background image

Содержание 802.11g Wireless Access Point ZyXEL G-560

Страница 1: ...ZyXEL G 560 802 11g Wireless Access Point User s Guide Version 2 0 January 2005...

Страница 2: ...XEL Communications Corporation All rights reserved Disclaimer ZyXEL does not assume any liability arising out of the application or use of any products or software described herein Neither does it con...

Страница 3: ...user is encouraged to try to correct the interference by one or more of the following measures 1 Reorient or relocate the receiving antenna 2 Increase the separation between the equipment and the rece...

Страница 4: ...urchaser This warranty is in lieu of all other warranties express or implied including any implied warranty of merchantability or fitness for a particular use or purpose ZyXEL shall in no event be hel...

Страница 5: ...zyxel com 1 714 632 0858 ftp us zyxel com ZyXEL Communications Inc 1130 N Miller St Anaheim CA 92806 2001 U S A support zyxel de 49 2405 6909 0 www zyxel de GERMANY sales zyxel de 49 2405 6909 99 ZyXE...

Страница 6: ...1 FTP SITE REGULAR MAIL support zyxel se 46 31 744 7700 www zyxel se SWEDEN sales zyxel se 46 31 744 7701 ZyXEL Communications A S Sj porten 4 41764 G teborg Sweden support zyxel fi 358 9 4780 8411 ww...

Страница 7: ...4 Chapter 2 Management Computer Setup 2 1 2 1 Introduction 2 1 2 2 Wired Connection 2 1 2 2 1 Setting Up Your Computer s IP Address 2 2 2 3 Wireless Connection 2 5 2 4 Resetting the G 560 2 5 2 4 1 Me...

Страница 8: ...9 6 6 802 1x Overview 6 11 6 7 Introduction to RADIUS 6 11 6 7 1 EAP Authentication Overview 6 12 6 8 Dynamic WEP Key Exchange 6 13 6 9 Introduction to WPA 6 13 6 9 1 User Authentication 6 13 6 9 2 E...

Страница 9: ...eshooting A 1 Problems Starting Up the G 560 A 1 Problems with the Ethernet Interface A 1 Problems with the Password A 2 Problems with Telnet A 2 Problems with the WLAN Interface A 3 Testing the Conne...

Страница 10: ...Wizard 3 Disable 3 6 Figure 3 7 Wizard 3 WEP 3 7 Figure 3 8 Wizard 3 WPA PSK 3 8 Figure 3 9 Wizard 4 Confirm Your Settings 3 8 Figure 4 1 Status 4 1 Figure 4 2 Status View Statistics 4 3 Figure 4 3 St...

Страница 11: ...File 7 4 Figure 7 4 Configuration Upload Successful 7 5 Figure 7 5 Network Temporarily Disconnected 7 6 Figure 7 6 Configuration Upload Error 7 6 Figure 7 7 Reset Warning Message 7 7 Figure 7 8 Firmw...

Страница 12: ......

Страница 13: ...nges 5 1 Table 5 2 System Settings 5 3 Table 5 3 Time Settings 5 5 Table 6 1 Wireless Settings 6 6 Table 6 2 Wireless Security Relational Matrix 6 16 Table 6 3 Security Disable 6 17 Table 6 4 Security...

Страница 14: ...r to the included CD for support documents Quick Start Guide Our Quick Start Guide is designed to help you get up and running right away It contains information on the configuration of key features an...

Страница 15: ...the G 560 in the user s guide User Guide Feedback Help us help you E mail all User Guide related comments questions or suggestions for improvement to techwriters zyxel com tw or send regular mail to...

Страница 16: ......

Страница 17: ...Overview I P Pa ar rt t I I OVERVIEW This part introduces the main features and applications of G 560 and shows how to access the web configurator and use the Wizard to set up the G 560...

Страница 18: ......

Страница 19: ...llows your G 560 to assign its SSID and security settings WEP or WPA PSK to the ZyXEL wireless adapters that support OTIST and are within transmission range The ZyXEL wireless adapters must also have...

Страница 20: ...ering Your G 560 checks the MAC address of the wireless station against a list of allowed or denied MAC addresses WEP Encryption WEP Wired Equivalent Privacy encrypts data frames before transmitting o...

Страница 21: ...ernet connection On The G 560 has a successful 10Mbps Ethernet connection Green Blinking The G 560 is sending receiving data On The G 560 has a successful 100Mbps Ethernet connection ETHN Amber Blinki...

Страница 22: ...e 1 2 Internet Access Application 1 4 2 Corporation Network Application In situations where users need to access corporate network resources and the Internet the G 560 is an ideal solution for wireles...

Страница 23: ...ZyXEL G 560 User s Guide Getting to Know Your G 560 1 5 Figure 1 3 Corporation Network Application...

Страница 24: ......

Страница 25: ...ed for a first time management session or wirelessly 2 2 Wired Connection You must prepare your computer computer network to connect to the G 560 if you are using a wired connection Your computer s IP...

Страница 26: ...puters using Windows NT 2000 XP Macintosh OS 7 and later operating systems Refer to the Setting Up Your Computer s IP Address appendix for other operating systems Windows 2000 NT XP The following exam...

Страница 27: ...g IP Address and fill in an IP address between 192 168 1 3 and 192 168 1 254 Type 255 255 255 0 as the Subnet mask Click Advanced 1 Figure 2 5 Internet Protocol Properties 6 Remove any previously inst...

Страница 28: ...P Settings 7 Click OK to close the Internet Protocol TCP IP Properties window 8 Click Close OK in Windows 2000 NT to close the Local Area Connection Properties window 9 Close the Network Connections w...

Страница 29: ...60 your network traffic is visible to any wireless networking device that is within range 2 4 Resetting the G 560 If you forget the G 560 s IP address or your password to access the G 560 you will nee...

Страница 30: ...defaults in two ways 1 Use the RESET button on the G 560 to upload the default configuration file hold this button in for about 10 seconds or release the button when the PWR LED starts blinking 2 Use...

Страница 31: ...method from the status screen Step 1 Make sure your G 560 hardware is properly connected refer to the Quick Start Guide Step 2 Prepare your computer computer network to connect to the G 560 refer to s...

Страница 32: ...word highly recommended as shown next Type a new password and retype it to confirm and click Apply or click Ignore to allow access without password change If you do not change the password the followi...

Страница 33: ...s of a series of screens to help you configure your G 560 for wireless stations to access your wired LAN Use the following buttons to navigate the Wizard Back Click Back to return to the previous scre...

Страница 34: ...eset button to restore the factory default IP address 3 Select Use fixed IP address to give the G 560 a static IP address The IP address you configure here is used for management of the G 560 accessin...

Страница 35: ...r up to 32 printable characters Spaces are allowed If you change this field on the G 560 make sure all wireless stations use the same SSID in order to access the network 2 A wireless device uses a cha...

Страница 36: ...curity on your G 560 your network is accessible to any wireless networking device that is within range With no wireless security a neighbor can access and see traffic in your network Figure 3 6 Setup...

Страница 37: ...ield Figure 3 7 Wizard 3 WEP WPA PSK 1 Type a pre shared key to have a more secure wireless connection Choose this option only if your wireless clients support it 2 Type from 8 to 63 ASCII characters...

Страница 38: ...wing read only screen shows the status of the current settings Use the summary table to check whether what you have configured is correct Click Finish to complete the wizard configuration and save you...

Страница 39: ...System Wireless and IP II Part II STATUS AND SETTINGS This part covers the information and web configurator screens of Status and Settings...

Страница 40: ......

Страница 41: ...atus screens 4 1 System Status Click STATUS to display a snapshot of your G 560 settings You can also view network statistics and a list of wireless stations currently associated with the G 560 Note t...

Страница 42: ...t This field displays whether the G 560 is set to obtain an IP address from a DHCP server or use a manually entered static IP address IP Address This is the Ethernet port IP address IP Subnet Mask Thi...

Страница 43: ...els in this screen Table 4 2 Status View Statistics LABEL DESCRIPTION Port This is the Ethernet or wireless port TxPkts This is the number of transmitted packets on this port RxPkts This is the number...

Страница 44: ...TATUS and then the View Association List button to display the screen as shown next Figure 4 3 Status View Association List The following table describes the labels in this screen Table 4 3 Status Vie...

Страница 45: ...nce only between your two branch offices you can assign any IP addresses to the hosts without problems However the Internet Assigned Numbers Authority IANA has reserved the following three blocks of I...

Страница 46: ...ddress when the connection is established The Internet Assigned Number Authority IANA reserved this block of addresses specifically for private use please do not use any other number unless you are to...

Страница 47: ...e characters long Spaces are allowed IP Address Assignment Obtain IP Address Automatically Select this option to have your G 560 use a dynamically assigned IP address from a router each time You must...

Страница 48: ...e same network segment as the G 560 The gateway helps forward packets to their destinations Leave this field as 0 0 0 0 if you do not know it Apply Click Apply to save your changes back to the G 560 R...

Страница 49: ...hour minute second format Enter the new time in this field and then click Apply Date yyyy mm dd This field displays the date of your G 560 in year month day format Enter the new date in this field and...

Страница 50: ......

Страница 51: ...adapters within range of each other that from an independent wireless network without the need of an access point AP Figure 6 1 IBSS Ad hoc Wireless LAN 6 1 2 BSS A Basic Service Set BSS exists when a...

Страница 52: ...BSSs each containing an access point with each access point connected together by a wired network This wired connection between APs is called a Distribution System DS An ESSID ESS IDentification uniqu...

Страница 53: ...rference Interference occurs when radio signals from different access points overlap causing interference and degrading performance Adjacent channels partially overlap however To avoid interference du...

Страница 54: ...efore an RTS Request To Send CTS Clear to Send handshake is invoked When a data frame exceeds the RTS CTS value you set between 0 to 2432 bytes the station that wants to transmit this frame must first...

Страница 55: ...0 will fragment the packet into smaller data frames A large Fragmentation Threshold is recommended for networks not prone to interference while you should set a smaller threshold for busy networks or...

Страница 56: ...ireless Settings The following table describes the labels in this screen Table 6 1 Wireless Settings LABEL DESCRIPTION Basic Settings Operation Mode Select Access Point from the drop down list At the...

Страница 57: ...o allow only IEEE 802 11b compliant WLAN devices to associate with the G 560 Select Pure G Mode to allow only IEEE 802 11g compliant WLAN devices to associate with the G 560 Select Mixed Mode to allow...

Страница 58: ...adapters support and to provide more reliable communications in busy wireless networks Select Short preamble if you are sure the wireless adapters support it and to provide more efficient communicatio...

Страница 59: ...data encryption and wireless station authentication 6 5 1 Data Encryption WEP provides a mechanism for encrypting data using encryption keys Both the AP and the wireless stations must use the same WE...

Страница 60: ...entication request to the AP which will then reply with a challenge text message The wireless station must then use the AP s default WEP key to encrypt the challenge text and return it to the AP which...

Страница 61: ...ADIUS user is a simple package exchange in which your G 560 acts as a message relay between the wireless station and the network RADIUS server Types of RADIUS Messages The following types of RADIUS me...

Страница 62: ...erver the access point helps a wireless station and a RADIUS server perform authentication The type of authentication you use depends on the RADIUS server or the AP The G 560 supports EAP TLS EAP TTLS...

Страница 63: ...on purposes since the Local User Database uses EAP MD5 which cannot be used to generate keys See later in this chapter and the appendices for more information on IEEE 802 1x RADIUS and EAP Therefore i...

Страница 64: ...are the same The only difference between the two is that WPA PSK uses a simple common password instead of user specific credentials The common password approach makes WPA PSK susceptible to brute for...

Страница 65: ...distributes a Pairwise Master Key PMK key to the AP that then sets up a key hierarchy and management system using the pair wise key to dynamically generate unique data encryption keys to encrypt ever...

Страница 66: ...tem instructing the wireless client how to use WPA At the time of writing the most widely available supplicants are the WPA patch for Windows XP Funk Software s Odyssey client and Meetinghouse Data Co...

Страница 67: ...N security configured Apply Click Apply to save your changes back to the G 560 Reset Click Reset to begin configuring this screen afresh 6 14 2 WEP WEP provides a mechanism for encrypting data using e...

Страница 68: ...labels in this screen Table 6 4 Security WEP LABEL DESCRIPTION Encryption Method Select WEP if you want to configure WEP encryption parameters Authentication Type Select Auto Open or Shared from the...

Страница 69: ...ually set the WEP keys enter the WEP key in the field provided Select a WEP key to use for data encryption The WEP keys are used to encrypt data Both the G 560 and the wireless stations must use the s...

Страница 70: ...WPA and WPA PSK are the same The only difference between the two is that WPA PSK uses a simple common password instead of user specific credentials Type a pre shared key from 8 to 63 ASCII characters...

Страница 71: ...l authentication server in dotted decimal notation Port Number Enter the port number of the external authentication server The default port number is 1812 You need not change this value unless your ne...

Страница 72: ...guring this screen afresh 6 14 5 802 1x The IEEE 802 1x standard outlines enhanced security methods for both the authentication of wireless stations and encryption key management Once you enable user...

Страница 73: ...key to be shared between the external authentication server and the G 560 The key must be the same on the external authentication server and your G 560 The key is not sent over the network Apply Clic...

Страница 74: ...ZyXEL G 560 User s Guide 6 24 Wireless Screens Figure 6 16 MAC Address Filter The following table describes the labels in this screen...

Страница 75: ...in these address fields Apply Click Apply to save your changes back to the G 560 Reset Click Reset to begin configuring this screen afresh 6 16 OTIST One Touch Intelligent Security Technology OTIST al...

Страница 76: ...lso make the same change on the wireless adapter s Yes If the G 560 has no wireless security configured select this checkbox to enable WPA PSK security and automatically generate a WPA PSK key on the...

Страница 77: ...ring Password To change your G 560 s password recommended click SETTINGS and then MANAGEMENT The screen appears as shown This screen allows you to change the G 560 s password If you forget your passwo...

Страница 78: ...save your changes back to the G 560 Reset Click Reset to reload the previous configuration for this screen 7 3 Logs The web configurator allows you to look at all of the G 560 s logs in one location...

Страница 79: ...ed the log Note This field displays additional information about the log entry Refresh Click Refresh to renew the log screen Clear Log Click Clear Log to clear all the logs 7 4 Configuration Screen Th...

Страница 80: ...7 3 Configuration File 7 4 1 Backup Configuration Backup configuration allows you to back up save the G 560 s current configuration to a file on your computer Once your G 560 is configured and functi...

Страница 81: ...le Path Type in the location of the file you want to upload in this field or click Browse to find it Browse Click Browse to find the file you want to upload Remember that you must decompress compresse...

Страница 82: ...e default G 560 IP address 192 168 1 2 If the upload was not successful the following screen will appear Click Return to go back to the Configuration File screen Figure 7 6 Configuration Upload Error...

Страница 83: ...ESET button 7 5 F W Upload Screen Find firmware at www zyxel com in a file that usually uses the system model name with a bin extension for example zyxel bin The upload process uses HTTP Hypertext Tra...

Страница 84: ...n this field or click Browse to find it Browse Click Browse to find the bin file you want to upload Remember that you must decompress compressed zip files before you can upload them Upload Click Uploa...

Страница 85: ...ry network disconnect In some operating systems you may see the following icon on your desktop Figure 7 10 Network Temporarily Disconnected After two minutes log in again and check your new firmware v...

Страница 86: ...creens Figure 7 11 Firmware Upload Error 7 6 Language Screen If you want to view the web configurator and corresponding web help in another language click SETTINGS MANAGEMENT and then Language Click t...

Страница 87: ...ENDICES This part provides troubleshooting and background information about setting up your computer s IP address wireless LAN 802 1x and IP subnetting It also provides information on the command inte...

Страница 88: ......

Страница 89: ...roblem In this case you should contact your local vendor The G 560 reboots automatically sometimes The supplied power to the G 560 is too low Check that the G 560 is receiving enough power Make sure t...

Страница 90: ...rs are on the same subnet Problems with the Password Chart A 3 Troubleshooting the Password PROBLEM CORRECTIVE ACTION I cannot access the G 560 The Password and Username fields are case sensitive Make...

Страница 91: ...ings Testing the Connection to the G 560 1 Click Start All Programs Accessories and then Command Prompt 2 In the Command Prompt window type ping followed by a space and the IP address of the G 560 192...

Страница 92: ......

Страница 93: ...ready be installed on computers using Windows NT 2000 XP Macintosh OS 7 and later operating systems After the appropriate TCP IP components are installed configure the TCP IP settings in order to comm...

Страница 94: ...lick Add c Select Microsoft from the list of manufacturers d Select TCP IP from the list of network protocols and then click OK If you need Client for Microsoft Networks a Click Add b Select Client an...

Страница 95: ...ally If you have a static IP address select Specify an IP address and type your information into the IP Address and Subnet Mask fields 2 Click the DNS Configuration tab If you do not know your DNS inf...

Страница 96: ...Properties window 5 Click OK to close the Network window Insert the Windows CD if prompted 6 Turn on your G 560 and restart your computer when prompted Verifying Your Computer s IP Address 1 Click Sta...

Страница 97: ...s IP Address B 5 1 Click start Start in Windows 2000 NT Settings Control Panel 2 In the Control Panel double click Network Connections Network and Dial up Connections in Windows 2000 NT 3 Right click...

Страница 98: ...XP and click Properties 5 The Internet Protocol TCP IP Properties window opens the General tab in Windows XP If you have a dynamic IP address click Obtain an IP address automatically If you have a sta...

Страница 99: ...ress in IP address and a subnet mask in Subnet mask and then click Add Repeat the above two steps for each IP address you want to add Configure additional default gateways in the IP Settings tab by cl...

Страница 100: ...ick Advanced and then the DNS tab to order them 8 Click OK to close the Internet Protocol TCP IP Properties window 9 Click Close OK in Windows 2000 NT to close the Local Area Connection Properties win...

Страница 101: ...s IP Address B 9 1 Click the Apple menu Control Panel and double click TCP IP to open the TCP IP Control Panel 2 Select Ethernet built in from the Connect via list 3 For dynamically assigned settings...

Страница 102: ...net mask box Type the IP address of your G 560 in the Router address box 5 Close the TCP IP Control Panel 6 Click Save if prompted to save changes to your configuration 7 Turn on your G 560 and restar...

Страница 103: ...DHCP from the Configure list 4 For statically assigned settings do the following From the Configure box select Manually Type your IP address in the IP Address box Type your subnet mask in the Subnet m...

Страница 104: ......

Страница 105: ...e workgroups a lower total cost of ownership for workspaces that are frequently reconfigured 4 It allows conference room users access to the network as they move from meeting to meeting getting up to...

Страница 106: ...nge of each other they can set up an independent network which is commonly referred to as an Ad hoc network or Independent Basic Service Set IBSS See the following diagram of an example of an Ad hoc w...

Страница 107: ...s of overlapping BSSs each containing an Access Point connected together by means of a Distribution System DS Although the DS could be any type of network it is almost invariably an Ethernet LAN Mobil...

Страница 108: ......

Страница 109: ...andard does not provide any central user account management User access control is done through manual modification of the MAC address table on the access point Although WEP data encryption offers a f...

Страница 110: ...ication Sequence The following figure depicts a typical wireless network with a remote RADIUS server for user authentication using EAPOL EAP Over LAN Diagram D 1 Sequences for EAP MD5 Challenge Authen...

Страница 111: ...curity With EAP TLS digital certifications are needed by both the server and the wireless stations for mutual authentication The server presents a certificate to the client After validating the identi...

Страница 112: ...ed in corporate environments but for public deployment a simple user name and password pair is more practical The following table is a comparison of the features of five authentication types Compariso...

Страница 113: ...e next left most bit In a class B address the first two octets make up the network number and the two remaining octets make up the host ID Class C addresses begin starting from the left with 1 1 0 In...

Страница 114: ...bnet mask is used to determine which bits are part of the network number and which bits are part of the host ID using a logical AND operation A subnet mask has 32 bits each bit of the mask corresponds...

Страница 115: ...ddress using both notations Chart F 4 Alternative Subnet Mask Notation SUBNET MASK IP ADDRESS SUBNET MASK 1 BITS LAST OCTET BIT VALUE 255 255 255 0 24 0000 0000 255 255 255 128 25 1000 0000 255 255 25...

Страница 116: ...k Binary 11111111 11111111 11111111 10000000 Subnet Address 192 168 1 0 Lowest Host ID 192 168 1 1 Broadcast Address 192 168 1 127 Highest Host ID 192 168 1 126 Chart F 6 Subnet 2 NETWORK NUMBER LAST...

Страница 117: ...or each subnet all 0 s is the subnet itself all 1 s is the broadcast address on the subnet Chart F 7 Subnet 1 NETWORK NUMBER LAST OCTET BIT VALUE IP Address 192 168 1 0 IP Address Binary 11000000 1010...

Страница 118: ...0 00000001 11000000 Subnet Mask Binary 11111111 11111111 11111111 11000000 Subnet Address 192 168 1 192 Lowest Host ID 192 168 1 193 Broadcast Address 192 168 1 255 Highest Host ID 192 168 1 254 Examp...

Страница 119: ...ass B addresses the subnet mask also determines which bits are part of the network number and which are part of the host ID A class B address has two host ID octets available for subnetting and a clas...

Страница 120: ...ng NO BORROWED HOST BITS SUBNET MASK NO SUBNETS NO HOSTS PER SUBNET 9 255 255 255 128 25 512 126 10 255 255 255 192 26 1024 62 11 255 255 255 224 27 2048 30 12 255 255 255 240 28 4096 14 13 255 255 25...

Страница 121: ...Sequence Spread Spectrum E EAP 1 2 6 8 EAP Authentication E 1 MD5 E 1 PEAP E 2 TLS E 1 TTLS E 1 Encryption 6 13 ESS See Extended Service Set See Extended Service Set ESS ID 6 3 Extended Service Set C...

Страница 122: ...rvice See RADIUS Restore 7 5 RF signals C 1 RTS Threshold 6 4 S Security Parameters 6 15 Service iv Service Set Identity See SSID Setup Key 6 26 SSID 6 3 Subnet Mask 5 2 Subnet Masks F 2 Subnetting F...

Страница 123: ...ZyXEL G 560 User s Guide Index G 3 WPA PSK 6 13 6 19 WPA PSK Application 6 14 Z ZyXEL Limited Warranty Note iv...

Отзывы: