C ONTROLLER 3000
U SER M ANUAL
CONTROLLER 3000 SERIES WIRELESS CONTROLLER 3000 NETWORK CONTROLLER 3000 NETWORK CONTROLLER 3500
USER MANUAL ©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 1
OF
92
C ONTROLLER 3000
U SER M ANUAL
© 2003 - 2006, ValuePoint Networks, Inc. All written material and information in this manual is a copyright of ValuePoint Networks, Inc. No part of this work may be reproduced, stored in a retrieval system, adapted or transmitted in any form, by any means-electronic, mechanical, photographic, optical recording or otherwise, for any purpose, without prior permission from ValuePoint Networks, Inc.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 2
OF
92
C ONTROLLER 3000
ABOUT
THE
U SER M ANUAL
MANUAL
Please read this manual before working with the Controller 3000 Series (Wireless Controller 3000 or Network Controller 3000/3500).
This manual is intended to provide a basic
understanding of the Controller 3000. Although utmost care has been taken to provide all the information in this manual that is required to understand the functionality of the Controller, any additional inquiries can be mailed to:
[email protected].
USAGE
AND
FEATURES
OF THE
MANUAL
To make it easy, this manual has a simple structure and the user can easily navigate through the sections to understand the various features of the Controller 3000. The first section introduces the user to the Controller 3000, its package contents, features and precautions to be taken while using the Controller. The second section describes the Installation Requirements and steps. Follow them carefully for successful installation of the Controller 3000. The third section describes the Configuration details of the Controller 3000.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 3
OF
92
C ONTROLLER 3000
U SER M ANUAL
CONTENTS 1.
INTRODUCTION ................................................... 5
2.
INSTALLATION ................................................. 10
2.1.
3.
REQUIREMENTS ................................................. 10
CONFIGURATION ............................................... 11
3.1.
BASIC FUNCTIONS .............................................. 11
3.2.
USING
4.
THE
WEB MANAGEMENT INTERFACE .................. 13
3.2.1.
LOGGING INTO THE CONTROLLER 3000 ................................ 14
3.2.2.
EXPRESS SETUP ............................................................. 18
3.2.3.
NETWORKS
3.2.4.
SECURITY ......................................................................
34
3.2.5.
CUSTOMIZATION ..............................................................
46
3.2.6.
MANAGEMENT .................................................................
55
3.2.7.
ADVANCED.....................................................................
60
3.2.8.
SYSTEM STATUS ............................................................. 66
3.2.9.
SYSTEM TOOLS .............................................................. 76
.................................................................... 19
3.2.10.
HELP ......................................................................... 84
3.2.11.
INDEX ........................................................................ 85
TROUBLE SHOOTING .......................................... 86
4.1.
WIFI PROBLEMS (WC-3000
4.2.
TCP/IP SETTINGS PROBLEMS ................................ 88
4.3.
OTHER PROBLEMS .............................................. 89
5.
......................... 87
APPENDIX A: REGULATORY COMPLIANCE ................ 91
5.1.
6.
ONLY)
FCC REGULATORY STATEMENT ................................ 91
LIMITED WARRANTY .......................................... 92
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 4
OF
92
C ONTROLLER 3000
1.
U SER M ANUAL
INTRODUCTION
This section of the Manual gives an overview of the Controller 3000 along with the Package Contents, Features and Precautions.
Overview The Controller 3000 was developed with an aim to provide high-speed access to the Internet for Public Networks. The Controller 3000 is deployed in a wireless broadband service network, which can recognize new users on the network and redirect them to the appropriate connection. In short, the user can access the Internet without changing configuration settings or needing technical assistance no matter what their configuration.
Package Contents The package contents of the Controller 3000 are: 1. One Controller 3000/3500 2. One AC Power Adapter 3. One CD containing user’s manual & Quick Start Guide 4. One UTP Ethernet/Fast Ethernet cable (Cat.5 Twisted-pair) 5. Two removable 4dbi omni-directional antennas
Features Some key features of the Controller 3000 are:
) Advanced Local Authentication Authentication can be controlled totally within the Controller 3000 using a local user database of 512 username/password accounts. Unlike the typical primitive Local Authentication feature on most HotSpot Gateways, Controller 3000 local accounts are richly manageable by account start and end dates and access time.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 5
OF
92
C ONTROLLER 3000
U SER M ANUAL
) Auto-IP Support of Subscriber IP Settings The wireless subscriber can access the Controller with no change to his existing IP related settings, such as IP address, subnet mask, or default gateway IP address in his notebook computer. No matter what settings the subscriber has in the notebook computer, the subscriber always can access the Controller. Note: The ‘Auto-IP’ Function can only be used with TCP/IP-based Networks.
) HTTP Auto-Proxy Support of Subscriber Browser Settings Some subscribers will have a HTTP Proxy configured in their web browser, generally
as
part
of
their
corporate
configuration.
The
Controller
will
automatically detect and re-route these proxied HTTP requests to provide seamless connectivity to the subscriber.
) Bandwidth limiting to insure Quality of Service for all subscribers (3500 only)
Bandwidth
usage by any single subscriber
can
be throttled back
to the
configured bits-per-second (bps). This prevents any one user from monopolizing the network.
) Secure Management via XML and SOAP XML combined with SOAP allows rich, full featured, and secure control and monitoring of the Controller 3000.
The Controller 3000 SOAP interface works
today with Hampton Inn’s HSIA Authentication, with future releases supporting Airpath Wireless’ WIBOSS™ Control Center and more.
) SMTP R EDIRECTION Corporate and ISP mail servers often will not accept E-Mail from another network.
With the Controller 3000, subscriber’s outgoing SMTP server requests
can be redirected to a SMTP server specified by administrator, so the subscriber can send out their email without changing the E-Mail configuration in their notebook computer.
) Café Account™ Customers can be given free access to the Network for a defined period, after which they would have to purchase more time to continue to browse or access the network from their laptop.
This is ideal to allow free “use but don’t abuse”
access to draw customers into the venue.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 6
OF
92
C ONTROLLER 3000
U SER M ANUAL
) Remote Configuration The Controller 3000 is easy for administrators to manage through the Webbased interface. The Web-based management is client-independent and is done by securely authenticating the administrator over SSL.
) Custom Branding of Subscriber Experience The
venue
owner
or
system
integrator
can
customize
the
branding
and
messaging for each HotSpot. Login pages, messages, and advertising can all be configured to match the Café, Hotel, or Airport experience.
) “Captured Portal” Home Page Redirection The Controller 3000 allows the venue owner to redirect subscribers to a corporate web site or custom portal, where branding, login methodology, billing, terms of service, and more can be controlled.
) Authenticated User Pass-through After their initial login to validate their account, subscribers can be given access to the network without needing to Login each time to their account. This means fewer lost and forgotten passwords and account names.
) Walled Garden A walled garden provides pages or web sites that can be accessed by subscribers without requiring authentication. The Controller allows up to 266 destination IP addresses and URLs.
) VPN (Virtual Private Network) Pass-through The Controller 3000 allows subscribers to access their existing VPN network at home or at the office. Unlike most public access gateways, the Controller allows all VPN connections through NAT and multiple connections to the same VPN server from a single venue.
) Login Pass-through by IP or MAC Address The Controller 3000 allows a list of client computers to access the Internet without requiring authentication.
The Controller allows up to 512 registered
MAC addresses.
) Secure HTML Login Page (SSL) ©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 7
OF
92
C ONTROLLER 3000
U SER M ANUAL
Login Page utilizes SSL to protect username and password during User login.
) Hardware Heartbeat Monitor This feature enables the Controller to continue functioning by resetting the system if the device experiences any problems due to unusual network activity (e.g. subscriber worms, viruses, or Denial of Service Attacks).
) Sophisticated Syslog Monitoring A sophisticated System Log (Syslog) server is built-in to log events and enable automated monitoring.
The System logs can be stored internally or events can
be broadcast to a local or remote Syslog Client.
) RADIUS Authentication Subscriber authentication on the Controller 3000 can be configured for the industry standard RADIUS AAA.
RADIUS allows you to control multiple sites
from a single NOC, or purchase authentication services from a third party billing provider.
) Subscriber VLAN Subscribers and local network machines can be isolated from one another using Subscriber VLAN. This prevents users from accessing or molesting each other on the public network, or accessing enterprise hardware belonging to the venue.
) Time based authentication list upload Security
and
Pass-through
information
for
the
entire
enterprise
can
centralized and updated in each controller automatically on a schedule.
be This
allows for easy synchronization of both authenticated and “blacklisted” user information between multiple venues.
) Terms of Service Based Authentication The Controller can be configured to enforce agreement to a customizable and branded terms of service page before subscribers can access the service.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 8
OF
92
C ONTROLLER 3000
U SER M ANUAL
) Public Static IP Pass-through Multiple
Public
Static
IP
addresses
can
be
provisioned
and
distributed
automatically to subscribers. While preserving the authentication, security, and branding features of the venue, these subscribers will have full access to their public IP for more sophisticated applications like VPN.
Precautions Please carefully read the following precautions before using the Controller 3000:
) Do not remove or open the enclosure. You could damage the Controller or suffer injury if you tamper with the Controller hardware.
) The Controller 3000 enclosure is not water resistant.
Avoid deploying the
Controller where it might get wet.
) Only connect the supplied AC power adapter, or an adapter of the exact same configuration and power characteristics. Using the wrong adapter could cause damage to the Controller or a dangerous electrical shock to the user.
) The Controller 3000 enclosure is not heat resistant. Do not deploy the Controller 3000 in direct sunlight or in proximity to another heat source.
) Please deploy the Controller 3000 where it is well ventilated.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 9
OF
92
C ONTROLLER 3000
2.
U SER M ANUAL
INSTALLATION
This section of the Manual gives information regarding the requirements and installation procedures for a successful installation of the Controller 3000.
2.1. REQUIREMENTS Check the following requirements installing the Controller 3000. 1. SYSTEM REQUIREMENTS System requirements: Management System:
PC with Ethernet or Wireless 802.11b network card
ISP Connection:
xDSL modem, Cable modem, or T1 Router.
Management Software:
Web Browser (Internet Explorer 6.0+ or Safari 2.01+ only)
Others:
Network Cable with a RJ-45 connector
2 . WAN N E T W O R K R E Q U I R E M E N T S Find out from your ISP whether the Controller will use a static or dynamic IP address. The most common configuration is DHCP, which assigns the IP addresses dynamically. If you are using a static IP address, you will need to get the full configuration from your ISP. Dynamic IP
Set Controller to DHCP Client
Static IP
Controller IP address Controller subnet mask Default gateway IP address Primary/Secondary DNS Server IP addresses
PPPoE
User name from your ISP Password from your ISP
Note: 1. The Controller’s default LAN IP address setting is ‘192.168.1.1’. 2. The Controller’s default LAN subnet mask setting is ‘255.255.255.0’.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 10
OF
92
C ONTROLLER 3000
3.
U SER M ANUAL
CONFIGURATION
This section of the Manual will give you information regarding access, login and usage of all the features of the Controller 3000.
3.1. BASIC FUNCTIONS The screen below shows the type of options the user will come across frequently while configuring the system. Description about the use of each part is available in next section along with the instructions on its usage. Rad io B u tto ns
D ro p d o w n L is t Box
T ext Box
Screen 1 Basic functionality
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
H elp
Command Buttons
P AGE 11
OF
92
C ONTROLLER 3000
U SER M ANUAL
1 . C H A N G I N G GU I S E T T I N G S ENTERING D AT A
IN A
TEXT BOX
To enter a data value in a text box click inside the text box and start typing. If the text box already contains some value, click at the end of the written text value and delete it with the backspace key. If the text box is grayed-out, this means the text is not editable. SELECTING
A
VALUE
FROM
DROPDOWN LIST
BOX
To select a value from a list first click on the arrow that is found on the right side of this list box and then select a value desired from the displayed list. R ADIO BUTTONS To select a radio button simply click on the desired radio button.
COMM AND BUTTONS To perform the actions as captioned on the button simply click on the button. For example: In the screen above, to apply the changes, simply click Apply to implement the changes made.
HELP To view the help for some menus, click on the Help icon displayed on the right top pane of the menu.
2. RESETTING
TO
F ACTORY DEFAULTS
SOFT RESET Connect to the Controller WEB GUI and navigate to System Tools – Factory Settings and select Reset Factory Defaults. H ARD RESET Once the unit has booted and the “System” light is flashing or solid, press the button labeled “Default” on the face of the Wireless Controller for ten seconds. The Controller 3500 only has one “Reset” button, so hold that button for ten seconds to reset the 3500. When the system light goes out this means that the Controller is rebooting. After rebooting, the Controller will be accessible at the default LAN IP Address of 192.168.1.1.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 12
OF
92
C ONTROLLER 3000
3.2. USING
THE
U SER M ANUAL
WEB MANAGEMENT INTERFACE
To access the Controller 3000 and utilize its menus enter the WAN or LAN IP address in the browser and press ‘Enter’.
Screen 2 Controller Welcome Screen
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 13
OF
92
C ONTROLLER 3000
3.2.1.
U SER M ANUAL
L O G G I N G I N T O T H E C O N T R O L L E R 3000
On performing the above steps, the Controller 3000 Home Page will appear on the screen as shown below. Through this Home page, you can access the Controller 3000 by providing the correct Login Name and Password. The password protection insures only authorized users access the Controller.
We recommend that you change the default username/password.
You can restore the factory default password with a hard reset if you forget your password.
Login Name
Password
Screen 3 Login Screen Login
Enter a valid Login Name here. The default Login is “root”.
Password
Enter the password in this field. The characters keyed-in will be displayed as asterisks (*) to maintain the secrecy of the password. The password entered in this field is specific to the user name entered above. The default password is “root”.
Get Started
After entering the user name and password, click on this button. The user name and password will be validated. If a correct user name and password has been supplied you will gain access to the Controller; otherwise an error message will be displayed.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 14
OF
92
C ONTROLLER 3000
U SER M ANUAL
After successful login, the Controller displays the following screen, which gives the Controller status and allows the user to navigate to different menus of the Controller 3000. Navigation Menu to submenus of the selected Menu
Configuration Menus
Screen 4 Home Page Configuration Menus
The Controller 3000 has ten menus. The first eight of the menus deal with configuration of the Controller settings. They are, 1. Express Setup 2. Networks 3. Security 4. Customization
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 15
OF
92
C ONTROLLER 3000
U SER M ANUAL 5. Management 6. Advanced 7. System Status 8. System Tools 9. Help 10. Index These menus allow the user to configure the settings. To access the menu, click on the respective menu button. The ninth menu is Help. It contains Frequently Asked Questions to help the user to understand the system better. The tenth menu is the index. This menu contains quick links to other menus and sub-menus, to navigate through the interface quickly. The final option is Apply Changes/Restart. Click this from any menu to implement the changes made to the settings. This restarts the controller immediately.
You must select OK on
each page that you wish to configure.
Navigation Menu
The Navigation Menu is available on the top pane of every menu as tabs for accessing different sub-menus of the respective menu. To access the sub-menus, click on the respective sub-menu name.
Status Bar
The Status Bar below the screen will indicate the actions performed.
Cancel and OK The command buttons Cancel and OK. can be seen in many menus of the Controller. In all the menus, the functionality of these commands is the same.
Cancel – Click this button to cancel any changes on the current page.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 16
OF
92
C ONTROLLER 3000
U SER M ANUAL
OK – Clicking this button causes the settings configured by the user to be saved. New settings may take effect immediately or on the next reboot.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 17
OF
92
C ONTROLLER 3000
3.2.2.
U SER M ANUAL
EXPRESS SETUP
This menu allows the user to configure the basic settings for accessing the Internet.
Screen 5 Express Setup WAN Port Mode In this section, select DHCP Client, Static IP or PPPoE setting options. 1. To connect via a Cable Modem or Local LAN select DHCP Client setting. This configures the device to obtain the IP address and other TCP/IP settings from your ISP.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 18
OF
92
C ONTROLLER 3000
U SER M ANUAL
2. To use a static IP address assigned by your ISP, or use local LAN settings, select Static IP and perform the following steps: 1. Type the IP Address provided by your ISP. 2. Type the Subnet Mask Address provided by your ISP. 3. Type the Gateway Address provided by your ISP. 4. Type
the
Primary
and
Secondary
DNS
server
addresses provided by your ISP. 3. To use PPPoE protocol to connect to your ISP, select PPPoE and perform the following steps: 1. Type the User Name for PPPoE protocol to connect the ISP. 2. Type the correct Password for the above User Name. 3. Select either Enable to activate Auto Connection or Disable to deactivate the Auto connection option. 4. Select the Number of Minutes for Auto Disconnection from the drop-down list box. Wireless Type the value for ESSID. Also, select the Channel for the wireless network from the drop down list box here. The values of the drop down are from 1 to 11. The Express Setup Page has a command button to apply all these settings and restart the Controller. Click Apply & Restart to implement the settings.
3.2.3.
NETWORKS
The Networks menu has four sub-menu tabs, 1. System 2. WAN/LAN 3. Server 4. Wireless Details of the above menus are as follows,
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 19
OF
92
C ONTROLLER 3000
U SER M ANUAL
1. SYSTEM This section of the Controller allows you to configure the System Settings. The following screen shows the System Settings menu.
Screen 6 System Settings
Management IP address Filter Select either Any or Specify radio buttons, to type the access IP address. By default, Any IP Address will be selected. The typed IP Addresses should not exceed 15 characters. When Specify is selected, only addresses within that range will be able to manage the Controller. Do a hard reset to factory defaults if you forget what addresses are allowed.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 20
OF
92
C ONTROLLER 3000
U SER M ANUAL
NAS ID The editable text box is the NAS ID of the Controller. This value will be sent in RADIUS Requests from the Controller to the RADIUS Server.
If Syslog is enabled, the NAS ID is
sent as part of the syslog messages. LAN IP settings Auto IP
In this section, select either Enable or Disable radio button to enable or disable the Auto IP subscriber address support. AutoIP will allow users with Static IP addresses to connect to the internet normally without changing their settings.
These
subscribers’ connections may be slower than DHCP subscribers’ due to the translation process to and from their static IP address by the Controller for each packet. Subscriber VLAN Security (requires Auto-IP enabled)
When
Subscriber
VLAN
Security and Auto-IP are enabled the Controller prevents subscribers and other machines on the network from being able to access each other or share resources, using Microsoft Networking for example. You will not be able to access or manage local machines or access points on the LAN with Subscriber VLAN Security enabled. Subscriber VLAN Security is also effective at blocking subscriber-to-subscriber traffic not connected directly to the Controller with some limitations: 1. LAN
Broadcast
traffic
is
not
blocked,
so
some
subscribers may see other computers listed under “Computers Near Me” in Windows.
These subscribers
will not be able to share files, ping, or access each other’s computers, however. 2. The first “PING” attempt between subscribers may succeed if the Controller has not previously seen traffic from that subscriber. Subsequent PING or other packets will be blocked.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 21
OF
92
C ONTROLLER 3000
U SER M ANUAL 3. Subscriber VLAN Security may not be effective across a switch or router.
In this case, direct packets between
subscribers cannot be detected by the Controller. If this switch-based
configuration
cannot
be
avoided,
ValuePoint recommends turning on Subscriber VLAN Security in the Access Points. This feature is available in the SuperAP 500 and 510g products from ValuePoint. Please contact your Access Point vendor with questions about Subscriber VLAN Security in other products. ICMP Ping Response
In this section, select either Enable or Disable radio button to enable or disable the user’s access to ping the device. By default, the Controller sets this option to Enable.
Multicast Packets
In this section, select either Enable or Disable radio button to enable or disable the Multicast Packets. By default, the Controller sets the Multicast Pass-through as Disable.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 22
OF
92
C ONTROLLER 3000 Calendar(UTC)
U SER M ANUAL This section has drop-down boxes for Date and Time. Select the Date and Time in UTC, from the drop down list boxes as shown in the screen 5. In addition, the user can fetch the system date and time from the computer by clicking on Get from my Computer. The selected date and time range should be between 23:59:59
1/1/2002
to
12/31/2035
and
00:00:00
to
respectively. Date and Time are stored in the
controller as Coordinated Universal Time (UTC/GMT). You must click OK on this page to set the internal clock.
Note: Use the ‘Get from my Computer’ feature the first time you configure the Controller to ensure that the correct local time is set. Scheduled Reboot
You can configure the Controller to reset automatically every day or X days at XX:XX time. Keep in mind the that time is UTC/GMT time, so if you want to reboot at 4AM local time make the conversion. This can be useful if you find you are having to reset the Controller at a particular site due to unusual subscriber activity.
Idle Time Out(Mins)
In this section, select a time out period for inactive subscribers to be disconnected.
Enter ‘0’ for no timeout of subscribers.
Subscribers who have an active ‘logout’ pop-up window open will not be timed out.
Note: Setting Idle Timeout to ‘0’ is not recommended for public networks. subscribers manually log out, their sessions will never be terminated.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
Unless these
P AGE 23
OF
92
C ONTROLLER 3000
U SER M ANUAL
3 . WAN /LAN This Menu allows you to configure the WAN/LAN settings of the Controller 3000.
Screen 7 WAN/LAN Setting Device IP (LAN IP) Setting Type the IP Address and Subnet Mask of your Controller 3000 here. By default, the Controller sets the value 192.168.1.1 as IP Address and 255.255.255.0 as Subnet Mask. WAN Port Mode Select among DHCP Client, Static IP or PPPoE Port Mode options here to indicate the WAN Port Mode. By default, the Controller selects DHCP Client as the port mode. 1. To connect via a Cable Modem and LAN with DHCP select DHCP Client Port Mode. 2. To use a static IP address assigned by your ISP or static WAN address select Static IP and perform the following steps:
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 24
OF
92
C ONTROLLER 3000
U SER M ANUAL 1. Enter the Static IP Address of the Controller. 2. Enter the Subnet Mask for the Controller. 3. Enter the Default Gateway Address. 4. Enter the Primary DNS Number. 5. Optionally, enter the Secondary DNS Number. 3. To use PPPoE protocol to connect to the ISP select PPPoE Port Mode and perform the following steps: 1. Enter the User Name for PPPoE protocol provided by the ISP. 2. Enter the correct Password. 3. Select either Enable to activate Auto Connection or Disable to deactivate the Auto connection option. When Auto Connection is enabled, the Controller will establish a PPPoE session automatically, regardless of subscriber activity. By default, the Controller sets Enabled as the value for Auto Connection. 4. Select the Auto Disconnection duration in minutes from the drop down list here. Auto Disconnection will close the PPPoE session if there is no user activity.
By
default, the Controller selects 5 Minutes as duration. Subscriber Bandwidth Limit(3500 only) Select Enable and Limit Per Subscriber to apply a bandwidth limit to each subscribers connection. WAN MAC Address
Select either Default WAN MAC Address or Change to option and type the respective WAN MAC Address of the network interface card here. By default, the Controller selects Default as the value. This feature can be used if your ISP requires a particular MAC Address to provide service.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 25
OF
92
C ONTROLLER 3000
U SER M ANUAL
4. SERVER This menu allows you to configure the various Server Settings of the Controller 3000.
Screen 8 Server Configuration DHCP Server Select the DHCP Server type you want by selecting the respective radio button here. The available options are DHCP Disable, DHCP Relay and DHCP Server. The default selection is DHCP Server. 1. To disable DHCP server, select DHCP Disable option.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 26
OF
92
C ONTROLLER 3000
U SER M ANUAL 2. To enable DHCP Relay, select the DHCP Relay option. This will allow the Controller to relay DHCP requests to another DHCP server. The DHCP addresses assigned by that Server will be relayed to subscribers.
You will need to configure
the following settings: A. Type the DHCP Relay IP Address in the text box. 3. To enable the DHCP Server on the Controller, select the DHCP Server option. You will need to configure the following settings: A. Type the DHCP Pool Start IP Address in the provided text box labeled DHCP Pool Start IP Address. B. Type the DHCP Pool Size in the text box labeled DHCP Pool Size. The size should be between 1 and 253. By default, the DHCP pool is 100 . C. Type the Lease Duration in minutes in the text box labeled as Lease Duration Minutes. By default, the lease duration is 8440 .
Note: You will need to match the IP Pool settings with the Controller LAN settings to insure that DHCP subscribers can connect successfully. You will receive a warning if the settings do not match, but the settings are not changed automatically. HTTP Auto-Proxy In this section, you can enable HTTP Auto-Proxy. HTTP Auto-Proxy will detect HTTP Proxy requests from the browser on the LAN and redirect them to a valid Internet connection. Subscribers may find their connection to be slower using Auto-Proxy, so disabling an invalid proxy setting is the best subscriber configuration. HTTP Auto-Proxy Ports
Type the HTTP Proxy Server Ports here. The HTTP Proxy will redirect outgoing connections on these ports.
By default, the
server ports are 8000, 8001, and 8080 . These are the typical HTTP Proxy ports used by subscribers. SMTP Redirect Enable or Disable the SMTP Server redirect. SMTP redirect sends subscriber email to a SMTP server that you designate. This will allow subscribers who are away from their normal
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 27
OF
92
C ONTROLLER 3000
U SER M ANUAL
corporate or home network to send mail successfully. The redirect process is transparent, so subscribers do not notice any difference. By default, SMTP redirect is Disabled. SMTP IP Address or Domain Name
Provide the SMTP Server address that you wish
to direct email traffic to here. Web Server HTTP Server
Type the Web Server Port here. By default, the port number is 80 .
SSL Security
Check the SSL Security check box to enable the SSL Security feature.
Enabling SSL will cause WEB GUI and Local Login
pages to be encrypted, but may slow down access to those pages. Authenticated users will not see any difference in page load times. By default, SSL Security is not enabled.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 28
OF
92
C ONTROLLER 3000
U SER M ANUAL
5 . W I R E L E S S (3 000 O N L Y ) This menu allows you to configure wireless settings on the Wireless Controller 3000.
Screen 9 Wireless
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 29
OF
92
C ONTROLLER 3000 Enable/Disable
U SER M ANUAL The Wireless Interface of the Wireless Controller 3000 can be enabled or disabled. The Network Controller 3000 will always show disabled.
Disabling the wireless LAN will improve the
performance of the WC-3000, and it is a good idea to disable the wireless when upgrading the firmware to prevent any unexpected
subscriber
activity
from
interfering
with
the
upgrade process. ESSID and Channel SSID Broadcast
Select Enable and Disable for SSID broadcast. By default, SSID Broadcast is enabled.
When SSID is disabled subscribers will
not see the network when they scan the area. Subscribers can still enter the network name manually into their WiFi client software. Transmission Rates
Select the maximum Transmission Rate. Setting a lower transmission rates can reduce administrative overhead and prevent users with a stronger signal from monopolizing the network.
ESSID
Enter the Service Set Identifier here. By default, the SSID is set to ValuePoint .
The SSID is the network name that the
subscriber will see when they scan the area for wireless networks. The SSID consists of alphanumeric characters with no spaces. Channel
Select the WiFi radio channel from this select box. You can select a value between 1 and 11 . In 802.11b channels 1, 6, 11 are the non-overlapping channels.
WiFi signals separated by
fewer than 4 channels will cause interference and increased ‘noise’ with each other, lowering connection speed and quality.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 30
OF
92
C ONTROLLER 3000
U SER M ANUAL
Security/802.1x Security Mode
Select the Wireless Security Mode from the drop down list here. Wireless Security protects subscriber data as it is transmitted to and from the Controller WLAN interface. The wireless security options are Open System 64-Bit WEP 128-Bit WEP 802 .1x EAP –MD5 No Encryption 802 .1x EAP –MD5 + 64-Bit WEP 802 .1x EAP –MD5 + 128 Bit WEP 802 .1x EAP –TLS No Encryption 802 .1x EAP –TLS + 64-Bit Key 802 .1x EAP –TLS + 128Bit Key
1. To disable Wireless Security select Open System. This is the default option. 2. To enable Wired Equivalent Privacy (WEP) select 64-Bit WEP or 128-bit WEP.
You can provide up to 4 hexadecimal
(characters 0-9,A-F) encryption keys.
Only one key can be
selected at a time. All clients must have the exact same key as the current Controller key (1-4) to connect to the Controller Radio.
The
default
64/128bit
WEP
key
values
are
1111111111 and 11111111111111111111111111. 3. In order to use 802.1x you need to configure both the individual subscriber’s 802.1x client and an 802.1x server. Please see the documentation for your 802.1x client and server for information on establishing an 802.1x session.
There are
several 802.1x configurations you can use depending on your client and server: a. MD5 / TLS. MD5 and TLS are two methods of securing the authentication process.
You will need to configure this
according to your 802.1x server and client settings. b. WEP / Dynamic Keys.
You can use standard WEP to
provide wireless security with matching keys on the
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 31
OF
92
C ONTROLLER 3000
U SER M ANUAL subscriber and Controller.
Most 802.1x servers can also
provide a rotating set of WEP keys, which prevents exploitation of some known WEP weaknesses.
If your
802.1x server supports this key rotation, select Key Rotation and the Re-keying Period in seconds.
Note: 802.1x will not work without extra software configured on each and every subscriber and an 802.1x server in the back office. The Controller just facilitates this connection; it does not provide any 802.1x services by itself.
Others Antenna Selection
This section has two radio buttons: Default Antenna and Diversity Antenna.
By default the Controller is set to
Diversity Antenna. Diversity antenna may improve detection of weak signals by allowing the Controller to compare the signal from both antennas. If you are going to use a single external antenna, select Default Antenna and connect your antenna to the connector labeled ‘Tx’. DTIM Interval
Type the DTIM Interval here. The Interval should be between 1 and 255 . By default, the value is 3 .
This setting, a multiple of the beacon period, determines how often the beacon contains a Delivery Traffic Indication Message (DTIM). The DTIM tells power-saving client devices that a packet is waiting for them. Beacon Interval
The Beacon Interval should be between 1 and 1000 . Beacon Interval is the frequency of the WiFi Beacon broadcast that informs
wireless
subscribers
of
the
SSID
and
other
administrative information. Fragmentation Threshold Type the Fragmentation Threshold here. The Threshold should be between 256 and 2346 and only even numbers can be entered here. By default, the fragmentation threshold is 2346 .
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 32
OF
92
C ONTROLLER 3000
U SER M ANUAL This setting determines the size at which the packets are fragmented. You can use a lower setting in areas where communication is poor or where there is a great deal of radio interference.
RTS Threshold
Type the RTS Threshold here. The Threshold should be between 256 and 2437 . By default, the RTS threshold is 2432 .
This setting determines the packet size at which the Controller 3000 issues a request to send (RTS) before sending the packet. A low RTS Threshold setting can be useful in areas where many client devices are associating with the Controller 3000, or in areas where the clients are far apart and can detect only the Controller 3000 and not other wireless subscribers. Default Default Values for wireless settings are restored.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 33
OF
92
C ONTROLLER 3000
3.2.4.
U SER M ANUAL
SECURITY
1. AUTHENTICATION This menu allows you to configure the Authentication Settings of the Controller 3000.
Screen 10 Authentication Configuration The Authentication Configuration has five radio button options: RADIUS Server, Local Authentication, Hampton Inn HSIA Authentication, Terms of Service and No Authentication. By default, Local Authentication is enabled.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 34
OF
92
C ONTROLLER 3000
U SER M ANUAL
RADIUS Server Remote Authentication Dial-In User Service (RADIUS) is an authentication and accounting service used by many service providers to track and control subscriber access.
The
Controller includes a RADIUS Client that can be configured to make RADIUS requests when subscribers authenticate.
RADIUS Authentication requires a RADIUS Server in the back
office in addition to the RADIUS Client. If the RADIUS Server option is selected the RADIUS specific settings are displayed:
Selecting RADIUS Server option Window
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 35
OF
92
C ONTROLLER 3000
U SER M ANUAL
The configurable options on this menu are:
Authentication Type Primary RADIUS Server
The Primary RADIUS Server provides the authentication and accounting for subscribers.
When the subscriber enters their
username and password, these parameters and other are sent to the RADIUS Server. The RADIUS server then responds back to the Controller with an ‘accept’ or ‘reject’ message. Controller RADIUS.
enforces
the
authentication
decision
The
made
by
To configure the Primary RADIUS Server configure
these values: 1. Primary RADIUS Server IP Address. 2. Primary RADIUS Server Authentication Port Number. By default, the value is 1812. This is the typical Authentication port, but your server may be different. 3. Primary
RADIUS
Server
Accounting
Port
Number.
By
default, the value is 1813 . This is the typical Accounting port, but your server may be different. 4. Primary RADIUS Server Shared Secret Key. The Shared Secret Key should not exceed 15 characters. The same key must be entered into your RADIUS server. Note: Your RADIUS Server may require additional information beyond the Shared Secret to accept RADIUS requests from the Controller. Common requirements are the NAS ID and IP Address of the RADIUS Client. Please consult your RADIUS Server documentation for more information on connecting RADIUS Clients. Secondary RADIUS Server
The
secondary
RADIUS
Server
has
the
same
configuration options. This RADIUS Server will be contacted if the Primary fails to respond. 1. Secondary RADIUS Server IP Address. 2. Secondary RADIUS Server Authentication Port Number. 3. Secondary RADIUS Server Accounting Port Number. 4. Secondary RADIUS Server Shared Secret Key.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 36
OF
92
C ONTROLLER 3000
U SER M ANUAL
Retry Times when Primary Fails Select the Number of Retries the Controller should make when the RADIUS Server fails from the drop down list box. After the selected retries on the Primary Server the Controller fails over to the Secondary Server. The Controller aborts the authentication request and returns an error after all retries fail against the secondary RADIUS server. Accounting Service
You can Enable or Disable Accounting Service here. Turning on accounting causes the Controller to send a summary of subscriber activity to the RADIUS server.
Authentication Method
Select the Authentication Method for RADIUS from the drop down list box here. The values of the drop down are PAP or CHAP .
PAP and CHAP are two security methods used by
RADIUS. Please consult your RADIUS Server documentation for details on which method your Server requires. Local Authentication If Local Authentication is selected, the menu displays three command buttons. They are Add/Modify User, Auto Create User and Set Auto Default.
Selecting Local Authentication option Window
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 37
OF
92
C ONTROLLER 3000 Add/Modify User
U SER M ANUAL Click Add/Modify User to add, delete and modify a user for local authentication. A pop-up window displays the names of all the authenticated persons. The window allows you to add, delete, suspend/resume, or modify the local users. Suspended users will not be able to log in until their account is resumed.
Popup window of Add/Modify User command Auto Create User
Click Auto Create User to create usernames and passwords automatically. These accounts will have the properties selected under Set Auto Defaults.
Indicate the number users to be
created by selecting a value from the drop-down list box that is found near to this command button.
By default the selected
value is 1 . When the user clicks Auto Create User a pop-up window shows the automatically generated usernames and passwords.
You can print using the regular browser printing
options from this page.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 38
OF
92
C ONTROLLER 3000
U SER M ANUAL
Popup window of Auto Create User command Set Auto Default
Click Set Auto Default to set default values to this section. Clicking this command will display a pop-up window with various authentication settings. Use these settings to define the kind of users and time limits to be automatically created. Click Apply to implement these settings. It may take a little while to generate a large number of accounts.
Popup window of Set Auto Default User command
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 39
OF
92
C ONTROLLER 3000
U SER M ANUAL
Hampton Inn HSIA Authentication To use the Hampton Inn HSIA Central Authentication Server (CAS), select Hampton Inn HSIA Authentication. This will open a dropdown with Hampton specific configurations. The default values are for testing only, please contact Hampton Inn for valid configuration settings for the hotel property you are installing.
Selecting Hampton Inn HSIA Authentication option Window Central Authentication Server
Enter the correct Central Authentication Server (CAS)
URL for the Hampton portal page. You will need to provide the correct CAS for subscriber authentication.
You must get the
Hampton CAS information from Hampton Inn Corporate Office or the Hampton Inn site owner. Property Code
Enter the Property Code provided by Hampton Inn for the property you are installing.
Property Zip
Enter the Property Zip Code.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 40
OF
92
C ONTROLLER 3000 Gateway IP
U SER M ANUAL In most cases this field is blank. Normally the Public IP of the Controller will be provided to the CAS automatically.
If the
Controller is behind a NAT firewall, you can use this field to override this and provide the IP Address of the Firewall here. Configure the NAT Firewall on your router to forward port 1111 to the Controller to enable Hampton Inn HSIA Authentication through NAT. Terms of Service To use the Terms of Service authentication, select this option. Subscribers will not be able to access the WAN until they click on the “I Accept” button on the terms of service page. You will need to upload an XML text file that contains the text of your terms of service and the post-authentication redirect.
You can upload this XML file under System Tools –
Maintenance – Terms of Service. You can also download the current terms of service file to use as a template. Configuring the 3000terms.xml file Within the 3000terms.xml file you can configure the following fields. To configure the fields just insert your text between the two tags <> >. Do not change the text within the < >. <window_name> This field determines the title of the Window that appears in the browser. <page_title> This field determines the title header that appears at the top of the terms of service page. <para1>
This field contains the first paragraph of the terms of service. Each of 10 paragraphs can be up to 1500 characters. You can add additional paragraphs under <para2>,<para3>, etc. Any Linefeed or Carriage Returns in the paragraph will be removed. If you need to format the text within a paragraph into blocks or tables use an externally hosted Terms of Service page.
The
internal terms of service only supports 10 paragraphs of plain text.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 41
OF
92
C ONTROLLER 3000
U SER M ANUAL
This field determines the web URL, if any, that the subscriber is redirected to after agreeing to the terms of service. If this field is blank the subscriber will be redirected as configured under Customization – Login – Default PostAuthentication Default.
This field determines the label on the button that the subscriber must click. Escaping XML Control Characters Some common characters are also control characters in XML, so you must “escape” or replace them with a special code if you want them to appear in your terms of service text. These characters are: Character
Escape Code
quote (")
"
Apostrophe (')
'
Ampersand (&)
&
less than (<)
<
greater than (>)
>
Example: If you wanted the text I agree to these "terms of service" You would use the tag: <para1>I agree to these "terms of service"
Note: The Terms of Service text is a legal agreement that is specific to your service. For this reason, ValuePoint Networks can not provide a standard or boilerplate Terms of Service. No Authentication If you do not wish to control subscriber access to Internet, select No Authentication. In this configuration, subscribers will still need to initiate a HTTP request by opening their web browser in order to be passed through the firewall.
This process is transparent to the
subscriber. If subscribers ping or send email before requesting a web page these requests
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 42
OF
92
C ONTROLLER 3000
U SER M ANUAL
will not go through. In effect, these subscribers are still authenticated for the purposes of logging and tracking usage, blocking banned users, and so forth.
Note: If you need some users to be connected without opening a web browser, or have equipment like security cameras which must remain connected, use the IP Address Passthrough table. These IP Addresses are always connected and not affected by any security setting. 2 . P AS S - T H R O U G H These settings allow you to define the pass-through subscribers and destinations when using Authentication.
Screen 11 Pass-through Menu
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 43
OF
92
C ONTROLLER 3000
U SER M ANUAL
There are two options for configuring Pass-through settings in the Controller.
If
you only need a limited number of entries, up to 48 per option, you can configure these from the GUI directly. If you need to configure more you must use the passthrough XML file 3000pass.xml. The XML file is uploaded through System Tools Maintenance – Pass-through.
It is only necessary to add subscribers to one
pass-through table, depending on what kind of connection they require. Pass-through Source IP
Type the Subscriber’s pass-through IP Address here. Subscribers or devices with these addresses will be permanently connected. These IP Addresses are not affected by the black list, redirection, or any other connection limitation. You can use this table for equipment like security cameras which must be permanently connected to the internet.
Pass-through MAC Address Type the Subscriber’s pass-through MAC Addresses here. Subscribers with these addresses will not be required to authenticate, but must open a web browser to be connected to the internet and are otherwise subject to security settings, advertisements, etc. Note: As with the No Authentication configuration, MAC Address Pass-through users will need to initiate a HTTP Web Browser connection to be added to the firewall so they can send email, ping, or make other connections through the Controller. Blacklist MAC Address
Type the MAC address of blocked Subscribers here. Subscribers with these MAC addresses will not be able to authenticate.
Pass-through Destination IP Address Type the pass-through Destination IP Addresses here. All subscribers will be able to access these IP addresses without having to authenticate. Pass-through URL (walled Garden) Type the pass-through Destination URL here. Subscribers will be able to access these web pages without having to authenticate. Note: Use the pass-through tables to allow access to web resources before the subscriber is logged in. This includes redirect login pages and any images/advertisements on those pages. If you want to redirect on logout add those pages here as well.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 44
OF
92
C ONTROLLER 3000
3.
U SER M ANUAL
DMZ FIREWALL
Screen 12 DMZ Firewall DMZ DMZ stands for Demilitarized Zone. This section allows the user to specify the IP Addresses for a DMZ server that can be freely accessed through the firewall. All Controller ports are forwarded to this internal address. Enable
Check this to enable the DMZ property.
DMZ Host IP
Type the IP Address for which access can be provided.
DoS Attack Protection This section allows the user to enable a service that protects the Controller from common remote Denial of Service attacks on the WAN port. Enable
Check this to enable the DoS Attack Protection.
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 45
OF
92
C ONTROLLER 3000
3.2.5.
U SER M ANUAL
C U S T O M I Z AT I O N
1. LOGIN PAG E This menu allows you to customize the Login Page settings of the Controller 3000.
Screen 13 Login Page
©2006, VALUEPOINT NETWORKS, INC. ALL RIGHTS RESERVED
P AGE 46
OF
92
C ONTROLLER 3000
U SER M ANUAL
Internal Select this option to keep the standard default login page. To view the standard Login Page that subscribers will see, click on the Preview button. Selecting this option will pop-up a dialog box prompting the user to enter the user id and password to be authenticated. Portal Select this option to redirect the Login Page URL to a Web Page hosted outside the controller.
In order to subscribers to login successfully, you will need to put the correct
HTML POST FORM on your Web Page. To see and cut/paste the required code, click on the View External Portal HTML Code button. When you put the HTML code on your portal page do not change the contents of the