User Guide
Page 17
... spectrums and the IEEE 802.11n standard's high bandwidth to install, configure and use different WLAN and security settings for how to eight simultaneous independent virtual APs. It uses Multiple BSSID and VLAN to provide up to help eliminate network threats. See the Quick Start Guide for various virtual and managed APs. CHAPTER 1 Introduction 1.1 Overview Your NWA3000-N series AP's business-class reliability, SMB features, and centralized wireless management make hardware connections.
... spectrums and the IEEE 802.11n standard's high bandwidth to install, configure and use different WLAN and security settings for how to eight simultaneous independent virtual APs. It uses Multiple BSSID and VLAN to provide up to help eliminate network threats. See the Quick Start Guide for various virtual and managed APs. CHAPTER 1 Introduction 1.1 Overview Your NWA3000-N series AP's business-class reliability, SMB features, and centralized wireless management make hardware connections.
User Guide
Page 22
... "security settings" refers to access the wired network, while X and Y communicate in AP + Bridge mode, security between APs (WDS) is the name of devices forming a single wireless network (usually an access point and one or more wireless clients). When the NWA3000-N series AP is in bridge mode. In Multiple BSS (MBSSID) mode, the 22 NWA3000-N Series User's Guide In the figure below, A and B use the same pre-shared key. Figure 6 AP + Bridge Application Y X A B 1.2.3 MBSSID A Basic Service Set...
... "security settings" refers to access the wired network, while X and Y communicate in AP + Bridge mode, security between APs (WDS) is the name of devices forming a single wireless network (usually an access point and one or more wireless clients). When the NWA3000-N series AP is in bridge mode. In Multiple BSS (MBSSID) mode, the 22 NWA3000-N Series User's Guide In the figure below, A and B use the same pre-shared key. Figure 6 AP + Bridge Application Y X A B 1.2.3 MBSSID A Basic Service Set...
User Guide
Page 23
... users, set varying access privileges, and prioritize network traffic to be a different access point. This centralized management can assign different wireless and security settings to each SSID appears to and from certain BSSs. Chapter 1 Introduction NWA3000-N series AP provides multiple virtual APs, each forming its own individual SSID profile. As in this group (ZLD-based models) can manage other APs in any wireless network, clients can also use legacy device information hyper-links to connect...
... users, set varying access privileges, and prioritize network traffic to be a different access point. This centralized management can assign different wireless and security settings to each SSID appears to and from certain BSSs. Chapter 1 Introduction NWA3000-N series AP provides multiple virtual APs, each forming its own individual SSID profile. As in this group (ZLD-based models) can manage other APs in any wireless network, clients can also use legacy device information hyper-links to connect...
User Guide
Page 36
... and manage certificates from wireless clients. System Host Name Configure the system and domain name for rogue APs. MON Mode Configure how the NWA3000-N series AP monitors for the NWA3000-N series AP. SSID Create and manage wireless SSID, security, and MAC filtering settings files that can be associated with different APs. Load Balancing Configure load balancing for the NWA3000N series AP. 36 NWA3000-N Series User's Guide SSH Configure SSH server and SSH service settings. TELNET Configure telnet server settings for traffic moving...
... and manage certificates from wireless clients. System Host Name Configure the system and domain name for rogue APs. MON Mode Configure how the NWA3000-N series AP monitors for the NWA3000-N series AP. SSID Create and manage wireless SSID, security, and MAC filtering settings files that can be associated with different APs. Load Balancing Configure load balancing for the NWA3000N series AP. 36 NWA3000-N Series User's Guide SSH Configure SSH server and SSH service settings. TELNET Configure telnet server settings for traffic moving...
User Guide
Page 79
... interface gets its IP address from a DHCP server. For example, this displays Status Summary status information for the interface. WLAN Interface When the NWA3000-N series AP is a backup interface in the virtual router. The possible values depend on the interface. Device HA is a backup). This is either the static IP address of the interface (if it is the master) or the management IP address (if it is down. NWA3000-N Series User's Guide 79 Use this AP. This interface has a static IP address. AP MAC...
... interface gets its IP address from a DHCP server. For example, this displays Status Summary status information for the interface. WLAN Interface When the NWA3000-N series AP is a backup interface in the virtual router. The possible values depend on the interface. Device HA is a backup). This is either the static IP address of the interface (if it is the master) or the management IP address (if it is down. NWA3000-N Series User's Guide 79 Use this AP. This interface has a static IP address. AP MAC...
User Guide
Page 85
... virtual router. This is available when the NWA3000-N series AP is not connected. This interface is not active on the physical port since it is connected. This interface has a static IP address. Click Renew to send a new DHCP request to the interface. NWA3000-N Series User's Guide 85 Device HA is the master interface in controller mode. This field displays the current IP address and subnet mask assigned to a DHCP server. Action Port Statistics Table Switch to update...
... virtual router. This is available when the NWA3000-N series AP is not connected. This interface is not active on the physical port since it is connected. This interface has a static IP address. Click Renew to send a new DHCP request to the interface. NWA3000-N Series User's Guide 85 Device HA is the master interface in controller mode. This field displays the current IP address and subnet mask assigned to a DHCP server. Action Port Statistics Table Switch to update...
User Guide
Page 133
... NWA3000-N series APs in the list. Inactivate To turn on a secure network. Link Status This tells whether the monitored interface's connection is the master NWA3000-N series AP's (static) IP address and subnet mask for this NWA3000-N series AP. Virtual Router IP / Netmask This is down or up. Now Server Port If this NWA3000-N series AP is the entry's index number in backup role can get updated configuration. Click the link if you have a backup NWA3000-N series AP...
... NWA3000-N series APs in the list. Inactivate To turn on a secure network. Link Status This tells whether the monitored interface's connection is the master NWA3000-N series AP's (static) IP address and subnet mask for this NWA3000-N series AP. Virtual Router IP / Netmask This is down or up. Now Server Port If this NWA3000-N series AP is the entry's index number in backup role can get updated configuration. Click the link if you have a backup NWA3000-N series AP...
User Guide
Page 143
... user can login unsuccessfully (for each type of the NWA3000-N series AP • limited-admin - Type the maximum number of time. Lease Time • admin - this , admin users can be between 1 and 99. User Lockout Settings Enable logon retry limit Select this check box if you do not select this is used for embedded RADIUS server and SNMPv3 user access This is the default lease time in one session before the IP address is logged...
... user can login unsuccessfully (for each type of the NWA3000-N series AP • limited-admin - Type the maximum number of time. Lease Time • admin - this , admin users can be between 1 and 99. User Lockout Settings Enable logon retry limit Select this check box if you do not select this is used for embedded RADIUS server and SNMPv3 user access This is the default lease time in one session before the IP address is logged...
User Guide
Page 153
...'s documentation to enable Advanced Encryption System (AES) security on your WDS enter the AP's MAC address and a pre-shared key. Each access point can use the same encryption method to TKIP. Configure WDS security and the relevant PSK in your WDS. Edit Activate Inactivate # Status Note: Other APs must use a different pre-shared key. Click this if the other ZyXEL NWA access points only. To turn on your network support WDS security...
...'s documentation to enable Advanced Encryption System (AES) security on your WDS enter the AP's MAC address and a pre-shared key. Each access point can use the same encryption method to TKIP. Configure WDS security and the relevant PSK in your WDS. Edit Activate Inactivate # Status Note: Other APs must use a different pre-shared key. Click this if the other ZyXEL NWA access points only. To turn on your network support WDS security...
User Guide
Page 199
... console port. Click Reset to return the screen to the NWA3000-N series AP via the console port using terminal emulation software and NOT the Console in this screen. Apply Reset The Console Port Speed applies to open this screen. Click Configuration > System > Console Speed to a console port connection using a terminal emulation program. Your NWA3000-N series AP supports 9600, 19200, 38400, 57600, and 115200 bps (default) for default console port settings. See Table 1 on page 25 for the console port. NWA3000-N Series User's Guide...
... console port. Click Reset to return the screen to the NWA3000-N series AP via the console port using terminal emulation software and NOT the Console in this screen. Apply Reset The Console Port Speed applies to open this screen. Click Configuration > System > Console Speed to a console port connection using a terminal emulation program. Your NWA3000-N series AP supports 9600, 19200, 38400, 57600, and 115200 bps (default) for default console port settings. See Table 1 on page 25 for the console port. NWA3000-N Series User's Guide...
User Guide
Page 201
... the NWA3000-N series AP blocks all HTTP connection attempts. 15.5.4 Configuring WWW Service Control Click Configuration > System > WWW to port 80 (by default) on the NWA3000-N series AP is optional and if selected means the HTTPS client must apply for a certificate for more information). Figure 89 HTTP/HTTPS Implementation Note: If you disable HTTP in the WWW screen). Authenticate Client Certificates is used so that...
... the NWA3000-N series AP blocks all HTTP connection attempts. 15.5.4 Configuring WWW Service Control Click Configuration > System > WWW to port 80 (by default) on the NWA3000-N series AP is optional and if selected means the HTTPS client must apply for a certificate for more information). Figure 89 HTTP/HTTPS Implementation Note: If you disable HTTP in the WWW screen). Authenticate Client Certificates is used so that...
User Guide
Page 213
... interface SSH client program to remotely access the NWA3000-N series AP. Click Yes to continue. Chapter 15 System 15.6.5 Examples of Secure Telnet Using SSH This section shows two examples using the OpenSSH client program that comes with most SSH client programs. Refer to your SSH client program user's guide. 15.6.5.1 Example 1: Microsoft Windows This section describes how to access the NWA3000-N series AP using the Secure Shell Client program. 1 Launch the SSH client and specify the connection information (IP address, port number...
... interface SSH client program to remotely access the NWA3000-N series AP. Click Yes to continue. Chapter 15 System 15.6.5 Examples of Secure Telnet Using SSH This section shows two examples using the OpenSSH client program that comes with most SSH client programs. Refer to your SSH client program user's guide. 15.6.5.1 Example 1: Microsoft Windows This section describes how to access the NWA3000-N series AP using the Secure Shell Client program. 1 Launch the SSH client and specify the connection information (IP address, port number...
User Guide
Page 219
... managers using SNMPv2c to access the NWA3000N series AP using SNMP. You can also configure profiles that service for remote management. Destination Type the IP address of the station to send your SNMP traps to configure your NWA3000-N series AP's SNMP settings, click Configuration > System > SNMP tab. The screen appears as shown. Use this screen to . NWA3000-N Series User's Guide 219 Chapter 15 System 15.9.3 Configuring SNMP To change the server port number for a service if needed...
... managers using SNMPv2c to access the NWA3000N series AP using SNMP. You can also configure profiles that service for remote management. Destination Type the IP address of the station to send your SNMP traps to configure your NWA3000-N series AP's SNMP settings, click Configuration > System > SNMP tab. The screen appears as shown. Use this screen to . NWA3000-N Series User's Guide 219 Chapter 15 System 15.9.3 Configuring SNMP To change the server port number for a service if needed...
User Guide
Page 243
...-N series AP checks the first line and applies the line if no errors are comments. The NWA3000-N series AP ignores any errors. 17.2 Configuration File Click Maintenance > File Manager > Configuration File to open this is not a startup-config.conf when you back up your previous settings. Errors in the configuration file or shell script and applies all of the valid commands. Use the Configuration File screen to your configuration file before making further configuration changes. You can also download configuration files...
...-N series AP checks the first line and applies the line if no errors are comments. The NWA3000-N series AP ignores any errors. 17.2 Configuration File Click Maintenance > File Manager > Configuration File to open this is not a startup-config.conf when you back up your previous settings. Errors in the configuration file or shell script and applies all of the valid commands. Use the Configuration File screen to your configuration file before making further configuration changes. You can also download configuration files...
User Guide
Page 273
... activate device HA before connecting the bridge interfaces or disable the bridge interfaces, connect the bridge interfaces, activate device HA, and finally reactivate the bridge interfaces. NWA3000-N Series User's Guide 273 Chapter 21 Troubleshooting If a RADIUS server authenticates wireless stations, the re-authentication timer on both. Device HA is the master or a backup. Change the RADIUS server's configuration if you need to use the same device HA mode (active- The management IP address should be connected to the same subnet as the interface IP address. • Enable monitoring...
... activate device HA before connecting the bridge interfaces or disable the bridge interfaces, connect the bridge interfaces, activate device HA, and finally reactivate the bridge interfaces. NWA3000-N Series User's Guide 273 Chapter 21 Troubleshooting If a RADIUS server authenticates wireless stations, the re-authentication timer on both. Device HA is the master or a backup. Change the RADIUS server's configuration if you need to use the same device HA mode (active- The management IP address should be connected to the same subnet as the interface IP address. • Enable monitoring...
User Guide
Page 276
... page 221 for analysis. 276 NWA3000-N Series User's Guide For example, if the security mode on the AP is set up to receive its static IP address. • Authentication of the wireless client with static IPs, make sure the authentication server is matches the security settings in diagnostic tools and CLI console to get an IP: Check the wireless client's own network configuration settings to ensure that it is set to capture data that the server settings for more . • If you...
... page 221 for analysis. 276 NWA3000-N Series User's Guide For example, if the security mode on the AP is set up to receive its static IP address. • Authentication of the wireless client with static IPs, make sure the authentication server is matches the security settings in diagnostic tools and CLI console to get an IP: Check the wireless client's own network configuration settings to ensure that it is set to capture data that the server settings for more . • If you...
User Guide
Page 280
Table 97 Firmware Specifications Default IP Address 192.168.1.2 Default Subnet Mask 255.255.255.0 (24 bits) Default Password 1234 Wireless LAN Standards IEEE 802.11a, IEEE 802.11b, IEEE 802.11g, IEEE 802.11n Security and Control • WPA and WPA2 (Wi-Fi Protected Access) support, Mixed WPA and WPA2 support • 64 and 128 bit WEP, Mixed 802.1x/WEP and WPA support • 802.1x authentication • EAP...
Table 97 Firmware Specifications Default IP Address 192.168.1.2 Default Subnet Mask 255.255.255.0 (24 bits) Default Password 1234 Wireless LAN Standards IEEE 802.11a, IEEE 802.11b, IEEE 802.11g, IEEE 802.11n Security and Control • WPA and WPA2 (Wi-Fi Protected Access) support, Mixed WPA and WPA2 support • 64 and 128 bit WEP, Mixed 802.1x/WEP and WPA support • 802.1x authentication • EAP...
User Guide
Page 299
...-N series AP could not connect to the CAPWAP server. 1st %02x ~ 6th %02x: Managed AP MAC Address. 7th %s: Managed AP Model Name. 8th %s: Managed AP Description. WLAN Controller End. The address configured for authenticating with SMTP account %s2. Registration Type:%s WLAN Controller Reset. The AP management service has ended. Add a Managed AP. Indicates that AP management services has started. Cannot resolve mail server address %s. The (listed) SMTP address configured for authenticating authentication failed. Mail server The user name or password configured for...
...-N series AP could not connect to the CAPWAP server. 1st %02x ~ 6th %02x: Managed AP MAC Address. 7th %s: Managed AP Model Name. 8th %s: Managed AP Description. WLAN Controller End. The address configured for authenticating with SMTP account %s2. Registration Type:%s WLAN Controller Reset. The AP management service has ended. Add a Managed AP. Indicates that AP management services has started. Cannot resolve mail server address %s. The (listed) SMTP address configured for authenticating authentication failed. Mail server The user name or password configured for...
User Guide
Page 302
... startup-config. 1st %s: Reset ZySH Daemon AC IP Change. Switch Managed AP to WLAN Controller. Firmware upgraded by a WLAN Controller. Discovery Type:%s The CAPWAP Client service started. 1st %s: Discovery type {By DHCP | Broadcast} Managed AP Reset. Disconnect to Standalone AP. ReBoot by WLAN Controller. WLAN Controller:%s The CAPWAP Client connected to Standalone Mode. 1st %s: WLAN Controller IP Address." Apply configuration by the WLAN controller. 1st %s: WLAN Controller IP Address." New Changed the managed AP's AC IP. WLAN Controller:%s The CAPWAP client's firmware...
... startup-config. 1st %s: Reset ZySH Daemon AC IP Change. Switch Managed AP to WLAN Controller. Firmware upgraded by a WLAN Controller. Discovery Type:%s The CAPWAP Client service started. 1st %s: Discovery type {By DHCP | Broadcast} Managed AP Reset. Disconnect to Standalone AP. ReBoot by WLAN Controller. WLAN Controller:%s The CAPWAP Client connected to Standalone Mode. 1st %s: WLAN Controller IP Address." Apply configuration by the WLAN controller. 1st %s: WLAN Controller IP Address." New Changed the managed AP's AC IP. WLAN Controller:%s The CAPWAP client's firmware...
User Guide
Page 384
... user objects 137 users 137 access, see also access users admin (type) 137 admin, see also admin users and service control 200 configuration overview 51 currently logged in 78 default lease time 143, 144 default reauthentication time 143, 145 lease time 141 limited-admin (type) 51, 138 lockout 143 reauthentication time 141 types of 137 user (type) 51, 138 user names 139 V Vantage Report (VRPT) 231, 237 virtual router 135 VRPT (Vantage Report) 231, 237 U upgrading firmware 248 uploading configuration files 247 firmware...
... user objects 137 users 137 access, see also access users admin (type) 137 admin, see also admin users and service control 200 configuration overview 51 currently logged in 78 default lease time 143, 144 default reauthentication time 143, 145 lease time 141 limited-admin (type) 51, 138 lockout 143 reauthentication time 141 types of 137 user (type) 51, 138 user names 139 V Vantage Report (VRPT) 231, 237 virtual router 135 VRPT (Vantage Report) 231, 237 U upgrading firmware 248 uploading configuration files 247 firmware...