manualshive.com logo in svg
background image

 www.zyxel.com

NWA-3100

802.11a/b/g Wireless Access Point

User’s Guide

Version 3.60
10/2006
Edition 1

Содержание NWA-3100

Страница 1: ...www zyxel com NWA 3100 802 11a b g Wireless Access Point User s Guide Version 3 60 10 2006 Edition 1...

Страница 2: ......

Страница 3: ...t away It contains information on setting up your network and configuring for Internet access Supporting Disk Refer to the included CD for support documents ZyXEL Web Site Please refer to www zyxel co...

Страница 4: ...A key stroke is denoted by square brackets and uppercase text for example ENTER means the enter or return key on your keyboard Enter means for you to type one or more characters and then press the ENT...

Страница 5: ...de 5 Icons Used in Figures Figures in this User s Guide may use the following generic icons The ZyXEL Device icon is not an exact representation of your device ZyXEL Device Computer Notebook computer...

Страница 6: ...t supply voltage for example 110V AC in North America or 230V AC in Europe Do NOT allow anything to rest on the power adaptor or cord and do NOT place the device where anyone can walk on the power ada...

Страница 7: ...Safety Warnings ZyXEL NWA 3100 User s Guide 7...

Страница 8: ...Safety Warnings ZyXEL NWA 3100 User s Guide 8...

Страница 9: ...n 81 MBSSID and SSID 97 Other Wireless Configuration 105 IP Screen 113 Rogue AP 117 Remote Management 123 Certificates 133 Log Screens 151 VLAN 157 Maintenance 175 SMT and Troubleshooting 185 Introduc...

Страница 10: ...Contents Overview ZyXEL NWA 3100 User s Guide 10...

Страница 11: ...ions for the ZyXEL Device 31 1 2 1 Access Point 31 1 2 2 AP Bridge 32 1 2 3 Bridge Repeater 33 1 2 4 MBSSID 35 1 2 5 Pre Configured SSID Profiles 36 1 3 Ways to Manage the ZyXEL Device 36 1 4 Good Hab...

Страница 12: ...3 2 2 Activate Periodic Rogue AP Detection 56 3 2 3 Set Up E mail Logs 57 3 2 4 Configure Your Other Access Points 58 3 2 5 Test the Setup 58 Part II The Web Configurator 61 Chapter 4 System Screens 6...

Страница 13: ...Identity 81 6 1 4 WEP Encryption 81 6 2 802 1x Overview 82 6 3 EAP Authentication Overview 82 6 4 Introduction to WPA 82 6 4 1 User Authentication 83 6 4 2 Encryption 83 6 4 3 WPA 2 PSK Application E...

Страница 14: ...2 1 2 Layer 2 Isolation Example 2 108 8 3 Configuring MAC Filter 109 8 4 Configuring Roaming 111 8 4 1 Requirements for Roaming 112 Chapter 9 IP Screen 113 9 1 Factory Ethernet Defaults 113 9 2 TCP I...

Страница 15: ...Summary 135 12 5 My Certificates 135 12 6 Certificate File Formats 137 12 7 Importing a Certificate 138 12 8 Creating a Certificate 139 12 9 My Certificate Details 141 12 10 Trusted CAs 144 12 11 Imp...

Страница 16: ...ist 177 15 4 Channel Usage 178 15 5 F W Upload Screen 178 15 6 Configuration Screen 180 15 6 1 Backup Configuration 181 15 6 2 Restore Configuration 181 15 6 3 Back to Factory Defaults 182 15 7 Restar...

Страница 17: ...he FTP command from the DOS Prompt 207 22 2 3 Backup Configuration Using TFTP 207 22 2 4 Example TFTP Command 208 22 2 5 Backup Via Console Port 209 22 3 Restore Configuration 210 22 3 1 Restore Using...

Страница 18: ...Limitations 222 23 4 System Timeout 222 Chapter 24 Troubleshooting 223 24 1 Power Hardware Connections and LEDs 223 24 2 ZyXEL Device Access and Login 223 24 3 Internet Access 225 Part IV Appendices a...

Страница 19: ...re 17 Tutorial VoIP Security Updated 49 Figure 18 Tutorial Activate VoIP Profile 49 Figure 19 Tutorial Guest Edit 50 Figure 20 Tutorial Guest Security Profile Edit 50 Figure 21 Tutorial Guest Security...

Страница 20: ...reless Multiple BSS 98 Figure 57 SSID 101 Figure 58 Configuring SSID 102 Figure 59 Layer 2 Isolation Application 106 Figure 60 Layer 2 Isolation Configuration Screen 107 Figure 61 Layer 2 Isolation Ex...

Страница 21: ...VLAN Group 167 Figure 103 Granting Permissions and User Profile Screens 167 Figure 104 Authentication Tab Settings 168 Figure 105 Encryption Tab Settings 168 Figure 106 Connection Attributes Screen 16...

Страница 22: ...Example 207 Figure 146 System Maintenance Backup Configuration 209 Figure 147 System Maintenance Starting Xmodem Download Screen 209 Figure 148 Backup Configuration Example 209 Figure 149 Successful B...

Страница 23: ...etwork 249 Figure 181 Basic Service Set 250 Figure 182 Infrastructure WLAN 251 Figure 183 RTS CTS 252 Figure 184 Pop up Blocker 261 Figure 185 Internet Options Privacy 262 Figure 186 Internet Options...

Страница 24: ...List of Figures ZyXEL NWA 3100 User s Guide 24...

Страница 25: ...le 15 STP Port States 73 Table 16 Wireless Access Point 75 Table 17 Wireless Bridge Repeater 79 Table 18 Security Modes 85 Table 19 Wireless Security Levels 86 Table 20 Security 87 Table 21 Security W...

Страница 26: ...AN 161 Table 60 Standard RADIUS Attributes 164 Table 61 System Status 175 Table 62 System Status Show Statistics 176 Table 63 Association List 177 Table 64 Channel Usage 178 Table 65 Firmware Upload 1...

Страница 27: ...Types 256 Table 91 Wireless Security Relational Matrix 257 Table 92 Subnet Masks 268 Table 93 Subnet Masks 269 Table 94 Maximum Host Numbers 269 Table 95 Alternative Subnet Mask Notation 269 Table 96...

Страница 28: ...List of Tables ZyXEL NWA 3100 User s Guide 28...

Страница 29: ...29 PART I Introduction Introducing the ZyXEL Device 31 Introducing the Web Configurator 39 Tutorial 43...

Страница 30: ...30...

Страница 31: ...access with MAC address filtering rogue AP detection and layer 2 isolation It also provides a high level of network traffic security supporting IEEE 802 1x Wi Fi Protected Access WPA WPA2 and WEP dat...

Страница 32: ...etwork while X and Y communicate in bridge mode When the ZyXEL Device is in AP Bridge mode security between APs the Wireless Distribution System or WDS is independent of the security between the wirel...

Страница 33: ...eater mode C has no Ethernet connection When the ZyXEL Device is in bridge mode you should enable STP to prevent bridge loops When the ZyXEL Device is in Bridge Repeater mode security between APs the...

Страница 34: ...Chapter 1 Introducing the ZyXEL Device ZyXEL NWA 3100 User s Guide 34 Figure 3 Bridge Application Figure 4 Repeater Application...

Страница 35: ...ccess privileges and prioritize network traffic to and from certain BSSs To the wireless clients in the network each SSID appears to be a different access point As in any wireless network clients can...

Страница 36: ...eryday management of the ZyXEL Device using a supported web browser Command Line Interface Line commands are mostly used for troubleshooting by service engineers SMT System Management Terminal is a te...

Страница 37: ...Repeater mode and has successfully established a Wireless Distribution System WDS connection Red Flashing The ZyXEL Device is starting up Off Either The ZyXEL Device is in Access Point or MBSSID mode...

Страница 38: ...ble the ZyAIR LED 3 ETHN Green On The ZyXEL Device has a 10 Mbps Ethernet connection Blinking The ZyXEL Device has a 10 Mbps Ethernet connection and is sending or receiving data Yellow On The ZyXEL De...

Страница 39: ...to the ZyXEL Device refer to the Quick Start Guide 2 Launch your web browser 3 Type 192 168 1 2 as the URL default 4 Type 1234 default as the password and click Login In some versions the default pas...

Страница 40: ...he management session automatically times out when the time period set in the Administrator Inactivity Timer field expires default five minutes Simply log back into the ZyXEL Device if this happens 2...

Страница 41: ...s of the ZyXEL Device is not known Use the web configurator to restore defaults refer to Chapter 15 on page 175 Transfer the configuration file to your ZyXEL Device using FTP See the section on SMT co...

Страница 42: ...r IP ROGUE AP Configuration Friendly AP Rogue AP REMOTE MGNT Telnet FTP WWW and SNMP CERTIFICATES My Certificates Trusted CAs LOGS View Logs and Log Settings and VLAN Wireless VLAN and RADIUS VLAN Cli...

Страница 43: ...e 97 to provide multiple wireless networks Each wireless network will cater for a different type of user You want to make three wireless networks one standard office wireless network with all the same...

Страница 44: ...To configure these settings you need to know the MAC Media Access Control addresses of the devices you want to allow users of the guest network to access The following table shows the addresses used...

Страница 45: ...g Mode drop down list box The screen displays as follows Figure 12 Tutorial Wireless LAN Change Mode This Select SSID Profile table allows you to activate or deactivate SSID profiles Your wireless net...

Страница 46: ...ELESS SSID The following screen displays Note that the SSID04 SSID profile the standard network is using the security01 security profile You cannot change this security profile without changing the st...

Страница 47: ...k so there is no need to broadcast the SSID to wireless clients scanning the area The standard network SSID04 is currently using the security01 profile so use a different profile for the VoIP network...

Страница 48: ...Profile Edit Change the Name field to VoIP_Security to make it easier to remember and identify In this example you do not have a RADIUS server for authentication so select WPA2 PSK in the Security Mo...

Страница 49: ...ross the wireless network 3 1 3 Configure the Guest Network When you are setting up the wireless network for guests to your office your primary concern is to keep your network secure while allowing ac...

Страница 50: ...sing the security01 profile and the VoIP network is using the security02 profile renamed VoIP_Security so select the security03 profile from the Security field Leave all the other fields at their defa...

Страница 51: ...e Profile Name for entry 3 displays Guest_Security and that the Security Mode is WPA PSK Figure 21 Tutorial Guest Security Updated 3 1 3 2 Set up Layer 2 Isolation Configure layer 2 isolation to contr...

Страница 52: ...s of the security profile are correct Access the Guest_SSID network and try to access other resources than those specified in the Layer 2 Isolation screen You can use the ping utility to do this Click...

Страница 53: ...Wireless Network Example In the figure the solid circle represents the range of your wireless network and the dashed circle represents the extent of the coffee shop s wireless network Note that the t...

Страница 54: ...5 Test the setup 3 2 1 Set Up and Save a Friendly AP list Take the following steps to set up and save a list of access points you want to allow in your network s coverage area 1 On a computer connecte...

Страница 55: ...ter Data Entry 3 Next you will save the list of friendly APs in order to provide a backup and upload it to your other access points Click the Configuration tab The following screen appears Figure 27 T...

Страница 56: ...on the network file server E in Figure 24 on page 53 The default filename is Flist Figure 29 Tutorial Save Friendly AP list 3 2 2 Activate Periodic Rogue AP Detection Take the following steps to activ...

Страница 57: ...message to your e mail inbox whenever a rogue AP is discovered in your wireless network s coverage area 1 Click LOGS Log Settings The following screen appears Figure 31 Tutorial Log Settings In this...

Страница 58: ...2 3 on page 57 but change the Mail Subject field so you can tell which AP the alerts come from ALERT_Access_Point_B etc 3 2 5 Test the Setup Next test your setup to ensure it is correctly configured L...

Страница 59: ...ZyXEL NWA 3100 User s Guide 59 Check your e mail You should have received at least one e mail alert your other ZyXEL Devices may also have sent alerts depending on their proximity and the output powe...

Страница 60: ...Chapter 3 Tutorial ZyXEL NWA 3100 User s Guide 60...

Страница 61: ...tem Screens 63 Wireless Configuration 67 Wireless Security Configuration 81 MBSSID and SSID 97 Other Wireless Configuration 105 IP Screen 113 Rogue AP 117 Remote Management 123 Certificates 133 Log Sc...

Страница 62: ...62...

Страница 63: ...up to 30 alphanumeric characters long Spaces are not allowed but dashes and underscores _ are accepted Domain Name This is not a required field Leave this field blank or enter the domain name here if...

Страница 64: ...ser Defined but leave the IP address set to 0 0 0 0 User Defined changes to None after you click Apply If you set a second choice to User Defined and enter the same IP address the second User Defined...

Страница 65: ...rmat is day month year time zone of the server Time RFC 868 format displays a 4 byte integer giving the total number of seconds since 1970 1 1 at 0 0 0 The default NTP RFC 1305 is similar to Time RFC...

Страница 66: ...this option if you use daylight savings time Daylight saving is a period from late spring to early fall when many countries set their clocks ahead of normal local time by one hour to give more daytime...

Страница 67: ...ommunications between wireless stations or between a wireless station and a wired network client go through one access point AP Intra BSS traffic is traffic between wireless stations in the BSS When I...

Страница 68: ...called a Distribution System DS An ESSID ESS IDentification uniquely identifies each ESS All access points and their associated wireless stations within the same ESS must have the same ESSID in order...

Страница 69: ...ty levels that the ZyXEL Device uses 5 3 2 ATC Automatic Traffic Classifier ATC is a bandwidth management tool that prioritizes data packets sent across the network ATC assigns each packet a priority...

Страница 70: ...WMM function prioritizes all packets transmitted onto the wireless network using WMM QoS and prioritizes all packets transmitted onto the wired network using ATC See Section 7 2 2 on page 101 for deta...

Страница 71: ...Points DSCPs indicating the level of service desired This allows the intermediary DiffServ compliant network devices to handle the packets differently depending on the code points without the need to...

Страница 72: ...f WMM QoS A Voice over IP VoIP device for example may allow you to define the DSCP value The following table lists which WMM QoS priority level the ZyXEL Device uses for specific DSCP values 5 4 Spann...

Страница 73: ...g any possible network loops STP aware bridges exchange Bridge Protocol Data Units BPDUs periodically When the bridged LAN topology changes a new spanning tree is constructed Once a stable network top...

Страница 74: ...less clients associated with your ZyXEL Device from communicating with other wireless clients APs computers or routers in a network 6 Use the MAC Filter screen to allow or restrict access to your wire...

Страница 75: ...n the Channel Usage tab to open the Channel Usage screen to make sure the channel is not already used by another AP or independent peer to peer wireless network To have the ZyXEL Device automatically...

Страница 76: ...st then change the wireless settings of your computer to match the ZyXEL Device s new settings Enable Breathing LED Select this check box to enable the breathing LED also known as the ZyAIR LED The bl...

Страница 77: ...sulting in possible throughput degradation and disruption of communications The following examples show two network topologies that can lead to this problem If two or more ZyXEL Devices in bridge mode...

Страница 78: ...loops ensure that you enable STP in the Wireless screen or your ZyXEL Device is not set to bridge mode while connected to both wired and wireless segments of the same LAN To have the ZyXEL Device act...

Страница 79: ...S handshake Setting this attribute to be larger than the maximum MSDU MAC service data unit size turns off the RTS CTS handshake Setting this attribute to zero turns on the RTS CTS handshake Enter a v...

Страница 80: ...See the section on applications for more information Figure 43 Wireless AP Bridge See the tables describing the fields in the Access Point and Bridge Repeater operating modes for descriptions of the...

Страница 81: ...ess clients but no RADIUS server If you don t have WPA 2 aware wireless clients then use WEP key encrypting A higher bit key offers better security at a throughput trade off You can manually enter 64...

Страница 82: ...supports EAP TLS EAP TTLS EAP MD5 and PEAP with RADIUS Refer to the Types of EAP Authentication appendix for descriptions on the common types The following figure shows an overview of authentication...

Страница 83: ...er stronger encryption Temporal Key Integrity Protocol TKIP uses 128 bit keys that are dynamically generated and distributed by the authentication server It includes a per packet key mixing function a...

Страница 84: ...sword matches 3 The AP derives and distributes keys to the wireless clients 4 The AP and wireless clients use the TKIP or AES encryption process to encrypt data exchanged between them Figure 45 WPA 2...

Страница 85: ...802 1x Static64 Select this to use 802 1x authentication with a static 64bit WEP key and an authentication server 802 1x Static128 Select this to use 802 1x authentication with a static 128bit WEP key...

Страница 86: ...evice EAP Extensible Authentication Protocol is used for authentication and utilizes static WEP key exchange It requires interaction with a RADIUS Remote Authentication Dial In User Service server eit...

Страница 87: ...you select 6 9 1 Security WEP Select WEP in the Security Mode field to display the following screen Table 20 Security LABEL DESCRIPTION Index This is the index number of the security profile address...

Страница 88: ...own list box The default setting is Auto ASCII Select this option to enter ASCII characters as the WEP keys Hex Select this option to enter hexadecimal characters as the WEP keys The preceding 0x is e...

Страница 89: ...the RADIUS server has priority Idle Timeout The ZyXEL Device automatically disconnects a wireless station from the wireless network after a period of inactivity The wireless station needs to send the...

Страница 90: ...preceded by 0x for each key If you chose 802 1x Static 128 bit then enter 13 characters ASCII string or 26 hexadecimal characters 0 9 A F preceded by 0x for each key There are four data encryption ke...

Страница 91: ...ch time each wireless station is connected to the wireless network for example using an authentication server If the wireless network is not keeping track of this information you can usually set this...

Страница 92: ...ng track of how much time each wireless station is connected to the wireless network for example using an authentication server If the wireless network is not keeping track of this information you can...

Страница 93: ...of this information you can usually set this value higher to reduce the number of delays caused by logging in again The default time interval is 3600 seconds or 1 hour Group Key Update Timer The Grou...

Страница 94: ...reless station from the wireless network after a period of inactivity The wireless station needs to send the username and password again before it can use the wireless network again Some wireless clie...

Страница 95: ...ernal server You can configure up to four RADIUS server profiles Each profile also has one backup authentication server and a backup accounting server These profiles can be assigned to an SSID profile...

Страница 96: ...value unless your network administrator instructs you to do so Share Secret Enter a password up to 128 alphanumeric characters as the key to be shared between the external authentication server and th...

Страница 97: ...associate with the same AP 7 1 2 Notes on Multiple BSS A maximum of eight BSSs are allowed on one AP simultaneously You must use different WEP keys for different BSSs If two stations have different B...

Страница 98: ...00 User s Guide 98 Figure 55 Multiple BSS with VLAN Example 7 1 5 Configuring Multiple BSSs Click WIRELESS Wireless and select MBSSID in the Operating Mode drop down list box to display the screen as...

Страница 99: ...lowest interference RTS CTS Threshold The threshold number of bytes for enabling RTS CTS handshake Data with a frame size larger than this value will perform the RTS CTS handshake Setting this attrib...

Страница 100: ...known as the ZyAIR LED The blue ZyAIR LED is on when the ZyXEL Device is on and blinks or breathes when data is being transmitted to from its wireless stations Clear the check box to turn this LED off...

Страница 101: ...e Name This field displays the identification name of each SSID profile on the ZyXEL Device SSID This field displays the name of the wireless profile on the network When a wireless client scans for an...

Страница 102: ...ans for an AP to associate with this is the name that is broadcast and seen in the wireless client utility Hide Name SSID Select Disable if you want the ZyXEL Device to broadcast this SSID a wireless...

Страница 103: ...S list the ZyXEL Device uses WMM on the wireless network and ATC on the wired network See Section 5 3 3 on page 70 for more information on ATC WMM If you select WMM_VOICE WMM_VIDEO WMM_BEST_EFFORT or...

Страница 104: ...Chapter 7 MBSSID and SSID ZyXEL NWA 3100 User s Guide 104...

Страница 105: ...uters or routers in a network In the following example layer 2 isolation is enabled on the ZyXEL Device Z in the figure to allow a guest wireless client A to access the main network router B the route...

Страница 106: ...on does not check the traffic between wireless clients that are associated with the same AP Intra BSS Traffic allows wireless clients associated with the same AP to communicate with each other 8 2 Con...

Страница 107: ...addresses These are the MAC address of a wireless client AP computer or router A wireless client associated with the ZyXEL Device can communicate with another wireless client AP computer or router onl...

Страница 108: ...or 3 Enter C s MAC address in the Allow devices with these MAC addresses field Figure 62 Layer 2 Isolation Example 1 8 2 1 2 Layer 2 Isolation Example 2 In the following example wireless clients 1 an...

Страница 109: ...ciation or exclude up to 32 devices from accessing the ZyXEL Device Deny Association Every Ethernet device has a unique MAC Media Access Control address The MAC address is assigned at the factory and...

Страница 110: ...ction Define the filter action for the list of MAC addresses in the MAC address filter table Select Deny Association to block access to the router MAC addresses not listed will be allowed to access th...

Страница 111: ...to another it scans and uses the channel of a new access point which then informs the other access points on the LAN about the change An example is shown in Figure 65 on page 111 With roaming a wirel...

Страница 112: ...gured with the same ESSID 2 If IEEE 802 1x user authentication is enabled and to be done locally on the access point the new access point must have the user profile for the wireless station 3 The adja...

Страница 113: ...r two branch offices for instance you can assign any IP addresses to the hosts without problems However the Internet Assigned Numbers Authority IANA has reserved the following three blocks of IP addre...

Страница 114: ...a DHCP server each time Note You must know the IP address assigned to the ZyXEL Device by the DHCP server to access the ZyXEL Device again Use fixed IP address Select this option if your ZyXEL Device...

Страница 115: ...Chapter 9 IP Screen ZyXEL NWA 3100 User s Guide 115 Apply Click Apply to save your changes Reset Click Reset to begin configuring this screen afresh Table 34 IP Setup LABEL DESCRIPTION...

Страница 116: ...Chapter 9 IP Screen ZyXEL NWA 3100 User s Guide 116...

Страница 117: ...can reveals a rogue AP you can use commercially available software to physically locate it Note that it is not necessary for a network to have a legitimate wireless LAN component for rogue APs to open...

Страница 118: ...nts A and B who attempt to connect This is known as a honeypot attack If a rogue AP in this scenario has sufficient power and is broadcasting the correct SSID Service Set IDentifier clients have no wa...

Страница 119: ...s any others that you know are not a threat those from neighboring networks for example It is recommended that you export save your list of friendly APs often especially if you have a network with a l...

Страница 120: ...etection on You must also enter a time value in the Period field Select No to turn rogue AP detection off Period min Enter the period you want the ZyXEL Device to wait between scanning for rogue APs b...

Страница 121: ...ess Enter the MAC address of the AP you wish to add to the list Description Enter a short explanatory description identifying the AP with a maximum of 32 alphanumeric characters Spaces underscores _ a...

Страница 122: ...splays the Service Set IDentifier also known as the network name of the AP Channel This field displays the wireless channel the AP is currently using Security This field displays the type of wireless...

Страница 123: ...secure Figure 73 Secure and Insecure Remote Management You may manage your ZyXEL Device from a remote location via To disable remote management of a service select Disable in the corresponding Server...

Страница 124: ...ion remains idle for longer than this timeout period The management session does not time out when a statistics screen is polling You can change the timeout period in the System screen 11 2 SSH You ca...

Страница 125: ...cured client is a trusted computer that is allowed to communicate with the ZyXEL Device using this service Select All to allow any computer to access the ZyXEL Device using this service Choose Selecte...

Страница 126: ...the server port number for a service if needed however you must use the same port number in order to use that service for remote management Server Access Select the interface s through which a comput...

Страница 127: ...PS proxy server listens on port 443 by default If you change the HTTPS proxy server port to a different number on the ZyXEL Device for example 8443 then you must notify people who need to access the Z...

Страница 128: ...able if TCP IP is configured Figure 78 SNMP Management Model An SNMP managed network consists of two main types of component agents and a manager Server Access Select the interface s through which a c...

Страница 129: ...to retrieve an object variable from the agent GetNext Allows the manager to retrieve the next object variable from a table or list within an agent In SNMPv1 when a manager wants to retrieve all elemen...

Страница 130: ...nabled on in order for the device to send authenticationFailure traps Use a MIB browser to enable or disable snmpEnableAuthenTraps Traps defined in the ZyXEL Private MIB whyReboot 1 3 6 1 4 1 890 1 5...

Страница 131: ...is public and allows all requests Destination Type the IP address of the station to send your SNMP traps to SNMP Service Port You may change the server port number for a service if needed however you...

Страница 132: ...Chapter 11 Remote Management ZyXEL NWA 3100 User s Guide 132...

Страница 133: ...n general works as follows 1 Tim wants to send a private message to Jenny Tim generates a public key pair What is encrypted with one key can only be decrypted using the other 2 Tim keeps the private k...

Страница 134: ...to transmit private keys 12 2 Self signed Certificates You can have the ZyXEL Device act as a certification authority and sign its own certificates 12 3 Verifying a Certificate Before you import a tru...

Страница 135: ...tion 12 4 Configuration Summary This section summarizes how to manage certificates Use the My Certificate screens to generate and export self signed certificates or certification requests and import t...

Страница 136: ...me used to identify this certificate It is recommended that you give each certificate a unique name Type This field displays what kind of certificate this is REQ represents a certification request and...

Страница 137: ...the delete icon to remove the certificate A window displays asking you to confirm that you want to delete the certificate You cannot delete a certificate that one or more features is configured to us...

Страница 138: ...cation request that was generated by the ZyXEL Device The certificate you import replaces the corresponding request in the My Certificates screen You must remove any spaces from the certificate s file...

Страница 139: ...the certificate on the ZyXEL Device Cancel Click Cancel to quit and return to the My Certificates screen Table 46 My Certificate Import LABEL DESCRIPTION Table 47 My Certificate Create LABEL DESCRIPTI...

Страница 140: ...generate and store a request for a certificate Use the My Certificate Details screen to view the certification request and copy it to send to the certification authority Copy the certification request...

Страница 141: ...ails Click CERTIFICATES My Certificates to open the My Certificates screen Figure 82 on page 136 Click the details button to open the My Certificate Details screen You can use this screen to view in d...

Страница 142: ...ault self signed certificate which signs the imported remote host certificates Select this check box to have the ZyXEL Device use this certificate to sign the trusted remote host certificates that you...

Страница 143: ...thority such as Common Name Organizational Unit Organization and Country With self signed certificates this is the same as the Subject Name field Signature Algorithm This field displays the type of al...

Страница 144: ...o convert the binary certificate into a printable form You can copy and paste a certification request into a certification authority s web page an e mail that you send to the certification authority o...

Страница 145: ...untry With self signed certificates this is the same information as in the Subject field Valid From This field displays the date that the certificate becomes applicable The text displays in red and in...

Страница 146: ...depth information about the certification authority s certificate change the certificate s name and set whether or not you want the ZyXEL Device to check a certification authority s list of revoked c...

Страница 147: ...heck box to have the ZyXEL Device not check incoming certificates that are issued by this certification authority against a Certificate Revocation List CRL Certificate Path Click the Refresh button to...

Страница 148: ...e has not yet become applicable Valid To This field displays the date that the certificate expires The text displays in red and includes an Expiring or Expired message if the certificate is about to e...

Страница 149: ...l PEM format PEM uses 64 ASCII characters to convert the binary certificate into a printable form You can copy and paste the certificate into an e mail to send to friends or colleagues or you can copy...

Страница 150: ...Chapter 12 Certificates ZyXEL NWA 3100 User s Guide 150...

Страница 151: ...log entries are all used the log will wrap around and the old logs will be deleted Click a column heading to sort the entries A triangle indicates the direction of the sort order Figure 89 View Log T...

Страница 152: ...arrants more serious attention Some categories such as System Errors consist of both logs and alerts You may differentiate them by their color in the View Log screen Alerts are displayed in red and lo...

Страница 153: ...he selected categories of logs Log Facility Select a location from the drop down list box The log facility allows you to log the messages to different files in the syslog server Refer to the documenta...

Страница 154: ...ogin Fail Someone has failed to log on to the router s web configurator interface TELNET Login Successfully Someone has logged on to the router via telnet TELNET Login Fail Someone has failed to log o...

Страница 155: ...nd a parameter to decide what to record 8 Echo 0 Echo message 11 Time Exceeded 0 Time to live exceeded in transit 1 Fragment reassembly time exceeded 12 Parameter Problem 0 Pointer indicates the error...

Страница 156: ...se the sys logs clear command to erase all of the ZyXEL Device s logs 13 5 Log Command Example This example shows how to set the ZyXEL Device to record the error logs and alerts and then view the resu...

Страница 157: ...a device is not a member of this VLAN then that device cannot manage the ZyXEL Device If no devices are in the management VLAN then no one will be able to access the ZyXEL Device and you will have to...

Страница 158: ...traffic based on the configuration in the RADIUS VLAN screen When you use wireless VLAN and RADIUS VLAN together the ZyXEL Device first tries to assign VLAN IDs based on RADIUS VLAN configuration If...

Страница 159: ...r network must belong to this VLAN group in order to manage the ZyXEL Device Note Mail and FTP servers must have the same management VLAN ID to communicate with the ZyXEL Device See Section 14 2 3 on...

Страница 160: ...rent VLAN IDs This allows you to split wireless stations into groups using similar VLAN IDs Second Rx VLAN ID Enter a number from 1 to 4094 but different from the VLAN ID Traffic received from the LAN...

Страница 161: ...can access the network through the ZyXEL Device VLAN Mapping Table Use this table to map names to VLAN IDs so that the RADIUS server can assign each user or user group a mapped VLAN ID See your RADIU...

Страница 162: ...Type a VLAN Group ID This should be the same as the management VLAN ID on the ZyXEL Device 6 Enable Tx Tagging on the port which you want to connect to the ZyXEL Device Disable Tx Tagging on the port...

Страница 163: ...n page 162 1 In the ZyXEL Device web configurator click VLAN to open the VLAN setup screen 2 Select the Enable VLAN Tagging check box and type a Management VLAN ID 10 in this example in the field prov...

Страница 164: ...the string in the Tunnel Private Group ID attribute is considered as a number ID format for example 2493 The range of the number ID Name string is between 1 and 4094 4c If a or b are not matched the Z...

Страница 165: ...S Remote Access Policy needs to be defined This allows the IAS to compare the user account being authenticated against the group memberships of each VLAN Group 1 Using the Remote Access Policy option...

Страница 166: ...mote Access Policy for VLAN Group 2 The Conditions window displays Select Add to add a condition for this policy to act on 3 In the Select Attribute screen click Windows Groups and the Add button Figu...

Страница 167: ...mbership Click the Edit Profile button Figure 103 Granting Permissions and User Profile Screens 7 The Edit Dial in Profile screen displays Click the Authentication tab and select the Extensible Authen...

Страница 168: ...performed as a safeguard Figure 105 Encryption Tab Settings 9 Click the IP tab and select the Client may request an IP address check box for DHCP support 10 Click the Advanced tab The current default...

Страница 169: ...the list three RADIUS attributes will be added Tunnel Medium Type Tunnel Pvt Group ID Tunnel Type Click the Add button Select Tunnel Medium Type Click the Add button Figure 107 RADIUS Attribute Scree...

Страница 170: ...4094 or a Name for this policy This Name should match a name in the VLAN mapping table on the ZyXEL Device Wireless stations belonging to the VLAN Group specified in this policy will be given a VLAN...

Страница 171: ...Click the Close button The completed Advanced tab configuration should resemble the following screen Figure 111 Completed Advanced Tab Repeat the Configuring Remote Access Policies procedure for each...

Страница 172: ...s example SSID01 s second Rx VLAN ID is set to 2 All incoming packets tagged with VLAN ID 2 are forwarded to SSID02 and also to SSID01 However SSID02 has no second Rx VLAN ID configured and the ZyXEL...

Страница 173: ...ows SSID03 tagged with a VLAN ID of 3 and a Second Rx VLAN ID of 4 Figure 113 Configuring SSID Second Rx VLAN ID Example 6 Click Apply to save these settings Outgoing packets from clients in SSID03 ar...

Страница 174: ...Chapter 14 VLAN ZyXEL NWA 3100 User s Guide 174...

Страница 175: ...for diagnostic purposes Figure 114 System Status The following table describes the labels in this screen Table 61 System Status LABEL DESCRIPTION System Name This is the System Name you can configure...

Страница 176: ...ity to send and receive simultaneously while half duplex indicates that traffic can flow in only one direction at a time The Ethernet port must use the same speed or duplex mode setting as the peer Et...

Страница 177: ...his button to apply the new poll interval you entered above Stop Click this button to stop refreshing statistics Table 62 System Status Show Statistics LABEL DESCRIPTION Table 63 Association List LABE...

Страница 178: ...ID This is the Service Set IDentification name of the AP in an Infrastructure wireless network or wireless station in an Ad Hoc wireless network For our purposes we define an Infrastructure network as...

Страница 179: ...to the ZyXEL Device again Figure 119 Firmware Upload In Process The ZyXEL Device automatically restarts in this time causing a temporary network disconnect In some operating systems you may see the fo...

Страница 180: ...was not successful the following screen will appear Click Return to go back to the F W Upload screen Figure 121 Firmware Upload Error 15 6 Configuration Screen See Chapter 22 on page 205 for informati...

Страница 181: ...vious settings Click Backup to save the ZyXEL Device s current configuration to your computer 15 6 2 Restore Configuration Restore configuration allows you to upload a new or previously saved configur...

Страница 182: ...the default configuration file you may need to change the IP address of your computer to be in the same subnet as that of the default ZyXEL Device IP address 192 168 1 2 See your Quick Start Guide fo...

Страница 183: ...evice to its factory default settings Refer to Section 2 2 on page 40 for more information 15 7 Restart Screen System restart allows you to reboot the ZyXEL Device without turning the power off Click...

Страница 184: ...Chapter 15 Maintenance ZyXEL NWA 3100 User s Guide 184...

Страница 185: ...roducing the SMT 187 General Setup 191 LAN Setup 193 SNMP Configuration 195 System Password 197 System Information and Diagnosis 199 Firmware and Configuration File Maintenance 205 System Maintenance...

Страница 186: ...186...

Страница 187: ...the password you will see the main menu Please note that if there is no activity for longer than five minutes default timeout period after you log in your ZyXEL Device will automatically log you out...

Страница 188: ...ng the SMT Interface The SMT System Management Terminal is the interface that you use to configure your ZyXEL Device Table 67 SMT Menus Overview MENUS SUB MENUS 1 General Setup 3 LAN Setup 3 2 TCP IP...

Страница 189: ...xt field respectively Entering information Type in or press SPACE BAR then press ENTER You need to fill in two types of fields The first requires you to type in the appropriate information The second...

Страница 190: ...ral Setup Use this menu to set up your general information 3 LAN Setup Use this menu to set up your LAN and WLAN connection 22 SNMP Configuration Use this menu to set up SNMP related parameters 23 Sys...

Страница 191: ...1 in the Main Menu to open Menu 1 General Setup as shown next Figure 131 Menu 1 General Setup Fill in the required fields Refer to the following table for more information about these fields Menu 1 G...

Страница 192: ...R These fields are not available on all models IP Address Enter the IP addresses of the DNS servers This field is available when you select User Defined in the field above When you have completed this...

Страница 193: ...AN Setup 18 2 TCP IP Ethernet Setup Use menu 3 2 to configure your ZyXEL Device for TCP IP To edit menu 3 2 enter 3 from the main menu to display Menu 3 LAN Setup When menu 3 appears press 2 and press...

Страница 194: ...your network and the gateway IP address if applicable IP Address Enter the LAN IP address of your ZyXEL Device in dotted decimal notation IP Subnet Mask Your ZyXEL Device will automatically calculate...

Страница 195: ...munity public Trusted Host 0 0 0 0 Trap Community public Destination 0 0 0 0 Press ENTER to Confirm or ESC to Cancel Table 72 Menu 22 SNMP Configuration FIELD DESCRIPTION SNMP Get Community Type the G...

Страница 196: ...ddress of the station to send your SNMP traps to When you have completed this menu press ENTER at the prompt Press ENTER to confirm or ESC to cancel to save your configuration or press ESC to cancel a...

Страница 197: ...configure the system password in this menu Figure 135 Menu 23 System Password You should change the default password If you forget your password you have to restore the default configuration file Refe...

Страница 198: ...Chapter 20 System Password ZyXEL NWA 3100 User s Guide 198...

Страница 199: ...can be used to monitor your ZyXEL Device Specifically it gives you information on your Ethernet and Wireless LAN status and the number of packets sent and received To get to System Status type 24 to...

Страница 200: ...Status This shows the status of the remote node TxPkts This is the number of transmitted packets to this remote node RxPkts This is the number of received packets from this remote node Cols This is th...

Страница 201: ...lowing table describes the fields in this menu Menu 24 2 System Information and Console Port Speed 1 System Information 2 Console Port Speed Please enter selection Menu 24 2 1 System Maintenance Infor...

Страница 202: ...you should look for clues when something goes wrong is the error log Follow the procedures to view the local error trace log 1 Type 24 in the main menu to display Menu 24 System Maintenance 2 From me...

Страница 203: ...he following figure Figure 143 Menu 24 4 System Maintenance Diagnostic Follow the procedure next to get to display this menu 1 From the main menu type 24 to open Menu 24 System Maintenance Menu 24 3 S...

Страница 204: ...Device and the connections Table 75 Menu 24 4 System Maintenance Menu Diagnostic FIELD DESCRIPTION Ping Host Ping the host to see if the links and TCP IP protocol on both systems are working DHCP Rel...

Страница 205: ...your computer under a filename of your choosing ZyNOS ZyXEL Network Operating System sometimes referred to as the ras file is the system firmware and has a bin filename extension With many FTP and TFT...

Страница 206: ...r to the ZyXEL Device 22 2 1 Backup Configuration Using FTP Enter 5 in Menu 24 System Maintenance to get the following screen Figure 144 Menu 24 5 Backup Configuration Table 76 Filename Conventions FI...

Страница 207: ...e ZyXEL Device supports the up downloading of the firmware and the configuration file using TFTP Trivial File Transfer Protocol over LAN Although TFTP should work over WAN as well it is not recommende...

Страница 208: ...he TFTP transfer For details on TFTP commands see following example please consult the documentation of your TFTP client program For UNIX use get to transfer from the ZyXEL Device to the computer and...

Страница 209: ...m Maintenance Starting Xmodem Download Screen 3 Run the HyperTerminal program by clicking Transfer then Receive File as shown in the following screen Figure 148 Backup Configuration Example 4 After a...

Страница 210: ...figuration 22 4 Uploading Firmware and Configuration Files Menu 24 7 System Maintenance Upload Firmware allows you to upgrade the firmware and the configuration file 1 WARNING PLEASE WAIT A FEW MINUTE...

Страница 211: ...You see the following screen when you telnet into menu 24 7 2 Menu 24 7 System Maintenance Upload Firmware 1 Upload System Firmware 2 Upload System Configuration File Enter Menu Selection Number Menu...

Страница 212: ...ee earlier in this chapter for more information on filename conventions 7 Enter quit to exit the FTP prompt Figure 154 FTP Session Example Menu 24 7 2 System Maintenance Upload System Configuration Fi...

Страница 213: ...les between the ZyXEL Device and the computer The file name for the firmware is ras and the configuration file is rom 0 rom zero not capital o Note that the telnet connection must be active and the SM...

Страница 214: ...ogram The procedure for other serial communications programs should be similar 22 4 8 Example Xmodem Firmware Upload Using HyperTerminal Click Transfer then Send File to display the following screen F...

Страница 215: ...then Send File to display the following screen Figure 158 Example Xmodem Upload Menu 24 7 2 System Maintenance Upload System Configuration File To upload system configuration file 1 Enter y at the pro...

Страница 216: ...Chapter 22 Firmware and Configuration File Maintenance ZyXEL NWA 3100 User s Guide 216 After the configuration upload process has completed restart the ZyXEL Device by entering atgo...

Страница 217: ...r more detailed information on CI commands Enter 8 from Menu 24 System Maintenance A list of valid commands can be found by typing help or at the command prompt Type exit to return to the SMT main men...

Страница 218: ...sabling and configuring the brute force password guessing protection mechanism for the password 23 1 3 1 Configuring Brute Force Password Guessing Protection Example sys pwderrtm 5 This command sets t...

Страница 219: ...01 New Date yyyy mm dd 2000 01 01 Time Zone GMT Daylight Saving No Start Date mm dd 01 01 End Date mm dd 01 01 Press ENTER to Confirm or ESC to Cancel Press Space Bar to Toggle Table 80 System Mainten...

Страница 220: ...ote Management Setup Remote management setup is for managing Telnet FTP and Web services You can customize the service port access interface and the secured client IP address to enhance security and f...

Страница 221: ...ET Server FTP Server HTTPS Server HTTP Server SNMP Service Each of these read only labels denotes a server or service that you may use to remotely manage the ZyXEL Device Port This field shows the por...

Страница 222: ...em Timeout There is a system timeout of five minutes 300 seconds for Telnet web FTP connections Your ZyXEL Device will automatically log you out if you do nothing in this timeout period except when it...

Страница 223: ...is connected to the ZyXEL Device and plugged in to an appropriate power source Make sure the power source is turned on 3 Disconnect and re connect the power adaptor or cord to the ZyXEL Device 4 If th...

Страница 224: ...d have forgotten it see the troubleshooting suggestions for I forgot the IP address for the ZyXEL Device 2 Check the hardware connections and make sure the LEDs are behaving as expected See the Quick...

Страница 225: ...or access the Login screen in the web configurator Ignore the suggestions about your browser V I cannot use FTP to upload download the configuration file I cannot use FTP to upload new firmware See t...

Страница 226: ...5 on page 37 If the ZyXEL Device is sending or receiving a lot of information try closing some programs that use the Internet especially peer to peer applications 2 Check the signal strength If the si...

Страница 227: ...IP Address 233 IP Address Assignment Conflicts 245 Wireless LANs 249 Indoor Installation Recommendations 259 Pop up Windows JavaScripts and Java Permissions 261 IP Addresses and Subnetting 267 Text F...

Страница 228: ...228...

Страница 229: ...ensions W x D x H 153 mm x 92 mm x 42 mm Distance between the centers of wall mounting holes on the device s back 60 mm Screw size for wall mounting 6mm 8mm 0 24 0 31 head width Table 83 Firmware Spec...

Страница 230: ...XEL Device allows SSL connections to take place through the ZyXEL Device MAC Address Filter Your ZyXEL Device checks the MAC address of the wireless station against a list of allowed or denied MAC add...

Страница 231: ...ety Standards UL CUL UL 60950 1 First Edition Table 87 European Plug Standards AC Power Adaptor Model MU18 2120150 C5 Input Power 100 240 Volts AC 50 60 Hz 0 6 A Output Power 12 Volts DC 1 5 A Power C...

Страница 232: ...Appendix A Product Specifications ZyXEL NWA 3100 User s Guide 232...

Страница 233: ...a third party TCP IP application package TCP IP should already be installed on computers using Windows NT 2000 XP Macintosh OS 7 and later operating systems After the appropriate TCP IP components ar...

Страница 234: ...then click Add 3 Select the manufacturer and model of your network adapter and then click OK If you need TCP IP 1 In the Network window click Add 2 Select Protocol and then click Add 3 Select Microsof...

Страница 235: ...select Obtain an IP address automatically If you have a static IP address select Specify an IP address and type your information into the IP Address and Subnet Mask fields Figure 164 Windows 95 98 Me...

Страница 236: ...to save and close the TCP IP Properties window 6 Click OK to close the Network window Insert the Windows CD if prompted 7 Turn on your ZyXEL Device and restart your computer when prompted Verifying Se...

Страница 237: ...WA 3100 User s Guide 237 Figure 166 Windows XP Start Menu 2 For Windows XP click Network Connections For Windows 2000 NT click Network and Dial up Connections Figure 167 Windows XP Control Panel 3 Rig...

Страница 238: ...l tab in Win XP and click Properties Figure 169 Windows XP Local Area Connection Properties 5 The Internet Protocol TCP IP Properties window opens the General tab in Windows XP If you have a dynamic I...

Страница 239: ...ings tab by clicking Add in Default gateways In TCP IP Gateway Address type the IP address of the default gateway in Gateway To manually configure a default metric the number of transmission hops clea...

Страница 240: ...perties window 10 Turn on your ZyXEL Device and restart your computer if prompted Verifying Settings 1 Click Start All Programs Accessories and then Command Prompt 2 In the Command Prompt window type...

Страница 241: ...Macintosh OS 8 9 Apple Menu 2 Select Ethernet built in from the Connect via list Figure 173 Macintosh OS 8 9 TCP IP 3 For dynamically assigned settings select Using DHCP Server from the Configure list...

Страница 242: ...onfiguration 7 Turn on your ZyXEL Device and restart your computer if prompted Verifying Settings Check your TCP IP properties in the TCP IP Control Panel window Macintosh OS X 1 Click the Apple menu...

Страница 243: ...rom the Configure box select Manually Type your IP address in the IP Address box Type your subnet mask in the Subnet mask box Type the IP address of your ZyXEL Device in the Router address box 5 Click...

Страница 244: ...Appendix B Setting up Your Computer s IP Address ZyXEL NWA 3100 User s Guide 244...

Страница 245: ...uter on the LAN Figure 176 IP Address Conflicts Case A You must set the ZyXEL Device to use different LAN and WAN IP addresses on different subnets if you enable DHCP server on the ZyXEL Device For ex...

Страница 246: ...you enable DHCP server on the ZyXEL Device For example you set the WAN IP address to 192 59 1 1 and the LAN IP address to 10 59 1 1 Otherwise It is recommended the ZyXEL Device uses a public WAN IP a...

Страница 247: ...Address Assignment Conflicts ZyXEL NWA 3100 User s Guide 247 Figure 179 IP Address Conflicts Case D This problem can be solved by adding a VLAN enabled switch or set the computers to obtain IP address...

Страница 248: ...Appendix C IP Address Assignment Conflicts ZyXEL NWA 3100 User s Guide 248...

Страница 249: ...ndent Basic Service Set IBSS The following diagram shows an example of notebook computers using wireless adapters to form an Ad hoc wireless LAN Figure 180 Peer to Peer Communication in an Ad hoc Netw...

Страница 250: ...ired connection between APs is called a Distribution System DS This type of wireless LAN topology is called an Infrastructure WLAN The Access Points not only provide communication with the wired netwo...

Страница 251: ...y overlap however To avoid interference due to overlap your AP should be on a channel at least five channels away from a channel that an adjacent AP is using For example if your region has 11 channels...

Страница 252: ...requested transmission Stations can send frames smaller than the specified RTS CTS directly to the AP without the RTS Request To Send CTS Clear to Send handshake You should only configure RTS CTS if...

Страница 253: ...ice RFC 2138 2139 for centralized user profile and accounting management on a network RADIUS server Support for EAP Extensible Authentication Protocol RFC 2486 that allows additional authentication me...

Страница 254: ...from unauthorized access Types of Authentication This appendix discusses some popular authentication types EAP MD5 EAP TLS EAP TTLS PEAP and LEAP The type of authentication you use depends on the RADI...

Страница 255: ...hods such as PAP CHAP MS CHAP and MS CHAP v2 PEAP Protected EAP Like EAP TTLS server side certificate authentication is used to establish a secure connection then use simple username and password meth...

Страница 256: ...y to the AP that then sets up a key hierarchy and management system using the pair wise key to dynamically generate unique data encryption keys to encrypt every data packet that is wirelessly communic...

Страница 257: ...password entered into each access point wireless gateway and wireless client As long as the passwords match a wireless client will be granted access to a WLAN If the AP or the wireless clients do not...

Страница 258: ...Appendix D Wireless LANs ZyXEL NWA 3100 User s Guide 258...

Страница 259: ...coverage area Antenna Gain Antenna gain measured in dB decibel is the increase in coverage within the RF beam width Higher antenna gain improves the range of the signal for better communications For a...

Страница 260: ...from 20 degrees very directional to 120 degrees less directional Directional antennas are ideal for hallways and outdoor point to point applications Positioning Antennas In general antennas should be...

Страница 261: ...ernet Explorer Pop up Blockers You may have to disable pop up blocking to log into your device Either disable pop up blocking enabled by default in Windows XP SP Service Pack 2 or allow pop up blockin...

Страница 262: ...y web pop up blockers you may have enabled Figure 185 Internet Options Privacy 3 Click Apply to save this setting Enable pop up Blockers with Exceptions Alternatively if you only want to allow pop up...

Страница 263: ...uide 263 Figure 186 Internet Options Privacy 3 Type the IP address of your device the web page that you do not want to have blocked with the prefix http For example http 192 168 167 1 4 Click Add to m...

Страница 264: ...splay properly in Internet Explorer check that JavaScripts are allowed 1 In Internet Explorer click Tools Internet Options and then the Security tab Figure 188 Internet Options Security 2 Click the Cu...

Страница 265: ...ttings Java Scripting Java Permissions 1 From Internet Explorer click Tools Internet Options and then the Security tab 2 Click the Custom Level button 3 Scroll down to Microsoft VM 4 Under Java permis...

Страница 266: ...ermissions ZyXEL NWA 3100 User s Guide 266 JAVA Sun 1 From Internet Explorer click Tools Internet Options and then the Advanced tab 2 Make sure that Use Java 2 for applet under Java Sun is selected 3...

Страница 267: ...share a common street name the hosts on a network share a common network number Similarly as each house has its own house number each host on the network has its own unique identifying number the hos...

Страница 268: ...n the IP address is part of the host ID The following example shows a subnet mask identifying the network number in bold text and host ID of an IP address 192 168 1 2 in decimal By convention subnet m...

Страница 269: ...wed by a continuous number of zeros for the remainder of the 32 bit mask you can simply specify the number of ones instead of writing the value of each octet This is usually specified by writing a fol...

Страница 270: ...shows the company network before subnetting Figure 193 Subnetting Example Before Subnetting You can borrow one of the host ID bits to divide the network 192 168 1 0 into two separate sub networks The...

Страница 271: ...168 1 254 Example Four Subnets The previous example illustrated using a 25 bit subnet mask to divide a 24 bit address into two subnets Similarly to divide a 24 bit address into four subnets you need t...

Страница 272: ...ubnet 3 IP SUBNET MASK NETWORK NUMBER LAST OCTET BIT VALUE IP Address 192 168 1 128 IP Address Binary 11000000 10101000 00000001 10000000 Subnet Mask Binary 11111111 11111111 11111111 11000000 Subnet...

Страница 273: ...ST BITS SUBNET MASK NO SUBNETS NO HOSTS PER SUBNET 1 255 255 255 128 25 2 126 2 255 255 255 192 26 4 62 3 255 255 255 224 27 8 30 4 255 255 255 240 28 16 14 5 255 255 255 248 29 32 6 6 255 255 255 252...

Страница 274: ...u entered You don t need to change the subnet mask computed by the ZyXEL Device unless you are instructed to do otherwise Private IP Addresses Every machine on the Internet must have a unique address...

Страница 275: ...e wireless LAN settings on multiple APs The AP can automatically get a configuration file from a TFTP server at startup or after renewing DHCP client information Figure 195 Text File Based Auto Config...

Страница 276: ...the following command to manually configure a TFTP server IP address and a file name for the AP to use for auto provisioning whenever the AP starts up See Section 23 1 on page 217 for how to access th...

Страница 277: ...rsion of the downloaded file is the same or smaller older the AP ignores the file If the version of the downloaded file is larger newer the AP uses the file Configuration File Rules You can only use t...

Страница 278: ...ust use the store compression method and a zip file extension When zipping a configuration file you can also add password protection using the same password that you use to log into the AP wcfg Comman...

Страница 279: ...dius 2 primary 172 23 3 4 1812 1234 enable wcfg radius 2 backup 172 23 3 5 1812 1234 enable wcfg radius save wcfg ssid 2 name ssid 8021x wcfg ssid 2 security Test 8021x wcfg ssid 2 radius radius rd wc...

Страница 280: ...that the commands are applied in order So for example you would place the commands that create security and SSID profiles before the commands that tell the AP to use those profiles ZYXEL PROWLAN VERSI...

Страница 281: ...me ssid wpapsk wcfg ssid 3 security Test wpapsk wcfg ssid 4 name ssid wpa2psk wcfg ssid 4 security Test wpa2psk wcfg ssid save line starting with is comment change to channel 8 wlan chid 8 change oper...

Страница 282: ...Appendix H Text File Based Auto Configuration ZyXEL NWA 3100 User s Guide 282...

Страница 283: ...tice Trademarks ZyNOS ZyXEL Network Operating System is a registered trademark of ZyXEL Communications Inc Other trademarks mentioned in this publication are used for identification purposes only and...

Страница 284: ...in conjunction with any other antenna or transmitter For operation within 5 15 5 25GHz frequency range it is restricted to indoor environment IEEE 802 11b or 802 11g operation of this product in the...

Страница 285: ...with damaged by an act of God or subjected to abnormal working conditions Note Repair or replacement as provided under this warranty is the exclusive remedy of the purchaser This warranty is in lieu...

Страница 286: ...Appendix I Legal Information ZyXEL NWA 3100 User s Guide 286...

Страница 287: ...78 2439 Web Site www zyxel com www europe zyxel com FTP Site ftp zyxel com ftp europe zyxel com Regular Mail ZyXEL Communications Corp 6 Innovation Road II Science Park Hsinchu 300 Taiwan Costa Rica S...

Страница 288: ...nki Finland France E mail info zyxel fr Telephone 33 4 72 52 97 97 Fax 33 4 72 52 19 20 Web Site www zyxel fr Regular Mail ZyXEL France 1 rue des Vergers Bat 1 C 69760 Limonest France Germany Support...

Страница 289: ...01 U S A Norway Support E mail support zyxel no Sales E mail sales zyxel no Telephone 47 22 80 61 80 Fax 47 22 80 61 81 Web Site www zyxel no Regular Mail ZyXEL Communications A S Nils Hansens vei 13...

Страница 290: ...il support ua zyxel com Sales E mail sales ua zyxel com Telephone 380 44 247 69 78 Fax 380 44 494 49 32 Web Site www ua zyxel com Regular Mail ZyXEL Ukraine 13 Pimonenko Str Kiev 04050 Ukraine United...

Страница 291: ...see CA certificates thumbprint algorithms 134 thumbprints 134 verifying fingerprints 134 certifications 283 notices 284 viewing 285 channel 251 interference 251 CI commands valid 218 Class of Service...

Страница 292: ...host 64 humidity 229 HyperTerminal 209 I IANA 274 Internet Assigned Numbers Authority see IANA IBSS 249 IEEE 802 1x 253 in band management 161 Independent Basic Service Set 178 249 Internet access 19...

Страница 293: ...me 89 90 91 93 94 registration product 285 related documentation 3 remote management Telnet 124 remote management limitations 124 222 remote management setup 220 remote node 200 required fields 189 RE...

Страница 294: ...TP restrictions 222 TFTP file transfer 213 time and date setting 219 time setting 65 time zone 220 ToS 71 trace records 202 trademarks 283 tutorial 43 Type of Service 71 U upload firmware 210 user aut...

Отзывы: