LINK W ILL NOT BE LIA BLE FOR THIRD -PA RTY CLA IM S A GA INST CUSTOM ER FOR LOSSES OR DA M A GES. D-LINK W ILL IN NO EVENT BE LIA BLE FOR A NY DA M A GES IN EXCESS OF THE A M OUNT D -LINK RECEIVED FROM THE END-USER FOR THE PRODUCT.
Wireless Controller User Manual Table of Contents Chapter 1. Introduction............................13 About this User Manual ....................14 Typographical Conventions ..................... 15 Chapter 2. Configuring Your Network ......................17 LAN Configuration ......................17 2.1.1 LAN DHCP Reserved IPs ....................21 2.1.2 LAN DHCP Leased Clients....................
Page 5
Wireless Controller User Manual 4.3.2 LAN Assoicated Clients ....................97 4.3.3 WLAN Assoicated Clients ....................98 Active Connections......................99 4.4.1 Sessions through the Cont roller ..................99 LAN Client Info........................100 4.5.1 Associated Clients ......................100 4.5.2 LAN Clients ......................... 102 4.5.3 Detected Clients ........................
Page 6
Wireless Controller User Manual 6.2.5 Russia L2TP and PP TP Option ................... 167 6.2.6 Option Configuration in an IP v6 Network ..............169 6.2.7 Checking Option Status ....................172 Features with Multipl e Option Links ................175 6.3.1 Auto Failover ........................175 6.3.2 Load Balancing ........................
Page 7
Wireless Controller User Manual Chapter 9. SSL VPN ............................241 Groups and Users......................243 9.1.1 Users and Passwords ..................... 251 Using SSL VPN Policies ....................253 9.2.1 Using Network Res ourc es ..................... 256 Application Port Forwarding ..................257 SSL VPN Client Configuration..................260 9.4.1 Creating Portal Layouts ....................
Page 8
Wireless Controller User Manual Appendix A. Glossary ............................. 318 Appendix B. Factory Default Settings........................ 321...
Page 9
Wireless Controller User Manual List of Figures Figure 1: Setup page for LA N TCP/IP settings (DHCP server) ..............20 Figure 2: Setup page for LA N TCP/IP settings (DHCP Relay) ..............21 Figure 3: LAN DHCP Reserved IPs ........................22 Figure 4: LAN DHCP Leased Clients ........................
Page 10
Wireless Controller User Manual Figure 35: AP Pofile - Radio configuration (Part-1)..................71 Figure 36: AP Pofile - Radio configuration (Part-2)..................73 Figure 37: AP Pofile - SSID configuration ......................75 Figure 39: AP Pofile - QoS configuration (P art-2) ................... 82 Figure 40: WLAN Setup Wizard..........................
Page 11
Wireless Controller User Manual Figure 73: Controller Associated Client Status....................134 Figure 74: Detected Client Status ........................136 Figure 75: Pre-Auth History ........................... 137 Figure 76: Detected Client Roam History ......................139 Figure 77: Valid Access Point Configuration ....................141 Figure 78: Add a Valid Access Point........................
Page 12
Figure 134: L2TP tunnel configuration – L2TP Server ................237 Figure 135: OpenVPN configuration ........................239 Figure 136: Example of clientless SSL VPN connections to the DWC-1000........242 Figure 137: List of groups ............................243 Figure 138: User group configuration ........................ 245...
Page 13
Wireless Controller User Manual Figure 139: SSLVPN Settings ..........................247 Figure 140: Group login policies options ......................248 Figure 141: Browser policies options ......................... 249 Figure 142: IP policies options ..........................250 Figure 143: A vailable Users with login status and associated Group ............ 251 Figure 144: User Configuration options ......................
Page 14
Wireless Controller User Manual Figure 175: Restoring configuration from a saved file will result in the current configuration being overwritten and a reboot ........................310 Figure 176: Firmware version information and upgrade option ..............311 Figure 178: Controller diagnostics tools available in the GUI..............314 Figure 179: Installing a License ...........................
Wireless Controller User Manual Chapter 1. Introduction D-Lin k W ireles s Co n t ro ller (DW C), DW C-1000, is a fu ll-feat u red wireles s LA N co n t ro ller d esig nin g fo r s mall n et wo rk en v iro n men t . Th e cen t ralized co n t ro l fu n ct io n co n t ain s v ario us access p oin t man agemen t fu n ctio ns, s uch as fast -roamin g , in t er-s ubn et ro amin g , au t o mat ic ch an n el an d p o wer ad ju s t men t , s elf -h ealin g et c.
Wireless Controller User Manual 1.1 About this User Manual Th is d o cu men t is a h ig h lev el man u al t o allo w n ew D-Lin k W ireles s Co n t ro ller u s ers t o co n fig u re co nnectiv ity , W LA N co n fig uratio n, s et up VPN t u n n els, es tablis h firewall ru les an d A P man ag emen t an d p erfo rm g en eral ad min is t rat iv e t as ks .
Wireless Controller User Manual 1.2 Typographical Conventions Th e fo llo win g is a lis t o f t h e v ario u s t erms , fo llo wed b y an examp le o f h o w t h at t erm is rep res en t ed in t h is d o cu men t : ...
Wireless Controller User Manual Chapter 2. Configuring Your Network To en ab le man ag emen t acces s fo r t h e b ro ws er b as ed web GUI acces s o r SNM P man ag er, y o u mu s t co nn ect t h e co ntro ller t o t h e n et work. Th e d efault IP ad d ress/sub net mas k o f t h e co n t ro ller man ag emen t in t erface is 1 9 2 .1 6 8 .1 0 .1 / 2 5 5 .2 5 5 .2 5 5 .0 an d DHCP s erv er o n t h e LA N is d is ab led b y d efault o n t h e co ntro ller.
Page 20
Wireless Controller User Manual o t h er LA N d ev ices can b e as s ig n ed IP ad d res s es , t h e d efau lt g at eway , as well as ad d res ses fo r DNS s erv ers , W in dows In ternet Name Serv ice (W INS) s erv ers .
Page 21
Wireless Controller User Manual DHCP S erver . W it h t h is o p t io n t h e co n t ro ller as s ig n s an IP ad d res s wit h in t h e s p ecified ran g e p lu s ad d it io n al s p ecified in fo rmat io n t o an y LA N d ev ice t h at req u es t s DHCP s erv ed ad d res s es .
Wireless Controller User Manual Figure 2 : Se tup page for LAN TCP/IP s e ttings (DHCP Re lay) W h en DHCP relay is ean ab le d , DHCP clien t s o n t h e LA N can receiv e IP ad d res s leas es an d co rres p o n d in g in fo rmat io n fro m a DHCP s erv er o n a d ifferen t s u b n et .
Wireless Controller User Manual IP Addres s es : Th e LA N IP ad d res s o f a h o s t t h at is res erv ed b y t h e DHCP s erv er. MAC Addres s es : Th e M A C ad d res s t h at will b e as s ig n ed t h e res erv ed IP ad d res s wh en it is o n t h e LA N.
Wireless Controller User Manual Figure 4 : LAN DHCP Le as e d Clie nts IP Addres s es : Th e LA N IP ad d res s o f a h o s t t h at mat ch es t h e res erv ed IP lis t . MAC Addres s es : Th e M A C ad d ress o f a LA N h o s t t h at h as a co n figu red IP ad d res s res erv at io n .
Wireless Controller User Manual Figure 5 : IPv6 LAN and DHCPv6 configurat io n If y o u ch an g e t h e IP ad d res s an d click Sav e Set t in g s , t h e GUI will n o t res p o n d.
Page 27
Wireless Controller User Manual DHCP v6 A s wit h an IPv 4 LA N n et wo rk, t h e ro u t er h as a DHCPv 6 s erv er. If en ab led , t h e ro u t er as s ig n s an IP ad d res s wit h in t h e s p ecified ran g e p lu s ad d it io n al s p ecified in fo rmat io n t o an y LA N PC t h at req u es t s DHCP s erv ed ad d res s es .
Wireless Controller User Manual Prefix Delegation Th e fo llo win g s et t in g s are u s ed t o co n fig u re t h e Prefix Deleg at io n : Prefi x Del eg ati on: Select t h is o p tio n t o en ab le p refix d eleg at io n in DHCPv 6 s erver. Th is o p t io n can b e s elected o n ly in St at eless A d dres s A u t o Co n fig u rat io n mo d e o f DHCPv 6 s erv er.
Wireless Controller User Manual o f IA s wit h clien t s . DHCP clien t s u s e DUIDs t o id en t ify a s erver in mes s ag es wh ere a s erv er n eed s t o b e id en t ified . IAID:A n id en t ifier fo r an IA , ch o s en b y t h e clien t .
Page 30
Wireless Controller User Manual Router Preference : t h is lo w/ med iu m/ h ig h p aramet er d etermin es t h e p referen ce as s o ciat ed wit h t h e RA DVD p ro ces s o f t h e ro u t er. Th is is u s efu l if t h ere are o t h er RA DVD en ab led d evices o n t h e LA N as it h elp s av o id co n flict s fo r IPv 6 clien t s .
Wireless Controller User Manual Figure 7 : Configu ri ng the Route r Adve rtis e me nt Dae mon Advertisement Prefixes Advanced > IPv6 > IPv6 LAN > Advertisement Prefixes Th e ro u t er ad v ert isemen ts co nfig ured wit h ad v ert is emen t p refixes allo w t h is ro u t er t o in fo rm h o s t s h o w t o p erfo rm s t at eles s ad d res s au t o co n fig u rat io n .
Wireless Controller User Manual IPv6 Prefi x: W h en u sin g Glo b al/ Lo cal/ ISA TA P p refixes , t h is field is u s ed t o d efin e t h e IPv 6 n et wo rk ad v ert is ed b y t h is ro u t er. IPv6 Prefi x Leng th: Th is v alu e in d icat es t h e n umb er co n tig u o u s , h ig h er o rd er b it s o f t h e IPv 6 ad d ress t h at d efin e u p t h e n et work p o rt io n o f t h e ad dress.
Wireless Controller User Manual ro b in o n ly . Th e d ev ice will b e p ro g rammed t o h an d le t h e t raffic u s ing t h e alg o rit h m co n fig u red h ere Figure 9 : Port Que ue Sche duling 2.2.2 Port Queue Status...
Wireless Controller User Manual Figure 10 : Port Que ue Status 2.2.3 Option QoS Configuration Setup > LAN QoS > Option QoS Configuration Th is p ag e allo ws co n fig u rin g t h e Op t io n Qo S an d d efin in g t h e b an d wid t h fo r Op t io n in t eface s .
Wireless Controller User Manual Figure 11 : Option QoS Configuratio n Opti on QoS : To en ab le Ban d wid t h man ag emen t s elect t h e ch eck b o x an d click A p p ly .
Wireless Controller User Manual Figure 12 : B andwid t h Profile Configurat io n 2.2.4 Traffic Selector Configuration Setup > LAN QoS > Traffic Selector Configuration A ft er y o u creat e a b an d wid t h p ro file, y o u can as s o ciat e it wit h a t raffic flo w .
Wireless Controller User Manual Figure 13 : Traffi c Se le ctor Configu rat io n Avai l abl e Profi l es :Select o n e o f t h e p rev io u s ly co n fig u red b an d wid t h p ro files t o as s o ciat e t h is t raffic s elect o r.
Wireless Controller User Manual 2.2.5 LAN QoS Configuration Setup > LAN QoS > LAN QoS Configuration En ab lin g Qo S o n LA N is an ad v an ced co n fig u rat io n , wh ich is req u ired o n ly if y o u exp ect co n g estio n o n t h e t raffic o n t h e LA N p o rt s .
Wireless Controller User Manual Figure 15 : 801.p Configu rat io n CoS Val ue : v alu e o f t h e co s in t h e PCP p art o f t h e LA N t raffic. Pri ori ty Queue ::Prio rit y fo r t h e p art icu lar Co S v alu e 2.2.7 DSCP Configuration Setup >...
Wireless Controller User Manual Figure 16 : DSCP Configuratio n DS CP: Lis t s t h e IP DSCP v alu es t o wh ich y o u can map an in t ern al t raffic clas s . Th e v alu es ran g e fro m 0-63.
Wireless Controller User Manual 2.2.8 Remark CoS to DSCP Setup > LAN QoS > Remark CoS to DSCP Remarkin g Co S t o DSCP is an ad v an ced Qo S co n fig uratio n, wh ere t h e Lay er 2 q u ality o f s erv ice field is t ran s lat ed t o a Lay er 3 Qo S field in t h e p acket , s o t h at u p s t ream ro u t ers can make a Qo S d ecis io n b as ed o n t h e DSCP field s et in t h e p acket .
Wireless Controller User Manual 2.3 VLAN Configuration Th e co n t ro ller s up port s v irt ual n et work is o lat ion o n t h e LA N wit h t h e u s e o f VLA Ns . LA N d ev ices can b e co n fig u red t o co mmu n icat e in a s u b n et wo rk d efin ed b y VLA N id en t ifiers .
Wireless Controller User Manual Figure 18 : Adding VLAN me mbe rs hips to the LAN 2.3.1 Associating VLANs to ports In o rd er t o t ag all t raffic t h ro u g h a s p ecific LA N p o rt wit h a VLA N ID, y o u can as s o ciat e a VLA N t o a p h y s ical p o rt .
Wireless Controller User Manual u n t ag ged d at a in t o Po rt 3 will b e as s ig ned PVID 3. A ll t ag g ed d ata s ent o u t o f t h e p o rt wit h t h e s ame PVID will b e u n t ag ged.
Wireless Controller User Manual memb ers h ip o p t io n s fo r a Gen eral o r Tru n k p o rt , t raffic can b e ro u t ed b et ween t h e s elect ed VLA N memb ers h ip IDs Figure 20 : Configu ri ng VLAN me mbe rs hip for a port 2.3.2 Multiple VLAN Subnets Setup >...
Wireless Controller User Manual Edi t: Th e Ed it b u t t o n will lin k t o t h e Po rt VLA N Co n fig u rat io n p ag e, allo win g y o u t o make ch an g es t o t h e s elect ed p o rt VLA N at t rib u t es .
Wireless Controller User Manual Figure 22 : DM Z configuratio n In o rd er t o co n fig u re a DM Z p o rt , t h e co n tro ller co n fig u rab le p o rt mu s t b e Setup >...
Page 48
Wireless Controller User Manual Advanced > Advanced Network > UPnP Un iv ers al Plu g a n d Play (UPn P) is a feat u re t h at allo ws t h e co n t ro ller t o d is co v ery d ev ices o n t h e n etwo rk t h at can co mmu n icat e wit h t h e co n t ro ller an d allo w fo r au t o co n fig u rat io n .
Wireless Controller User Manual Figure 23 : UPnP Configuratio n UPnP Port map Table Th e UPn P Po rt map Tab le h as t h e d et ails o f UPn P d ev ices t h at res p o n d t o t h e co n t ro ller ad v ert isemen ts.
Wireless Controller User Manual 2.6 Captive Portal LA N an d W LA N u s ers can g ain in t ernet acces s v ia web p o rt al au t h en t icat io n wit h t h e DW C.
Wireless Controller User Manual Figure 24 : Captive Portal Se tup Th e fo llo win g act io n s are s u p p o rt ed fro m t h is p ag e : Edi t: Can ed it t h e ad d ed p o licies . Enabl e : Can en ab le t h e ad d ed p o licies .
Wireless Controller User Manual Add: W ill let y o u ad d a n ew p ro file. M aximu m allo wed n u mb er o f p ro files are 5 exclu d in g d efau lt . S how Previ ew: W ill s h o w p rev iew o f t h e p ag e, if a p ro file is s elect ed .
Wireless Controller User Manual Captive Portal Configuration Cap t iv e p o rt al lo g in p age d isp lay can b e alt ered b y mo d ify in g t he s ettin gs av ailable h ere.
Wireless Controller User Manual Figure 27 : Captive Portal Configuratio n (Part -2) Header Detai l s : It allo ws u s er t o co n fig u re h o w t h e h ead er p o rt io n o f t h e p ag e s h o u ld b e d is p lay ed .
Wireless Controller User Manual Font Col or : Co lo r in wh ich t h e t ext is t o b e d is p lay ed . Log i n Detai l s : Log i n S ecti on Ti tl e : Tit le fo r t h e Lo g in Bo x Wel come Mes s ag e : M es s ag e wh ich is d is p lay ed wh en a u s er v is it s t h e p ag e.
Wireless Controller User Manual Figure 28 : Active Runtime s e s s ions 2.6.3 W LAN CP Interface Association Advanced > Captive Portal > WLAN CP Interface Association Fro m t h e In t erface A sso ciat ion p ag e, y o u can as s o ciat e a co n fig u red cap t iv e p o rt al wit h a s p ecific p h y s ical in t erface o r wireles s n et wo rk (SSID).
Wireless Controller User Manual n u mb er an d SSID. Ph y s ical (wired ) in t erfaces are id en t ified b y t h e Po rt Des crip t io n t h at in clu d es s lo t n u mb er, p o rt n u mb er, an d in t erface t y p e. Figure 29 : WLAN CP Inte rface As s ociation Us e t h e fo llo win g s t ep s t o as s o ciat e o n e o r mo re in t erfaces wit h a cap t iv e p o rt al.
Wireless Controller User Manual Us e t h e fo llo win g s t eps t o remo v e an in t erface fro m t h e A s sociated In t erfaces lis t fo r a cap t iv e p o rt al.
Wireless Controller User Manual Figure 30 : WLAN global configurat io n IP Addres s : Th is field s h o ws t h e IP ad d res s o f t h e W LA N in t erface o n t h e co n t ro ller.
Page 60
Wireless Controller User Manual cco n t ro ller, it lo o ks u p t h e M A C ad d res s o f t h e A P in t h e Valid A P d at ab as e. If it fin d s t h e M A C ad d ress in t h e d at ab ase, t he co nt roller v alid ates t h e A P an d as s u mes man ag emen t .
Wireless Controller User Manual 2.8 Wireless Discovery configuration Th e wireles s c o n t ro ller can d is co v er, v alid at e, au t h en t icat e, o r mo n it o r t h e fo llo win g s y s t em d ev ices : •...
Wireless Controller User Manual click A d d . A ll IP ad d res ses in t h e ran ge are ad ded t o t he IP Lis t . On ly t h e las t o ct et is allo wed t o d iffer b et ween t h e Fro m ad d res s an d t h e To ad d res s .
Wireless Controller User Manual mu lt icas t d o main . Th e wireles s co n t ro ller p erio d ically s en d s a mu lt icas t p acket co n t ain in g t h e d is co v ery mes s ag e o n each VLA N en ab led fo r d is co v ery Th e fo llo win g act io n s are s u p p o rt ed fro m t h is p ag e : Add: A d d s t h e d at a in t h e IP A d d res s o r VLA N field t o t h e ap p ro p riat e lis t .
Wireless Controller User Manual Figure 32 : Wire le s s Dis cove ry s tatus Th e fo llo win g act io n s are s u p p o rt ed fro m t h is p ag e : Refres h: Up d at es t h e p ag e wit h t h e lat es t in fo rmat io n 2.8.2 AP Profile Global Configuration Advanced >...
Wireless Controller User Manual Figure 33 : AP Profile Global Configuratio n Profi l e Name : Th e A cces s Po in t p ro file n ame y o u a d d ed . Us e 0 t o 32 ch aract ers . On ly alp h an u meric ch aract ers are allo wed .
Wireless Controller User Manual Figure 34 : AP Profile Lis t Fo r each A P p ro file, y o u can co nfig ure t h e fo llo win g feat ures: • Pro file s et t in gs (Name, Hard ware Ty p e ID, W ired Net wo rk Dis co v ery VLA N ID) •...
Page 67
Wireless Controller User Manual Profi l e : Th e A cces s Po in t p ro file n ame y o u ad ded. Us e 0 t o 32 ch aract ers. Profi l e S tatus : can h av e o n e o f t h e fo llo win g v alu es: •...
Wireless Controller User Manual Radio Configuration Radi o Mode : Fro m t h is field , y o u can s elect t h e rad io t h at y o u wan t t o co n fig u re. By d efau lt , Rad io 1 o p erat es in IEEE 802.11a/ n mo d e, an d Rad io 2 o p erat es in IEEE 802.11b / g / n mo d e.
Page 69
Wireless Controller User Manual RF S can Other Channel s : Th e acces s p oin t can p erform RF s can s t o co llect in fo rmat io n ab o u t o t her wireles s d ev ices wit h in ran g e an d t h en rep o rt t h is in fo rmat io n t o t h e DW C-1000 wireles s co n t ro ller.
Page 70
Wireless Controller User Manual h ig h er t h ro u ghp ut wh en it d o es n o t n eed t o b e co mp at ib le wit h leg acy d ev ices (802.11b / g o r 802.11a). Radi o 2 s upports : •...
Page 71
Wireless Controller User Manual 10 p er s eco n d ). Th e Beaco n In t erv al v alu e is s et in millis eco n d s . En t er a v alu e fro m 20 t o 2000. Automati c Channel : Th e ch an n el d efin es t h e p ort io n o f t h e rad io s p ect ru m t h at t h e rad io u ses fo r t ran smit t in g an d receivin g.
Page 72
Wireless Controller User Manual Rate Li mi ti ng : En ab lin g mu lt icas t an d b ro ad cas t rat e limit in g can imp ro v e o v erall n et wo rk p erfo rman ce b y limit in g t h e n u mb er o f p acket s t ran s mit t ed acro s s t h e n et wo rk.
Wireless Controller User Manual Figure 35 : AP Pofile - Radio configurat io n (Part-1) Trans mi t Li feti me : Sh o ws t h e n u mb er o f millis eco n d s t o wait b efo re t ermin at in g at t emp t s t o t ran s mit t h e M SDU aft er t h e in it ial t ran s mis s io n .
Page 74
Wireless Controller User Manual rat e limit s e t t in g is 50 p acket s p er s eco n d . Th is field is d is ab led if Rat e Limit in g is d is ab led . Recei ve Li feti me: Sh o ws t h e n u mb er o f millis eco n d s t o wait b efo re t ermin at in g at t emp t s t o reas s emb le t h e M M PDU o r M SDU aft er t h e in it ial recep t io n o f a frag men t ed M M PDU o r M SDU.
Wireless Controller User Manual Figure 36 : AP Pofile - Radio configurat io n (Part-2) Protecti on: Th e p ro t ect ion feat u re co n t ain s ru les t o g u aran t ee t h at 802.11 t ran s mis sio ns d o n o t cause in t erferen ce wit h leg acy s tatio ns o r ap p licatio n s .
Page 76
Wireless Controller User Manual S hort Guard Interval : Th e g u ard in t erv al is t h e d ead t ime, in n an o second s , b et ween OFDM s y mb o ls . Th e g u ard in t erv al p rev en t s In t er -Sy mb o l an d In t er-Carrier In t erferen ce (ISI, ICI).
Wireless Controller User Manual SSID Configuration Th e SSID Co n fig u rat io n p age d isp lays t he v irt u al acces s p o in t (VA P) s et t in g s as s o ciat ed wit h t h e s elect ed A P p ro file.
Page 78
Wireless Controller User Manual Radi o Mode : Fro m t h is field , y o u can s elect t h e rad io t h at y o u wan t t o co n fig u re. By d efau lt , Rad io 1 o p erat es in IEEE 802.11a/ n mo d e, an d Rad io 2 o p erat es in IEEE 802.11b / g / n mo d e.
Wireless Controller User Manual QoS Configuration Qu alit y o f Serv ice (Qo S) p ro v id es y o u wit h t h e ab ilit y t o s pecify p aramet ers o n mu lt ip le q u eu es fo r in creas ed t h ro u g h p u t an d b et t er p erfo rman ce o f d ifferen t iat ed wireles s t raffic , d ifferen t t y p es o f au d io , v id eo , an d s t reamin g med ia as well as t rad it io n al IP d at a o v er t h e DW C-1000.
Page 80
Wireless Controller User Manual effect iv ely s p ecify in g min imu m an d maximu m wait t imes (t h ro u g h Co n t en t io n W in d o ws ) fo r t ran s mis s io n . Th e s et t in g s d es crib ed h ere ap p ly t o d at a t ran s mis sio n b eh av ior o n t h e access p oin t o n ly , n ot t o t h at o f t h e clien t s t at io n s .
Page 81
Wireless Controller User Manual Data 3 (B ack g round): Lo wes t p rio rit y q u eu e, h ig h t h ro u g h p u t . Bu lk d at a t h at req uires maximu m t h ro u gh put an d is n o t t ime -s en sitiv e is s en t t o t h is q u eu e (FTP d at a, fo r examp le).
Page 82
Wireless Controller User Manual WMM Mode : W i-Fi M u lt iM ed ia (W M M ) is en abled b y d efault . W it h W MM en ab led , Qo S p rio rit izat io n an d co o rd in at io n o f wireles s med iu m acces s is o n .
Page 83
Wireless Controller User Manual firs t ran d o m n u mb er g en erated will b e a n u mb er b et ween 0 an d t h e n u mb er s p ecified h ere. If t h e firs t ran do m b acko ff wait t ime exp ires b efo re t h e d at a frame is s en t , a ret ry co un ter is in cremen ted an d t h e ran d o m b acko ff v alu e (win d o w) is d o u b led .
Wireless Controller User Manual Chapter 3. Configuring Wireless LAN 3.1 WLAN Setup Wizard Setup > Wizard > WLAN Setup Wizard Th e W LA N Set u p W izard is av ailab le fo r u s ers fo r co n fig u rin g t h e b as ic wireles s co n t ro ller s et t in g s s u ch as rad io , SSID an d A cces s Po in t .
Wireless Controller User Manual Chapter 4. Monitoring Status and Statistics 4.1 System Overview Th e St at u s p ag e allo ws y o u t o g et a d et ailed o v erv iew o f t h e s y s t em co n fig u rat io n . Th e s et t in g s fo r t h e wired an d wireles s in t erfaces are d is p lay ed in t h e DW C-1000 St at u s p age, an d t hen t h e resu ltin g h ard ware res ou rce an d co nt roller u s ag e d et ails are s u mmarized o n t h e co n t ro ller Das h b o ard .
Wireless Controller User Manual Figure 41 : Das hboard CPU Uti l i zati on Th is s ect io n d is p lay s t h e ro u t er's p ro ces s o r s t at is t ics . CPU us ag e by us er : Percen t o f t h e CPU u t ilizat io n b ein g co nsu med cu rren tly b y all u s er s p ace p ro ces s es , s u ch as SSL VPN o r man ag emen t o p erat io n s .
Wireless Controller User Manual Free Memory: In d icat es av ailab le free memo ry in s y s t em. Cached Memory: In d icat es cach ed memo ry in s y s t em. B uffer Memory: In d icat es b u ffered memo ry in s y s t em 4.1.2 Dev ice Status Status >...
Wireless Controller User Manual Figure 43 : De vice Status dis play (continue d) 4.1.3 W ireless LAN AP information Status > Device Info > Wireless LAN AP Information Th e M an ag ed A P s t at u s p ag es allo ws t o acces s co n fig u rat io n an d as s o ciat io n in fo rmat io n ab o u t man ag ed A Ps an d t h eir n eig h b o rs .
Wireless Controller User Manual Vi ew Nei g hbor APs : Sh o ws t h e n eigh bor A Ps t h at t he s pecified A P h as d is co v ered t h ro u g h p erio d ic RF s c an s o n t h e s elect ed rad io in t erface. Vi ew Nei g hbor Cl i ents : Sh o ws in fo rmat io n abo u t wireles s clien t s as s o ciat ed wit h an A P o r d et ect ed b y t h e A P rad io .
Wireless Controller User Manual Di s covered: Th e A P is d is co v ered an d b y t he co n t ro ller, b u t is n o t y et au t h en t icat ed . ...
Wireless Controller User Manual Figure 45 : Clus te r inform at ion Cl us ter Control l er IP Addres s : IP ad d res s o f t h e co n t ro ller t h at co n t ro ls t h e clu s t er.
Wireless Controller User Manual 4.1.5 Resource Utilization Status > Dashboard > Interface Th e Das h b oard p ag e p resents h ard ware an d u sag e s t at is t ics . Th e CPU an d M emo ry u t ilizat io n is a fu n ct io n o f t h e av ailab le h a rd ware an d cu rren t co n fig u rat io n an d t raffic t h ro u g h t h e co nt ro ller.
Wireless Controller User Manual 4.2 Traffic Statistics 4.2.1 W ired Port Statistics Status > Traffic Monitor > Device Statistics Det ailed t ran s mit an d receiv e s t at is t ics fo r each p h y s ical p o rt are p res en t ed h ere. Each in t erface (Op t io n 1, Op t io n 2/ DM Z, LA N, an d VLA Ns ) h av e p o rt s p ecific p acket lev el in fo rmat io n p ro v id ed fo r rev iew.
Wireless Controller User Manual 4.3 Managed AP and Associated Clients Statistics 4.3.1 Managed AP Statistics Status > Traffic Monitor > Managed AP Statistics Th e man ag ed A P s t atist ics p ag e s h o ws in fo rmat io n ab o u t t raffic o n t h e wired an d wireles s in t erfaces o f t h e access p o in t.
Wireless Controller User Manual Figure 49 : M anage d AP Statis tics Th e fo llo win g act io n s are s u p p o rt ed fro m t h is p ag e: Vi ew Detai l s : Sh o ws d et ailed s t at u s in fo rmat io n co llect ed fro m t h e A P. Vi ew Radi o Detai l s : Sh o ws d et ailed s t at u s fo r a rad io in t erface Vi ew VAP Detai l s : Sh o ws s u mmary in fo rmat io n ab o u t t h e v irt u al acces s p o in t s...
Wireless Controller User Manual Figure 50 : LAN As s ociate d Clie nts Th e fo llo win g act io n s are s u p p o rt ed fro m t h is p ag e: Refres h: Up d at es t h e p ag e wit h t h e lat es t in fo rmat io n Vi ew Detai l s : Sh o ws d et ailed s t at u s as s o ciat ed clien t .
Wireless Controller User Manual B ytes Trans mi tted: Th is field s h o ws t h e b y t es t ran s mit t ed t o t h e clien t s t at io n B ytes Recei ved: Th is field s h o ws t h e b y t es receiv ed t o t h e clien t s t at io n Figure 51 : WLAN As s ociate d Clie nts Th e fo llo win g act io n s are s u p p o rt ed fro m t h is p ag e:...
Wireless Controller User Manual Figure 52 : Lis t of curre nt Active Fire wall Se s s ions 4.5 LAN Client Info 4.5.1 Associated Clients Status > LAN Client Info > Associated Clients Th e clien t s t h at are as s o ciat ed wit h t h e A Ps t h e co n t ro ller man ag es as d is p lay ed .
Wireless Controller User Manual Figure 53 : As s ociate d C lie nts MAC Addres s : Th e Et h ern et ad d res s o f t h e clien t s t at io n . If t h e M A C ad d res s is fo llo wed b y an as t erisk (* ), t h e clien t is as s o ciat ed wit h an A P man ag ed b y a p eer co n t ro ller.
Wireless Controller User Manual • Di s as s ociated: Th e clien t h as d isasso ciat ed fro m t h e man a g ed A P. If t h e clien t d o es n o t ro am t o an o t h er man ag ed A P wit h in t h e clien t ro am t imeo u t , it will b e d elet ed .
Wireless Controller User Manual Figure 54 : Lis t of LAN hos ts 4.5.3 Detected Clients Status > LAN Client Info > Detected Clients W ireles s clien ts are d etect ed b y t h e wireles s sy stem wh en t h e clien t s eit h er at t emp t t o in t eract wit h t h e s ystem o r wh en t h e s y s t em d et ect s t raffic fro m t h e clien t s .
Wireless Controller User Manual Figure 55 : De te cte d Clie nts MAC Addres s : Th e Et h ern et M A C ad d res s o f t h e clien t . Cl i ent Name : Sh o ws t h e n ame o f t h e clien t , if av ailab le, fro m t h e Kn o wn Clien t Dat ab as e.
Wireless Controller User Manual Ag e : Time s in ce an y ev ent h as b een receiv ed fo r t h is clien t t h at u pd at ed t he d etected clien t d at ab as e en t ry . Create Ti me : Time s in ce t h is en try was firs t ad ded t o t h e d et ected clien ts d at ab as e.
Page 108
Wireless Controller User Manual Figure 56 : AP s tatus Total Acces s Poi nts Uti l i zati on Total Acces s Poi nts : To t al n u mb er o f M an ag ed A Ps in t h e d at ab as e. Th is v alu e is alway s eq u al t o t h e s u m o f M an ag ed A cces s Po in t s , Co n n ect io n Failed A cces s Po in t s , an d Dis co v ered A cces s Po in t s .
Page 109
Wireless Controller User Manual Di s covered Acces s Poi nts : A Ps t h at h av e a co n n ect io n wit h t h e co n t ro ller, b u t h av en 't b een co mp let ely co n fig u red .
Wireless Controller User Manual 4.6.2 AP Summary Status > Access Point Info> APs Summary Th e Lis t o f A P p ag e s h o ws s u mmary in fo rma t io n ab o u t man ag ed , failed , an d ro g u e access p oin ts t h e co ntro ller h as d is co vere d o r d et ect ed .
Page 111
Wireless Controller User Manual • Manag ed: Th e A P p ro file co n fig u ratio n h as b een ap p lied t o t h e A P an d it 's o p erat in g in man ag ed mo d e. •...
Wireless Controller User Manual 4.6.3 Managed AP Status Status > Access Point Info> Managed AP Status In t h e M an ag ed A P St at u s p ag e, y o u can acces s a v ariet y o f in fo rmat io n ab o u t each A P t h at t h e co n t ro ller man ag es .
Wireless Controller User Manual • Manag ed: Th e A P p ro file co n fig u ratio n h as b een ap p lied t o t h e A P an d it 's o p erat in g in man ag ed mo d e. •...
Wireless Controller User Manual No Databas e Entry: Th e M A C ad d res s o f t h e A P is n o t in t h e lo cal Valid A P d at ab ase o r t h e ext ern al RA DIUS s erv er d at ab as e, s o t h e A P h as n o t b een v alid at ed .
Wireless Controller User Manual M AC Address: The Ethernet address of the AP . If the MAC address of the AP is followed by an asterisk (*), it was reported by a peer controller. IP Addre s s : The IP address of the AP . Las t Failure Type : Indicates the last type of failure that occurre d, which can be one of the following: ...
Page 116
Wireless Controller User Manual S S ID: Serv ice Set ID o f t h e n et wo rk, wh ich is b ro ad cas t in t h e d et ect ed b eaco n frame. Phys i cal Mode : In d icat es t h e 802.11 mo d e b ein g u s ed o n t h e A P.
Wireless Controller User Manual Figure 60 : AP RF Scan Status 4.7 Global Info 4.7.1 Global status Status > Global Info > Global Status Th e DW C-1000 co n t ro ller p erio d ically co llect s in fo rmat io n fro m t h e A Ps it man ag es an d fro m as s ociat ed p eer co n t ro ller.
Wireless Controller User Manual Figure 62 : Global Status (Part 2)
Page 120
Wireless Controller User Manual WLAN Control l er Operati onal S tatus : Th is s t at us field d is p lays t he o p eratio nal s t at us o f t h is co ntro ller (a W LA N co n t ro ller). Th e W LA N Co n t ro ller may b e co n figured as en ab led , b ut is o p eratio nally d is abled d ue t o co nfig uratio n d ep end en cies.
Page 121
Wireless Controller User Manual Rog ue AP Mi ti g ati on Li mi t: M aximu m n u mb er o f A Ps fo r wh ich t h e s y s tem can s end d e-au t h en ticatio n frames .
Page 122
Wireless Controller User Manual Total Roam Hi s tory Entri es : Cu rren t n u mb er o f ro am h is t o ry en tries in u s e b y t h e s y s tem. AP Provi s i oni ng Count: Cu rren t n u mb er o f A P p ro v is io nin g ent ries co nfig ured o n t h e s y s tem.
Wireless Controller User Manual 4.7.2 Peer Contorller Status Status > Global Info > Peer Controller > Status Th e Peer Co n t ro ller St at u s p ag e p ro v id es in fo rmat io n ab o u t o t h er W ireles s Co n t ro llers in t h e n et wo rk.
Wireless Controller User Manual Figure 63 : Pe e r Controlle r Status Th e fo llo win g act io n s are s u p p o rt ed fro m t h is p ag e Refres h: Up d at es t h e p ag e wit h t h e lat es t in fo rmat io n 4.7.3 Peer Controller Configuration Status Status >...
Wireless Controller User Manual Confi g urati on Control l er IP Addres s : Sh o ws t h e IP A d d ress o f t h e co nt roller t h at s en t t h e co n fig u rat io n in fo rmat io n . Confi g urati on: Id en t ifies wh ich p art s o f t h e con fig u rat io n t h e co n t ro ller receiv ed fro m t h e p eer co n t ro ller.
Wireless Controller User Manual MAC Addres s : Sh o ws t h e M A C ad d res s o f each A P man ag ed b y t h e p eer co n t ro ller. Peer Control l er IP: Sh o ws t h e IP ad d ress o f t h e p eer co n t ro ller t h at man ag es t h e A P.
Wireless Controller User Manual Po lled : Th e co n t ro ller h as at t emp t ed t o co n t act t h e IP ad d res s . Dis co v ered: Th e co n t ro ller co n t act ed t h e p eer co n t ro ller o r t h e A P in t h e L3/ IP Dis co v ery lis t an d h as au th ent icat ed o r v alid at ed t h e d ev ice.
Page 128
Wireless Controller User Manual Current Recei ve S tatus : In d icat es t he g lo bal s tatu s wh en wireles s co nfig u rat ion i s receiv ed fro m a p eer co n t ro ller. Th e p o s s ib le s t at u s v alu es are as fo llo ws : ...
Wireless Controller User Manual Ti mes tamp: In d icat es t he las t t ime t h is co n tro ller receiv ed an y co n fig u rat io n d at a fro m a p eer co n t ro ller. Th e Peer Co n t ro ller M an ag ed A P St at u s p ag e d is p lay s in fo rmat io n ab o u t t h e A Ps t h at each p eer co n troller in t h e clu s ter man ag es.
Wireless Controller User Manual Imag e Type : Sp ecifies t h e t y p e o f s o ft ware t h e h ard ware req u ires . Figure 68 : AP Hardware Capabil it y 4.8 Wireless Client Status 4.8.1 Client Status Status >...
Wireless Controller User Manual Figure 69 : Clie nt Status 8 0 2 .1 1 Cl i ents – Data 8 0 2 .1 1 a Cl i ents: To t al n u mb er o f IEEE 802.11a o n ly clien t s t h at are au t henticat ed . 8 0 2 .1 1 b/ g Cl i ents : To t al n u mb er o f IEEE 802.11b / g o n ly clien t s t h at are au t h en t icat ed .
Wireless Controller User Manual au t h en t icat ed . Th es e in clu d e IEEE 802.11a/ n , IEEE 802.11b / g / n , 5 GHz IEEE 802.11n , 2.4GHz IEEE 802.11n . Cl i ents – Data Total Cl i ents : To t al n u mb er o f clien t s in t h e d at ab as e.
Wireless Controller User Manual AP MAC Addres s : Th e Et h ern et ad d res s o f t h e A P. S S ID: Th e n et wo rk o n wh ich t h e clien t is co n n ect ed . B S S ID: Th e Et h ern et M A C ad d res s fo r t h e man ag ed A P VA P wh ere t h is clien t is as s o ciat ed .
Wireless Controller User Manual Shows information about access points that the Vi ew Nei g hbor AP S tatus : client detects. 4.8.3 Associated Client SSID Status Status > Wireless Client Info> Associated Clients > SSID Status Each man ag ed A P can h av e u p t o 16 d ifferen t n et wo rks t h at each h as a u n iq u e SSID.
Wireless Controller User Manual 4.8.4 Associated Client VAP Status Status > Wireless Client Info> Associated Cl ients > VAP Status Each A P h as 16 Virt u al A cces s Po in t s (VA Ps ) p er rad io , an d ev ery VA P h as a u n iq u e M A C ad d ress (BSSID).Th e VA P A s s o ciated Clien t St at u s p age wh ich s hows in fo rmat io n ab o u t t h e VA Ps o n t h e man ag ed A P t h at h av e as s o ciat ed wireles s clien t s .
Wireless Controller User Manual Th e fo llo win g act io n s are s u p p o rt ed fro m t h is p ag e : Di s as s oci ate : Dis as s o ciat es t h e clien t fro m t h e man ag ed A P. Refres h: Up d at es t h e p ag e wit h t h e lat es t in fo rmat io n 4.8.5 Controller Associated Client Status Status >...
Wireless Controller User Manual 4.8.6 Detected Client Status Status > Wireless Client Info> Detected Clients W ireles s clien ts are d etect ed b y t h e wireles s sy stem wh en t h e clien ts eit h er at t emp t t o in t eract wit h t h e s ystem o r wh en t h e s yst em d et ects t raffic fro m t h e clien t s .
Wireless Controller User Manual Figure 74 : De te cte d Clie nt Status Th e fo llo win g act io n s are s u p p o rt ed fro m t h is p ag e : Del ete : Delet e t h e s elected clien t fro m t h e lis t .
Wireless Controller User Manual t arg et A P mu s t h av e a VA P wit h an SSID an d s ecu rit y co n fig u rat io n t h at mat ch es t h at o f t h e clien t , in clu d in g M A C au t h en t icat io n , en cry p t io n met h o d , an d p re - s h ared key o r RA DIUS p aramet ers .
Wireless Controller User Manual 4.8.8 Detected Client Roam History Status > Wireless Client Info> Roam History Th e wireles s s y stem keep s a reco rd o f clien t s as t hey ro am fro m o n e man ag ed AP to an o t h er man ag ed A P.
Wireless Controller User Manual Figure 76 : De te cte d Clie nt Roam His tory Th is p a g e in clu d es t h e fo llo win g b u t t o n : Refres h: Up d at es t h e p ag e wit h t h e lat es t in fo rmat io n .
Wireless Controller User Manual Chapter 5. AP Management Th e A P M an ag emen t co n t ain s lin ks t o t h e fo llo win g p ag es t h at h elp y o u man ag e an d main t ain t h e A Ps o n y o u r DW C-1000 wireles s co n t ro ller n et wo rk: ...
Wireless Controller User Manual Th e fo llo win g act io n s are s u p p o rt e d fro m t h is p ag e: Edi t: To ed it A P d et ails in Valid A P p ag e. Del ete : To d elet e a v alid A P p ro v id e v alid M A C ad d res s in Valid A P p ag e.
Page 145
Wireless Controller User Manual o r SNM P. If y o u s elect t h e St an d alo n e mo d e, t h e s creen refres h es an d d ifferen t field s ap p ear. Fo r St an dalo ne mo d e t h e fo llo win g field s are en ab led Exp ect ed SSID, Exp ect ed Ch an n el, Exp ect ed W DS M o d e, Exp ect ed Secu rit y M o d e an d Exp ect ed W ired Net wo rk M o d e.
Wireless Controller User Manual Any: Select t h is o p t io n if t h e s t an d alo n e A P mig h t u s e a W DS lin k. Expected S ecuri ty Mode : Select t h e o p t io n t o s p ecify t h e t y p e o f s ecu rit y t h e A P u s es : ...
Page 147
Wireless Controller User Manual o p erat io nal ch ann el o n ev ery A P it man ag es an d ch an g es t h e ch an n el if t h e cu rren t ch an n el is n o is y Channel Pl an: Each A P is d u al-b an d capable o f o p erat in g in t h e 2.4 GHz an d 5 GHz freq u en cies .
Wireless Controller User Manual Figure 79 : RF configurat io n Channel Pl an Hi s tory Depth : Th e ch an n el p lan h is t o ry lis t s t h e ch an n els t h e co n t ro ller as s ig n s each o f t h e A Ps it man ag es aft er a ch an n el p lan is ap p lied .
Wireless Controller User Manual p o wer lev el in t h e A P p ro file is t h e d efau lt lev el fo r t h e A P, an d t h e p o wer will n o t b e ad ju s t ed b elo w t h e v alu e in t h e A P p ro file.
Wireless Controller User Manual Operati onal S tatus : Th is field s h o ws wh et h er t h e co n t ro ller is u s in g t h e au t o mat ic ch an n el ad ju s t men t alg o rit h m o n t h e A P rad io s . Las t Iterati on: Th e n u mb er in t h is field in d icat es t h e mo s t recen t it erat io n o f ch an n el p lan ad ju s t men t s .
Page 151
Wireless Controller User Manual man u ally ru n t h e ch an n el p lan ad ju s t men t feat u re, s elect t h e rad io t o u p d at e t h e ch an n els o n (5 GHz o r 2.4 GHz) an d click St art .
Wireless Controller User Manual 5.2.4 Manual Power Adjustment Plan Setup > AP Management > RF Management > Manual Power Adjustment Plan If y o u s elect M anual as t h e Po wer A d ju stmen t M o d e o n t h e Co n fig u rat io n t ab , y o u can man u ally in it iat e t h e p o wer ad ju s t men t alg o rit h m o n t h e M an u al Po wer A d ju s t men t s p ag e .
Wireless Controller User Manual Figure 82 : M anual Powe r Adjus tme nt Plan 5.3 Access Point Software Download Setup > AP Management > Software Download Th e wireles s co n t ro ller can u p g rad e s o ft ware o n t h e A Ps t h at it man ag es . ...
Page 155
Wireless Controller User Manual Gro u p Size field , en t er t h e n u mb er o f A Ps t h at can b e u p g rad ed at t h e s ame t ime.
Wireless Controller User Manual Figure 83 : Acce s s Point Software Download 5.4 Local OUI Database Summary Setup > AP Management > Local OUI Database To h elp id en t ify A P an d W ireles s Clien t ad ap t er man u fact u rers d et ect ed in t h e wireles s n et wo rk, t h e wireles s co n t ro ller co n t ain s a d at ab a s e o f reg is t ered Org an izat io n ally Un iq u e Id entifiers (OUIs ).
Wireless Controller User Manual Figure 84 : Local OUI Databas e 5.5 AP Provisioning Summary Setup > AP Management > AP Provisioning Summary Status Th e A P Pro v is io n in g feat u re h elp s y o u ad d n ew A Ps t o an exis t in g co n t ro ller clu s t er.
Page 158
Wireless Controller User Manual New Pri mary IP Addres s : En t er t h e IP ad d res s o f p rimary co n t ro ller t o wh ich t h e A P s h o u ld t ry t o co n n ect . New B ack up IP Addres s : En t er t h e IP ad d res s o f co nt roller t o wh ich t h e A P s ho u ld t ry t o co n n ect if it is u n ab le t o co n n ect t o t h e p rimary co n t ro ller.
Wireless Controller User Manual Figure 85 : AP Provis ioning Summary Status Th e fo llo win g act io n s are s u p p o rt ed fro m t h is p ag e: Del ete : Remo v e t h e s elect ed A P fro m t h e A P p ro v is io n in g lis t . Del ete Al l : Remo v e all A Ps fro m t h e A P p ro v is io n in g lis t .
Wireless Controller User Manual s et t in gs co n fig u red in t h e A P p ro file (in clu d in g au t o mat ic ch an n el s elect io n ) an d t ake effect immed iat ely .
Page 161
Wireless Controller User Manual Radi o Interface: Id en t ifies t h e rad io t o wh ich t h e ch an n el an d p o wer s et t in g s ap p ly . Channel : Select t h e A P an d click t h e Ed it Ch an n el/ Po wer b u t t o n t o acces s t h e M an ag ed A P Ch an n el/ Po wer A d ju s t p ag e.
Wireless Controller User Manual Chapter 6. Connecting to the Internet: Option Setup Th is co n t oller h as t wo Op t ion p ort s t h at can b e u s ed t o es t ab lis h a co n n ect io n t o t h e in t ern et .
Wireless Controller User Manual Figure 87 : Inte rne t Conne ction Se tup Wizard Yo u can s t art u sin g t h e W izard b y lo g g ing in wit h t h e ad min is trato r p as s wo rd fo r t h e co n t ro ller.
Wireless Controller User Manual (L2TP). Req u ired field s fo r t h e s elected ISP t y p e b ecome h ig h lig h ted . En t er t h e fo llo wing in fo rmat io n as n eed ed an d as p ro v id ed b y y o u r ISP: PPPoE Profi l e Name .
Wireless Controller User Manual 6.2.2 Option DNS Serv ers Th e IP A d d res s es o f Op t io n Do main Name Serv ers (DNS) are t y p ically p ro v id ed d y n amically fro m t h e ISP b u t in s o me cas es y ou can d efin e t h e s tatic IP ad d resses of t h e s erv ers .
Wireless Controller User Manual Figure 88 : M anual Option1 configurat io n 6.2.4 PPPoE Setup > Internet Settings > Option1 Settings > Option1 Setup Th e PPPo E ISP s et t in g s are d efin ed o n t h e Op t io n Co n fig u rat io n p ag e. Th ere are t wo t y p es o f PPPo E ISP‟s s u p p o rt ed...
Wireless Controller User Manual Figure 89 : PPPoE configuratio n for s tandard ISPs M o s t PPPo E ISP‟s u s e a s in g le co nt rol an d d ata co nnect ion , an d req u ire u s ern ame / p as s word cre dent ials t o lo g in an d au thent icate t h e DW C-1000 wit h t h e ISP.
Wireless Controller User Manual Figure 90 : Option1 configu rat ion for Japane s e M ultiple PPPoE (part 1) Th ere are a few key elemen t s o f a mu lt ip le PPPo E co n n ect io n : ...
Wireless Controller User Manual On ly HTTP req u es ts t h at s pecifically id en t ify t h e s econd ary co nnectio n‟s d o main n ame (fo r examp le * .flet s ) will u s e t h e s eco n d ary p ro file t o acces s t h e co n t en t av ailab le t h ro u g h t h is s econ dary PPPo E t ermin al.
Page 170
Wireless Controller User Manual p ro v id ed b y t h e ISP. Fo r DHCP clien t co n n ect io n s , y o u can ch o o s e t h e M A C ad d res s o f t h e co n t ro ller t o reg is t er wit h t h e ISP.
Wireless Controller User Manual Figure 92 : Rus s ia L2TP ISP configurat io n 6.2.6 Option Configuration in an IPv 6 Network Advanced > IPv6 > IPv6 Option1 Config Fo r IPv 6 Op t io n co n n ect io n s , t h is co n t ro ller can h av e a s t at ic IPv 6 ad d res s o r receiv e co n n ect io n in fo rmat io n wh en co n fig u red as a DHCPv 6 clien t .
Page 172
Wireless Controller User Manual t o y o u r co n tro ller, t h e IPv 6 p refix len g t h d efin ed b y t h e ISP is n eed ed . Th e d efau lt IPv 6 Gat eway ad d res s is t h e s erver at t he ISP t h at t h is co nt roller will co n n ect t o fo r acces sin g t h e in t ern et .
Wireless Controller User Manual Figure 93 : IPv6 Option1 Se tup page Prefix Deleg at io n : Select t his o pt ion t o req uest co ntro ller ad v ert is emen t p refix fro m an y av ailab le DHCPv 6 s erv ers av ailab le o n t h e ISP, t h e o b t ain ed p refix is u p d at ed t o t h e ad v ert is ed p refixes o n t h e LA N s id e.
Wireless Controller User Manual Pas s word: En t er t h e p as s wo rd req u ired t o lo g in t o t h e ISP. Authenti cati on Type : Th e t y p e o f A u t h en t icat io n in u s e b y t h e p ro file: A u t o - Neg o t iat e/ PA P/ CHA P/ M S-CHA P/ M S-CHA Pv 2.
Page 175
Wireless Controller User Manual Pri mary DNS : Primary DNS s erv er IP ad d res s o f t h e Op t io n p o rt . S econdary DNS : Seco n d ary DNS s erv er IP ad d res s o f t h e Op t io n p o rt . If t h e Co n n ect io n St at u s in d icat ed t h at t h e as s o ciat io n wit h t h e ISP is act iv e, t h en t h e Op t io n can b e d is co n n ect ed b y clickin g t h e Dis ab le b u t t o n .
Wireless Controller User Manual Figure 94 : Conne ction Status inform at io n of Option1 Th e Op t io n s t at u s p ag e allo ws y o u t o En ab le o r Dis ab le s t at ic Op t io n lin ks . Fo r Op t io n s et t in g s t h at are d y n amically receiv ed fro m t h e ISP, y o u can Ren ew o r Releas e t h e lin k p aramet ers if req u ired .
Wireless Controller User Manual 6.3 Features with Multiple Option Links Th is co n t roller s u pp orts mu lt ip le Op t io n lin ks . Th is allo ws y o u t o t ake ad v an t ag e o f failo v er an d lo ad b alan cing featu res t o en s ure certain in t ern et d epend en t s erv ices are p rio rit ized in t h e ev en t o f u n s t ab le Op t io n co n n ect iv it y o n o n e o f t h e p o rt s .
Wireless Controller User Manual DNS l ook up us i ng Opti on S ervers : DNS Lo o ku p o f t h e cu s t o m DNS Serv ers can b e s p ecified t o ch eck t h e co n n ect iv it y o f t h e p rimary lin k. ...
Page 179
Wireless Controller User Manual Fo r examp le, if t h e maximu m b an d wid t h o f p rimary Op t io n is 1 Kb p s an d t h e lo ad t o leran ce is s et t o 70.
Wireless Controller User Manual Figure 95 : Load B alancing is available whe n multiple Option ports are configure d and Protocol B indings have be e n de fine d 6.3.3 Protocol Bindings...
Wireless Controller User Manual Advanced > Routing > Protocol Bindings Pro t o co l b in d in gs are req uired wh en t h e Lo ad Balan cin g feat ure is in u s e. Ch o o s in g fro m a lis t o f co n fig u red s erv ices o r an y o f t h e u s er -d efin ed s erv ices , t h e t y p e o f t raffic can b e as s ig n ed t o g o o v er o n ly o n e o f t h e av ailab le Op t io n p o rt s .
Wireless Controller User Manual Any: No s p ecific n et work n eed s t o b e g iv en. S i ng l e Addres s : Limit t o o n e co mp u t er. Req u ires t h e IP ad d ress o f t h e co mp u ter t h at will b e p art o f t h e s o u rce n etwo rk fo r t h is p ro tocol b in d in g Addres s Rang e: Select if y o u wan t t o allo w co mp u t ers wit h in an IP ad d ress ran g e t o b e a p art o f t h e s o urce n etwo rk.
Page 183
Wireless Controller User Manual y o u r ISP h as as s ig n ed an IP ad d res s fo r each o f t h e co mp u t ers t h at y o u u s e, s elect Clas s ic Ro u t in g .
Wireless Controller User Manual Figure 97 : Routing M ode is us e d to configure traffic routing be twe e n Option and LAN, as we ll as Dynamic routing (RIP)
Wireless Controller User Manual 6.4.2 Dynamic Routing (RIP) Th e fo llo win g feat u re is av ailab le u p o n licen s ed act iv at io n o f VPN / Firewall feat u res fo r t h e s y s t em. Setup >...
Wireless Controller User Manual If RIP-2B o r RIP-2M is t h e s elect ed v ersio n, au th en ticat io n b et ween t h is co n t ro ller an d o t h er co n t ro llers (co n fig u red wit h t h e s ame RIP v ers io n ) is req u ired . M D5 au t h en ticat io n is u sed in a firs t / s eco n d key exch an g e p ro ces s .
Wireless Controller User Manual Gateway: IP ad d ress o f t h e g ateway t h rou gh wh ich t h e d es t in at io n h o s t o r n et wo rk can b e reach ed .
Wireless Controller User Manual Figure 101 : OSPFv2 Configuratio n OS PFv2 Enabl e : A ch eck b o x t o en ab le/ d is ab le OSPFv 2. Interface : Th e p h y s ical n et wo rk in t erface o n wh ich OSPFv 2 is En ab led / Dis ab led . Area: Th e area t o wh ich t h e in t erface b elo n g s .En t er v alu es fro m 1 t o 255 .Two ro u t ers h avin g a co mmo n s eg men t;...
Wireless Controller User Manual Th is v alu e mu s t b e t h e s ame fo r all ro u t ers at t ach ed t o a co mmo n n et wo rk. Th e d efau lt v alu e is 10 s eco n d s .
Wireless Controller User Manual 6.7 IGMP Setup Th e fo llo win g feat u re is av ailab le u p o n licen s ed act iv at io n o f VPN / Firewall feat u res fo r t h e s y s t em. Advanced >...
Wireless Controller User Manual Add: To ad d a n et wo rk/ h o s t ad d res s alo n g wit h mas k len g t h . Edi t: To ed it a n et wo rk/ h o s t ad d res s alo n g wit h mas k len g t h . Del ete: To d elet e a n et wo rk/ h o s t ad d res s alo n g wit h mas k len g t h ..
Wireless Controller User Manual 6.9 IP Aliases Th e fo llo win g feat u re is av ailab le u p o n licen s ed act iv at io n o f VPN / Firewall feat u res fo r t h e s y s t em. Setup >...
Wireless Controller User Manual Chapter 7. Securing the Private Network Th e fo llo win g feat u re is av ailab le u p o n licen s ed act iv at io n o f VPN / Firewall feat u res fo r t h e s y s t em.
Wireless Controller User Manual 7.1 Firewall Rules Advanced > Firewall Settings > Firewall Rules In b o u n d (Op t io n t o LA N/ DM Z) ru les rest rict access t o t raffic en t erin g y o u r n et wo rk, s elect iv ely allo win g o n ly s pecific o u t side u sers t o access s p ecific lo cal res o u rces .
Wireless Controller User Manual Figure 106 : Lis t of Available Fire wal l Rule s 7.2 Defining Rule Schedules Tools > Schedules Firewall ru les can b e en abled o r d is ab led au t o mat ically if t h ey are as s o ciat ed wit h a co n fig u red s chedule.
Wireless Controller User Manual Figure 107 : Lis t of Available Sche dule s to bind to a fire wal l rule 7.3 Configuring Firewall Rules Th e fo llo win g feat u re is av ailab le u p o n licen s ed act iv at io n o f VPN / Firewall feat u res fo r t h e s y s t em.
Page 200
Wireless Controller User Manual Chose the From Zone to be the source of originating traffic: either the secure LAN, public DMZ, or insecure Option. For an inbound rule Option should be selected as the From Zone. Choose the To Zone to be the destination of traffic covered by this rule. If the From Zone is the Option, the to Zone can be the public DMZ or secure LAN.
Page 201
Wireless Controller User Manual Inbound rules can use Destination NAT (DNAT) for managing traffic from the Option. Destination NAT is available when the To Zone = DMZ or secure LAN. W it h an in b o u n d allo w ru le y o u can en t er t h e in t ern al s erv er ad d res s t h at is h o s t in g t h e s elect ed s erv ice.
Wireless Controller User Manual Figure 108 : Example whe re an outbound SNAT rule is us e d to map an e xte rnal IP addre s s (209.156.200.225) to a private DM Z IP addre s s (10.30.30.30 )
Wireless Controller User Manual Figure 109 : The fire wal l rule configuratio n page allows you to de fine the To/From zone , s e rvice , action, s che dule s , and s pe cify s ource /de s tination IP addre s s e s as ne e de d.
Wireless Controller User Manual 7.3.1 Firewall Rule Configuration Examples Exampl e 1 : A llo w in b o u n d HTTP t raffic t o t h e DM Z S i tuati on: Yo u h o s t a p u b lic web s erv er o n y o u r lo cal DM Z n et wo rk. Yo u wan t t o allo w in b o u n d HTTP req u ests fro m an y o u t sid e IP ad d ress t o t h e IP ad d res s o f y o u r web s erv er at an y t ime o f d ay .
Page 205
Wireless Controller User Manual Par am eter V alu e From Zone Insecure (Option 1/ Option2) To Zone Secure (LAN) Service CU-SEEME:UDP Action ALLOW alw ays Send to Local Server (DNAT IP) 192.168.10.11 Destination Users Address Range From 132.177.88.2 134.177.88.254 Enable Port Forw arding Yes (enabled) Exampl e 3 : M u lt i-NA T co n fig u rat io n...
Page 206
Wireless Controller User Manual LA N IP ad d res s : 192.168.10.1; s u b n et 255.255.255. 0 W eb s erv er h o s t in t h e DM Z, IP ad d res s : 192.168.12.222 ...
Wireless Controller User Manual Defin e “weeken d ” t o mean 12 am Sat u rd ay mo rn in g t o 12 am M o n d ay mo rn in g – all d ay Sat u rd ay & Su n d ay ...
Wireless Controller User Manual As we defined our schedule in schedule “Weekend”, this is available in the dropdown menu We want to block the IP range assigned to the marketing group. Let‟s say they have IP 192.168.10.20 to 192.168.10.30. On the Source Users dropdown, select Address Range and add this IP range as the from and To IP addresses.
Wireless Controller User Manual Figure 111 : Lis t of us e r de fine d s e rvice s . 7.5 ALG support Advanced > Firewall Settings > ALGs A p p licat io n Lev el Gat eway s (A LGs ) are s ecu rit y co mp o nent t hat en h ance t h e firewall an d NA T s u p p ort o f t h is co ntro ller t o s eamles sly s u ppo rt ap plicat ion lay er p ro t o co ls .
Wireless Controller User Manual Figure 112 : Available ALG s upport on the controlle r. 7.6 VPN Passthrough for Firewall Advanced > Firewall Settings > VPN Passthrough Th is co n t roller‟s firewall s et t in g s can b e co n fig u red t o allo w en cry p t ed VPN t raffic fo r IPs ec, PPTP, an d L2TP VPN t u n n el co nn ectio ns b et ween t h e LA N an d in t ern et .
Wireless Controller User Manual Figure 113 : Pas s through options for VPN tunne ls 7.7 Client Advanced > Client Th e Kn o wn Clien t Su mmary s h o ws t h e wireles s clien ts cu rrently in t h e Kn o wn Clien t Dat ab as e an d allo ws y o u t o ad d n ew clien t s o r mo d ify exis t in g clien t s t o t h e d atabase.
Wireless Controller User Manual Gl obal Acti on: Us e t h e g lo b al wh it e -lis t o r b lack-lis t act io n co n fig u red o n t h e A d v an ced Glo b al Co n fig u rat io n p ag e t o d et ermin e h o w t o h an d le t h e clien t .
Wireless Controller User Manual t rig g erin g wait s fo r an o u t b o u n d req u es t fro m t h e LA N/ DM Z o n o n e o f t h e d efin ed o u t g o ing p ort s, an d t h en o pens an in co min g p ort fo r t h at s pecified t y pe o f t raffic.
Wireless Controller User Manual Th e ap p licat io n ru le s t atus p age will lis t an y act iv e ru les , i.e. in co min g p o rt s t h at are b ein g t rig g ered b as ed o n o u t b o u n d req u es t s fro m a d efin ed o u t g o in g p o rt .
Wireless Controller User Manual 7.10.1 Content Filtering Th e fo llo win g feat u re is av ailab le u p o n licen s ed act iv at io n o f VPN / Firewall feat u res fo r t h e s y s t em. Advanced >...
Wireless Controller User Manual Figure 117 : Conte nt Filte ring us e d to block acce s s to proxy s e rve rs and pre ve nt Active X controls from be ing downloade d 7.10.2 Approv ed URLs Advanced >...
Wireless Controller User Manual Figure 118 : Two trus te d domains adde d to the Approve d URLs Lis t 7.10.3 Blocked Keywords Advanced > Website Filter > Blocked Keywords Key wo rd b lo ckin g allo ws y o u t o b lo ck all web s it e URL‟s o r s it e co n t ent t h at con tains t h e key wo rd s in t h e co n fig u red lis t .
Wireless Controller User Manual Figure 119 : One k e yword adde d to the block lis t 7.10.4 Export W eb Filter Advanced > Website Filter > Export Export Approved URLs : Feat u re en ab les t h e u s er t o exp o rt t h e URLs t o b e allo wed t o a cs v file wh ich c an t h en b e d own lo aded t o t h e lo cal h o st .
Wireless Controller User Manual Figure 120 : Export Approve d URL lis t 7.11 IP/MAC Binding Advanced > IP/MAC Binding A n o t h er av ailab le securit y meas u re is t o o n ly allo w o u t bou nd t raffic (fro m t h e LA N to Op t io n ) wh en t h e LA N n o d e h as an IP ad d ress mat ch ing t he M A C ad d ress b o und t o it.
Wireless Controller User Manual Figure 121 : Example binding a LAN hos t’s M AC Addre s s to a s e rve d IP addre s s In t h e ab o v e examp le , if t h ere is an IP/ M A C Bin d in g v io lat io n , t h e v io lat in g p acket will b e d ro p p ed an d lo g s will b e cap t u red .
Wireless Controller User Manual Figure 122 : RADIUS Se rve r Configuratio n Authenti cati on S erver IP Addres s (Pri mary) : IP ad d res s o f t h e p rimary RA DIUS au t h en t icat io n s erv e r. Authenti cati on S erver IP Addres s (S econdary) : IP ad d res s o f t h e s eco n d ary RA DIUS au t h en t icat io n s erv er.
Wireless Controller User Manual Retri es : Th is d et ermin es t h e n u mb er o f t ries t h e ro u t er will make t o t h e RA DIUS s erv er b efo re g iv in g u p .
Wireless Controller User Manual p o rt is co n n ect ed is les s t h an wh en all o f t h e av ailab le LA N p o rt s h a v e an act iv e Et h ern et co n n ect io n .
Wireless Controller User Manual Chapter 8. IPsec / PPTP / L2TP VPN Th e fo llo win g feat u re is av ailab le u p o n licen s ed act iv at io n o f VPN / Firewall feat u res fo r t h e s y s t em.
Wireless Controller User Manual Figure 125 : Example of Gate way-to - Gate way IPs e c VPN tunne l us ing two DWC controlle rs conne cte d to the Inte rne t...
Wireless Controller User Manual Figure 126 : Example of thre e IPs e c clie nt conne ctions to the inte rnal ne twork through the DWC IPs e c gate way...
Wireless Controller User Manual 8.1 VPN Wizard Setup > Wizard > VPN Wizard Yo u can u s e t h e VPN wizard t o q u ickly creat e b o t h IKE an d VPN p o licies . On ce t h e IKE o r VPN p o licy is crea t ed , y o u can mo d ify it as req u ired .
Page 229
Wireless Controller User Manual Set t h e Co n n ectio n Name an d p re -sh ared key : t h e co nn ectio n n ame is u s ed fo r man ag emen t, and t h e p re -s h ared key will b e req u ired o n t h e VPN clien t o r g at eway t o es t ab lis h t h e t u n n el Det ermin e t h e lo cal g at eway fo r t h is t u n n el;...
Wireless Controller User Manual Local Option ID w an_local.com (only applies to Client policies) Remote Option ID w an_remote.com (only applies to Client policies) Encryption Algorithm 3DES Authentication Algorithm SHA-1 Authentication Method Pre-shared Key PFS Key-Group DH-Group 2(1024 bit) Life Time (Phase 1) 24 hours Life Time (Phase 2) 8 hours...
Wireless Controller User Manual Tran s p ort : Th is is u sed fo r en d -t o -en d co mmu n icat io n b et ween t h is co n t ro ller an d t h e t u n n el en d p o in t, eit h er an o ther IPs ec g at eway o r an IPs ec VPN clien t o n a h o s t .
Page 232
Wireless Controller User Manual On ce t h e t u n nel t y p e an d en d poin t s o f t h e t u n n el are d efin ed y o u can d et ermin e t h e Ph as e 1 / Ph as e 2 n eg o t iatio n t o u se fo r t h e t un nel.
Wireless Controller User Manual Figure 129 : IPs e c policy configurat ion continue d (Auto policy via IKE) A M an u al p o licy d o es n ot u s e IKE an d in s t ead relies o n man u al key in g t o exch an g e au t h en ticat io n p aramet ers b etween t h e t wo IPs ec h o s t s .
Wireless Controller User Manual u s in g A u to p olicies wit h IKE are p referred as in s o me IPs ec imp lemen t at io n s t h e SPI (s ecu rit y p aramet er in d ex) v alu es req u ire co n v ers io n at each en d p o in t . DW C-1000 s u p p o rt s VPN ro ll-o v er feat u re.
Wireless Controller User Manual W it h a co n fig u red RA DIUS s erv er, t h e co nt roller co n nects t o a RA DIUS s erv er an d p as s es t o it t h e credent ials t h at it receiv es fro m t h e VPN clien t . Yo u can s ecu re t h e co n n ectio n b etween t h e co n t ro ller an d t h e RA DIUS s erv er wit h t h e au t h en t icat io n p ro t o co l s u p p o rt ed b y t h e s erv er (PA P o r CHA P).
Wireless Controller User Manual 8.4 PPTP / L2TP Tunnels Th is co n t ro ller s u p p o rt s VPN t u n n els fro m eit h er PPTP o r L2TP ISP s erv e rs . Th e co n t ro ller act s as a b ro ker d ev ice t o allo w t h e ISP's s erv er t o creat e a TCP co n t ro l co n n ect io n b et ween t h e LA N VPN clien t an d t h e VPN s erv er.
Wireless Controller User Manual Figure 131 : PPTP tunne l configuratio n – PPTP Clie nt Figure 132 : PPTP VPN conne ction s tatus Setup > VPN Settings > PPTP > PPTP Server A PPTP VPN can b e es t ablis hed t h rou gh t h is co nt roller. On ce en abled a PPTP s erver is av ailab le o n t h e co n troller fo r LA N an d Op t io n PPTP clien t u s ers t o access .
Wireless Controller User Manual Figure 133 : PPTP tunne l configuratio n – PPTP Se rve r 8.4.2 L2TP Tunnel Support Setup > VPN Settings > L2TP > L2TP Server A L2TP VPN can b e es t ablis hed t h rou gh t h is co nt roller. On ce en abled a L2TP s erver is av ailab le o n t h e co n troller fo r LA N an d Op t io n L2TP clien t u s ers t o access .
Wireless Controller User Manual Figure 134 : L2TP tunne l configuratio n – L2TP Se rve r 8.4.3 OpenVPN Support Setup > VPN Settings > OpenVPN > OpenVPN Configuration Op en VPN allo ws p eers t o au t h en t icat e each o t h er u s in g a p re -s h ared s ecret key , cert ificat es , o r u sername/ passwo rd .
Page 240
Wireless Controller User Manual Mode: Op en VPN d aemo n mo d e. It can ru n in s erv er mo d e, clien t mo d e o r acces s s erv er clien t mo d e. In access s erv er clien t mo d e, t h e u ser h as t o d o wn lo ad t h e au t o lo g in p ro file fro m t h e Op en v p n A cces s Serv er an d u p lo ad t h e s ame t o co n n ect .
Chapter 9. SSL VPN Th e fo llo win g feat u re is av ailab le u p o n licen s ed act iv at io n o f VPN / Firewall feat u res fo r t h e s y s t em. Th e co n t ro ller p ro vid es an in t rin sic SSL VPN feat u re as an alt ernate t o t he s tandard IPs ec VPN.
Wireless Controller User Manual 9.1 Groups and Users Advanced > Users > Groups Th e g ro u p p ag e allo ws creat in g , ed it in g an d d elet in g g ro u p s . Th e g ro u p s are as s o ciat ed t o s et o f u s er t y pes.
Page 246
Wireless Controller User Manual Xauth Us er : Th is u s er‟s au t h en t icat io n is p erfo rmed b y an ext ern ally co n fig u red RA DIUS o r o t h e r En t erp rise s erv er. It is n o t p art o f t h e lo cal u s er d at ab as e.
Wireless Controller User Manual Figure 138 : Us e r group configu rat ion W h en SSLVPN u s ers are s elect ed , t h e SSLVPN s et t in g s are d is p lay ed wit h t h e fo llo win g p aramet ers as cap t u red in SSLVPN Set t in g s .
Page 248
Wireless Controller User Manual LDAP B as e DN: Th is is t h e b as e d o main n ame fo r t h e LDA P au t h en t icat io n s erv er. If t h ere are mu lt ip le LDA P au t h e n ticatio n s erv ers , u s er can en t er t h e d et ails fo r u p t o t wo LDA P Bas e DN.
Wireless Controller User Manual Figure 139 : SSLVPN Se ttings Log i n Pol i ci es To s et lo g in p o licies fo r t h e g r o u p , s elect t h e co rres p o n d in g g ro u p click “Lo g in p o licies ”.
Wireless Controller User Manual Deny Log i n from Opti on i nterface : En ab le t o p rev en t t h e u s ers o f t h is g ro u p fro m lo g g in g in fro m a Op t io n (wid e area n et wo rk) in t erface.
Wireless Controller User Manual Yo u can ad d t o t h e lis t o f Defin ed Bro ws ers b y s elect in g a clien t b ro ws er fro m t h e d ro p d o wn men u an d clickin g A d d.
Wireless Controller User Manual Al l ow Log i n from Defi ned B rows ers : Th e lis t o f d efin ed b ro ws ers b elo w will b e u s ed t o allo w t h e u sers o f t h is g ro u p fro m lo g g in g in t o t h e co n t ro ller GUI. A ll n o n - d efin ed b ro ws ers will b e d en ied fo r lo g in fo r t h is g ro u p .
Wireless Controller User Manual Advanced > Users > Users Th e u s ers p ag e allo ws ad d in g , ed it in g an d d elet in g exis t in g g ro u p s . Th e u s er are as s o ciat ed t o co nfig u red g rou ps.
Page 254
Wireless Controller User Manual S el ect Group: A g ro u p is ch o s en fro m a lis t o f co n fig u red g ro u p s . Pas s word: Th e p as s wo rd as s o ciat ed wit h t h e u s er n ame. Confi rm Pas s word: Th e s ame p as s wo rd as ab o v e is req u ired t o mit ig at e ag ai n s t t y p in g erro rs .
Wireless Controller User Manual Figure 144 : Us e r Configu rat io n options 9.2 Using SSL VPN Policies Setup > VPN Settings > SSL VPN Server > SSL VPN Policies SSL VPN Po licies can b e creat ed o n a Glo b al, Gro u p , o r Us er lev el. Us er l ev el p o licies t ake p reced en ce o v er Gro u p lev el p o licies an d Gro u p lev el p o licies t ake p reced ence o ver Glo b al p o licies .
Wireless Controller User Manual Figure 14 5: Lis t of SSL VPN police s (Global filte r) To ad d a SSL VPN p o licy , y o u mu s t firs t as sig n it t o a u s er, g ro u p , o r make it g lo b al (i.e.
Wireless Controller User Manual On ce d efin ed , t h e p olicy g o es in t o effect immed iat ely . Th e p o licy n ame, SSL s erv ice it ap p lies t o , d es t in at io n (n et wo rk res o u rce o r IP ad d res s es ) an d p er mis s io n (d en y / p ermit ) is o u t lin ed in a lis t o f co n fig u red p o licies fo r t h e co n t ro ller.
Wireless Controller User Manual Appl y Pol i cy To: Th is refers t o t h e LA N res o u rces man ag ed b y t h e DW C-1000, an d t h e p o licy can p ro v id e (o r p rev en t ) acces s t o n et wo rk res o u rces , IP ad d res s , IP n et wo rk, et c.
Wireless Controller User Manual res o u rce as req u ired . A n et wo rk res o u rce can b e d efin ed b y co n fig u rin g t h e fo llo win g in t h e GUI: Res ource Name: A u n iq u e id en t ifier n ame fo r t h e re s o u rce.
Page 260
Wireless Controller User Manual ad d res s an d TCP p o rt n u mb er o f t h e ap plicat ion t o b e t u nn elled . Th e t able b elo w lis t s s o me co mmo n ap p licat io n s an d co rres p o n d in g TCP p o rt n u mb ers : T CP Ap p lication Po r t Num ber...
Page 261
Wireless Controller User Manual Local S erver IP addres s : Th e IP ad d res s o f t h e lo cal s erv er wh ich is h o s t in g t h e ap p licat io n .
Wireless Controller User Manual Figure 148 : Lis t of Available Applicat io ns for SSL Port Forward i ng 9.4 SSL VPN Client Configuration Setup > VPN Settings > SSL VPN Client > S SL VPN Client A n SSL VPN t u n n el clien t p ro vid es a p o in t-to -po int co nnect ion b etween t h e b ro ws er - s id e mach in e an d t h is co n t ro ller.
Wireless Controller User Manual Th e IP ad d res s es o f t h e clien t ‟s n et wo rk in t erfaces (Et h ern et , W ireles s , et c.) can n o t b e id en t ical t o t h e co n t ro ller‟s IP ad d res s o r a s erv er o n t h e co rp o rat e LA N t h at is b ein g acces s ed t h ro u g h t h e SSL VPN t u n n el.
Page 264
Wireless Controller User Manual all ad d res ses o n t h e p riv at e n etwo rk are accessib le o ver t h e VPN t u n n el. Clien t routes are n o t req u ired . DNS S uffi x: Th e DNS s u ffix n ame wh ich will b e g iv en t o t h e SSL VPN clien t .
Wireless Controller User Manual Figure 150 : Configu re d clie nt route s only apply in s plit tunne l mode 9.4.1 Creating Portal Layouts Setup > VPN Settings > SSL VPN Server > Portal Layouts Th e co n t ro ller allo ws y o u t o create a cu sto m p ag e fo r remo t e SSL VPN u s ers t h at is p res en t ed u p o n au t h en t icat io n .
Page 266
Wireless Controller User Manual Portal Layout Name: A d es crip t iv e n ame fo r t h e cu s t o m p o r t al t h at is b ein g co n fig u red . It is u s ed as p art o f t h e SSL p o rt al URL. Portal S i te Ti tl e: Th e p o rt al web b ro ws er win d o w t it le t h at ap p ears wh en t h e clien t acces s es t h is p o rt al.
Wireless Controller User Manual Figure 151 : SSL VPN Portal configu rat ion 9.5 Active VPN Tunnels Th e fo llo win g feat u re is av ailab le u p o n licen s ed act iv at io n o f VPN / Firewall feat u res fo r t h e s y s t em.
Wireless Controller User Manual Pol i cy Name : IKE o r VPN p o licy as s o ciat ed wit h t h is SA . Endpoi nt: IP ad d res s o f t h e remo t e VPN g at eway o r clien t . Tx (KB ): Kilo b y t es o f d at a t ran s mit t ed o v er t h is SA .
Page 269
Wireless Controller User Manual Connect S tatus : St at u s o f t h e SSL co n n ect io n b et ween t h is co n t ro ller an d t h e remo t e VPN clien t : No t Co n n ect ed o r Co n n ect ed .
Wireless Controller User Manual Chapter 10. Advanced System Functionalities 10.1 USB Device Setup Setup > USB Settings > USB Status Th e DW C-1000 W ireles s co n t ro ller h as a USB in t erface fo r p rin t er acces s , file s h arin g .
Wireless Controller User Manual Figure 153 : USB De vice De te ction 10.2 USB Share Port Setup > USB Settings > USB Status Th e DW C-1000 W ireles s co n troller h as a USB in t erface fo r p rin t er acces s t h is p ag e allo ws y o u t o en able USB d ev ice s u p p o rt fo r b o t h in t erface USB1 an d USB2.
Wireless Controller User Manual Figure 154 : USB Share Port 10.3 Authentication Certificates Advanced > Certificates Th is g at eway u s es d ig it al cert ificat es fo r IPs ec VPN au t h en t icat io n as well as SSL v alid at io n (fo r HTTPS an d SSL VPN au t h en t icat io n ).
Page 273
Wireless Controller User Manual Expi ry Ti me : Th e d at e aft er wh ich t h is Tru s t ed cert ificat e b eco mes in v alid A s elf cert ificat e is a cert ificat e is s u ed b y a CA id en t ify in g y o u r d ev ice (o r s elf- s ig n ed if y o u d o n‟t wan t t h e id ent ity p ro tect ion o f a CA ).
Wireless Controller User Manual Figure 155 : Ce rtificate s ummary for IPs e c and HTTPS manage me nt ® 10.4 Intet Th is feat u re is av ailab le u p o n licen s ed act iv at io n o f VPN / Firewall feat u res fo r t h e s y s t em.
Wireless Controller User Manual ® Ro u t ers , In t el A M T Tech n o lo g y co u ld cro s s In t ern et s eamles s ly an d it 's an id eal s o lu t io n t o h elp IT man ag ers fo r as s et man ag emen t o v er In t ern et .
Page 276
Wireless Controller User Manual s ep arat ed lis t o f Op t io n h o s t ad d res s es t h at are t o b e allo wed acces s t o t h e Lo cal Serv er (LA N Ho s t ).
Wireless Controller User Manual Chapter 11. Advanced Wireless Controller Features 11.1 Advanced Global Wireless Controller Configuration Advanced > Global > General Th e field s o n t h e ad v an ced W ireles s Glo b al Co n fig u rat io n p ag e are s et t in g s t h at ap p ly t o t h e DW C-1000 W ireles s Co n t ro ller.
Page 278
Wireless Controller User Manual Figure 157 : Wire le s s Configu rat io n Peer Group ID: In o rd er t o s u p p o rt larg er n et wo rks , y o u can co n fig u re wireles s co n t ro llers as p eers , wit h u p t o 8 co n t ro llers in a clu s t er (p eer g ro u p ).
Page 279
Wireless Controller User Manual AP Fai l ure S tatus Ti meout: Th is v alu e d et ermin es h o w lo n g t o keep an en t ry in t h e A P A u t h enticatio n Failu re St at us lis t . Each en t ry in t h e s t at us lis t s hows an ag e, an d wh en t h e ag e reaches t h e v alue y ou co nfig ure in t h e t imeo u t field , t h e en t ry is d elet ed .
Wireless Controller User Manual Th e Clien t Qo S feat u re ext en d s t h e p rimary Qo S cap ab ilit ies o f t h e Un ified W ireles s co nt roller t o t h e wireles s d o main . M o re s p ecifically , acces s co n t ro l lis t s (A CLs ) an d d ifferen t iated s ervice (DiffServ ) p o licies are ap plied t o wireles s clien ts as s o ciat ed t o t h e A P.t h e maximu m M TU s ize o f exis t in g n et wo rk in fras t ru ct u re wh ich is s et u p t o co n t ro ller an d ro u t e 1518 (1522-t ag g ed ) b y t e frames .
Wireless Controller User Manual Figure 158 : Dis tribute d Tunne ling Di s tri buted Tunnel Cl i ents : Sp ecify t h e maximu m n u mb er o f d is t rib u t ed t u n neling clien t s t h at can ro am away fro m t h e Ho me A P at t h e s ame t ime.
Page 282
Wireless Controller User Manual Fig ure 159 : Dis tribute d Tunne ling Clie nts Di s tri buted Tunnel Pack ets : Tran s mit t ed: To t al n u mb er o f p acket s sent b y all A Ps v ia d is t rib u t ed t u n n els .
Wireless Controller User Manual 11.4 Peer Controller Configuration 11.4.1 Peer Controller Configuraiton Request Status Advanced > Peer Controller > Configuraiton Request Status Th e Peer Co n t ro ller Co n fig u rat io n feat u re allo ws y o u t o s en d a v ariet y o f co n fig u ratio n in fo rmat io n fro m o n e co n tro ller t o all o t h er co nt rollers.
Wireless Controller User Manual No t St art ed . Receiv in g Co n fig u rat io n . Sav in g Co n fig u rat io n . Su cces s . Failu re In v alid Co d e Vers io n .
Page 285
Wireless Controller User Manual Figure 161 : Pe e r Controlle r Configuraito n Gl obal : En ab le t h is field t o in clu d e t h e b as ic an d ad v an ced g lo b al s et t in g s in t h e co n fig u ratio n t hat t h e co n t ro ller p u s h es t o it s p eers .
Wireless Controller User Manual Known Cl i ent: En ab le t h is field t o in clu d e t h e Kn o wn Clien t Dat ab as e in t h e co n fig u rat io n t h at t h e co n t ro ller...
Page 287
Wireless Controller User Manual Manag ed S S ID from a fak e manag ed AP : A h acker may s et u p an A P wit h t h e s ame M A C ad d res s as o ne o f t h e man ag ed A Ps an d co n fig u re it t o s en d o n e o f t h e man ag ed SSIDs .
Page 288
Wireless Controller User Manual s t an d alo n e A P in t h e lo cal o r RA DIUS Valid A P d at ab as e. Th is t es t may d et ect n et wo rk mis co n fig u rat io n as well as p o t en t ial in t ru s io n at t emp t s .
Page 289
Wireless Controller User Manual leg it imat e A Ps are clas s ified as ro g u es b efo re en ab lin g t h e at t ack feat u re. Th is feat u re is d is ab led b y d efau lt .
Wireless Controller User Manual Figure 162 : WIDS AP Configuratio n 11.5.2 W IDS Client Configuration Advanced > WIDS Security > Client Th e s et t in gs y o u co nfig ure o n t he W IDS Clien t Co n fig u rat io n p ag e h elp d et ermin e wh et h er a d et ected clien t is clas s ified as a ro g u e.
Page 291
Wireless Controller User Manual • Pro b e Req u es t s • 802.11 A u t h en t icat io n Req u es t s • 802.11 De -A u t h en t icat io n Req u es t s . In o rd er t o h elp d et ermin e wh et h er a clien t is p o s in g a t h reat t o t h e n et wo rk b y flo o d in g t h e n et wo rk wit h man ag emen t t raffic, t h e s y s t em keep s t rack o f t h e n u mb er o f t imes t h e A P receiv ed each mes sage t y p e an d t h e h ig hest mes s ag e rat e d et ect ed in a s in g le RF Scan rep o rt .
Page 292
Wireless Controller User Manual Known Cl i ent Databas e Look up Method: W h en t h e co n t ro ller d et ect s a clien t o n t h e n et wo rk it p erfo rms a lo o ku p in t h e Kn o wn Clien t d at ab as e. Sp ecify wh et h er t h e co n t ro ller s h o u ld u s e t h e lo cal o r RA DIUS d at ab as e fo r t h es e lo o ku p s .
Wireless Controller User Manual Chapter 12. Administration & Management 12.1 Remote Management Bo t h HTTPS an d t eln et acces s can b e res t rict ed t o a s u b s et o f IP ad d res s es . Th e co n t ro ller ad min is t rat o r can d efin e a kn o wn PC, s in g le IP ad d res s o r ran g e o f IP ad d res ses t h at are allo wed t o access t he GUI wit h HTTPS.
Wireless Controller User Manual wit h t h e GUI fo r ad min is t rat o r u s ers . To acces s t h e CLI, t y p e “cli” in t h e SSH o r co n s o le p ro mp t an d lo g in wit h ad min is t rat o r u s er cred en t ials .
Wireless Controller User Manual Figure 165 : SNM P Us e rs , Traps , and Acce s s Control Tools > Admin > SNMP System Info Th e co n t ro ller is id en t ified b y an SNM P man ag er v ia t h e Sy s t em In fo rmat io n . Th e id en t ifier s et t in g s Th e Sy s Name s et h ere is als o u s ed t o id en t ify t h e co n t ro ller fo r Sy s Lo g lo g g in g .
Wireless Controller User Manual Figure 166 : SNM P s ys te m inform at io n for this controlle r 12.4 SNMP Traps Advanced > Global > SNMP Traps If y o u u s e Simp le Net wo rk M an ag emen t Pro t o co l (SNM P) t o man ag e t h e DW C-1000 wireles s co n t roller, y o u can co nfig u re t h e SNM P ag ent o n t h e co ntro ller t o s en d t rap s t o t h e SNM P man ag er o n y o u r n et wo rk.
Wireless Controller User Manual Figure 167 : SNM P Traps AP Fai l ure Traps : If y o u en ab le t h is field , t h e SNM P ag en t s en d s a t rap if an A P fails t o as s o ciat e o r au t h en t icat e wit h t h e co n t ro ller.
Page 299
Wireless Controller User Manual Cl i ent S tate Chang e Traps : If y o u en ab le t his field , t h e SNM P ag en t s en ds a t rap fo r o n e o f t h e fo llo win g reas o n s as s o ciat ed wit h t h e wireles s clien t : ...
Wireless Controller User Manual 8- Det ect ed Clien t s Lis t . 12.5 Configuring Time Zone and NTP Tools > Date and Time Yo u can co n fig u re y o u r t ime zo n e , wh et h er o r n o t t o ad ju s t fo r Day lig h t Sav in g s Time, an d wit h wh ich Net wo rk Time Pro t o co l (NTP) s erv er t o s y n ch ro n ize t h e d at e an d t ime.
Wireless Controller User Manual Figure 168 : Date , Time , and NTP s e rve r s e tup 12.6 Log Configuration Th is co n t ro ller allo ws y o u t o cap t u re lo g mes s ag es fo r t raffic t h ro u g h t h e firewall, VPN, an d o v er t h e wireles s A P.
Wireless Controller User Manual 12.6.1 Defining W hat to Log Tools > Log Settings > Logs Facility Th e Lo g s Facilit y p ag e allo ws y o u t o d et ermin e t h e g ran u larit y o f lo g s t o receiv e fro m t h e co n t roller.
Wireless Controller User Manual Figure 169 : Facility s e ttings for Logging Th e d is p lay fo r lo g g in g can b e cu s t omized b as ed o n wh ere t h e lo g s are s en t , eit h er Status >...
Page 304
Wireless Controller User Manual Traffic t h ro u g h each n etwo rk s egmen t (LA N, Op t io n , DM Z) can b e t racked b ased on wh et h er t h e p acket was accep t ed o r d ro p p ed b y t h e firewall. A ccep t ed Packet s are t h o s e t h at were s u cces s fu lly t ran s ferred t h ro u g h t h e co rres p o n d in g n et wo rk s eg men t (i.e.
Wireless Controller User Manual Figure 170 : Log configuratio n options for traffic through controlle r 12.6.2 Sending Logs to E-mail or Syslog Tools > Log Settings > Remote Logging On ce y o u h av e co nfig ured t h e t y p e o f lo g s t h at y o u wan t t h e co n t ro ller t o co llect , t h ey can b e s ent t o eit h er a Sy s lo g s erver o r an E-M ail ad d res s.
Page 306
Wireless Controller User Manual On ce y o u en ab le t h e o p t io n t o e -mail lo g s , en t er t h e e -mail s erv er‟s ad d res s (IP ad d res s o r FQDN) o f t h e SM TP s erv er.
Wireless Controller User Manual Figure 171 : E-mail configurat io n as a Re mote Logging option A n ext ern al Sy s lo g s erver is o ft en u sed b y n etwo rk ad min is trato r t o collect an d s tore lo g s fro m t h e co n tro ller.
Wireless Controller User Manual s erv er s elect t h e ch eckb o x n ext t o an emp t y Sy s lo g s erv er field an d as s ig n t h e IP ad d res s o r FQDN t o t h e Name field .
Wireless Controller User Manual Status > Logs > VPN Logs Th e fo llo win g feat u re is av ailab le u p o n licen s ed act iv at io n o f VPN / Firewall feat u res fo r t h e s y s t em.
Wireless Controller User Manual Figure 174 : SSL VPN logs dis playe d in GUI e ve nt vie we r 12.7 Backing up and Restoring Configuration Settings Tools > System Yo u can b ack u p t h e co n t ro ller cu s t o m co n fig u rat io n s et t in g s t o res t o re t h em t o a d ifferen t d ev ice o r t h e s ame co n tro ller aft er s ome o t h er ch ang es.
Page 311
Wireless Controller User Manual Fo r b ackin g u p co nfig u rat io n o r res t o rin g a p rev io u s ly s av ed co n fig u rat io n , p leas e fo llo w t h e s t ep s b elo w: To save a copy of your current settings, click the Backup button in the Save Current Settings option.
Wireless Controller User Manual Figure 175 : Re s toring configuratio n from a s ave d file will re s ult in the curre nt configurat io n be ing ove rwritte n and a re boot 12.8 Upgrading Wirelesss Controller Firmware Tools >...
Wireless Controller User Manual Figure 176 : Firmware ve rs ion inform atio n and upgrade option Th is co n t ro ller als o s u p p o rt s an au t o mat ed n o t ificat io n t o d et ermin e if a n ewer firmware v ers io n is av ailab le fo r t h is co nt roller.
Page 314
Wireless Controller User Manual Each co n fig u red Op t io n can h av e a d ifferen t DDNS s erv ice if req u ir ed . On ce co n fig u red , t h e co n t ro ller will u p d at e DDNS s erv ices ch an g es in t h e Op t io n IP ad d res s s o t h at feat u res t h at are d ep en d en t o n acces s in g t h e co n t ro ller Op t io n v ia FQDN will b e d irect ed t o t h e co rrect IP ad d ress.
Wireless Controller User Manual Figure 177 : Dynamic DNS configurat ion 12.9.1 Using Diagnostic Tools Tools > System Check Th e co n t ro ller h as b u ilt in t o o ls t o allo w an ad min is t rat o r t o ev alu at e t h e co mmu n icat io n s t at u s an d o v erall n et wo rk h ealt h .
Wireless Controller User Manual Figure 178 : Controlle r diagnos tics tools available in the GUI 12.9.2 Ping Th is u t ilit y can b e u s ed t o t es t co n n ect iv it y b et ween t h is co n t ro ller an d an o t h er d ev ice o n t h e n et wo rk co n n ect ed t o t h is co n t ro ller.
Wireless Controller User Manual 12.9.4 DNS Lookup To ret riev e t h e IP ad d ress o f a W eb , FTP, M ail o r an y o t h er s erv er o n t h e In t ern et , t y p e t h e In t ern et Name in t h e t ext b o x an d click Lo o ku p .
Wireless Controller User Manual Chapter 13. License Activation Tools > License Yo u can act iv at e A P6 an d VPN licen s e s in t h is co n t ro ller b y p ro v id in g v alid A ct iv at io n Key an d click A ct iv at e key .
Wireless Controller User Manual Figure 179 : Ins talling a Lice ns e Figure 180 : Available Lice ns e s Dis play afte r ins talling a Lice ns e Th e n ew feat u re s will b e en ab le d aft er s y s t em reb o o t .
Wireless Controller User Manual Appendix A. Glossary Address Resolution Protocol. Broadcast protocol for mapping IP addresses to MAC addresses. CHAP Challenge-Handshake Authentication Protocol. Protocol for authenticating users to an ISP. Dynamic DNS. System for updating domain names in real time. Allow s a domain name to be DDNS assigned to a device w ith a dynamic IP address.
Page 321
Wireless Controller User Manual Internet Key Exchange Security Protocol. Protocol for establishing security associations and ISAKMP cryptographic keys on the Internet. Internet service provider. Media-access-control address. Unique physical-address identifier attached to a netw ork MAC Address adapter. Maximum transmission unit. Size, in bytes, of the largest packet that can be passed on. The MTU for Ethernet is a 1500-byte packet.
Page 322
Wireless Controller User Manual Remote Authentication Dial-In User Service. Protocol for remote user authentication and RADIUS accounting. Provides centralized management of usernames and passw ords. Rivest-Shamir-Adleman. Public key encryption algorithm. Transmission Control Protocol. Protocol for transmitting data over the Internet w ith guaranteed reliability and in-order delivery.
Appendix B. Factory Default Settings Fe at u re De s cription De f au lt Setting User login URL http://192.168.10.1 Device login User name (case sensitive) admin Login password (case sensitive) admin Option MAC address Use default address Internet Option MTU size 1500 Connection...
Page 324
Wireless Controller User Manual DHCP starting IP address 192.168.10.2 DHCP ending IP address 192.168.10.100 Time zone Time zone adjusted for Daylight Saving Time Disabled SNMP Disabled Remote management Disabled Disabled (except traffic on port Inbound communications from the Internet 80, the HTTP port) Outbound communications to the Internet Enabled (all) Firew all...