User Guide
Page 12
... ...218 15.9.2 SNMP Traps ...218 15.9.3 Configuring SNMP 219 15.9.4 Adding or Editing an SNMPv3 User Profile 220 15.10 Internal RADIUS Server 221 15.10.1 Configuring the Internal RADIUS Server 222 15.10.2 Adding or Editing a Trusted AP Profile 224 15.11 Technical Reference ...225 Chapter 16 Log and Report ...227...
... ...218 15.9.2 SNMP Traps ...218 15.9.3 Configuring SNMP 219 15.9.4 Adding or Editing an SNMPv3 User Profile 220 15.10 Internal RADIUS Server 221 15.10.1 Configuring the Internal RADIUS Server 222 15.10.2 Adding or Editing a Trusted AP Profile 224 15.11 Technical Reference ...225 Chapter 16 Log and Report ...227...
User Guide
Page 58
...: Enter 10.10.99.10. • Management VLAN ID: Enter '99' as the VLAN ID tag. • Click Apply to set up the controller's internal RADIUS server and user accounts. See Chapter 7 on page 103 for details. 4.1.3 Set Up Wireless User Authentication This section shows you first logged into the NWA3000...
...: Enter 10.10.99.10. • Management VLAN ID: Enter '99' as the VLAN ID tag. • Click Apply to set up the controller's internal RADIUS server and user accounts. See Chapter 7 on page 103 for details. 4.1.3 Set Up Wireless User Authentication This section shows you first logged into the NWA3000...
User Guide
Page 61
2 The Add Security Profile window opens. NWA3000-N Series User's Guide 61 Chapter 4 Tutorials 2a Profile Name: Enter wap2. 2b Security Mode: Select wpa2 from the list of available wireless security encryption methods. 2c Under Security Mode, select 802.1X then set the Radius Server Type to Internal. 2d Click OK. 3 Next, open the Configuration > Object > AP Profile > SSID > SSID List screen and click the Add button.
2 The Add Security Profile window opens. NWA3000-N Series User's Guide 61 Chapter 4 Tutorials 2a Profile Name: Enter wap2. 2b Security Mode: Select wpa2 from the list of available wireless security encryption methods. 2c Under Security Mode, select 802.1X then set the Radius Server Type to Internal. 2d Click OK. 3 Next, open the Configuration > Object > AP Profile > SSID > SSID List screen and click the Add button.
User Guide
Page 67
... also: Chapter 6 on page 83 and Chapter 13 on page 165. 4.2.1 Rogue AP Containment When the NWA3000-N series AP discovers a rogue AP within its broadcast radius, it can react in one , then the NWA3000-N series AP can interfere with it . Chapter 4 Tutorials When the Edit AP List window opens, configure the...
... also: Chapter 6 on page 83 and Chapter 13 on page 165. 4.2.1 Rogue AP Containment When the NWA3000-N series AP discovers a rogue AP within its broadcast radius, it can react in one , then the NWA3000-N series AP can interfere with it . Chapter 4 Tutorials When the Edit AP List window opens, configure the...
User Guide
Page 71
... as long as the area in an area with a large number of competing APs, set the DCS Sensitivity Level to other APs within its broadcast radius. Generally, as long as any wireless clients are to Low. Choose FourChannel Deployment to them. 1 Click Configuration > Wireless > DCS. Choose Three-Channel Deployment to have...
... as long as the area in an area with a large number of competing APs, set the DCS Sensitivity Level to other APs within its broadcast radius. Generally, as long as any wireless clients are to Low. Choose FourChannel Deployment to them. 1 Click Configuration > Wireless > DCS. Choose Three-Channel Deployment to have...
User Guide
Page 105
... IP address of the CAPWAP AP controller on CAPWAP This section lists some additional features of ZyXEL's implementation of the CAPWAP protocol. • When the AP controller uses its internal Remote Authentication Dial In User Service (RADIUS) server, managed APs also use the AP controller's authentication server to authenticate wireless clients. •...
... IP address of the CAPWAP AP controller on CAPWAP This section lists some additional features of ZyXEL's implementation of the CAPWAP protocol. • When the AP controller uses its internal Remote Authentication Dial In User Service (RADIUS) server, managed APs also use the AP controller's authentication server to authenticate wireless clients. •...
User Guide
Page 120
... idle the longest will be kicked first. Devices that the AP withholds the connection until it shunts the connection to another AP within the broadcast radius that there are idle, then the priority shifts to an overloaded AP will be kicked first. otherwise, a wireless client attempting to connect to Signal Strength... can take. If none of 6 Mbps. For example, here the AP has a balanced bandwidth allotment of the connected devices are multiple APs within its broadcast radius.
... idle the longest will be kicked first. Devices that the AP withholds the connection until it shunts the connection to another AP within the broadcast radius that there are idle, then the priority shifts to an overloaded AP will be kicked first. otherwise, a wireless client attempting to connect to Signal Strength... can take. If none of 6 Mbps. For example, here the AP has a balanced bandwidth allotment of the connected devices are multiple APs within its broadcast radius.
User Guide
Page 122
... AP surveys the other devices. Figure 52 Configuration > Wireless > DCS Each field is currently broadcasting suddenly comes into use by other APs within its broadcast radius. Chapter 9 Wireless 9.6 DCS Use this screen to have the NWA3000-N series AP automatically select the radio channel upon which it and determining what channels are...
... AP surveys the other devices. Figure 52 Configuration > Wireless > DCS Each field is currently broadcasting suddenly comes into use by other APs within its broadcast radius. Chapter 9 Wireless 9.6 DCS Use this screen to have the NWA3000-N series AP automatically select the radio channel upon which it and determining what channels are...
User Guide
Page 138
... Accounts (continued) TYPE ABILITIES limited-admin Look at NWA3000-N series AP configuration (web, CLI) Access Users user Perform basic diagnostics (CLI) Used for the embedded RADIUS server and SNMPv3 user access Browse user-mode commands (CLI) LOGIN METHOD(S) WWW, TELNET, SSH, Console Note: The default admin account is not associated with...
... Accounts (continued) TYPE ABILITIES limited-admin Look at NWA3000-N series AP configuration (web, CLI) Access Users user Perform basic diagnostics (CLI) Used for the embedded RADIUS server and SNMPv3 user access Browse user-mode commands (CLI) LOGIN METHOD(S) WWW, TELNET, SSH, Console Note: The default admin account is not associated with...
User Guide
Page 139
... • debug • ldap-users • operator • sync • admin • any • devicehaecived • ftp • lp • mail • radius-users • root • uucp • zyxel • bin • games • news • shutdown • daemon • halt • nobody • sshd NWA3000-N Series User's Guide 139 User...
... • debug • ldap-users • operator • sync • admin • any • devicehaecived • ftp • lp • mail • radius-users • root • uucp • zyxel • bin • games • news • shutdown • daemon • halt • nobody • sshd NWA3000-N Series User's Guide 139 User...
User Guide
Page 140
... screen, go to 60 printable ASCII characters. Table 49 Configuration > User > User > Add/Edit A User LABEL DESCRIPTION User Name Type the user name for embedded RADIUS server and SNMPv3 user access This field is used for this user can look at and change it correctly. this user account. User names have...
... screen, go to 60 printable ASCII characters. Table 49 Configuration > User > User > Add/Edit A User LABEL DESCRIPTION User Name Type the user name for embedded RADIUS server and SNMPv3 user access This field is used for this user can look at and change it correctly. this user account. User names have...
User Guide
Page 143
this is used for embedded RADIUS server and SNMPv3 user access This is logged out. Admin users renew the session every time the main screen refreshes in minutes for administration account ...
this is used for embedded RADIUS server and SNMPv3 user access This is logged out. Admin users renew the session every time the main screen refreshes in minutes for administration account ...
User Guide
Page 148
... MAC filtering profiles on the NWA3000-N series AP. Wireless stations associating to keep network communications private. In other words, it is done using an external RADIUS server. 148 NWA3000-N Series User's Guide Authentication is the name of the wireless network that defines stronger encryption, authentication and key management than WPA.
... MAC filtering profiles on the NWA3000-N series AP. Wireless stations associating to keep network communications private. In other words, it is done using an external RADIUS server. 148 NWA3000-N Series User's Guide Authentication is the name of the wireless network that defines stronger encryption, authentication and key management than WPA.
User Guide
Page 152
... to reduce data collisions on the wireless network if you enter here. Note: Reducing the output power also reduces the NWA3000-N series AP's effective broadcast radius. 152 NWA3000-N Series User's Guide Message Protocol Data Unit (MPDU) aggregation collects Ethernet frames along with it transmits. The threshold (number of the access point...
... to reduce data collisions on the wireless network if you enter here. Note: Reducing the output power also reduces the NWA3000-N series AP's effective broadcast radius. 152 NWA3000-N Series User's Guide Message Protocol Data Unit (MPDU) aggregation collects Ethernet frames along with it transmits. The threshold (number of the access point...
User Guide
Page 159
...following table describes the labels in the Web Configurator and is displayed here. Server Activate Radius Server Enter the IP address of the RADIUS server to enable 802.1x secure authentication. Radius Server Type Select internal to use the NWA3000-N series AP's internal authentication database, ... or select a security profile from the list: wep, wpa, wpa2, or wpa2mix. 802.1X Select this screen. Radius Server Enter the port number of the RADIUS server to be used for authentication. Only the default screen is only for IP Address authentication. Table 57 SSID > Security...
...following table describes the labels in the Web Configurator and is displayed here. Server Activate Radius Server Enter the IP address of the RADIUS server to enable 802.1x secure authentication. Radius Server Type Select internal to use the NWA3000-N series AP's internal authentication database, ... or select a security profile from the list: wep, wpa, wpa2, or wpa2mix. 802.1X Select this screen. Radius Server Enter the port number of the RADIUS server to be used for authentication. Only the default screen is only for IP Address authentication. Table 57 SSID > Security...
User Guide
Page 221
...SNMPv3 communications. Select the type of trusted APs. Select whether the SNMPv3 user can use its internal Remote Authentication Dial In User Service (RADIUS) server to authenticate the wireless clients of encryption the SNMPv3 user must use to connect to a network by MD5 for authentication...Select DES to use AES to the NWA3000-N series AP using this SNMPv3 user profile. Click OK to save your changes. 15.10 Internal RADIUS Server The NWA3000-N series AP can have read-only or read and write access to encrypt the SNMPv3 communications. Authentication Select the type of ...
...SNMPv3 communications. Select the type of trusted APs. Select whether the SNMPv3 user can use its internal Remote Authentication Dial In User Service (RADIUS) server to authenticate the wireless clients of encryption the SNMPv3 user must use to connect to a network by MD5 for authentication...Select DES to use AES to the NWA3000-N series AP using this SNMPv3 user profile. Click OK to save your changes. 15.10 Internal RADIUS Server The NWA3000-N series AP can have read-only or read and write access to encrypt the SNMPv3 communications. Authentication Select the type of ...
User Guide
Page 222
...the Object > Users screen. 222 NWA3000-N Series User's Guide Certificates ensure that the RADIUS server can function as an AP and as a RADIUS server at the same time. 15.10.1 Configuring the Internal RADIUS Server Use this is held on the utility must have a user name and password configured...login details to the NWA3000-N series AP. Chapter 15 System The following figure shows how this screen to turn the NWA3000-N series AP's internal RADIUS server off or on, select the certificate it uses, and maintain a list of trusted client APs. Wireless clients make access requests to trusted...
...the Object > Users screen. 222 NWA3000-N Series User's Guide Certificates ensure that the RADIUS server can function as an AP and as a RADIUS server at the same time. 15.10.1 Configuring the Internal RADIUS Server Use this is held on the utility must have a user name and password configured...login details to the NWA3000-N series AP. Chapter 15 System The following figure shows how this screen to turn the NWA3000-N series AP's internal RADIUS server off or on, select the certificate it uses, and maintain a list of trusted client APs. Wireless clients make access requests to trusted...
User Guide
Page 223
... this to edit the selected trusted AP profile. Server The following screen displays. Authentication Server Certificate Select the certificate the NWA3000-N series AP's internal RADIUS server uses for which the NWA3000-N series AP authenticates wireless clients. This field is a sequential value, and it and click Inactivate. The following ... > Auth. NWA3000-N Series User's Guide 223 Server LABEL DESCRIPTION Enable Authentication Server Select this to have the NWA3000-N series AP use its internal RADIUS server to authenticate wireless clients connecting to trusted APs.
... this to edit the selected trusted AP profile. Server The following screen displays. Authentication Server Certificate Select the certificate the NWA3000-N series AP's internal RADIUS server uses for which the NWA3000-N series AP authenticates wireless clients. This field is a sequential value, and it and click Inactivate. The following ... > Auth. NWA3000-N Series User's Guide 223 Server LABEL DESCRIPTION Enable Authentication Server Select this to have the NWA3000-N series AP use its internal RADIUS server to authenticate wireless clients connecting to trusted APs.
User Guide
Page 224
... this to turn on this screen afresh. 15.10.2 Adding or Editing a Trusted AP Profile This screen allows you to add or edit an internal RADIUS server trusted AP profile. Profile Name Type a name for all computers in this screen, click the Configuration > System > Auth. Server screen's Add button or select...
... this to turn on this screen afresh. 15.10.2 Adding or Editing a Trusted AP Profile This screen allows you to add or edit an internal RADIUS server trusted AP profile. Profile Name Type a name for all computers in this screen, click the Configuration > System > Auth. Server screen's Add button or select...
User Guide
Page 225
...User's Guide 225 Description OK Cancel Both the NWA3000-N series AP's IP address and this shared secret must be configured in the "external RADIUS" server fields of the trusted AP. Click Cancel to exit this screen without saving your NWA3000-N series AP. When authentication begins, a ..., no spaces) as the key for more information on page 319 for encrypting communications between the NWA3000-N series AP and this chapter. Internal RADIUS Server PEAP (Protected EAP) and MD5 authentication is not sent over a secure TLS connection. Specify a name and password only, do not ...
...User's Guide 225 Description OK Cancel Both the NWA3000-N series AP's IP address and this shared secret must be configured in the "external RADIUS" server fields of the trusted AP. Click Cancel to exit this screen without saving your NWA3000-N series AP. When authentication begins, a ..., no spaces) as the key for more information on page 319 for encrypting communications between the NWA3000-N series AP and this chapter. Internal RADIUS Server PEAP (Protected EAP) and MD5 authentication is not sent over a secure TLS connection. Specify a name and password only, do not ...