All brand and product names mentioned in this manual are trademarks and/or registered trademarks of their
respective holders.
Federal Communication Commission Interference Statement
This equipment has been tested and found to comply with the limits for a Class B digital device, pursuant to Part 15 of FCC
Rules. These limits are designed to provide reasonable protection against harmful interference in a residential installation. This
equipment generates, uses, and can radiate radio frequency en ergy and, if not installed and used in accordance with the
instructions, may cause harmful interference to radio communications. However, there is no guarantee that interference w ill no t
occur in a particular installation. If this equipment does cause harmful interference to radio or television reception, which can be
determined by turning the equipment off and on, the user is encouraged to try to correct the interference by one or more of the
following measures:
1. Reorient or relocate the receiving antenna.
2. Increase the separation between the equipment and receiver.
3. Connect the equipment into an outlet on a circuit different from that to which the receiver is connected.
4. Consult the dealer or an experienced radio technician for help.
FCC Caution
To assure continued compliance. (example-use only shielded interface cables when connecting to computer or peripheral
devices). Any changes or modifications not expressly approved by the party responsible for compliance could void the user ’s
authority to operate the equipment.
This device complies with Part 15 of the FCC Rules. Operation is subject to the Following two conditions: ( 1 ) This device may
not cause harmful interference, and ( 2 ) this Device must accept any interference received, including interference that may
cause undesired operation.
Federal Communication Commission (FCC) Radiation Exposure Statement
This equipment complies with FCC radiation exposure set forth for an uncontrolled environment. In order to avoid the
possibility of exceeding the FCC radio frequency exposure limits, human proximity to the antenna shall not be less than 20 cm
2
(8 inches) during normal operation.
Safety
This equipment is designed with the utmost care for the safety of those who install and use it. Ho wever, special attention must
be paid to the dangers of electric shock and static electricity when working with electrical equipment. All guidelines of this and
of the computer manufacture must therefore be allowed at all times to ensure the safe use of the equipment.
EU Countries Not Intended for Use
The ETSI version of this device is intended for home and office use in Austria Belgium, Denmark, Finland, France (with
Frequency channel restrictions). Germany, Greece, Ireland, Italy, Luxembourg .The Netherlands, Portugal, Spain, Sweden and
United Kingdom.
The ETSI version of this device is also authorized for use in EFTA member states Iceland, Liechtenstein, Norway and
Switzerland.
WEEE regulation
To avoid the potential effects on the environment and human health as a result of the presence of
hazardous substances in electrical and electronic equipment, end users of electrical and electronic
equipment should understand the meaning of the crossed-out wheeled bin symbol. Do not dispose of
WEEE as unsorted municipal waste and have to collect such WEEE separately.
Revision
User’s Manual for PLANET Wireless LAN Switch
Model: WLS-1280
Rev: 1.0 (Oct, 2006)
Part No. EM-WLS1280
3
Table of Contents
1.Before You Start ............................................................................................................................3
3.1.3Panel Function Descriptions .........................................................................................................................9
4.1.5LAN Port Roles...........................................................................................................................................33
4.2.2Black List Configuration.............................................................................................................................57
4.4.3Monitor IP List..........................................................................................................................................101
4.4.4Walled Garden List ...................................................................................................................................102
4.4.5Proxy Server Properties ............................................................................................................................103
4.4.8VPN T erm ination......................................................................................................................................105
5. Appendix A – Console Interface...............................................................................................120
6. Appendix B – Network Configuration on PC..........................................................................123
7. Appendix C – IPSec VPN.........................................................................................................128
8. Appendix D –Proxy Setting for Hotspot...................................................................................133
9. Appendix E –Proxy Setting for Enterprise ..............................................................................136
10. Appendix F –Disclaimer for Users...........................................................................................141
ii
1. Before You Start
1.1 Preface
This manual is for Hotspot owners or administrators in enterprises to set up network environment using PLANET
WLS-1280. It contains step by step procedures and graphic examples to guide MIS staff or individuals with slight
network system knowledge to complete the installation.
1.2 Document Convention
yFor any caution or warning that requires special attention of readers, a highlight box with the eye-catchi ng ital ic
font is used as below:
Warning: For security purposes, you should immediately change the Administrator’s password.
Indicates that clicking this button will return to the homepage of this section.
Indicates that clicking this button will return to the previous page..
Indicates that clicking this button will apply all of your settings.
Indicates that clicking this button will clear what you set before these settings are applied.
2. System Overview
2.1 Introduction of PLANET WLS-1280
PLANET WLS-1280 is an all-in-one product specially designed for Hotspot wireless network environment. It
integrates “Access Control” and “Wireless Network Access” into one system to fulfill the needs in Hotspot
environment.
3
2.2 System Concept
PLANET WLS-1280 is specially designed for user aut hentication, a uthorization and man age m ent. The u ser account
information is stored in the local database or a specified external dat abases server. User authentication is processed
via the SSL encrypted web interface. This interface is com patible to most desktop device s and p alm computers. The
following figure is an example of PLANET WLS-1280 set to control a part of the company’s intranet. The whole
managed network includes the cable network users and the wireless network users.
4
2.3 Specification
2.3.1 Hardware Specification
yGeneral
Form Factor: Mini-desktop
Dimensions (W x D x H): 243 mm x 150 mm x 45.5 mm
Weight: 1.4 Kg
Operating Temperature: 0 ~ 45 oC
Storage Temperature: 0 ~ 65 oC
Power: 110~220 VAC, 50/60 Hz
Ethernet Interfaces: 10 x Fast Ethernet (10/100 Mbps)
yConnectors & Display
WAN Ports: 2 x 10BASE-T/100BASE-TX RJ-45
LAN Ports: 8 x 10BASE-T/100BASE-TX RJ-45
Console Port: 1 x RJ-11
LED Indicators: 1 x Power, 1 x Status, 2 x WAN, 8 x LAN
2.3.2 Technical Specification
yNetworking
Supports Router, NAT mode
Supports Static IP, DHCP, PPPoE on WAN interface
Configurable LAN ports authentication
Supports IP Plug and Play (IP PnP)
Built-in DHCP server and supports DHCP relay
Supports NAT:
1. IP/Port Destination Redirection
2. DMZ Server Mapping
3. Virtual Server Mapping
Supports static route
Supports SMTP redirection
Supports Wal l ed Garden (free surfing zone)
Supports MAC Address Pass-Through
Supports HTTP Proxy
Supports DoS attack protection
Supports user Black List
Allows user identity plus MAC address authentication for local accounts
yUser Management
Supports up to 120 concurrent users
Provides 500 local accounts
Provides 2000 on-demand accounts
Simultaneous support for multiple authentication methods (Local and On-demand accounts, POP3(S),
LDAP, RADIUS, NT Domain)
Role-based and policy-based access control (per-role assignments based on Firewall policies, Routing,
Login Schedule, Bandwidth)
Customizable login and logout portal page
User Session Management:
1. SSL protected login portal page
2. Supports multiple logins with one single account
3. Session idle timer
4. Session/account expiration control
5. Friendly notification email to provide a hyperlink to login portal page
6. Windows domain transparent login
7. Configurable login time frame
yAP Management
Supports up to 12 manageable IEEE 802.11 compliant APs
Centralized remote management via HTTP/SNMP interface
Automatic discovery of managed APs and list of managed APs
Allows administrators to add and delete APs from the device list
Allows administrators to enable or disable managed APs
Provides MAC Access Control List of client stations for each managed AP
Locally maintained configuration profiles of managed APs
Single UI for upgrading and restoring managed APs’ firmware
System status monitoring of managed APs and associated client stations
Automatic recovery of APs in case of system failure
System alarms and status reports on managed APs
yMonitoring and Reporting
Status monitoring of on-line users
IP-based monitoring of network devices
WAN connection failure alert
Syslog support for diagnosing and troubleshooting
User traffic history logging
yAccounting and Billing
6
Support for RADIUS accounting, RADIUS VSA (Vendor Specific Attribute s)
Built-in billing profiles for on-demand accounts
Enables session expiration control for on-demand accounts by time (hour) and data volume (MB)
Provides billing report on screen for on-demand accounts
Detailed per-user traffic history based on time and data volume for both local and on-demand accounts
Traffic history report in an automatic email to administrator
ySystem Administration
Multi-lingual, web-based management UI
SSH remote management
Remote firmware upgrade
NTP time synchronization
Backup and restore of system configuration
7
3. Base Installation
3.1 Hardware Installation
3.1.1 System Requirements
y Standa rd 10/100BaseT including five network cables with RJ-45 connectors
y All PCs need to install the TCP/IP network proto col
3.1.2 Package Contents
The standard package of PLANET WLS-1280 in cludes:
y PLANET WLS-1280 x 1
y CD-ROM x 1
y Quick Installation Guide x 1
y Power Adapter (DC 12V) x 1
y Cross Over Ethernet Cable x 1
y Console Cable x 1
Warning: It is highly recommended to use all the supplies in the package inste ad of sub stituting any com ponents by
other suppliers to guarantee best performance.
8
3.1.3 Panel Function Descriptions
Front Panel
y LED: There are four kinds of LED, PWR, Status, WAN and LAN LED, to indicate different status of the system.
y WAN1/WAN2: The two WAN ports are connected to a network which is not managed by PLANET WLS-1280
system, and this port can be used to connect the ATU-Router of ADSL, the port of Cable Modem, or the Switch
or Hub on the LAN of a company. WAN2 doesn’t support load balance with WAN1
yLAN1~LAN8: Client machines connect to PLANET WLS-1280 via LAN ports. Each LAN port can be configured
to one of two roles, controlled or uncontrolled. The differences of these two roles for a client connected to are:
¾ Clients connected to controlled port to need authentication to access network.
¾ Clients connected to uncontrolled port can access the web management interfa c e.
Rear Panel
9
y Reset: Press this button to restart the system.
y Console: The system can be configured via serial console port. An administrator can use terminal emulation
program such as Microsoft’s HyperTerminal to login to the configuration console interface to change admin
password or monitor syste m status, etc.
yDC+12V: The power adapter attaches here.
3.1.4 Installation Steps
Please follow the following steps to install PLANET WLS-1280:
1. Connect the 12V DC power adapter to the power connector socket on the rear panel. The Power LED should be
on to indicate a proper connection.
2. Connect an Ethernet cable to the WAN1 Port on the front panel. Connect the other end of the Ethernet cable to
ADSL modem, cable modem or a switch/hub of the internal network. The LED of WAN1 port should be on to
indicate a proper connection.
3. Connect an Ethernet cable to one of the LAN5~LAN8 Port on the front panel. Connect the other end of the
Ethernet cable to a client’s PC. The LED of the connected port should be on to indicate a pro per connection.
(Note: The default role of these four ports is Uncontrolled Port.)
4. Connect an Ethernet cable to one of the LAN1~LAN4 Port on the front panel. Connect the other end of the
Ethernet cable to a client PC, AP or switch in manag e d network. The LED of the connected port should be o n to
indicate a proper connection. (Note: The default role of these four ports is Controlled Port.)
Attention:
1. PLANET WLS-1280 supports Auto Sensing MDI/MDIX. You may use either straight through or cross over cable
to connect the Ethernet Port.
2. Usually a straight cable could be applied when PLANE T WLS -1280 connect s to a n Access Point which supports
10
automatic crossover. If af ter the AP hardware resets, PLANET WL S-1280 could not be able to co nnect to t he AP
while connecting with a straight cable, the user have to pull out and plug-in the straight cable again. This
scenario does NOT occur while using a cros sover cable.
After the hardware of PLANET WLS-1280 is installed completely, t he system is ready to be configured in the
following sections.
11
3.2 Software Configuration
3.2.1 Quick Configuration
There are two ways to configure the system: using Configuration Wizard or change the setting by demands
manually. The Configuration Wizard has 6 steps providing a simple and easy way to guide you through the setup of
PLANET WLS-1280. Follow the procedures and instructions given by the Wizard to enter the required information
step by step. After saving and re sta rting PLANET WLS-128 0, it is ready to use. There will be 6 steps as listed belo w:
1. Change Admin’s Password
2. Choose System’s Time Zone
3. Set System Information
4. Select the Connection Type for WAN Port
5. Set Authentication Methods
6. Save and Restart PLANET WLS-1280
Please follow the following steps to complete the quick configuration.
1. Use the network cable of the 10/100BaseT to connect a PC to the uncontrolled port, and then start a browser
(such as Microsoft IE or Firefox). Next, enter the gateway IP address as the web management interfa ce’s URL,
the default is
default username and password, in the User Name and Password column. Click Enter to log in.
https://192.168.2.254. In the opened webpage, you will see the login screen. Enter “admin”, the
Caution :If you can’t get the login screen, the reasons may be: 1. The PC is set incorrectly so that the PC can’t obtain the
IP address automatically from the LAN port; 2. The IP address and the default gateway are not under the same network
segment. Please use default IP address such as 192.168.2.xx in your network and then try it again. For the PC
configuration on PC, please refer to 6. Appendix B – Network Configuration on PC.
12
PLANET WLS-1280 supports three kinds of account interface. You can log in as admin, manager or operator. The
default username and password as follows.
Admin: The administrator can access all area of PLANET WLS-1280.
User Name: admin
Password: admin Manager: The manager can access the area under User Authentication to manage the user account, but no
permission to change the settings of the profiles of Firewall, Specific Route and Schedule.
User Name: manager
Password: manager Operator: The operator can only access the area of Create On-demand User to create and print out the new
on-demand user accounts.
User Name: operator
Password: operator
2. After successfully logging into PLANET WLS-1280, enter the web management interface and see the welcome
screen. There is a Logout button on the upper right corner to log out the system when finished.
3.Then, run the configuration wizard to complete the configuration. ClickSystem Configuration to the System
Configuration homepage.
13
4. Click the System Configuration from the top menu and the homepage of System Configuration will appear.
Then, click on Configuration Wizard and click the Run Wizard button to start the wizard.
14
5. Configuration Wizard
A welcome screen that briefly introduces the 6 steps will appear. Click Next to begin.
yStep 1. Change Admin’s Password
Enter a new password for the admin account and retype it in the verify password field (twenty-character
maximum and no spaces).
Click Next to continue.
15
yStep 2. Choose System’s Time Zone
Select a proper time zone via the drop-down menu.
Click Next to continue.
yStep 3. Set System Information
Home Page: Enter the URL to where the users should be directed when they are successfully
authenticated.
NTP Server: Enter the IP address or do main name of external time server for PLANET WLS-1280 time
synchronization or use the default.
DNS Server: Enter a DNS Server provided by the ISP (Internet Service Provider). Contact the ISP if the
DNS IP Address is unknown.
Click Next to continue.
16
yStep 4. Select the Connection Type for WAN Port
Three are three types of WAN1 port to select in wizard: Static IP Address, Dynamic IP Address and PPPoE Client.
Select a proper Internet connection type and click Next to continue.
¾Static IP Address: Set WAN Port’s Static IP Address
Enter the “IP Address”, “Subnet Mask” and “Default Gateway” provided by your ISP or network
administrator.
Click Next to continue.
¾Dynamic IP Address
If this option is selected, PLANET WLS-1280 will obtain IP settings from external DHCP server on
network connected by WAN1 automatically.
Click Next to continue.
17
¾PPPoE Client: Set PPPoE Client’s Information
Enter the “Username” and “Password” provided by the ISP.
Click Next to continue.
yStep 5. Set Authentication Methods
Set the user’s information in advance. Enter an easily identified name as the postfix name in the Postfix
field (e.g. Local), select a policy to assign to, and choose an authentication method.
Click Next to continue. Different information has to be provided for each kind of authentication method:
18
¾Local User: Add User
A new user can be added to the local user data base. To add a user here, enter the Username (e.g.
test), Password (e.g. test), MAC (optional, to specify the valid MAC address of this user) and assign it
a policy (or use the default). Click the ADD button to add the user..
Attention: The policy selected in this step is applied to this user only.
Per-user policy setting take over the group polic y setting at precious step
unless you select None here. Click Next to continue.
¾POP3 User: POP3
Enter IP/Domain Name and server port of the POP3 server provided by the ISP, and then choose
enable SSL or not.
Click Next to continue.
19
¾RADIUS User: RADIUS
Enter RADIUS server IP/Domain Name, authentication port, accounting port and secret key. Then
choose to enable accounting service or not, and choose the desired authentication method.
Click Next to continue.
¾LDAP User: LDAP
Configure external LDAP user data base here. Enter the “LDAP Server”, “Server Port”, “Base DN”
and “Account Attribute”.
Click Next to continue.
20
¾NT Domain User: NT Domain
When NT Domain User is selected, enter the information for “Server IP Address”, and choose to
enable/disable “Transparent Login”.
If “Transparent Login ” is enabled, users are l ogged in PLANET WL S-1280’ s NT Domai n active directory
and authenticated automatically when they log into their Windows OS domain.
Click Next to continue.
yStep 6. Save and Restart PLANET WLS-1280
Click Restart to save the current settings and restart PLANET WLS-1280. The Setup Wizard is now
completed.
ySetup Wizard. During PLANET WLS-1280 re start, a “Rest arting no w. Pleas e wait for a while.” message
will appear on the screen. Please do not interrupt PLANET WLS-1280 until the message has disappeared.
This indicates that a complete and successful restart process has finished.
21
Caution: During every step of the wizard, if you wish to go back to modify the settings, please click the Back
button to go back to the previous step.
3.2.2 User Login Portal Page
To login from the login portal p age via the co ntrolled port, the user h ave to be identified the user na me and p assword.
The administrator also can verify the correctness of the configuration steps of PLANET WLS-1280.
1. First, connect a user-end device (for example, a PC) to the controlled port of PLANET WLS-1280, and set the
device to obtain IP address automatically. After the client obtains the network address, please open up an
Internet browser and the default login webpage will appear on the Internet browser.
Enter a valid user name and password. Assumeing local user database is chose n in the configuration wizard,
enter the username and password created and then click Submit button (e.g. test@Local for the username and test for the password).
2. Login succeed page will appear if PLANET WLS-1280 has been installed and configured successfully. Now,
clients can browse the network or surf the Internet.
22
3. If the screen shows “Sorry, this feature is available for on-demand user only ”, it means that the
“Remaining” button has been clicked. This button is only for on-demand use rs only. For clients other than
on-demand users, please click the Submit button.
4. An on-demand user can enter the username and password in the “User Login Page” and click the Remaining
button to view the remaining time the account.
5. When an on-demand user logs in successfully, the following Login Successfully screen will appear. There is
an extra line showing “Remaining usage” and a “Redeem” button.
23
yRemaining usage: Show the remaining time or data volume that the on-demand user can use to surf
Internet.
yRedeem: When the remaining time or data size is insufficient, the client has to pay for adding credit at the
counter, and then, the clie nt will get a new username and password. After clicking the Redeem button, a
login screen will appear . Please enter the new username and password obtained and click Redeem button.
The total available use time and data size after adding credit will show up.
4. Web Interface Configuration
This chapter will guide you through further detailed settings. The following table is the UI and functions of PLANET
WLS-1280.
OPTION
System
Configuration
Configuration
FUNCTION
Wizard
System
Information
WAN1
Configuration
WAN2 &
Failover
User
Authentication
Authentication
Configuration
Black List
Configuration
Policy
Configuration
Additional
Configuration
AP
Management
AP List
AP Discovery Privilege List
Manual
Configuration
Template
Settings
Network
Configuration
Network
Address
Translation
Monitor IP List
Walled Garden
List
Utilities Status
Change
System Status
Password
Backup/Restore
Interface Status
Settings
Firmware
Current Users
Upgrade
Restart Traffic History
LAN Port Roles
Controlled
Configuration
Uncontrolled
Configuration
Firmware
Management
AP Upgrade Dynamic DNS
IP Mobility
24
Proxy Server
Properties
Notification
Configuration
VPN
Termination
Caution: After finishing the configuration of the settings, please click Apply and pay attention to see if a
restart message appears on the screen. If such message appears, system m ust be restarted to allow the
settings to take effect. All on-line users will be disconnected during restart.
25
4.1 System Configuration
This section includes the following functions: Configuration Wizard, System Information, WAN1 Configuration,
WAN2 & Failover, LAN Port Role s, Controlled Configuration and Uncontrolled Configuration.
4.1.1 Configuration Wizard
There are two ways to configure the system: using Configuration Wizard or change the setting by demands
manually. The Configuration Wizard has 6 steps providing a simple and easy way to go through the basic setups of
PLANET WLS-1280 and is served as Quick Configuration. Please refer to 3.2.2 Quick Configuration for the
introduction and description of Configuration Wizard.
26
4.1.2 System Information
Most of the major system information about PLANET WLS-1280 can be set here. Please refer to the following
description for each field:
y System Name: Set the system’s name or use the default.
y Device Name: Enter an identifiable name for this device.
y Home Page: Enter the website of a Web Server to be the homepage. When users log in successfully, they will
be directed to the homepage set. Usually, the homepage is the company’s website, such as
http://www.yahoo.com. Regardl ess of the original webpage set in the users’ computers, they will be redirect to
this page after login.
yAccess History IP: Specify an IP address of the administrator’s computer or a billing system to get billing
history information of PLANET WLS-1280 with fix format URLs.
Traffic Hist o ry :
https://10.2.3.213/status/history/2005-02-17
27
Loading...
+ 122 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.