ZyXEL Communications ZyXEL ZyAIR G-570S User Manual
ZyXEL Communications ZyXEL ZyAIR G-570S User Manual

ZyXEL Communications ZyXEL ZyAIR G-570S User Manual

802.11g wireless access point
Hide thumbs Also See for ZyXEL ZyAIR G-570S:
Table of Contents

Advertisement

Quick Links

ZyXEL G-570S
802.11g Wireless Access Point
User's Guide
Version 1.00
11/2005

Advertisement

Table of Contents
loading

Summary of Contents for ZyXEL Communications ZyXEL ZyAIR G-570S

  • Page 1 ZyXEL G-570S 802.11g Wireless Access Point User’s Guide Version 1.00 11/2005...
  • Page 2: Copyright

    ZyXEL Communications Corporation. Published by ZyXEL Communications Corporation. All rights reserved.
  • Page 3: Interference Statements And Certifications

    Interference Statements and Federal Communications Commission (FCC) Interference Statement This device complies with Part 15 of FCC rules. Operation is subject to the following two conditions: • This device may not cause harmful interference. • This device must accept any interference received, including interference that may cause undesired operations.
  • Page 4 ZyXEL G-570S User’s Guide Cet appareil numérique de la classe B est conforme à la norme NMB-003 du Canada. Certifications 1 Go to www.zyxel.com. 2 Select your product from the drop-down list box on the ZyXEL home page to go to that product's page.
  • Page 5: Safety Warnings

    For your safety, be sure to read and follow all warning notices and instructions. • Do NOT open the device or unit. Opening or removing covers can expose you to dangerous high voltage points or other risks. ONLY qualified service personnel can service the device.
  • Page 6: Zyxel Limited Warranty

    ZyXEL G-570S User’s Guide ZyXEL Limited Warranty ZyXEL warrants to the original end user (purchaser) that this product is free from any defects in materials or workmanship for a period of up to two years from the date of purchase. During the warranty period, and upon proof of purchase, should the product have indications of failure due to faulty workmanship and/or materials, ZyXEL will, at its discretion, repair or replace the defective products or components without charge for either parts or labor, and to whatever...
  • Page 7: Customer Support

    1-800-255-4101 www.us.zyxel.com +1-714-632-0882 +1-714-632-0858 ftp.us.zyxel.com +47-22-80-61-80 www.zyxel.no +47-22-80-61-81 ZyXEL G-570S User’s Guide REGULAR MAIL ZyXEL Communications Corp. 6 Innovation Road II Science Park Hsinchu 300 Taiwan ZyXEL Communications Czech s.r.o. Modranská 621 143 01 Praha 4 - Modrany Ceská Republika...
  • Page 8 Poland ZyXEL Russia Ostrovityanova 37a Str. Moscow, 117279 Russia ZyXEL Communications Alejandro Villegas 33 1º, 28043 Madrid Spain ZyXEL Communications A/S Sjöporten 4, 41764 Göteborg Sweden ZyXEL Ukraine 13, Pimonenko Str. Kiev, 04050 Ukraine ZyXEL Communications UK Ltd.,11 The Courtyard,...
  • Page 9: Table Of Contents

    Copyright ... 2 Interference Statements and Certifications ... 3 Safety Warnings ... 5 ZyXEL Limited Warranty... 6 Customer Support... 7 Table of Contents ... 9 List of Figures ... 13 List of Tables ... 17 Preface ... 19 Chapter 1 Getting to Know Your G-570S ...
  • Page 10 ZyXEL G-570S User’s Guide Chapter 3 Introducing the Web Configurator... 35 3.1 Web Configurator Overview ...35 3.2 Accessing the G-570S Web Configurator ...35 3.3 Configuring the G-570S Using the Wizard ...37 3.3.3.1 Disable ...39 3.3.3.2 WEP ...40 3.3.3.3 WPA(2)-PSK ...41 3.4 Navigating the Advanced Screens ...43 3.4.1 Navigation Panel ...44 Chapter 4...
  • Page 11 6.8 EAP Authentication Overview ...77 6.9 Dynamic WEP Key Exchange ...78 6.10 Introduction to WPA and WPA2 ...78 6.10.1 Encryption ...79 6.10.2 User Authentication ...79 6.11 WPA(2)-PSK Application Example ...79 6.12 WPA(2) with RADIUS Application Example ...80 6.13 Security Parameters Summary ...81 6.14 Wireless Client WPA Supplicants ...81 6.15 Configuring Wireless Security ...81 6.17.1 Enabling OTIST ...89...
  • Page 12 ZyXEL G-570S User’s Guide IP Subnetting ... 151 Index... 159 Table of Contents...
  • Page 13: List Of Figures

    ZyXEL G-570S User’s Guide List of Figures Figure 1 WDS Functionality Example ... 22 Figure 2 Internet Access Application ... 24 Figure 3 Corporate Network Application ... 25 Figure 4 Wireless Client Application ... 25 Figure 5 Bridge Application ... 26 Figure 6 Bridge Repeater Application ...
  • Page 14 ZyXEL G-570S User’s Guide Figure 39 Bridge Loop: Two Bridges Connected to Hub ... 67 Figure 40 Bridge Loop: Bridge Connected to Wired LAN ... 67 Figure 41 Wireless Settings: Bridge ... 68 Figure 42 Wireless Settings: AP+Repeater ... 71 Figure 43 WEP Authentication Steps ...
  • Page 15 ZyXEL G-570S User’s Guide Figure 82 Windows 95/98/Me: TCP/IP Properties: DNS Configuration ... 124 Figure 83 Windows XP: Start Menu ... 125 Figure 84 Windows XP: Control Panel ... 125 Figure 85 Windows XP: Control Panel: Network Connections: Properties ... 126 Figure 86 Windows XP: Local Area Connection Properties ...
  • Page 16 ZyXEL G-570S User’s Guide List of Figures...
  • Page 17: List Of Tables

    ZyXEL G-570S User’s Guide List of Tables Table 1 Front Panel LED Description ... 27 Table 2 Factory Defaults ... 33 Table 3 Global Icon Key ... 44 Table 4 Screens Summary ... 45 Table 5 Status ... 47 Table 6 Status: View Statistics ... 49 Table 7 Status: View Association List ...
  • Page 18 ZyXEL G-570S User’s Guide Table 39 Classes of IP Addresses ... 151 Table 40 Allowed IP Address Range By Class ... 152 Table 41 “Natural” Masks ... 152 Table 42 Alternative Subnet Mask Notation ... 153 Table 43 Two Subnets Example ... 153 Table 44 Subnet 1 ...
  • Page 19: Preface

    Help us help you. E-mail all User Guide-related comments, questions or suggestions for improvement to techwriters@zyxel.com.tw or send regular mail to The Technical Writing Team, ZyXEL Communications Corp., 6 Innovation Road II, Science-Based Industrial Park, Hsinchu, 300, Taiwan. Thank you.
  • Page 20: Graphics Icons Key

    ZyXEL G-570S User’s Guide Graphics Icons Key G-570S Server Telephone Computer Notebook computer Modem Wireless Signal Switch Router Preface...
  • Page 21: Getting To Know Your G-570S

    Getting to Know Your G-570S This chapter introduces the main features and applications of the G-570S. 1.1 Introducing the G-570S Wireless Access Point The ZyXEL G-570S is a 4-in-1 Access Point with Super G and Turbo G wireless technology. Access Point (AP), repeater, bridge and wireless client functions allow you to use the G-570S in various network deployments.
  • Page 22: Figure 1 Wds Functionality Example

    ZyXEL G-570S User’s Guide Figure 1 WDS Functionality Example OTIST (One-Touch Intelligent Security Technology) OTIST allows your G-570S to assign its SSID and security settings (WEP or WPA-PSK) to the ZyXEL wireless adapters that support OTIST and are within transmission range. The ZyXEL wireless adapters must also have OTIST enabled.
  • Page 23: Wireless Lan Mac Address Filtering

    WPA2 WPA 2 (IEEE 802.11i) is a wireless security standard that defines stronger encryption, authentication and key management than WPA. SSL Passthrough The G-570S allows SSL connections to go through the G-570S. SSL (Secure Sockets Layer) uses a public key to encrypt data that's transmitted over an SSL connection. Both Netscape Navigator and Internet Explorer support SSL, and many Web sites use the protocol to obtain confidential user information, such as credit card numbers.
  • Page 24: Applications For The G-570S

    ZyXEL G-570S User’s Guide Output Power Management Output Power Management is the ability to set the level of output power. There may be interference or difficulty with channel assignment when there is a high density of APs within a coverage area. In this case you can lower the output power of each access point, thus enabling you to place access points closer together.
  • Page 25: Wireless Client Application

    The following figure depicts a typical application of the G-570S in an enterprise environment. The three computers with wireless adapters are allowed to access the network resource through the G-570S after account validation by the network authentication server. Figure 3 Corporate Network Application 1.3.3 Wireless Client Application The G-570S can function as a wireless client to connect to a network via an Access Point (AP).
  • Page 26: Bridge / Repeater

    ZyXEL G-570S User’s Guide 1.3.4 Bridge / Repeater The G-570S can act as a wireless network bridge and establish wireless links with other APs. The G-570Ss in the following example are using bridge mode with a star configuration. A, B, C and D are connected to independent wired networks and have bridge connections at the same time (B, C and D can communicate with A).
  • Page 27: Access Point And Repeater

    1.3.5 Access Point and Repeater Set the G-570S to AP+Repeater mode to have it simultaneously provide access for wireless clients and use the repeater function. This allows you to extend the coverage of your wireless network without installing Ethernet cable to connect the G-570S. In the following figure, B is in AP+Repeater mode.
  • Page 28 ZyXEL G-570S User’s Guide Table 1 Front Panel LED Description COLOR ETHN Green Amber OTIST Green WLAN Green STATUS DESCRIPTION Blinking The G-570S is sending/receiving data. The G-570S has a successful 10Mbps Ethernet connection. Blinking The G-570S is sending/receiving data. The G-570S has a successful 100Mbps Ethernet connection.
  • Page 29: Management Computer Setup

    Management Computer Setup This chapter describes how to prepare your computer to access the G-570S web configurator. 2.1 Introduction You can connect a computer to the G-570S for management purposes either using an Ethernet connection (recommended for a first time management session) or wirelessly. 2.2 Wired Connection You must prepare your computer/computer network to connect to the G-570S if you are using a wired connection.
  • Page 30: Windows 2000/Nt/Xp

    ZyXEL G-570S User’s Guide 2.2.1.1 Windows 2000/NT/XP The following example figures use the default Windows XP GUI theme. 1 Click start (Start in Windows 2000/NT) > Settings > Control Panel. 2 In the Control Panel, double-click Network Connections (Network and Dial-up Connections in Windows 2000/NT).
  • Page 31: Figure 12 Local Area Connection Properties

    Figure 12 Local Area Connection Properties 5 Select Use the following IP Address and fill in an IP address (between 192.168.1.3 and 192.168.1.254). • Type 255.255.255.0 as the Subnet mask. • Click Advanced Figure 13 Internet Protocol Properties 6 Remove any previously installed gateways in the IP Settings tab and click OK to go back to the Internet Protocol TCP/IP Properties screen.
  • Page 32: Wireless Connection

    ZyXEL G-570S User’s Guide Figure 14 Advanced TCP/IP Settings 7 Click OK to close the Internet Protocol (TCP/IP) Properties window. 8 Click Close (OK in Windows 2000/NT) to close the Local Area Connection Properties window. 9 Close the Network Connections window (Network and Dial-up Connections in Windows 2000/NT).
  • Page 33: Restarting The G-570S

    Note: The wireless stations and G-570S must use the same SSID, channel and wireless security settings for wireless communication. If you do not enable any wireless security on your G-570S, your network traffic is visible to any wireless networking device that is within range. 2.4 Restarting the G-570S Press and immediately release the RESET button to restart the G-570S.
  • Page 34 ZyXEL G-570S User’s Guide Chapter 2 Management Computer Setup...
  • Page 35: Introducing The Web Configurator

    This chapter describes how to configure the G-570S using the Wizard. 3.1 Web Configurator Overview The web configurator is an HTML-based management interface that allows easy G-570S setup and management via Internet browser. Use Internet Explorer 6.0 and later or Netscape Navigator 7.0 and later versions.
  • Page 36: Figure 16 Web Configurator Address

    ZyXEL G-570S User’s Guide Figure 16 Web Configurator Address 5 Type "1234" (default) as the password and click Login. Figure 17 Login Screen 6 Select your language and click Apply. Figure 18 Language Screen 7 The following screen displays. Select Go Wizard Setup and click Apply to use the wizard setup screens for initial configuration (see Advanced Setup and click Apply to go directly to the advanced screens (see on page...
  • Page 37: Configuring The G-570S Using The Wizard

    Figure 19 Select Wizard or Advanced Setup Screen 3.3 Configuring the G-570S Using the Wizard The wizard consists of a series of screens to help you configure your G-570S for wireless stations to access your wired LAN. Use the following buttons to navigate the Wizard: Back Click Back to return to the previous screen.
  • Page 38: Figure 20 Wizard: Basic Settings

    ZyXEL G-570S User’s Guide Figure 20 Wizard: Basic Settings 3.3.2 Wizard: Wireless Settings Use this wizard screen to set up the wireless LAN. See the chapter on the wireless screens for background information. 1 The SSID is a unique name to identify the device in a wireless network. Enter up to 32 printable characters.
  • Page 39: Disable

    Figure 21 Wizard: Wireless Settings 3.3.3 Wizard: Security Settings Use this screen to configure security for your wireless LAN. The screen varies depending on what you select in the Encryption Method field. Select Disable to have no wireless security configured, select WEP, or select WPA-PSK if your wireless clients support WPA-PSK. Select WPA2-PSK if your wireless clients support WPA2-PSK Go to SETTINGS >...
  • Page 40: Wep

    ZyXEL G-570S User’s Guide Figure 22 Setup Wizard 3: Disable 3.3.3.2 WEP 1 WEP (Wired Equivalent Privacy) encrypts data frames before transmitting over the wireless network. Select 64-bit, 128-bit or 152-bit from the WEP Encryption drop- down list box and then follow the on-screen instructions to set up the WEP keys. 2 Choose an encryption level from the drop-down list.
  • Page 41: Wpa(2)-Psk

    Figure 23 Wizard 3: WEP 3.3.3.3 WPA(2)-PSK Only select WPA-PSK or WPA2-PSK if your wireless clients support it. Type a pre-shared key from 8 to 63 ASCII characters (including spaces and symbols). This field is case-sensitive. Chapter 3 Introducing the Web Configurator ZyXEL G-570S User’s Guide Use Passphrase to automatically generate...
  • Page 42: Figure 24 Wizard 3: Wpa(2)-Psk

    ZyXEL G-570S User’s Guide Figure 24 Wizard 3: WPA(2)-PSK 3.3.4 Wizard: Confirm Your Settings This read-only screen shows the status of the current settings. Use the summary table to check whether what you have configured is correct. Click Finish to complete the wizard configuration and save your settings.
  • Page 43: Navigating The Advanced Screens

    Figure 25 Wizard: Confirm Your Settings For more detailed background information, see the rest of this User's Guide. 3.4 Navigating the Advanced Screens The STATUS screen is the first advanced screen that displays. This section explains how to navigate the advanced configuration screens. See the chapter on the Status screen for details about the individual screen.
  • Page 44: Navigation Panel

    ZyXEL G-570S User’s Guide Figure 26 Status Screen The following table describes the global web configurator icons (in the upper left corner of most screens). Table 3 Global Icon Key ICON 3.4.1 Navigation Panel After you enter the password, use the links on the navigation panel to go to the various advanced screens.
  • Page 45: Table 4 Screens Summary

    The following table describes the sub-menus. Table 4 Screens Summary LINK Status System Wireless Wireless Settings Use this screen to configure wireless LAN. Security MAC Filter OTIST Management Password Logs Configuration F/W Upload Note: See the rest of this User's Guide for configuration details and background information on all G-570S features using the web configurator.
  • Page 46 ZyXEL G-570S User’s Guide Chapter 3 Introducing the Web Configurator...
  • Page 47: Chapter 4 Status Screens

    This chapter describes the Status screens. 4.1 System Status Click Status to open the following screen. The Status screen display a snapshot of your device’s settings. You can also view network statistics and a list of wireless stations currently associated with your device. Note that these labels are READ-ONLY and are meant to be used for diagnostic purposes.
  • Page 48 ZyXEL G-570S User’s Guide Table 5 Status LABEL DESCRIPTION MAC Address This field displays the MAC address of the device. The MAC (Media Access Control) or Ethernet address on a LAN (Local Area Network) is unique to your computer. A network interface card such as an Ethernet adapter has a hardwired address that is assigned at the factory.
  • Page 49: Figure 28 Status: View Statistics

    Figure 28 Status: View Statistics The following table describes the labels in this screen. Table 6 Status: View Statistics LABEL DESCRIPTION Ethernet Packets This row displays the numbers of packets received and transmitted by the Ethernet port. Bytes This row displays the numbers of bytes received and transmitted by the Ethernet port.
  • Page 50: Figure 29 Status: View Association List

    ZyXEL G-570S User’s Guide 4.1.2 Association List Click STATUS and then the View Association List button to display the Association List screen. When the device is not in wireless client mode, this screen displays which wireless stations are currently associated to the device in the Association List screen. Figure 29 Status: View Association List The following table describes the labels in this screen.
  • Page 51: Table 8 Status: View Association List: Wireless Client Mode

    The following table describes the labels in this screen. Table 8 Status: View Association List: Wireless Client Mode LABEL DESCRIPTION SSID This field displays the SSID (Service Set IDentifier) of each wireless device that the device detected. BSSID This field displays the BSSID (Basic Service Set IDentifier) of each wireless network that the device detected.
  • Page 52 ZyXEL G-570S User’s Guide Chapter 4 Status Screens...
  • Page 53: Chapter 5 System Screen

    This chapter provides information on the System screen. 5.1 TCP/IP Parameters 5.1.1 IP Address Assignment Every computer on the Internet must have a unique IP address. If your networks are isolated from the Internet, for instance, only between your two branch offices, you can assign any IP addresses to the hosts without problems.
  • Page 54: Figure 31 System Settings

    ZyXEL G-570S User’s Guide If the ISP did not explicitly give you an IP network number, then most likely you have a single user account and the ISP will assign you a dynamic IP address when the connection is established. The Internet Assigned Number Authority (IANA) reserved this block of addresses specifically for private use;...
  • Page 55 Table 10 System Settings LABEL DESCRIPTION Use fixed IP Select this option to have your device use a static IP address. When you select this address option, fill in the fields below. IP Address Enter the IP address of your device in dotted decimal notation. Subnet Mask Enter the subnet mask.
  • Page 56 ZyXEL G-570S User’s Guide Chapter 5 System Screen...
  • Page 57: Chapter 6 Wireless Screens

    This chapter discusses how to configure wireless settings and wireless security on your G- 570S. 6.1 Wireless LAN Overview This section introduces the wireless LAN (WLAN) and some basic scenarios. 6.1.1 IBSS An Independent Basic Service Set (IBSS), also called an Ad-hoc network, is the simplest WLAN configuration.
  • Page 58: Ess

    ZyXEL G-570S User’s Guide Figure 33 Basic Service set 6.1.3 ESS An Extended Service Set (ESS) consists of a series of overlapping BSSs, each containing an access point, with each access point connected together by a wired network. This wired connection between APs is called a Distribution System (DS).
  • Page 59: Wireless Lan Basics

    Figure 34 Extended Service Set 6.2 Wireless LAN Basics This section describes the wireless LAN network terms. 6.2.1 Channel A channel is the radio frequency(ies) used by IEEE 802.11b wireless devices. Channels available depend on your geographical area. You may have a choice of channels (for your region) so you should use a different channel than an adjacent AP (access point) to reduce interference.
  • Page 60: Rts/Cts

    ZyXEL G-570S User’s Guide 6.2.3 RTS/CTS A hidden node occurs when two stations are within range of the same access point, but are not within range of each other. The following figure illustrates a hidden node. Both stations (STA) are within range of the access point (AP) or wireless gateway, but out-of-range of each other, so they cannot “hear”...
  • Page 61: Fragmentation Threshold

    6.2.4 Fragmentation Threshold A Fragmentation Threshold is the maximum data fragment size (between 256 and 2432 bytes) that can be sent in the wireless network before the G-570S will fragment the packet into smaller data frames. A large Fragmentation Threshold is recommended for networks not prone to interference while you should set a smaller threshold for busy networks or networks that are prone to interference.
  • Page 62: Figure 36 Wireless Settings: Access Point

    ZyXEL G-570S User’s Guide Figure 36 Wireless Settings: Access Point The following table describes the labels in this screen. Table 11 Wireless Settings: Access Point LABEL DESCRIPTION Operation Mode Select the operating mode from the drop-down list. The options are Access Point, Wireless Client, Bridge and AP+Repeater.
  • Page 63 Table 11 Wireless Settings: Access Point (continued) LABEL DESCRIPTION Wireless Mode Select 802.11b only to allow only IEEE 802.11b compliant WLAN devices to associate with the device. Select 802.11g only to allow only IEEE 802.11g compliant WLAN devices to associate with the device. Select Auto (11g/11b) to allow either IEEE 802.11b or IEEE 802.11g compliant WLAN devices to associate with the device.
  • Page 64: Figure 37 Wireless Settings: Wireless Client

    ZyXEL G-570S User’s Guide Table 11 Wireless Settings: Access Point (continued) LABEL DESCRIPTION Super-G Mode Super-G mode provides higher speed transmissions than regular IEEE 802.11g. The other device must also support super-G mode in order for the device to use it for the wireless connection.
  • Page 65: Table 12 Wireless Settings: Wireless Client

    The following table describes the labels in this screen. Table 12 Wireless Settings: Wireless Client LABEL DESCRIPTION Operation Mode Select the operating mode from the drop-down list. The options are Access Point, Wireless Client, Bridge and AP+Repeater. SSID Wireless stations associating to the access point (AP) must have the same SSID. Enter a descriptive name (up to 32 printable characters) for the wireless LAN.
  • Page 66: Figure 38 Bridging Example

    ZyXEL G-570S User’s Guide Table 12 Wireless Settings: Wireless Client (continued) LABEL DESCRIPTION Turbo-G Mode Turbo-G mode provides higher speed transmissions than regular IEEE 802.11g or super-G mode. The other device must also support turbo-G mode in order for the device to use it for the wireless connection.
  • Page 67: Figure 39 Bridge Loop: Two Bridges Connected To Hub

    ZyXEL G-570S User’s Guide Be careful to avoid bridge loops when you enable bridging in the G-570S. Bridge loops cause broadcast traffic to circle the network endlessly, resulting in possible throughput degradation and disruption of communications. The following examples show two network topologies that can lead to this problem: If two or more G-570Ss (in bridge mode) are connected to the same hub as shown next.
  • Page 68: Figure 41 Wireless Settings: Bridge

    ZyXEL G-570S User’s Guide Select Bridge as the Operation Mode to have the device act as a wireless bridge only. Figure 41 Wireless Settings: Bridge The following table describes the labels in this screen. Chapter 6 Wireless Screens...
  • Page 69: Table 13 Wireless Settings: Bridge

    Table 13 Wireless Settings: Bridge LABEL DESCRIPTION Operation Mode Select the operating mode from the drop-down list. The options are Access Point, Wireless Client, Bridge and AP+Repeater. Note: If you are configuring the device from a computer connected SSID The device does not use the SSID with bridge mode. You do not need to configure Hide SSID The device does not use the SSID with bridge mode.
  • Page 70 ZyXEL G-570S User’s Guide Table 13 Wireless Settings: Bridge (continued) LABEL DESCRIPTION Output Power Set the output power of the device in this field. If there is a high density of APs Management within an area, decrease the output power of the device to reduce interference with other APs.
  • Page 71: Figure 42 Wireless Settings: Ap+Repeater

    ZyXEL G-570S User’s Guide Figure 42 Wireless Settings: AP+Repeater Chapter 6 Wireless Screens...
  • Page 72: Table 14 Wireless Settings: Ap + Repeater

    ZyXEL G-570S User’s Guide The following table describes the labels in this screen. Table 14 Wireless Settings: AP + Repeater LABEL DESCRIPTION Operation Mode Select the operating mode from the drop-down list. The options are Access Point, Wireless Client, Bridge and AP+Repeater. SSID Wireless stations associating to the access point (AP) must have the same SSID.
  • Page 73: Wireless Security Overview

    Table 14 Wireless Settings: AP + Repeater (continued) LABEL DESCRIPTION Output Power Set the output power of the device in this field. If there is a high density of APs Management within an area, decrease the device’s output power to reduce interference with other APs.
  • Page 74: Encryption

    ZyXEL G-570S User’s Guide The figure below shows the possible wireless security levels on your G-570S. EAP (Extensible Authentication Protocol) is used for authentication and utilizes dynamic WEP key exchange. It requires interaction with a RADIUS (Remote Authentication Dial-In User Service) server either on the WAN or your LAN to provide authentication service for wireless stations.
  • Page 75: Hide G-570S Identity

    6.4.4 Hide G-570S Identity If you hide the ESSID, then the G-570S cannot be seen when a wireless client scans for local APs. The trade-off for the extra security of “hiding” the G-570S may be inconvenience for some valid WLAN clients. 6.5 WEP Overview WEP (Wired Equivalent Privacy) as specified in the IEEE 802.11 standard provides methods for both data encryption and wireless station authentication.
  • Page 76: Overview

    ZyXEL G-570S User’s Guide Open system authentication involves an unencrypted two-message procedure. A wireless station sends an open system authentication request to the AP, which will then automatically accept and connect the wireless station to the network. In effect, open system is not authentication at all as any station can gain access to the network.
  • Page 77: Eap Authentication Overview

    • Access-Request Sent by an access point, requesting authentication. • Access-Reject Sent by a RADIUS server rejecting access. • Access-Accept Sent by a RADIUS server allowing access. • Access-Challenge Sent by a RADIUS server requesting more information in order to allow access. The access point sends a proper response from the user and then sends another Access- Request message.
  • Page 78: Dynamic Wep Key Exchange

    ZyXEL G-570S User’s Guide Figure 44 EAP Authentication The details below provide a general description of how IEEE 802.1x EAP authentication works. For an example list of EAP-MD5 authentication steps, see the IEEE 802.1x appendix. 1 The wireless station sends a “start” message to the G-570S. 2 The G-570S sends a “request identity”...
  • Page 79: Encryption

    Key differences between WPA(2) and WEP are improved data encryption and user authentication. If both an AP and the wireless clients support WPA2 and you have an external RADIUS server, use WPA2 for stronger data encryption. If you don't have an external RADIUS server, you should use WPA2-PSK (WPA2-Pre-Shared Key) that only requires a single (identical) password entered into each access point, wireless gateway and wireless client.
  • Page 80: Wpa(2) With Radius Application Example

    ZyXEL G-570S User’s Guide Figure 45 WPA(2)-PSK Authentication 6.12 WPA(2) with RADIUS Application Example You need the IP address of the RADIUS server, its port number (default is 1812), and the RADIUS shared secret. A WPA(2) application example with an external RADIUS server looks as follows.
  • Page 81: Security Parameters Summary

    6.13 Security Parameters Summary Refer to this table to see what other security parameters you should configure for each authentication method/ key management protocol type. You enter manual keys by first selecting 64-bit WEP, 128-bit WEP or 152-bit WEP from the WEP Encryption field and then typing the keys (in ASCII or hexadecimal format) in the key text boxes.
  • Page 82: Figure 47 Wireless Security: Disable

    ZyXEL G-570S User’s Guide 6.15.1 Wireless Security: Disable If you do not enable any wireless security on your device, your network is accessible to any wireless networking device that is within range. Figure 47 Wireless Security: Disable The following table describes the labels in this screen. Table 17 Wireless Security: Disable LABEL DESCRIPTION...
  • Page 83: Figure 48 Wireless Security: Wep

    Figure 48 Wireless Security: WEP The following table describes the labels in this screen. Table 18 Wireless Security: WEP LABEL DESCRIPTION Encryption Method Select WEP if you want to configure WEP encryption parameters. Authentication Select Auto, Open or Shared from the drop-down list box. Type WEP Encryption Select 64 bit WEP, 128 bit WEP or 152 bit WEP to enable data encryption.
  • Page 84: Figure 49 Wireless Security: Wpa(2)-Psk

    ZyXEL G-570S User’s Guide 6.15.3 Wireless Security: WPA(2)-PSK Select WPA-PSK, WPA2-PSK or WPA-PSK & WPA2-PSK in the Encryption Method drop down list-box to display the screen displays as next. Figure 49 Wireless Security: WPA(2)-PSK The following table describes the labels in this screen. Table 19 Wireless Security: WPA-PSK LABEL DESCRIPTION...
  • Page 85: Figure 50 Wireless Security: Wpa(2)

    Figure 50 Wireless Security: WPA(2) The following table describes the labels in this screen. Table 20 Wireless Security: WPA(2) LABEL DESCRIPTION Encryption Method Select WPA, WPA2 or WPA & WPA2 to configure user authentication and improved data encryption. Note: WPA, WPA2 and IEEE 802.1x wireless security are not Authentication Enter the IP address of the external authentication server in dotted decimal Server IP Address...
  • Page 86: Figure 51 Wireless Security: 802.1X

    ZyXEL G-570S User’s Guide Table 20 Wireless Security: WPA(2) (continued) LABEL DESCRIPTION Global-Key This is how often the AP sends a new group key out to all clients. The re-keying Update process is the WPA equivalent of automatically changing the WEP key for an AP and all stations in a WLAN on a periodic basis.
  • Page 87: Table 21 Wireless Security: 802.1X

    The following table describes the labels in this screen. Table 21 Wireless Security: 802.1x LABEL DESCRIPTION Encryption Method Select 802.1X to configure authentication of wireless stations and encryption key management. Note: WPA, WPA2 and IEEE 802.1x wireless security are not Data Encryption Select None to allow wireless stations to communicate with the access points without using dynamic WEP key exchange.
  • Page 88: Figure 52 Mac Filter

    ZyXEL G-570S User’s Guide The following applies if you set the device to client mode and want to connect to an AP that uses a MAC filter. After the device turns on in client mode, it clones the MAC address of the first packets that it receives from devices connected to the Ethernet port.
  • Page 89: Enabling Otist

    The following table describes the labels in this screen. Table 22 MAC Filter LABEL DESCRIPTION Active Select the check box to enable MAC address filtering and define the filter action for the list of MAC addresses in the MAC address filter table. Select Allow the following MAC address to associate to permit access to the device, MAC addresses not listed will be denied access to the device.
  • Page 90: Wireless Client

    ZyXEL G-570S User’s Guide Hold in the OTIST button for one or two seconds. 6.17.1.1.2 Web Configurator Click WIRELESS > SETTINGS > OTIST to configure and enable OTIST. The screen appears as shown. Note: At the time of writing the device does not support OTIST in the wireless client mode.
  • Page 91: Starting Otist

    Figure 54 Example Wireless Client OTIST Screen 6.17.2 Starting OTIST Note: You must click Start in the AP OTIST web configurator screen and in the wireless client(s) Adapter screen all within three minutes (at the time of writing). You can start OTIST in the wireless clients and AP in any order but they must all be within range and have OTIST enabled.
  • Page 92: Notes On Otist

    ZyXEL G-570S User’s Guide 2 This screen appears while OTIST settings are being transferred. It closes when the transfer is complete. Figure 56 OTIST in Progress (AP) Figure 57 OTIST in Progress (Client) • In the wireless client, you see this screen if it can't find an OTIST-enabled AP (with the same Setup key).
  • Page 93: Figure 59 Start Otist

    Figure 59 Start OTIST? 2 If an OTIST-enabled wireless client loses its wireless connection for more than ten seconds, it will search for an OTIST-enabled AP for up to one minute. (If you manually have the wireless client search for an OTIST-enabled AP, there is no timeout; click Cancel in the OTIST progress screen to stop the search.) 3 When the wireless client finds an OTIST-enabled AP, you must still click Start in the AP OTIST web configurator screen or hold in the OTIST button (for one or two seconds)
  • Page 94 ZyXEL G-570S User’s Guide Chapter 6 Wireless Screens...
  • Page 95: Chapter 7 Management Screens

    This chapter describes the Maintenance screens. 7.1 Maintenance Overview Use these maintenance screens to change the password, view logs, back up or restore the G- 570S configuration and change the web configurator language. 7.2 Password To change your device's password (recommended), click SETTINGS > MANAGEMENT. The screen appears as shown.
  • Page 96: Figure 61 Management: Logs

    ZyXEL G-570S User’s Guide Table 24 Management: Password (continued) LABEL DESCRIPTION Apply Click Apply to save your changes back to the device. Cancel Click Cancel to reload the previous configuration for this screen. 7.3 Logs Click SETTINGS > MANAGEMENT > Logs to open the Logs screen. You can view logs and alert messages in this screen.
  • Page 97: Figure 62 Management: Configuration File

    Table 25 Management: Logs (continued) LABEL DESCRIPTION Source This field lists the source IP address and the port number of the incoming packet that caused the log. Destination This field lists the destination IP address and the port number of the outgoing packet that caused the log.
  • Page 98: Backup Configuration

    ZyXEL G-570S User’s Guide 7.4.1 Backup Configuration Backup configuration allows you to back up (save) the device's current configuration to a file on your computer. Once your device is configured and functioning properly, it is highly recommended that you back up your configuration file before making configuration changes. The backup configuration file will be useful in case you need to return to your previous settings.
  • Page 99: Back To Factory Defaults

    Figure 64 Network Temporarily Disconnected If you uploaded the default configuration file you may need to change the IP address of your computer to be in the same subnet as that of the default device IP address (192.168.1.2). If the upload was not successful, the following screen will appear. Click Return to go back to the Configuration File screen.
  • Page 100: Figure 67 Management: F/W Upload

    ZyXEL G-570S User’s Guide Click SETTINGS > MANAGEMENT > F/W Upload to display the screen as shown. Follow the instructions in this screen to upload firmware to your device. Figure 67 Management: F/W Upload The following table describes the labels in this screen. Table 27 Management: F/W Upload LABEL DESCRIPTION...
  • Page 101: Figure 69 Network Temporarily Disconnected

    ZyXEL G-570S User’s Guide Figure 69 Network Temporarily Disconnected After two minutes, log in again and check your new firmware version in the System Status screen. If the upload was not successful, the following status message displays at the bottom of the screen.
  • Page 102 ZyXEL G-570S User’s Guide Chapter 7 Management Screens...
  • Page 103: Chapter 8 Troubleshooting

    This chapter covers potential problems and possible remedies. After each problem description, some instructions are provided to help you to diagnose and to solve the problem. 8.1 Problems Starting Up the G-570S Table 28 Troubleshooting the Start-Up of Your G-570S PROBLEM CORRECTIVE ACTION None of the LEDs...
  • Page 104: Problems With The Wlan Interface

    ZyXEL G-570S User’s Guide 8.3 Problems with the WLAN Interface Table 30 Troubleshooting the WLAN Interface PROBLEM Cannot access the G-570S from the WLAN. I cannot ping any computer on the WLAN. 8.4 Problems with the Ethernet Interface Table 31 Troubleshooting the Ethernet Interface PROBLEM I cannot access the G-570S from the...
  • Page 105: Pop-Up Windows, Javascripts And Java Permissions

    Table 31 Troubleshooting the Ethernet Interface (continued) PROBLEM Cannot access the web configurator. 8.4.1 Pop-up Windows, JavaScripts and Java Permissions In order to use the web configurator you need to allow: • Web browser pop-up windows from your device. • JavaScripts (enabled by default). •...
  • Page 106: Figure 71 Pop-Up Blocker

    ZyXEL G-570S User’s Guide 8.4.1.1.1 Disable pop-up Blockers 1 In Internet Explorer, select Tools, Pop-up Blocker and then select Turn Off Pop-up Blocker. Figure 71 Pop-up Blocker You can also check if pop-up blocking is disabled in the Pop-up Blocker section in the Privacy tab.
  • Page 107: Figure 73 Internet Options

    8.4.1.1.2 Enable pop-up Blockers with Exceptions Alternatively, if you only want to allow pop-up windows from your device, see the following steps. 1 In Internet Explorer, select Tools, Internet Options and then the Privacy tab. 2 Select Settings…to open the Pop-up Blocker Settings screen. Figure 73 Internet Options 3 Type the IP address of your device (the web page that you do not want to have blocked) with the prefix “http://”.
  • Page 108: Javascripts

    ZyXEL G-570S User’s Guide Figure 74 Pop-up Blocker Settings 5 Click Close to return to the Privacy screen. 6 Click Apply to save this setting. 8.4.1.2 JavaScripts If pages of the web configurator do not display properly in Internet Explorer, check that JavaScripts are allowed.
  • Page 109: Figure 75 Internet Options

    ZyXEL G-570S User’s Guide Figure 75 Internet Options 2 Click the Custom Level... button. 3 Scroll down to Scripting. 4 Under Active scripting make sure that Enable is selected (the default). 5 Under Scripting of Java applets make sure that Enable is selected (the default). 6 Click OK to close the window.
  • Page 110: Java Permissions

    ZyXEL G-570S User’s Guide Figure 76 Security Settings - Java Scripting 8.4.1.3 Java Permissions 1 From Internet Explorer, click Tools, Internet Options and then the Security tab. 2 Click the Custom Level... button. 3 Scroll down to Microsoft VM. 4 Under Java permissions make sure that a safety level is selected. 5 Click OK to close the window.
  • Page 111: Figure 77 Security Settings - Java

    Figure 77 Security Settings - Java 8.4.1.3.1 JAVA (Sun) 1 From Internet Explorer, click Tools, Internet Options and then the Advanced tab. 2 make sure that Use Java 2 for <applet> under Java (Sun) is selected. 3 Click OK to close the window. Chapter 8 Troubleshooting ZyXEL G-570S User’s Guide...
  • Page 112: Testing The Connection To The G-570S

    ZyXEL G-570S User’s Guide Figure 78 Java (Sun) 8.5 Testing the Connection to the G-570S 1 Click Start, (All) Programs, Accessories and then Command Prompt. 2 In the Command Prompt window, type “ping” followed by a space and the IP address of the G-570S (192.168.1.2 is the default).
  • Page 113 ZyXEL G-570S User’s Guide Chapter 8 Troubleshooting...
  • Page 114 ZyXEL G-570S User’s Guide Chapter 8 Troubleshooting...
  • Page 115: Product Specifications

    See also the introduction chapter for a general overview of the key features. Specification Tables Table 32 Device Specifications Default IP Address Default Subnet Mask Default Password Dimensions Weight Ethernet Port Antenna Power Requirements Operation Temperature Storage Temperature Operation Humidity Storage Humidity Table 33 Feature Specifications Protocol Support...
  • Page 116: Table 34 Wireless Rf Specifications

    ZyXEL G-570S User’s Guide Table 33 Feature Specifications (continued) Operating Modes Wireless Links Management Security Diagnostics Capabilities Built-in Diagnostic Tools for FLASH memory, RAM, Ethernet port and Hardware Features Table 34 Wireless RF Specifications Data Rate Communication Method Transmission/Emission Type Access Point Client Bridge...
  • Page 117: Table 35 Approvals

    Table 34 Wireless RF Specifications Security RF frequency range Data modulation type Output Power Sensitivity Coverage Antenna a. Peak Output Power is 11b: 17.32 dBm, 11g: 21.48 dBm, Turbo mode: 22.25 dBm Approvals Table 35 Approvals SAFETY ELECTROSTATIC DISCHARGE RADIO-FREQUENCY ELECTROMAGNETIC FIELD EFT/BURST SURGE...
  • Page 118: Table 36 Power Adaptor Specifications

    ZyXEL G-570S User’s Guide Table 35 Approvals (continued) VOLTAGE DIPS/ INTERRUPTION EM FIELD FROM DIGITAL TELEPHONES LAN COMPATIBILITY FOR WIRELESS PC CARD Power Adaptor Specifications Table 36 Power Adaptor Specifications AUSTRALIAN PLUG STANDARDS AC Power Adapter Model Input Power Output Power Power Consumption Safety Standards EUROPEAN PLUG STANDARDS...
  • Page 119 Table 36 Power Adaptor Specifications (continued) Power Consumption Safety Standards Appendix A Product Specifications ZyXEL G-570S User’s Guide 12 Watts CE mark, EN60950 (2001)
  • Page 120 ZyXEL G-570S User’s Guide Appendix A Product Specifications...
  • Page 121: Setting Up Your Computer's Ip Address

    Setting up Your Computer’s IP Address All computers must have a 10M or 100M Ethernet adapter card and TCP/IP installed. Windows 95/98/Me/NT/2000/XP, Macintosh OS 7 and later operating systems and all versions of UNIX/LINUX include the software components you need to install and use TCP/ IP on your computer.
  • Page 122: Figure 80 Windows 95/98/Me: Network: Configuration

    ZyXEL G-570S User’s Guide Figure 80 WIndows 95/98/Me: Network: Configuration Installing Components The Network window Configuration tab displays a list of installed components. You need a network adapter, the TCP/IP protocol and Client for Microsoft Networks. If you need the adapter: 1 In the Network window, click Add.
  • Page 123: Figure 81 Windows 95/98/Me: Tcp/Ip Properties: Ip Address

    3 Select Microsoft from the list of manufacturers. 4 Select Client for Microsoft Networks from the list of network clients and then click 5 Restart your computer so the changes you made take effect. Configuring 1 In the Network window Configuration tab, select your network adapter's TCP/IP entry and click Properties 2 Click the IP Address tab.
  • Page 124: Figure 82 Windows 95/98/Me: Tcp/Ip Properties: Dns Configuration

    ZyXEL G-570S User’s Guide Figure 82 Windows 95/98/Me: TCP/IP Properties: DNS Configuration 4 Click the Gateway tab. • • 5 Click OK to save and close the TCP/IP Properties window. 6 Click OK to close the Network window. Insert the Windows CD if prompted. 7 Turn on your G-570S and restart your computer when prompted.
  • Page 125: Figure 83 Windows Xp: Start Menu

    Figure 83 Windows XP: Start Menu 2 In the Control Panel, double-click Network Connections (Network and Dial-up Connections in Windows 2000/NT). Figure 84 Windows XP: Control Panel 3 Right-click Local Area Connection and then click Properties. Appendix B Setting up Your Computer’s IP Address ZyXEL G-570S User’s Guide...
  • Page 126: Figure 85 Windows Xp: Control Panel: Network Connections: Properties

    ZyXEL G-570S User’s Guide Figure 85 Windows XP: Control Panel: Network Connections: Properties 4 Select Internet Protocol (TCP/IP) (under the General tab in Win XP) and then click Properties. Figure 86 Windows XP: Local Area Connection Properties 5 The Internet Protocol TCP/IP Properties window opens (the General tab in Windows XP).
  • Page 127: Figure 87 Windows Xp: Internet Protocol (Tcp/Ip) Properties

    • • Figure 87 Windows XP: Internet Protocol (TCP/IP) Properties 6 If you do not know your gateway's IP address, remove any previously installed gateways in the IP Settings tab and click OK. Do one or more of the following if you want to configure additional IP addresses: •...
  • Page 128: Figure 88 Windows Xp: Advanced Tcp/Ip Properties

    ZyXEL G-570S User’s Guide Figure 88 Windows XP: Advanced TCP/IP Properties 7 In the Internet Protocol TCP/IP Properties window (the General tab in Windows XP): • • Click Obtain DNS server address automatically if you do not know your DNS server IP address(es). If you know your DNS server IP address(es), click Use the following DNS server addresses, and type them in the Preferred DNS server and Alternate DNS server fields.
  • Page 129: Figure 89 Windows Xp: Internet Protocol (Tcp/Ip) Properties

    Figure 89 Windows XP: Internet Protocol (TCP/IP) Properties 8 Click OK to close the Internet Protocol (TCP/IP) Properties window. 9 Click Close (OK in Windows 2000/NT) to close the Local Area Connection Properties window. 10 Close the Network Connections window (Network and Dial-up Connections in Windows 2000/NT).
  • Page 130: Figure 90 Macintosh Os 8/9: Apple Menu

    ZyXEL G-570S User’s Guide Figure 90 Macintosh OS 8/9: Apple Menu 2 Select Ethernet built-in from the Connect via list. Figure 91 Macintosh OS 8/9: TCP/IP 3 For dynamically assigned settings, select Using DHCP Server from the Configure: list. Appendix B Setting up Your Computer’s IP Address...
  • Page 131: Figure 92 Macintosh Os X: Apple Menu

    4 For statically assigned settings, do the following: • • • • 5 Close the TCP/IP Control Panel. 6 Click Save if prompted, to save changes to your configuration. 7 Turn on your G-570S and restart your computer (if prompted). Verifying Settings Check your TCP/IP properties in the TCP/IP Control Panel window.
  • Page 132: Figure 93 Macintosh Os X: Network

    ZyXEL G-570S User’s Guide Figure 93 Macintosh OS X: Network 4 For statically assigned settings, do the following: • • • • 5 Click Apply Now and close the window. 6 Turn on your G-570S and restart your computer (if prompted). Verifying Settings Check your TCP/IP properties in the Network window.
  • Page 133: Figure 94 Red Hat 9.0: Kde: Network Configuration: Devices

    Note: Make sure you are logged in as the root administrator. Using the K Desktop Environment (KDE) Follow the steps below to configure your computer IP address using the KDE. 1 Click the Red Hat button (located on the bottom left corner), select System Setting and click Network.
  • Page 134: Figure 96 Red Hat 9.0: Kde: Network Configuration: Dns

    ZyXEL G-570S User’s Guide • • 3 Click OK to save the changes and close the Ethernet Device General screen. 4 If you know your DNS server IP address(es), click the DNS tab in the Network Configuration screen. Enter the DNS server information in the fields provided. Figure 96 Red Hat 9.0: KDE: Network Configuration: DNS 5 Click the Devices tab.
  • Page 135: Figure 98 Red Hat 9.0: Dynamic Ip Address Setting In Ifconfig-Eth0

    1 Assuming that you have only one network card on the computer, locate the configuration file (where eth0 configuration file with any plain text editor. • Figure 98 Red Hat 9.0: Dynamic IP Address Setting in ifconfig-eth0 DEVICE=eth0 ONBOOT=yes BOOTPROTO=dhcp USERCTL=no PEERDNS=yes TYPE=Ethernet...
  • Page 136: Figure 101 Red Hat 9.0: Restart Ethernet Card

    ZyXEL G-570S User’s Guide Figure 101 Red Hat 9.0: Restart Ethernet Card [root@localhost init.d]# network restart Shutting down interface eth0: Shutting down loopback interface: Setting network parameters: Bringing up loopback interface: Bringing up interface eth0: Verifying Settings Enter in a terminal screen to check your TCP/IP properties. ifconfig Figure 102 Red Hat 9.0: Checking TCP/IP Properties [root@localhost]# ifconfig...
  • Page 137: Appendix C Wireless Lans

    Wireless LAN Topologies This section discusses ad-hoc and infrastructure wireless LAN topologies. Ad-hoc Wireless LAN Configuration The simplest WLAN configuration is an independent (Ad-hoc) WLAN that connects a set of computers with wireless stations (A, B, C). Any time two or more wireless adapters are within range of each other, they can set up an independent network, which is commonly referred to as an Ad-hoc network or Independent Basic Service Set (IBSS).
  • Page 138: Figure 104 Basic Service Set

    ZyXEL G-570S User’s Guide Figure 104 Basic Service Set An Extended Service Set (ESS) consists of a series of overlapping BSSs, each containing an access point, with each access point connected together by a wired network. This wired connection between APs is called a Distribution System (DS). This type of wireless LAN topology is called an Infrastructure WLAN.
  • Page 139: Figure 105 Infrastructure Wlan

    Figure 105 Infrastructure WLAN Channel A channel is the radio frequency(ies) used by IEEE 802.11a/b/g wireless devices. Channels available depend on your geographical area. You may have a choice of channels (for your region) so you should use a different channel than an adjacent AP (access point) to reduce interference.
  • Page 140: Figure 106 Rts/Cts

    ZyXEL G-570S User’s Guide Figure 106 RTS/CTS When station A sends data to the AP, it might not know that the station B is already using the channel. If these two stations send data at the same time, collisions may occur when both sets of data arrive at the AP at the same time, resulting in a loss of messages for both stations.
  • Page 141: Table 37 Ieee 802.11G

    A large Fragmentation Threshold is recommended for networks not prone to interference while you should set a smaller threshold for busy networks or networks that are prone to interference. If the Fragmentation Threshold value is smaller than the RTS/CTS value (see previously) you set then the RTS (Request To Send)/CTS (Clear to Send) handshake will never occur as data frames will be fragmented before they reach RTS/CTS size.
  • Page 142 ZyXEL G-570S User’s Guide • Authentication Determines the identity of the users. • Authorization Determines the network services available to authenticated users once they are connected to the network. • Accounting Keeps track of the client’s network activity. RADIUS is a simple package exchange in which your AP acts as a message relay between the wireless station and the network RADIUS server.
  • Page 143: Figure 107 Eap Authentication

    EAP Authentication EAP (Extensible Authentication Protocol) is an authentication protocol that runs on top of the IEEE802.1x transport mechanism in order to support multiple types of user authentication. By using EAP to interact with an EAP-compatible RADIUS server, the access point helps a wireless station and a RADIUS server perform authentication.
  • Page 144: Wep Encryption

    ZyXEL G-570S User’s Guide However, MD5 authentication has some weaknesses. Since the authentication server needs to get the plaintext passwords, the passwords must be stored. Thus someone other than the authentication server may access the password file. In addition, it is possible to impersonate an authentication server as MD5 authentication method does not perform mutual authentication.
  • Page 145: Figure 108 Wep Authentication Steps

    WEP Authentication Steps Three different methods can be used to authenticate wireless stations to the network: Open System, Shared Key, and Auto. The following figure illustrates the steps involved. Figure 108 WEP Authentication Steps Open system authentication involves an unencrypted two-message procedure. A wireless station sends an open system authentication request to the AP, which will then automatically accept and connect the wireless station to the network.
  • Page 146: Table 38 Comparison Of Eap Authentication Types

    ZyXEL G-570S User’s Guide Dynamic WEP Key Exchange The AP maps a unique key that is generated with the RADIUS server. This key expires when the wireless connection times out, disconnects or reauthentication times out. A new WEP key is generated each time reauthentication is performed. If this feature is enabled, it is not necessary to configure a default encryption key in the Wireless screen.
  • Page 147 TKIP uses 128-bit keys that are dynamically generated and distributed by the authentication server. It includes a per-packet key mixing function, a Message Integrity Check (MIC) named Michael, an extended initialization vector (IV) with sequencing rules, and a re-keying mechanism. TKIP regularly changes and rotates the encryption keys so that the same encryption key is never used twice.
  • Page 148: Figure 109 Roaming Example

    ZyXEL G-570S User’s Guide If the roaming feature is not enabled on the access points, information is not communicated between the access points when a wireless station moves between coverage areas. The wireless station may not be able to communicate with other wireless stations on the network and vice versa.
  • Page 149 ZyXEL G-570S User’s Guide 5 The access points must be connected to the Ethernet and be able to get IP addresses from a DHCP server if using dynamic IP address assignment. Appendix C Wireless LANs...
  • Page 150 ZyXEL G-570S User’s Guide Appendix C Wireless LANs...
  • Page 151: Table 39 Classes Of Ip Addresses

    IP Addressing Routers “route” based on the network number. The router that delivers the data packet to the correct destination host uses the host ID. IP Classes An IP address is made up of four octets (eight bits), written in dotted decimal notation, for example, 192.168.1.1.
  • Page 152: Table 40 Allowed Ip Address Range By Class

    ZyXEL G-570S User’s Guide Since the first octet of a class “A” IP address must contain a “0”, the first octet of a class “A” address can have a value of 0 to 127. Similarly the first octet of a class “B” must begin with “10”, therefore the first octet of a class “B”...
  • Page 153: Table 42 Alternative Subnet Mask Notation

    Since the mask is always a continuous number of ones beginning from the left, followed by a continuous number of zeros for the remainder of the 32 bit mask, you can simply specify the number of ones instead of writing the value of each octet. This is usually specified by writing a “/”...
  • Page 154: Table 44 Subnet 1

    ZyXEL G-570S User’s Guide Note: In the following charts, shaded/bolded last octet bit values indicate host ID bits “borrowed” to form network ID bits. The number of “borrowed” host ID bits determines the number of subnets you can have. The remaining number of host ID bits (after “borrowing”) determines the number of hosts you can have on each subnet.
  • Page 155: Table 46 Subnet 1

    Example: Four Subnets The above example illustrated using a 25-bit subnet mask to divide a class “C” address space into two subnets. Similarly to divide a class “C” address into four subnets, you need to “borrow” two host ID bits to give four possible combinations of 00, 01, 10 and 11. The subnet mask is 26 bits (11111111.11111111.11111111.11000000) or 255.255.255.192.
  • Page 156: Table 49 Subnet 4

    ZyXEL G-570S User’s Guide Table 49 Subnet 4 IP Address IP Address (Binary) Subnet Mask (Binary) Subnet Address: 192.168.1.192 Broadcast Address: 192.168.1.255 Example Eight Subnets Similarly use a 27-bit mask to create 8 subnets (001, 010, 011, 100, 101, 110). The following table shows class C IP address last octet values for each subnet.
  • Page 157: Table 52 Class B Subnet Planning

    Subnetting With Class A and Class B Networks. For class “A” and class “B” addresses the subnet mask also determines which bits are part of the network number and which are part of the host ID. A class “B” address has two host ID octets available for subnetting and a class “A” address has three host ID octets (see The following table is a summary for class “B”...
  • Page 158 ZyXEL G-570S User’s Guide Appendix D IP Subnetting...
  • Page 159: Index

    Numerics 110V AC 230V AC Abnormal Working Conditions Accessories Acts of God Address Assignment Ad-hoc Advanced Encryption Standard Airflow Alternative Subnet Mask Notation AP (access point) Association List Authentication 75, 145 Authority Auto MDI/MDI-X Auto-negotiating Basement Basic Service Set 57, 137 Cables, Connecting Certificate Authority Certifications...
  • Page 160 ZyXEL G-570S User’s Guide 74, 77, 79 EAP Authentication Electric Shock Electrical Pipes Encryption 79, 146 Equal Value 58, 138 ESS IDentification Ethernet Ports Europe European Plug Standards Exposure Extended Service Set 58, 138 Extensible Authentication Protocol Failure Compliance Rules, Part 15 FCC Rules Federal Communications Commission Finland, Contact Information...
  • Page 161 North American Plug Standards Norway, Contact Information Open System Opening Operating Condition Operation Humidity Operation Temperature Out-dated Warranty Outlet Pairwise Master Key (PMK) Parts Password Patent Permission Photocopying Pipes Pool Postage Prepaid. Power Adaptor Specifications Power Cord Private IP Address Product Model Product Page Product Serial Number...
  • Page 162 Wide Wired Equivalent Privacy Wireless Client WPA Supplicants WLAN Interference Workmanship Worldwide Contact Information WPA with RADIUS Application WPA2 WPA-PSK WPA-PSK Application Written Permission ZyNOS ZyXEL Communications Corporation ZyXEL Home Page ZyXEL Limited Warranty Note ZyXEL Network Operating System Index...

Table of Contents