TFTP method 3 3 3 1 Upgrading Firmware by HTTP Fig 19 Firmware...

Page 24: ...owsers Fig 21 Configuration restore by HTTP To restore configuration of the HD24613 by HTTP 1 Click Browse and then select a correct configuration hex file You have to make sure the file name is the AP s MAC address The firmware file path will be shown in the Firmware file name text box 2 Click Restore to upload the configuration file to the HD24613 3 3 3 3 Upgrading Firmware by TFTP To configure ...

Page 25: ...n which the firmware files reside 5 On the computer run a Web browser and click the General Firmware Tools hyperlink 6 Choose TFTP as the Firmware management protocol 7 Specify the IP address of the computer which acts as a TFTP server If you don t know the IP address of the computer open a Command Prompt and type IpConfig then press the Enter key 8 Trigger the firmware upgrade process by clicking...

Page 26: ...be used as a TFTP server and as a managing computer to trigger the backup process 2 Connect the computer and one of the LAN Ethernet switch port with a normal Ethernet cable 3 Configure the IP address of the computer so that the computer and the HD24613 are in the same IP subnet 4 On the computer run the TFTP Server utility Select the Accept write requests check box and specify the folder to which...

Page 27: ... t know the IP address of the computer open a Com mand Prompt and type IpConfig then press the Enter key 8 Trigger the restoring process by clicking Restore The HD24613 will then download the confi guration backup file from the TFTP server NOTE Make sure the file is a valid configuration backup file for the HD24613 TIP If you want to remotely back up or restore configuration from the Internet adju...

Page 28: ...ation Fig 28 Basic DHCP server settings NOTE There should be only one DHCP server on the LAN otherwise DHCP would not work prop erly If there is already a DHCP server on the LAN disable the DHCP server functionality of the HD24613 NOTE By default the DHCP server function is disabled 3 4 2 2 Static DHCP Mappings IP addresses of servers are often static so that clients could always locate the server...

Page 29: ...ring IEEE 802 11 Related Settings 3 5 1 Communication 3 5 1 1 Basic Basic IEEE 802 11g related communication settings include HD24613 functionality RF type Reg ulatory domain Channel number Multiple Network name SSID Data rate and Transmit power For specific needs such as configuring the HD24613 as a wireless LAN to LAN bridge the HD24613 functionality can be disabled so that no wireless client ca...

Page 30: ...1 Link integrity settings When the Ethernet LAN interface is detected to be disconnected from the wired network all currently associated wireless clients are disassociated by the HD24613 and no wireless client can associate with the HD24613 The detection mechanism is based on pinging the IP address specified in Reference host 3 5 1 3 Association Control Fig 32 Association control settings If the n...

Page 31: ...34 AP 2 acts as an access point for the notebook computers and it forwards packets sent from the notebook computers to AP 1 through WDS Then AP 1 forwards the packets to the Ethernet LAN Packets destined for the note book computers follow a reverse path from the Ethernet LAN through the APs to the notebook com puters In this way AP 2 plays a role of AP repeater Fig 34 Wireless Distribution System ...

Page 32: ...C address of port 1 to 00 02 65 01 C5 TIP Plan your wireless network and draw a diagram so that you know how a HD24613 is connected to other peer HD24613 s or wireless bridges by WDS TIP Plan your wireless network and draw a diagram so that you know how a bridge is connected to other peer bridges by WDS See the following figure for an example network planning diagram Fig 37 Sample wireless bridge ...

Page 33: ...ation algorithm WEP keys MAC Address Based Access Control TABLE OF SECURITY SETTING DEFINITIONS SSID The network name SSID Broadcasts Enable or Disable SSID broadcast Enabling this feature broadcasts the SSID across the network Wireless Client Isolation When the HD24613 is in AP Bridge mode wireless to wireless traffic can be blocked so that the wireless clients cannot see each other This capabili...

Page 34: ...ent computer with an any SSID cannot associate with the AP Fig 38 Basic IEEE 802 11g security settings When the Wireless client isolation setting is set to This AP Only wireless clients of this HD24613 cannot see each other and wireless to wireless traffic is blocked When the setting is set to All APs in This Subnet traffic among wireless users of different HD24613 s in the same IP subnet is block...

Page 35: ...d STA 2 is blocked by AP 1 while wireless traffic between STA 2 and STA 3 which are associated with different APs is still allowed If the All APs in This Subnet option is used as shown in Fig 40 AP 1 and AP 2 communicates with each other via an inter AP protocol to share their STA association information to block wireless traffic among all the STAs Choose from up to 7 security modes z Open System ...

Page 36: ...g to the IEEE 802 11 standard WEP can be used for authentication and data encryption Normally Shared Key authentication is used if WEP data encryption is enabled In rare cases Open System authentication may be used when WEP data encryption is enabled The Authentication algo rithm setting is provided for better compatibility with wireless clients with various WLAN network adapters There are three o...

Page 37: ...Set the Access control type to inclusive 3 Specify the MAC address of a wireless client to be denied access and then click Add 4 Repeat Steps 3 for other wireless clients To delete an entry in the access control table z Click Delete next to the entry NOTE The size of the access control table is 64 Fig 42 MAC ACL download settings Instead of manually entering MAC addresses to the access control tab...

Page 38: ... EAPOL Extensible Authentication Protocol Over LAN The RADIUS serv er can record accounting information such as when a user logs on to the wireless LAN and logs off from the wireless LAN for monitoring or billing purposes The IEEE 802 1x functionality of the access point is controlled by the security mode see Section Er ror Reference source not found So far the wireless access point supports two a...

Page 39: ...US server after failing to communicate with the primary RADIUS server An IEEE 802 1x capable wireless access point and its RADIUS server s share a secret key so that they can authenticate each other In addition to its IP address a wireless access point can identify it self by an NAS Network Access Server identifier Each IEEE 802 1x capable wireless access point must have a unique NAS identifier Fi...

Page 40: ...ers When this feature is enabled the Ethernet type field of the MAC Media Access Control header of a packet incoming from the WLAN or Ethernet interface is inspected for filtering To set a rule specify the hex decimal Ethernet type number and give the rule a name Fig 46 Ethernet type filters settings 3 6 1 2 IP Protocol Filters When this feature is enabled the protocol source address and destinati...

Page 41: ...dress range is 192 168 0 0 to 192 168 0 255 3 6 1 3 TCP UDP Port Filters The destination port field the TCP or UDP header of a packet incoming from the WLAN or Ethernet interface is inspected for filtering Fig 48 TCP UDP port filters settings To set a rule specify the decimal Destination Port Protocol type TCP UDP and the name of the higher level protocol Application Name 3 6 2 Management 3 6 2 1 ...

Page 42: ...ystem events are divided into the following categories General System and network connectivity status changes Built in AP Wireless client association and WEP authentication status changes MIB II traps Cold Start Warm Start Link Up Link Down and SNMP Authentication Failure RADIUS user authentication RADIUS user authentication status changes NOTE The SNMP Authentication Failure trap is issued when u...

Page 43: ...38 Fig 51 SNMP settings To specify a trap target 1 Type the IP address of the target host 2 Type the Community for the host 3 Select the corresponding check box next to the IP address text box ...

Page 44: ...sing of the AP Security Mode Open System Selected WEP Key Key 1 WEP Key 1 00 00 00 00 00 WEP Key 2 00 00 00 00 00 WEP Key 3 00 00 00 00 00 WEP Key 4 00 00 00 00 00 MAC Address Based Access Control Disabled Access Control Table Type Inclusive Wireless Client Isolation Disabled AP Load balancing Disabled Link Integrity Disabled Association Control Max Number of Clients 64 Block Clients if Traffic Lo...

Page 45: ...over B 1 Wireless Settings Problems z The wireless client computer cannot associate with the HD24613 Is the wireless client in infrastructure mode Check the operating mode of the wireless adapter Is the SSID identical to that of the HD24613 Verify that the SSID setting of the wireless adapter matches that of the HD24613 Is the WEP enabled If necessary ensure that the appropriate WEP settings of th...

Page 46: ... communication path could be broken at some of the stages The OS provided network diagnostic tool ping exe can be employed to find out TCP IP related commu nication problems NOTE If two or more NICs are installed and operating on a client computer TCP IP may not work properly due to incorrect entries in the routing table Use the OS provided command line network tool route exe to add or delete entr...

Page 47: ...e client computer does not respond to ping from the client computer Solve the preceding problem first Are the IP address of the HD24613 and the IP address of the client computer in the same IP subnet If you cannot find any incorrect settings of the AP the default gateway may be really down or there are other communication problems on the network backbone z The DNS server s of the client computer d...

Reviews: