Manuel d'utilisation / d'entretien du produit AT-TQ2403 du fabricant Allied Telesis
Aller à la page of 292
AT-TQ2403 Management Software User's Guide PN 613-001156 Rev. B.
2 AT-TQ2403 - Ma nagement Software - User's Guide Copyright © 2011 Allied Telesis, Inc. All rights reserved. No part of this publication may be reproduced without prior written permission from Allied Telesis, Inc. Microsoft and Internet Explorer are re gistered trademarks of Microsoft Co rporation.
AT-TQ2403 Ma nagement Software User's Gu ide 3 S AFETY N OTICE Do not open service or change any component. Only qualified technicians are allo wed to service the equipment. Observe safety precautions to avoid electric shock Check voltage before connecti ng to the power supply.
4 AT-TQ2403 - Ma nagement Software - User's Guide E LECTRICAL S AFETY AND E MISSIONS S TANDARDS This product meets the fo llowing standards. U.S. Federal Communications Comm ission Interference Statement This equipment has been test ed and found to comply with the limits for a Class B digital device, pursuant to Part 15 of t he FCC Rules.
AT-TQ2403 Ma nagement Software User's Gu ide 5 Electromagnetic compatibility and Radio spectrum Matters (ERM); Wideband transmission systems ; Data transmission equipment operating in the 2,4 GH z ISM band and using wide band mo dulati o n techniques; Harmonized EN covering es sential requirements under article 3.
6 AT-TQ2403 - Ma nagement Software - User's Guide C ONTENTS Preface ............................................................................................................................... .....................................15 Purpose of This Guide .
AT-TQ2403 Ma nagement Software User's Gu ide 7 Navigating to Configuration Information for a Specific AP and Managing Standalone APs ........... 37 Navigating to an AP by Us ing its IP Address in a URL ............................................
8 AT-TQ2403 - Ma nagement Software - User's Guide Ethernet (Wir ed) Settings ...........................................................................................................................79 Wireless Settings .........................
AT-TQ2403 Ma nagement Software User's Gu ide 9 Chapter 17: Load Balancing ............................................................................................................................ 116 Understanding Load Balancing ..............
10 AT-TQ2403 - Ma nagement Software - User's Guide Appendix A: Security Settings on Wi reless Clients and RADIUS Server Setup ................................. 151 Network Infrastructure a nd Choosing Between Built-in or Externa l Authentication S erver .
AT-TQ2403 Ma nagement Software User's Gu ide 11 Keyboard Shortcuts ............................................................................................................................... .2 6 8 Tab Completion and Help ....................
12 AT-TQ2403 - Ma nagement Software - User's Guide F IGURES Figure 1: Kick Start Welcome Dialog Box ............................................................................................................... 22 Figure 2: Kick Start Se arch Results Dialog Box .
AT-TQ2403 Ma nagement Software User's Gu ide 13 Figure 38: Ethernet (Wired) Settings Page ............................................................................................................... 89 Figure 39: Wireless Settings Page .......
14 AT-TQ2403 - Ma nagement Software - User's Guide Figure 78: Radius Server Setti ng – Input New Radius Clie nt ............................................................................. 178 Figure 79: Radius Server Setting – New Radius Client Sett ing .
AT-TQ2403 Ma nagement Software User's Gu ide 15 Pr eface Purpose of This Guide This guide is intended for customers and/or networ k adminis trators who are re sponsible for installing and maintaining the AT-TQ 2403 Management S oftware.
16 AT-TQ2403 - Ma nagement Software - User's Guide Contacting Allied T elesis This section provides Allied Telesis contact informatio n for technical support as well as sales and corporate information. Online Suppor t You can request technical support onl ine by accessing the Allied Telesis Knowledge Base: http://www.
AT-TQ2403 Ma nagement Software User's Guide 17 Chapter 1: Pr eparing to Set Up the A T -TQ2403 Wir eless Access P oint Before you plug in and boo t a new AT-TQ2403 Ma nagement Software, review the fol lowing sections fo r a quick check of required hard ware components, softwa re, client conf igurations, and compatibility issues .
18 AT-TQ2403 - Ma nagement Software - User's Guide The administration web browser must have JavaScript e nabled to support the interactive features of the administrati on interface. It mu st also support HTTP uploads to use the firmware upgrade feature.
AT-TQ2403 Ma nagement Software User's Guide 19 username and password, certificate, or similar user identity proof. Security modes are Static WEP, IEEE 802.1x, WPA with RADI US server, and WPA-PSK. For information on configuri ng security on the access point, see “ Configuring S ecurity ”.
20 AT-TQ2403 - Ma nagement Software - User's Guide Recovering an IP Address If you experience trouble communicati ng with the access point, you can recover a static IP address by resetting the ac.
AT-TQ2403 Ma nagement Software User's Guide 21 Chapter 2: Setting up the A T -TQ2403 Mana gement Softwar e Setting up and deploying on e or more AT-TQ2403 Ma nagement Software is in effect creating and launching a wireless n etwork.
22 AT-TQ2403 - Ma nagement Software - User's Guide 2. Insert the AT-TQ2403 Wireless Access Point CD into the CD-ROM drive on your computer. The Kick S tart Welcome dialog box is displaye d, as shown in Figure 1 Figure 1: Kick Start Welcome Dialog Box 3.
AT-TQ2403 Ma nagement Software User's Guide 23 4. Review the list of access points found Kick S tart d etects the IP addresses of AT-TQ 2 403 Management Software. Access po ints are listed with their locations, me dia acc ess control (MAC) addresses, and IP addresses, as shown in Figure 2.
24 AT-TQ2403 - Ma nagement Software - User's Guide Password: friend Figure 4: Log-in Dialog Box Note: The user name can n ot be modified. 8. Enter the username and password and click OK When you log in for the first time, the Basic Settings page is displayed, as shown in Figure 5.
AT-TQ2403 Ma nagement Software User's Guide 25 Configuring the Basic Settings and Starting the Wireless Netw ork Provide a minimal set of conf iguration information by defi ning the basic settings for your wire less network.
26 AT-TQ2403 - Ma nagement Software - User's Guide prevent others from seeing your password as you type. Confirm New Password Rety pe the new administrato r password to confirm that you typed it as you intended. Network Name (SSID) En ter a name for the wireless network as a character string.
AT-TQ2403 Ma nagement Software User's Guide 27 Chapter 3: Configuring Basic Settings The basic configuration tasks are desc ribed in the f ollowing sectio ns: Navigating to Basic Settings .
28 AT-TQ2403 - Ma nagement Software - User's Guide Re view / Describe the Access P oint Figure 7: Basic Settings Page Step 1 Field Description IP Address Shows IP address assigned to this acce ss point.
AT-TQ2403 Ma nagement Software User's Guide 29 Pr o vide Netw ork Settin gs Figure 8: Basic Settings Step 2 Field Description Current Password Enter the current administrator passw ord. You must correctly e n ter the current password before you a re able to change it.
30 AT-TQ2403 - Ma nagement Software - User's Guide Update Basic Settings Figure 9: Basic Settings Page Step 3 Whe n you have reviewed the new configuration, click U pdate to apply the setti ngs and deploy the access points as a wireless network.
AT-TQ2403 Ma nagement Software User's Guide 31 Chapter 4: Managing Access P oints and Clusters The AT-TQ2403 Manageme nt Software shows current basic configuration settings for clus tered access .
32 AT-TQ2403 - Ma nagement Software - User's Guide Na vigating to Access P oints Manag ement To view or edit information on access poin ts in a cluster, click the Cluster > Access Points tab.
AT-TQ2403 Ma nagement Software User's Guide 33 What Kinds of APs Can Cluster Together? A single AT-TQ2403 Wireless Access Point can form a cl uster with itself (a "cluster of one") and with other AT-TQ2403 Wireless Access Points of the same model.
34 AT-TQ2403 - Ma nagement Software - User's Guide When Channel Pl anning is enab led, the radio Channel is not synced across the cl uster. Security settings MAC address filtering Setting.
AT-TQ2403 Ma nagement Software User's Guide 35 Intra-Cluster Security For purposes of ease-of- use, the clustering component is designed to let new devices join a c luster without strong authentication.
36 AT-TQ2403 - Ma nagement Software - User's Guide Field Description Mac Address Media Access Control (MAC) address of the access point. A MAC address is a permanent, unique hardware address for any device that represents an interface to the networ k.
AT-TQ2403 Ma nagement Software User's Guide 37 Stopping Clustering To stop clustering and remove a partic ular access point from a cluster, do the following . 1. Go to the Administration Web pages for the access point yo u want to remove from the cluster.
38 AT-TQ2403 - Ma nagement Software - User's Guide All clustered access points are shown on the Cluster > Access Points page. To navigate to clustered access points, you can simply click on the IP addre ss for a specific cluster member show n in the list.
AT-TQ2403 Ma nagement Software User's Guide 39 Chapter 5: Managing User Accounts The AT-TQ2403 M anagement Sof tware includes user manageme nt capabilities for controlling c lient access to access points.
40 AT-TQ2403 - Ma nagement Software - User's Guide Figure 13: User Manage ment Page Vie wing User Accounts User accounts are shown at the top of the screen under " User Accounts". The Username, Real name and Status (enabled or disabled) of the user are shown.
AT-TQ2403 Ma nagement Software User's Guide 41 Field Description Password Specify a password for this user. Passwords are strings of 4 to 256 charac ters. Please do not include '<' and '&'. 2. When you have filled in the fields, cli ck Add Account to add the account.
42 AT-TQ2403 - Ma nagement Software - User's Guide A user with an account that is enabled can log on to the wireless access points in your netw ork as a client. Disabling a User Account To disable a user account, click the chec kbox next to the username and click Disable .
AT-TQ2403 Ma nagement Software User's Guide 43 Chapter 6: Session Monitoring The AT-TQ2403 Ma nagement Software provides real-time session monitori ng information including which clients a re associated with a particular access po int, data rates, transmit/receive statistics, signal strength, and idle time.
44 AT-TQ2403 - Ma nagement Software - User's Guide Note: A sessio n is not the same as an association , which describes a client connection to a particular access point. A client network conn ection can shift from one clustered AP to another within the context of the same session.
AT-TQ2403 Ma nagement Software User's Guide 45 Field Description Rx Total Ind icates number of total packets receiv ed by the client during the current session. Tx Total Indicates number of total packets trans m itted to the client during this session.
46 AT-TQ2403 - Ma nagement Software - User's Guide Chapter 7: Channel Manag ement The following Channel Management to pics are covered here: Navigating to Channel Management Understanding.
AT-TQ2403 Ma nagement Software User's Guide 47 Understanding Channel Mana ge ment When Channel M anagement is enabled, the A T-TQ2403 AP automatically assigns radio channels used by clustered access points to reduce mutual interfere n ce (or interference with other acces s points outside of its cluster).
48 AT-TQ2403 - Ma nagement Software - User's Guide With automated channel management, APs in the cluster are automatica lly re-assigned to non-inte rfering channels as shown in below figure.
AT-TQ2403 Ma nagement Software User's Guide 49 Figure 19: After Channel Management Enable Whe n automatic channel assignm ent is enabled, the Channel Manager periodically maps radio channels used.
50 AT-TQ2403 - Ma nagement Software - User's Guide Viewing Last Propos ed Set of Changes The Proposed Channel Assignments show s the last channel pla n . The plan lists all access points in th e cluster by IP Address, and shows the proposed cha nnels for each AP.
AT-TQ2403 Ma nagement Software User's Guide 51 Field Description Change channels if interference is reduced by at least Specify the minimum percentage of interference reductio n a proposed plan must achieve in order to be applied. The default is 25 percent.
52 AT-TQ2403 - Ma nagement Software - User's Guide Chapter 8: Wir eless Neighborhood The Wireless Neighborhood view shows those access points within range of any access point in the cluster.
AT-TQ2403 Ma nagement Software User's Guide 53 Understanding Wir eless Ne ighborhood Information The Wireless Neighborhood shows all access points wit h in range of every member of the cluster, shows which access points are within range of which cl uster members, and distinguishes between clus ter members and non-members.
54 AT-TQ2403 - Ma nagement Software - User's Guide Field Description Cluster The Cluster list at the top of the table s hows IP addresses for all access points in the cluster. (This is the same list of cluster members show n on the Cluster > Access Points tab described in “ Navigating to Acce ss Points Management ”.
AT-TQ2403 Ma nagement Software User's Guide 55 Vie wing Details for a Cluster Member To view details on a cluster member AP, click on the IP address of a cluster member a t the top of the page. Figure 21: Cluster Member Setting Detail The fo llowing table e xplains the details shown about the selected AP.
56 AT-TQ2403 - Ma nagement Software - User's Guide Field Description Channel Shows the channel on whic h the access point is currently broadcasting. The Channel defines t he portion of the radio spectrum t hat the radio uses for transmitting and receiving.
AT-TQ2403 Ma nagement Software User's Guide 57 Chapter 9: Configuring Security The following sectio ns describe how to configur e Securit y settings on the AT-TQ 2403 Management Software: Und.
58 AT-TQ2403 - Ma nagement Software - User's Guide and also may be the right convenience trade-off for other scenarios whe re the priority is making it as easy as possible for clients to connec t.
AT-TQ2403 Ma nagement Software User's Guide 59 + 2 4-bit initiali zation vector (IV)) or 128-bit (104-bit secret key + 24-bit IV) Sh ared Key for data encryption. Key Management Encryption A lgorithm User Authentication Static WEP uses a fixed key that is provided by the administrator.
60 AT-TQ2403 - Ma nagement Software - User's Guide Additionally, compa tibility issues may be cumbersome because of the variety of authe ntication methods supported and the lack of a st andard implementati on method. Therefore, IEEE 802.1x mode is not as secure a so lution as Wi-Fi Protected Access (WPA) or WPA2.
AT-TQ2403 Ma nagement Software User's Guide 61 Th is security mode also provides backwards-compa ti bility for wireless clients that support only th e original WPA. Key Management Encryption A lgorithm User Authenticatio n WPA Enterprise mode provides dynamically-generated keys that are periodically refreshed.
62 AT-TQ2403 - Ma nagement Software - User's Guide Does Prohibiting the Broadc ast SSID Enhance Security? You can suppress (prohibit) this broadcast to discou rage stations from automatically d iscovering your access point.
AT-TQ2403 Ma nagement Software User's Guide 63 Broadcast SSID, Station Isol ation, and Security Mode To configure security on the access point, select a secu rity mode and fill in the relat ed fields as described in the following tabl e.
64 AT-TQ2403 - Ma nagement Software - User's Guide Field Description Security Mode Select the Security Mode . Select one of the following: None (Pla in-text ) Static WEP IEEE 802.1x WPA Personal WPA Enterprise For a Guest network, the only security mode that can be applied is None (Plain-text) .
AT-TQ2403 Ma nagement Software User's Guide 65 For a minimum leve l of protection on a guest netw ork, you can choose to suppress (prohibit) the broadcast of the SSID (network name) to discourage cl ient stations from automatically discovering your access point.
66 AT-TQ2403 - Ma nagement Software - User's Guide Field Description Transfer Key Index Select a key index from the drop-down menu. Key inde xes 1 through 4 are available. The default is 1. The Transfer Key Index indica tes which W EP key the access point will use to encrypt the data it transmits.
AT-TQ2403 Ma nagement Software User's Guide 67 Field Description Authentication The authenticatio n algo rithm defines the method used to d etermine whether a client station is allowed to associate with an access point wh en static WEP is the security m ode.
68 AT-TQ2403 - Ma nagement Software - User's Guide Example of Using Static WEP For a simple example, su ppose you configure three WEP keys on the access point.
AT-TQ2403 Ma nagement Software User's Guide 69 If you have a second client s tation, that station also needs to have o ne of the WEP keys defined on the AP.
70 AT-TQ2403 - Ma nagement Software - User's Guide If you selected IEEE 802.1x Security Mode, provide t h e following: Figure 28: Security Setting Page – IEE E802.
AT-TQ2403 Ma nagement Software User's Guide 71 Field Description Radius IP Enter the Radius IP in the tex t box. The Radius IP is the IP address of the RADIUS server. You can configure two RADIUS servers. The secondary server only when the first server is not available.
72 AT-TQ2403 - Ma nagement Software - User's Guide If you selected WPA Personal S ecurity Mode, provide the following: Figure 29: Security Setting Page – WPA Personal Setting Pa ge Field Descri.
AT-TQ2403 Ma nagement Software User's Guide 73 Field Description Cipher Suites Select the cipher suite you want to use: TKIP CCMP (AES) Both Temporal Key Integrity Protocol (TKIP) is the default. TKIP: It provides a more secure encr yption solut i on than WEP keys.
74 AT-TQ2403 - Ma nagement Software - User's Guide Figure 30: Security Setting Page – WPA Enterprise Setting Page Field Description WPA Ve rsions Select the type s of client st ations you want .
AT-TQ2403 Ma nagement Software User's Guide 75 Field Description Cipher Suites Select the cipher you want to use: TKIP CCMP (AES) Both Temporal Key Integrity Protocol (TKIP) is the default. TKIP: It provides a more secure encr yption solut ion than WEP keys.
76 AT-TQ2403 - Ma nagement Software - User's Guide Field Description Use internal radius server You can choose whether to use the b uilt-in authenticatio n server provided with the AT-TQ2403 Man agement Soft ware, or you can use an external radius server.
AT-TQ2403 Ma nagement Software User's Guide 77 Field Description Require VLAN ID in Dynamic VLAN Dynamic mode is enabled when you click the checkbox. If you have enabled dynamic mode and try to establish wir eless connection between wireless client and AP, the AP must receive VLAN ID information from Radius server in authentication proc ess.
78 AT-TQ2403 - Ma nagement Software - User's Guide Chapter 10: Maintenance and Monitoring The maintenan ce and monitoring tasks described here all pertain to viewing a n d modifying settings o n specific access points; not o n a cluster configurat io n that is automatically shared by multiple access points.
AT-TQ2403 Ma nagement Software User's Guide 79 Th is page displays the current settings of the AT-TQ 2403 M anagement Software. It displays the Et hernet (Wired) Settings and the Wireless Sett ings.
80 AT-TQ2403 - Ma nagement Software - User's Guide Note: The AT-TQ2403 Manageme nt Software acquires its date a n d time information using the network time proto col (NTP). This data is reported in UTC format (also known as Greenwich Mean Time).
AT-TQ2403 Ma nagement Software User's Guide 81 all messages wit h a severity level between 4 and 0 will appear in the Event log. Theref ore, less severe messages and notices will be ignored.
82 AT-TQ2403 - Ma nagement Software - User's Guide Setting Up the Log Relay Host To use Kernel Log relaying, you m ust configure a re mote server to rec eive the syslog messages. This procedure will vary depending on th e ty pe of machine you use as the remote log host .
AT-TQ2403 Ma nagement Software User's Guide 83 Events Log The Events Log shows system events on the access point such as stations associating, being authenticated, and other occ urrences. The real-time Events Log is always shown o n the Status > Events Administration We b UI page for the access poin t you are monitori ng.
84 AT-TQ2403 - Ma nagement Software - User's Guide Field Description IP Address IP Address for the access point. MAC Address Media Access Control (MAC) address for the specified interface. A MAC address is a permanent, unique hardware address for any device that represents an interface to the network.
AT-TQ2403 Ma nagement Software User's Guide 85 The associated statio ns are disp layed along with informatio n about packet traffic transmit ted and received for each station. Note: The Authenticated and Associated Status shows only the und erlying IEEE 802.
86 AT-TQ2403 - Ma nagement Software - User's Guide Information provided on n eighboring access points is described in the following ta ble. Field Description MAC Address Shows the MAC address of th e neighboring access point. A MAC address is a hardware address that uniquely identifies each node of a network.
AT-TQ2403 Ma nagement Software User's Guide 87 Field Description Band This indicates the IEEE 802.11 mode being used on this access point . (For example, IEEE 802.11a, IEE E 802.11b, IEEE 802.11g. ) The number shown ind i cates the mode according to the fo llowing map: 2.
88 AT-TQ2403 - Ma nagement Software - User's Guide Chapter 11: Setting the Ethernet (Wir ed) Interface Ethernet (Wir ed) Settings describe the co nfiguration of your Ether n et local area network (LAN ). Note: The Ethernet Set tings, including guest a ccess, are not shared across the cluster.
AT-TQ2403 Ma nagement Software User's Guide 89 Figure 38: Ethernet (Wired) Settings Page Setting the DNS HostName Field Description DNS Hostname Enter the DNS name for the access point i n the text box. This is the host name. It may be provided by your ISP or network administrator, or you can provide your ow n.
90 AT-TQ2403 - Ma nagement Software - User's Guide Enabling or Disab ling Guest Access You can provide controlled guest access over an isol at ed network and a secure internal LAN on the same AT-TQ2403 Managem ent Software.
AT-TQ2403 Ma nagement Software User's Guide 91 Field Description Virtual Wireless Networks Select Enabled to enable VLANs for the Internal network and for additional networks.
92 AT-TQ2403 - Ma nagement Software - User's Guide Field Description VLAN ID If you have enabled VWNs or Guest a ccess via VLAN, this field will be enabled. Provide a number between 1 and 4094 for the Internal VLAN. This VLAN ID must not be the same as the Guest VLA N ID or a VWN VLAN ID.
AT-TQ2403 Ma nagement Software User's Guide 93 Field Description Secure Management You can restrict access to ma nagement IP interface to the specified client. Select Enabled to ena ble Secure Management feature. Only the s p ecified client can access the management IP i nterface (Web pages, telnet) of t his access point.
94 AT-TQ2403 - Ma nagement Software - User's Guide Field Description Static IP Address If you chose Sta tic IP as the Connection T ype, these fields will be enabled. Enter the Static IP Address in the text boxes. Subnet Mask Enter the Subnet Mask in the text box es.
AT-TQ2403 Ma nagement Software User's Guide 95 Chapter 12: Setting the Wir eless Interface Wireless settings describe as pects of the local area network (LAN) r elated specifically to the radio device in the access point (802.
96 AT-TQ2403 - Ma nagement Software - User's Guide Configuring 802.11d Regulator y Domain Suppor t You can enable or disable IE EE 802.11d Regulatory Do main Support to broadcast the access point country code information as described belo w. Field Description 802.
AT-TQ2403 Ma nagement Software User's Guide 97 I f you are operatin g in an 802 .11h enable d domain, then the channel sele ction of the BSS will always be "Auto". Even if ano ther channel has been has been configured, th is will be ignored and auto- channel selection will occur.
98 AT-TQ2403 - Ma nagement Software - User's Guide Field Description Channel Select the Channel . The range of channels and the default is determined b y the Mode of the radio interface. The Channel defines the por tion of the radi o spectrum the radio uses for t ransmitting and receiving.
AT-TQ2403 Ma nagement Software User's Guide 99 Field Description Wireless Network Name (SSID) Enter the SSID for t he internal WLAN. The Service Set Identifier (SS ID) is a string of up to 32 characters tha t uniquely id entifies a wireless local area network.
100 AT-TQ2403 - Ma nagement Software - User's Guide Chapter 13: Setting up Guest Access Out-of -the -box Guest Interface features allow you to configure th e AT-TQ2403 Man agement Software for controlled guest access to an iso lated network.
AT-TQ2403 Ma nagement Software User's Guide 101 Configuring the Guest Interface To configure the Gues t interface on the AT-TQ 2403 Management Software, perform t hese configuration steps: 1.
102 AT-TQ2403 - Ma nagement Software - User's Guide 1. Navigate to the Manage > Guest Login tab. Figure 40: Guest Login Setting P age 2. Choose Enabled to activate the W elcome screen. 3. In the Welcome Screen Text field, type the text message you would like guest clie nts to see on the captive portal.
AT-TQ2403 Ma nagement Software User's Guide 103 Figure 41: Guest Network Diagram Example.
104 AT-TQ2403 - Ma nagement Software - User's Guide Chapter 14: Configuring Vir tual Wir eless Netw orks The following sectio ns describe how to configure mu ltiple wireless networks on Virtual L.
AT-TQ2403 Ma nagement Software User's Guide 105 Configuring VLANs Note: To configure additional netw orks on VLANs, you m ust first enable Virtual Wireless Networks on the Ethernet Settings page. S ee “ Enabling or Disabling Virtual Wireless Networks on the AP ”.
106 AT-TQ2403 - Ma nagement Software - User's Guide Field Description Broadcast SSID Select the Broadc as t SSI D setting by selecting the Broadcast SSI D checkbox. By default, t h e access point br oadcasts (allows) the Servic e Set Identifier (SSID) in its beacon frames.
AT-TQ2403 Ma nagement Software User's Guide 107 Chapter 15: Configuring Radio Settings The following sectio ns describe how to config ure Radio Setti ngs on the AT-TQ2403 Management Software: .
108 AT-TQ2403 - Ma nagement Software - User's Guide Figure 43: Radio Setting Page Field Description Radio Specify Radio One or Radio Two. The rest of the settings on this tab apply to the radio selected in this field . Be sure to configure settings for bot h radios.
AT-TQ2403 Ma nagement Software User's Guide 109 Field Description Mode The Mode defines the Physical Layer (PHY) standard being used by the radio. The AT-TQ2403 is available as a dual band access point. Select one of these modes: For Radio Interface 1 IEEE 802.
110 AT-TQ2403 - Ma nagement Software - User's Guide Field Description Broadcast/Multicast Rate Limit Burst Setting a rate limit burst de termines how much traffic bursts can be before all traffic exceeds the rate limit. This burst limit allows intermittent bursts of traffic on a network above the set rate limit.
AT-TQ2403 Ma nagement Software User's Guide 111 Field Description DTIM Period All Beacon frames include a Traffic In formation Map informatio n element (TIM IE). In some beacon frames, the TIM IE includes a Delivery Traffic Information Map (DTIM) message.
112 AT-TQ2403 - Ma nagement Software - User's Guide Field Description RTS Threshold Specify an RTS Threshold value between 0 and 2347. The RTS thres hold specifies the packet size at which packe t transmission is governed by the RTS/CTS transaction.
AT-TQ2403 Ma nagement Software User's Guide 113 Field Description Rate Sets Check t h e transmissio n rate sets you want the access point to sup p ort and the basic rate sets you want the access point to advertise. Rates are expressed in megabits per second.
114 AT-TQ2403 - Ma nagement Software - User's Guide Chapter 16: Contr olling Access b y MA C Addr ess Filtering A Media Access Control (MAC) address is a hardware address that uniquely identifies each node of a network.
AT-TQ2403 Ma nagement Software User's Guide 115 For the G uest interface, MAC Filtering sett ings apply to both BSSes. MAC Filtering settings apply to bot h radios.
116 AT-TQ2403 - Ma nagement Software - User's Guide Chapter 17: Load Balancing The AT-TQ2403 Ma nagement Software allows you to bala nce the distribution of wireless clien t connections across multiple access points .
AT-TQ2403 Ma nagement Software User's Guide 117 Load Balancing and QoS Load balancing also plays a part in contributing to Quality of Service (QoS) for Voice Over IP (VoIP) and other such time-sensi tive applicatio ns competing for bandwidth and timely access to the air waves on a wireless network.
118 AT-TQ2403 - Ma nagement Software - User's Guide Field Description Load Balancing To enable load balancing on t his access point, click Enable . To disable load balancing o n this access point, click Disable . Utilization for No New Associations Utilization rate limits re late to wireless bandwidth utilization.
AT-TQ2403 Ma nagement Software User's Guide 119 Chapter 18: Pr e-Config Ro gue AP Pre-config Rogue Configurat ion notifies you when access points are not in the Access Points list. Access points are filtered by MAC address, a hard ware ID number that uniquely ide n tifies each node of a network.
120 AT-TQ2403 - Ma nagement Software - User's Guide Using Pr e-Config Ro gue AP Field Description AP Detection To set AP Detection, click Enabled . Detection Interval Use the drop-down me nu to specify the schedule for AP Detection. A range of intervals is provided, from "15 Minutes" to "4 Weeks".
AT-TQ2403 Ma nagement Software User's Guide 121 Chapter 19: Configuring Quality of Ser vice (QoS) Quality of Service (QoS) provides you with the ability to specify param eters on multip le queues.
122 AT-TQ2403 - Ma nagement Software - User's Guide 802.11e and WMM Standards Support QoS describes a range of technologies for controllin g data streams on shared network co nnections. The IEEE 802.1 1e task group has defined a QoS st andard for transmission quality and availability of service on wir eless networ ks.
AT-TQ2403 Ma nagement Software User's Guide 123 is sent to this queue. Data 3 (Background). Lowest priority queue, high throughput. Bulk data that re quires maximum throughput and is not time-s ensitive is sent to this queue (FTP data, for example).
124 AT-TQ2403 - Ma nagement Software - User's Guide is based on CSMA/CA protocol, defines the interframe space (IFS) between data frames. Data frames wait for an amount of time defined as the a rbitration interframe space (AIFS) before transmitti ng.
AT-TQ2403 Ma nagement Software User's Guide 125 802.1q and DSCP tags IEEE 802.1q is an extension of the IE EE 802 standard and is responsible for QoS provision. One purpose of 802.1q is to prioritize net work traffic at the data link/ MAC layer. The 802.
126 AT-TQ2403 - Ma nagement Software - User's Guide The table belo w outlines the VLAN priority and DSCP values. Table 1 VLAN Priority VLAN Priority Priority DSCP value 0 Best Effort 0 1 Backgrou.
AT-TQ2403 Ma nagement Software User's Guide 127 Note: For the G uest interface or VWNs (Virtual APs), Qo S queue settings apply to the access point load as a whole (all BSS s together). These settings apply to both radios bu t the traffic for each radio is queue d independently.
128 AT-TQ2403 - Ma nagement Software - User's Guide Field Description AIFS (Inter-Frame Space) The Arbitration Inter-Frame Spacing (AIFS) specifies a wait time ( in milliseconds) for data frames. Valid values for AIFS are 1 through 255. For more information , see “ EDCA Control of Data Frames and Arbitration Interframe Spaces ”.
AT-TQ2403 Ma nagement Software User's Guide 129 Field Description Max. Burst Length AP EDCA Parameter Only (The Max. Burst Leng th applies only to traffic flowing from the access point to the cl ient station.) This value specifies (in milliseconds) the Maximu m Burst Length allowed for packet bursts on the wireless ne twork.
130 AT-TQ2403 - Ma nagement Software - User's Guide Field Description Queue Queues are defined for differ ent types of data transmitted from station-to-AP: Data 0 (Voice) Low latency and guaranteed b andwidth. Time-sensitiv e data such as VoIP should be sent to this queue .
AT-TQ2403 Ma nagement Software User's Guide 131 Field Description cwMax (Maximum Contention Window) The value specified here in the Maximum Contentio n Window is the upper limit (in milliseconds) f or the do ubling of the random backoff value.
132 AT-TQ2403 - Ma nagement Software - User's Guide Chapter 20: Configuring the Wir eless Distribution System (WDS) The AT-TQ2403 Ma nagement Software lets you connect multipl e access points using a Wireless Distribution System (WDS ). WDS allows access points to communicat e with one another wirelessly.
AT-TQ2403 Ma nagement Software User's Guide 133 Figure 50: Bridge Distant Wired LA N by WDS Diagram Using WDS to Extend the Network Beyond the Wired Coverage Area An ESS can extend the reach of the ne twork into areas where cabling would be difficult, costly, or ineffi cient.
134 AT-TQ2403 - Ma nagement Software - User's Guide For more information a bout the effectiv en ess of different security modes, see “ Configuring Security ”. This topic also covers use o f the unencrypted secu rity mode for AP-to-statio n traffic on the Guest network, which is intended f or less sensitive data traffic.
AT-TQ2403 Ma nagement Software User's Guide 135 Configuring WDS Settings The following notes summarize some critical guidelines regarding WDS conf iguration. Please read all the notes before proceeding with WDS configuration. Note: Whe n using WDS, be sure to conf igure WDS settings on both access points participating in the WDS li nk.
136 AT-TQ2403 - Ma nagement Software - User's Guide Field Description Remote Address Specify the MAC address of the destina tion access point; that is, the access point to which data will be sent or "ha n ded-off" and from which data will be received, in other words the AP to whic h you are creating the WDS bridge.
AT-TQ2403 Ma nagement Software User's Guide 137 http://IPAddressOfAccessPoint where IPAddressOfAccessPoint is the address of MyAP1. 2. Navigate to the WDS tab on MyAP1 A dministration Web pages. The MAC addr ess for MyAP1 (the access point you are curr ently viewing) wi ll s h o w a s t h e Local Address at the top of the page.
138 AT-TQ2403 - Ma nagement Software - User's Guide Chapter 21: Configuring Simple Netw ork Mana gement Pr otocol (SNMP) on the AP The following sections descri be supported SNMP MIBs, and show h.
AT-TQ2403 Ma nagement Software User's Guide 139 Figure 52: SNMP Setting Diagram Suppor ted MIBs MIBs are a collection of objects or files tha t exist in a virtual database on a network . SNMP uses a specific set of commands and queries to obta in information fro m the MIB.
140 AT-TQ2403 - Ma nagement Software - User's Guide C ategory MIB Le vel of Su pport Standard IEEE M IB Bridge-MIB Partial, read-only support includ ing root bridge We do not impl ement th e optional StaticTable.
AT-TQ2403 Ma nagement Software User's Guide 141 Field Description SNMP Enabled/Disabled You can choose whether or not you want to enable SNMP on your network. By default SN MP is Enabled. To enable SNMP, click Enabled . To disable SNMP, click Disabled .
142 AT-TQ2403 - Ma nagement Software - User's Guide Field Description Restrict the source of SNMP requests to only the designated hosts or subnets You can restrict the source of perm itted SNMP requests. To restrict the source of permitted S NMP requests, click Enabled .
AT-TQ2403 Ma nagement Software User's Guide 143 by send ing a trap of the event. After recei ving the event in formation, th e manager can choose what action, if any, to take. Field Description Community name for traps Enter the global community s tring associated with SNMP traps.
144 AT-TQ2403 - Ma nagement Software - User's Guide Chapter 22: Enabling the Netw ork Time Pr otocol Ser v er The Network Time Protocol (NTP) is an Internet st andard protoco l that synchronizes computer cloc k times on your network.
AT-TQ2403 Ma nagement Software User's Guide 145 Enabling or Disab ling a Network Time Protocol (NTP) Ser v er To configure your access point to use a network time pr otocol (NTP) server, first enable the use of NTP, and then select the NTP server you want to use.
146 AT-TQ2403 - Ma nagement Software - User's Guide Chapter 23: Backing up and Restoring a Configuration You can save a copy of the current s e t t i n g s o n t h e A T - T Q 2 4 0 3 M a n a g e m e n t S o f t w a r e t o a b a c k u p configuration file.
AT-TQ2403 Ma nagement Software User's Guide 147 Resetting F actor y Default Configuration If you are experiencing problems wit h the AT-TQ2403 Manageme nt Software and have tried all other troubleshooting measures, us e the Reset Configuratio n function.
148 AT-TQ2403 - Ma nagement Software - User's Guide Y ou can keep the default file name (config.cbk) or re name the backup file, but be sure to save the file with a .cbk extension. Restoring the Configuration fr om a Pre viously Sa v ed File To restore the configuration on an access point to prev iously saved settings: 1.
AT-TQ2403 Ma nagement Software User's Guide 149 Figure 57: Configuration Setting Page 2. Click the Reboot butto n. The AP will reboot. Upgrading the Firmwar e As new versions of the AT-TQ2403 Management Soft ware firmware become available, you can upgrade the firmware on your devices to take adva ntages of new features and enhanceme nts.
150 AT-TQ2403 - Ma nagement Software - User's Guide Figure 58: Upgrade Page Information about the current firmware version is di splaye d and an option to upgrade a new firmware image is provided. 2. If you know the path t o the New Firmware Image file, enter it in the New Firmware Image textbox.
AT-TQ2403 Ma nagement Software User's Guide 151 Appendix A: Security Settings on Wir eless Clients and RADIUS Ser v er Setup Typically, users wil l configure security on their wireless clients for access to many different ne tworks (access points).
152 AT-TQ2403 - Ma nagement Software - User's Guide Netw ork Infrastructure and Choosing Betw een Built-in or External Authentication Ser ver Network security configurati ons including Public Key.
AT-TQ2403 Ma nagement Software User's Guide 153 Accessing the Micr osoft Windo ws Wireless Client Security Settings Generally, on Windows XP there are two ways to get to the sec urity properties for a wireless client: 1.
154 AT-TQ2403 - Ma nagement Software - User's Guide List of available networks will ch ange depending on client locatio n. Each network (or access point) that that is detected by t h e client shows up in this list. (" Refresh " updates the list with c u rrent information .
AT-TQ2403 Ma nagement Software User's Guide 155 If you do have security configured on a client for proper ties of an unsecure networ k, the security settings actually can prevent successf ul access to the network because of t he mismatch between cli ent and access point security configurations.
156 AT-TQ2403 - Ma nagement Software - User's Guide Figure 62: Security Setting P a ge – Static WEP Setti ng Page . . . then configure WEP security on eac h client as follows.
AT-TQ2403 Ma nagement Software User's Guide 157 Field Setting Network Authentication "Open" or "Shared", depending on how you configur ed this option on the access point. Note : When the Authe ntication Algorithm on the access point is set to "Both", clients set to either Shared or Open can associate with the A P.
158 AT-TQ2403 - Ma nagement Software - User's Guide IEEE 802.1x Client Using EAP/PEAP The Built-In Authenti cation Server on the AT -TQ2403 Management Sof tware uses Protected Extensible Authentication Protocol (EAP) referred to here as "EAP/PEAP".
AT-TQ2403 Ma nagement Software User's Guide 159 Figure 65: Client Side Security Setting - IEEE802.1x Security Setting Detail.
160 AT-TQ2403 - Ma nagement Software - User's Guide 1. Configure the following set tings on the Ass ociation tab on the Network Properties dialog. Association Tab Field Setting Network Authentication Open Data Encryption WEP Note: An RC4 stream cipher is used to encrypt the fram e body and cyclic redundancy checking (CRC) of each IEEE 802.
AT-TQ2403 Ma nagement Software User's Guide 161 Logging on to the Wireless Network with an IEEE 802.1x PEAP Client IEEE 802.1x PEAP clie nts should now be able to a ssociate with the access point. Client users will be prompted for a user name and password to authenticate w ith the network.
162 AT-TQ2403 - Ma nagement Software - User's Guide Figure 66: Security Setting Page – IEEE802.1x Setting Page . . . then configure IEEE 802.1x secur ity with certificate authentication on each client as follows .
AT-TQ2403 Ma nagement Software User's Guide 163 Figure 67: Client Side Security Setting - IEEE802.1x Security Setting Detail.
164 AT-TQ2403 - Ma nagement Software - User's Guide 1. Configure the following set tings on the Ass ociation tab on the Network Properties dialog. Association Tab Field Setting Network Authentication Open Data Encryption WEP Note : An RC4 stream cipher is u sed to encrypt the frame body and cyclic redundancy checking (CRC) of each IEEE 802.
AT-TQ2403 Ma nagement Software User's Guide 165 Configuring WP A/WP A2 Enterprise (RADIUS) Security on a Client Wi-Fi Protected Access 2 (WPA2) with Remote Authentic ation Dial-In User Service (RADIUS) is an implementa tion of the Wi-Fi Alliance IEEE 8 02.
166 AT-TQ2403 - Ma nagement Software - User's Guide Figure 68: Security Setting Page – WPA Enterprise Setting Page First set up user accounts on the access point ( User Management tab)… Figure 69: User Manage ment Page . . . then configure WPA security with PEAP authentication on each client as follows.
AT-TQ2403 Ma nagement Software User's Guide 167 Figure 70: Client Side Security Setting – WPA Enterprise Setting Detail.
168 AT-TQ2403 - Ma nagement Software - User's Guide 1. Configure the following settings on the Associ ation and Authentication tabs on the Network Properties dialog. Association Tab Field Setting Network Authentication WPA Data Encryption TKIP or A E S depending on h ow th is option is configured on the access point.
AT-TQ2403 Ma nagement Software User's Guide 169 WPA/WPA2 Enterprise (RADIUS) Client Using EAP-TLS Certificate Extensible Authenticatio n Protocol (EAP) Transport Layer Security (TLS), or EAP-TLS, is an authentication protocol that supports the use of smart cards and certificates.
170 AT-TQ2403 - Ma nagement Software - User's Guide Figure 71: Security Setting Page – WPA Enterprise Setting Page . . . then configure WPA security with certifi cate authentication on each client as follows.
AT-TQ2403 Ma nagement Software User's Guide 171 Figure 72: Client Side Security Setting – WPA Setting Detail.
172 AT-TQ2403 - Ma nagement Software - User's Guide 1. Configure the following set tings on the Ass ociation tab on the Network Properties dialog. Association Tab Field Setting Network Authentication WPA Data Encryption TKIP or A E S depending on h ow th is option is configured on the access point.
AT-TQ2403 Ma nagement Software User's Guide 173 To use t his type of security, you m u st do the following: 1. Add the AT-TQ2403 Wirele ss Access Point to the list of RADIUS server clients. (There are some kind of Radius server support EAP-SIM, such as : FreeRadius) 2.
174 AT-TQ2403 - Ma nagement Software - User's Guide Figure 74: Client Side Security Setting – WPA Setting Detail Configure the following sett ings on the “Security Settings” of the Intel PROSet dialog.
AT-TQ2403 Ma nagement Software User's Guide 175 Configuring WP A/WP A2 P ersonal (PSK) Security on a Client Wi-Fi Protected Access (WPA) with Pre-Shared Key (P SK) is a Wi-F i Alliance subset of IEEE 802.
176 AT-TQ2403 - Ma nagement Software - User's Guide Association Tab Field Setting Network Authentication WPA – PSK Data Encryption TKIP or A E S depending on h ow th is option is configured on the access point.
AT-TQ2403 Ma nagement Software User's Guide 177 proced ures will vary depending on the RADIUS serv er you use and how you configure it. For this example, we use the Internet Auth entication Service that comes wi th Microsoft Windows 200 3 server.
178 AT-TQ2403 - Ma nagement Software - User's Guide Figure 77: Radius Server – In ternet Authentication Service 2. In the left panel, right clic k on " RADIUS Clients " node and choose New > Radius Client from the popup menu.
AT-TQ2403 Ma nagement Software User's Guide 179 4. For the "S hared secret" enter the RADIUS Key you provided to the access point (on the Security page). Re-type the key to confirm. Figure 79: Radius Server Setting – New Radius Client Setting 5.
180 AT-TQ2403 - Ma nagement Software - User's Guide Obtaining a TLS-EAP Cer tificate for a Clie n t Note: If you want to use IEEE 802 . 1x mode with EAP-TLS certi ficates for authentication a.
AT-TQ2403 Ma nagement Software User's Guide 181 Figure 82: Welcome Message from Certification Server 3. Click Request a certificate to get the login pro m pt for the RADIUS server. 4. Provide a valid user name and password to access the RADIUS server.
182 AT-TQ2403 - Ma nagement Software - User's Guide 6. Click Yes on the dialog displayed to install the certificate. Figure 85: User Certification Inst allation – Identifying Information 7. Click Submit to complete and click Yes to confirm the submit tal on the popup dialog.
AT-TQ2403 Ma nagement Software User's Guide 183 Figure 87: User Certification Inst allation – Certification Issued A success message is displayed indicating the certificate is now installed on t h e client.
184 AT-TQ2403 - Ma nagement Software - User's Guide In the case of FreeRADIUS se rver, the following options may be set in the users f ile to add the necessary attributes.
AT-TQ2403 Ma nagement Software User's Guide 185 Appendix B: T r oubleshooting This section provides informa tion about how to solve common pro blems you might encounter in the course of updating network c onfigurations on netw orks served by multi p le, clustered access points.
186 AT-TQ2403 - Ma nagement Software - User's Guide Reset the access point from its Administrati on UI. To do this, go to http://IPAddressOfAccessPoint , navigate to Reset Config uration , and click the Reset button. (IP addresses for APs are on the Clu ster > Access Points page for any cluster member .
AT-TQ2403 Ma nagement Software User's Guide 187 Appendix C: Command Line Interface (CLI) for AP Configuration In addition to the W eb based user interface, the AT-TQ240 3 Management Software includes a command line interface (CLI) for administering the access po int.
188 AT-TQ2403 - Ma nagement Software - User's Guide Upgrade the Firmware Keyboard Shortcuts and Tab Completion Help CLI Classes and Properties Reference Comparison of Settings Configu.
AT-TQ2403 Ma nagement Software User's Guide 189 Feature or Setting Configurable from CLI Configurable from Web UI User Accounts Yes Yes User Database Backup and Restore You cannot backup or restore a user database from the CLI. Please use the Web UI to do this as described in Backing Up and Restoring a User Database .
190 AT-TQ2403 - Ma nagement Software - User's Guide Feature or Setting Configurable from CLI Configurable from Web UI Time Protocol Yes Yes Reboot the AP Yes Yes Reset the AP to Factory Defaults .
AT-TQ2403 Ma nagement Software User's Guide 191 Software (ma nager, friend), a n d press " Enter " after each. (The password is masked, so it will not be displayed on the screen.) When the user name and password is accepted, the screen displays the AT-TQ2403 Management Software help comma nd prompt.
192 AT-TQ2403 - Ma nagement Software - User's Guide This brings up the SSH comma nd window and establish es a connection t o the access point. Th e login prompt is displayed . login as: 3. Enter the defaul t Administrator user name and password for the AT-TQ2 403 Management Software (manager, friend), and press " Enter " after each.
AT-TQ2403 Ma nagement Software User's Guide 193 CLI Command Description get The "get" command allows you to get the property values of existing instances of a class. Classes can be "named" or "unnamed". T he command syntax is: get unnamed-class [ property .
194 AT-TQ2403 - Ma nagement Software - User's Guide CLI Command Description set The "set" command allows you to set the proper ty values of existing ins tances of a class. set unnamed-class [ with qualifier-pro perty qualifier-value ...
AT-TQ2403 Ma nagement Software User's Guide 195 CLI Command Description Add The "add" command allows you to add a new in stance or group of instances of a class. add unique-named-class i nstance [ property value . .. ] add group-named-class instance [ property v alue .
196 AT-TQ2403 - Ma nagement Software - User's Guide Hitting TAB once will attem pt to complete the curr ent command. If multiple completions exist, a beep will sound and no results will be displayed. Enter TAB again to display all available completio ns.
AT-TQ2403 Ma nagement Software User's Guide 197 prop erty , " get system version ". Hit ENTER to display the output results of the command.
198 AT-TQ2403 - Ma nagement Software - User's Guide Interface Description br vw nx The bridge interface for Virtual W ireless Network (VWN) where "x" indicates the number of the VWN. wlan0 The wireless (radio) interface for the Interna l network.
AT-TQ2403 Ma nagement Software User's Guide 199 Running Configuration - The runnin g configurati on contains the settin gs with whi ch the AP is currently running.
200 AT-TQ2403 - Ma nagement Software - User's Guide Feature or Setting CLI Comm and Get the Firmware Version for the Access Point get system version Get the Location of the Access Point get clust.
AT-TQ2403 Ma nagement Software User's Guide 201 -------- ------------- ip 10.10.55. 216 mac 00:a0:c9:8c:c4:7e Get Common Information on All Interfaces for an AP The fo llowing example show s common information (including IP addresses) for all inter faces.
202 AT-TQ2403 - Ma nagement Software - User's Guide brvwn12 bridge down 00:00:00:00:0 0:00 brvwn1 bridge down 00:00:00:00:00: 00 brvwn4 bridge down 00:00:00:00:00: 00 brvwn14 bridge down 00:00:00:00:0 0:00 lo loopback up 00:00: 00:00:00:00 127.0.
AT-TQ2403 Ma nagement Software User's Guide 203 Get the Wireless Network Name (SSID) AT-TQ2403# get interface wlan0 ssid allied Set the Wireless Network Name (SSID) AT-TQ 2403# set interface wlan.
204 AT-TQ2403 - Ma nagement Software - User's Guide cluster-name vicky-cluster Determine only whether an AP is clustered or not The get cluster clustered co mmand returns a value of 0 or 1. If the com mand returns a value o f 1, then the AP is a member of a cluster.
AT-TQ2403 Ma nagement Software User's Guide 205 Feature or Setting CLI Command To set the user’s real name: set radius-user UserName RealName For example: set radius-user samantha realname &quo.
206 AT-TQ2403 - Ma nagement Software - User's Guide AT-TQ2403# set radius-user samantha password bewitched 4. Repeat this process to add some othe r users (end ora, darren, and w ally) AT-TQ2403#.
AT-TQ2403 Ma nagement Software User's Guide 207 Feature or Setting CLI Comm and Global comma nds to get details on all Basic Service Sets (BSSs). This is a useful command to use to get a comprehensive picture of how the AP is currently configured.
208 AT-TQ2403 - Ma nagement Software - User's Guide Feature or Setting CLI Comm and Enable Remote Logging and Specify the Log Relay Host for the Log As a prerequisite to remote logging, the Log Relay Host must be configured firs t as described in “ Setting Up the Log Relay Host ”.
AT-TQ2403 Ma nagement Software User's Guide 209 Get Current Settings for the Ethernet (Wired) Management Interface The following example sho ws how to use the CLI to get the Ethernet (Wired) sett ings for the Management interface for an access point.
210 AT-TQ2403 - Ma nagement Software - User's Guide Get the Network Name (SSID) for the Wi reless Internal Interface The following exampl e shows how to get the SSID of a Wireless Internal Interface. You can see from the value that is returned, tha t the SSID of this AP is "allied ".
AT-TQ2403 Ma nagement Software User's Guide 211 static-c hanne l 36 channel 36 Property Value --------------------------------- ------------------------------------------------ tx-power 100 tx-rx.
212 AT-TQ2403 - Ma nagement Software - User's Guide You can set a Severity of between 0 (most severe) and 7 (l east severe). Setting a Severit y of 7 will result in all persistent messages bein g sent to the Event Log. However, if you se t a Severity of 4, only messages with a Severity between 0 and 4 will be sent to the Ev en t Log.
AT-TQ2403 Ma nagement Software User's Guide 213 AT-TQ240 3# get log Property Value --------------------------------- - depth 128 persistence no severity 7 relay-enabled 0 relay-host relay-port 514 When you start a new AP, the Log Relay Host is di sabled .
214 AT-TQ2403 - Ma nagement Software - User's Guide AT-TQ2403# set log relay-host myserver Specify the Relay Port To specify the Relay Port for the syslog server: set log relay-port Number_Of_LogRelayP ort Where Number_Of_LogRelayPort is the po rt number fo r the Log Relay Host.
AT-TQ2403 Ma nagement Software User's Guide 215 tx- packets --------------------------------- --------------------------------------------------- -------------------------------- wlan1 00:0 e:35:.
216 AT-TQ2403 - Ma nagement Software - User's Guide ssid Service Set IDentifier (a.k.a., Network Name) supported-rates Supported rate s list type Type (AP, Ad hoc, or Other) wpa WPA security enabled To get the neighbor ing access points, type get detected-ap .
AT-TQ2403 Ma nagement Software User's Guide 217 Feature or Setting CLI Command Deny Management via WLAN Enable: set management deny-w lan-management-enabled 1 Ping Telnet HTTP SNMP TFTP Deny: set.
218 AT-TQ2403 - Ma nagement Software - User's Guide Note: For more information on DHCP and S ta tic IP conn ection ty pes, see the topic “ Understanding Dynamic and Static IP A ddressing on the AT-TQ2403 Manage ment Software ”.
AT-TQ2403 Ma nagement Software User's Guide 219 Re-Configure Static IP Addressing Values Note: This section assumes y ou have already set the AP to use Static IP Addressing and set some in itial values as described in “ Get/Change the Connection Type (DH CP or Static IP) ”.
220 AT-TQ2403 - Ma nagement Software - User's Guide 2. T u rn off Dyna mic DNS Name servers and re-check the settings: AT-TQ2403# set host dns-via-dhcp down AT-TQ2403# get host dns-via-dh cp down 3. Get the current IP addresses for the DNS Nameservers: AT-TQ240 3# get host stat ic-dns-1 10.
AT-TQ2403 Ma nagement Software User's Guide 221 Note: Before config uring this feature, make sure y ou are familiar with the names of the interfaces as described in “ Understanding Inter faces as Presented in the CLI ”.
222 AT-TQ2403 - Ma nagement Software - User's Guide Caution: You cannot use a ssh or telnet connection to configure VLANs, because you will lose network connectivity to the access point when you remove the bridge-port. Therefore, you must use a serial port connect i on to configure VLANs through the CLI.
AT-TQ2403 Ma nagement Software User's Guide 223 welcome-scre en-text Thank you for using wireless Guest Access as provided by this AT-TQ2403. Upon clicking "Acce pt", you will gain access to our wireless guest ne twork. This network allows complete acc ess to the Internet but is external to the corporate network.
224 AT-TQ2403 - Ma nagement Software - User's Guide Feature or Setting CLI Command Enable or Disable a VWN set vwn vwnx status up This will enable VWN x . set vwn vwnx status down This will disable VWN x. Where x is the VWN number. The VWN number can be between 1 and 14.
AT-TQ2403 Ma nagement Software User's Guide 225 Feature or Setting CLI Command Configure Security on the VWN Configuring security on a VWN is the same process as configuring security on an ac cess point. The same options are available. For more information, see “ Config ure Security on the VWN ”.
226 AT-TQ2403 - Ma nagement Software - User's Guide Get the SSID of a VWN In this example, su ppose you want to determine the SSID of VWN 14 on an AP. AT-TQ2403# get interface wl an0vwn14 ssid myoffice Set the SSID for a VWN The SSID for a wireless network can be any alphan umeric string, up to a maximum of 32 c haracters.
AT-TQ2403 Ma nagement Software User's Guide 227 use wlan 1vwn<x>. For infor mation on the options for configuring security on an access point, see “ Security ”.
228 AT-TQ2403 - Ma nagement Software - User's Guide suite: AT-TQ2403# set bss wlan0bssvwn7 open-system-auth entication on AT-TQ2403# set bss wlan1bssvwn7 open-system-auth entication on AT-TQ2403#.
AT-TQ2403 Ma nagement Software User's Guide 229 Feature or Setting CLI Command Get Detailed Description of Current Security get bss wlan0bssInternal detail g et interface wlan0 detail Set the Bro.
230 AT-TQ2403 - Ma nagement Software - User's Guide wpa-cipher-ccmp off wpa-allowed on wpa2-allowed on rsn-preauthent ication off Set the Broadcast SSID (Allow or Prohibit) To set the Broadcast S.
AT-TQ2403 Ma nagement Software User's Guide 231 Set Security to Static WEP 1. Set the Security Mode 2. Set the Transfer Key Index 3. Set the Key Length 4. Set the Key T ype 5. Set the WEP Keys 6. Set the Authen tication Algorithm 7. Get Current Security Sett ings After Re-Conf i guring to S tatic WEP Security Mode 1.
232 AT-TQ2403 - Ma nagement Software - User's Guide 4. Set the Key Typ e Valid values for Key Type are ASCII or Hex. The follow ing commands set the Key Type.
AT-TQ2403 Ma nagement Software User's Guide 233 Feature or Setting CLI Command To set Authentication Algorit h m to Both : set bss wlan0bssInternal open -system-authentication on set bss wlan0bss.
234 AT-TQ2403 - Ma nagement Software - User's Guide status up description Wireless - Internal mac 00:01:02:03:02:00 ip 0.0.0.0 mask static-ip 0.0.
AT-TQ2403 Ma nagement Software User's Guide 235 5. Get C urrent Security Sett ings After Re-Conf iguring to IEEE 802.1x Security Mode 1. Set the Security Mode AT-TQ 2403# set interface w l an0 security dot1x 2. Set the Authentication Server You can use the built-in authe n tication server on the access point or an e xternal RADIUS server.
236 AT-TQ2403 - Ma nagement Software - User's Guide For our example, we’ll disable RADIUS accounting since we’re us ing the built-in server : AT-TQ2403# set bss wlan0bssI nternal radius-accounting off 5. Get Current Security Settings After Re-C onfiguring to IEEE 802.
AT-TQ2403 Ma nagement Software User's Guide 237 2. Set the WPA Versions Select the WPA version based on what types of client stations you want to support. Feature or Setting CLI Comma nd To support WPA clients: WPA: If all client statio ns on the network support the origin al WPA but none supp ort the newer WPA2, then use WPA.
238 AT-TQ2403 - Ma nagement Software - User's Guide Feature or Setting CLI Command To set the cipher suite to CCMP (AES) only: CCMP (AES) - Counter mode/CBC- MAC Protocol (CCMP) is an encryption method for IEEE 802.11i that uses the Advanced Encryption Algorithm (AES).
AT-TQ2403 Ma nagement Software User's Guide 239 wpa- personal The following command gets details on how the in ternal network is configured, including details on Security.
240 AT-TQ2403 - Ma nagement Software - User's Guide 2. Set the WPA Versions Select the WPA version based on what types of client stations you want to support. Feature or Setting CLI Command To support WPA clients: WPA: If all client statio ns on the network support the original WPA but none support th e newer WPA2, then use WPA.
AT-TQ2403 Ma nagement Software User's Guide 241 Feature or Setting CLI Command To enable pre -authentication for WPA2 clients: Enable pre-a uthentication if you want WPA2 wireless clients to send pre-authenticatio n packet.
242 AT-TQ2403 - Ma nagement Software - User's Guide To set the cipher suite to Both: Both - When the authen tication algorithm is set to "Both", both TKIP and AES clie nts can associate with the access point. WPA clients must ha ve either a valid TKIP key or a valid CCMP (AES) key to be able to associate with the AP.
AT-TQ2403 Ma nagement Software User's Guide 243 Note: RADIUS accounting is not supported by the bu ilt-in server, so if you are using the built-in server make sure that RADIUS accounting is off.
244 AT-TQ2403 - Ma nagement Software - User's Guide mac-acl-name default radius-accounting on radius-ip 142.77.1.1 radius-key KeepSecret radius-port 1812 radius-accounting-port 1813 vlan-tagged-i.
AT-TQ2403 Ma nagement Software User's Guide 245 Th is table shows a quick view of Radio S ettings commands and links to detai led examples. Feature or Setting CLI Comma nd Get Radio Settings get radio get radio wlan0 get radio wlan0 detail Get IEEE 802.
246 AT-TQ2403 - Ma nagement Software - User's Guide Get Radio Channel To get the current setting for radio Channel: AT-TQ2403# get radio wlan0 ch annel 36 (The radio in this example is on Cha nnel 36.
AT-TQ2403 Ma nagement Software User's Guide 247 rate-limit-en able off rate-limit 50 rate-limit-burst 75 Get Supported Rate Set The Supported Rate Set is what the access poin t supports. The AP will automatical ly choose the most efficient rate based on factors like error rates and dist ance of client statio ns from the AP.
248 AT-TQ2403 - Ma nagement Software - User's Guide Note: To get a list of all properties you can set on t h e A P r a d i o , t y p e t h e f o l l o w i n g a t t h e CLI prompt: set radio wlan0 [Space] [Tab ] [Tab] 1. T urn the Radio On or Off 2.
AT-TQ2403 Ma nagement Software User's Guide 249 Feature or Setting CLI Command Atheros Turbo 2.4 GHz set radio wlan0 mode turbo-g Atheros Dynamic Turbo 2.4 GHz set radio wlan0 mode dynamic-tur bo-g The following comma nd sets the Wireless Mode to IEEE 802 .
250 AT-TQ2403 - Ma nagement Software - User's Guide Note that this setting for a "static -channel" only tak es effect if the Chann el Policy (channel-po licy) is set to static. The channels available will depend on the radio mode of your access point and the country in which the AP is operating.
AT-TQ2403 Ma nagement Software User's Guide 251 Radio Mode Basic Rates Supported Rates g (IEEE 802.11g) 11, 5.5, 2, 1 Mbps 54, 48, 36, 24 , 18, 12, 11, 9, 6, 5.
252 AT-TQ2403 - Ma nagement Software - User's Guide AT-TQ2403# get b asic-rate name rate ------------------------- wlan1 5.5 wlan1 2 wlan1 1 wlan0 24 wlan0 12 wlan0 6 wlan0 48 The following comma.
AT-TQ2403 Ma nagement Software User's Guide 253 mu lticast and broadcast packets b uffered at the AP will be tra n smitted immediately after the transmission of this beacon frame. T h e measurement is in beacon interva l s. Specify a DTIM period within a range of 1 - 255 beaco ns.
254 AT-TQ2403 - Ma nagement Software - User's Guide 4. Getting Curren t MAC Filtering Set tings: 5. Get the T ype of MAC Filtering List Currently Set (Accept or Deny) 6.
AT-TQ2403 Ma nagement Software User's Guide 255 AT-TQ240 3# remove mac-acl default mac 00:01:02: 03:04:04 4. Getting Current MAC Filtering Settings Get the Type of MAC Filtering List Currently Se.
256 AT-TQ2403 - Ma nagement Software - User's Guide Quality of Service Note: Before configuring thi s feature from th e CL I, make sure you are familiar with the names of the interfaces as described in “ Understanding Interfaces as Presented i n the CLI ”.
AT-TQ2403 Ma nagement Software User's Guide 257 Feature or Setting CLI Command Setting Minimum and Maximum Contention W indows (cwmin, cwmax) On the AP: set tx-queue wlan 0 with queue Q u eue_Nam.
258 AT-TQ2403 - Ma nagement Software - User's Guide Station Enhanced Distrib uted Channel Access (EDCA) Pa rameters affect traffic flowing from the client station to the access point (s tation-to-AP). Keep in mi nd that station-to-AP parameters apply only w hen WMM is enabled as described in “Enable/D isable Wi-Fi Multimedia”.
AT-TQ2403 Ma nagement Software User's Guide 259 wl an1 be 3 15 1023 0 wlan1 bk 7 15 1023 0 wlan0 vo 2 3 7 47 wlan0 vi 2 7 15 94 wlan0 be 3 15 1023 0 wlan0 bk 7 15 1023 0 Set Arbitration Interframe Spaces (AIFS) Arbitration Inter-Frame Spacing (AIFS) specifies a wait time (in milliseco nds) for data frames.
260 AT-TQ2403 - Ma nagement Software - User's Guide wlan1 vi 2 7 1 5 9 4 wlan1 be 3 15 1023 0 wlan1 bk 7 15 1023 0 wlan0 vo 14 3 7 4 7 wlan0 vi 2 7 15 94 wlan0 be 3 15 1023 0 wlan0 bk 7 15 1023 0.
AT-TQ2403 Ma nagement Software User's Guide 261 cwmax_ Value Where Queue_Name is the queue on the station to which you want the setting to apply a nd cwmin_Value and cwmax_V alue are the values (in mi lliseconds) you want to s pecify for contention back-off windows.
262 AT-TQ2403 - Ma nagement Software - User's Guide Set Transmission Opportunity Limit (t xop-limit) for WMM client stations The Transmission O pportunity Limit (txop- limit) specifies an interval of time ( i n milliseconds) wh en a WMM client station has the right to init iate transm issions on the wireless network.
AT-TQ2403 Ma nagement Software User's Guide 263 AT-TQ2403# set interface wlan0wds0 remote-mac MAC _Address_Of_Remote_AP For example: AT-TQ2403# set in terface wlan0wds0 remo te-mac 00:E0:B8: 76:1.
264 AT-TQ2403 - Ma nagement Software - User's Guide priority port-isolation ssid bss security wpa-personal-key wep-key-ascii no wep-key-length 104 wep-default-key wep-key-1 ep-key-2 wep-key-3 wep.
AT-TQ2403 Ma nagement Software User's Guide 265 4. Allow/Prohibit SNMP SET Commands set snmp rw-status up set snmp rw-status down 5. Set the read-write community name for permitted SETs set snm p rw-community <na me> 6.
266 AT-TQ2403 - Ma nagement Software - User's Guide AT-TQ2403# set ntp auto-syn c up 4. Interval to Synchronize If S ynchronize Auto matically is enabled, the device will synchronize time with the NTP server at each specified interval. This interva l is set in minutes.
AT-TQ2403 Ma nagement Software User's Guide 267 Reset the AP to Factory Defaults If you are experiencing extre me problems with the AT-TQ2403 Management Soft ware and have tried all other troubleshooting meas ures, you can reset the a ccess point.
268 AT-TQ2403 - Ma nagement Software - User's Guide 2. Set the upgrade URL from the CLI. This URL should be the URL of the upgrade file on the web server . AT-TQ2403# set firmware-upgrade upgrade-url http://10.10.28.2 49/upgrade.img 3. It is good practice to check the validity of the upgrade file.
AT-TQ2403 Ma nagement Software User's Guide 269 Action on CLI Keyboard Shortcut Move the cursor forward on the current line, one character at a time Ctrl-f Right Arrow Key Start over at a blan k command prompt (aban dons the input on the cu rrent line) Ctrl-c Remove one character on the current line.
270 AT-TQ2403 - Ma nagement Software - User's Guide add Add an instance to the running configuration factory-reset Reset the system to factory defaults get Get property values of t h e running co.
AT-TQ2403 Ma nagement Software User's Guide 271 access-poi nt Guest, VLAN and VWN settings ap-list AP list for rogue AP detection bss Basic Service Set of radios channel-planne r Channel planner settings cluster Cluste ring-based confi guration set tings config Configuration settings dhcp-client DHCP client settings dot11 IEEE 802.
272 AT-TQ2403 - Ma nagement Software - User's Guide AT-TQ2403# remove ap-list AP list for rogue AP detection basic-rate Basic rates of radios bridge-port Bridge ports of bridge interfaces bss Bas.
AT-TQ2403 Ma nagement Software User's Guide 273 Figure 90: Kick Start Search Results Dialog Box.
274 AT-TQ2403 - Ma nagement Software - User's Guide Glossar y 0-9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z 0-9 802 IE EE 802 ( IEEE S td. 802-2001) is a family of standards for peer-to- peer communication o ver a LAN. These technologies use a shared-medium, with inform ation broadcast for all st ations to receive.
AT-TQ2403 Ma nagement Software User's Guide 275 802.11a Turbo IEEE 802.11a Tur bo is a proprietary va riant of the 802.11a standard from Atheros Communications. It supports accelerated data rates ranging from 6 to 108Mbps. Atheros Turbo 5 GHz is IE EE 802.
276 AT-TQ2403 - Ma nagement Software - User's Guide 802.11i IEEE 802.11i is a comprehen sive IEEE standard for secu rity in a wireless local area network (WLAN) that describes Wi-Fi Protected A ccess 2 (WPA2). It defines enhance m ents to the MAC Layer to coun ter the some of the weaknesses of WEP .
AT-TQ2403 Ma nagement Software User's Guide 277 A A ccess Point An access point is the communication hub for the devices on a WLAN, providing a connection or br idge between wireless and wired network devices. It s upports a Wireless Networking Framework called Infrastructure Mode.
278 AT-TQ2403 - Ma nagement Software - User's Guide frequency hopping spread spectrum, d ire ct sequence spread spectrum, etc.). The optional Traffic Indicatio n Map (TIM) identifies stations , using power saving mode, that have data frames queued for them.
AT-TQ2403 Ma nagement Software User's Guide 279 trans national authorities su ch as the Federal Communications Commission (FCC), the European Telecommunicatio ns Standards Institute (ETSI), the Kore an Communications Commission, or the Telecom Engineering Center ( TELEC).
280 AT-TQ2403 - Ma nagement Software - User's Guide The Document Object Model (DO M) is an interface that al lows programs and scripts to dynamically access and update the content, struc ture, an d style of documents.
AT-TQ2403 Ma nagement Software User's Guide 281 The Extended Rate Protocol refers to the protocol used by IEEE 802.11g stations (over 20 Mbps transmission rates at 2.4GHz) when paired with Ort h ogonal Frequency Division Multiplexing (OFDM). Built into ERP and the IEEE 8 02.
282 AT-TQ2403 - Ma nagement Software - User's Guide HTTPS The Secure Hypertext Transfer Protocol (HTTPS) is the secure version of HTTP, the communication protocol of the World Wide Web. HTTPS is buil t into the browser. If you are using HTTPS you will notice a closed lock icon at the bott om corner of your browser page.
AT-TQ2403 Ma nagement Software User's Guide 283 An IP address i s partitioned into two portions: the networ k prefix and a host number on that network. A Subnet Mask is used to define the por tions. There are two special host numbers: The Network Address consists of a host number that is all zeroes (for example, 192.
284 AT-TQ2403 - Ma nagement Software - User's Guide LAN A Local Area Network (LAN) is a communications ne twork covering a limited area, for example, the computers in your home that you want to network to gether or a couple of floors in a building.
AT-TQ2403 Ma nagement Software User's Guide 285 MTU The Maxi mum Transmission Unit is the largest physica l packet size, measured in bytes, that a network can transmit. Any messages larger than the MT U are fr agmented into smaller packets before being sent.
286 AT-TQ2403 - Ma nagement Software - User's Guide with low-level protoco ls for communication and a ddressing. For example , protocols such as CSMA/CA and components like MAC addresses, and Frames are all defined and dealt with as a part of the Data-Link layer.
AT-TQ2403 Ma nagement Software User's Guide 287 The Point-to-P oint Protocol is a stan dard for transmitting network layer datagrams (IP packets) over serial point-to-point links. PPP is designed to operate both over asynchronous connectio ns and bit-oriented synchronous systems.
288 AT-TQ2403 - Ma nagement Software - User's Guide In IEEE 802.11 parlance, roaming cl ients are mobile client st ations or devices on a wireless network (WL AN) that require use of more than one Access Point (AP) as they move out of and into range of different base station service areas.
AT-TQ2403 Ma nagement Software User's Guide 289 SNM P Traps SNMP traps enable the asynchronous com munication from network devices to managed agents.
290 AT-TQ2403 - Ma nagement Software - User's Guide T TCP The Transmission Control Protocol (T CP) is built on top of Inter net Protocol (IP). It adds reliable communication (guarantees delivery .
AT-TQ2403 Ma nagement Software User's Guide 291 V VLAN A virt ual LAN (VLAN) is a software-based, logical grouping of devices o n a network that allow them to act as if they are connected to a single physical network, eve n though they may not be.
292 AT-TQ2403 - Ma nagement Software - User's Guide Stations communicate t hrough an Access Point in an I nfrastructure Mode network. A sing le access point creates an infrastructure basic service set (BSS ) whereas multiple access points are organized in an extended service set (ESS).
Un point important après l'achat de l'appareil (ou même avant l'achat) est de lire le manuel d'utilisation. Nous devons le faire pour quelques raisons simples:
Si vous n'avez pas encore acheté Allied Telesis AT-TQ2403 c'est un bon moment pour vous familiariser avec les données de base sur le produit. Consulter d'abord les pages initiales du manuel d'utilisation, que vous trouverez ci-dessus. Vous devriez y trouver les données techniques les plus importants du Allied Telesis AT-TQ2403 - de cette manière, vous pouvez vérifier si l'équipement répond à vos besoins. Explorant les pages suivantes du manuel d'utilisation Allied Telesis AT-TQ2403, vous apprendrez toutes les caractéristiques du produit et des informations sur son fonctionnement. Les informations sur le Allied Telesis AT-TQ2403 va certainement vous aider à prendre une décision concernant l'achat.
Dans une situation où vous avez déjà le Allied Telesis AT-TQ2403, mais vous avez pas encore lu le manuel d'utilisation, vous devez le faire pour les raisons décrites ci-dessus,. Vous saurez alors si vous avez correctement utilisé les fonctions disponibles, et si vous avez commis des erreurs qui peuvent réduire la durée de vie du Allied Telesis AT-TQ2403.
Cependant, l'un des rôles les plus importants pour l'utilisateur joués par les manuels d'utilisateur est d'aider à résoudre les problèmes concernant le Allied Telesis AT-TQ2403. Presque toujours, vous y trouverez Troubleshooting, soit les pannes et les défaillances les plus fréquentes de l'apparei Allied Telesis AT-TQ2403 ainsi que les instructions sur la façon de les résoudre. Même si vous ne parvenez pas à résoudre le problème, le manuel d‘utilisation va vous montrer le chemin d'une nouvelle procédure – le contact avec le centre de service à la clientèle ou le service le plus proche.