TP Link WR842ND Users Guide

TL-WR842ND
300Mbps Multi-Function Wireless N Router
Rev: 1.0.0
1910010537
COPYRIGHT & TRADEMARKS
Specifications are subject to change without notice. is a registered trademark of TP-LINK TECHNOLOGIES CO., LTD. Other brands and product names are trademarks or registered trademarks of their respective holders.
No part of the specifications may be reproduced in any form or by any means or used to make any derivative such as translation, transformation, or adaptation without permission from TP-LINK TECHNOLOGIES CO., LTD. Copyright © 2011 TP-LINK TECHNOLOGIES CO., LTD. All rights reserved.
http://www.tp-link.com
FCC STATEMENT
This equipment has been tested and found to comply with the limits for a Class B digital device, pursuant to part 15 of the FCC Rules. These limits are designed to provide reasonable protection against harmful interference in a residential installation. This equipment generates, uses and can radiate radio frequency energy and, if not installed and used in accordance with the instructions, may cause harmful interference to radio communications. However, there is no guarantee that interference will not occur in a particular installation. If this equipment does cause harmful interference to radio or television reception, which can be determined by turning the equipment off and on, the user is encouraged to try to correct the interference by one or more of the following measures:
Reorient or relocate the receiving antenna.
Increase the separation between the equipment and receiver.
Connect the equipment into an outlet on a circuit different from that to which the receiver
is connected.
Consult the dealer or an experienced radio/ TV technician for help.
This device complies with part 15 of the FCC Rules. Operation is subject to the following two conditions:
1) This device may not cause harmful interference.
2) This device must accept any interference received, including interference that may cause undesired operation.
Any changes or modifications not expressly approved by the party responsible for compliance could void the user’s authority to operate the equipment.
Note: The manufacturer is not responsible for any radio or tv interference caused by unauthorized modifications to this equipment. Such modifications could void the user’s authority to operate the equipment.
For operation within 5.15-5.25GHz frequency range, it is restricted to indoor environment.
For products in the USA market, only channel 1-11 can be operated.
FCC RF Radiation Exposure Statement
This equipment complies with FCC RF radiation exposure limits set forth for an uncontrolled environment. This device and its antenna must not be co-located or operating in conjunction with any other antenna or transmitter.
“To comply with FCC RF exposure compliance requirements, this grant is applicable to only Mobile Configurations. The antennas used for this transmitter must be installed to provide a separation distance of at least 20 cm from all persons and must not be co-located or operating in conjunction with any other antenna or transmitter.”
CE Mark Warning
This is a Class B product. In a domestic environment, this product may cause radio interference, in which case the user may be required to take adequate measures.
National restrictions
This device is intended for home and office use in all EU countries (and other countries following the EU directive 1999/5/EC) without any limitation except for the countries mentioned below:
Country Restriction Reason/remark
Bulgaria None
Outdoor use limited to 10
France
Italy None
Luxembourg None
mW e.i.r.p. within the band
2454-2483.5 MHz
General authorization required for outdoor use and
public service
Military Radiolocation use. Refarming of the 2.4 GHz
band has been ongoing in recent years to allow current
relaxed regulation. Full implementation planned 2012
If used outside of own premises, general authorization is
required
General authorization required for network and service
supply(not for spectrum)
Norway Implemented
Russian Federation None Only for indoor applications
Note: Please don’t use the product outdoors in France.
This subsection does not apply for the geographical area
within a radius of 20 km from the centre of Ny-Ålesund
This device has been designed to operate with the antennas listed below, and having a maximum gain of 5 dBi. Antennas not included in this list or having a gain greater than 5 dBi are strictly prohibited for use with this device. The required antenna impedance is 50 ohms.
To reduce potential radio interference to other users, the antenna type and its gain should be so chosen that the equivalent isotropically radiated power (e.i.r.p.) is not more than that permitted for successful communication.
TP-LINK TECHNOLOGIES CO., LTD
DECLARATION OF CONFORMITY
For the following equipment:
Product Description: 300Mbps Multi-Function Wireless N Router
Model No.: TL-WR842ND
Trademark: TP-LINK
We declare under our own responsibility that the above products satisfy all the technical regulations applicable to the product within the scope of Council Directives:
Directives 1999/5/EC
The above product is in conformity with the following standards or other normative documents
EN 300 328 V1.7.1: 2006
EN 301 489-1 V1.8.1:2008& EN 301 489-17 V2.1.1:2009
Recommendation 1999/519/EC
EN62311:2008
Directives 2004/108/EC
The above product is in conformity with the following standards or other normative documents
EN 55022:2006 +A1:2007
EN 55024:1998+A1:2001+A2:2003
EN 61000-3-2:2006+A1:2009+A2:2009
EN 61000-3-3:2008
Directives 2006/95/EC
The above product is in conformity with the following standards or other normative documents
EN60950-1:2006+A11:2009 +A1:2010
Person is responsible for marking this declaration:
Yang Hongliang Product Manager of International Business
TP-LINK TECHNOLOGIES CO., LTD.
South Building, No.5 Keyuan Road, Central Zone, Science & Technology Park, Nanshan,
Shenzhen, P. R. China
CONTENTS
Package Contents.....................................................................................................1
Chapter 1. Introduction.........................................................................................2
1.1 Overview of the Router............................................................................................... 2
1.2 Conventions ...............................................................................................................3
1.3 Main Features ............................................................................................................3
1.4 Panel Layout ..............................................................................................................4
1.4.1 The Front Panel.............................................................................................. 4
1.4.2 The Rear Panel ..............................................................................................5
Chapter 2. Connecting the Router .......................................................................7
2.1 System Requirements ................................................................................................7
2.2 Installation Environment Requirements...................................................................... 7
2.3 Connecting the Router ...............................................................................................7
Chapter 3. Quick Installation Guide..................................................................... 9
3.1 TCP/IP Configuration ................................................................................................. 9
3.2 Quick Installation Guide ...........................................................................................10
Chapter 4. Configuring the Router ....................................................................19
4.1 Login ........................................................................................................................ 19
4.2 Status .......................................................................................................................19
4.3 Quick Setup.............................................................................................................. 20
4.4 WPS......................................................................................................................... 21
4.5 Network.................................................................................................................... 23
4.5.1 WAN ............................................................................................................. 23
4.5.2 LAN ..............................................................................................................33
4.5.3 MAC Clone ................................................................................................... 34
4.6 Wireless ...................................................................................................................35
4.6.1 Wireless Settings.......................................................................................... 35
4.6.2 Wireless Security.......................................................................................... 38
4.6.3 Wireless MAC Filtering................................................................................. 42
4.6.4 Wireless Advanced....................................................................................... 44
4.6.5 Wireless Statistics......................................................................................... 45
4.7 DHCP.......................................................................................................................46
4.7.1 DHCP Settings .............................................................................................46
- I -
4.7.2 DHCP Clients List......................................................................................... 47
4.7.3 Address Reservation .................................................................................... 48
4.8 VPN.......................................................................................................................... 49
4.8.1 IKE................................................................................................................ 49
4.8.2 IPsec ............................................................................................................51
4.8.3 Security Alliance List..................................................................................... 53
4.9 USB Settings............................................................................................................ 54
4.9.1 Storage Sharing............................................................................................ 54
4.9.2 FTP Server ................................................................................................... 56
4.9.3 Media Server ................................................................................................ 57
4.9.4 Print Server...................................................................................................60
4.9.5 User Accounts .............................................................................................. 61
4.10 Forwarding ............................................................................................................... 63
4.10.1 Virtual Servers.............................................................................................. 63
4.10.2 Port Triggering.............................................................................................. 65
4.10.3 DMZ.............................................................................................................. 67
4.10.4 UPnP ............................................................................................................ 67
4.11 Security ....................................................................................................................69
4.11.1 Basic Security...............................................................................................69
4.11.2 Advanced Security........................................................................................ 70
4.11.3 Local Management ....................................................................................... 72
4.11.4 Remote Management ...................................................................................73
4.12 Parental Control ....................................................................................................... 74
4.13 Access Control......................................................................................................... 77
4.13.1 Rule .............................................................................................................. 77
4.13.2 Host .............................................................................................................. 83
4.13.3 Target............................................................................................................ 84
4.13.4 Schedule....................................................................................................... 87
4.14 Advanced Routing.................................................................................................... 88
4.14.1 Static Routing List......................................................................................... 89
4.14.2 System Routing Table................................................................................... 90
4.15 Bandwidth Control.................................................................................................... 91
4.15.1 Control Settings............................................................................................91
4.15.2 Rules List...................................................................................................... 91
4.16 IP & MAC Binding Setting ........................................................................................ 93
4.16.1 Binding Settings............................................................................................ 93
- II -
4.16.2 ARP List........................................................................................................95
4.17 Dynamic DNS...........................................................................................................95
4.17.1 Comexe.cn DDNS ........................................................................................ 96
4.17.2 Dyndns.org DDNS ........................................................................................ 97
4.17.3 No-ip.com DDNS .......................................................................................... 98
4.18 System Tools............................................................................................................ 99
4.18.1 Time Setting..................................................................................................99
4.18.2 Diagnostic................................................................................................... 101
4.18.3 Firmware Upgrade...................................................................................... 102
4.18.4 Factory Defaults .........................................................................................104
4.18.5 Backup & Restore....................................................................................... 104
4.18.6 Reboot........................................................................................................ 105
4.18.7 Password.................................................................................................... 105
4.18.8 System Log................................................................................................. 106
4.18.9 Statistics .....................................................................................................108
Appendix A: FAQ .................................................................................................. 111
Appendix B: Configuring the PCs....................................................................... 117
Appendix C: Specifications .................................................................................120
Appendix D: Glossary .......................................................................................... 121
- III -
TL-WR842ND 300Mbps Multi-Function Wireless N Router

Package Contents

The following items should be found in your package:
¾ TL-WR842ND 300Mbps Multi-Function Wireless N Router
¾ DC Power Adapter for TL-WR842ND 300Mbps Multi-Function Wireless N Router
¾ Quick Installation Guide
¾ Resource CD for TL-WR842ND 300Mbps Multi-Function Wireless N Router, including:
This Guide
Other Helpful Information
Note:
)
Make sure that the package contains the above items. If any of the listed items are damaged or missing, please contact your distributor.
- 1 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router

Chapter 1. Introduction

Thank you for choosing the TL-WR842ND 300Mbps Multi-Function Wireless N Router.

1.1 Overview of the Router

The TL-WR842ND 300Mbps Multi-Function Wireless N Router integrates 4-port Switch, Firewall, NAT-Router and Wireless AP. Powered by 2x2 MIMO technology, the 300Mbps Multi-Function Wireless N Router delivers exceptional range and speed, which can fully meet the need of Small Office/Home Office (SOHO) networks and the users demanding higher networking performance. Additionally, the TL-WR842ND provides a USB port which supports storage/FTP/Media/Print Server.
The TL-WR842ND 300Mbps Multi-Function Wireless N Router provides up to 300Mbps wireless connection with other 802.11n wireless clients. The incredible speed makes it ideal for handling multiple data streams at the same time, which ensures your network stable and smooth. The performance of this 802.11n wireless Router will give you the unexpected networking experience at speed much faster than 802.11g. It is also compatible with all IEEE 802.11g and IEEE 802.11b products.
Multiple Security Protections
With multiple protection measures, including SSID broadcast control and wireless LAN 64/128/152-bit WEP encryption, Wi-Fi Protected Access (WPA2- PSK, WPA- PSK), as well as advanced Firewall protections, the TL-WR842ND 300Mbps Multi-Function Wireless N Router provides complete data privacy.
The TL-WR842ND 300Mbps Multi-Function Wireless N Router provides flexible access control, so that parents or network administrators can establish restricted access policies for children or staff. It also supports Virtual Server and DMZ host for Port Triggering, and then the network administrators can manage and monitor the network in real time with the remote management function.
Incredible Speed
Flexible Access Control
Simple Installation
Since the Router is compatible with virtually all the major operating systems, it is very easy to manage. Quick Setup Wizard is supported and detailed instructions are provided step by step in this user guide. Before installing the Router, please look through this guide to know all the Router’s functions.
- 2 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router

1.2 Conventions

The Router or TL-WR842ND mentioned in this guide stands for TL-WR842ND 300Mbps Multi-Function Wireless N Router without any explanation.

1.3 Main Features

¾ Complies with IEEE 802.11n to provide a wireless data rate of up to 450Mbps.
¾ One 10/100M Auto-Negotiation RJ45 Internet port, four 10/100M Auto-Negotiation RJ45 LAN
ports, supporting Auto MDI/MDIX.
¾ Provides USB Port supporting storage/FTP/Media/Print Server.
¾ Provides WPA/WPA2, WPA-PSK/WPA2-PSK authentication, TKIP/AES encryption security.
¾ Up to 5 VPN tunnels enable remote VPN connections.
¾ Up to 4 SSIDs support multiple wireless networks with different SSIDs and passwords.
¾ Shares data and Internet access for users, supporting Dynamic IP/Static IP/PPPoE Internet
access.
¾ Supports Virtual Server, Special Application and DMZ host.
¾ Supports UPnP, Dynamic DNS, Static Routing.
¾ Provides Automatic-connection and Scheduled Connection on certain time to the Internet
¾ Built-in NAT and DHCP server supporting static IP address distributing.
¾ Supports Parental Control and Access Control.
¾ Connects Internet on demand and disconnects from the Internet when idle for PPPoE.
¾ Provides 64/128/152-bit WEP encryption security and wireless LAN ACL (Access Control
List).
¾ Supports Flow Statistics.
¾ Supports firmware upgrade and Web management.
- 3 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router

1.4 Panel Layout

1.4.1 The Front Panel

Figure 1-1 Front Panel sketch
The Router’s LEDs are located on the front panel (View from left to right).
Name Status Indication
The device has a system error.
The device is initialising.
There is a device linked to the corresponding port but there is no activity.
A wireless device is connecting to the network by WPS function. This process will last in the first 2 minutes.
A wireless device has been successfully added to the network by WPS function.
A wireless device failed to be added to the network by WPS function.
SYS
(Wireless)
(LAN 1-4) (Internet)
(USB)
(WPS)
Off
On
Flashing The device is working properly.
Off The wireless function is disabled.
Flashing The wireless function is enabled.
Off There is no device linked to the corresponding port.
On
Flashing There is an active device linked to the corresponding port.
Off No storage device or printer is plugged into the USB port. On A storage device or printer has connected to the USB port.
Slow Flash
On
Quick Flash
Table 1-1 The LEDs Description
- 4 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Note:
)
After a device is successfully added to the network by WPS function, the WPS LED will keep on for about 5 minutes and then turn off.

1.4.2 The Rear Panel

Figure 1-2 Rear Panel sketch
The following parts are located on the rear panel (View from left to right).
¾ POWER: The Power socket is where you will connect the power adapter. Please use the
power adapter provided with this TL-WR842ND 300Mbps Multi-Function Wireless N Router.
¾ WAN: This port is where you will connect the DSL/cable Modem, or Ethernet.
¾ 1,2,3,4 (LAN): These ports (1, 2, 3, 4) connect the Router to the local PC(s).
¾ USB: The USB port connects to a USB storage device or a USB printer.
¾ WPS/RESET: Press this button to quickly establish a connection between the Router and
client devices that support Wi-Fi Protected Setup. Press and hold this button for more than 5 seconds (approximately 8 seconds) to reset the Router.
There are two ways to reset to the Router's factory defaults:
1) Use the Factory Defaults function on “System Tools Factory Defaults” page in the Router's Web-based Utility.
- 5 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
2) Use the Factory Default WPS/RESET button: With the Router powered on, use a pin to press and hold the WPS/RESET button (approximately 8 seconds) until the SYS LED becomes quick-flash from slow-flash. And then release the button and wait the Router to reboot to its factory default settings.
¾ WIFI ON/OFF: Press this button to enable or disable Wi-Fi.
¾ Wireless antenna: To receive and transmit the wireless data.
- 6 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router

Chapter 2. Connecting the Router

2.1 System Requirements

¾ Broadband Internet Access Service (DSL/Cable/Ethernet)
¾ One DSL/Cable Modem that has an RJ45 connector (which is not necessary if the Router is
connected directly to the Ethernet.)
¾ PCs with a working Ethernet Adapter and an Ethernet cable with RJ45 connectors
¾ TCP/IP protocol on each PC
¾ Web browser, such as Microsoft Internet Explorer, Mozilla Firefox or Apple Safari

2.2 Installation Environment Requirements

¾ Place the Router in a well ventilated place far from any heater or heating vent
¾ Avoid direct irradiation of any strong light (such as sunlight)
¾ Keep at least 2 inches (5 cm) of clear space around the Router
¾ Operating Temperature: 0~40 (32~104℉)
¾ Operating Humidity: 10%~90%RH, Non-condensing

2.3 Connecting the Router

Before installing the Router, make sure your PC is connected to the Internet through the broadband service successfully. If there is any problem, please contact your ISP. After that, please install the Router according to the following steps. Don't forget to pull out the power plug and keep your hands dry.
1. Power off your PC, Cable/DSL Modem, and the Router.
2. Locate an optimum location for the Router. The best place is usually at the center of your wireless network.
3. Adjust the direction of the antenna. Normally, upright is a good direction.
4. Connect the PC(s) and each Switch/Hub in your LAN to the LAN Ports on the Router, shown in Figure 2-1. (If you have the wireless NIC and want to use the wireless function, you can skip this step.)
5. Connect the DSL/Cable Modem to the Internet port on the Router, shown in Figure 2-1.
- 7 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Note:
)
If you want to use the Router to share files or printer, plug the USB storage device to the USB port or connect the printer to the Router with a matching cable.
6. Connect the power adapter to the power socket on the Router, and the other end into an electrical outlet. The Router will start to work automatically.
7. Power on your PC and Cable/DSL Modem.
Figure 2-1 Hardware Installation
- 8 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router

Chapter 3. Quick Installation Guide

This chapter will show you how to configure the basic functions of your 300Mbps Multi-Function Wireless N Router using Quick Setup Wizard within minutes.

3.1 TCP/IP Configuration

The default domain name of the Router is http://tplinklogin.net and the default Subnet Mask is
255.255.255.0. These values can be changed as you desire. In this guide, we use all the default
values for description.
Connect the local PC to the LAN ports of the Router and then you can configure the IP address for your PC by the following method: Set up the TCP/IP Protocol in "Obtain an IP address automatically" mode on your PC. If you need instructions as to how to do this, please refer to
Appendix B: "Configuring the PC”.
PC.
Now, you can run the Ping command in the command prompt to verify the network connection between your PC and the Router. The following example is in Windows 2000 OS.
Open a command prompt, and type ping 192.168.0.1, and then press Enter.
¾ If the result displayed is similar to the Figure 3-1, it means the connection between your PC
and the Router has been established well.
Then the built-in DHCP server will assign IP address for the
Figure 3-1 Success result of Ping command
- 9 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
¾ If the result displayed is similar to Figure 3-2, it means the connection between your PC and
the Router failed.
Figure 3-2 Failure result of Ping command
Please check the connection following these steps:
1. Is the connection between your PC and the Router correct?
Note:
)
The 1/2/3/4 LEDs of LAN ports which you link to on the Router and LEDs on your PC's adapter should be lit.
2. Is the TCP/IP configuration for your PC correct?
)
If the Router's IP address is 192.168.0.1, your PC's IP address must be within the range of
192.168.0.2 ~ 192.168.0.254.
3. Is the default LAN IP of the Router correct?
Note:
) Note:
If the LAN IP of the modem connected with your router is 192.168.0.x, the default LAN IP of the Router will automatically switch from 192.168.0.1 to 192.168.1.1 to avoid IP conflict. Therefore, in order to verify the network connection between your PC and the Router, you can open a command prompt, and type ping 192.168.1.1, and then press Enter.

3.2 Quick Installation Guide

With a Web-based utility, it is easy to configure and manage the 300Mbps Multi-Function Wireless N Router. The Web-based utility can be used on any Windows, Macintosh or UNIX OS with a web browser, such as Microsoft Internet Explorer, Mozilla Firefox or Apple Safari. However, as the USB
- 10 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Settings interface may not be opened with some web browsers, it is strongly recommended that you use Internet Explorer.
1. To access the configuration utility, open a web-browser and type in the default domain name
http://tplinklogin.net
in the address field.
Figure 3-3 Log in the Router
After a moment, a login window will appear, similar to Figure 3-4. Enter admin for the User Name and Password, both in lower case letters. Then click the OK button or press the Enter key.
Figure 3-4 Login Windows
Note:
)
If the above screen does not pop up, it means that your Web-browser has been set to a proxy. Go to Tools menu>Internet Options>Connections>LAN Settings, in the screen that appears, cancel the Using Proxy checkbox, and click OK to finish it.
2. After successfully logging in, you can click the Quick Setup menu to quickly configure your Router.
- 11 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 3-5 Quick Setup
3. Click Next, and then WAN Connection Type page will appear as shown in Figure 3-6.
Figure 3-6 WAN Connection Type
The Router provides Auto-Detect function and supports three popular ways PPPoE, Dynamic IP and Static IP to connect to the Internet. It’s recommended that you make use of the Auto-Detect function. If you are sure of what kind of connection type your ISP provides, you can select the very type and click Next to go on configuring.
4. If you select Auto-Detect, the Router will automatically detect the connection type your ISP provides. Make sure the cable is securely plugged into the WAN port before detection. The appropriate configuration page will be displayed when an active Internet service is successfully detected by the Router.
1) If the connection type detected is PPPoE, the next screen will appear as shown in Figure
3-7.
- 12 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 3-7 Quick Setup - PPPoE
¾ User Name/Password - Enter the User Name and Password provided by your ISP.
These fields are case-sensitive. If you have difficulty with this process, please contact your ISP.
¾ Confirm Password - Enter the password again to make sure that the password is
correct.
2) If the connection type detected is Dynamic IP, the next screen will appear as shown in
Figure 3-8.
Figure 3-8 Quick Setup – MAC Clone
A MAC address is a 12-digit code assigned to a unique piece of hardware for identification. Some ISPs will register the MAC address of your computer when you access the Internet for the first time via the cable/ADSL modem they offered. If you add a router into your network to share the Internet, the ISP may not recognize the new MAC address of the router and will not offer the Internet connection any more. Therefore, it is necessary to clone the MAC address of the computer to the router.
z If you are visiting the Router from the main computer, please select Yes, and then click
Clone MAC Address.
- 13 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 3-9 Quick Setup – MAC Clone
z If you are visiting the Router from another computer, rather than the main computer,
please select No, and then enter the main computer’s MAC in the field WAN MAC Address.
Figure 3-10 Quick Setup – MAC Clone
Note:
)
1. It’s strongly recommended that you visit and configure the Router from the main computer.
2. To find the main computer’s MAC, please go to Start > Run on your main computer, type in cmd and press Enter. At the command prompt, enter ipconfig/all and press Enter. The MAC will be displayed under Physical Address.shown in the following figure
- 14 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 3-11 Find MAC Address
3) If the connection type detected is Static IP, the next screen will appear as shown in Figure 3-12.
Figure 3-12 Quick Setup - Static IP
¾ IP Address - This is the WAN IP address as seen by external users on the Internet
(including your ISP). Your ISP will provide you with the IP address you need to enter here. Enter the IP address into the field.
¾ Subnet Mask - The Subnet Mask is used for the WAN IP address. Your IPS will provide
you with the subnet mask which is usually 255.255.255.0.
¾ Default Gateway - Your ISP will provide you with the Gateway address which is the ISP
server’s address. Enter the gateway IP address into the box if required.
¾ Primary DNS - Enter the DNS Server IP address into the box if required.
- 15 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
¾ Secondary DNS - If your ISP provides another DNS server, enter it into this field.
5. Click Next to continue, the Wireless settings page will appear as shown in Figure 3-13.
Figure 3-13 Quick Setup – Wireless
¾ Wireless Radio - Choose from the drop-down list to enable or disable the wireless
radio.
¾ Wireless Network Name - Also called the SSID (Service Set Identification). Enter a
value of up to 32 characters. The same name must be assigned to all wireless devices in your network. Considering your wireless network security, the default SSID is set to be TP-LINK_XXXXXX (XXXXXX indicates the last unique six numbers of each Router’s MAC address). This value is case-sensitive. For example, TEST is NOT the same as test.
¾ Region - Select your region from the drop-down list. This field specifies the region
where the wireless function of the Router can be used. It may be illegal to use the wireless function of the Router in a region other than one of those specified in this field. If your country or region is not listed, please contact your local government agency for assistance.
) Note:
Limited by local law regulations, version for North America does not have region selection option.
- 16 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
¾ Channel - This field determines which operating frequency will be used. It is not
necessary to change the wireless channel unless you notice interference problems with another nearby access point. If you select auto, then the AP will select the best channel automatically.
¾ Mode - This field determines the wireless mode which the Router works on.
11b only - Select if all of your wireless clients are 802.11b.
11g only - Select if all of your wireless clients are 802.11g.
11n only- Select only if all of your wireless clients are 802.11n.
11bg mixed - Select if you are using both 802.11b and 802.11g wireless clients.
11bgn mixed - Select if you are using a mix of 802.11b, 11g, and 11n wireless clients.
¾ Channel Width - Select any channel width from the drop-down list. The default setting
is automatic, which can adjust the channel width for your clients automatically.
¾ Max Tx Rate - You can limit the maximum transmission rate of the Router through this
field.
¾ Disable Security - The wireless security function can be enabled or disabled. If
disabled, the wireless stations will be able to connect the Router without encryption. It is recommended strongly that you choose one of following options to enable security.
¾ WPA-PSK/WPA2-PSK - Select WPA based on pre-shared passphrase.
z PSK Password - You can enter ASCII or Hexadecimal characters.
For ASCII, the key can be made up of any numbers from 0 to 9 and any letters from A to Z, the length should be between 8 and 63 characters.
For Hexadecimal, the key can be made up of any numbers from 0 to 9 and letters from A to F, the length should be between 8 and 64 characters.
Please also note the key is case-sensitive, this means that upper and lower case keys will affect the outcome. It would also be a good idea to write down the key and all related wireless security settings.
¾ No Change - If you choose this option, wireless security configuration will not change!
These settings are only for basic wireless parameters. For advanced settings, please refer to
4.6 Wireless
.
6. Click the Next button. You will then see the Finish page.
If you don’t make any change on the Wireless page, you will see the Finish page as shown in Figure 3-14. Click the Finish button to finish the Quick Setup.
- 17 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 3-14 Quick Setup - Finish
If there is anything changed on the Wireless page, you will see the Finish page as shown in Figure 3-15. Click the Reboot button to make your wireless configuration take effect and finish the Quick Setup.
Figure 3-15 Quick Setup – Finish
- 18 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router

Chapter 4. Configuring the Router

This chapter will show each Web page's key functions and the configuration way.

4.1 Login

After your successful login, you will see the sixteen main menus on the left of the Web-based utility. On the right, there are the corresponding explanations and instructions.
The detailed explanations for each Web page’s key function are listed below.

4.2 Status

The Status page provides the current status information about the Router. All information is read-only.
- 19 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-1 Router Status

4.3 Quick Setup

Please refer to 3.2 Quick Installation Guide.
- 20 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router

4.4 WPS

This section will guide you to add a new wireless device to an existing network quickly by WPS (Wi-Fi Protected Setup) function.
a). Choose menu “WPS”, and you will see the next screen (shown in Figure 4-2 ).
Figure 4-2 WPS
¾ WPS Status - Enable or disable the WPS function here.
¾ Current PIN - The current value of the Router's PIN is displayed here. The default PIN of the
Router can be found in the label or User Guide.
¾ Restore PIN - Restore the PIN of the Router to its default.
¾ Gen New PIN - Click this button, and then you can get a new random value for the Router's
PIN. You can ensure the network security by generating a new PIN.
¾ Add device - You can add a new device to the existing network manually by clicking this
button.
b). To add a new device:
If the wireless adapter supports Wi-Fi Protected Setup (WPS), you can establish a wireless connection between wireless adapter and Router using either Push Button Configuration (PBC) method or PIN method.
Note:
)
To build a successful connection by WPS, you should also do the corresponding configuration of the new device for WPS function meanwhile.
I. Use the Wi-Fi Protected Setup Button
Use this method if your client device has a Wi-Fi Protected Setup button.
Step 1: Press the WPS/RESET button on the back panel of the Router, as shown in the following
figure.
- 21 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
You can also keep the default WPS Status as Enabled and click the Add device button in Figure 4-2, then Choose “Press the button of the new device in two minutes” and click Connect. (Shown in the following figure)
Figure 4-3 Add A New Device
Step 2: Press and hold the WPS button of the client device directly. Step 3: The Wi-Fi Protected Setup LED flashes for two minutes during the Wi-Fi Protected Setup
process.
Step 4: When the WPS LED is on, the client device has successfully connected to the Router. Step 5: Refer back to your client device or its documentation for further instructions.
II. Enter the client device’s PIN on the Router
Use this method if your client device has a Wi-Fi Protected Setup PIN number.
Step 1: Keep the default WPS Status as Enabled and click the Add device button in Figure 4-2,
then the following screen will appear.
Figure 4-4 Add A New Device
Step 2: Enter the PIN number from the client device in the field on the above WPS screen. Then
click Connect button.
Step 3: Connect successfully” will appear on the screen of Figure 4-4, which means the client
device has successfully connected to the Router.
- 22 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
III. Enter the Router’s PIN on your client device
Use this method if your client device asks for the Router’s PIN number.
Step 1: On the client device, enter the PIN number listed on the Router’s Wi-Fi Protected Setup
screen. (It is also labeled on the bottom of the Router.)
Step 2: The Wi-Fi Protected Setup LED flashes for two minutes during the Wi-Fi Protected
Setup process.
Step 3: When the WPS LED is on, the client device has successfully connected to the Router. Step 4: Refer back to your client device or its documentation for further instructions.
Note:
)
1) The WPS LED on the Router will light green for five minutes if the device has been
2) The WPS function cannot be configured if the Wireless Function of the Router is disabled.
successfully added to the network.
Please make sure the Wireless Function is enabled before configuring the WPS.

4.5 Network

Figure 4-5 the Network menu
There are three submenus under the Network menu (shown in Figure 4-5): WAN, LAN and MAC
Clone. Click any of them, and you will be able to configure the corresponding function.

4.5.1 WAN

Choose menu “Network WAN”, you can configure the IP parameters of the WAN on the screen below.
1. If your ISP provides the DHCP service, please choose Dynamic IP type, and the Router will automatically get IP parameters from your ISP. You can see the page as follows (Figure 4-6):
- 23 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-6 WAN – Dynamic IP
This page displays the WAN IP parameters assigned dynamically by your ISP, including IP address, Subnet Mask, Default Gateway, etc. Click the Renew button to renew the IP parameters from your ISP. Click the Release button to release the IP parameters.
¾ MTU Size - The normal MTU (Maximum Transmission Unit) value for most Ethernet networks
is 1500 Bytes. It is not recommended that you change the default MTU Size unless required by your ISP.
¾ Use These DNS Servers - If your ISP gives you one or two DNS addresses, select Use
These DNS Servers and enter the primary and secondary addresses into the correct fields.
Otherwise, the DNS servers will be assigned dynamically from your ISP.
Note:
)
If you find error when you go to a website after entering the DNS addresses, it is likely that your DNS servers are set up improperly. You should contact your ISP to get DNS server addresses.
¾ Host Name - This option specifies the Host Name of the Router.
¾ Get IP with Unicast DHCP - A few ISPs' DHCP servers do not support the broadcast
applications. If you cannot get the IP Address normally, you can choose this option. (It is rarely required.)
- 24 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Click the Save button to save your settings.
2. If your ISP provides a static or fixed IP Address, Subnet Mask, Gateway and DNS setting,
select Static IP. The Static IP settings page will appear, shown in Figure 4-7.
Figure 4-7 WAN - Static IP
¾ IP Address - Enter the IP address in dotted-decimal notation provided by your ISP.
¾ Subnet Mask - Enter the subnet Mask in dotted-decimal notation provided by your ISP,
usually is 255.255.255.0.
¾ Default Gateway - (Optional) Enter the gateway IP address in dotted-decimal notation
provided by your ISP.
¾ MTU Size - The normal MTU (Maximum Transmission Unit) value for most Ethernet networks
is 1500 Bytes. It is not recommended that you change the default MTU Size unless required by your ISP.
¾ Primary/Secondary DNS - (Optional) Enter one or two DNS addresses in dotted-decimal
notation provided by your ISP.
Click the Save button to save your settings.
3. If your ISP provides a PPPoE connection, select PPPoE/Russia PPPoE option. And you should enter the following parameters (Figure 4-8):
- 25 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-8 WAN - PPPoE
¾ User Name/Password - Enter the User Name and Password provided by your ISP. These
fields are case-sensitive.
¾ Secondary Connection - It’s available only for PPPoE Connection. If your ISP provides an
extra Connection type such as Dynamic/Static IP to connect to a local area network, then you can check the radio button of Dynamic/Static IP to activate this secondary connection.
z Disabled - The Secondary Connection is disabled by default, so there is PPPoE
connection only. This is recommended.
z Dynamic IP - You can check this radio button to use Dynamic IP as the secondary
connection to connect to the local area network provided by ISP.
z Static IP - You can check this radio button to use Static IP as the secondary connection
to connect to the local area network provided by ISP.
¾ Connect on Demand - In this mode, the Internet connection can be terminated automatically
after a specified inactivity period (Max Idle Time) and be re-established when you attempt to access the Internet again. If you want your Internet connection keeps active all the time, please enter “0” in the Max Idle Time field.
Otherwise, enter the number of minutes you want
to have elapsed before your Internet access disconnects.
¾ Connect Automatically - The connection can be re-established automatically when it was
- 26 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
down.
¾ Time-based Connecting - The connection will only be established in the period from the
start time to the end time (both are in HH:MM format).
Note:
)
Only when you have configured the system time on “System Tools Time page, will the Time-based Connecting function take effect.
¾ Connect Manually - You can click the Connect/Disconnect button to connect/disconnect
immediately. This mode also supports the Max Idle Time function as Connect on Demand mode. The Internet connection can be disconnected automatically after a specified inactivity period and re-established when you attempt to access the Internet again.
Click the Connect button to connect immediately. Click the Disconnect button to disconnect immediately.
Caution: Sometimes the connection cannot be terminated although you specify a time to Max Idle Time because some applications are visiting the Internet continually in the background.
If you want to do some advanced configurations, please click the Advanced button, and the page shown in Figure 4-9 will then appear:
Figure 4-9 PPPoE Advanced Settings
¾ MTU Size - The default MTU size is “1480” bytes, which is usually fine. It is not
recommended that you change the default MTU Size unless required by your ISP.
¾ Service Name/AC Name - The service name and AC (Access Concentrator) name should
not be configured unless you are sure it is necessary for your ISP.
- 27 -
In most cases, leaving
TL-WR842ND 300Mbps Multi-Function Wireless N Router
these fields blank will work.
¾ ISP Specified IP Address - If your ISP does not automatically assign IP addresses to the
Router during login, please click “Use IP address specified by ISP” check box and enter the IP address provided by your ISP in dotted-decimal notation.
¾ Detect Online Interval - The Router will detect Access Concentrator online at every interval.
The default value is “0”. You can input the value between “0” and “120”. The value “0” means no detect.
¾ Primary DNS/Secondary DNS - If your ISP does not automatically assign DNS addresses to
the Router during login, please click “Use the following DNS servers” check box and enter the IP address in dotted-decimal notation of your ISP’s primary DNS server. If a secondary DNS server address is available, enter it as well.
Click the Save button to save your settings.
4. If your ISP provides BigPond Cable (or Heart Beat Signal) connection, please select BigPond Cable. And you should enter the following parameters (Figure 4-10):
Figure 4-10 WAN - BigPond Cable
¾ User Name/Password - Enter the User Name and Password provided by your ISP. These
fields are case-sensitive.
¾ Auth Server - Enter the authenticating server IP address or host name.
¾ Auth Domain - Type in the domain suffix server name based on your location.
- 28 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
e.g.
NSW / ACT - nsw.bigpond.net.au VIC / TAS / WA / SA / NT - vic.bigpond.net.au QLD - qld.bigpond.net.au
¾ MTU Size - The normal MTU (Maximum Transmission Unit) value for most Ethernet networks
is 1500 Bytes. It is not recommended that you change the default MTU Size unless required by your ISP.
¾ Connect on Demand - In this mode, the Internet connection can be terminated automatically
after a specified inactivity period (Max Idle Time) and be re-established when you attempt to access the Internet again. If you want your Internet connection keeps active all the time, please enter “0” in the Max Idle Time field.
Otherwise, enter the number of minutes you want
to have elapsed before your Internet access disconnects.
¾ Connect Automatically - The connection can be re-established automatically when it was
down.
¾ Connect Manually - You can click the Connect/Disconnect button to connect/disconnect
immediately. This mode also supports the Max Idle Time function as Connect on Demand mode. The Internet connection can be disconnected automatically after a specified inactivity period and re-established when you attempt to access the Internet again.
Click the Connect button to connect immediately. Click the Disconnect button to disconnect immediately.
Caution: Sometimes the connection cannot be terminated although you specify a time to Max Idle Time because some applications are visiting the Internet continually in the background.
Click the Save button to save your settings.
5. If your ISP provides L2TP connection, please select L2TP/Russia L2TP option. And you should enter the following parameters (Figure 4-11):
- 29 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-11 WAN - L2TP/Russia L2TP
¾ User Name/Password - Enter the User Name and Password provided by your ISP. These
fields are case-sensitive.
¾ Dynamic IP/ Static IP - Choose either as you are given by your ISP. Click the Connect
button to connect immediately. Click the Disconnect button to disconnect immediately.
¾ Connect on Demand - You can configure the Router to disconnect from your Internet
connection after a specified period of inactivity (Max Idle Time). If your Internet connection has been terminated due to inactivity, Connect on Demand enables the Router to automatically re-establish your connection as soon as you attempt to access the Internet again. If you wish to activate Connect on Demand, check the radio button. If you want your Internet connection to remain active at all times, enter 0 in the Max Idle Time field. Otherwise, enter the number of minutes you want to have elapsed before your Internet connection terminates.
- 30 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
¾ Connect Automatically - Connect automatically after the Router is disconnected. To use this
option, check the radio button.
¾ Connect Manually - You can configure the Router to make it connect or disconnect manually.
After a specified period of inactivity (Max Idle Time), the Router will disconnect from your Internet connection, and you will not be able to re-establish your connection automatically as soon as you attempt to access the Internet again. To use this option, check the radio button. If you want your Internet connection to remain active at all times, enter "0" in the Max Idle Time field. Otherwise, enter the number of minutes that you wish to have the Internet connecting last unless a new link is requested.
Caution: Sometimes the connection cannot be disconnected although you specify a time to Max Idle Time, because some applications are visiting the Internet continually in the background.
Click the Save button to save your settings.
6. If your ISP provides PPTP connection, please select PPTP/Russia PPTP option. And you
should enter the following parameters (Figure 4-12):
- 31 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-12 PPTP Settings
¾ User Name/Password - Enter the User Name and Password provided by your ISP. These
fields are case-sensitive.
¾ Dynamic IP/ Static IP - Choose either as you are given by your ISP and enter the ISP’s IP
address or the domain name.
If you choose static IP and enter the domain name, you should also enter the DNS assigned by your ISP. And click the Save button.
Click the Connect button to connect immediately. Click the Disconnect button to disconnect immediately.
¾ Connect on Demand - You can configure the Router to disconnect from your Internet
connection after a specified period of inactivity (Max Idle Time). If your Internet connection has been terminated due to inactivity, Connect on Demand enables the Router to
- 32 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
automatically re-establish your connection as soon as you attempt to access the Internet again. If you wish to activate Connect on Demand, check the radio button. If you want your Internet connection to remain active at all times, enter “0” in the Max Idle Time field. Otherwise, enter the number of minutes you want to have elapsed before your Internet connection terminates.
¾ Connect Automatically - Connect automatically after the Router is disconnected. To use this
option, check the radio button.
¾ Connect Manually - You can configure the Router to make it connect or disconnect manually.
After a specified period of inactivity (Max Idle Time), the Router will disconnect from your Internet connection, and you will not be able to re-establish your connection automatically as soon as you attempt to access the Internet again. To use this option, click the radio button. If you want your Internet connection to remain active at all times, enter "0" in the Max Idle Time field. Otherwise, enter the number in minutes that you wish to have the Internet connecting last unless a new link is requested.
Caution: Sometimes the connection cannot be disconnected although you specify a time to Max Idle Time because some applications are visiting the Internet continually in the background.
Click the Save button to save your settings.
Note:
)
If you don't know how to choose the appropriate connection type, click the Detect button to allow the Router to automatically search your Internet connection for servers and protocols. The connection type will be reported when an active Internet service is successfully detected by the Router. This report is for your reference only. To make sure the connection type your ISP provides, please refer to the ISP. The various types of Internet connections that the Router can detect are as follows:
z PPPoE - Connections which use PPPoE that requires a user name and password.
z Dynamic IP - Connections which use dynamic IP address assignment.
z Static IP - Connections which use static IP address assignment.
The Router can not detect PPTP/L2TP/BigPond connections with your ISP. If your ISP uses one of these protocols, then you must configure your connection manually.

4.5.2 LAN

Choose menu “Network LAN”, you can configure the IP parameters of the LAN on the screen as below.
- 33 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-13 LAN
¾ MAC Address - The physical address of the Router, as seen from the LAN. The value can't
be changed.
¾ IP Address - Enter the IP address of your Router or reset it in dotted-decimal notation
(factory default: 192.168.0.1).
¾ Subnet Mask - An address code that determines the size of the network. Normally use
255.255.255.0 as the subnet mask.
Note:
)
1) If you change the IP Address of LAN, you must use the new IP Address to log in the Router.
2) If the new LAN IP Address you set is not in the same subnet, the IP Address pool of the DHCP server will change accordingly at the same timewhile the Virtual Server and DMZ Host will not take effect until they are re-configured.

4.5.3 MAC Clone

Choose menu “Network MAC Clone”, you can configure the MAC address of the WAN on the screen below, Figure 4-14:
Figure 4-14 MAC Address Clone
Some ISPs require that you register the MAC Address of your adapter. Changes are rarely needed here.
¾ WAN MAC Address - This field displays the current MAC address of the WAN port. If your
ISP requires you to register the MAC address, please enter the correct MAC address into this field in XX-XX-XX-XX-XX-XX format (X is any hexadecimal digit).
- 34 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
¾ Your PC's MAC Address - This field displays the MAC address of the PC that is managing
the Router. If the MAC address is required, you can click the Clone MAC Address To button and this MAC address will fill in the WAN MAC Address field.
Click Restore Factory MAC to restore the MAC address of WAN port to the factory default value.
Click the Save button to save your settings.
Note:
)
Only the PC on your LAN can use the MAC Address Clone function.

4.6 Wireless

Figure 4-15 Wireless menu
There are five submenus under the Wireless menu (shown in Figure 4-15): Wireless Settings, Wireless Security, Wireless MAC Filtering, Wireless Advanced and Wireless Statistics. Click any of them, and you will be able to configure the corresponding function.

4.6.1 Wireless Settings

Choose menu “Wireless Wireless Settings”, you can configure the basic settings for the wireless network on this page.
- 35 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-16 Wireless Settings
¾ SSID (1-4) - Up to four SSIDs for each BSS (Basic Service Set) can be entered in the filed
SSID1 ~ SSID4. The name can be up to 32 characters. The same name (SSID) must be assigned to all wireless devices in your network. Check the Enable box to enable the desired SSID. The wireless stations connected to different SSIDs can not communicate with each other.
Note:
)
Multiple SSIDs can be set up in public places, like coffee house, for guests to allow virtual segregation stations which share the same channel.
¾ Region - Select your region from the drop-down list. This field specifies the region where the
wireless function of the Router can be used. It may be illegal to use the wireless function of the Router in a region other than one of those specified in this field. If your country or region is not listed, please contact your local government agency for assistance.
When you select your local region from the drop-down list, click the Save button, then the Note Dialog appears. Click OK.
- 36 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Note Dialog
Note:
)
Limited by local law regulations, version for North America does not have region selection option.
¾ Channel - This field determines which operating frequency will be used. The default channel
is set to Auto, so the Router will choose the best channel automatically. It is not necessary to change the wireless channel unless you notice interference problems with another nearby access point.
¾ Mode - Select the desired mode.
11b only - Select if all of your wireless clients are 802.11b.
11g only - Select if all of your wireless clients are 802.11g.
11n only- Select only if all of your wireless clients are 802.11n.
11bg mixed - Select if you are using both 802.11b and 802.11g wireless clients.
11bgn mixed - Select if you are using a mix of 802.11b, 11g, and 11n wireless clients.
Select the desired wireless mode. When 802.11b mode is selected, only 802.11b wireless stations can connect to the Router. When 802.11g mode is selected, only 802.11g wireless stations can connect to the Router. When 802.11n mode is selected, only 802.11n wireless stations can connect to the Router. It is strongly recommended that you set the Mode 11bng mixed, and all of 802.11b, 802.11g and 802.11n wireless stations can connect to the Router.
¾ Channel width - Select the channel width from the drop-down list. The default setting is
automatic, which can adjust the channel width for your clients automatically.
Note:
)
If 11b only, 11g only or 11bg mixed is selected in the Mode field, the Channel Width selecting field will turn grey and the value will become 20M, which is unable to be changed.
¾ Max Tx Rate - You can limit the maximum tx rate of the Router through this field.
¾ Enable Wireless Router Radio - The wireless radio of this Router can be enabled or
disabled to allow wireless stations access.
¾ Enable SSID Broadcast - When wireless clients survey the local area for wireless networks
to associate with, they will detect the SSID broadcast by the Router. If you select the Enable SSID Broadcast checkbox, the Wireless Router will broadcast its name (SSID) on the air.
¾ Enable WDS - Check this box to enable WDS. With this function, the Router can bridge two
- 37 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
or more Wlans. If this checkbox is selected, you will have to set the following parameters as shown in Figure 4-17. Make sure the following settings are correct.
Figure 4-17
¾ SSID(to be bridged) - The SSID of the AP your Router is going to connect to as a client.
You can also use the search function to select the SSID to join.
¾ BSSID(to be bridged) - The BSSID of the AP your Router is going to connect to as a
client. You can also use the search function to select the BSSID to join.
¾ Search - Click this button, you can search the AP which runs in the current channel.
¾ Key type - This option should be chosen according to the AP's security configuration. It
is recommended that the security type is the same as your AP's security type
¾ WEP Index - This option should be chosen if the key type is WEP(ASCII) or
WEP(HEX).It indicates the index of the WEP key.
¾ Auth Type - This option should be chosen if the key type is WEP(ASCII) or
WEP(HEX).It indicates the authorization type of the Root AP.
¾ Password - If the AP your Router is going to connect needs password, you need to fill
the password in this blank.
Note:
)
If one of SSID (2~3) is enabled, the Enable WDS checkbox will turn gray and cannot be enabled.

4.6.2 Wireless Security

Choose menu “Wireless Wireless Security”, you can configure the security settings of your wireless network.
There are five wireless security modes supported by the Router: WEP (Wired Equivalent Privacy), WPA (Wi-Fi Protected Access), WPA2 (Wi-Fi Protected Access 2), WPA-PSK (Pre-Shared Key), WPA2-PSK (Pre-Shared Key).
- 38 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-18 Wireless Security
¾ SSID - Select the desired SSID from the drop-down list.
¾ Disable Security - If you do not want to use wireless security, check this radio button. But it’s
strongly recommended to choose one of the following modes to enable security.
¾ WEP - It is based on the IEEE 802.11 standard. If you check this radio button, you will find a
notice in red as show in Figure 4-19.
- 39 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-19 WEP
Type - you can choose the type for the WEP security on the drop-down list. The default
setting is Automatic, which can select automatically based on the wireless station's capability and request.
WEP Key Format - Hexadecimal and ASCII formats are provided here. Hexadecimal
format stands for any combination of hexadecimal digits (0-9, a-f, A-F) in the specified length. ASCII format stands for any combination of keyboard characters in the specified length.
WEP Key - Select which of the four keys will be used and enter the matching WEP key that
you create. Make sure these values are identical on all wireless stations in your network.
Key Type - You can select the WEP key length (64-bit, or 128-bit, or 152-bit.) for
encryption. "Disabled" means this WEP key entry is invalid.
64-bit -
not promoted) or 5 ASCII characters.
128-bit - You can enter 26 hexadecimal digits (any combination of 0-9, a-f, A-F, zero key is not promoted) or 13 ASCII characters.
152-bit - You can enter 32 hexadecimal digits (any combination of 0-9, a-f, A-F, zero key is not promoted) or 16 ASCII characters.
You can enter 10 hexadecimal digits (any combination of 0-9, a-f, A-F, zero key is
Shared Key or Open System authentication type
Note:
)
If you do not set the key, the wireless security function is still disabled even if you have selected Shared Key as Authentication Type.
¾ WPA /WPA2- Enterprise - It’s based on Radius Server.
Version - you can choose the version of the WPA security on the drop-down list. The
default setting is Automatic, which can select (WPA version 2) automatically based on the wireless station's capability and request.
Encryption - You can select either Automatic, or TKIP or AES.
)
If you check the WPA/WPA2 radio button and choose TKIP encryption, you will find a
Note:
WPA (Wi-Fi Protected Access) or WPA2
- 40 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
notice in red as shown in Figure 4-20.
Figure 4-20 WPA/WPA2 - Enterprise
Radius Server IP - Enter the IP address of the Radius server.
Radius Port - Enter the port number of the Radius server.
Radius Password - Enter the password for the Radius server.
Group Key Update Period - Specify the group key update interval in seconds. The value
should be 30 or above. Enter 0 to disable the update.
¾ WPA-PSK/WPA2-PSK- Personal - It’s the WPA/WPA2 authentication type based on
pre-shared passphrase.
Version - you can choose the version of the WPA-PSK security on the drop-down list. The
default setting is Automatic, which can select WPA2-PSK (Pre-shared key of WPA) automatically based on the wireless station's capability and request.
Encryption - When WPA-PSK or WPA is set as the Authentication Type, you can select
either Automatic, or TKIP or AES as Encryption.
Note:
)
If you check the WPA-PSK/WPA2-PSK radio button and choose TKIP encryption, you will find a notice in red as shown in Figure 4-21.
WPA-PSK (Pre-shared key of WPA) or
Figure 4-21 WPA/WPA2 – Personal
PSK Passphrase - You can enter ASCII characters between 8 and 63 characters or 8 to 64 Hexadecimal characters.
Group Key Update Period - Specify the group key update interval in seconds. The value
should be 30 or above. Enter 0 to disable the update.
- 41 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Be sure to click the Save button to save your settings on this page.

4.6.3 Wireless MAC Filtering

Choose menu “Wireless MAC Filtering”, you can control the wireless access by configuring the Wireless MAC Filtering function, shown in Figure 4-22.
Figure 4-22 Wireless MAC Filtering
To filter wireless users by MAC Address, click Enable. The default setting is Disabled.
¾ MAC Address - The wireless station's MAC address that you want to filter.
¾ Status - The status of this entry, either Enabled or Disabled.
¾ Description - A simple description of the wireless station.
To Add a Wireless MAC Address filtering entry, click the Add New… button. The "Add or Modify Wireless MAC Address Filtering entry" page will appear, shown in Figure 4-23:
Figure 4-23 Add or Modify Wireless MAC Address Filtering entry
To add or modify a MAC Address Filtering entry, follow these instructions:
1. Enter the appropriate MAC Address into the MAC Address field. The format of the MAC Address is XX-XX-XX-XX-XX-XX (X is any hexadecimal digit). For example: 00-0A-EB-B0-00-0B.
- 42 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
2. Give a simple description for the wireless station in the Description field. For example: Wireless station A.
3. Select Enabled or Disabled for this entry on the Status drop-down list.
4. Click the Save button to save this entry.
To modify or delete an existing entry:
1. Click the Modify in the entry you want to modify. If you want to delete the entry, click the Delete.
2. Modify the information.
3. Click the Save button.
Click the Enable All button to make all entries enabled
Click the Disabled All button to make all entries disabled.
Click the Delete All button to delete all entries.
Click the Next button to go to the next page.
Click the Previous button to return to the previous page.
For example: If you desire that the wireless station A with MAC address 00-0A-EB-B0-00-0B and the wireless station B with MAC address 00-0A-EB-00-07-5F are able to access the Router, but all the other wireless stations cannot access the Router, you can configure the Wireless MAC Address Filtering list by following these steps:
1. Click the Enable button to enable this function.
2. Select the radio button “Allow the entries specified by any enabled entries in the list to access” for Filtering Rules.
3. Delete all or disable all entries if there are any entries already.
4. Click the
1) Enter the MAC address
2) Enter wireless station A/B in the Description field.
3) Select Enabled in the Status drop-down list.
4) Click the Save button.
Add New... button.
00-0A-EB-B0-00-0B/00-0A-EB-00-07-5F
in the MAC Address field.
5) Click the Back button.
The filtering rules that configured should be similar to the following list:
- 43 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router

4.6.4 Wireless Advanced

Choose menu “Wireless Wireless Advanced”, you can configure the advanced settings of your wireless network.
Figure 4-24 Wireless Advanced
¾ Transmit Power - Here you can specify the transmit power of Router. You can select High,
Middle or Low which you would like. High is the default setting and is recommended.
¾ Beacon Interval - Enter a value between 20-1000 milliseconds for Beacon Interval here.
The beacons are the packets sent by the Router to synchronize a wireless network. Beacon Interval value determines the time interval of the beacons. The default value is 100.
¾ RTS Threshold - Here you can specify the RTS (Request to Send) Threshold. If the packet
is larger than the specified RTS Threshold size, the Router will send RTS frames to a particular receiving station and negotiate the sending of a data frame. The default value is
2346.
¾ Fragmentation Threshold - This value is the maximum size determining whether packets
will be fragmented. Setting the Fragmentation Threshold too low may result in poor network performance because of excessive packets. 2346 is the default setting and is recommended.
- 44 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
¾ DTIM Interval - This value determines the interval of the Delivery Traffic Indication Message
(DTIM). A DTIM field is a countdown field informing clients of the next window for listening to broadcast and multicast messages. When the Router has buffered broadcast or multicast messages for associated clients, it sends the next DTIM with a DTIM Interval value. You can specify the value between 1-15 Beacon Intervals. The default value is 1, which indicates the DTIM Interval is the same as Beacon Interval.
¾ Enable WMM - WMM function can guarantee the packets with high-priority messages being
transmitted preferentially. It is strongly recommended.
¾ Enable Short GI - This function is recommended for it will increase the data capacity by
reducing the guard interval time
¾ Enabled AP Isolation - This function can isolate wireless stations on your network from
each other. Wireless devices will be able to communicate with the Router but not with each other. To use this function, check this box. AP Isolation is disabled by default.
Note:
)
If you are not familiar with the setting items in this page, it's strongly recommended to keep the provided default values; otherwise it may result in lower wireless network performance.
.

4.6.5 Wireless Statistics

Choose menu “Wireless Wireless Statistics”, you can see the MAC Address, Current Status, Received Packets and Sent Packets for each connected wireless station.
Figure 4-25 Wireless Statistics
MAC Address - The connected wireless station's MAC address
¾
¾ Current Status - The connected wireless station's running status, one of STA-AUTH/
STA-ASSOC/ STA-JOINED/ WPA/ WPA-PSK/ WPA2/ WPA2-PSK/ AP-UP/ AP-DOWN/ Disconnected
¾ Received Packets - Packets received by the station
¾ Sent Packets - Packets sent by the station
You cannot change any of the values on this page. To update this page and to show the current connected wireless stations, click on the Refresh button.
- 45 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
If the numbers of connected wireless stations go beyond one page, click the Next button to go to the next page and click the Previous button to return the previous page.
Note:
)
This page will be refreshed automatically every 5 seconds.

4.7 DHCP

Figure 4-26 The DHCP menu
There are three submenus under the DHCP menu (shown in Figure 4-26), DHCP Settings, DHCP Clients List and Address Reservation. Click any of them, and you will be able to configure the corresponding function.

4.7.1 DHCP Settings

Choose menu “DHCP DHCP Settings”, you can configure the DHCP Server on the page as shown in Figure 4-27.The Router is set up by default as a DHCP (Dynamic Host Configuration Protocol) server, which provides the TCP/IP configuration for all the PC(s) that are connected to the Router on the LAN.
Figure 4-27 DHCP Settings
¾ DHCP Server - Enable or Disable the DHCP server. If you disable the Server, you must
have another DHCP server within your network or else you must configure the computer manually.
¾ Start IP Address - Specify an IP address for the DHCP Server to start with when assigning
IP addresses. 192.168.0.100 is the default start address.
- 46 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
¾ End IP Address - Specify an IP address for the DHCP Server to end with when assigning IP
addresses. 192.168.0.199 is the default end address.
¾ Address Lease Time - The Address Lease Time is the amount of time a network user will
be allowed connection to the Router with their current dynamic IP Address. Enter the amount of time in minutes and the user will be "leased" this dynamic IP Address. After the time is up, the user will be automatically assigned a new dynamic IP address. The range of the time is 1 ~ 2880 minutes. The default value is 120 minutes.
¾ Default Gateway - (Optional.) It is suggested to input the IP address of the LAN port of the
Router. The default value is 192.168.0.1.
¾ Default Domain - (Optional.) Input the domain name of your network.
¾ Primary DNS - (Optional.) Input the DNS IP address provided by your ISP or consult your
ISP.
¾ Secondary DNS - (Optional.) Input the IP address of another DNS server if your ISP
provides two DNS servers.
Note:
)
To use the DHCP server function of the Router, you must configure all computers on the LAN as "Obtain an IP Address automatically".

4.7.2 DHCP Clients List

Choose menu “DHCP DHCP Clients List”, you can view the information about the clients attached to the Router in the screen as shown in Figure 4-28.
Figure 4-28 DHCP Clients List
¾ Client Name - The name of the DHCP client
¾ MAC Address - The MAC address of the DHCP client
¾ Assigned IP - The IP address that the Router has allocated to the DHCP client
¾ Lease Time - The time of the DHCP client leased. After the dynamic IP address has expired,
a new dynamic IP address will be automatically assigned to the user.
You cannot change any of the values on this page. To update this page and to show the current attached devices, click the Refresh button.
- 47 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router

4.7.3 Address Reservation

Choose menu “DHCP Address Reservation”, you can view and add a reserved address for clients via the next screen (shown in Figure 4-29).When you specify a reserved IP address for a PC on the LAN, that PC will always receive the same IP address each time when it accesses the DHCP server. Reserved IP addresses should be assigned to the servers that require permanent IP settings.
Figure 4-29 Address Reservation
¾ MAC Address - The MAC address of the PC for which you want to reserve an IP address.
¾ Reserved IP Address - The IP address reserved for the PC by the Router.
¾ Status - The status of this entry, either Enabled or Disabled.
To Reserve an IP address:
1. Click the Add New… button. Then Figure 4-30 will pop up.
2. Enter the MAC address (in XX-XX-XX-XX-XX-XX format.) and IP address (in dotted-decimal notation) of the computer for which you want to reserve an IP address.
3. Click the Save button.
Figure 4-30 Add or Modify an Address Reservation Entry
To modify or delete an existing entry:
1. Click the Modify in the entry you want to modify. If you want to delete the entry, click the Delete.
- 48 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
2. Modify the information.
3. Click the Save button.
Click the Enable/Disabled All button to make all entries enabled/disabled.
Click the Delete All button to delete all entries.
Click the Next button to go to the next page and Click the Previous button to return the previous page.

4.8 VPN

Figure 4-31 The VPN menu
There are three submenus under the VPN menu (shown in Figure 4-31), IKE, IPsec and Security Alliance List. Click any of them, and you will be able to configure the corresponding function.
VPN (Virtual Private Network) is a private network established via the public network, generally via the Internet. However, the private network is a logical network without any physical network lines, so it is called Virtual Private Network which can guarantee a secured data exchange.

4.8.1 IKE

IKE (Internet Key Exchange) Proposal is used for key negotiation before VPN tunnels based on IPSec are established. Here you could easily set up high-security connections with IKE but make sure that the IKE settings should be the same for the local and peer endpoints.
Choose menu “VPNIKE”, you can view the information of IKE Policies in this table (shown in Figure 4-33) and edit them by the action buttons.
Figure 4-32 List of IKE Policy
To add a new IKE Policy entry, click the Add button and the next screen will pop-up as shown in Figure 4-33. You can set parameters for IKE Policy entry on this page.
- 49 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-33 IKE Policy Settings
¾ Policy Name - Specify a unique name to the IKE policy for identification and management
purposes.
¾ Exchanged Mode - Select the IKE Exchange Mode in phase 1, and ensure the remote VPN
peer uses the same mode.
z Main mode - Provides identity protection and exchanges more information, which
applies to the scenarios with higher requirement for identity protection.
z Aggressive mode - Establishes a faster connection but with lower security, which
applies to scenarios with lower requirement for identity protection.
¾ Local/Peer ID Type - Select the type of Local ID/Peer ID for negotiation in Aggressive
mode.
¾ Local/Peer ID - If "IP" is selected, enter the IP Address of gateway for negotiation; if "NAME"
is selected, enter the name for negotiation.
¾ Authentication Algorithm - Select the authentication algorithm for IKE Negotiation.
¾ Encryption Algorithm - Select the encryption algorithm for IKE Negotiation.
¾ DH Group - Select the parameter of Diffie-Hellman algorithm for IKE Negotiation.
¾ Pre-shared Key - Manually enter ASCII characters for the Pre-shared key that should be the
same for the local and peer endpoints.
¾ Lifetime - Manually enter the number of seconds for the IKE Lifetime (The period of time to
pass before establishing a new IKE security association (SA) with the peer endpoint). The default value is 28800.
- 50 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
¾ DPD - Enable or disable DPD (Dead Peer Detect) function. If enabled, a Dead Peer Detection
(DPD) packet is sent from the VPN Concentrator to the VPN Client to ensure its peer is still there.
¾ DPD Interval - Manually enter the number of seconds for the DPD Interval. The default value
is 10.
To modify or delete an existing entry:
1. Find the desired entry in the table.
2. Click modify or delete as desired on the Configuration column.
Click the Delete All button to delete all entries.

4.8.2 IPsec

IPsec (IP Security) is a set of services and protocols defined by IETF (Internet Engineering Task Force) to provide high security for IP packets and prevent attacks.
To ensure a secured communication, the two IPsec peers use IPsec protocol to negotiate the data encryption algorithm and the security protocols for checking the integrity of the transmission data, and exchange the key to data de-encryption.
Choose menu “VPNIPsec”, you can view the information of IPsec Policies in this table (shown in Figure 4-34) and edit them by the action buttons. Check the Enable box and click the Save button to enable IPsec function.
Figure 4-34 List of IPsec Policy
To add a new IPsec Policy entry, click the Add button and the next screen will pop-up as shown in Figure 4-35. You can set parameters for IPsec Policy entry on this page.
- 51 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-35 IPsec Policy Settings
¾ Policy Name - Enter the name for the IPsec Policy.
¾ Local Subnet - Enter the local (LAN) subnet and mask.(ex. 192.168.0.0/24)
¾ Peer Subnet - Enter the Peer subnet and mask.
¾ Peer Gateway - Enter the Peer gateway or domain.
¾ Negotiation Mode - Here you could find two options, IKE Negotiation Mode and Manually
Mode. You are recommended to select the default mode-- IKE Negotiation Mode, and all the parameters could be negotiated automatically according to IKE. If Manually Mode is selected, you should manually set up the Encryption and SPI parameters according to the instructions.
¾ Security Protocol - Select the Security Protocol from the drop-down list. Here you could find
AH (Authentication Header) and ESP (Encapsulation Security Payload) protocols.
¾ Authentication Algorithm - Select the Authentication Algorithm for IPsec connection. You
could also keep the default value "Auto".
¾ Encryption Algorithm - Select the Encryption Algorithm for IPsec connection. You could also
keep the default value "Auto".
¾ In SPI - It is for direction in SPI parameter set in manual mode, and the parameter must be
the same as peer Out SPI.
¾ In Authentication Key - It is for direction in authentication key set in manual mode, and the
key must be the same as peer Out Authentication Key.
¾ Out SPI - It is for direction out SPI parameter set in manual mode, and the parameter must be
same as peer In SPI.
- 52 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
¾ Out Authentication Key - It is for direction out authentication key set in manual mode, and
the key must be same as peer In Authentication Key.
¾ PFS Group - Select the PFS property from the drop-down list that should be the same for the
local and remote endpoints. If you select "None" for local endpoint, any value is accepted for remote endpoint.
¾ Lifetime - Manually enter the number of seconds for the IPsec Lifetime. The default value is
28800.
¾ Enable - Enable or Disable current policy.
To modify or delete an existing entry:
3. Find the desired entry in the table.
4. Click modify or delete as desired on the Configuration column.
Click the Delete All button to delete all entries.

4.8.3 Security Alliance List

Choose “VPNSecurity Alliance List”, you can view the information of the IPsec SA (Security Alliance) in this table (shown in Figure 4-36).
Figure 4-36 List of Security Alliance
¾ Name - Here displays the name or description of the IPsec policy.
¾ SPI - Here displays the SPI (Security Parameter Index) of each specific IPsec policy.
¾ Tunnel Initiator - Tunnel initiator gateway.
¾ Tunnel Receiver - Tunnel receiver gateway.
¾ Security Protocol - Here displays the Security Protocol of the IPsec policy.
¾ AH Auth - Here displays the AH Authentication Algorithm of the IPsec policy.
¾ ESP Auth - Here displays the ESP Authentication Algorithm of the IPsec policy.
¾ ESP Encr - Here displays the ESP Encryption Algorithm of the IPsec policy.
Figure 4-36 displays the connection status of the NO.1 entry in the List of IPsec policy in Figure 4-35. As shown in the figure, the IP address of WAN and the default gateway of remote peer are
- 53 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
10.0.0.10 and 10.0.0.1 respectively. Security protocol and other parameters for IPsec tunnel and
the remote router should be configured the same.
As Security Association is unidirectional, an ingoing SA and an outgoing SA are created to protect data flows for each tunnel after IPsec tunnel is successfully established. The ingoing SPI value and outgoing SPI value are different. However, the Incoming SPI value must match the Outgoing SPI value at the other end of the tunnel, and vice versa.

4.9 USB Settings

Figure 4-37 The USB Settings menu
There are four submenus under the USB Settings menu (shown in Figure 4-37), Storage Sharing, FTP Server, Media Server, Print Server and User Accounts. Click any of them, and you will be able to configure the corresponding function.

4.9.1 Storage Sharing

Choose menu “USB SettingsStorage Sharing”, you can configure a USB disk drive attached to the Router and view volume and share properties such as share name, capacity, used space, and free space, etc on this page as shown below.
Figure 4-38 Storage Sharing
¾ Service Status - Indicates the Network Sharing service's current status. You can click
the Start button to start the Storage Sharing service and click the Stop button to stop it.
¾ Volume - The volume name of the USB drive the users have access to.
¾ Capacity - The storage capacity of the USB driver.
- 54 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
¾ Used - The used space of the USB driver.
¾ Free - The available space of the USB driver.
¾ Use% - The percentage of the used space.
¾ Shared - Indicates the shared or non-shared status of the volume. When the volume is
shared, you can click the Disable to stop sharing the volume; when volume is non-shared, you can click the Enable button to share the volume.
Click the Start button to start the Network Sharing service.
Click the Stop button to stop the Network Sharing service.
Click the Eject Disk button to safely remove the USB storage device that is connected to USB port. This takes the drive offline. A message (as shown in Figure 4-39) will appear on your web browser when it is safe to detach the USB disk.
Figure 4-39 Safe Unplug Message
Click the Rescan button to start a new scan.
Follow the instructions below to set up your Router as a file server:
1. Plug an external USB hard disk drive or USB flash drive into this Router.
2. Click the Rescan button to find the USB drive that has been attached to the Router.
3. Click the Start button to start the Storage Sharing service.
4. Click the Enable button under Shared to enable the disk to share.
5. Click the Open the disk to visit the sharing disk.
Note:
)
1. The Router cannot automatically locate new USB drive. You have to click the Rescan button manually to display a list of volumes and information about them.
2. The new settings will not take effect until you restart the service.
3. To unplug the USB drive, click Eject Disk button first. Simply pulling USB drive out of the USB port can cause damage to the device and loss of data.
4. Mounted volumes are subject to the 8-volume limit. So you cannot access more than 8 volumes on the USB storage device.
- 55 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router

4.9.2 FTP Server

Choose menu “USB SettingsFTP Server”, you can create an FTP server that can be accessed from the Internet or your local network.
Figure 4-40 FTP Server Configuration
¾ Server Status - Indicates the FTP Server's current status.
¾ Internet Access - Select enable to allow access of the FTP server from the Internet.
Otherwise, select disable to only allow local network access.
¾ Service Port - Enter the FTP Port number to use. The default is 21.
¾ Name - This folder's display name.
¾ Partition - The name of the partition is displayed.
¾ Folder - The real full path of the specified folder.
To set up your FTP Server, please follow the instructions below:
1. Plug an external USB hard disk drive or USB flash drive into this Router.
2. Click the Enable/Disable radio box to enable/disable Internet access to FTP from WAN port.
3. Specify a port for the FTP server to use (The default port number is 21).
4. The Internet Address displays the WAN IP address of this router, so that other users can access FTP via this address.
5. If WAN type is PPPOE/PPTP/L2TP, two connections will be available. Therefore, users can access FTP server via two connections. Users in a private LAN can access ftp server via Public Address while Internet users can access ftp server via Internet Address.
6. Click the Start button to start the ftp server.
- 56 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
To add a new folder, follow the instructions below.
1. Click Add New Folder in Figure 4-40.
Figure 4-41 Add or Modify Share Folder
2. Select the Share entire partition or a specific folder option.
3. Enter display name of the share folder in Display Name filed.
4. Click the Save button to save the settings.
You can click the upper button to go to the upper folder. You can click the Back button to return to the ftp server configuration page.
Note:
)
1. The max share folders number is 10. If you want to share a new folder when the number has reached 10, you can delete an existing share folder and then add a new one.
2. If you want to change the FTP settings, you need to restart FTP Server to make the changes take effect.
3. The max FTP clients number is 2.

4.9.3 Media Server

Choose menu “USB SettingsMedia Server”, you can create media server that allows you to share stored content with other computers and devices on your home network and on the Internet.
- 57 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-42 Media Server Setting
¾ Server Name – The name of this Media Server.
¾ Server Status - Indicates the Media Server’s current status, started or stopped. You can
click the Start button to start the Media Server and click the Stop button to stop it.
¾ Name - The display name of this folder.
¾ File System - The file system type on the partition can be FAT32 or NTFS.
¾ Folder - The real full path of the specified folder.
¾ Delete - You can delete the share folder by clicking Delete.
To set up your media server, please follow the instructions below:
1. Plug an external USB hard disk drive or USB flash drive into this Router, and then the screen
will appear as shown in Figure 4-43.
Figure 4-43 Media Server Setting
2. Click the Start button to start the media server, and then the screen will appear as shown in
Figure 4-44.
- 58 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-44 Media Server Setting
3. Click the Add share folder button to specify a folder as the search path of media server. The
screen will then appear as shown in Figure 4-45.
Figure 4-45 Add New Folder
¾ Display Name - You can enter a display name for the share folder. ¾ Share entire partition - You can select this option and then the folders contained in
this partition will all be shared.
¾ Folder Location- Displays the location of this folder. ¾ Select - You can select this option to share the specified folder. ¾ Folder - Name of folders that is in current path. ¾ upper - You can click the upper button to get into the upper folder. ¾ Save - You can click the Save button to save your settings and the page will be
redirected to the media server configuration page.
¾ Back - You can click the Back button to discard the settings and just go to the media
server configuration page.
To add a new share folder for your media server, please follow the instructions below:
- 59 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
a) Select the Share entire partition or a specified folder option.
b) Enter the display name of the share folder in Display Name edit box.
c) Click the Save button to save the configuration and the page will be redirected to the
media server configuration page as shown in Figure 4-46.
Figure 4-46 Media Server Setting
4. Click the Scan All button to scan all the share folders immediately. You can also select the
Auto-scan, at the same time, select an auto scan interval time by drop-down list. In this case, the media server will auto scan the share folders.
Note:
)
The max share folders number is 6 and the max share media files number is 100. If you want to share a new folder when the number has reached 6, you can delete an existing share folder and then add a new one.

4.9.4 Print Server

Choose menu “USB SettingsPrint Server”, you can configure print server on this page as shown below.
Figure 4-47 Pint Server Setting
There are three states of the print server, they are as follows:
¾ Online - Indicates the print service has been turned on, and no user is using the print
services at present. You can click the "Stop" button to stop the print service.
¾ Offline - Indicates the print service feature is disabled. You can click "Start" button to start the
- 60 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
print service.
¾ Busy - Indicates the print service has been turned on, but at this moment other users are
using print services.

4.9.5 User Accounts

You can specify the user name and password for Storage Sharing and FTP Server users on this page. Storage Sharing users can use Internet Explorer to access files on the USB drive. FTP Server users can log into the FTP Server via FTP Client.
There are two default user accounts that can access the Storage Sharing and FTP Server. They are Administrator and Guest (as shown in Figure 4-48). Administrator has read/write access to Storage Sharing and can access FTP Server while Guest has read-only access to Storage Sharing and can not access FTP Server.
Figure 4-48 User Account Management
Only Administrator can use a Web browser to transfer the files from a PC to the Writable shared volume on the USB drive.
To add a new user account, please follow the steps below:
1. Click Add New User button, and the screen will appear as shown in Figure 4-49.
2. Self-define a User Name.
3. Enter the password in the Password field.
4. Re-enter the password in the Confirm Password field.
5. Choose the Storage Authority from the drop-down list, Read and Write or Read Only.
6. Choose FTP Access from the drop-down list, Yes or No.
- 61 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-49 Add or Modify User Account
¾ User Name - Type the user name that you want to give access to the USB drive. The user
name must be composed of alphanumeric symbols not exceeding 15 characters in length.
¾ Password - Enter the password in the Password field. The password must be composed of
alphanumeric symbols not exceeding 15 characters in length. For security purposes, the password for each user account is not displayed.
¾ Confirm Password - Re-enter the password here.
¾ Storage Authority – Choose Read and Write or Read Only from the drop-down list to
assign access authority of Storage Sharing to the user.
¾ FTP Access – Choose Yes or No from the drop-down list to decide whether the user can
access FTP Server or not.
¾ Save - You can click the SAVE button to save your settings.
¾ Back - You can click the Back button to discard the settings and just go to the media server
configuration page.
Note:
)
1. The two default user accounts cannot be deleted.
2. Please restart the service for the new settings to take effect.
3. If you cannot use the new user name and password to access the shares, press Windows logo + R to open the Run dialog box and type net use \\192.168.0.1 /delete /yes and press Enter. (192.168.0.1 is your router's LAN IP address. If the LAN IP of the modem connected with your router is 192.168.0.x, the default LAN IP of the Router will automatically switch from
192.168.0.1 to 192.168.1.1 to avoid IP conflict; in this case, please try net use \\192.168.1.1 /delete / yes.)
- 62 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router

4.10 Forwarding

Figure 4-50 The Forwarding menu
There are four submenus under the Forwarding menu (shown in Figure 4-50): Virtual Servers, Port Triggering, DMZ and UPnP. Click any of them, and you will be able to configure the corresponding function.

4.10.1 Virtual Servers

Choose menu “ForwardingVirtual Servers”, and then you can view and add virtual servers in the next screen (shown in Figure 4-51). Virtual servers can be used for setting up public services on your LAN. A virtual server is defined as a service port, and all requests from Internet to this service port will be redirected to the computer specified by the server IP. Any PC that was used for a virtual server must have a static or reserved IP address because its IP address may change when using the DHCP function.
Figure 4-51 Virtual Servers
¾ Service Port - The numbers of External Service Ports. You can enter a service port or a
range of service ports (the format is XXX – YYY; XXX is the Start port and YYY is the End port).
¾ Internal Port - The Internal Service Port number of the PC running the service application.
You can leave it blank if the Internal Port is the same as the Service Port, or enter a specific port number when Service Port is a single one.
¾ IP Address - The IP address of the PC running the service application. ¾ Protocol - The protocol used for this application, either TCP, UDP, or All (all protocols
- 63 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
supported by the Router).
¾ Status - The status of this entry, "Enabled" means the virtual server entry is enabled. ¾ Common Service Port - Some common services already exist in the drop-down list. ¾ Modify - To modify or delete an existing entry.
To set up a virtual server entry:
1. Click the Add New... button. (pop-up Figure 4-52)
2. Select the service you want to use from the Common Service Port list. If the Common Service Port menu does not list the service that you want to use, enter the number of the service port or service port range in the Service Port field.
3. Enter the IP address of the computer running the service application in the IP Address field.
4. Select the protocol used for this application in the Protocol drop-down list, either TCP, UDP, or All.
5. Select the Enabled option in the Status drop-down list.
6. Click the Save button.
Figure 4-52 Add or Modify a Virtual Server Entry
) Note:
It is possible that you have a computer or server that has more than one type of available service. If so, select another service, and type the same IP address for that computer or server.
To modify or delete an existing entry:
1. Find the desired entry in the table.
2. Click Modify or Delete as desired on the Modify column.
Click the Enable/ Disabled All button to make all entries enabled/ disabled. Click the Delete All button to delete all entries.
- 64 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Click the Next button to go to the next page and click the Previous button to return to the previous page.
) Note:
If you set the service port of the virtual server as 80, you must set the Web management port on System Tools –> Remote Management page to be any other value except 80 such as 8080. Otherwise there will be a conflict to disable the virtual server.

4.10.2 Port Triggering

Choose menu “ForwardingPort Triggering”, you can view and add port triggering in the next screen (shown in Figure 4-53). Some applications require multiple connections, like Internet games, video conferencing, Internet telephoning and so on. Port Triggering is used for some of these applications that cannot work with a pure NAT Router.
Figure 4-53 Port Triggering
To add a new rule, follow the steps below.
1. Click the Add New… button, the next screen will pop-up as shown in Figure 4-54.
2. Select a common application from the Common Applications drop-down list, then the
Trigger Port field and the Incoming Ports field will be automatically filled. If the Common Applications do not have the application you need, enter the Trigger Port and the Incoming Ports manually.
3. Select the protocol used for Trigger Port from the Trigger Protocol drop-down list, either TCP, UDP, or All.
4. Select the protocol used for Incoming Ports from the Incoming Protocol drop-down list, either TCP or UDP, or All.
5. Select Enable in Status field.
6. Click the Save button to save the new rule.
- 65 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-54 Add or Modify a Triggering Entry
¾ Trigger Port - The port for outgoing traffic. An outgoing connection using this port will trigger
this rule.
¾ Trigger Protocol - The protocol used for Trigger Ports, either TCP, UDP, or All (all
protocols supported by the Router).
¾ Incoming Port - The port or port range used by the remote system when it responds to the
outgoing request. A response using one of these ports will be forwarded to the PC which triggered this rule. You can input at most 5 groups of ports (or port sections). Every group of ports must be separated with ",", for example, 2000-2038, 2046, 2050-2051, 2085, 3010-3030.
¾ Incoming Protocol - The protocol used for Incoming Port, either TCP, UDP, or ALL (all
protocols supported by the Router).
¾ Status - The status of this entry, Enabled means the Port Triggering entry is enabled. ¾ Modify - To modify or delete an existing entry. ¾ Common Applications - Some popular applications already listed in the drop-down list of
Incoming Protocol.
To modify or delete an existing entry:
5. Find the desired entry in the table.
6. Click Modify or Delete as desired on the Modify column.
Click the Enable All button to make all entries enabled.
Click the Disabled All button to make all entries disabled.
Click the Delete All button to delete all entries
- 66 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Once the Router is configured, the operation is as follows:
1. A local host makes an outgoing connection to an external host using a destination port number defined in the Trigger Port field.
2. The Router records this connection, opens the incoming port or ports associated with this entry in the Port Triggering table, and associates them with the local host.
3. When necessary, the external host will be able to connect to the local host using one of the ports defined in the Incoming Ports field.
) Note:
1. When the trigger connection is released, the corresponding opened ports will be closed.
2. Each rule can only be used by one host on the LAN at a time. The trigger connection of other hosts on the LAN will be refused.
3. Incoming Ports ranges cannot overlap each other.

4.10.3 DMZ

Choose menu “ForwardingDMZ”, and then you can view and configure DMZ host in the screen (shown in Figure 4-55).The DMZ host feature allows one local host to be exposed to the Internet for a special-purpose service such as Internet gaming or videoconferencing. The Router forwards packets of all services to the DMZ host. Any PC whose port is being forwarded must have its DHCP client function disabled and should have a new static IP Address assigned to it because its IP Address may be changed when using the DHCP function.
Figure 4-55 DMZ
To assign a computer or server to be a DMZ server:
1. Click the Enable button.
2. Enter the IP address of a local PC that is set to be DMZ host in the DMZ Host IP Address field.
3. Click the Save button.

4.10.4 UPnP

Choose menu “ForwardingUPnP”, and then you can view the information about UPnP in the screen (shown in Figure 4-56). The Universal Plug and Play (UPnP) feature allows the devices,
- 67 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
such as Internet computers, to access the local host resources or devices as needed. UPnP devices can be automatically discovered by the UPnP service application on the LAN.
Figure 4-56 UPnP Setting
¾ Current UPnP Status - UPnP can be enabled or disabled by clicking the Enable or Disable
button. This feature is enabled by default.
¾ Current UPnP Settings List - This table displays the current UPnP information.
App Description - The description about the application which initiates the UPnP
request.
External Port - The port which the Router opened for the application.
Protocol - The type of protocol which is opened.
Internal Port - The port which the Router opened for local host.
IP Address - The IP address of the local host which initiates the UPnP request.
Status - Either Enabled or Disabled. "Enabled" means that the port is still active;
otherwise, the port is inactive.
Click the Enable button to enable UPnP.
Click the Disable button to disable UPnP.
Click the Refresh button to update the Current UPnP Settings List.
- 68 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router

4.11 Security

Figure 4-57 The Security menu
There are four submenus under the Security menu as shown in Figure 4-57: Basic Security, Advanced Security, Local Management and Remote Management. Click any of them, and you will be able to configure the corresponding function.

4.11.1 Basic Security

Choose menu “Security Basic Security”, and then you can configure the basic security in the screen as shown in Figure 4-58.
Figure 4-58 Basic Security
¾ Firewall - A firewall protects your network from the outside world. Here you can enable or
disable the Router’s firewall.
SPI Firewall - SPI (Stateful Packet Inspection, also known as dynamic packet filtering)
helps to prevent cyber attacks by tracking more state per session. It validates that the traffic passing through the session conforms to the protocol. SPI Firewall is enabled by factory default. If you want all the computers on the LAN exposed to the outside world, you can disable it.
- 69 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
¾ VPN - VPN Passthrough must be enabled if you want to allow VPN tunnels using VPN
protocols to pass through the Router.
PPTP Passthrough - Point-to-Point Tunneling Protocol (PPTP) allows the
Point-to-Point Protocol (PPP) to be tunneled through an IP network. To allow PPTP tunnels to pass through the Router, click Enable.
L2TP Passthrough - Layer Two Tunneling Protocol (L2TP) is the method used to
enable Point-to-Point sessions via the Internet on the Layer Two level. To allow L2TP tunnels to pass through the Router, click Enable.
IPSec Passthrough - Internet Protocol security (IPSec) is a suite of protocols for
ensuring private, secure communications over Internet Protocol (IP) networks, through the use of cryptographic security services. To allow IPSec tunnels to pass through the Router, click Enable.
¾ ALG - It is recommended to enable Application Layer Gateway (ALG) because ALG allows
customized Network Address Translation (NAT) traversal filters to be plugged into the gateway to support address and port translation for certain application layer "control/data" protocols such as FTP, TFTP, H323 etc.
FTP ALG - To allow FTP clients and servers to transfer data across NAT, click Enable.
TFTP ALG - To allow TFTP clients and servers to transfer data across NAT, click
Enable.
H323 ALG - To allow Microsoft NetMeeting clients to communicate across NAT, click
Enable.
RTSP ALG - To allow some media player clients to communicate with some streaming
media servers across NAT, click Enable.
Click the Save button to save your settings.

4.11.2 Advanced Security

Choose menu “Security Advanced Security”, and then you can protect the Router from being attacked by TCP-SYN Flood, UDP Flood and ICMP-Flood in the screen as shown in
4-59
.
Figure
- 70 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-59 Advanced Security
¾ Packets Statistics Interval (5~60) - The default value is 10. Select a value between 5 and
60 seconds from the drop-down list. The Packets Statistics Interval value indicates the time section of the packets statistics. The result of the statistics is used for analysis by SYN Flood, UDP Flood and ICMP-Flood.
¾ DoS Protection - Denial of Service protection. Check the Enable or Disable button to
enable or disable the DoS protection function. Only when it is enabled, will the flood filters be enabled.
) Note:
Dos Protection will take effect only when the Traffic Statistics in “System Tool Traff i c Statistics” is enabled.
¾ Enable ICMP-FLOOD Attack Filtering - Enable or Disable the ICMP-FLOOD Attack
Filtering.
¾ ICMP-FLOOD Packets Threshold (5~3600) - The default value is 50. Enter a value
between 5 ~ 3600. When the current ICMP-FLOOD Packets number is beyond the set value, the Router will startup the blocking function immediately.
¾ Enable UDP-FLOOD Filtering - Enable or Disable the UDP-FLOOD Filtering.
¾ UDP-FLOOD Packets Threshold (5~3600) - The default value is 500. Enter a value
between 5 ~ 3600. When the current UPD-FLOOD Packets number is beyond the set value, the Router will startup the blocking function immediately.
- 71 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
¾ Enable TCP-SYN-FLOOD Attack Filtering - Enable or Disable the TCP-SYN-FLOOD
Attack Filtering.
¾ TCP-SYN-FLOOD Packets Threshold (5~3600) - The default value is 50. Enter a value
between 5 ~ 3600. When the current TCP-SYN-FLOOD Packets numbers is beyond the set value, the Router will startup the blocking function immediately.
¾ Ignore Ping Packet From WAN Port - Enable or Disable Ignore Ping Packet From WAN
Port. The default setting is disabled. If enabled, the ping packet from the Internet cannot access the Router.
¾ Forbid Ping Packet From LAN Port - Enable or Disable Forbid Ping Packet From LAN Port.
The default setting is disabled. If enabled, the ping packet from LAN cannot access the Router. This function can be used to defend against some viruses.
Click the Save button to save the settings.
Click the Blocked DoS Host List button to display the DoS host table by blocking.

4.11.3 Local Management

Choose menu “Security Local Management”, and then you can configure the management rule in the screen as shown in Figure 4-60. The management feature allows you to deny computers in LAN from accessing the Router.
Figure 4-60 Local Management
By default, the radio button “All the PCs on the LAN are allowed to access the Router's Web-Based Utility” is checked. If you want to allow PCs with specific MAC Addresses to access the Setup page of the Router's Web-Based Utility locally from inside the network, check the radio button “Only the PCs listed can browse the built-in web pages to perform Administrator tasks”, and then enter each MAC Address in a separate field. The format for the MAC Address is XX-XX-XX-XX-XX-XX (X is any hexadecimal digit). Only the PCs with MAC address listed can
- 72 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
use the password to browse the built-in web pages to perform Administrator tasks while all the others will be blocked.
After click the Add button, your PC's MAC Address will be placed in the list above.
Click the Save button to save your settings.
) Note:
If your PC is blocked but you want to access the Router again, use a pin to press and hold the WPS/RESET button (hole) on the back panel for approximately 8 seconds to reset to the Router’s factory defaults.

4.11.4 Remote Management

Choose menu “Security Remote Management”, and then you can configure the Remote Management function in the screen as shown in Figure 4-61. This feature allows you to manage your Router from a remote location via the Internet.
Figure 4-61 Remote Management
Web Management Port - Web browser access normally uses the standard HTTP service
¾
port 80. This Router's default remote management web port number is 80. For greater security, you can change the remote management web port to a custom port by entering that number in the box provided. Choose a number between 1 and 65534 but do not use the number of any common service port.
¾ Remote Management IP Address - This is the current address you will use when accessing
your Router from the Internet. This function is disabled when the IP address is set to the default value of 0.0.0.0. To enable this function change 0.0.0.0 to a valid IP address. If set to
255.255.255.255, then all the hosts can access the Router from internet.
) Note:
1. To access the Router, you should type your Router's WAN IP address into your browser's address (in IE) or Location (in Navigator) box, followed by a colon and the custom port number. For example, if your Router's WAN address is 202.96.12.8, and the port number used is 8080, please enter http://202.96.12.8:8080 in your browser. Later, you may be asked for the Router's password. After successfully entering the username and password, you will be able to access the Router's web-based utility.
- 73 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
2. Be sure to change the Router's default password to a very secure password.

4.12 Parental Control

Choose menu “Parental Control”, and then you can configure the parental control in the screen as shown in Figure 4-62. The Parental Control function can be used to control the internet activities of the child, limit the child to access certain websites and restrict the time of surfing.
Figure 4-62 Parental Control Settings
To add a new entry, please follow the steps below.
1. Click the Add New… button and the next screen will pop-up as shown in Figure 4-63.
- 74 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-63 Add or Modify Parental Control Entry
Parental Control - Check Enable if you want this function to take effect; otherwise,
¾
check Disable.
¾ MAC Address of Parental PC - In this field, enter the MAC address of the controlling
PC, or you can make use of the Copy To Above button below.
¾ MAC Address of Your PC - This field displays the MAC address of the PC that is
managing this Router. If the MAC Address of your adapter is registered, you can click the Copy To Above button to fill this address to the MAC Address of Parental PC field above.
¾ Website Description - Description of the allowed website for the PC controlled.
¾ Schedule - The time period allowed for the PC controlled to access the Internet. For
detailed information, please go to “Access Control Schedule”.
¾ Enable - Check this option to enable a specific entry.
¾ Modify - Here you can edit or delete an existing entry.
2. Enter the MAC address of the PC (e.g. 00-11-22-33-44-AA) you’d like to control in the MAC
Address of Child PC field, or you can choose the MAC address from the All Address in Current LAN drop-down list.
- 75 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
3. Give a description (e.g. Allow Google) for the website allowed to be accessed in the Website
Description field.
4. Enter the allowed domain name of the website, either the full name or the keywords (e.g.
google) in the Allowed Domain Name field. Any domain name with keywords in it (www.google.com
5. Select from the Effective Time drop-down list the schedule (e.g. Schedule_1) you want. If
there are not suitable schedules for you, click the Schedule in red below to go to the Advance Schedule Settings page and create the schedule you need.
6. In the Status field, you can select Enabled or Disabled to enable or disable your entry.
7. Click the Save button.
Click the Enable All button to enable all the rules in the list.
Click the Disable All button to disable all the rules in the list.
Click the Delete All button to delete all the entries in the table.
Click the Next button to go to the next page, or click the Previous button to return to the previous page.
, www.google.com.cn) will be allowed.
For example: If you desire that the child PC with MAC address 00-11-22-33-44-AA can access
www.google.com
without any restriction, you should follow the settings below.
1. Click “Parental Control” menu on the left to enter the Parental Control Settings page. Check
Enable and enter the MAC address 00-11-22-33-44-BB in the MAC Address of Parental PC field.
2. Click “Access Control Schedule” on the left to enter the Schedule Settings page. Click
Add New... button to create a new schedule with Schedule Description is Schedule_1, Day is Sat and Time is all day-24 hours.
3. Click “Parental Control” menu on the left to go back to the Add or Modify Parental Control
Entry page:
1. Click Add New... button.
2. Enter 00-11-22-33-44-AA in the MAC Address of Child PC field.
3. Enter “Allow Google” in the Website Description field.
4. Enter “www.google.com” in the Allowed Domain Name field.
5. Select “Schedule_1” you create just now from the Effective Time drop-down list.
on Saturday only while the parent PC with MAC address 00-11-22-33-44-BB is
6. In Status field, select Enable.
4. Click Save to complete the settings.
Then you will go back to the Parental Control Settings page and see the following list, as shown in Figure 4-64.
- 76 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-64 Parental Control Settings

4.13 Access Control

Figure 4-65 Access Control
There are four submenus under the Access Control menu as shown in Figure 4-59: Rule, Host, Target and Schedule. Click any of them, and you will be able to configure the corresponding function.

4.13.1 Rule

Choose menu “Access Control Rule”, and then you can view and set Access Control rules in the screen as shown in Figure 4-66.
Figure 4-66 Access Control Rule Management
- 77 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
¾ Enable Internet Access Control - Select the check box to enable the Internet Access
Control function, so the Default Filter Policy can take effect.
¾ Rule Name - Here displays the name of the rule and this name is unique.
¾ Host - Here displays the host selected in the corresponding rule.
¾ Target - Here displays the target selected in the corresponding rule.
¾ Schedule - Here displays the schedule selected in the corresponding rule.
¾ Enable - Here displays the status of the rule, enabled or not. Check this option to enable a
specific entry.
¾ Modify - Here you can edit or delete an existing rule.
¾ Setup Wizard - Click the Setup Wizard button to create a new rule entry.
¾ Add New... - Click the Add New... button to add a new rule entry.
¾ Enable All - Click the Enable All button to enable all the rules in the list.
¾ Disable All - Click the Disable All button to disable all the rules in the list.
¾ Delete All - Click the Delete All button to delete all the entries in the table.
¾ Move - You can change the entry’s order as desired. Enter in the first box the ID number of
the entry you want to move and in the second box another ID number, and then click the Move button to change the entries’ order.
¾ Next - Click the Next button to go to the next page.
¾ Previous - Click the Previous button to return to the previous page.
There are two methods to add a new rule.
Method One:
1. Click Setup Wizard button and the next screen will appear as shown in Figure 4-67.
Figure 4-67 Quick Setup – Create a Host Entry
¾ Host Description - In this field, create a unique description for the host (e.g. Host_1).
- 78 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
¾ Mode - Here are two options, IP Address and MAC Address. You can select either of
them from the drop-down list.
If the IP Address is selected, you can see the following item:
¾ LAN IP Address - Enter the IP address or address range of the host in dotted-decimal
format (e.g. 192.168.0.23).
If the MAC Address is selected, you can see the following item:
¾ MAC Address - Enter the MAC address of the host in XX-XX-XX-XX-XX-XX format (e.g.
00-11-22-33-44-AA).
2. Click Next when finishing creating the host entry, and the next screen will appear as shown in
Figure 4-68.
Figure 4-68 Quick Setup – Create an Access Target Entry
¾ Target Description - In this field, create a description for the target. Note that this
description should be unique (e.g. Target_1).
¾ Mode - Here are two options, IP Address and Domain Name. You can choose either of
them from the drop-down list.
If the IP Address is selected, you will see the following items:
¾ IP Address - Enter the IP address (or address range) of the target (targets) in
dotted-decimal format (e.g. 192.168.0.23).
¾ Target Port - Specify the port or port range for the target. For some common service
ports, you can make use of the Common Service Port item below.
- 79 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
¾ Protocol - Here are four options, All, TCP, UDP, and ICMP. Select one of them from the
drop-down list for the target.
¾ Common Service Port - Here lists some common service ports. Select one from the
drop-down list, and the corresponding port number will be filled in the Target Port field automatically. For example, if you select "FTP", "21" will be filled in the Target Port automatically.
If the Domain Name is selected, you will see the following items:
¾ Domain Name - Here you can enter 4 domain names, either the full name or the
keywords (for example, google). Any domain name with keywords in it (www.google.com, www.google.cn) will be blocked or allowed.
3. Click Next when finishing creating the access target entry, and the next screen will appear as
shown in Figure 4-69.
Figure 4-69 Quick Setup – Create an Advanced Schedule Entry
¾ Schedule Description - In this field, create a description for the schedule. Note that this
description should be unique (e.g. Schedule_1).
¾ Day - Choose Select Days and select the certain day (days), or choose Everyday.
¾ Time - Select "24 hours", or specify the Start Time and Stop Time yourself.
¾ Start Time - Enter the start time in HHMM format (HHMM are 4 numbers). For example
0800 is 8:00.
¾ Stop Time - Enter the stop time in HHMM format (HHMM are 4 numbers). For example
2000 is 20:00.
- 80 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
4. Click Next when finishing creating the advanced schedule entry, and the next screen will
appear as shown in Figure 4-70.
Figure 4-70 Quick Setup – Create an Internet Access Control Entry
¾ Rule - In this field, create a name for the rule. Note that this name should be unique (e.g.
Rule_1).
¾ Host - In this field, select a host from the drop-down list for the rule. The default value is
the Host Description you set just now.
¾ Target - In this filed, select a target from the drop-down list for the rule. The default value
is the Target Description you set just now.
¾ Schedule - In this field, select a schedule from the drop-down list for the rule. The
default value is the Schedule Description you set just now.
¾ Status - In this field, there are two options, Enable or Disable. Select Enable so that the
rule will take effect. Select Disable so that the rule won't take effect.
5. Click Finish to complete adding a new rule.
Method Two:
1. Click the Add New… button and the next screen will pop up as shown in Figure 4-71.
2. Give a name (e.g. Rule_1) for the rule in the Rule Name field.
3. Select a host from the Host drop-down list or choose “Click Here To Add New Host List”.
4. Select a target from the Target drop-sown list or choose “Click Here To Add New Target
List”.
5. Select a schedule from the Schedule drop-down list or choose “Click Here To Add New
Schedule”.
6. In the Status field, select Enabled or Disabled to enable or disable your entry.
- 81 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
7. Click the Save button.
Figure 4-71 Add Internet Access Control Entry
For example: If you desire to allow the host with MAC address 00-11-22-33-44-AA to access www.google.com only from 18:00 to 20:00 on Saturday and Sunday, and forbid other hosts in the LAN to access the Internet, you should follow the settings below:
1. Click the submenu Rule of Access Control in the left to return to the Rule List page. Select
Enable Internet Access Control and choose "Allow the packets specified by any enabled access control policy to pass through the Router".
2. We recommend that you click Setup Wizard button to finish all the following settings.
3. Click the submenu Host of Access Control in the left to enter the Host List page. Add a new
entry with the Host Description is Host_1 and MAC Address is 00-11-22-33-44-AA.
4. Click the submenu Target of Access Control in the left to enter the Target List page. Add a
new entry with the Target Description is Target_1 and Domain Name is www.google.com.
5. Click the submenu Schedule of Access Control in the left to enter the Schedule List page.
Add a new entry with the Schedule Description is Schedule_1, Day is Sat and Sun, Start Time is 1800 and Stop Time is 2000.
6. Click the submenu Rule of Access Control in the left, Click Add New... button to add a new
rule as follows:
In Rule Name field, create a name for the rule. Note that this name should be unique, for example Rule_1.
In Host field, select Host_1.
In Target field, select Target_1.
In Schedule field, select Schedule_1.
In Status field, select Enable.
Click Save to complete the settings.
Then you will go back to the Access Control Rule Management page and see the following list.
- 82 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router

4.13.2 Host

Choose menu “Access Control Host”, and then you can view and set a Host list in the screen as shown in Figure 4-72. The host list is necessary for the Access Control Rule.
Figure 4-72 Host Settings
¾
Host Description - Here displays the description of the host and this description is unique.
¾ Information - Here displays the information about the host. It can be IP or MAC.
¾ Modify - To modify or delete an existing entry.
To add a new entry, please follow the steps below.
1. Click the Add New… button.
2. In the Mode field, select IP Address or MAC Address.
z If you select IP Address, the screen shown is Figure 4-73.
1) In Host Description field, create a unique description for the host (e.g. Host_1).
2) In LAN IP Address field, enter the IP address.
z If you select MAC Address, the screen shown is Figure 4-74.
1) In Host Description field, create a unique description for the host (e.g. Host_1).
2) In MAC Address field, enter the MAC address.
3. Click the Save button to complete the settings.
Click the Delete All button to delete all the entries in the table.
Click the Next button to go to the next page, or click the Previous button to return to the previous page.
- 83 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-73 Add or Modify a Host Entry
Figure 4-74 Add or Modify a Host Entry
For example: If you desire to restrict the internet activities of host with MAC address 00-11-22-33-44-AA, you should first follow the settings below:
1. Click Add New... button in Figure 4-72 to enter the Add or Modify a Host Entry page.
2. In Mode field, select MAC Address from the drop-down list.
3. In Host Description field, create a unique description for the host (e.g. Host_1).
4. In MAC Address field, enter 00-11-22-33-44-AA.
5. Click Save to complete the settings.
Then you will go back to the Host Settings page and see the following list.

4.13.3 Target

Choose menu “Access Control Target ”, and then you can view and set a Target list in the screen as shown in Figure 4-75. The target list is necessary for the Access Control Rule.
- 84 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-75 Target Settings
¾ Target Description - Here displays the description about the target and this description is
unique.
¾ Information - The target can be IP address, port, or domain name.
¾ Modify - To modify or delete an existing entry.
To add a new entry, please follow the steps below.
1. Click the Add New… button.
2. In Mode field, select IP Address or Domain Name.
3. If you select IP Address, the screen shown is Figure 4-76.
Figure 4-76 Add or Modify an Access Target Entry
1) In Target Description field, create a unique description for the target (e.g.
Target_1).
2) In IP Address field, enter the IP address of the target.
3) Select a common service from Common Service Port drop-down list, so that the
Target Port will be automatically filled. If the Common Service Port drop-down list doesn’t have the service you want, specify the Target Port manually.
4) In Protocol field, select TCP, UDP, ICMP or ALL from the drop-down list.
4. If you select Domain Name, the screen shown is Figure 4-77.
- 85 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-77 Add or Modify an Access Target Entry
1) In Target Description field, create a unique description for the target (e.g.
Target_1).
2) In Domain Name field, enter the domain name, either the full name or the keywords
(for example, google) in the blank. Any domain name with keywords in it (www.google.com, www.google.cn) will be blocked or allowed. You can enter 4 domain names.
5. Click the Save button.
Click the Delete All button to delete all the entries in the table.
Click the Next button to go to the next page, or click the Previous button to return to the previous page.
For example: If you desire to restrict the internet activities of host with MAC address 00-11-22-33-44-AA in the LAN to access www.google.com
only, you should first follow the
settings below:
1. Click Add New… button in Figure 4-75 to enter the Add or Modify an Access Target Entry page.
2. In Mode field, select Domain Name from the drop-down list.
3. In Target Description field, create a unique description for the target (e.g. Target_1).
4. In Domain Name field, enter www.google.com.
5. Click Save to complete the settings.
Then you will go back to the Target Settings page and see the following list.
- 86 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router

4.13.4 Schedule

Choose menu “Access Control Schedule”, and then you can view and set a Schedule list in the next screen as shown in Figure 4-78. The Schedule list is necessary for the Access Control Rule.
Figure 4-78 Schedule Settings
¾ Schedule Description - Here displays the description of the schedule and this description is
unique.
¾ Day - Here displays the day(s) in a week.
¾ Time - Here displays the time period in a day.
¾ Modify - Here you can edit or delete an existing schedule.
To add a new schedule, follow the steps below:
1. Click Add New... button shown in Figure 4-78 and the next screen will pop-up as shown in Figure 4-79.
2. In Schedule Description field, create a unique description for the schedule (e.g. Schedule_1).
3. In Day field, select the day or days you need.
4. In Time field, you can select all day-24 hours or you may enter the Start Time and Stop Time in the corresponding field.
5. Click Save to complete the settings.
Click the Delete All button to delete all the entries in the table.
Click the Next button to go to the next page, or click the Previous button to return to the previous page.
- 87 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-79 Advanced Schedule Settings
For example: If you desire to restrict the internet activities of host with MAC address 00-11-22-33-44-AA to access www.google.com Sunday, you should first follow the settings below:
1) Click Add New... button shown in Figure 4-78 to enter the Advanced Schedule Settings page.
2) In Schedule Description field, create a unique description for the schedule (e.g. Schedule_1).
3) In Day field, check the Select Days radio button and then select Sat and Sun.
4) In Time field, enter 1800 in Start Time field and 2000 in Stop Time field.
5) Click Save to complete the settings.
Then you will go back to the Schedule Settings page and see the following list.
only from 18:00 to 20:00 on Saturday and

4.14 Advanced Routing

Figure 4-80 Advanced Routing
There are two submenus under the Advanced Routing menu as shown in Figure 4-80: Static Routing List and System Routing Table. Click any of them, and you will be able to configure the
- 88 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
corresponding function.

4.14.1 Static Routing List

Choose menu “Advanced Routing Static Routing List”, and then you can configure the static route in the next screen (shown in Figure 4-81). A static route is a pre-determined path that network information must travel to reach a specific host or network.
Figure 4-81 Static Routing
To add static routing entries:
1. Click Add New… shown in Figure 4-81, you will see the following screen.
Figure 4-82 Add or Modify a Static Route Entry
2. Enter the following data:
¾ Destination Network - The Destination Network is the address of the network or host that
you want to assign to a static route.
¾ Subnet Mask - The Subnet Mask determines which portion of an IP Address is the
network portion, and which portion is the host portion.
¾ Default Gateway - This is the IP Address of the gateway device that allows for contact
between the Router and the network or host.
3. Select Enabled or Disabled for this entry on the Status drop-down list.
- 89 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
4. Click the Save button to make the entry take effect.
Other configurations for the entries:
Click the Delete button to delete the entry.
Click the Enable All button to enable all the entries.
Click the Disable All button to disable all the entries.
Click the Delete All button to delete all the entries.
Click the Previous button to view the information in the previous screen, click the Next button to view the information in the next screen.

4.14.2 System Routing Table

Choose menu “Advanced Routing System Routing Table”, and then you can view the System Routing Table in the next screen (shown in
Figure 4-83). System routing table views all of
the valid route entries in use. The Destination IP address, Subnet Mask, Gateway, and Interface will be displayed for each entry.
Figure 4-83 System Routing Table
¾ Destination Network - The Destination Network is the address of the network or host to
which the static route is assigned.
¾ Subnet Mask - The Subnet Mask determines which portion of an IP address is the network
portion, and which portion is the host portion.
¾ Gateway - This is the IP address of the gateway device that allows for contact between the
Router and the network or host.
¾ Interface - This interface tells you either the Destination IP Address is on the LAN & WLAN
(internal wired and wireless networks), or on the WAN (Internet).
- 90 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router

4.15 Bandwidth Control

Figure 4-84 Bandwidth Control
There are two submenus under the Bandwidth Control menu as shown in Figure 4-84: Control Settings and Rules List. Click any of them, and you will be able to configure the corresponding function. The detailed explanations for each submenu are provided below.

4.15.1 Control Settings

Choose menu “Bandwidth Control Control Settings”, and then you can configure the Egress Bandwidth and Ingress Bandwidth in the next screen. Their values you configure should be less than 100000Kbps. For optimal control of the bandwidth, please select the right Line Type and ask your ISP for the total bandwidth of the egress and ingress.
Figure 4-85 Bandwidth Control Settings
¾ Enable Bandwidth Control - Check this box so that the Bandwidth Control settings can take
effect.
¾ Line Type - Select the right type for you network connection. If you don’t know how to choose,
please ask your ISP for the information.
¾ Egress Bandwidth - The upload speed through the WAN port
¾ Ingress Bandwidth - The download speed through the WAN port.
.

4.15.2 Rules List

Choose menu “Bandwidth Control Rules List”, and then you can view and configure the Bandwidth Control rules in the screen below.
- 91 -
TL-WR842ND 300Mbps Multi-Function Wireless N Router
Figure 4-86 Bandwidth Control Rules List
¾ Description - This is the information about the rules such as address range.
¾ Egress bandwidth - This field displays the max and mix upload bandwidth through the WAN
port, the default is 0.
¾ Ingress bandwidth - This field displays the max and mix download bandwidth through the
WAN port, the default is 0.
¾ Enable - This displays the status of the rule.
¾ Modify - Click Modify to edit the rule. Click Delete to delete the rule.
To add/modify a Bandwidth Control rule, follow the steps below.
1. Click Add New… shown in Figure 4-86, you will see a new screen shown in Figure 4-87.
2. Enter the information like the screen shown below.
Figure 4-87 Bandwidth Control Rule Settings
3. Click the Save button.
- 92 -
Loading...