background image

 

1

 

 

LevelOne 

 

WBR-5400

 

 

MIMO Wireless 1W,4L Broadband Router 

 

            User`s Manual

 

Ver 1.00-0512

Содержание WBR-5400

Страница 1: ...1 LevelOne WBR 5400 MIMO Wireless 1W 4L Broadband Router User s Manual Ver 1 00 0512 ...

Страница 2: ...found to comply with the limits for a Class B digital device pursuant to Part 15 of the FCC Rules These limits are designed to provide reasonable protection against radio interference in a commercial environment This equipment can generate use and radiate radio frequency energy and if not installed and used in accordance with the instructions in this manual may cause harmful interference to radio ...

Страница 3: ... 4 2 STATUS 14 4 3 WIZARD 15 4 4 BASIC SETTING 17 4 4 1 Primary Setup WAN Type Virtual Computers 18 4 5 FORWARDING RULES 34 4 5 1 Virtual Server 35 4 5 2 Special AP 37 4 5 3 Miscellaneous Items 38 4 6 SECURITY SETTINGS 39 4 6 1 Packet Filter 40 4 6 2 Domain Filter 45 4 6 3 URL Blocking 47 4 6 4 MAC Address Control 49 4 6 5 Miscellaneous Items 51 4 7 ADVANCED SETTINGS 53 4 7 1 System Time 53 4 7 2 ...

Страница 4: ...4 APPENDIX B 802 1X SETTING 76 APPENDIX C RESET TO FACTORY DEFAULT 82 RESET TO FACTORY DEFAULT 82 ...

Страница 5: ...ic IP with Road Runner Firewall All unwanted packets from outside intruders are blocked to protect your Intranet DHCP server supported All of the networked computers can retrieve TCP IP settings automatically from this product Web based configuring Configurable through any networked computer s web browser using Netscape or Internet Explorer Virtual Server supported Enable you to expose WWW FTP and...

Страница 6: ...overage and fully compatible with 802 11g and 802 11b Security functions Packet filter supported Packet Filter allows you to control access to a network by analyzing the incoming and outgoing packets and letting them pass or halting them based on the IP address of the source and destination Domain Filter Supported Let you prevent users under this device from accessing specific URLs URL Blocking Su...

Страница 7: ...info by mail Dynamic dns Supported At present the router has 3 ddns dyndns TZO com and dhs org SNMP Supported The router supports basic SNMP function Routing Table Supported Now the router supports static routing Schedule Rule supported Customers can control some functions like virtual server and packet filters when to access or when to block Other functions UPNP Universal Plug and Play Supported ...

Страница 8: ...linking STATUS is flashed once per second to indicate system is alive On The WAN port is linked WAN WAN port activity Green Blinking The WAN port is sending or receiving data WLAN Wireless activity Green Blinking Sending or receiving data via wireless On An active station is connected to the corresponding LAN port Link 1 4 Link status Green Blinking The corresponding LAN port is sending or receivi...

Страница 9: ...ear Panel Ports Port Description PWR DC Power inlet WAN the port where you will connect your cable or DSL modem or Ethernet router Port 1 4 the ports where you will connect networked computers and other devices ...

Страница 10: ...e LAN ports of this product b Wireless LAN connection locate this product at a proper position to gain the best transmit performance Figure 2 3 Setup of LAN and WAN connections for this product 3 Setup WAN connection Prepare an Ethernet cable for connecting this product to your cable xDSL modem or Ethernet backbone Figure 2 3 illustrates the WAN connection 4 Power on Connecting the power cord to p...

Страница 11: ...lly that is via DHCP server of this product After installing the TCP IP communication protocol you can use the ping command to check if your computer has successfully connected to this product The following example shows the ping procedure for Windows 95 platforms First execute the ping command ping 192 168 123 254 If the following messages appear Pinging 192 168 123 254 with 32 bytes of data Repl...

Страница 12: ...l l le e es s ss s s B B Br r ro o oa a ad d db b ba a an n nd d d R R Ro o ou u ut t te e er r r This product provides Web based configuration scheme that is configuring by your Web browser such as Netscape Communicator or Internet Explorer This approach can be adopted in any MS Windows Macintosh or UNIX based platforms ...

Страница 13: ...ion is established you will see the web user interface of this product There are two appearances of web user interface for general users and for system administrator To log in as an administrator enter the system password the factory setting is admin in the System Password field and click on the Log in button If the password is correct the web appearance will be changed into administrator configur...

Страница 14: ... on the Sidenote column You can click this button to renew or release IP manually B Statistics of WAN enables you to monitor inbound and outbound packets Note After successful login you can switch the language in the Web based user interface There are four languages available which are English Deutsh Chinese and Korean Please select the language by clicking the option on the top right corner ...

Страница 15: ... Wizard will guide you through a basic configuration procedure step by step Press Next Setup Wizard will automatically detect your WAN type If WAN type can not be detected successfully Dynamic IP Address will be assigned ...

Страница 16: ...16 Setup Wizard Select WAN Type For detail settings please refer to 4 4 1 primary setup For the rest of the steps Setup Wizard will guide you through a basic configuration Press Next ...

Страница 17: ...17 4 4 Basic Setting ...

Страница 18: ...18 4 4 1 Primary Setup WAN Type Virtual Computers Press Change ...

Страница 19: ... ISP 4 4 1 2 Dynamic IPAddress 1 Host Name optional Required by some ISPs for example Home 2 Renew IP Forever this feature enables this product to renew your IP address automatically when the lease time is expiring even when the system is idle 4 4 1 3 Dynamic IPAddress with Road Runner Session Management e g Telstra BigPond 1 LAN IP Address is the IP address of this product It must be the default ...

Страница 20: ...rd your ISP assigned to you If you don twant to change the password keep it empty 3 Connection ID optional Input the connection ID if your ISP requires it 4 Maximum Idle Time the time of no activity to disconnect your PPTP session Set it to zero or enable Auto reconnect to disable this feature If Auto reconnect is enabled this product will connect to ISP automatically after system is restarted or ...

Страница 21: ...ress 3 Server IP Address the IP address of the L2TP server 4 L2TP Account and Password the account and password your ISP assigned to you If you don t want to change the password keep it empty Maximum Idle Time the time of no activity to disconnect your L2TP session Set it to zero or enable Auto reconnect to disable this feature If Auto reconnect is enabled this product will automatically connect t...

Страница 22: ...ws you to setup the one to one mapping of multiple global IP address and local IP address Global IP Enter the global IP address assigned by your ISP Local IP Enter the local IP address of your LAN PC corresponding to the global IP address Enable Check this item to enable the Virtual Computer feature ...

Страница 23: ...23 4 4 2 DHCP Server Press More ...

Страница 24: ...oose Disable or Enable 2 Lease Time this feature allows you to configure IP s lease time DHCP client 3 IP pool starting Address IP pool ending Address Whenever there is a request the DHCP server will automatically allocate an unused IP address from the IP address pool to the requesting computer You must specify the starting and ending address of the IP address pool 4 Domain Name Optional this info...

Страница 25: ...io channel number The permissible channels depend on the Regulatory Domain The factory setting is as follow channel 11 for North America channel 13 for European ETSI channel 14 for Japan WEP Security Select the data privacy algorithm you want Enabling the security can protect your data while it is transferred from one station to another The standardized IEEE 802 11 WEP 128 or 64 bit is used here W...

Страница 26: ...eless user must authenticate to this router first to use the Network service RADIUS Server IP IP address or the 802 1X server s domain name RADIUS port The port setting of 802 1X server RADIUS Shared Key Key value shared by the RADIUS server and this router This key value is consistent with the key value in the RADIUS server ...

Страница 27: ...encryption methods TKIP and AES 1 Select Preshare Key Mode 2 Fill in the key Ex 12345678 Pre share Key Mode Either ASCII or HEX can be selected Pre share Key Please input either 32 ASCII characters or 64 Hexadecimal digits as Pre share key ...

Страница 28: ...bled the Wireless user must authenticate to this router first to use the Network service RADIUS Server IP address or the 802 1X server s domain name RADIUS Shared Key Key value shared by the RADIUS server and this router This key value is consistent with the key value in the RADIUS server ...

Страница 29: ...tion key must be entered manually You can input either 32 ASCII characters or 64 Hexadecimal digits as Pre share key Pre share Key Mode Either ASCII or HEX can be selected Pre share Key Please input either 32 ASCII characters or 64 Hexadecimal digits as Pre share key ...

Страница 30: ...encryption key is got from RADIUS Server dynamically RADIUS Server IP The 802 1X server s IP address RADIUS port The 802 1X server s service port RADIUS Shared Key Key value shared by the RADIUS server and this router This key value is consistent with the key value in the RADIUS server ...

Страница 31: ...share key encryption key must be entered manually You can input either 32 ASCII characters or 64 Hexadecimal digits as Pre share key Pre share Key Mode Either ASCII or HEX can be selected Pre share Key Please input either 32 ASCII characters or 64 Hexadecimal digits as Pre share key ...

Страница 32: ...IUS Server The encryption key is got from RADIUS Server dynamically RADIUS Server IP The 802 1X server s IP address RADIUS port The 802 1X server s service port RADIUS Shared Key Key value shared by the RADIUS server and this router This key value is consistent with the key value in the RADIUS server ...

Страница 33: ...33 4 4 4 Change Password You can change Password here We strongly recommend you to change the system password for security reason ...

Страница 34: ...34 4 5 Forwarding Rules ...

Страница 35: ...ort will be redirected to the Private Port of assigned computer specified by the Server IP Virtual Server can work with Scheduling Rules and give user more flexibility on Access control For Detail please refer to Scheduling Rule For example if you have an FTP server port 21 at 192 168 123 1 a Web server port 80 at 192 168 123 2 and a VPN server at 192 168 123 6 then you need to specify the followi...

Страница 36: ...68 123 7 192 168 123 10 and 192 168 123 77 You can assign different public port to different IP The public port can be set at any port But please must avoid the confliction And anyone who would like to connect must be aware of the port difference Public Port Private Server IP Enable 777 80 192 168 123 7 V 888 80 192 168 123 10 V 999 80 192 168 123 77 V ...

Страница 37: ...ations fails to make an application work try setting your computer as the DMZ host instead 1 Trigger the outbound port number issued by the application 2 Incoming Ports when the trigger packet is detected the inbound packets sent to the specified port numbers are allowed to pass through the firewall This product provides some predefined settings Select your application and click Copy to to add the...

Страница 38: ... way communication for Internet games Video conferencing Internet telephony and other special applications NOTE This feature should be used only when needed Non standard FTP port You have to configure this item if you want to access an FTP server whose port number is not 21 This setting will be lost after rebooting UPnP Setting Enable or disable the UPnP function of WBR 5400 ...

Страница 39: ...39 4 6 Security Settings ...

Страница 40: ...he two filtering policies 1 Allow all to pass except those match the specified rules 2 Deny all to pass except those match the specified rules You can specify 8 rules for each direction inbound or outbound For each rule you can define the following Source IP address Source port address Destination IP address Destination port address Protocol TCP or UDP or both Use Rule For source or destination IP...

Страница 41: ...re flexibility on Access control For Detail please refer to Scheduling Rule Each rule can be enabled or disabled individually Inbound Filter To enable Inbound Packet Filter click the check box next to Enable in the Inbound Packet Filter field Suppose you have SMTP Server 25 POP Server 110 Web Server 80 FTP Server 21 and News Server 119 defined in Virtual Server or DMZ Host Example 1 1 2 3 100 1 2 ...

Страница 42: ...ple 2 1 2 3 100 1 2 3 119 They can do everything except read net news port 119 and transfer files via FTP port 21 Others are all allowed After Inbound Packet Filter setting is configured click the save button ...

Страница 43: ...tbound Packet Filter field Example 1 192 168 123 100 192 168 123 149 They are allowed to send mail port 25 receive mail port 110 and browse Internet port 80 port 53 DNS is necessary to resolve the domain name 192 168 123 10 192 168 123 20 They can do everything block nothing Others are all blocked ...

Страница 44: ...2 192 168 123 100 192 168 123 119 They can do everything except read net news port 119 and transfer files via FTP port 21 Others are allowed After Outbound Packet Filter setting is configured click the save button ...

Страница 45: ...ion when someone accesses the specific URLs Privilege IPAddresses Range Setting a group of hosts and privilege these hosts to access network without restriction Domain Suffix A suffix of URL to be restricted For example com xxx com Action When someone is accessing the URL met the domain suffix what kind of action you want Check drop to block the access Check log to log these access Enable Check to...

Страница 46: ...tion will be record in log file 2 URL include www sina com will not be blocked but the action will be record in log file 3 URL include www google com will be blocked but the action will not be record in log file 4 IP address X X X 1 X X X 20 can access network without restriction ...

Страница 47: ...to input a keyword only In other words Domain filter can block specific website while URL Blocking can block hundreds of websites by simply a keyword URL Blocking Enable Checked if you want to enable URL Blocking URL If any part of the Website s URL matches the pre defined word the connection will be blocked For example you can use pre defined word sex to block all websites if their URLs contain p...

Страница 48: ...ction will be record in log file 2 URL include sina will be blocked and the action will be record in log file 3 URL include cnnsi will be blocked and the action will be record in log file 4 URL include espn will be blocked and the action will be record in log file ...

Страница 49: ... If a client is denied to connect to this device it means the client can t access to the Internet either Choose allow or deny to allow or deny the clients whose MAC addresses are not in the Control table please see below to connect to this device Association control Check Association control to enable the controlling of which wireless client can associate to the wireless LAN If a client is denied ...

Страница 50: ... allow the corresponding client to connect to this device A When Association control is checked check A will allow the corresponding client to associate to the wireless LAN In this page we provide the following Combobox and button to help you to input the MAC address You can select a specific client in the DHCP clients Combobox and then click on the Copy to button to copy the MAC address of the cl...

Страница 51: ...net mask bits nn notation to specified a group of trusted IP addresses For example 10 1 2 0 24 NOTE When Remote Administration is enabled the web server port will be shifted to 88 You can change web server port to other port too Administrator Time out The time of no activity to logout automatically Set it to zero to disable this feature Discard PING from WAN side When this feature is enabled any h...

Страница 52: ...detect and log the DoS attack comes from the Internet Currently the router can detect the following DoS attack SYN Attack WinNuke Port Scan Ping of Death Land Attack etc VPN PPTP IPSec Pass Through Please enable this feature if you need to establish a PPTP or IPSEC connection that will pass through this device ...

Страница 53: ...53 4 7 Advanced Settings 4 7 1 System Time ...

Страница 54: ...s device locates Get Date and Time using PC s Date and Time Selected if you want to synchronize the router time setting with your connected PC Set Date and Time manually Selected if you want to Set Date and Time manually Daylight Saving Select and configure the daylight saving period to fit the local environment Function of Buttons Sync Now Synchronize system time with network time server ...

Страница 55: ...unction E mail Alert Enable Check if you want to enable Email alert send syslog via email SMTP Server IP Port Input the SMTP server IP and port which are concated with If you do not specify port number the default value is 25 For example mail your_url com or 192 168 1 100 26 E mail addresses The recipients who will receive these logs You can assign more than 1 recipient using or to separate these ...

Страница 56: ...h time you connect your Internet service provider Before you enable Dynamic DNS you need to register an account on one of these Dynamic DNS servers that we list in provider field To enable Dynamic DNS click the check box next to Enable in the DDNS field Next you can enter the appropriate information about your Dynamic DNS Server You have to define Provider Host Name Username E mail Password Key Yo...

Страница 57: ...57 Example After Dynamic DNS setting is configured click the save button The new settings will be effective after reboot ...

Страница 58: ...emote or both to enable SNMP function If Local is checked this device will response request from LAN If Remote is checked this device will response request from WAN Get Community Setting the community of GetRequest your device will response Set Community Setting the community of SetRequest your device will accept WAN Access IPAddress WBR 5400 will only respond the SNMP packet to the device with th...

Страница 59: ...59 Example 1 This device will response to SNMP client which s get community is set as public 2 This device will response to SNMP client which s set community is set as private ...

Страница 60: ... allow packets to find proper routing path and allow different subnets to communicate with each other Routing Table settings are settings used to setup the functions of static Static Routing For static routing you can specify up to 8 routing rules You can enter the destination IP address subnet mask gateway hop for each routing rule and then enable or disable the rule by checking or unchecking the...

Страница 61: ...8 123 103 1 ˇ So if for example the client3 wanted to send an IP data gram to 192 168 0 2 it would use the above table to determine that it had to go via 192 168 123 103 a gateway And if it sends Packets to 192 168 1 11 will go via 192 168 123 216 Each rule can be enabled or disabled individually After routing table setting is configured click the save button ...

Страница 62: ...62 4 7 6 Schedule Rule You can set the schedule time to decide which service will be turned on or off Select the enable item Press Add New Rule ...

Страница 63: ...63 You can write a rule name and set which day and what time to schedule from Start Time to End Time The following example configure ftp time as everyday 14 10 to 16 20 ...

Страница 64: ... you want to Enable the Scheduler Edit To edit the schedule rule Delete To delete the schedule rule and the rule of the rules behind the deleted one will decrease one automatically Schedule Rule can be apply to Virtual server and Packet Filter for example ...

Страница 65: ...65 Exanple1 Virtual Server Apply Rule 1 ftp time everyday 14 10 to 16 20 Exanple2 Packet Filter Apply Rule 1 ftp time everyday 14 10 to 16 20 ...

Страница 66: ...66 4 8 Toolbox ...

Страница 67: ...67 4 8 1 System Log You can View system log by clicking the View Log button ...

Страница 68: ...68 4 8 2 Firmware Upgrade You can upgrade firmware by clicking Firmware Upgrade button ...

Страница 69: ...a bin file Once you want to restore these settings please click Firmware Upgrade button and use the bin file you saved 4 8 4 Reset to default You can also reset this product to factory default by clicking the Reset to default button 4 8 5 Reboot You can also reboot this product by clicking the Reboot button ...

Страница 70: ...ure the target device must be Wake on LAN enabled and you have to know the MAC address of this device say 00 11 22 33 44 55 Clicking Wake up button will make the router to send the wake up frame to the target device immediately Domain Name or IP address for Ping Test Allow you to configure an IP and ping the device You can ping a specific IP to test whether it is alive ...

Страница 71: ...l computer If not please refer to your network card manual Moreover the Section B 2 tells you how to set TCP IP values for working with this NAT Router correctly A 1 Install TCP IP Protocol into Your PC 1 Click Start button and choose Settings then click Control Panel 2 Double click Network icon and select Configuration tab in the Network window 3 Click Add button to add network component into you...

Страница 72: ...t TCP IP Protocol for Working with NAT Router 1 Click Start button and choose Settings then click Control Panel 2 Double click Network icon Select the TCP IP line that has been associated to your network card in the Configuration tab of the Network window 3 Click Properties button to set the TCP IP protocol for this NAT Router 4 Now you have two setting methods ...

Страница 73: ...73 a Select Obtain an IP address automatically in the IP Address tab b Don t input any value in the Gateway tab ...

Страница 74: ...b B Configure IP manually a Select Specify an IP address in the IP Address tab The default IP address of this product is 192 168 123 254 So please use 192 168 123 xxx xxx is between 1 and 253 for IP Address field and 255 255 255 0 for Subnet Mask field ...

Страница 75: ... address of this product default IP is 192 168 123 254 in the New gateway field and click Add button c In the DNS Configuration tab add the DNS values which are provided by the ISP into DNS Server Search Order field and click Add button ...

Страница 76: ...rosoft Windows XP Professional with Service Pack 1a Authentication Server Windows 2000 RADIUS server with Service Pack 3 and HotFix Q313664 Note Windows 2000 RADIUS server only supports PEAP after upgrade to service pack 3 and HotFix Q313664 You can get more information from http support microsoft com default aspx scid kb en us 313664 2 DUT Configuration 1 Enable DHCP server 2 WAN setting static I...

Страница 77: ...1X check the Enable checkbox 2 Enter the RADIUS server IP 3 Enter the shared key The key shared by the RADIUS server and DUT 4 We will change 802 1X encryption key length to fit the variable test condition 3 1 3 Setup Network adapter on PC 1 Choose the IEEE802 1X as the authentication method Fig 2 Note Figure 2 is a setting picture of Windows XP without service pack 1 If users upgrade to service p...

Страница 78: ...78 Figure 2 Enable IEEE 802 1X access control ...

Страница 79: ...cess Point 3 Set authentication type of wireless client and RADIUS server both to EAP_TLS 4 Disable the wireless connection and enable again 5 The DUT will send the user s certificate to the RADIUS server and then send the message of authentication result to PC1 Fig 5 6 Windows XP will prompt that the authentication process is success or fail and end the authentication procedure Fig 6 7 Terminate ...

Страница 80: ...80 Figure 4 Certificate information on PC1 Figure 5 Authenticating ...

Страница 81: ...PC2 5 Windows XP will prompt that the authentication process is success or fail and end the authentication procedure 6 Terminate the test steps when PC2 get dynamic IP and PING remote host successfully Support Type The router supports the types of 802 1x Authentication PEAP CHAPv2 and PEAP TLS Note 1 PC1 is on Windows XP platform without Service Pack 1 2 PC2 is on Windows XP platform with Service ...

Страница 82: ...rst turn off the router and press the RESET button in And then power on the router and push the RESET button down until the Status LED start flashing then remove the finger If LED flashes about 8 times the RESTORE process is completed However if LED flashes 2 times repeat 2 Restore directly when the router power on First push the RESET button about 5 seconds and STATUS will start flashing about 5 ...

Отзывы: