The contents of this publication may not be reproduced in any part or as a whole, transcribed, stored in a
retrieval system, translated into any language, or transmitted in any form or by any means, electronic,
mechanical, magnetic, optical, chemical, photocopying, manual, or otherwise, without the prior written
permission of ZyXEL Communications Corporation.
Published by ZyXEL Communications Corporation. All rights reserved.
Disclaimer
ZyXEL does not assume any liability arising out of the application or use of any products, or software
described herein. Neither does it convey any license under its patent rights nor the patent rights of others.
ZyXEL further reserves the right to make changes in any products described herein without notice. This
publication is subject to change without notice.
Trademarks
ZyNOS (ZyXEL Network Operating System) is a registered trademark of ZyXEL Communications, Inc.
Other trademarks mentioned in this publication are used for identification purposes only and may be
properties of their respective owners.
ii Copyright
ZyAIR G-500 Wireless Access Point User’s Guide
Federal Communications Commission
(FCC) Interference Statement
This device complies with Part 15 of FCC rules. Operation is subject to the following two conditions:
• This device may not cause harmful interference.
• This device must accept any interference received, including interference that may cause undesired
operations.
This equipment has been tested and found to comply with the limits for a Class B digital device pursuant to
Part 15 of the FCC Rules. These limits are designed to provide reasonable protection against harmful
interference in a commercial environment. This equipment generates, uses, and can radiate radio frequency
energy, and if not installed and used in accordance with the instructions, may cause harmful interference to
radio communications.
If this equipment does cause harmful interference to radio/television reception, which can be determined by
turning the equipment off and on, the user is encouraged to try to correct the interference by one or more of
the following measures:
1. Reorient or relocate the receiving antenna.
2. Increase the separation between the equipment and the receiver.
3. Connect the equipment into an outlet on a circuit different from that to which the receiver is connected.
4. Consult the dealer or an experienced radio/TV technician for help.
Caution
1. To comply with FCC RF exposure compliance requirements, a separation distance of at least 20 cm
must be maintained between the antenna of this device and all persons.
2. This transmitter must not be co-located or operating in conjunction with any other antenna or
transmitter.
Notice 1
Changes or modifications not expressly approved by the party responsible for compliance could void the
user's authority to operate the equipment.
Certifications
1. Go to www.zyxel.com
2. Select your product from the drop-down list box on the
ZyXEL home page to go to that product's page.
3. Select the certification you wish to view from this page.
FCC Statement iii
ZyAIR G-500 Wireless Access Point User’s Guide
ZyXEL Limited Warranty
ZyXEL warrants to the original end user (purchaser) that this product is free from any defects in materials
or workmanship for a period of up to two years from the date of purchase. During the warranty period, and
upon proof of purchase, should the product have indications of failure due to faulty workmanship and/or
materials, ZyXEL will, at its discretion, repair or replace the defective products or components without
charge for either parts or labor, and to whatever extent it shall deem necessary to restore the product or
components to proper operating condition. Any replacement will consist of a new or re-manufactured
functionally equivalent product of equal value, and will be solely at the discretion of ZyXEL. This warranty
shall not apply if the product is modified, misused, tampered with, damaged by an act of God, or subjected
to abnormal working conditions.
Note
Repair or replacement, as provided under this warranty, is the exclusive remedy of the purchaser. This
warranty is in lieu of all other warranties, express or implied, including any implied warranty of
merchantability or fitness for a particular use or purpose. ZyXEL shall in no event be held liable for indirect
or consequential damages of any kind of character to the purchaser.
To obtain the services of this warranty, contact ZyXEL's Service Center for your Return Material
Authorization number (RMA). Products must be returned Postage Prepaid. It is recommended that the unit
be insured when shipped. Any returned products without proof of purchase or those with an out-dated
warranty will be repaired or replaced (at the discretion of ZyXEL) and the customer will be billed for parts
and labor. All repaired or replaced products will be shipped by ZyXEL to the corresponding return address,
Postage Paid. This warranty gives you specific legal rights, and you may also have other rights that vary
from country to country.
Safety Warnings
1. To reduce the risk of fire, use only No. 26 AWG or larger telephone wire.
2. Do not use this product near water, for example, in a wet basement or near a swimming pool.
3. Avoid using this product during an electrical storm. There may be a remote risk of electric shock from
lightening.
iv ZyXEL Warranty
ZyAIR G-500 Wireless Access Point User’s Guide
Customer Support
Please have the following information ready when you contact customer support.
• Product model and serial number.
• Warranty Information.
• Date that you received your device.
• Brief description of the problem and the steps you took to solve it.
Customer Support........................................................................................................................................... v
List of Figures................................................................................................................................................xii
List of Tables..................................................................................................................................................xv
OVERVIEW.................................................................................................................................................... I
Chapter 1 Getting to Know Your ZyAIR ...................................................................................................1-1
1.1Introducing the ZyAIR Wireless Access Point ..........................................................................1-1
SYSTEM, WIRELESS AND IP .................................................................................................................. III
Chapter 4 System Screens ...........................................................................................................................4-1
Chapter 7 IP Screen .....................................................................................................................................7-1
MAINTENANCE........................................................................................................................................... V
12.1.1Procedure To Configure Menu 1......................................................................................12-1
Chapter 13 LAN Setup ..............................................................................................................................13-1
APPENDICES............................................................................................................................................. VII
Appendix A Troubleshooting......................................................................................................................A-1
Appendix B Brute-Force Password Guessing Protection ........................................................................B-1
Appendix C Setting up Your Computer’s IP Address ..............................................................................C-1
Appendix D Wireless LAN and IEEE 802.11............................................................................................D-1
Appendix E Wireless LAN With IEEE 802.1x.......................................................................................... E-1
Appendix F Types of EAP Authentication................................................................................................. F-1
Appendix G IP Subnetting......................................................................................................................... G-1
Appendix H Command Interpreter.......................................................................................................... H-1
Appendix I Log Descriptions.......................................................................................................................I-1
Appendix J Index .........................................................................................................................................J-1
Table of Contents xi
ZyAIR G-500 Wireless Access Point User’s Guide
List of Figures
Figure 1-1 Internet Access Application...........................................................................................................1-4
Figure 4-3 Time Setting..................................................................................................................................4-4
Figure 5-2 Basic Service set ...........................................................................................................................5-2
Figure 5-3 Extended Service Set.....................................................................................................................5-3
Figure 7-1 IP Setup.........................................................................................................................................7-1
Figure 8-1 Telnet Configuration on a TCP/IP Network ..................................................................................8-2
Figure 10-1 System Status ........................................................................................................................... 10-1
Figure 10-2 System Status: Show Statistics ................................................................................................. 10-2
Figure 10-3 Association List........................................................................................................................ 10-4
Table 4-3 Time Setting................................................................................................................................... 4-4
Table 6-5 Wireless LAN: 802.1x/WPA for 802.1x Protocol ........................................................................ 6-16
Table 6-6 Wireless LAN: 802.1x/WPA for WPA Protocol ........................................................................... 6-19
Table 6-7 Wireless LAN: 802.1x/WPA for WPA-PSK Protocol .................................................................. 6-21
Table 6-8 Local User Database .................................................................................................................... 6-23
Table 7-1 IP Setup.......................................................................................................................................... 7-2
Table 10-1 System Status............................................................................................................................. 10-1
Table 10-2 System Status: Show Statistics................................................................................................... 10-2
Table 10-3 Association List.......................................................................................................................... 10-4
Table 18-2 General Commands for Third Party FTP Clients........................................................................18-3
Table 18-3 General Commands for Third Party TFTP Clients .....................................................................18-5
Table 19-1 Menu 24.10 System Maintenance : Time and Date Setting........................................................19-3
Table 20-1 Menu 24.11 Remote Management Control.................................................................................20-2
xvi List of Tables
ZyAIR G-500 Wireless Access Point User’s Guide
Preface
Congratulations on your purchase from the ZyAIR G-500 802.11g Wireless Access Point.
An access point (AP) acts as a bridge between the wireless and wired networks, extending your existing
wired network without any additional wiring.
This User’s Guide is designed to guide you through the configuration of your ZyAIR using the web
configurator or the SMT.
Use the web configurator, System Management Terminal (SMT) or command
interpreter interface to configure your ZyAIR. Not all features can be configured
through all interfaces.
The web configurator parts of this guide contain background information on features configurable by the web
configurator and the SMT. The SMT parts of this guide contain background information solely on features
not configurable by the web configurator.
Don’t forget to register your product online for free future product updates and
information at www.zyxel.com for global products, or at www.us.zyxel.com for
North American products.
Related Documentation
Supporting Disk
Refer to the included CD for support documents.
Quick Installation Guide
Our Quick Installation Guide is designed to help you get up and running right away. It contains
information on the configuration of key features and hardware connections and installation.
ZyXEL Web Site
The ZyXEL download library at www.zyxel.com
also refer to www.zyxel.com
for an online glossary of networking terms.
contains additional support documentation. Please
Syntax Conventions
• “Enter” means for you to type one or more characters (and press the carriage return). “Select” or
“Choose” means for you to use one predefined choices.
• Enter, or carriage return, key; [ESC] means the escape key and [SPACE BAR] means the space bar.
[UP] and [DOWN] are the up and down arrow keys.
Preface xvii
ZyAIR G-500 Wireless Access Point User’s Guide
• Mouse action sequences are denoted using a comma. For example, “click the Apple icon, Control
Panels and then Modem” means first click the Apple icon, then point your mouse pointer to Control
Panels and then click Modem.
• For brevity’s sake, we will use “e.g.,” as a shorthand for “for instance”, and “i.e.,” for “that is” or “in
other words” throughout this manual.
• The ZyAIR G-500 802.11g Wireless Access Point may be referred to simply as the ZyAIR in the user’s
guide.
User Guide Feedback
Help us help you. E-mail all User Guide-related comments, questions or suggestions for improvement to
techwriters@zyxel.com.tw or send regular mail to The Technical Writing Team, ZyXEL Communications
Corp., 6 Innovation Road II, Science-Based Industrial Park, Hsinchu, 300, Taiwan. Thank you.
xviii Preface
Overview
PPaarrtt II::
OVERVIEW
This part introduces the main features and applications of ZyAIR and shows how to access the web configurator and
use the Wizard to setup the ZyAIR.
I
ZyAIR G-500 Wireless Access Point User’s Guide
Chapter 1
Getting to Know Your ZyAIR
This chapter introduces the main features and applications of the ZyAIR.
1.1 Introducing the ZyAIR Wireless Access Point
The ZyAIR extends the range of your existing wired network without any additional wiring efforts. The
ZyAIR provides easy network access to mobile users. The ZyAIR offers highly secured wireless connectivity
to your wired network with IEEE 802.1x, WEP data encryption, WPA (Wi-Fi Protected Access) and MAC
address filtering. Both IEEE802.11b and IEEE802.11g compliant WLAN devices can associate with the
ZyAIR.
The ZyAIR is easy to install and configure. The embedded web-based configurator and SNMP network
management enables remote configuration and management of your ZyAIR.
1.2 ZyAIR Features
The following sections describe the features of the ZyAIR.
This auto-negotiating feature allows the ZyAIR to detect the speed of incoming transmissions and adjust
appropriately without manual intervention. It allows data transfer of either 10 Mbps or 100 Mbps in either
half-duplex or full-duplex mode depending on your Ethernet network.
The LAN interface automatically adjusts to either a crossover or straight-through Ethernet cable.
Reset Button
The ZyAIR reset button is built into the top panel. Use this button to restore the factory default password to
1234; IP address to 192.168.1.2, subnet mask to 255.255.255.0.
Brute-Force Password Guessing Protection
The ZyAIR has a special protection mechanism to discourage brute-force password guessing attacks on the
ZyAIR's management interfaces. You can specify a wait-time that must expire before entering a fourth
password after three incorrect passwords have been entered. Please see the appendix for details about this
feature.
Getting to Know Your ZyAIR 1-1
ZyAIR G-500 Wireless Access Point User’s Guide
802.11g Wireless LAN Standard
ZyAIR products containing the letter “G” in the model name, such as ZyAIR G-500 and ZyAIR G-2000,
comply with the 802.11g wireless standard.
802.11g will be fully compatible with the 802.11b standard. This means an 802.11b radio card can interface
directly with an 802.11g access point (and vice versa) at 11 Mbps or lower depending on range. 802.11g has
several intermediate rate steps between the maximum and minimum data rates. The 802.11g data rate and
modulation are as follows:
IEEE 802.11g
DATA RATE (MBPS) MODULATION
1 DBPSK (Differential Binary Phase Shift Keyed)
2
5.5 / 11 CCK (Complementary Code Keying)
6/9/12/18/24/36/48/54 OFDM (Orthogonal Frequency Division Multiplexing)
DQPSK (Differential Quadrature Phase Shift Keying
)
The ZyAIR may be prone to RF (Radio Frequency) interference from other 2.4 GHz
devices such as microwave ovens, wireless phones, Bluetooth enabled devices,
and other wireless LANs.
Wi-Fi Protected Access
Wi-Fi Protected Access (WPA) is a subset of the IEEE 802.11i security specification draft. Key differences
between WPA and WEP are user authentication and improved data encryption.
SSL Passthrough
SSL (Secure Sockets Layer) uses a public key to encrypt data that's transmitted over an SSL connection.
Both Netscape Navigator and Internet Explorer support SSL, and many Web sites use the protocol to obtain
confidential user information, such as credit card numbers. By convention, URLs that require an SSL
connection start with “https” instead of “http”. The ZyAIR allows SSL connections to take place through the
ZyAIR.
Wireless LAN MAC Address Filtering
Your ZyAIR checks the MAC address of the wireless station against a list of allowed or denied MAC
addresses.
WEP Encryption
WEP (Wired Equivalent Privacy) encrypts data frames before transmitting over the wireless network to help
keep network communications private.
1-2 Getting to Know Your ZyAIR
ZyAIR G-500 Wireless Access Point User’s Guide
IEEE 802.1x Network Security
The ZyAIR supports the IEEE 802.1x standard to enhance user authentication. Use the built-in user profile
database to authenticate up to 32 users using MD5 encryption. Use an EAP-compatible RADIUS (RFC2138,
2139 - Remote Authentication Dial In User Service) server to authenticate a limitless number of users using
EAP (Extensible Authentication Protocol). EAP is an authentication protocol that supports multiple types of
authentication.
SNMP
SNMP (Simple Network Management Protocol) is a protocol used for exchanging management information
between network devices. SNMP is a member of the TCP/IP protocol suite. Your ZyAIR supports SNMP
agent functionality, which allows a manger station to manage and monitor the ZyAIR through the network.
The ZyAIR supports SNMP version one (SNMPv1) and version two c (SNMPv2c).
Full Network Management
The embedded web configurator is an all-platform web-based utility that allows you to easily access the
ZyAIR’s management settings. Most functions of the ZyAIR are also software configurable via the SMT
(System Management Terminal) interface. The SMT is a menu-driven interface that you can access from a
terminal emulator over a telnet connection.
Logging and Tracing
♦ Built-in message logging and packet tracing.
♦ Unix syslog facility support.
Embedded FTP and TFTP Servers
The ZyAIR’s embedded FTP and TFTP servers enable fast firmware upgrades as well as configuration file
backups and restoration.
Wireless Association List
With the wireless association list, you can see the list of the wireless stations that are currently using the
ZyAIR to access your wired network.
Wireless LAN Channel Usage
The Wireless Channel Usage screen displays whether the radio channels are used by other wireless devices
within the transmission range of the ZyAIR. This allows you to select the channel with minimum interference
for your ZyAIR.
1.3 Applications for the ZyAIR
Here are some application examples of what you can do with your ZyAIR.
Getting to Know Your ZyAIR 1-3
ZyAIR G-500 Wireless Access Point User’s Guide
1.3.1 Internet Access Application
The ZyAIR is an ideal access solution for wireless Internet connection. A typical Internet access application
for your ZyAIR is shown as follows.
Figure 1-1 Internet Access Application
1.3.2 Corporation Network Application
In situations where users are always on the move in the coverage area but still need access to corporate
network access, the ZyAIR is an ideal solution for wireless stations to connect to the corporate network
without expensive network cabling.
The following figure depicts a typical application of the ZyAIR in an enterprise environment. The three
computers with wireless adapters are allowed to access the network resource through the ZyAIR after
account validation by the network authentication server.
1-4 Getting to Know Your ZyAIR
ZyAIR G-500 Wireless Access Point User’s Guide
Figure 1-2 Corporation Network Application
Getting to Know Your ZyAIR 1-5
ZyAIR G-500 Wireless Access Point User’s Guide
Chapter 2
Introducing the Web Configurator
This chapter describes how to access the ZyAIR web configurator and provides an overview of its
screens. The default IP address of the ZyAIR is 192.168.1.2.
2.1 Accessing the ZyAIR Web Configurator
Step 1. Make sure your ZyAIR hardware is properly connected (refer to the Quick Installation Guide).
Step 2. Prepare your computer/computer network to connect to the ZyAIR (refer to the appendix).
Step 3. Launch your web browser.
Step 4. Type "192.168.1.2" (default) as the URL.
Step 5. Type "1234" (default) as the password and click Login. In some versions, the default password
appears automatically - if this is the case, click Login.
Step 6. You should see a screen asking you to change your password (highly recommended) as shown
next. Type a new password (and retype it to confirm) and click Apply or click Ignore to allow
access without password change.
Figure 2-1 Change Password Screen
Step 7. You should now see the SYSTEM screen.
Introducing the Web Configurator 2-1
ZyAIR G-500 Wireless Access Point User’s Guide
The management session automatically times out when the time period set in the
Administrator Inactivity Timer field expires (default five minutes). Simply log back into
the ZyAIR if this happens to you.
2.2 Resetting the ZyAIR
If you forget your password or cannot access the ZyAIR, you will need to reload the factory-default
configuration file or use the RESET button on the top panel of the ZyAIR. Uploading this configuration file
replaces the current configuration file with the factory-default configuration file. This means that you will
lose all configurations that you had previously. The password will be reset to “1234”, also.
2.2.1 Method of Restoring Factory-Defaults
You can erase the current configuration and restore factory defaults in three ways:
1. Use the RESET button on the top panel of the ZyAIR to upload the default configuration file (hold this
button in for about 10 seconds or until the PWR/SYS LED turns red). Use this method for cases when
the password or IP address of the ZyAIR is not known.
2. Use the web configurator to restore defaults (refer to the chapter on maintenance).
3. Transfer the configuration file to your ZyAIR using FTP. See later in the part on SMT configuration for
more information.
2-2 Introducing the Web Configurator
ZyAIR G-500 Wireless Access Point User’s Guide
(
2.3 Navigating the ZyAIR Web Configurator
The following summarizes how to navigate the web configurator.
Follow the instructions below or click the icon (located in the top right corner
of most screens) to view online help.
Click LOGOUT at
any time to exit the
web configurator.
Click WIZARD SETUP for initial configuration including general
setup, Wireless LAN setup and IP address assignment.
Click the links under ADVANCED to configure advanced
features such as SYSTEM (General Setup, Password and
Time Zone), WIRELESS (Wireless, MAC Filter, Roaming,
802.1x/WPA, Local User Database and RADIUS), IP, REMOTE MGNT (Telnet, FTP, WWW and SNMP) and Logs
View reports and Log Settings).
Click the MAINTENANCE to view information about your ZyAIR or upgrade
configuration/firmware files. Maintenance includes Status (Statistics), Association
List, F/W (firmware) Upload, Configuration (Backup, Restore Default) and
Figure 2-2 Navigating the ZyAIR Web Configurator
Introducing the Web Configurator 2-3
Loading...
+ 186 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.