background image

G

ATEWAY 

C

ONTROLLER 

S

ERIES

 

 

U

SER 

M

ANUAL

 

2011, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED

 

 

 

P

AGE 

40

 OF 

124 

3 . 2. 4 .  S

E C U R I T Y

 

 

1

1

.

.

 

  A

U T H E N T I C A T I O N

 

This menu allows you to configure the Authentication Settings of the Gateway 
Controller. 

 

Screen 8   Authentication Configuration 

 
The Authentication Configuration has six radio button options: RADIUS Server
Local Authentication,  Hampton Inn HSIA Authentication, Terms of Service, 
No Authentication 
and  PMS Based Authentication.  By default,

 

Local 

Authentication

 

is enabled. 

 

Note:

 Authenticated subscribers can logout of the session by typing 

http://1.1.1.1

 in the 

web browser. 

 

RADIUS Server 

Remote Authentication Dial-In User Service (RADIUS) is an authentication and 
accounting service used by many service providers to track and control subscriber 
access.  The Controller includes a RADIUS Client that can be configured to make 
RADIUS requests when subscribers authenticate.  RADIUS Authentication requires a 
RADIUS Server in the back office in addition to the RADIUS Client.  
 

Summary of Contents for Gateway controller Series

Page 1: ...GATEWAY CONTROLLER SERIES USER MANUAL 2011 VALUEPOINT NETWORKS INC ALL RIGHTS RESERVED PAGE 1 OF 124 G GA A T T E E W W A A Y Y C CO O N N T T R RO O L L L L E E R R 3 35 56 60 0 USER MANUAL...

Page 2: ...ritten material and information in this manual is a copyright of ValuePoint Networks Inc No part of this work may be reproduced stored in a retrieval system adapted or transmitted in any form by any m...

Page 3: ...e latest release notes for your firmware version for any changes or new features not covered in this manual U U S S A A G G E E A A N N D D F F E E A A T T U U R R E E S S O O F F T T H H E E M M A A...

Page 4: ...SE T U P 18 3 2 3 NE T W O R K S 20 3 2 4 SE C U R I T Y 40 3 2 5 CU S T O M I Z A T I O N 55 3 2 6 MAN AG E M E N T 72 3 2 7 AD V AN C E D 82 3 2 8 SY S T E M ST AT U S 97 3 2 9 SY S T E M TO O L S 1...

Page 5: ...e 1 One Gateway Controller 2 One AC Power Adapter 3 One CD containing user s manual Quick Start Guide Features Some key features of the Gateway Controller are Advanced Local Authentication Totally con...

Page 6: ...subscriber s outgoing SMTP server requests to a SMTP server specified by administrator so the subscriber can send out their email without changing the E Mail configuration in their notebook computer C...

Page 7: ...ation IP addresses and URLs VPN Virtual Private Network Pass through The Gateway Controller allows subscribers to access their existing VPN network at home or at the office Unlike most public access g...

Page 8: ...sharing files or accessing enterprise hardware belonging to the venue Time based authentication list upload Security and Pass through information for the entire enterprise can be centralized and updat...

Page 9: ...customize the default pages used internally by the Controller or create an entire custom web site File Sharing TCP Session Limiting Limiting subscriber TCP sessions prevents spikes of activity by a si...

Page 10: ...recautions Please carefully read the following precautions before using the Gateway Controller Do not remove or open the enclosure You could damage the Controller or suffer injury if you tamper with t...

Page 11: ...rer or Firefox other browsers may not work as expected Others Network Cable with a RJ 45 connector 2 2 WAN NETWORK REQUIREMENTS Find out from your ISP whether the Controller will use a static or dynam...

Page 12: ...guring the system Description about the use of each part is available in next section along with the instructions on its usage Screen 1 Basic functionality 1 1 CHANGING GUI SETTINGS ENTERING DATA IN A...

Page 13: ...layed on the right top pane of the menu 2 2 RESETTING TO FACTORY DEFAULTS SOFT RESET Connect to the Controller WEB GUI and navigate to System Tools Factory Settings and select Reset Factory Defaults H...

Page 14: ...you can access the Gateway Controller by providing the correct Login Name and Password The password protection insures only authorized users can access the Controller We recommend that you change the...

Page 15: ...rd has been supplied you will gain access to the Controller otherwise an error message will be displayed After successful login the Controller displays the following screen which gives the Controller...

Page 16: ...The final option is Apply Changes Restart Click this from any menu to implement the changes made to the settings This restarts the controller immediately You must select OK on each page that you wish...

Page 17: ...EPOINT NETWORKS INC ALL RIGHTS RESERVED PAGE 17 OF 124 OK Clicking this button causes the settings configured by the user to be saved New settings may take effect immediately or on the next reboot The...

Page 18: ...ons 1 To connect via a Cable Modem or Local LAN select DHCP Client setting This configures the device to obtain the IP address and other TCP IP settings from your ISP 2 To use a static IP address assi...

Page 19: ...ISP select PPPoE and perform the following steps 1 Type the User Name for PPPoE protocol to connect the ISP 2 Type the correct Password for the above User Name 3 Select either Enable to activate Auto...

Page 20: ...S The Networks menu tabs control basic configuration of the gateway along with IP addressing DHCP and other features that affect customer network access 1 1 SYSTEM This section of the Controller allow...

Page 21: ...ob s Hotel could have the NAS ID bobshotel LAN IP settings Auto IP In this section select either Enable or Disable radio button to enable or disable the Auto IP subscriber address support Auto IP will...

Page 22: ...vailable in the SuperAP products from ValuePoint Please contact your Access Point vendor with questions about LAN Isolation in other products Auto LAN Isolation Exception List If you want some devices...

Page 23: ...you wish to change the NTP server or manually set the time NTP Server Type Manual This section has drop down boxes for Date and Time Select the Date and Time in UTC from the drop down list boxes as s...

Page 24: ...e default 0 means a subscriber sending no packets in one minute is idle Increasing this number allows minimal activity to be marked as idle if this is your requirement Note Setting Idle Timeout to 0 i...

Page 25: ...ng Gateway IP LAN IP Setting Primary LAN Network Type the IP Address and Subnet Mask of your Gateway Controller here By default the Controller sets the value 192 168 1 1 as IP Address and 255 255 255...

Page 26: ...ets in addition to the primary LAN IP These subnets are intended for equipment or users that are not on the main public network though they may still need authentication and bandwidth limits For each...

Page 27: ...e Controller selects DHCP Client as the port mode 1 To connect via a Cable Modem and LAN with DHCP select DHCP Client Port Mode 2 To use a static IP address assigned by your ISP or static WAN address...

Page 28: ...pages Fortunately the Gateway Controller provides numerous options to make sure every subscriber has a fair share of the available connection Important Note In our experience 10 20 of subscribers on...

Page 29: ...Symmetrical those subscribers are still on profile 14 which will revert to 8096 8096 Global Bandwidth Limit Select Enable to provide a universal bandwidth limit that affects all subscribers Upload and...

Page 30: ...10 for the first floor 201 210 for the second etc You must have VLAN switches to tag this incoming traffic The Gateway Controller does not tag untagged LAN packets ID Selection By default the Controll...

Page 31: ...124 WAN MAC Address Select either Default WAN MAC Address or Change to option and type the respective WAN MAC Address of the network interface card here By default the Controller selects Default as th...

Page 32: ...RIES USER MANUAL 2011 VALUEPOINT NETWORKS INC ALL RIGHTS RESERVED PAGE 32 OF 124 3 3 SERVER This menu allows you to configure the various Server Settings of the Gateway Controller Screen 7 Server Conf...

Page 33: ...B Type the DHCP Pool Size in the text box labeled DHCP Pool Size The size should be between 1 and 1024 By default the DHCP pool is 100 C Type the Lease Duration in minutes in the text box labeled as L...

Page 34: ...and Secondary must be in the same subnet and have the same DHCP Pool configuration DHCP must be configured to DHCP Server without static DHCP assignments This enables the Controllers to manage the DH...

Page 35: ...on pinging a reference IP or WAN default gateway In the case of failure the gateway will stop issuing DHCP leases and signal the working peer to take over existing subscribers When the failure is reso...

Page 36: ...d to log in again but should not have to reboot or renew DHCP Static VPN IPs On both peer Controllers Static VPN IPs must be enabled and the same WAN IP addresses must be configured These Static IPs m...

Page 37: ...llow subscribers who are away from their normal corporate or home network to send mail successfully The redirect process is transparent so subscribers do not notice any difference By default SMTP redi...

Page 38: ...emporarily If you wish to add permanent routes that are recreated on boot use the persistent route table Delete Delete the current route This option is not available for all routing table entries If y...

Page 39: ...hance to reset If you wish to add entries that are recreated on boot use the ARP route table Delete Delete the current ARP binding If the IP is active in the network the table will update rapidly but...

Page 40: ...s of Service No Authentication and PMS Based Authentication By default Local Authentication is enabled Note Authenticated subscribers can logout of the session by typing http 1 1 1 1 in the web browse...

Page 41: ...are Authentication Type Primary RADIUS Server The Primary RADIUS Server provides the authentication and accounting for subscribers When the subscriber enters their username and password these paramet...

Page 42: ...Client Please consult your RADIUS Server documentation for more information on connecting RADIUS Clients Secondary RADIUS Server The secondary RADIUS Server has the same configuration options This RA...

Page 43: ...RADIUS Server documentation for details on which method your Server requires Port Limit for Client Bandwidth You can Enable or Disable Per Subscriber based Bandwidth Control RADIUS accounts will recei...

Page 44: ...They are Auto Create User Set Auto Default and Add Modify User Screen 10 Selecting Local Authentication option Window Auto Create User Click Auto Create User to create usernames and passwords automat...

Page 45: ...uto Default Click Set Auto Default to set default values to this section Clicking this command will display a pop up window with various authentication settings Use these settings to define the kind o...

Page 46: ...r needs more time you will have to edit the account User Login Type Select the User Login Type here There are three account types Single PC Login allows only a single computer to access the account by...

Page 47: ...r example if a hotel has Ethernet in the rooms and WiFi in the lobby whichever is used first will lock the Single PC account to that MAC address only Add Modify User Click Add Modify User to add delet...

Page 48: ...lease contact Hampton Inn for valid configuration settings for the hotel property you are installing Screen 14 Selecting Hampton Inn HSIA Authentication option Window Central Authentication Server Ent...

Page 49: ...System Tools Maintenance Terms of Service You can also download the current terms of service file to use as a template Configuring the Terms_of_Service htm file You can customize the HTML file however...

Page 50: ...his feature to enable PMS Based Authentication This feature allows guests at a hotel to receive a local authentication account on check in to the hotel The account parameters are defined in the Contro...

Page 51: ...password fields take guest last name and room number respectively PMS internal Logging PMS Billing records sent from the controller to the PMS Server are stored in etc PMS_Billing log file inside the...

Page 52: ...Charge for PMS Authenticated subscribers Strict IP Conflict Detection for Login Strict IP Conflict detection will return an error That IP is already in use if a subscriber attempts to log in with an I...

Page 53: ...ere are two options for configuring Pass through settings in the Controller If you only need a limited number of entries up to 48 per option you can configure these from the GUI directly If you need t...

Page 54: ...ith the No Authentication configuration MAC Address Pass through users will need to initiate a HTTP Web Browser connection to be added to the firewall so they can send email ping or make other connect...

Page 55: ...RIES USER MANUAL 2011 VALUEPOINT NETWORKS INC ALL RIGHTS RESERVED PAGE 55 OF 124 3 2 5 CUSTOMIZATION 1 1 LOGIN PAGE This menu allows you to customize the Login Page settings of the Gateway Controller...

Page 56: ...ler In order to subscribers to login successfully you will need to put the correct HTML POST FORM on your Web Page To see and cut paste the required code click on the View External Portal HTML Code bu...

Page 57: ...r original request after authentication Please consult your Web Designer on the use of CGI variables in web server design Note This CGI is appended to the URL request as entered under Portal Page URL...

Page 58: ...ackground Color by clicking on the icon given right after the Background Color field Contact Information Type Contact Information for the ISP or Support if any here Administrator Comments Type the Adm...

Page 59: ...rated by the controller The Custom page can be configured by selecting the Page Title Background Color Message Text Message Text Color and Message Background color Free Access Caf Account Free Access...

Page 60: ...Portal HTML Code button and cut paste the HTML code into your page Example Usage If you set free access to 30 minutes every 24 hours this would allow any user to access the internet for 30 minutes on...

Page 61: ...OINT NETWORKS INC ALL RIGHTS RESERVED PAGE 61 OF 124 2 2 MESSAGE CUSTOMIZATION This menu allows the user to customize the message text of the Gateway Controller The message customization screen appear...

Page 62: ...ired Background Color by clicking on the icon given right after the Background Color text box Message Type the Welcome Message which is to be displayed in the in the welcome page here Message Text Col...

Page 63: ...ption Type additional comments or continue Main Message here This accepts up to 150 characters Time Count Label This has two text boxes namely With Session Timeout and Without Session Timeout Type the...

Page 64: ...done automatically by the controller like login redirection The subscriber must click on a logout button or link on either the logout pop up window or the link provided by the site Following Goodbye r...

Page 65: ...d but they can be replaced To replace these files upload your custom files with the same name Selecting Default button will restore the original default page Screen 19 Upload Pages Default Pages Inter...

Page 66: ...egal terms of service text but keep the POST FORM elements Banner jpg This is the default image used by the Terms of Service Custom and Default Login pages You can reference this image on your customi...

Page 67: ...ou to create a page with legal terms and conditions that subscribers must agree to before they can use the service Subscribers do not log in with a username or password they just accept the terms Set...

Page 68: ...al login portal with multiple pages Set Customization Login Page Login Page Internal Portal Download the Internal_Portal htm template from Customization Upload Pages This page becomes the index page f...

Page 69: ...ling sites to create valid user accounts and whatever else you need on your portal Note The Controller web server will provide file access and basic HTTP services only You will not be able to use serv...

Page 70: ...equency at which the Advertisement is to be displayed by selecting either of Show Once or Show Every or Disable option here The frequency is set in minutes If the user has selected Show Once option th...

Page 71: ...S INC ALL RIGHTS RESERVED PAGE 71 OF 124 Ad X Type the URL Links to the advertisements which are to be displayed Note The Logout pop up window generates the automatic advertisements You must enable th...

Page 72: ...part this is information related to the network connections and hardware You can enable SNMP using the configuration page You will need a SNMP client or network monitoring software to access the SNMP...

Page 73: ...news is that the law provides a Safe Harbor against liability for ISPs and other service providers provided they can show that is was an end user violating the copyright and that the material is no l...

Page 74: ...ords the log is compressed and processed with User IDs and sent to the TFTP server If the TFTP server is unavailable the Controller will try three times to send the file after that the file is lost be...

Page 75: ...f a DMCA infringement report from MPAA Title Coraline Infringement Source BitTorrent Initial Infringement Timestamp 28 Aug 2009 11 12 06 GMT Recent Infringement Timestamp 28 Aug 2009 11 12 06 GMT Infr...

Page 76: ...or MAC address they request 3 3 ACCESS POINT MONITOR PORT FORWARDING This menu allows the user to configure the Access Point Monitor which will facilitate management of your public access network The...

Page 77: ...pe from the drop down list box The values of the drop down are TCP and UDP Connection Select the Connection of the Device from the drop down list box The values of the drop down are Wired and Wireless...

Page 78: ...nternal device In this case the Controller and Device Port are the same port Be careful not to forward ports you need on the Controller such as the HTTP GUI on port 80 IP Address Type the Device LAN I...

Page 79: ...LOGGING CONFIGURATION This menu allows the user to configure the SysLog settings of the Gateway Controller Screen 23 System Logging Configuration System Logging Configuration This section has two rad...

Page 80: ...mation such as uptime and Controller IP address Access Point Information Check on the Access Point Information check box to include in the log the details of the current LAN Devices Status Logged in U...

Page 81: ...Information option will report all SysLog messages 4 Checking the Debug option will display extensive debug messages in the controller The debug output will generate a large volume of SysLog traffic a...

Page 82: ...omatically domains you have registered at DynDNS org This can help in case where the WAN IP is dynamic but you want static access to the GUI or AP Monitor Please register with DynDNS org for instructi...

Page 83: ...The value typed is calculated in terms of minutes The Controller will send a message to DynDNS org at this interval with the current IP address In our experience updating too frequently less than 1440...

Page 84: ...configure the Controller to route all authenticated traffic through a Generic Routing Encapsulation GRE tunnel The GRE Tunnel takes all authenticated LAN traffic and transmits it to a remote server o...

Page 85: ...IP Address of the Controller side of the tunnel Local Tunnel Subnet Mask The LAN subnet of the Controller side of the tunnel Remote Tunnel IP Address The LAN IP Address of the remote side of the tunn...

Page 86: ...he two network subnets traffic to the overlapping addresses will not be sent through the tunnel This might be the case if you have a central VPN terminator that serves multiple Controllers Remote Gate...

Page 87: ...utomatic Phase 1 Phase 1 of VPN is when the two sides identify each other as legitimate VPN gateways and agree on how to establish the connection Mode You can choose a longer version of the initial co...

Page 88: ...DES is more secure but require more resources Authentication You can choose MD5 or SHA1 SHA1 is a little more secure Perfect Forward Secrecy You can enable PFS to make the key generation a little slow...

Page 89: ...e same SPI for incoming and outgoing tunnels This value must match the setting on the other gateway Encryption Key You must enter a hexadecimal value of the following length DES 16 3DES 48 Authenticat...

Page 90: ...ll of the settings including VPN ID Protocol and Key Timeouts All Phase 1 and Phase 2 settings much match of course Check the VPN Log to see if there are any obvious errors If your first choice of Enc...

Page 91: ...lter will block or allow all traffic of a particular protocol to or from an IP Address range This is typically used to restrict all access to internal or external addresses Source and destination IPs...

Page 92: ...0 0 0 0 0 Start Port Enter the Start Port number Port numbers can be in the range 0 to 65535 The drop down menu gives some sample rules for typically unwanted subscriber applications There is no guar...

Page 93: ...address List page The page contains all the correct IP properties and the available addresses are displayed automatically Subscribers can also receive the Static IP addresses automatically via DHCP Su...

Page 94: ...NTROLLER SERIES USER MANUAL 2011 VALUEPOINT NETWORKS INC ALL RIGHTS RESERVED PAGE 94 OF 124 Screen 26 Subscriber Static IP Subscriber Static IP Select one of the three available options for Subscriber...

Page 95: ...e the Main Message or Title for the Automatic subscriber static IP page in this text box A maximum of 80 characters are allowed in the text box Automatic Page Message Type additional comments to be di...

Page 96: ...er Static IP Addresses Enter the sequential block of subscriber static IP addresses and the corresponding subnet mask gateway IP address and DNS IP addresses A list of 10 static IP addresses can be co...

Page 97: ...PAGE 97 OF 124 3 2 8 SYSTEM STATUS This menu tab opens up the submenus showing status of the Controller and subscribers 1 1 SYSTEM This menu displays current system information like Host Name LAN MAC...

Page 98: ...net Mask of the Gateway Controller WAN Port Default IP Gateway Here the menu displays the Default IP Gateway of the Gateway Controller WAN Port DNS Primary DNS Server Here the menu displays the IP Add...

Page 99: ...om boot time Controller NAS ID Here the menu displays the Host Name of the Gateway Controller Firmware Image Here the menu displays the Firmware Version of the Gateway Controller Hotspot Version Here...

Page 100: ...HCP Server DHCP Mode Here the menu displays the DHCP mode When using Dual WAN this field will show the Dual WAN role Primary or Secondary and status Startup Please wait for startup to complete Recover...

Page 101: ...og in with a username password IP Address IP Address of current user MAC Address MAC Address of current user RX Received Megabytes of data TX Sent Megabytes of data Avg Average Megabytes of usage per...

Page 102: ...Clients MAC Address The MAC Address of DHCP user IP Address The IP Address of DHCP user Note The DHCP Clients table is not an accurate list of subscribers using the service DHCP Clients only shows PCs...

Page 103: ...allows you to monitor the real time usage status of the Gateway Controller by seeing open and ongoing connections to and from the Controller This table allows you to monitor subscriber activity and l...

Page 104: ...n Port number Status Status of the connection Unreplied connections have not received a reply from the destination Assured connections are active connections Source Received source IP address Destinat...

Page 105: ...ser defined label Status Here the menu displays the status of the device IP Address Here the menu displays the Device IP Address MAC Address Here the menu displays the device s MAC address Management...

Page 106: ...124 6 6 SYSLOG This part of the menu displays the system log details for viewing when Local SysLog is enabled In this example debug messages are enabled Screen 32 SysLog The command buttons First Pre...

Page 107: ...S INC ALL RIGHTS RESERVED PAGE 107 OF 124 3 2 9 SYSTEM TOOLS 1 1 MAINTENANCE This menu allows the user manage the device configuration and to upgrade the firmware in this device by using a file via HT...

Page 108: ...e Name Enter the name of firmware image file available on the TFTP Server Upgrade This is a command button Clicking this will upgrade the selected firmware Note You must have a TFTP server running and...

Page 109: ...configuration file Export Configuration Export Click Export to save the current settings to the local system Right click and select the option of Save Target As and save the file to your computer Fac...

Page 110: ...ort to load the user database Export Local User Database Click Export to save the current user database to the local system Right click and select the option of Save Target As and save the file to you...

Page 111: ...the Import button will restore the current pass through entries with the values from the imported file Export Pass through Click Export to save the document setting to the local system Right click an...

Page 112: ...certificate A self signed certificate can be created by combining your key and cert into a single file Clicking the Upload button will upload the certificate to the flash The uploaded certificate is e...

Page 113: ...e password are matching Subscriber Manager A supervisor account can be created in this section and the supervisor is provided with powers to manage the subscribers and view the system status Username...

Page 114: ...L 2011 VALUEPOINT NETWORKS INC ALL RIGHTS RESERVED PAGE 114 OF 124 manage the Controller remotely Dynamic DNS settings will be preserved as well in case the Controller is using DHCP OK Click OK to res...

Page 115: ...GATEWAY CONTROLLER SERIES USER MANUAL 2011 VALUEPOINT NETWORKS INC ALL RIGHTS RESERVED PAGE 115 OF 124 3 2 10 HELP This menu contains helpful information about the Gateway Controller Screen 36 HELP...

Page 116: ...3 2 11 INDEX This menu displays all the menus and submenus of the Controller that configure the system Along with the menu it displays the submenus These submenus come with hyperlinks so you can click...

Page 117: ...ntroller or both the Controller and the PPPoE Cable Modem may restore the WAN connection Make sure the types of the Ethernet cables are correct There are two types normal and crossover If all Network...

Page 118: ...ntries in the routing table Use the Windows Device Manager to disable unnecessary NICs The most common configuration that causes this problem is when the Ethernet and WiFi LAN Cards are both enabled o...

Page 119: ...ss assigned to the Controller o Reset the Controller to Factory Default which will restore the default address The Controller stops working and does not respond o Press the Reset button on the Control...

Page 120: ...GHTS RESERVED PAGE 120 OF 124 o Delete the contents of the web cache under Tools Internet Options Temporary Internet Files Delete Files o Repair the network connection in Windows by right clicking on...

Page 121: ...RxOK TxError RxError Logged in Users Type Information scheduled ID NAS ID Logged in Users Number of logged in users For each user ID NAS ID User username user IP user MAC interface login time RxData...

Page 122: ...e Acct Output Packets Acct Output Octets Acct Input Packets Acct Input Octets Acct Session Time Acct Session ID Acct Terminate Cause Acct Multi Session Id Access Reject Port Limit Used for Per user ba...

Page 123: ...generates uses and can radiate radio frequency energy and if not installed and used in accordance with the instructions may cause harmful interference to radio communications However there is no guar...

Page 124: ...nal to the product such as electric power fluctuations or failure f Use of supplies or parts not meeting our specifications g Normal wears and tears h Any other cause that does not relate to a product...

Reviews: