Comet Labs WRB64, WRB64MIMO User Manual

__________________________________________________________
MIMO Wireless router
4-port 10/100 Mbps Switch
and VPN server built-in
User guide
Version 1.01 – Aug. 2006
English
__________________________________________________________
Thank you very much for your purchasing of our Wireless. It supports IEEE802.11G Standard, transferring date with speed of 54 Mbps, also conforms to IEEE802.11B Standard. Our wireless router and MIMO Wireless router satisfy enterprise with small scale, SOHO user to lay out WAN and LAN. WRB64 and WRB64MIMO provide multi-protection for the security for the networks, such as support or prohibit SSID broadcast, not allowing AP to broadcast SSID network name for SSID prevention. WRB64 and WRB64MIMO support WEP for the security of WLANS with powerful firewall. WRB64 and WRB64MIMO allow many PCs to share one PC’s WAN Cable and one Internet account by ISP. WRB64 and WRB64MIMO allow various ways to internet, such as ADSL, Cable Modem, dial up automatically, easy to configure. WRB64 and WRB64MIMO combine 4 ports Ethernet Switch to connect with Ethernet adapters. VLAN server allow Internet user to visit website, FTP and other service in LAN. WRB64 and WRB64MIMO control the outside visit, configure different authorized access. WRB64 and WRB64MIMO support Web management, DMZ, network game and videoconference.
This manual is the user’s guide for WRB64 and WRB64MIMO.
This manual consists of hardware specification, installation guide, configuration guide and definition on how to use WRB64 and WRB64MIMO.
Pls use this manual for your reference.
For installation, please refer to chapter 4. For the Internet connection, please refer to chapter 6.
__________________________________________________________
TABLE OF CONTENTS
1. WARNING ..........................................................................................5
2. PACKAGE CONTENTS........................................................................6
3. SPECIFICATIONS ................................................................................7
4. INSTALLATION ................................................................................. 11
4.1 Before installation ................................................................... 11
4.2 Installation ................................................................................... 11
4.3 NETWORK MAP..........................................................................13
5. TCP/IP Networking parameters ...................................................14
5.1 Windows 2000 SETUP .............................................................. 14
5.2 Windows XP SETUP .................................................................19
6. Router homepage connection ......................................................24
6.1 – Internet connection wizard .................................................28
6.2 – Wireless wizard......................................................................29
6.3 manual configuration of the Internet connection..............30
6.3.1 – Authentication PPPoE (ADSL)....................................... 30
6.3.2 WAN Dynamic IP address.................................................35
6.3.3 Static IP address ............................................................... 38
6.3.4 Wireless WAN Client ................................................... 40
6.4 Wireless Status ....................................................................... 41
6.5 LAN Status ................................................................................. 43
7. BASIC SETUP.................................................................................... 44
7.1 WAN SETUP................................................................................ 44
7.2 Wireless Setup ..........................................................................45
7.2.1 Basic configuration........................................................... 46
7.2.2 Advanced Configuration ..................................................47
7.3 LAN configuration – LAN DHCP SETUP ..................................51
7.4 Ethernet - Link Setup/Info .....................................................55
7.5 static routing - Routing Table................................................57
8 – SYSTEM setup ................................................................................. 58
8.1 Administration and right access – Admin Setup..................58
__________________________________________________________
8.2 Firmware Upgrade ...................................................................61
8.3 System log ................................................................................. 64
8.4 Other functions - Miscellaneous............................................ 66
9 Quality of service - QoS.................................................................71
9.1 Basic Setup ................................................................................71
9.2 IP QoS ......................................................................................... 73
9.3 Application QoS ........................................................................75
9.4 Port QoS.....................................................................................77
10 - Network addresses translation - NAT......................................79
10.1 Applications ............................................................................79
10.2 - Internal Server.....................................................................82
10.3 Port Forwarding ..................................................................84
10.4 Port Triggering ....................................................................86
10.5 Address translation - NAT ON/OFF ..................................... 88
11 Advanced Setup ............................................................................. 89
11.1 Firewall....................................................................................89
11.2 Dynamic DNS - DDNS..............................................................92
11.3 – WOL (Wake on LAN) ............................................................94
11.4 - URL Filtering ........................................................................96
11.5 Remote Management............................................................. 98
11.6 - Scheduler............................................................................100
11.7 - VPN Setup ...........................................................................102
Appendix A Ethernet cabling ........................................................ 104
__________________________________________________________
1. WARNING
1. Pls used adaptor provided by manufacturer, otherwise will break the Wireless router.
2. Do not drop the router down or any damage to the Router and its electronic component.
3. Do not disassemble IP Router, otherwise warranty for repair will not be guaranteed
4. Do not exposure IP Router under Sunshine, to avoid heat.
5. Pls keep IP Router dry and away from fire.
6. Pls keep IP Router under shield and run under 0-40 to the perfect state.
__________________________________________________________
2. PACKAGE CONTENTS
The package content of the router is:
1. A wireless router or MIMO Wireless router Model-nr WRB64 or WRB64MIMO
2. DC Power adapter (7.5V, 1.5A)
3. Ethernet Cable
4. CD-ROM containing this manual
__________________________________________________________
3. SPECIFICATIONS
This Wireless IP Router is a highly integrated Wireless IP Router with many functions such as Gateway, Switch, DHCP server, Firewall etc:
11G 54Mbps :Support 802.11g and 802.11b , high-speed data rate up to 54Mbps for 802.11g (draft) and 11Mbps for
802.11b with wide range coverage.
MIMO: Support 802.11g and 802.11b Integration of Multiple input, Multiple Output technology for better performance.
Ne twor k Address Transform (NAT) With providing Internet application this IP Router can allow more than one user to connect with Internet at the same time by sharing one public
IP address; it supports many connection ways:xDSL、Cable ModemLAN/ Leased Line and so on.
4 Ports 10/100M Switch:It has 4 Network 10/100M switch portsport support MDI/MDIX automatic identification
function, Switch port can connect to other switches, so that can support over hundred computers to go to Internet at the same time.
PPPoE (ADSL) Automatic Disconnection/Connection Users can optionally choose automatic disconnection in idle time and connection in access time to save Internet access cost.
DHCP Server Supported:All of the networked computers can retrieve TCP/IP settings automatically from this product.
Static IP address Binding: Authorize user to manage and configure PC in LAN in most by binding MAC address and IP address together.
__________________________________________________________
System Memorandum: WRB64 and WRB64MIMO record routing history and forwarder to administrator mailbox.
UPnP: Defaulted UPnP enable user to configure networking hardware and software. Management Based on Web Page
Both network configuration and system configuration are based on inside Web Server. The user interface is clear and usage is easy. By this interface users can also update software to enhance the system stability and expansibility.
Internet Access Control:Different administration can be setup for different users. Data Package Filtration: Port Filtration, IP Address Filtration, MAC Address filtration, Key word Filtration enable user to configure IP router to analyze data package can be forwarded or refused.
Virtual Server:Allow other users from Internet access WWW, FTP server or other servers in LAN.
QoS: Control the IP Router bandwidth forwarding and transferring by configuration IP Address QoS, application QoS and port QoS.
Firewall:Users can randomly refuse or allow data from Internet
Scheduler: Manage and control Local Network accessing Internet by configuration time.
DMZ Server:Allow one computer to be totally opened to Internet to make sure special application can run.
Remote Management:Users can totally manage office or home network wherever they are.
DDNS:By this function users can set up their own web station.
__________________________________________________________
Remote Wake-up: Enable user to remote wake up PCs in LAN.
Support VPN Pass-throughSupports VPN Pass-through PPTP
dialogue,and also supports users to configure VPN Server and Client in LAN.
VPN server: Allow you to setup VPN server, allow 5 VPN client logging at same time
__________________________________________________________
Detailed Specifications
WIRELESS IP ROUTER
Standard IEEE802.11g, IEEE802.11b, IEEE802.3 IEEE802.3u
Protocol TCP/IP, NAT, DHCP, UDP, FTP, PPPoE PPTP, http, DNS, IPSec/VPN Pass-through
External ports WAN: One 10/100 Mbps RJ-45 port LAN: Four 10/100 Mbps switched ports
Frequency 2.412 – 2.472 GHz
Communication 54 Mbps, 48, 36, 24, 18, 12, 9, 6, 11 Mbps 5.5, 2, 1
Channels 14 (Europe: from 1 to 13)
Modulation CCK, DQPSK, DBPSK, OFDM
RF Power 16-18 dBm
Antenna 1* 2.4 GHz Dipole Antenna (WRB64) 3 * 2.4 GHz Dipole Antenna (WRB64MIMO)
Cable UTP 100Base-TX: UTP/STP 5 or above std.
Interface Web UI
CPU/RAM KENDIN KS8695PX (ARM9) 2 MB FLASH – 16 MB SDRAM
OS Windows 95/98SE/ME/NT/2000/XP MacOS – Linux or other UNIX system
__________________________________________________________
4. INSTALLATION
4.1 Before installation
4.1.1. Firstly please confirm your computer OS (Windows 95, 98, NT, ME, 2000, XP, Linux, Mac) and Web browser (Internet Explorer 4.0 with JavaScript
function、Netscape Navigator 4.0 or above version).
4.1.2. Make sure there is LAN Card which has been correctly installed in your computer.
4.1.3. If you are xDSL user, please remember your user ID and password.
4.1.4. If you connect Internet by LAN or WAN, please get the following information from your network administrator: IP address is static or dynamic, DNS, default gateway, account and so on.
* If your computer has installed ADSL PPPoE dial-
up software before the installation of IP Router, please backup your installation software and uninstall your ADSL PPPoE dial-up software by Start->control panel->Add or Remove Programs.
4.2 Installation
4.2.1. Setup WAN connection: connect broadband cable (xDSL, Cable Modem or LAN/ Leased cable) with WAN port of IP Router.
4.2.2. Setup LAN connection: connect your computer LAN card’s port or your switch UPLINK port with one LAN port of IP Router by a common network cable.
__________________________________________________________
Note: All LAN ports of IP Router can automatically sense
cross cable, so you can either use through cable or cross cable to connect LAN card or switch.
4.2.3. Turn on the power: connect and the power supply, turn on it. Then IP Router comes to self-detect state. During the self-detect: PWR LED will be long light, RUN LED will slow flash after correct startup, other four LAN LED and WAN LED will flash only twice rapidly, then the system will come to normal work state.
4.2.4. Start computer
__________________________________________________________
4.3 NETWORK MAP
Note:During the usage, the sequence of turn on is:firstly turn on Modem’s power supply,1 minute after Modem
startup turn on IP Router power supply, then turn on the computer.
__________________________________________________________
5. TCP/IP Networking parameters
Users should configure local network to access Internet by IP Router. Users should know the default configuration of IP Router before installation. Users must connect with IP Router again after configure computer’s local network. Please make sure your computer setting is as follows, Otherwise IP Router can not be correctly connected (Linux and Mac users please setup as follows by relative conference).
The default configuration of IP Router is:
— IP address192.168.0.1
— Subnet Masks255.255.255.0
Users can setup static or dynamic IP configuration.
5.1 Windows 2000 SETUP
(1) Install IP Router. (2) Start Windows 2000 and check LAN LED is on or off. If
off, please confirm the connection of your computer with IP Router.
(3) Click “start”->“Setting”->“Panel Control”
__________________________________________________________
(4) Double click the “Network and Dial-up Connection” in “control panel”.
(5) Click “Local area connection”->“Properties”
->“Internet protocol (TCP/IP)”and “Properties”.
__________________________________________________________
(6) Click “General” bar, Select “Obtain an IP address automatically” and “Obtain DNS server address automatically”
__________________________________________________________
(7) Click “OK”.
(8) Click ”Start” ->“Run”.
(9) Input ”cmd”, then click “OK”.
(10) Input “ipconfig” in Pop-up Command window.
Please make sure your IP is the same with below. If same then your configurations is suc c ess ful , o r plea s e re d o the above steps and restart your computer.
The IP address is between 192.168.0.2 and 192.168.0.254
the subnet mask is 255.255.255.0
the default gateway is 192.168.0.1
__________________________________________________________
(11) Input “ping 192.168.0.1”, then “Enter”. (12) If you can see “Reply from 192.168.0.1: bytes=32
time=2ms TTL=64,then the connection between your computer and IP Router is completed.
__________________________________________________________
5.2 Windows XP SETUP
(1) Install IP Router.
(2) Start Windows XP and check LAN LED is on or off. If
off, please confirm the connection of your computer with IP Router.
(3) Click “Start”->“Setting”->“Panel Control”
(4) Double click the “Network and Internet
Connections” in “control panel”.
(5) Click “Network connection”->“local area connection”->“properties”-> “Internet
protocolTCP/IP” and “Properties”.
(6) Click “General “, Select “Obtain an IP address
automatically” and “Obtain DNS server address automatically”
(7) Click “OK”
__________________________________________________________
__________________________________________________________
(8) Click “Start”->“Run”
(9) Input “cmd “, Click “OK”
__________________________________________________________
(10) Input “ipconfig” in the pop-up command window.
(11) Please make sure your IP is the same with below. If
same then your configurations is su cc es sf ul , o r pleas e redo the above steps and restart your computer.
The IP address is between 192.168.0.2 and 192.168.0.254
The subnet mask is 255.255.255.0
The default gate way is 192.168.0.1
(12) Input “ping 192.168.0.1”, then “Enter”.
(13) If you can see “Reply from 192.168.0.1: bytes=32
time=2ms TTL=64”,then the connection between your computer and IP router is completed.
__________________________________________________________
__________________________________________________________
6. Router homepage connection
Run Internet Explorer ( ) and click the “Stop ( )
button in Internet Explorer’s toolbar.
Input the following URL in the address bar: http://192.168.0.1
192.168.0.1 is the default address of the router.
The homepage of the router is displayed and offers three options:
1) – You can access the configuration pages by clicking on the ‘LOGIN’ button.
INFO / When delivered, no authentication (login/password) is required. Access to the router Web UI is free. If you have already entered a login and password, you will have to enter them to access to the web configuration pages.
2) – You can start the « INTERNET WIZARD » to configure the Internet connection.
3) – You can start the « WIRELESS WIZARD » to configure the Wireless connection.
This page is also displaying several information:
Conn. Type : Current WAN connection type.
Conn. Status: Status of the current connection
WAN IP: IP WAN current address.
__________________________________________________________
Connected PC: IP address of the computer which is connected to the router.
__________________________________________________________
Connection to the Web UI homepage. The detailed configuration of the router is presented in the next chapter.
All configuration web pages have a similar presentation:
Six tabs are available:
- Status: Status of router (WAN, Wireless, LAN, … )
- Basic Setup: (WAN, Wireless, LAN/DHCP, Link, …)
- System: (Login, Alert, upgrade, logs, …)
- QoS: Bandwidth management
- NAT: Applications, virtual servers, port trigger, …
- Advanced: Firewall, DDNS, URL Filtering, VPN, …
In each tab, a list of functions is available.
On each page there is also three buttons on the top right side:
__________________________________________________________
Refresh – Reload the stored parameters.
Save – Save the full configuration of all parameters entered to
the flash memory of the router. The parameters are then available even after a power shut down or a reboot.
The “Apply” button is transferring the parameters you configure in the web page into the RAM of the router. In case of power loss, the parameters will be lost
Help – Display for each page a description of the function and different items in the page.
__________________________________________________________
6.1 – Internet connection wizard
The Internet connection wizard is offering two choices: A manual connection enabling to enter all detailed of the connection. But the wizard is also offering an automatic configuration by searching for the connection type and authentication mode.
Within less than two minutes, the wizard is displaying you all the parameters. If any PPPoE account is required, the wizard will ask for the PPPoE login and password.
(DHCP Client connection for example).
__________________________________________________________
6.2 – Wireless wizard
Please send the radio region domain. Because Europe may not be referenced, please select ‘Others’.
During a few seconds, the router is searching for existing wireless network that may affect the performance and stability of the wireless network of the router.
WARNING / the very first models of wireless cards sold in France were accepting only channels 10 to 13. To keep compatibility with these equipments, we suggest you to use a free channel in this range. The channel 11 is the usual radio channel in France. If this channel is not free, please use channel 13 or another channel which is a least 2 channels far from a busy channel.
__________________________________________________________
6.3 manual configuration of the Internet connection
6.3.1 – Authentication PPPoE (ADSL)
First, make sure that the WAN LED is illuminated. If this LED remains off, please verify the connection between the modem and the WAN port of the router.
__________________________________________________________
Click on the radio button next to the “PPPoE User (ADSL)”.
Enter the PPPoE account login and password. In the “User ID” and “Password”. This information is provided to you by your ISP
MTU: Value of the packet size. (Default = 1454). It can be
extended up to 1500, but never change it without any request from your ISP hot line.
Disconnect PPP session if idle time is longer than (Min):
This function is usually not used on ADSL Line, but may be usual on some other links. You can define the maximum idle time before disconnection.
Connect On Demand: In case of disconnection, the router
will try automatically to re-establish the connection.
Prevent reconnection although no response from PPP server: By selecting this option, the router will not try to re-establish the Internet connection.
Click “Apply” to validate these parameters.
The following window is displayed.
If the message “Successfully connected” is displayed in
the “Conn. State“ , the link with Internet is established.
__________________________________________________________
if the message “Invalid ID/password” is displayed, you
may have mistype the PPPoE user account or login. Please verify, make sure you have correctly entered upper and lowercase characters. Letters I (India) in uppercase and l (Lima) in lowercase, 0 (zero) and 0 (Oscar) may be very similar in some fonts.
If the “Conn. State” is remaining unchanged, PPPoE may
not be the kind of service provided by your ISP. Please verify it and restart the Internet wizard.
You may also display the full status of the WAN connection in the STATUS tab, function WAN STATUS.
__________________________________________________________
Physical Address: display the router WAN M.A.C address. — WAN IP Address — Subnet mask, Default Gateway, Primary DNS server and Secondary DNS are also displayed. All this information has been sent to the router by the ISP.
The “Disconnect” button enables you to disconnect the Internet connection immediately. The no Internet connection has been established the button title is displayed as «Connect ».Clicking on this button will request the router to establish the internet link.
When parameters are validated, you still need to save it
into the router flash memory by clicking on the “Save” button.
__________________________________________________________
Restart all connected PCs.
__________________________________________________________
6.3.2 WAN Dynamic IP address
Using this method, the router is receiving its WAN IP address automatically from the ISP.
Connect the modem to the WAN of the router. Please
make sure that the WAN port LED is illuminated. If the LED remains OFF, please check the link between the router and the modem.
Click on the “Basic Setup” tab and select the “WAN
Setup” function:
Click on the DHCP User radio button (Cable Modem,
VDSL, LAN, IP ADSL)
Then, click on the « Apply » button to validate the
parameters.
the following window is displayed
__________________________________________________________
If « Conn. State » is displaying “Successful connected”,
the internet link is established. If « Conn. State » is displaying “Connecting to Internet”, verify the link, the connection cannot be established. Please check with your ISP that he is providing automatically a WAN IP address to the router.
INFO / Rare are the ISPs which are still registering the M.A.C address of the first PC connected. If the ISP is confirming DHCP connection, you may have to clone your PC M.A.C address to the router. By activating the « Physical address clone », and clicking on the « Search M.A.C. address » you can perform this function.
Allow private IP to be accepted: A reserved IP address
usually not available on the Internet will be accepted if you check this box.
When the parameters are validated, do not forget to click on the “Save” button to transfer the configuration to the flash memory .
__________________________________________________________
Restart all PCs connected to the router.
__________________________________________________________
6.3.3 Static IP address
If your ISP has provided a static IP address, you can directly enter it.
Input WAN IP address: specify the static IP address given
by your ISP.
__________________________________________________________
Subnet mask: provided also by your ISP
Default Gateway: IP address of your ISP’s router
connected to your router.
Primary DNS Server and Secondary DNS Server: also
provided by your ISP
Click on the « Apply » button to validate the parameters.
The following window is displayed.
By clicking on the “Show Internet Information”, the WAN
Status page will be displayed confirming the parameters you entered.
If the connection is established, the « Connection
Status » is displaying “successful connection” — Physical Address: displays the WAN M.A.C address of the router. — Please verify the value of Subnet mask, Default Gateway, Primary DNS server and secondary DNS server.
Click on the “Save” button to store these parameters into the router’s flash memory.
INFO / You can specify the DNS primary and secondary name servers. If you are not using your ISP’s DNS server, you may experience some problems with mail or surfing. Some rare ISPs are not accepting DNS flow not addressed to their own DNS Servers.
__________________________________________________________
6.3.4 Wireless WAN Client
You can use the Wireless connection as the WAN connection to communicate to the wired equipments
Click on the ”Basic Setup” tab and select the “WAN SETUP”:
The WAN port is then disconnected and the communications are coming from the wireless network. The wireless equipments can no longer connect to the wireless AP.
Click on « Apply » to validate these parameters.
Then, you need to configure the wireless network, defining the SSID and encryption method
__________________________________________________________
6.4 Wireless Status
Click “Status”->“Wireless Status” as following:
This web show current wireless part configuration, including:
Wireless Status: Show current wireless connector
status.
SSID (networking name): Show current wireless
networking name.
Mode: Current used wireless connector forwarding
mode
__________________________________________________________
Region: Show current channel region information
Channel: show current used channel
SSID Broadcast: Show SSID is on or off
Authentication Type: Show current used certification
way
Encryption Strength: Show WEP encryption length
(64/128 bits)
MAC Authentication: Show how to identify wireless
customer by MAC address.
__________________________________________________________
6.5 LAN Status
Click on the “Status” tab and select the “LAN Status” function:
LAN Information : Show user current LAN connecting status (LAN port and wireless connection ) and DHCP server status, include MAC address of the LAN port ,and IP rent regions and quantities of IP address shared by IP Router among IP address ,subnet mask, DHCP server in LAN .
Shared IP information: Show IP address information rent by DHCP server
Serial Number: The position in the subject Physical Address: MAC address of the client PC Types: Wireless /Wired, dynamic / static
__________________________________________________________
7. BASIC SETUP
7.1 WAN SETUP
Report to Chapter 6.3 to configure the WAN port in one of the four connection modes:
- Authentication PPPoE WAN
- DHCP Client – Dynamic IP address
- Static IP address
- Wireless WAN client
__________________________________________________________
7.2 Wireless Setup
Click the ”Basic Setup” tab and select the “Wireless SETUP” function:
This page is displaying two sections: First section for basic setup, second section for wireless security features.
__________________________________________________________
7.2.1 Basic configuration
Status: displays the communication type and wireless
operating mode (MIMO or 802.11g/b - on/off, AP/Mode Client)
Operation: Activate or deactivate the wireless function? When selection is OFF, the wireless AP is no longer transmitting or receiving radio waves.
SSID: specify the wireless network name.
Mode: Three modes are available:
- g and b: Both 802.11g and 802.11b equipments can communicate with the AP.
- g only: Only 802.11g devices can communicate.
- b only: Only 802.11b devices can communicate.
NOTE / the « g and b » mode is insuring compatibility with old equipments working at 11 Mbps , but is reducing the wireless communications performances to insure this compatibility.
Region: Specify the radio communications domain. If Europe is not specified in the list, please select "Others". Radio channels from 1 to 13 are then available.
Channel: Select the radio channel. In WAN Client mode, this option is disabled. The AP is becoming a client for any other access Point and will automatically select the radio channel of the AP to be connected.
Broadcast of SSID Option: If activated (crossed), the wireless network name (SSID) will be broadcasted.
When the basic configuration is done, click on “Apply” to validate these parameters.
__________________________________________________________
7.2.2 Advanced Configuration
7.2.2.1 Wireless Security Setup
Your « Authentication type » and « Encryption Strength » selections will modify automatically the presentation of the other parameters.
Authentication type: OPEN System or Sharing KEP or AUTO modes are similar to the usual modes found in Windows XP configuration.
Encryption Strength: WEP 64/128 Bit
Encryption Strength: WEP 64 Bit or WEP 128 Bit. Encryption key length.
Key Input: String (alphabetical – keyword) or HEX (Hexadecimal – from 0 to 9 and le tte rs for A to F). in 64-Bit WEP, length of the string is 5 characters. In hexadecimal mode: length is 10 characters
En 128-Bit WEP mode, the string length is 13 characters, in hexadecimal 26 characters are needed.
__________________________________________________________
You can enter up to 4 keys, but only one key is activated (The one selected by a radio button).
To validate your configuration, please click on “ Apply ”.
Authentication type: WPA-PSK
The WPA-PSK mode (Personal sharing Key) offers a better security than WEP by using longer encryption keys and avoiding some of the wicknesses of WEP protocols.
Encryption strength: TKIP The key can count up to 63 characters.
Encryption strength: AES Maximum length key: 63 characters. This mode is offering a different coding system and may be mandatory when using WDS function with some APs such as the Apple Airport Extreme.
__________________________________________________________
7.2.2.2 MAC Authentication – M.A.C addresses
filtering
Policy:
Accept all: No filtering at all.
Reject registered M.A.C. addresses: Specified M.A.C.
addresses will not be allowed to connect.
Accept registered M.A.C. addresses: Only registered
M.A.C addresses will be able to connect.
NOTE / In this last mode, do not forget to change this
parameter when changing a wireless card in a computer.
__________________________________________________________
7.2.2.3 WDS configuration – Wireless distribution system
This functionality allows different access points (Maximum 6) to relay the wireless communications from the transmitter to the final destination. You can generate a meshed network.
In each AP, you need to enter the wireless M.A.C addresses of all the other APs you want to communicate with.
Then your router is acting both as multipoints bridge relay and as a simple access point.
NOTE / WDS connection between various APs may require WPA-PSK in AES mode. A technical note explaining how to configure WDS is available on comet Lab’s web site at www.cometlabs.com
When the parameters are set, do not forget to apply and save the settings to avoid their loss after a power shortage or reboot process.
__________________________________________________________
7.3 LAN configuration – LAN DHCP SETUP
Click on ”Basic Setup” and select “LAN/DHCP SETUP”:
LAN IP and DHCP parameters can be set in this page.
__________________________________________________________
System IP address:IP address in LAN. This IP address is factory default value 192.168.0.1, and you can change it
192.168.0.1
Subnet MaskLAN subnet mask.
DHCP Setup The router is including a DHCP server which simplifies the TCP/IP configuration of the various equipments in your network by providing a unique IP address to each equipment.
DHCP Server Status: DHCP server actual status running (Active) or Stopped.
DHCP Server operation: Start or stop the DHCP server.
DHCP IP Pool: IP address range automatically allocated
by the DHCP server.
Manual DNS configuration: Let DJCP server automatically allocated the DNS server to client PC.
NOTE / Some ISPs do not accept DNS server IP addresses which are not belonging to them.
Static Lease Management
This function makes sure the
convenient control of the IP address in LAN computers. Static lease IP can obligate static IP address for computer with appointed MAC address. Afterwards when the computer asks
__________________________________________________________
DHCP server for IP address, DHCP server will give it the obligated IP address.
To generate the link between IP address and M.A.C address for equipments already connected to the router, click on « Add Hardware address & IP pair on the real network » button.
Si you wish to connect some other equipment or want to perform this configuration manually, click on « Add hardware address & IP pair manually » button.
The check box « Get hardware address & IP from this host » allows you to get the MA.A.C address of the computer running the Web UI.
Do not forget to click on « Apply » to validate your modifications and click on SAVE to record the parameters in flash memory of your router.
Twin IP Setup
–WAN IP address directed to a computer in your
LAN.
__________________________________________________________
This function enables one computer in your LAN to receive and to send packets from the Internet line without using the NAT system (Network address translation).
The selected computer is directly exposed to Internet. This function is usually dedicated to debugging, traffic analysis, …
Check the box « Twin IP » and specify the M.A.C. address of the computer. Click on « Apply » to validate the modifications.
__________________________________________________________
7.4 Ethernet - Link Setup/Info
Click “Basic setup” and select ” Link Setup/Info”:
__________________________________________________________
All information about link speed and duplex mode are detailed for each port. Statistics about traffic are also available.
Section Link Setup For each port, you can specify:
Port: WAN Port or LAN port.
Mode: Automatic or manual setup.
In the manual mode, you can specify two parameters: Speed 10 or 100 Mbps
Duplex: Half or full-duplex
Click on « Apply » to validate your parameters.
Link Information section Display the status of each port indicating speed link and duplex mode.
Link Statistics section For each port (LAN and WAN) :
- Number of packets received,
- Number of bytes received,
- Number of broadcasts received,
- Number of multicasts received
- Number of errors received
- Number of packets sent
- Number of bytes sent
- Number of collisions detected
__________________________________________________________
7.5 static routing - Routing Table
When several routers have to communicate in a single network, you need to declare static routes to make each router knowing the others. This function is mandatory if you have to cross another router to access a second subnet:
Static routes can access either computer (Host) or network (NET):
NET: Access to a network HOST: access to a unique
device.
Target: LAN IP address.
Mask: Specify the number of bits for the subnet mask
Gateway: specify the router IP address in your current
subnet.
Click on the « ADD » for validation.
__________________________________________________________
8 – SYSTEM setup
8.1 Administration and right access – Admin Setup
Click on “System” and select “Admin Setup”
Login Account Setup section:
Current Login ID: actual user login.
By default, this field is empty, no user authentication is required. You do not need to fill this filed. If you set one login/password, you need to specify the current user login.
__________________________________________________________
Current password: if you want to change the password,
you need to enter the actual password.
New Login ID: please specify the new login.
New password: Enter the new password.
Re-type New password: confirm the new password a
second time. This field will be compared with “New password” field to make sure you specified the same new password.
Click on “Apply” for validation.
NOTE / For router configuration protection a login/password is recommended.
NOTE / If you have lost the password, it is possible to reset the router parameters to default values by pushing the RESET button during 5 seconds after power on.
ATTENTION: All parameters will be lost; the IP address will be set to 192.168.0.1. (See Chapter 6.3).
Admin E-Mail Setup section:
You can send the router log events
to an e-mail address.
__________________________________________________________
Admin E-mail: Complete e-mail address (ex:
admin@cometlabs.com
) of destination.
Mail Server (SMTP): SMTP mail server IP address.
E-mail of sender: Sender e-mail address
Use authentication: If your SMTP server is requiring
authentication, please check this box and specify:
SMTP Account: mail account login
SMTP Password: mail account password.
Do not forget to click on « Apply » for parameters validation.
To record these parameters into the flash memory of your router, do not forget to click on the « Save » button.
__________________________________________________________
8.2 Firmware Upgrade
Click on “System” and select “Firmware Upgrade“
Before any firmware upgrade, please take a note of your current firmware version running in the router.
Go to www.cometlabs.com
into the pro ducts section, select the product and click on the firmware link, in the page. Make sure there is a new version and click to download it. It is either a .bin or .img compressed in a .zip file. Decompress the file. The generated file can be transferred to the router.
NOTE / Be careful, the Comet labs product range is wide and you need to use a firmware reserved for your model. Please do not hesitate to contact our technical support for detailed information or confirmation before upgrading.
Click on the “Browse” button and select the file to download.
__________________________________________________________
Then click on the “Open” button, the filename is now appearing in the « New Firmware » field.
Click on the « Upgrade » to start the updating process.
Then the process is successfully terminated, the router will restart automatically.
Verify the version of the firmware in the web UI to make sure the update is performed successfully.
NOTE / The upgrade process is taking around 60 seconds. During this time, do not interrupt it; do not switch the router off. Interrupting the upgrade may leave the router in an indeterminate state.
__________________________________________________________
NOTE / Do not use the wireless network for upgrading the firmware. Disturbances in the wireless communications may generate problems and leave the router in an indeterminate state.
__________________________________________________________
8.3 System log
Click on “System” and select “System log”:
Section System log setup:
Operation: You can click on the Start/Stop button to activate the record of the router events.
Clear System Log: The « Clear » button will remove all existing events from the log.
__________________________________________________________
System Log History: Up to 400 events can be stored. If you have asked for mailing the log events, the mail will be transmitted every 400 events.
In all cases, you can see in the log, the different errors occurred. Errors are displayed in RED color.
__________________________________________________________
8.4 Other functions - Miscellaneous.
Click on “System” and select “Misc.”
Host name Setup section:
__________________________________________________________
Setup Hostname: Configure IP Router name in the networking presented on the report forwarded to administrator mailbox.
Config Mgmt Restart section:
Config Backup: Enable user to backup all the configurations.
Config Restore: Restore previous configuration on router.
Restore Default: Restore defaulted configuration provided by manufacturer, including:
Defaulted user name: Blank
Defaulted IP address: 192.168.0.1
Defaulted Subnet Mask: 255.255.255.0 Restore default configuration provided by manufacturer, router will reboot automatically.
Restart System: Click “Restart System”, router will reboot automatically. System Time Setup: For sake of Scheduler. pls configure accurate time system. Refresh router current time in accurate time zone: Or choose other system server until time to be refreshed.
UPNP Setup: UPNP is configured as defaulted. General plug and play UPNP refer to system architecture for the networking between PC and other universal intelligent equipments, especially for the SOHO user. UPnP works with wired or wireless.
__________________________________________________________
System Time Setup section: It is important for your router to be up to time. It is useful for the events log pour confirm date and time when an error has occurred. This function is also important in case of scheduled Internet blocking defined.
One of the best way to maintain an exact time is to coordinate the router with a NTP server (network time protocol) available on the Internet.
Time Server: Click on the first radio button if you want to use a pre-configured NTP server. Click on the second radio button to specify the IP address of your NTP server.
Summer Time: to automatically adjust the time with summer time, please check this box.
Standard Time Zone: Select your local time zone.
Section UPnP Setup: By default uPnP is activated. This function enables Windows XP users who have activated the « Display network uPnP devices icons » in the « Network favorites » to see and access the router with a simple click.
Uncheck the « Enable UPnP Server » box, to disable this function.
__________________________________________________________
Auto-connecting Setup page section: When checking this box, After an Internet disconnection or when the DHCP lease time is over, the default web page will displayed each time you will try to surf on the web.
If you select auto-reconnection mode, then this function is deactivated.
Connect with system setup-page automatically …: For people who want to connect to the Internet only when they need it, they can display the connection page.
Login Page Setup section:
__________________________________________________________
If you want to disable access to the internet and wireless wizard, please check the radio button « The login page would not be displayed » and click on the « Apply » button.
__________________________________________________________
9 Quality of service - QoS
9.1 Basic Setup
Click on “QoS” and select “Basic Setup”
This function enables to manage the bandwidth of your Internet link.
QoS Basic Setup Section:
QoS Operation: To activate QoS, you need to click on the « Start » button. If the field « QoS Status » is already displaying « started », QoS is already active.
__________________________________________________________
WAN speed Setup section:
Internet Type: please specify the type of Internet line you are connected to.
Download rate: Specified in megabits or kilobits per second.
Upload rate: Specified in megabits or kilobits per second.
Do not specify decimals, comma or decimal point not allowed
Click on the « Apply » button for validation.
__________________________________________________________
9.2 IP QoS
If QoS has not been activated like recommended in section 9.1, this page will not be accessible.
Click on “QoS” and select “IP QoS” :
You can define a minimum guaranteed bandwidth or a limited maximum bandwidth.
IP Address: specify the IP address range affected by this QoS rule.
Twin IP, permits to specify that only the computer selected for twin IP is affected by this rule. (See Twin IP function in the end of chapter 6.3).
__________________________________________________________
Operation mode: Specify the kind of rule you want to establish Minimum Guarantee or Maximum Limited.
Download rate: Specify the reception bandwidth minimum allocated or maximum limited.
Upload rate: Specify the emission bandwidth minimum allocated or maximum limited.
Click on the « Apply » button to validate and see the rule listed.
The « Del » button enables to remove a rule. You need to check the box corresponding to the rule, then click on the “Del” button to remove it.
NOTE / If you are modifying the Internet bandwidth capacity, all rules will be deactivated.
__________________________________________________________
9.3 Application QoS
Click on “QoS” and select “Application QoS”
For some pre-defined applications known for the bandwidth needed, you can control or guarantee it. For the non defined applications, please identify the IP ports and manage the QoS by IP ports. Please see chapter 9.4 – Port QoS.
To establish a rule for a pre-defined application, check the corresponding box.
Operation mode: Define the mode (Min. Guarantee) or (Max. Limit).
__________________________________________________________
Download rate: specify the reception rate in Kilobits or megabits.
Upload rate: specify the emission rate in Kilobits or megabits.
Click on « Apply » button to validate the rule and have it listed.
NOTE / If you are modifying the Internet bandwidth capacity, all rules will be deactivated.
NOTE / Do not forget to click on the “Save button” to record the parameters into the flash memory of your router.
__________________________________________________________
9.4 Port QoS
Click on “QoS” and select “Port QoS"
If you know the IP ports (TCP and UDP) used by the application, you can dedicate or limit the bandwidth of the application.
External Port #: specify in these fields the port number or the range of ports used by the application.
Protocol: select TCP, UDP or both (ALL).
Operation mode: Define the mode
(Min. Guarantee) or (Max. Limit).
Download rate: specify the reception rate in Kilobits or megabits.
__________________________________________________________
Upload rate: specify the emission rate in Kilobits or megabits.
Click on « Apply » button to validate the rule and have it listed.
NOTE / If you are modifying the Internet bandwidth capacity, all rules will be disabled.
The « Del » button enables to remove a rule. You need to check the box corresponding to the rule, then click on the “Del” button to remove it.
NOTE / If you are modifying the Internet bandwidth capacity, all rules will be disabled.
__________________________________________________________
10 - Network addresses translation - NAT
10.1 Applications
Click on “NAT” and select ”Applications”:
__________________________________________________________
Application setup section: Some applications such as networking games, video conferencing software, are generating multiple communications flow. These applications are hard to manage for usual firewalls. This function permits to redirect the data flow coming from the Internet to a particular computer at a specific IP address.
Check the box corresponding to your application and specify the IP address of the computer which will receive the data flow from this application.
Click on « Apply » to validate the parameters.
Do not forget to click on the “Save” button to transfer the parameters to the flash memory of your router.
List of IP ports used by these applications:
Ports Applications
TCP 812, TCP 986 BuddyBuddy TCP 8000 WinAmp broadcasts TCP 9292, TCP 9999 GuruGuru TCP 1720 Netmeeting TCP 6699, UDP 6257 WinMX TCP 3389, UDP 3389 Windows Remote desktop UDP 22321 Soribada2
__________________________________________________________
FTP Private port section: To redirect the FTP access (port 20 and 21) to non-standard ports, you can specify the new ports.
Port Number: Enter the value of the new port, and then click on the « Add » button. The new po rt is appearing in the port list below.
To remove a port, check the box located before the port number and then click on the « Del » button.
__________________________________________________________
10.2 - Internal Server
Click on “NAT” and select “Internal Server”:
The router is equipped with a firewall; any access to your local area servers is following filtering rules.
The virtual server is redirecting some specific ports to some of your LAN IP servers without having to define some complex firewall rules.
__________________________________________________________
Internal Server Setup section: These services (DNS、SMTP、POP3, http, NEWS, FTP, Telnet or PPTP) are using a single port.
Check the box corresponding to the service, enter the LAN IP address of the server, the data flow will then be sent to this IP address. You can also choose to reconfigure the external port. The internal cannot be modified.
Then click on « Apply » button for validation.
DMZ Setup section: The DMZ function enables to open all services and all ports to one computer into your local area network.
ATTENTION: This computer will be directly exposed on the Internet and only the NAT system will protect this computer.
Check the box, and then enter the server IP address.
Click on « Apply » button for validation.
Note / Do not forget to click on the “save” button to record the modifications into the flash memory.
__________________________________________________________
10.3 Port Forwarding
Click on “NAT” and select ”Port Forwarding”:
You can redirect data flow from a range of external IP ports to another range of internal ports on a specific LAN server.
Rule Name: this name is of no importance.
Protocol: TCP or UDP
External Port Range: Define the range of external IP
ports.
__________________________________________________________
Internal PC IP Address: Define the IP address of the server which will receive the data flow from the range of external ports.
Internal Port Range: Define the range of the internal ports. The external and internal ranges must count the same number of ports.
Click on the « Apply » button to validate the parameters.
Do not forget to record the configuration parameters by clicking on the “SAVE” button.
To remove a forwarding rule, check the box corresponding to the rule in the DEL column and click on the “DEL” button.
You can disable a forwarding rule by unchecking the box named « OP ». To reactivate it, you have to recheck the same box and click on the « OP » button.
__________________________________________________________
10.4 Port Triggering
Click on “NAT” and select the ”Port Trigger”:
When opening a session on some ports, the triggering rule is opening some other ports for some other sessions to the same IP address.
Rule Name: This name has no specific function
Port Trigger: Define the port or the range of ports for
triggering. * Protocol: TCP/UDP
__________________________________________________________
* Port Range: Enter the first and last number of ports in the range of triggering. Any port in this range activated will immediately open the forwarding port range to accept packets.
Port Forward: Define the port or the ports range to open.
* Protocol: TCP / UDP
* Port RangeEnter the port range (separated by space)
Click on the « Add » button for validation.
NOTE / Do not forget to click on the « Save » link to record the configuration to the flash memory of the router.
__________________________________________________________
10.5 Address translation - NAT ON/OFF
Click on “NAT” and select “NAT ON/OFF”:
This function enables to deactivate the address and port translation system (NAT and PAT).
If you check the box and click on the « Apply & Reload » button, you will immediately disable the NAT/PAT system.
NOTE / If this option is checked (NAT deactivated), all the functions linked to NAT system will be become inoperative:
- Applications
- Internal Server
- Port forwarding
- Port Trigger
__________________________________________________________
11 Advanced Setup
11.1 Firewall
Click on “Advanced” and select ”Firewall”:
This function enables to block deny of service attacks, avoid Internet link saturation and define firewall rules.
__________________________________________________________
Blocking DoS section: Select the type of attacks to block:
SYN Flooding TCP
SMURF
IP Source routing
IP Spoofing
BY default, the DoS attacks are stopped, each check box is activated (crossed).
You can also block the ICMP Ping command.
Blocking ICMP from Internet: when a ping command is coming from the Internet, the router will not answer.
Blocking ICMP from LAN to Internet: when a ping command is coming from your LAN, the router will not answer.
Connecting filtering section: You can establish the packets filtering rules based on the direction (IN or OUT), the IP source and destination addresses, the protocols (TCP/UDP) and the M.A.C addresses. You can choose to stop or forwarder the packets satisfying the rule.
DirectionYou can define the direction of the filtering rule. “WAN”->”LAN” from the Internet to your LAN “LAN”->”WAN” from the LAN to the Internet.
Source H/W address: You can click on the « Search MAC Address » to list the MAC address known from the router.
__________________________________________________________
Source IP AddressIP address from the sender. The sender can be a network, a sub network or a host
Net Mask: number of bits defining the subnet mask of the sender. (255.255.255.0 = 24 bits)
Destination IP Address: IP address from the receiver. The receiver can be a network, a sub network or a host
Net Mask: number of bits defining the subnet mask of the sender. (255.255.255.0 = 24 bits)
Protocolfour options: Any, TCPUDP or ICMP.
Destination Port If you select « ANY »,
you are blocking all ports.
Accept/Drop: specify if the packets satisfying to the rule definition will be blocked (DROP) or forwarded (Accept)
Then click on the « Add » button to validate the rule. The list of rules established is displayed under the zone of definition. By clicking in the check box of the column “modify” on the line of a filtering rule, you select the rule. When clicking on the “modify” button in the top of the column, the rule is displayed in the rule definition zone for edition.
To remove a rule, click in the check box in the « Del » column, and then click on the “Del” button in the title of the column.
NOTE / Do not forget to save the configuration parameters to the flash memory by clicking on the “SAVE” link. NOTE / choose a method, either allowing traffics or blocking traffics. We recommend you to create allowing rules. Everything not permit is blocked.
__________________________________________________________
11.2 Dynamic DNS - DDNS
Click on “Advanced” and select ”DDNS”:
A large majority of ISPs do not offer or invoice fixed IP WAN address. Your internet address is changing regularly. The DynDNS function is enabling you to create a hostname for your router WAN IP address. When the WAN IP address is changing, the new IP address is sent to the DNS server which is immediately recording the new address. With such solution, you can access your router and site anytime by its hostname.
This service is free from several companies. You can contact
www.dyndns.org
to cerate a free account.
Define your hostname – (Ex: claure.dyndns.org
), a login (User
ID) and a password to access your account.
__________________________________________________________
When you account has been created, you must enter the same information into your router. When you WAN IP address is changing, the router will inform the DNS server at ww.dyndns.org of the new IP address
Host NameHostname including the full domain (Ex. claure.dyndns.org).
DDNS Service provider: Specify the dynDNS supplier domain.
User IDenter the dynDNS account login.
Passwordenter the dynDNS account password.
Click on the « Add » to validate the parameters.
NOTE / Do not forget to click on the « Save » link to store the parameters into the flash memory of the router.
The list below is displayed the status of your connection and inform you if the update has been successfully terminated. If you wish to delete the hostname, please check the box in the Del Column, and then click on the “Del” Button in the title of the column.
If you check the box in the “Update” column and click on the “Update” button in the title of the column, you will send an update request to the dynDNS server. Attention: Too many updates without IP address changes may generate the lock of your account by DynDNS supplier.
__________________________________________________________
11.3 – WOL (Wake on LAN)
Click on “Advanced” and select ”WOL”:
This function allows you to wake on networked equipment inside you LAN. Make sure that the system you want to wake-up is compatible with Wake-on-LAN. Check inside its BIOS and SETUP that the Wake-on-LAN function is enabled.
Wake-on-LAN configuration:
PC Name: give a name to this computer
Physical Address: Specify the M.A.C address of the
equipment. The « Search Mac Address » button helps you by displaying the known MAC addresses from the router.
Then click on the « Add » button.
__________________________________________________________
The equipment is now in the list. Clicking on the « Del » button, you can remove the equipment from the list.
Wake-on-LAN of the computer. Display the same web page and click on the « Wake-up PC » located on the line of the equipment you want to wake up.
NOTE / Do not forget to click on the « Save » link to store the parameters into the router’s flash memory.
__________________________________________________________
11.4 - URL Filtering
Click on “Advanced” and select ”URL Filter»:
To limit or to regulate the users Internet access, you can set filters on the URL, MAC address, IP address, domain, iteration, or applications type.
Operation: click on the « Start » button to activate the service. If the field « Status » is displaying the message « Started », the filtering service is already active.
IP address: Select the IP address or IP range you want to filter.
__________________________________________________________
Physical: If you prefer to filter based on MAC address, you can click the corresponding radio button and enter the MAC address in the field “Physical”.
Input String :Enter the URL address, a single keyboard or a combination of keywords separated by a space. — if you enter www.xxx.com the complete web site will be blocked — if you specify some keywords such as « sex xxx » the users will not longer have access to a site like www.sex.com
,
www.xxx.com
, www.whitehouse.com/sex/
To limit access to Instant messaging systems, downloads and peer-to-peer software, Internet networking games, you can select the application in the pop-up list.
__________________________________________________________
11.5 Remote Management
Click on “Advanced” and select ”Remote Mgmt”:
Before accessing the router web user interface remotely, you need to activate this service and define an IP port.
Service configuration:
Operation: click on the « Start » option in the pop-up list to start this service. If the field « Status » is displaying « Start with …. », the service is already active. You can stop this service anytime by selection « Stop » in the pop­ up list.
Management Port: Specify the IP port you would like to address to access the router. (Please do not use port 80, it is the standard web port which is the target of many attacks).
Click on the « Apply » button to validate the parameters.
__________________________________________________________
NOTE / Do not forget to click on the « Save » link to store the complete configuration into the flash memory of the router.
Access your router from the Internet: In your favorite browser type “http://” followed by the WAN IP address of the router or its hostname if you activated the DynDNS service) “:” (followed by the port number). In our sample:
http://82.64.154.148:11000
or
http://claure.dynsdns.org:11000
NOTE / The text « http:// » is mandatory to inform the protocol used to access this port.
__________________________________________________________
11.6 - Scheduler
Click on “Advanced” and select ”Scheduler”:
This function enables to schedule access to internet for a user, a group of users or specific computers. Outside of the define period of time, the Internet access is allowed.
Days to Block: Specify the days to block or click on Everyday check box if you want to block everyday.
Time to block: Specify the beginning and ending time (24 Hours). All day will allow you to block the access from (de 00:00:00 to 23:59:59).
Loading...