background image

 

 

Revision: 3.2.1 

Summary of Contents for WS5G2

Page 1: ...Revision 3 2 1...

Page 2: ...and Configuration 6 3 3 Entrance of Web Mode Provision 7 3 4 System Basic 8 3 4 1 Information Overview 8 3 4 2 Quick Setting 8 Chapter 4 Network Configuration 13 4 1 Port Classification 13 4 2 AP Acc...

Page 3: ...r 8 Authentication 60 8 1 OTP SMS Gateway 60 8 2 Portal Server 60 8 3 Radius Server 62 8 4 LDAP Server 64 8 5 MAC Access Control 66 8 6 Access Time Control 67 Chapter 9 Statistics 70 9 1 Thin AP List...

Page 4: ...agement function originally resided in each access point to WLC while the AP only remains its fundamental wireless access and security capabilities Hence the WLC focuses on AP s configuration user aut...

Page 5: ...Fi capabilities are referred to as UEs AP Access Point Base station equipment for STAs to access the wired network or other STAs from the wireless network are referred to as APs TAP Thin Access Point...

Page 6: ...Data Cable Power Cable Yes Yes Yes Plastic Stand For Stack up Yes Yes Yes 10G SPF Optical Transceiver Module LC LC Multi Mode Optical Fiber Note If any of the items mentioned above is not included in...

Page 7: ...g and wireless clients data tunnel which could be a RJ45 port other than the Management Port Console Port The Console Port is for debug or troubleshooting by IT staff USB 2 0 Ports Two USB 2 0 ports w...

Page 8: ...sing port for all Thin APs connecting to WLC while the northbound ports based on WLC internal VLAN Interfaces VIF connect to the Portal Radius for user authentication and Internet for user services Tw...

Page 9: ...ccessed by using any standard Web browsing software like Internet Explorer or Chrome The Web interface simplifies system management and configuration even if the administrator is a junior engineer The...

Page 10: ...tandard Web browser software like Internet Explorer or Chrome using the HTTP HTTPS protocol To access the Web provisioning entering the default IP address 192 168 2 228 accessing in the management por...

Page 11: ...ed immediately after a successful login Figure 3 4 System Information Overview Page In this system information overview page it provides the hardware information and firmware information of WLC and al...

Page 12: ...Quick Setting for WLC These parameters in Quick Setting page are described in details as following Parameter Description Network Configuration WLAN Port IP Address WLAN port is the southbound port fo...

Page 13: ...End IP Addresses The built in DHCP server of WLC uses this IP address pool to allocate IP addresses to thin APs and user clients The start IP and end IP limit the range of available IP addresses DHCP...

Page 14: ...2 4GHz Security There are three types of wireless security provided for 2 4GHz radio module to select o Open System When the wireless client associates with the 2 4GHz radio module only SSID are requi...

Page 15: ...not require encryption o WPA2 PSK When wireless client associates with the 5GHz radio module in thin AP it must be authenticated by WPA2 with the preset PSK key encryption o WPA2 Radius When wireless...

Page 16: ...e 4 1 WLC Port Classification These parameters in Network Port Classification page is described in details as following Parameter Description GE1 This is the default management port for WLC also used...

Page 17: ...southbound interface for establishing the CAPWAP tunnel with thin AP Select Network AP Access Port in the menu to enter the configuration page as following Figure 4 2 AP Access Port Configuration The...

Page 18: ...e parameters modified it is necessary to Save Configuration and then reboot system to make them to take effect 4 3 MANAGEMENT PORT The first 1000Base T RJ45 port that is the GE1 port must be the manag...

Page 19: ...o divide which subnet the WLC is belonged to Click the Apply button to accept the changes Click the Cancel button to discard the changes 4 4 VLAN CREATION If the Wi Fi system is deployed in a VLAN con...

Page 20: ...width during transmission Portal Server Bind the Portal server to the new VLAN so user clients in this VLAN will use this Portal server for authentication Physical Ports Note Only those ports which ha...

Page 21: ...ation page as following Figure 4 6 Physical Ports Page These parameters in Network Port VLAN page is described in details as following Parameter Description Enable ForcedRate This is a switch to disab...

Page 22: ...er 3 virtual interface which is used by WLC upper control plane applications to communicate with the outside world Since the WLC has an underlying data plane for packet forwarding or upward transmissi...

Page 23: ...tivate this VLAN Interface VIF8 This VLAN Interface is default used as WLAN port i e the WLC southbound port for thin AP accessing also called as TAP port The default IP address is 192 168 3 228 Click...

Page 24: ...in Network L2GRE page is described in details as following Parameter Description GRE Port Specify the physical port of WLC as the local peer of L2GRE tunnel Note this must be the port which has been...

Page 25: ...button Total number of L2GRE tunnels for WLC is limited to 4 Each L2GRE tunnel configuration in this table can be modified by selection and then click the Edit button under the table Click the Add Ne...

Page 26: ...re 4 12 IPSec Tunnel Network Configuration Page These parameters in above page are described in details as following Parameter Description Network Settings Enable IPSec VPN If customer needs to use IP...

Page 27: ...enter the next page Figure 4 13 IPSec Tunnel Protected Data Flows Configuration Page These parameters in above page are described in details as following Parameter Description Protected Data Flows Th...

Page 28: ...guration Encryption Algorithm Select one from AES128 AES192 and AES256 according to remote IPSec Gateway configuration Authentication Algorithm Select one from SHA256 SHA384 and SHA512 according to re...

Page 29: ...ay configuration Further after complete this page configuration click Next button to enter the last page Figure 4 15 IPSec Tunnel Configuration Finish Page 4 9 DHCP SETTINGS The Hyperion series WLC ha...

Page 30: ...re to establish the CAPWAP management tunnel Usually one WLC is enough Interface Binding current DHCP server configuration to the port TAP The thin AP port which is the WLAN port for thin AP accessing...

Page 31: ...se time is 3600 seconds Click the Add button to append a new entry to the list Click the Apply button to accept the changes Click the Cancel button to discard the changes Click the Delete button to re...

Page 32: ...e selected entry Click the Edit button to modify the selected entry 4 11 STATIC ROUTE When a data packet is sent to a specific target IP address in a different subnet from the originator since the rou...

Page 33: ...e routing algorithm is based on routing protocols including RIPv1 and OSPF Need to bind dynamic routing to the VLAN interface VIF through which the user service traffic passes and routes to the destin...

Page 34: ...ion DHCP Server page is described in details as following Parameter Description WLC AC IPv6 Address For AP Access Here providing an IPv6 address actually represents the CAPWAP tunnel termination IPv6...

Page 35: ...he IPv6 Router Advertisement messages include unsolicited and solicited The IPv6 routers send unsolicited Router Advertisement RA messages pseudo periodically that is the interval between unsolicited...

Page 36: ...to enable DHCPv6 for other information RA Reachable Time 0 360000 ms This is the Neighbor Discover Reachable time in milliseconds within which the WLC assumes a neighbor is reachable after receiving...

Page 37: ...0 Page 34 Click the Apply button to accept the changes Click the Cancel button to discard the changes Click the Delete button to remove the selected IPv6 router advertisement entry from list Click th...

Page 38: ...h can be combined to implement the provisioning of the thin AP 6 1 AP GROUPING We know that the thin AP is configured by downloading profiles from the WLC through the CAPWAP tunnel However if a profil...

Page 39: ...igured VAP profiles will be listed in the left window for selection Select a VAP profile in left window and then click the button to bind it to the VAP in each radio module Module 1 is the 2 4GHz modu...

Page 40: ...tion file called the common profile There is already a preset common profile with default parameter settings in WLC it can be modified to match the actual application of the customer Customers can als...

Page 41: ...s Wireless LAN Controller User Manual 58 150008 IQN_V1 0 Page 38 Figure 6 4 Create and Edit AP Common Profile Page These parameters in Thin AP Configuration Common Profile page is described in details...

Page 42: ...otocol Select the protocol to match the packet for applying QoS rules o All QoS rule will be applied to all packets o TCP QoS rule will be applied to TCP packet o UDP QoS rule will be applied to UDP p...

Page 43: ...e When the traffic in a thin AP reaches this threshold any new client attempting to associate with this thin AP will be rejected AP Traffic Difference If the balance mode Traffic is selected set the m...

Page 44: ...the rejection time window is shifted off Bluetooth Management Settings This function is for the specific AP to support Apple iBeacon which is the Apple s implementation of Bluetooth low energy BLE wi...

Page 45: ...new wireless profiles for different AP groups Click the Edit button to modify an existing profile in the list Click the Select All button to select all profiles in the list Click the Add New button t...

Page 46: ...derived from 802 11n The latest 802 11 specification supports multiple HT modes including HT20 HT40 HT80 and even HT160 which are integer multiples of the 20MHz bandwidth The larger the suffix number...

Page 47: ...ver each virtual AP may have some parameter settings independent of each other therefore a specific virtual AP configuration file called a VAP Profile must be configured for different virtual APs Sele...

Page 48: ...data traffic bypasses WLC and is forwarded directly from the thin AP to the Internet Service VLAN Assign a service VLAN ID for the virtual AP according to its SSID requirement Note that the VLAN must...

Page 49: ...switch to make the user clients associated to it get free from Web authentication The selection is Yes or No Access Limit Schedule The Access Limit Schedule is used to prohibit the user clients from...

Page 50: ...user client to which you want to apply the bandwidth control Uplink Bandwidth The data transmitting bandwidth of the user client corresponding to this MAC address Downlink Bandwidth The data receivin...

Page 51: ...GRADE In the Wi Fi system with WLC the thin AP can upgrade its firmware through WLC centrally instead of upgrading one at a time It can be done by entering Thin AP Configuration AP Firmware Upgrade Se...

Page 52: ...fect thin APs in all group by overlaying the thin AP its own auto Tx power policy configured in wireless profile as long as the Tx Power Mode in the wireless profile is enabled by the Auto option Auto...

Page 53: ...ed to the thin AP o Traffic The load balancing policy is based on the user traffic pressure in the thin AP Enable Manually Grouping A thin AP usually scans neighbor APs to be automatically grouped If...

Page 54: ...be rejected Users Number Difference Between Modules If Users Number is selected in Enable Spectrum Navigation here to set the users number difference threshold between two radio modules When the diffe...

Page 55: ...d it triggers the channel switching The triggering level can be set by High Medium and Low Enable Manually Grouping Thin AP usually scans neighbor APs to be automatically grouped If manual grouping is...

Page 56: ...as following Figure 7 1 TimeZone and Datetime Configuration Page These parameters in WLC Configuration TimeZone and Date page is described in details as following Parameter Description Device Name As...

Page 57: ...Graphic Statistics Platform Configuration Page These parameters in WLC Configuration Graphic Stat Platform page is described in details as following Parameter Description Enable Graphic Stat Platform...

Page 58: ...re its hard disk spaces with NAS Select WLC Configuration Samba in the menu to enter the configuration page as following Figure 7 3 WLC Samba Configuration Page These parameters in WLC Configuration S...

Page 59: ...ults by analyzing the incoming and outgoing data packets The captured packets can be exported to a specific file for Wireshark to review Select WLC Configuration Packet Capture in the menu to enter th...

Page 60: ...ntion days are configured here Syslog Server IP Address Entering the IP address of the remote Log Server Port Entering the communication port the remote Log Server Log Server List WLC supports multipl...

Page 61: ...assword Restore the password which is set in factory Thin AP Password Setting This is a hyperlink which to the thin AP password setting page FTP Super Password Setting WLC has a built in FTP server fo...

Page 62: ...arameter Description Backup Current Configuration to A Bin File Save current configuration of WLC to a binary file Click the Backup button to start saving Sometimes it needs to click the Refresh butto...

Page 63: ...age as following Figure 8 1 OTP SMS Gateway Configuration Page These parameters in Authentication OTP SMS Gateway page is described in details as following Parameter Description OTP SMS Gateway Select...

Page 64: ...ame for this Portal Server in order to be mnemonic URL Enter the Uniform Resource Locator URL of Portal Server AC Name ACN CTY PRO OPE The full name of WLC in the format of Network Access Site ID NAS...

Page 65: ...dius Server in the menu to enter the configuration page as following Figure 8 3 Radius Server Configuration Page These parameters in Authentication Radius Server page are described in details as follo...

Page 66: ...hreshold for the WLC to determine whether the user authentication is failure If the WLC does not receive a authentication result within this set time it is judged as an authentication failure Authenti...

Page 67: ...r Port Number 1 65535 The protocol port number of the secondary accounting server Secondary Accounting Secret This is the key for WLC to prove that it is a legitimate device of the secondary Accountin...

Page 68: ...s separated by comma User Search Filter A user search filter provides a mechanism for defining the criteria for matching entries in an User Search Request Its syntax supports the and operators and pro...

Page 69: ...CONTROL This is a black and white list based on the MAC address of the user client to allow or prohibit the user client to access the thin AP The user clients in the white list will be allowed to asso...

Page 70: ...ol list by click Add button MAC ACL Search With the radio button of Filter by MAC checked entering a MAC address to be searched in the access control list Access List List the MAC address of each user...

Page 71: ...kes effect for those user clients tagged with specific VLAN ID Name of Limit Time Table Assign a literal name for this Access Time Schedule table in order to be mnemonic VLAN ID If Access Limit Schedu...

Page 72: ...utton to discard the changes Click the Add button to add a new Access Limit Time entry to the table Click the Edit button to modify the selected Access Limit Time in table Click the Delete button to r...

Page 73: ...igure 9 1 Thin AP List Click the Previous and Next buttons to turn page if this list is too big in size 9 2 STATION LIST Station is the user wireless client As long as the user client has associated t...

Page 74: ...ugh the WLC It is very useful for analyzing user behavior This requires the Wi Fi system is operating in the Central Switching mode i e the user traffic is firstly concentrated to WLC and then central...

Page 75: ...ist is too big in size 9 5 REALTIME LOG The real time system log is the current log which shows what is happening in the WLC system Therefore the log information will scroll quickly in the Real time L...

Page 76: ...th 152 mm 197 mm 197 mm Form Factor 1U 1U 1U Weight 2 7 kg 2 7 kg 2 7 kg Ports RJ45 1G 4 6 6 SFP 10G 2 4 CPU QTY 1 1 1 Memory Size 8 GB 16 GB 32 GB Type DDR3 DDR4 DDR4 Storage Primary Size 64 GB 64 GB...

Page 77: ...d as DOA Dead on Arrival after conclusive test within the first 30 days of its shipping date from Z COM After 30 days from the shipping date defective products covered within the warranty are consider...

Page 78: ...uthorities Correct disposal and recycling will help prevent potential negative consequences to the environment and human health For more detailed information about the disposal of your old equipment p...

Reviews: