background image

110752/0310

LANCOM Systems GmbH

Adenauerstr. 20/B2

52146 Würselen

Germany

E-Mail: [email protected]

Internet www.lancom.eu

LANCOM

 1811n Wireless

LANCOM

 1821n Wireless

LANCOM

 1811n Wir

eless 

쮿

 

LANCOM

 1821n Wir

eless

쮿

  

Handbuch

쮿

  

Manual

.

.

.

c

o

n

n

e

c

t

i

n

g  

y

o

u

r  

b

u

s

i

n

e

s

s

110752_LC-18x1n-MANUAL-cover_REV1   1

110752_LC-18x1n-MANUAL-cover_REV1   1

19.03.2010   13:39:26

19.03.2010   13:39:26

Summary of Contents for 1821n Wireless

Page 1: ... eu Internet www lancom eu LANCOM 1811n Wireless LANCOM 1821n Wireless LANCOM 1811n Wireless 쮿 LANCOM 1821n Wireless 쮿 Handbuch 쮿 Manual c o n n e c t i n g y o u r b u s i n e s s 110752_LC 18x1n MANUAL cover_REV1 1 110752_LC 18x1n MANUAL cover_REV1 1 19 03 2010 13 39 26 19 03 2010 13 39 26 ...

Page 2: ...LANCOM 1811n Wireless LANCOM 1821n Wireless ...

Page 3: ...ed trademarks of Microsoft Corp The LANCOM Systems logo LCOS and the name LANCOM are registered trademarks of LANCOM Systems GmbH All other names or descriptions used may be trademarks or registered trademarks of their owners Subject to change without notice No liability for technical errors or omissions Products from LANCOM Systems include software developed by the OpenSSL Project for use in the ...

Page 4: ...des The LANCOM 1811n Wirelessand LANCOM 1821n Wireless provide a maximum wireless LAN performance of up to 300 Mbps thanks to the support of the IEEE 802 11n standard The 802 11n standard includes many new mechanisms such as the use of MIMO 40 MHz channels packet aggregation and block acknowledgement in order to increase the bandwidth available for user applications significantly This allows a mor...

Page 5: ...would additionally like to ask you to refer to our Internet site www lan com eu for the latest information about your product and technical develop ments and also to download our latest software versions Components of the documentation The documentation of your device consists of the following parts Installation Guide User manual Reference manual Menu Reference Guide You are now reading the user m...

Page 6: ...our staff from a variety of departments in order to ensure you the best possible support when using your LANCOM product Should you find any errors or if you would like to suggest improvements ple ase do not hesitate to send an e mail directly to info lancom eu Our online services www lancom eu are available to you around the clock if you have any questions on the content in this manual or if you r...

Page 7: ...1821n Wireless Preface 6 EN Information symbols Very important instructions Failure to observe these may result in damage Important instruction that should be observed Additional information that may be helpful but is not essential ...

Page 8: ... System requirements 26 2 2 1 Configuring the LANCOM devices 26 2 2 2 Operating access points in managed mode 26 2 3 Status displays and interfaces 26 2 3 1 Device connectors 33 2 4 Hardware installation 35 2 5 Software installation 37 2 5 1 Starting the software setup 37 2 5 2 Which software should I install 38 3 Basic configuration 39 3 1 Details you will need 39 3 1 1 TCP IP settings 39 3 1 2 C...

Page 9: ...tructions for WEBconfig 61 6 Providing dial in access 62 6 1 Which details are necessary 62 6 1 1 General information 63 6 1 2 Settings for TCP IP 64 6 1 3 Settings for NetBIOS routing 65 6 2 Settings on the dial in computer 65 6 2 1 Dialing in via VPN 65 6 2 2 Dialing in via ISDN 65 6 3 Instructions for LANconfig 66 6 4 1 Click VPN for LANCOM Advanced VPN Client 66 6 5 Instructions for WEBconfig ...

Page 10: ...ssories 85 9 1 Optional AirLancer Extender antennas 85 9 1 1 Antenna diversity 86 9 1 2 Polarization diversity 86 9 1 3 MIMO 86 9 1 4 Installing the AirLancer Extender antennas 86 9 2 LANCOM Public Spot Option 88 10 Advice assistance 90 10 1 No WAN connection can be established 90 10 2 Slow DSL transmission 90 10 3 Unwanted connections under Windows XP 91 10 4 Cable testing 91 11 Appendix 93 11 1 ...

Page 11: ...ral You can see from the table What your LANCOM can do further below which functions your device supports Please refer to the reference manual for further information on this topic A wireless LAN connects individual end user devices PCs and mobile compu ters to form a local network also called Local Area Network In contrast to a traditional LAN communication takes place over a wireless connection ...

Page 12: ...the main office Please observe the corresponding notices to this in this documenta tion or in the LCOS reference manual 1 1 1 Modes of operation of wireless LANs and access points Wireless LAN technology and access points in wireless LANs are used in the following modes of operation Simple direct connection between terminal devices with an access point ad hoc mode Extensive wireless LANs possibly ...

Page 13: ... gross data rates of up to 54 Mbps which turn out to be approx 22 Mbps net Networks based on 802 11n currently achieve a gross data throughput of up to 300 Mbps in reality approx 120 to 130 Mbps net theoretically the standard defi nes up to 600 Mbps with four data streams For the first time maximum speeds exceed the 100 Mbps of cable based Fast Ethernet networks which are currently standard in mos...

Page 14: ...sical layers describes how data must be transformed in order for them to be transmitted as individual bits over the physical medium In this process the following steps are performed in a wireless LAN device Modulation of digital data into analog carrier signals Modulation of the carrier signal into a radio signal in the selected fre quency band which for a wireless LAN is either 2 4 or 5 GHz The s...

Page 15: ...s increase the maximum useable bandwidth of 54 Mbps for 802 11a g to 65 Mbps for 802 11n This increase is not exactly spectacular but it can be further improved by using the following features MIMO technology MIMO multiple input multiple output is the most important new technology contained in 802 11n MIMO uses several transmitters and several receivers to transmit up to four parallel data streams...

Page 16: ...hese electromagnetic waves are reflected by the surrounding surfaces causing a broadcast signal to reach the WLAN cli ent s antenna over many different paths this is also referred to as multipath propagation Each of these paths has a different length meaning that indivi dual signals reach the client with a different time delay These time delayed signals interfere with each other at the WLAN client...

Page 17: ...receiver decides for itself which of the incoming signals is to be processed thus avoiding loss from interference MIMO thus allows the simultaneous transmission of several signals over one shared medium such as the air Individual transmitters and receivers must be positioned a minimum distance apart from one another although this is just a few centimeters This separation results in differing refle...

Page 18: ...employed that use polarization channels turned through 90 to each other These so called dual slant antennas are really two antennas in one housing Since a third signal does not offer additional reliability outdoor applications generally use as many antennas or polarization channels as there are data streams for transmission 40 MHz channels As the above explanation of OFDM modulation states data th...

Page 19: ... or two channels should be employed As the implementation of 40 MHz with separate control and extension chan nels is more efficient in the 802 11n standard than in the conventional turbo mode more than double the amount of carrier signals can be obtained 108 in total The maximum data throughput when using improved OFDM modu lation and two parallel data streams thus rises to 270 Mbps Short guard in...

Page 20: ...data each data packet in a wireless LAN system contains additional information such as a preamble and MAC address information Time is lost to the management events that occur when the transmission medium is actually accessed Thus the transmitter must negotiate access authorization with the other receivers before transmitting each data packet frame further delays are caused by data packet collision...

Page 21: ... that the packet was received correctly and does not need to be repeated This principle also applies to aggregated frames in 802 11n Two different methods are used for frame aggregation These are not explai ned in detail here but they differ in the way aggregated frames are acknow ledged Mac Service Data Units Aggregation MSDUA combines several Ethernet packets together to form one common wireless...

Page 22: ...net access LAN LAN coupling over VPN LAN LAN coupling over ISDN RAS server over VPN RAS server over ISDN IP router NetBIOS proxy for coupling Microsoft peer to peer networks over ISDN DHCP and DNS server for LAN and DMZ N N mapping for routing networks with the same IP address ranges over VPN Configuring LAN ports as additional WAN ports Policy based routing Load balancing for bundling multiple DS...

Page 23: ...t short guard interval Internal antennas 1 1 External antennas and connectors for AirLancer Extender antennas 2 2 Access point mode Client mode Managed mode for central configuration of WLAN modules by a WLAN Controller Point to point mode six P2P paths can be defined per WLAN interface Turbo mode Double the bandwidth at 2 4 GHz and 5 GHz Super AG incl hardware compression and bursting Multi SSID ...

Page 24: ...ly switchable as a WAN interface for connecting SDSL modems 4 4 USB connector USB 2 0 host port full speed 12 Mbps for connecting a USB printer and for future extensions Security functions IPSec encryption via external software VPN client 5 integrated VPN tunnels for secure network connections IPSec encryption in hardware optional activated with the VPN 25 option IP masquerading NAT PAT to conceal...

Page 25: ...ws Dial Up Networking Serial configuration interface Call back function with PPP authentication mechanisms allowing only predefined ISDN call numbers FirmSafe for no risk firmware updates Optional software extensions LANCOM VPN Option with 25 active tunnels for protection of network couplings and hardware acceleration LANCOM Public Spot Option LANCOM Next Buiness Day Service Extension CPE item no ...

Page 26: ...starting the installation In addition to the base station itself the package should contain the following accessories If anything is missing please contact your retailer or the address stated on the delivery slip of the unit LANCOM 1811n Wireless DSL LANCOM 1821 Wireless ADSL Power adapter LAN connector cable green plugs WAN connector cable dark blue plugs ADSL connector cable transparent plugs IS...

Page 27: ...ode or as components in a WLAN infrastructure which is controlled from a central WLAN Controller managed mode Split management can be used to separate the WLAN configuration from the rest of the router configuration This allows router settings and VPN settings to be adjusted locally for example in a branch office or home office installa tion and the WLAN configuration is regulated by a LANCOM WLAN...

Page 28: ... front panel LANCOM 1811n Wireless LANCOM 1821n Wireless Top The two top mounted LEDs enable the main function status to be assessed even if the device is positioned vertically VPN LANCOM 1811n Wireless WAN Status WAN Status WAN Data WAN Data ETH 1 ETH 1 ETH 2 ETH 2 ETH 3 ETH 3 ETH 4 ETH 4 VPN 1821 Wireless ADSL ADSL Status ADSL Status ETH 1 ETH 1 ETH 2 ETH 2 ETH 3 ETH 3 ETH 4 ETH 4 ADSL Data ADSL...

Page 29: ... perma nently Device operational Red green Blinking alterna tely Device insecure Configuration password not set Orange green In the housing cover blinking alternately with the online LED At least one WLAN module is in managed mode and has not found a WLAN Controller yet The correspon ding WLAN module s is are switched off until a WLAN Controller is found to supply a configuration or until being sw...

Page 30: ...EBconfig charge protection and all parameters are to be found under LCOS menu tree Setup Charges Reset budgets Power Power Signal that a charge or time limit has been reached Off No active connection Green Flashing Opening the first connection Green Inverse flashing Opening an additional connection Green On perma nently At least one connection is established Red On perma nently Error establishing ...

Page 31: ...d red constantly on Error while establishing connection off No network device connected green constantly on Connection to network device operational no data traffic green flickering Data traffic send or receive Off Interface deactivated Green Blinking flashing Handshake training Green Permanently Synchronization successful Red Flickering Error CRC error framing error etc Red On permanently No sync...

Page 32: ...status WLAN Link Provides information about the WLAN connections via the internal WLAN module Off Not connected or no S0 voltage no error message Green Blinking D channel initialization establishing contact to provider Green On perma nently D channel operational Red Flickering D channel error Red On perma nently D channel activation failed off No connection established green Blinking Dialling gree...

Page 33: ...cted WLAN stati ons and P2P wireless connections followed by a pause default Alternatively the frequency of the flashed can indicate the received signal strength of a P2P link or the received signal strength from an access point to which this device is connected in client mode Green Blinking DFS scanning or other scan procedure Red Blinking Hardware error in the WLAN module Green Flickering TX dat...

Page 34: ...not have an external con nector Second Ethernet socket 10 100Base Tx for connection to the LAN Both 10 Mbit or 100 Mbit connections are supported The available transfer rate is detected automatically autosensing LANCOM 1811n Wireless WAN connector USB connector USB host ISDN S0 port Serial configuration port LANCOM 1821n Wireless ADSL port Reset switch Connector for antenna 3 LANCOM 1811n Wireless...

Page 35: ...device Pressing the button for 5 seconds or longer restarts the device and resets the configuration to its factory settings All LEDs on the device light up continuously Once the switch is released the device will restart with the restored factory settings After resetting the device starts completely unconfigured and all set tings are lost If possible be sure to backup the current device confi gura...

Page 36: ...to the threshold values LAN First connect the LANCOM Router base station to your LAN or to an individual PC For that purpose plug the included network cable green plugs into the LAN connector of the device and the other end into a free network connecting socket of your local network into a free socket of a hub switch or into the network socket of an individual PC The LAN connector identifies autom...

Page 37: ...figuration of the print server can be found in the LCOS reference manual Configuration port you may optionally connect the router directly to the serial port RS 232 V 24 of a PC Use the cable supplied for this pur pose Connect the configuration port of the LANCOM with a free serial port of the PC Connect to power Connect socket of the unit to a power supply using the included power adapter Use the...

Page 38: ...ip this section if you use your LANCOM Wireless Router exclusively with computers running operating systems other than Windows 2 5 1 Starting the software setup Place the product CD into your drive The setup program will start automati cally If the setup does not start automatically run AUTORUN EXE in the root directory of the LANCOM CD In Setup select Install software The following selection menu...

Page 39: ...indows computer to monitor all of your LANCOM routers and LANCOM access points WLANmonitor enables the observation and surveillance of wireless LAN networks Clients connected to the access points are shown and even non authenticated access points and clients can be displayed as well rogue AP detection and rogue client detection With Documentation you copy the documentation files onto your PC Selec...

Page 40: ...n ease At the end of this chapter we show you the necessary settings for the work place computers in the LAN so that they can access the device without pro blem 3 1 Details you will need The Basic Settings Wizard is used to set the LANCOM Wireless Routers basic TCP IP parameters and to protect the device with a configuration password The following description of the information required by the wiz...

Page 41: ...P address 172 23 56 254 network mask 255 255 255 0 The integrated DHCP server is also activated so that the LANCOM Wireless Router can assign the devices in the LAN IP addresses automatically Should you still configure manually Fully automatic TCP IP configuration is optional Instead of this you can select manual configuration Make this selection after considering the following Select automatic co...

Page 42: ...omain names if you have selected Off as the DHCP mode of operation or if another network device is assuming the role of DNS server in the Server mode of operation 3 1 2 Configuration protection Using a password secures access to the LANCOM Wireless Router s configu ration and thus prevents unauthorized modification The device s configura tion contains a great deal of sensitive data such as data fo...

Page 43: ... attempting to register with the network name ANY Selecting a radio channel The access point operates in a specific radio channel The radio channel is selected from a list of up to 13 channels in the 2 4 frequency band or up to 19 channels in the 5 GHz frequency band individual radio channels are blocked in some countries Please refer to the appendix for more details The channel and frequency rang...

Page 44: ... Router for cost budgets and the accounting function 3 1 5 Charge protection Charge protection prevents DSL connections being established above and beyond a predefined amount and therefore protects you from unexpectedly high connection charges If you operate the LANCOM Router on a DSL link that is charged on a time basis you can set the maximum connection time in minutes The budget can be complete...

Page 45: ...ration you can continue with step Give the LANCOM an address from the applicable IP address range Con firm with Next In the window that follows you first set the password to the configura tion Entries are case sensitive and should be at least 6 characters long You also define whether the device can be configured from the local net work only or if remote configuration via WAN i e from a remote net ...

Page 46: ...re maximum security Accessing the device with WEBconfig To carry out a configuration with WEBconfig you need to know how to con tact the device Device behavior and accessibility for configuration via a Web browser depend on whether the DHCP server and DNS server are active in the LAN already and whether these two server processes share the assignment in the LAN of IP addresses to symbolic names WE...

Page 47: ...3 56 254 With the factory settings and an activated DHCP server the device for wards all incoming DNS requests to the internal Web server This means that a connection can easily be made to set set up an uncon figured LANCOM by entering any name into a Web browser If the configuration computer does not retrieve its IP address from the LANCOM DHCP server it determines the current IP address of the c...

Page 48: ...base of the device If there is no DNS server in the LAN or if it is not coupled to the DHCP server the device cannot be reached via the name In this case the follo wing options remain Under LANconfig use the function Find devices or under WEBconfig use the search for other devices option from any other networked LANCOM Use suitable tools to find out the IP address assigned to the LANCOM by DHCP an...

Page 49: ...ver HTTPS Always use the HTTPS connection for increa sed security whenever possible Setup Wizards The setup Wizards allow quick and easy configuration of the most common device settings Select the Wizard and enter the appropriate data on the fol lowing screens The settings are not stored in the device until inputs are confirmed on the last screen of the Wizard ...

Page 50: ... and WLAN for devices with a radio module but it also communicates its own IP address as the standard gateway and DNS server For this reason the PCs have to be set up to automatically retrieve their own IP address and those of the standard gateway and DNS server via DHCP IP address allocation by a separate DHCP server For this reason the workstation PCs have to be set up to automatically retrieve ...

Page 51: ...s to be connected to one of the device s ETH ports When set ting up the Internet access you define which ETH port the ADLS modem has been connected to Does the Setup Wizard know your Internet provider The Wizard is preset with access data for the principal Internet providers in your country and offers you a selection list If you find your Internet provider in this list then you generally do not ha...

Page 52: ...d in such cases can close the connection before the hold time expires In case of flatrate billing you can also set up line polling to monitor the function of the remote site Apart from that you can opt to keep flatrate connections permanently active keep alive In case a connection should fail it is re estab lished automatically Dynamic channel bundling ISDN only If required the second ISDN B chann...

Page 53: ...ine select Extras Setup Wizard In the selection menu select the Setup Wizard Set up Internet connec tion and confirm the selection with Next In the following windows you select your country your Internet provider if possible and you enter your access data Depending on availability the Wizard provides further options for your Internet connection After entering all of the necessary data the Wizard t...

Page 54: ...your UMTS provider for informa tion on limitations that may apply The Wizard will inform you as soon as the entries are complete Close the configuration with Finish 4 1 2 Instructions for WEBconfig Select the entry Set up Internet connection from the main menu In the following windows you select your country your Internet provider if possible and you enter your access data Depending on availabilit...

Page 55: ...ctivity must be configured Note that the configuration information at both ends must match The following instructions assume that LANCOM Routers are being operated at both ends It is possible to set up network connectivity between routers from other manufacturers However this mixed con figuration frequently requires far reaching modifications to both devices In cases like this refer to the Referen...

Page 56: ...y is required via VPN simple method with pre shared keys and or via ISDN For further information on VPN based network connectivity by other methods refer to the LANCOM Reference Manual Connecti vity Entry Gateway 1 Gateway 2 VPN Does the remote site have an ISDN connec tion Yes No Yes No VPN Type of local IP address Static dynamic Static dynamic VPN Type of remote IP address Static dynamic Static ...

Page 57: ... will cause your LANCOM to be renamed Ensure that you give different names to the two remote devices The name of the remote site is required for identifying the devices In the field ISDN number the telephone number of the remote ISDN site is specified Enter the full telephone number for the remote site including all necessary prefixes e g area codes The ISDN calling line ID specified is used to id...

Page 58: ... for the TCP IP router In the TCP IP network correct addressing is of extreme importance For net work connectivity it should be observed that both networks are logically separated For this reason they require their own network number e g 10 0 1 x and 10 0 2 x The two network numbers must be different Unlike with Internet access network connectivity makes all of IP addresses visible in all particip...

Page 59: ...de visible from the remote LAN not with their own IP address but with a freely definable address such as that of the VPN gateway This avoids giving stations in a remote LAN direct access to the computers in your own LAN For example if extranet VPN mode is set up to provide access from the branch office LAN to the main office from the IP address 10 10 2 100 and computer 10 10 2 10 then accesses the...

Page 60: ...p of both routers you can start testing the network connection Try to communicate with a computer in the remote LAN e g with ping The LANCOM Router should automatically connect to the remote site and make contact to the requested computer Ping the quick test of a TCP IP con nection To test a TCP IP connection simply send a ping from your computer to a computer in the remote network Details on the ...

Page 61: ...izard It is even possible to simultaneously couple multiple routers to a central network In LANconfig mark the routers at branch offices which are to be coupled to a central router via VPN Use drag drop by mouse to place the devices onto the entry for the cen tral router The 1 Click VPN Site to Site Wizard will be started Enter a name for this access and select the address under which the router i...

Page 62: ...he device properties 5 4 Instructions for WEBconfig In WEBconfig VPN based network connectivity cannot be set up in the Wizard The manual configuration has to be used instead Refer to the reference manual for information on this Carry out the configuration on both routers one after the other In the main menu launch the Wizard Connect two local area networks Follow the Wizard s instructions and ent...

Page 63: ...e The dial in computer needs an ISDN adapter or an ISDN modem The protocol of data transfer is PPP This ensures that all normal devices and operating systems are supported Setting up dial in access is carried out with the familiar convenience of a Setup Wizard Security aspects Of course your LAN has to be protected from unauthorized access For this reason a LANCOM provides a range of security mech...

Page 64: ... dialing in Incoming number The optional ISDN calling line ID is used by the LANCOM Router for additional user authentication This security function should not be employed if the user will be dialing in from various ISDN connections Connecti vity Entry VPN ISDN User name VPN ISDN Password VPN Shared Secret for encryption VPN Hide own stations when accessing remote network extranet VPN ISDN Incomin...

Page 65: ... both manual and automatic IP address assignment ensure that the addresses are freely available in your local network In our example the PC is assigned with the IP address 10 0 1 101 when it dials in This IP address allows the PC to fully participate in the LAN With the appro priate rights it can access any other device in the LAN This relationship also applies in the other direction The remote PC...

Page 66: ... you a 30 day test version of the LANCOM Advanced VPN Client on the CD supplied A precise description of the VPN client and notes on its setup are also to be found on the CD The Wizard then requests the parameters that were specified when setting up the RAS access in the LANCOM Router 6 2 2 Dialing in via ISDN A number of settings are required by the dial in computer This example is based on a Win...

Page 67: ...h Finish Configure the access account on the dial in PC as described Subsequently test the connection see box Ping the quick test of a TCP IP connec tion 6 4 1 Click VPN for LANCOM Advanced VPN Client VPN accesses for employees who dial into the network with the LANCOM Advanced VPN Client are very easy to set up with the Setup Wizard and expor ted to a file This file can then be imported as a prof...

Page 68: ...t can be used by other appli cations to send e mails When setting up the VPN access certain settings are made to optimize ope rations with the LANCOM Advanced VPN Client including Gateway If defined in the LANCOM VPN Router a DynDNS name is used here or alternatively the IP address FQDN Combination of the name of the connection a sequential number and the internal domain in the LANCOM VPN Router D...

Page 69: ...structions for WEBconfig In the main menu launch the Wizard Provide remote access RAS Fol low the Wizard s instructions and enter the necessary data Configure the access account on the dial in PC as described Subsequently test the connection see box Ping the quick test of a TCP IP connec tion ...

Page 70: ...ring machines online banking and eurofile transfer All functions are supplied via the network without the necessity of additional hardware at each individual workstation thus eliminating the costs of equipping the worksta tions with ISDN adapters or modems All you need do is install the office com munications software on the individual workstations With LANCAPI by LANCOM it is possible to send fax...

Page 71: ...COM CAPI Faxmodem and MS Win dows fax service 7 1 Installation of the LANCOM CAPI Faxmodem Select the entry Install LANCOM software in the setup program of your LANCOM CD Highlight the option CAPI Faxmodem click Next and follow the instruc tions of the installation routine ISDN PC PC PC ROUTER FAX LANCOM with LANCAPI Server PCs with faxsoftware LANCAPI Client CAPI Faxmodem and MS Windows fax servi...

Page 72: ...to the Phone and Modem Options of the control panel 7 2 Installation of the MS Windows fax service Select the option Printers and Faxes from the control panel Select the option Set up faxing from the window Printers and Fax Fol low if necessary the instructions of the installation tool Into the recent window an icon will appear for the newly installed fax printer ...

Page 73: ...le you can send it directly from your respective application If you only want to send a short message select the MS Windows fax service You can use of course any other fax software alternatively 7 3 1 Send a fax with any given office application Open as usual a document in your office application and select the menu item File Print Adjust the fax device as printer Click on OK A wizard appears that...

Page 74: ... 1811n Wireless LANCOM 1821n Wireless Chapter 7 Sending faxes with LANCAPI 73 EN The fax client console will open Select the menu item Send a Fax A wizard will assist you through the remaining sending process ...

Page 75: ...rase Security LEPS Access control by MAC address Optional IPSec over WLAN VPN 8 1 1 Encrypted data transfer Encryption takes on a special role in the transfer of data in wireless LANs Wireless communication with IEEE 802 11 is supplemented with the the encryption standards 802 11i WPA and WEP The aim of the encryption methods is to provide wireless LAN with levels of security equivalent to those i...

Page 76: ...ty with older WLAN clients regularly change the WEP key in your access point If the data is of a high security nature further improvements include addi tionally authenticating the client with the 802 1x method 802 1x EAP page 77 or activate an additional encryption of the WLAN connection as used for VPN tunnels IPSec over WLAN page 78 In special cases a combination of these two mechanisms is possi...

Page 77: ...ion consists of the first letter L follo wed by the LAN MAC address of the access point in ASCII characters The LAN MAC addresses of the LANCOM devices always begin with the character string 00A057 You will find the LAN MAC address on a sticker on the base of the device Only use the number labeled as MAC address that starts with 00A057 The other numbers that may be found are not the LAN MAC addres...

Page 78: ... additional column in the ACL to assign an individual passphrase consisting of any 4 to 64 ASCII characters to each MAC address The connection to the access point and the subsequent encryp tion with IEEE 802 11i or WPA is only possible with the right combination of passphrase and MAC address LEPS can be used locally in the device and can also be centrally managed with the help of a RADIUS server a...

Page 79: ...PN support and the LANCOM Advanced VPN Client that operates under Windows 2000 XP and Windows Vista Client software from third parties is available for other operating systems 8 2 Tips for the proper treatment of keys and passphra ses By observing a few vital rules on the treatment of keys you can significantly increase the security of encryption techniques Keep your keys as secret as possible Nev...

Page 80: ...e configuration for a fixed period You can modify the critical number of attempts and also the duration of the lock By default the device locks for five minutes after five incorrect entries of the password Along with these basic settings you can use the Security settings Wizard to check the settings of your wireless network if so equipped 8 3 1 LANconfig Wizard Mark your LANCOM in the selection wi...

Page 81: ... security settings Wizard to check and change any settings The following values are edited Device password The protocols to be available for accessing the configuration from local and remote networks The parameters for locking the configuration the number of incorrect password entries and the duration of the lock Security parameters such as WLAN name closed network function WPA passphrase WEP key ...

Page 82: ... permit or prevent individual cli ents accessing your wireless LAN The decision is based on the MAC address that is permanently programmed into wireless network adapters To check the access control list go to the configuration area in LANconfig and select WLAN security on the Stations tab The LANCOM Enhanced Passphrase Security LEPS uses an additional column in the ACL to assign an individual pass...

Page 83: ... The stateful inspection firewall of LANCOM devices ensures that you local network cannot be attacked from the outside Activate the firewall in LANconfig under Firewall QoS on the General tab Note that firewall security mechanisms incl IP masquerading port filters access lists are active only for data connections that are trans mitted via the IP router Direct data connections via the bridge are no...

Page 84: ...ration sessions via LANconfig WEBconfig Telnet or TFTP As standard this table contains no entries meaning that computers with any IP address can use TCP IP and Telnet or TFTP to commence accessing the device The first time an IP address is entered with its associated netmask the filter is activated and only the IP addresses contained in this entry are entitled to make use of internal functions Fur...

Page 85: ...ng switched on the device calls itself at the corresponding telephone number to check that it is still con nected to the correct ISDN connection for further information see the reference manual The scripting function can store the entire configuration in RAM only so that restarting the device will cause the configuration to be deleted The configuration is not written to the non volatile flash memo...

Page 86: ...ns An over view of the supported antennas is available from the LANCOM Web site under www lancom eu You will also find further information on calculating the best configu ration for AirLancer Extender antennas and third party antennas that you wish to connect to the device in the LANCOM Antenna Calculator which can be downloaded from our Web site at www lancom eu When assembling separately purchas...

Page 87: ...same unit for the transmission to the client Antenna diversity ensures that the various clients associated with the Access Point always use the send receive unit with the best signal 9 1 2 Polarization diversity Other diversity techniques process the two signals and combine them into a single signal The most common methods are space diversity and polarization diversity LANCOM Systems supplies vari...

Page 88: ...ternet Wireless LAN technology is ideal for offering wireless Internet services to the public in locations such as airports railway stations restaurants or cafes via so called HotSpots The LANCOM Public Spot Option is intended for operators of public wireless networks It enables the easy installation and maintenance Please note the following when connecting antennas The configuration of the device...

Page 89: ...hentication authorization accounting This is remedied by the LANCOM Systems Open User Authentication OUA the core component of the LANCOM Public Spot Option OUA implements the authentication of all wireless clients by user name and password It checks the authorization of each user with a RADIUS server Accounting data online time volumes on a per user and per session basis can be passed on to the c...

Page 90: ...LANCOM 1811n Wireless LANCOM 1821n Wireless Chapter 9 Options and accessories 89 EN ...

Page 91: ...viders If your DSL provider is unknown to the Wizard you have to set the protocol yourself The protocol specified by your DSL provider should work without pro blem You can check and adjust your protocol settings under LANconfig Communication General Communication layers WEBconfig LCOS Menu Tree Setup WAN module Layer list 10 2 Slow DSL transmission The speed of data transmission over an Internet D...

Page 92: ...rs attempt to update the time by acces sing a time server in the Internet For this reason Windows XP computers booting in the WLAN cause the LANCOM to connect to the Internet To prevent Windows XP computers from automatically synchronising the time right click on the time Change time date Internet time off 10 4 Cable testing A cabling defect might have occurred if no data is transmitted over LAN o...

Page 93: ...idual interfaces are show up in a list The following results can occur OK Cable plugged in correctly line ok open with distance 0m No cable plugged in or interruption within less than 10 meters distance open with indication of distance Cable is plugged in but defect short circuited at the indicated distance Impedance error The pair of cables is not terminated with the correct impedance at the othe...

Page 94: ... your country for operating antenna systems Information about the calculation of conforming antenna configurations under www lancom eu Outband serial V 24 V 28 port 8 pol mini DIN Power supply 12V DC over external power adapter or PoE compliant with IEEE 802 3af Permitted power supplies NEST 12V 1A DC S Hohlstkr 2 1 5 5mm RoHS LANCOM item no 110524 Type identification on the power supply Type 15 2...

Page 95: ... Art no 61214 AirLancer Extender O 30 2 4 GHz outdoor antenna Art no 60478 AirLancer Extender O 70 2 4 GHz outdoor antenna Art no 60469 AirLancer Extender O D80g 2 4GHz polarizations diversity outdoor antenna Art no 61221 AirLancer Extender O 360ag dualband omnidirectionaloutdoor antenna Art no 61223 AirLancer Extender O 18a 5 GHz outdoor antenna Art no 61210 AirLancer Extender O D60a 5GHz polariz...

Page 96: ...1 2 Connector wiring 11 2 1 Ethernet interface 10 100Base TX 8 pin RJ45 sockets ISO 8877 EN 60603 7 11 2 2 ADSL interface Only LANCOM 1821n Wireless 6 pin RJ11 socket Connector Pin Line 1 T 2 T 3 R 4 PoE G 5 PoE G 6 R 7 PoE 48 V 8 PoE 48 V Connector Pin IAE 1 2 3 a 4 b 5 6 ...

Page 97: ...pter 11 Appendix 96 EN 11 2 3 DSL interface LANCOM 1811n Wireless only 6 pin RJ45 socket 11 2 4 ISDN S0 interface 8 pin RJ45 socket ISO 8877 EN 60603 7 Connector Pin IAE 1 T 2 T 3 R 4 5 6 R Connector Pin Line IAE 1 2 3 T 2a 4 R 1a 5 R 1b 6 T 2b 7 8 ...

Page 98: ...ms herewith declares that the devices of the type described in this documentation are in agreement with the basic requirements and other relevant regulations of the 1995 5 EC directive The CE declarations of conformity for your device are available for download on the LANCOM Systems web site www lancom eu Connector Pin Line 1 CTS 2 RTS 3 RxD 4 RI 5 TxD 6 DSR 7 DCD 8 DTR U GND ...

Page 99: ...mon ISDN Application Programming Interface CAPI 69 Configuration access 44 Configuration file 83 Configuration interface 24 Connector cable 25 Configuration password 81 Configuration port 33 Configuration protection 23 41 Connector wiring 95 ADSL interface 95 Configuration port 97 DSL interface 96 ISDN S0 interface 96 LAN interface 95 Outband 97 Cost budget 43 D Declaration of conformity 97 Defaul...

Page 100: ...4 Dial in number 51 Dynamic channel bundling 51 MSN 43 S0 port 33 ISDN calling line ID 56 63 64 ISDN connection Basic settings 43 ISDN data compression 51 ISDN leased line option 22 ISDN modem 62 ISDN number 56 ISDN PBX 43 ISDN S0 connection 23 L LAN Connector cable 25 LAN connection 33 LANCAPI 22 43 LANCOM Enhanced Passphrase Security 74 LANCOM Public Spot Option 88 LANCOM VPN Option 24 LANconfig...

Page 101: ...S 65 Server 21 Setup 62 Specify MSN 43 TCP IP 64 User name 63 Windows workgroup search 65 Remote configuration 44 Remote configuration via ISDN 24 Reset switch 33 Reset the toll protection 29 Routing table 83 S SDSL modem 23 Security Protecting the configuration 74 Security checklist 80 Security settings 90 self sufficient 11 26 SNMP Configuration protection 82 Software installation 37 SSID 42 44 ...

Page 102: ... EN Turbo Mode 22 U UDP 83 V Virtual Private Networks VPN 21 VPN client 65 W WAN Connector cable 25 WAN Anschluss 33 WEBconfig 45 HTTPS 45 System requirements 26 WEP 22 74 79 80 Windows workgroup search 58 Wireless LANs Operating modes 11 WPA 22 74 77 80 ...

Reviews: