Edimax AC-M1000 User Manual
Edimax AC-M1000 User Manual

Edimax AC-M1000 User Manual

Edimax technology network access controller user's manual
Hide thumbs Also See for AC-M1000:

Advertisement

Quick Links

AC-M3000 / AC-M1000
Network Access Controller
User's Manual
Version 1.00

Advertisement

Table of Contents
loading

Summary of Contents for Edimax AC-M1000

  • Page 1 AC-M3000 / AC-M1000 Network Access Controller User’s Manual Version 1.00...
  • Page 2 The product you have purchased and the setup screen may appear slightly different from those shown in this QIG. For more detailed information about this product, please refer to the User's Manual on the CD-ROM. Software and specifications subject to change without notice. Please visit our web site for the update.
  • Page 3: Table Of Contents

    System Overview ...4 Introduction of Edimax AC-M3000...4 System Concept ...4 Specification ...5 2.3.1 Hardware Specification...5 2.3.2 Technical Specification ...5 2.3.3 Comparison of AC-M3000 and AC-M1000...7 Base Installation ...8 Hardware Installation...8 3.1.1 System Requirements...8 3.1.2 Package Contents ...8 3.1.3 Panel Function Descriptions ...9 3.1.4...
  • Page 4 Appendix B – Network Configuration on PC ...125 Appendix C – IPSec VPN ...130 Appendix D –Proxy Setting for Hotspot...135 Appendix E –Proxy Setting for Enterprise ...140 Appendix F –Disclaimer for On-Demand Users ...146 Appendix G—DHCP Relay ...155 Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 5: Before You Start

    This manual is for Hotspot owners, SMBs, or administrators in enterprises to set up network environment using Edimax AC-M3000/AC-M1000. It contains step by step procedures and graphic examples to guide MIS staff or individuals with slight network system knowledge to complete the installation.
  • Page 6: System Overview

    Edimax AC-M3000/AC-M1000 User’s Manual 2. System Overview 2.1 Introduction of Edimax AC-M3000 Edimax AC-M3000 is a Network Access Controller, specially designed for the small scaled wireless and wired network management and access control. The major functional areas include user management, access control, AP management, and security management.
  • Page 7: Specification

    Supports Walled Garden (free surfing zone) Supports MAC Address Pass-Through Supports HTTP Proxy Security Supports data encryption: WEP (64/128-bit), WPA, WPA2 Supports authentication: WPA-PSK, WPA2-PSK, IEEE 802.1x (EAP-MD5, EAP-TLS, CHAP, PEAP) Supports VPN Pass-through (IPSec and PPTP) Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 8 Allows user identity plus MAC address authentication for local accounts User Management Supports up to 120 concurrent users for AC-M3000 (50 concurrent users for AC-M1000) Provides 500 local accounts for AC-M3000 (250 local accounts for AC-M1000) Provides 2000 on-demand accounts...
  • Page 9: Comparison Of Ac-M3000 And Ac-M1000

    System Administration Multi-lingual, web-based management UI SSH remote management Remote firmware upgrade NTP time synchronization Backup and restore of system configuration 2.3.3 Comparison of AC-M3000 and AC-M1000 Capacity and Performance Concurrent Users Local Accounts On-demand user Accounts Managed Access Points...
  • Page 10: Base Installation

    Power Adapter (DC 12V) x 1 Cross Over Ethernet Cable x 1 Console Cable x 1 Warning: It is highly recommended to use all the supplies in the package instead of substituting any components by other suppliers to guarantee best performance. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 11: Panel Function Descriptions

    Console: The system can be configured via a serial console port. The administrator can use a terminal emulation program such as Microsoft’s HyperTerminal to login to the configuration console interface to change admin password or monitor system status, etc. DC+12V: The power adapter attaches here. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 12: Installation Steps

    AP while connecting with a straight cable, the user have to pull out and plug-in the straight cable again. This scenario does NOT occur while using a crossover cable. After the hardware of Edimax AC-M3000 is installed completely, the system is ready to be configured in the following sections. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 13: Software Configuration

    Please use default IP address such as 192.168.2.xx in your network and then try it again. For the PC configuration on PC, please refer to 6. Appendix B – Network Configuration on PC. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 14 There is a Logout button on the upper right corner to log out the system when finished. Then, run the configuration wizard to complete the configuration. Click System Configuration, the System Configuration page will appear. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 15 Edimax AC-M3000/AC-M1000 User’s Manual Then, click on Configuration Wizard and click the Run Wizard to start the wizard.
  • Page 16 Verify Password field (twenty-character is the maximum and spaces are not allowed). Click Next to continue. Step 2. Choose System’s Time Zone Select a proper time zone via the drop-down menu. Click Next to continue. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 17 “Default Gateway” provided by your ISP or network administrator. Click Next to continue. Dynamic IP Address If this option is selected, Edimax AC-M3000 will get an IP address for WAN1 from an external DHCP server automatically. Click Next to continue. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 18 ADD button to add this user.. Attention: The policy selected in this step is applied to this user only. Per-user policy setting takes over the group policy setting at precious step unless you select None here. Click Next to continue. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 19 Edimax AC-M3000/AC-M1000 User’s Manual POP3 User: POP3 Enter Domain Name/IP, Server Port of the POP3 server provided by the ISP, and then choose to enable SSL or not. Click Next to continue. RADIUS User: RADIUS Enter the Domain Name/IP of the RADIUS server, Authentication Port, Accounting Port and Secret Key.
  • Page 20 “Restarting now. Please wait for a moment…” message will appear on the screen. Please do not interrupt Edimax AC-M3000 until the message has disappeared. This indicates that a completed and successful restart process is finished. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 21: User Login Portal Page

    Password (e.g. test@local for the username and test for the password). Click Submit button. 2. Login succeed page will appear if Edimax AC-M3000 has been installed and configured successfully. Now, clients can access the network or surf on the Internet. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 22 After clicking the Redeem button, a Redeem Page will appear. Please enter the new username and password obtained and click Enter button. The total available time or data size will be shown up after adding credit. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 23: Web Interface Configuration

    AP List Configuration Black List AP Discovery Configuration Policy Manual Configuration Configuration Additional Template Configuration Settings Firmware Management AP Upgrade Edimax AC-M3000/AC-M1000 Network Utilities Configuration Network Change Address Password Translation Backup/Restore Privilege List Settings Firmware Monitor IP List Upgrade Walled Garden...
  • Page 24: System Configuration

    Edimax AC-M3000/AC-M1000 User’s Manual 4.1 System Configuration This section includes the following functions: Configuration Wizard, System Information, WAN1 Configuration, WAN2 & Failover, LAN Port Roles, Controlled Configuration and Uncontrolled Configuration. 4.1.1 Configuration Wizard There are two ways to configure the system: using Configuration Wizard or changing the setting by demands manually.
  • Page 25: System Information

    Edimax AC-M3000/AC-M1000 User’s Manual 4.1.2 System Information Most of the major system information about Edimax AC-M3000 can be set here. Please refer to the following description for each field:...
  • Page 26 Please specify the time zone and IP address of at least one NTP server in the system configuration interface for adjusting the system time automatically. (Universal Time is Greenwich Mean Time, GMT). Time can also be set manually when selecting “Set Device Date and Time”. Please enter the date and Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 27: Wan1 Configuration

    Edimax AC-M3000/AC-M1000 User’s Manual time into these fields. 4.1.3 WAN1 Configuration There are 4 connection types for the WAN1 Port: Static IP Address, Dynamic IP Address, PPPoE Client and PPTP Client.
  • Page 28 Username, Password, MTU and CLAMPMSS. There is a Dial on Demand function under PPPoE. If this function is enabled, a Maximum Idle Time can be set. When the idle time is reached, the system will automatically disconnect itself Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 29 Edimax AC-M3000/AC-M1000 User’s Manual PPTP Client: Point to Point Tunneling Protocol is a service that applies to broadband connection used mainly in Europe and Israel. Select Static to specify the IP address of the PPTP Client manually or select DHCP to get the IP address automatically.
  • Page 30: Wan2 & Failover

    Edimax AC-M3000/AC-M1000 User’s Manual 4.1.4 WAN2 & Failover Except selecting None to disable WAN2 port, there are 2 connection types for the WAN2 port: Static IP Address and Dynamic IP Address. The probe target supports up to three URLs. Check “Warning of Internet Disconnection”...
  • Page 31 Dynamic IP Address: Select this item when WAN2 Port can obtain an IP address automatically. For example, a DHCP Server is available for WAN2 Port. The probe target supports up to three URLs. Check “Warning of Internet Disconnection” box to work with the WAN Failover function. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 32: Lan Port Roles

    The differences of these two roles for a client connected to are: Clients connecting to the Controlled Port need authentication to access the network; Clients connecting to Uncontrolled Port don’t need authentication to access the network and can also access the web management interface. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 33: Controlled Configuration

    1. Disable DHCP Server: Disable DHCP Server function of Edimax AC-M3000. 2. Enable DHCP Server: Choose Enable DHCP Sever function and set the appropriate configuration for the built-in DHCP server of Edimax AC-M3000. The fields with red asterisks are required. Please fill in these fields. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 34 Reserved IP Address. After clicking, the Reserved IP Address List as shown in the following figure will appear. Enter the related Reserved IP Address, MAC, and Description (not compulsory). When finished, click Apply to complete the setting. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 35: Uncontrolled Configuration

    DHCP Relay, please see Appendix G—DHCP Relay. 4.1.7 Uncontrolled Configuration The clients of Uncontrolled Port don’t need authentication before they can access the network. In this section, you can set the related configuration of Uncontrolled Port. Uncontrolled Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 36 IP address of the DHCP scope. End IP Address means the last IP address of the DHCP scope. These two settings define the IP address range that will be assigned to the clients’ of Uncontrolled Port. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 37 Enter the related Reserved IP Address, MAC, and Description (not compulsory). When finished, click Apply to complete the setting. Enable DHCP Relay: The DHCP Server IP address must be entered when this function is enabled. For more details about DHCP Relay, please see Appendix G—DHCP Relay. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 38: User Authentication

    Edimax AC-M3000/AC-M1000 User’s Manual 4.2 User Authentication This section includes the following functions: Authentication Configuration, Black List Configuration, Policy Configuration, and Additional Configuration. 4.2.1 Authentication Configuration This function is used to configure the settings of authentication servers. Edimax AC-M3000 supports five types of authentication methods: Local User, POP3, Radius, LDAP, and NTDomain and provides up to three authentication servers and one on-demand user authentication server.
  • Page 39 Edimax AC-M3000/AC-M1000 User’s Manual Server 1~3: There are 5 kinds of authentication methods that Edimax AC-M3000 supports: Local User, POP3, RADIUS, LDAP and NTDomain. Click the server name to enter the Authentication Server page. Server Name: Set a name for the server using numbers (0 to 9), alphabets (a to z or A to Z), dash (-), underline (_) and dot (.) with a maximum of 40 characters, all other letters are not allowed.
  • Page 40 Remark: Enter any additional information that will appear at the bottom of the receipt. Billing Notice Interval: While an on-demand user is still logged in, the system will update the billing notice of the login successful page by the time interval defined here. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 41 Delete All: This will delete all users at once. Delete: This will delete a specific user individually. Billing Configuration: Click this to enter the Billing Configuration page. In the Billing Configuration page, the administrator may configure up to 10 billing plans. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 42 Valid Duration: This is the duration of time that the user can use the account after the activation of the account. After this duration, the account will self-expire. Price: The price charged for this billing plan. Create On-demand User: Click this to enter the Create On-demand User page. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 43 Edimax AC-M3000/AC-M1000 User’s Manual Pressing the Create button for the desired plan, an on-demand user will be created, then click Printout to print a receipt which will contain this on-demand user’s information. There are 2000 on-demand user accounts available. Billing Report: Click this to enter the On-demand users Summary report page. In On-demand users...
  • Page 44 Search: Select a time period to get a periodical report. The report tells the total expenses and individual accounting of each plan for all plans available for that period of time. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 45 Edit Local User List: Click the hyperlink of Edit User Setting to enter the Local User List page. Add User: Click this to enter the Add User interface. Fill in the necessary information such as “Username”, “Password”, “MAC” (optional) and “Remark” (optional). Select a desired Policy, check whether to enable Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 46 Edimax AC-M3000/AC-M1000 User’s Manual VPN Termination. Click Apply to save all the settings after finishing to add users. Upload User: Click this to enter the Upload User interface. Click the Browse button to select the text file for uploading the user accounts. Then click Submit to complete the upload process.
  • Page 47 Edimax AC-M3000/AC-M1000 User’s Manual The uploading file should be a text file and the format of each line is "ID, Password, MAC, Policy, Remark, IPSec" without the quotes. There must be no spaces between the fields and commas. The MAC field could be omitted but the trailing comma must be retained.
  • Page 48 Edimax AC-M3000/AC-M1000 User’s Manual Refresh: Click this to renew the Users List page. Search: Enter a keyword of a username that you want to search and click this button to perform the search. All...
  • Page 49 Radius Roaming Out / 802.1x Authentication: Radius Roaming Out / 802.1x Authentication: These 2 functions can be enabled or disabled by checking the radio buttons. Checking either of them makes the hyperlink of Radius Client List appear. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 50 RADIUS), letting the "authenticator" middleman simply pass the packets back and forth. 4.2.1.2 Authentication Method – POP3 Choose POP3 in the Authentication Method field, the hyperlink next to the drop-down menu will become POP3 Setting. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 51 Enable SSL Connection: If this function is enabled, the POP3s protocol will be used to encrypt the authentication. 4.2.1.3 Authentication Method – Radius Choose Radius in the Authentication Method field, the hyperlink next to the drop-down menu will become to Radius Setting. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 52 Edimax AC-M3000/AC-M1000 User’s Manual When POP3, Radius, LDAP or NTDomain is selected from the drop-down memu, the function of Enable VPN Termination will show up. Check Enable VPN Termination to enable this function. Click the hyperlink of Radius Setting for further configuration. Enter the related information of the primary server and/or the secondary server (the secondary server is not required).
  • Page 53 Authentication Protocol: There are two methods, CHAP and PAP, for selection. Edit Policy Mapping: Click the hyperlink of Edit Policy Mapping to enter the Policy Mapping page. Choose to enable or disable policy mapping by RADIUS class attributes. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 54 Setting for further configuration. Enter the related information of the primary server and/or the secondary server (the secondary server is not required). The blanks with red asterisks are necessary information. These settings will become effective immediately after clicking the Apply button. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 55 Domain Setting for further configuration. Enter the related information of the primary server and/or the secondary server (the secondary server is not required). The blanks with red asterisks are necessary information. These settings will become effective immediately after clicking the Apply button. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 56: Black List Configuration

    Name: Set the name of the black list and it will show in the pull-down menu above. Add User to List: Click the hyperlink of Add User to List, the Add Users to Blacklist page will appear for adding users to the selected black list. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 57 Edimax AC-M3000/AC-M1000 User’s Manual After entering the usernames in the Username field and the related information in the Remark field (not required). Click Apply to save the settings.
  • Page 58: Policy Configuration

    Delete button to remove that user from the black list. 4.2.3 Policy Configuration Each policy has three profiles, Firewall Profile, Specific Route Profile, and Schedule Profile as well as Bandwidth settings such as Total Bandwidth, Individual Maximum Bandwidth, and Individual Request Bandwidth for that policy. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 59 Edimax AC-M3000/AC-M1000 User’s Manual Firewall Profile Click the hyperlink of Setting for Firewall Profile, the Firewall Profile page will appear. Click the numbers of Filter Rule Item to edit individual rules and click Apply to save the settings. The rule status will show on the list.
  • Page 60 Edimax AC-M3000/AC-M1000 User’s Manual Rule Item: This is the rule selected. Rule Name: The rule name can be changed here. The rule name can be set to easily identify, for example: “from file server”, “HTTP request” or “to web”, etc.
  • Page 61 This function is used to restrict the time for users to log in. Please enable/disable the desired time slot and click Apply to save the settings. These settings will become effective immediately after clicking the Apply button. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 62 Select the bandwidth from the drop-down menu. It’s the total bandwidth the users under this particular policy need to share. Individual Maximum Bandwidth Select the bandwidth from the drop-down menu. It’s the most bandwidth an individual user can obtain under this Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 63: Additional Configuration

    Session Timeout: The time that the user can access the network while roaming. When the time is up, the user will be kicked out automatically. Idle Timeout: If a user has been idled with no network activities, the system will automatically kick out the user. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 64 Choose Default Page to use the default login page. b. Choose Template Page to make a customized login page here. Click Select to pick up a color and then fill in all of the blanks. Click Preview to see the result first. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 65 Edimax AC-M3000/AC-M1000 User’s Manual c. Choose Uploaded Page and upload a login page. Click the Browse button to select the file to upload. Then click Submit to complete the upload process.
  • Page 66 Edimax AC-M3000/AC-M1000 User’s Manual After the upload process is completed, the new login page can be previewed by clicking Preview button at the bottom. The user-defined login page must include the following HTML codes to provide the necessary fields for...
  • Page 67 The basic design is to have the disclaimer and login function in the same page but with the login function hidden until users agree with the disclaimer. For more details about the codes of the disclaimer, please refer to Appendix F. If the page is successfully loaded, an upload success page will show up. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 68 Edimax AC-M3000/AC-M1000 User’s Manual “Preview” can be clicked to see the uploaded page. If a user checks “I agree” and clicks Next, then he/she is prompted to fill in the login name and password. If a user checks “I disagree” and clicks Next, a window will pop up to tell user that he/she cannot log in...
  • Page 69 Edimax AC-M3000/AC-M1000 User’s Manual d. Choose the External Page selection and get the login page from the specific website. Enter the website address in the “External Page Setting” field and then click Apply. After applying the setting, the new login page can be previewed by clicking Preview button at the bottom...
  • Page 70 Edimax AC-M3000/AC-M1000 User’s Manual 3. Logout Page: The administrator can apply customized logout page here. The process is similar to that of Login Page. The different part is the HTML code of the user-defined logout interface must include the following HTML code that the user can enter the username and password.
  • Page 71 Edimax AC-M3000/AC-M1000 User’s Manual 4. Login Success Page: The administrator can use the default login success page or get the customized login success page by setting the template page, uploading the page or using the external website. After finishing the setting, you can click Preview to see the login success page.
  • Page 72 Edimax AC-M3000/AC-M1000 User’s Manual c. Choose Uploaded Page and you can get the login success page by uploading. Click the Browse button to select the file for the login success page upload. Then click Submit to complete the upload process.
  • Page 73 Edimax AC-M3000/AC-M1000 User’s Manual After the upload process is completed, the new login success page can be previewed by clicking Preview button at the bottom. f the user-defined login success page includes an image file, the image file path in the HTML code must be the image file you will upload.
  • Page 74 Choose Template Page to make a customized login success page for On-Demand here. Click Select to pick up a color and then fill in all of the blanks. You can click Preview to see the result first. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 75 Edimax AC-M3000/AC-M1000 User’s Manual c. Choose Uploaded Page and you can get the Login Success Page Section for On-Demand Users. Click the Browse button to select the file for the login success page for On-Demand. Then click Submit to complete the upload process.
  • Page 76 Edimax AC-M3000/AC-M1000 User’s Manual After the upload process is completed, the new login success page for On-Demand can be previewed by clicking Preview button at the bottom. f the user-defined login success page for On-Demand includes an image file, the image file path in the HTML code must be the image file you will upload.
  • Page 77 Choose Template Page to make a customized logout success page here. Click Select to pick up a color and then fill in all of the blanks. You can click Preview to see the result first. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 78 Edimax AC-M3000/AC-M1000 User’s Manual c. Choose Uploaded Page and you can get the logout success page by uploading. Click the Browse button to select the file for the logout success page upload. Then click Submit to complete the upload process.
  • Page 79 Edimax AC-M3000/AC-M1000 User’s Manual After the upload process is completed, the new logout success page can be previewed by clicking Preview button at the bottom. f the user-defined logout success page includes an image file, the image file path in the HTML code must be the image file you will upload.
  • Page 80 1Mbyte and the level for Time is 5 minutes. POP3 Message: If a user tries to retrieve mail from POP3 mail server before login, the users will receive a welcome mail from Edimax AC-M3000. The administrator can edit the content of this welcome mail. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 81 Edimax AC-M3000/AC-M1000 User’s Manual Enhance User Authentication: With this function enabled, only the users with their MAC addresses in this list can log into Edimax AC-M3000. There will only be 40 users allowed in this MAC address list. User authentication is still required for these users. Please click the Permit MAC Address List to fill in these MAC addresses, select Enable, and then click Apply.
  • Page 82: Ap Management

    Edimax AC-M3000/AC-M1000 User’s Manual 4.3 AP Management This section includes the following functions: AP List, AP Discovery, Manual Configuration, Template Settings, Firmware Management and AP Upgrade. 4.3.1 AP List All of the supported APs under the management of Edimax AC-M3000 will be shown in the list. At first the list is empty;...
  • Page 83 Edimax AC-M3000/AC-M1000 User’s Manual After adding an AP: Check any AP and click the button below to Reboot, Enable, Disable and Delete the checked AP. Click Apply Template to select one template to apply to the AP.
  • Page 84 Edimax AC-M3000/AC-M1000 User’s Manual AP Name Click AP Name and enter the interface about related settings. There four kinds of settings, General Settings, LAN Interface Setting, Wireless Interface Setting and Access Control Setting. Click the hyperlink of each individual setting to have further configurations.
  • Page 85 Edimax AC-M3000/AC-M1000 User’s Manual Password and Remark here if desired. Firmware information can also be viewed here. LAN Setting: Click LAN to enter the LAN Setting interface. Input the data of LAN including IP address, Subnet Mask and Default Gateway of AP.
  • Page 86 Select from a range of transmission speed or keep the default setting, Auto, to make the Access Point automatically use the fastest rate possible. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 87 Select Authentication Type (Open System, Shared Key or Both), Key Length (64 bits or 128 bits), Key Index (Key1~Key4) and then input the Key. Check 802.1x Authentication to enable this function and enter the related data, if necessary. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 88 WPA2: Wi-Fi Protected Access version 2. The follow on security method to WPA for Wi-Fi networks that provides stronger data protection and network access control. Select 802.1x or WPA-PSK security type and enter the related information below. WPA2 only can use AES encryption type. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 89 Edimax AC-M3000/AC-M1000 User’s Manual WPA Mixed: If using TKIP and AES encryption type at the same time is desired, choose this security type. Select 802.1x or WPA-PSK security type and enter the related information below. Access Control: In this function, when the status is Enabled, only these clients which MAC addresses are listed in the list can be allowed to connect Edimax AC-M3000.
  • Page 90 Edimax AC-M3000/AC-M1000 User’s Manual Status After clicking the hyperlink of Status, the basic information of the AP including AP Name, AP Type, LAN MAC, LAN MAC, Wireless LAN MAC, Up Time, Report Time, SSID, Number of Associated Clients and Remark will be shown.
  • Page 91 Edimax AC-M3000/AC-M1000 User’s Manual System Status: The table shows the information about AP Name, AP Status and Last Reporting Time. LAN Status: The table shows the information about IP Address, Subnet Mask and Gateway.
  • Page 92 Edimax AC-M3000/AC-M1000 User’s Manual Wireless LAN Status: The table shows all of the related wireless information. Access Control Status: The table shows the status of MAC of clients under the control of the AP. Associated Client Status: The table shows the clients connecting to the AP and the related information of...
  • Page 93: Ap Discovery

    If any IP address among the IP range assigned for a specific AP is used, there will be a warning message showing up. Please change the Base IP or Pool Size of the desired Interface to provide available IP addresses Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 94 Edimax AC-M3000/AC-M1000 User’s Manual for APs and then click Discover again. For the desired AP, input the desired name and password, select one template to apply, select the check box, and click Add to add the AP to the AP List. (About the template, please see 4.3.4 Template Settings).
  • Page 95 Edimax AC-M3000/AC-M1000 User’s Manual Click Configuring to go to the related configuration. For the details, please refer to 4.3.1 AP List. Auto-Discovery: Click Configure to enter the Auto-Discovery interface and have further configuration.
  • Page 96: Manual Configuration

    Interface and applied with the selected template. 4.3.3 Manual Configuration The supported APs can also be added manually. Enter the related information of the AP and select a Template. Click ADD and then the AP will be added to the AP List. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 97: Template Settings

    Edimax AC-M3000/AC-M1000 User’s Manual 4.3.4 Template Settings Template is a model that can be copied to every AP without having to configure the each AP individually. There are three templates provided. Click Edit to go to configuration. Except configuring all the template setting, copy the configuration of an AP to the template by selecting a Source AP and revise some settings is also acceptable.
  • Page 98 Edimax AC-M3000/AC-M1000 User’s Manual After click the hyperlink of Template ID to enter the Template Edit page, revise the configuration for demand such as SSID or Channel. About other functions of Wireless section, please refer to 4.3.1 AP List. Access Control function provides to control the clients’ devices that are allowed to associate with the APs applied with the desired template setting.
  • Page 99: Firmware Management

    Edimax AC-M3000/AC-M1000 User’s Manual 4.3.5 Firmware Management In this function, AP’s firmware can be uploaded. The current firmware can also be downloaded to the local storage.
  • Page 100: Ap Upgrade

    Edimax AC-M3000/AC-M1000 User’s Manual 4.3.6 AP Upgrade Check the APs which need to be upgraded and select the upgrade version of firmware, and click Apply to upgrade firmware.
  • Page 101: Network Configuration

    There are three parts, DMZ (Demilitarized Zone), Public Accessible Server and Port and Redirect, need to be set. DMZ (Demilitarized Zone) In the DMZ functions, the administrator can define mandatory external to internal IP mapping, hence a user on Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 102 TCP protocol or the UDP protocol. In the Enable column, check the desired server to enable. These settings will become effective immediately after clicking the Apply button. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 103 Edimax AC-M3000/AC-M1000 User’s Manual Port and IP Redirect In this function, the administrator can set up to 40 sets of the IP address ports for redirection purpose. When users attempt to connect to the port of a Destination IP Address listed here, the connection packet will be converted and redirected to the port of the Translated to Destination IP Address.
  • Page 104: Privilege List

    IP addresses of these clients in this list. The Remark is optional but useful to keep track. Edimax AC-M3000 provides up to 100 privilege IP addresses. These settings will become effective immediately after clicking Apply. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 105: Monitor Ip List

    If the monitored IP address does not respond, the system will send an e-mail to notify the administrator that such destination is not reachable. After entering the related information, click Apply and these settings will become Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 106: Walled Garden List

    Edimax AC-M3000/AC-M1000 User’s Manual effective immediately. When the monitored devices have built-in Web servers and connect to the LAN interfaces operating under NAT mode, they can be accessed by the hyperlink of theirs IP addresses. To add the monitored IP addresses as hyperlink accessible mode by clicking Add button in Link column.
  • Page 107: Proxy Server Properties

    Edimax AC-M3000/AC-M1000 User’s Manual Caution: To use the domain name, the Edimax AC-M3000 has to connect to DNS server first or this function will not work. 4.4.5 Proxy Server Properties Edimax AC-M3000 supports External Proxy Server functions and provides a built-in Internal Proxy Server...
  • Page 108 Edimax AC-M3000 as the proxy server regardless of the clients’ original proxy settings. For more details about how to set up the proxy servers, please refer to Appendix D and Appendix E. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 109: Dynamic Dns

    Virtual Private Network, or VPN, a type of technology designed to increase the security of information transferred over the Internet. VPN can work with either wired or wireless networks, as well as with dial-up connections over Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 110 Edimax AC-M3000/AC-M1000 User’s Manual POPS. VPN creates a private encrypted tunnel from the end user's computer, through the local wireless network, through the Internet, all the way to the corporate servers and database. VPN has serveral kinds of protocols and Edimax AC-M3000 supports IPSec. IPSec is a technology provided by Windows 2000 that allows you to create encrypted channels between two servers.
  • Page 111: Utilities

    User Name: operator Password: operator The administrator can change the passwords here. Please enter all the required fields with red asterisks if changing the password is desired. Click Apply to activate this new password. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 112: Backup/Restore Settings

    Edimax AC-M3000/AC-M1000 User’s Manual Caution: If the administrator’s password is lost, the administrator’s password still can be changed through the text mode management interface on the serial port, console/printer port. 4.5.2 Backup/Restore Settings This function is used to backup/restore the settings of Edimax AC-M3000. Also, Edimax AC-M3000 can be reset to...
  • Page 113: Firmware Upgrade

    Apply to go on with the firmware upgrade process. It might take a few minutes before the upgrade process completes and the system needs to be restarted afterwards to make the new firmware effective. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 114: Restart

    Click YES to restart Edimax AC-M3000; click NO to go back to the previous screen. Please don’t power off the system until this restart process has finished. Caution: The connection of all online users of the system will be disconnected when system is in the process of restarting. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 115: Status

    Edimax AC-M3000/AC-M1000 User’s Manual 4.6 Status This section includes System Status, Interface Status, Current Users, Traffic History, and Notification Configuration to provide system status information and online user status. 4.6.1 System Status This section provides an overview of the system for the administrator.
  • Page 116 Edimax AC-M3000/AC-M1000 User’s Manual The description of the table is as follows: Description Item The present firmware version of Edimax AC-M3000 Current Firmware Version The system name. The default is Edimax AC-M3000 System Name...
  • Page 117: Interface Status

    The system time is shown as the local time. The number of minutes allowed for the users to be Idle Timer inactive. Enabled/disabled stands for the current setting to allow/disallow multiple logins form the same account. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 118 Edimax AC-M3000/AC-M1000 User’s Manual The description of the table is as follows. Description Item The MAC address of the WAN1 port. MAC Address The IP address of the WAN1 port. WAN1 IP Address The Subnet Mask of the WAN1 port.
  • Page 119: Current Users

    The WINS server IP. N/A means that it is not configured. The start IP address of the DHCP IP range. The end IP Address of the DHCP IP range. Lease Time Minutes of the lease time of the IP address. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 120: Traffic History

    Traffic History As shown in the following figure, each line is a traffic history record consisting of 9 fields, Date, Type, Name, IP, MAC, Pkts In, Bytes In, Pkts Out, and Bytes Out, of user activities. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 121: Notification Configuration

    The Edimax AC-M3000 will save the traffic history into the internal DRAM. If the administrator wants the system to automatically send out the history to a particular email address, please enter the related information in these fields. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 122 Pegasus uses CRAM-MD5 or Login but can not be configured which method to use. Syslog Configuration: There are 2 parts: Traffic History and On-demand User Log. Enter the IP address and Port to specify which and from where the report should be sent. . Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 123: Help

    Edimax AC-M3000/AC-M1000 User’s Manual 4.7 Help On the screen, the Help button is on the upper right corner. Click Help to the Online Help window and then click the hyperlink of the items to get the information.
  • Page 124: Appendix A - Console Interface

    If you are still unable to see the welcome screen or the main menu of the console, please check the connection of the cables and the settings of the terminal simulation program. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 125 Main menu: Go back to the main menu. Change admin password Besides supporting the use of console management interface through the connection of null modem, the Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 126 AC-M3000 Admin username and password after logging in the system for the first time. Reload factory default Choosing this option will reset the system configuration to the factory defaults. Restart Cipherium Edimax AC-M3000 Choosing this option will restart Edimax AC-M3000. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 127: Appendix B - Network Configuration On Pc

    If the Internet Connection of this client PC has been configured as use local area network already, you can skip this setup. Windows XP 1. Choose Start > Control Panel > Internet Option. 2. Choose the “Connections” label, and then click Setup. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 128 3. Click Next when Welcome to the New Connection Wizard screen appears. 4. Choose “Connect to the Internet” and then click Next. 5. Choose “Set up my connection manually” and then click Next. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 129 6. Choose “Connect using a broadband connection that is always on” and then click Next. 7. Finally, click Finish to exit the Connection Wizard. Now, you have completed the setup. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 130 Area Connection” icon and select “Properties” 3. Select “General” label and choose “Internet Protocol (TCP/IP)” and then click Properties. Now, you can choose to use DHCP or specific IP address, please proceed to the following steps. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 131 AC-M3000: IP address, Subnet Mask, New gateway and DNS server address. Please choose “Use the following IP address” and enter the information given from the network administrator in “IP address”, “Subnet mask” and the “DNS address(es)” and then click OK. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 132: Appendix C - Ipsec Vpn

    The ActiveX is a software component running inside Internet Explorer. The ActiveX component can be checked by the following windows. From Windows Internet Explorer, click “Manage add-ons” button inside “Programs” page under “Tools” to show the add-ons programs list. You can see VPNClient.ipsec was enabled. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 133 The crash of Windows Internet Explorer may cause the same result. 3. Internet Connection Firewall In Windows XP and Windows XP SP1, the Internet Connection Firewall is not compatible with IPSec. Internet Connection Firewall will drop packets from tunneling of IPSec VPN. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 134 The ActiveX component for IPSec VPN is running paralleled with the web page of “Login Success”. Unless user decides to close the session and to disconnect with NAC Edimax AC-M3000, the following conditions or behaviors of using browser shall be avoided in order to maintain the built IPSec VPN tunnel always alive. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 135 The crash of Internet Explorer on running ActiveX Suggestion: Please reboot client’s computer, once Windows service is resumed, go through the login process again. b. Terminate the Internet Explorer Task from Windows Task Manager Suggestion: Don’t terminate this VPN task of Internet Explorer. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 136 Suggestion: Click “Cancel” if you do not intend to stop the IPSec VPN connection yet. 6. Non-supported OS and Browser In current version, Windows Internet Explorer is the only browser supported by Edimax AC-M3000.Windows XP and Windows 2000 are the only two supported OS along with this release. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 137: Appendix D -Proxy Setting For Hotspot

    Gateway need to be set. Please follow the steps to complete the proxy configuration: Login Gateway by using “admin”. Click the Network Configuration from top menu and the homepage of the Network Configuration will appear. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 138 Edimax AC-M3000/AC-M1000 User’s Manual Click the Proxy Server Properties from left menu and the homepage of the Proxy Server Properties will appear.
  • Page 139 Edimax AC-M3000/AC-M1000 User’s Manual Add the ISP’s proxy Server IP and Port into External Proxy Server Setting.
  • Page 140 Edimax AC-M3000/AC-M1000 User’s Manual Enable Built-in Proxy Server in Internal Proxy Server Setting.
  • Page 141 Edimax AC-M3000/AC-M1000 User’s Manual Click Apply to save the settings.
  • Page 142: Appendix E -Proxy Setting For Enterprise

    Gateway. Please follow the steps to complete the proxy configuration: Gateway setting Login Gateway by using “admin”. Click the Network Configuration from top menu and the homepage of the Network Configuration will appear. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 143 Edimax AC-M3000/AC-M1000 User’s Manual Click the Proxy Server Properties from left menu and the homepage of the Proxy Server Properties will appear.
  • Page 144 Add your proxy Server IP and Port into External Proxy Server Setting. Disable Built-in Proxy Server in Internal Proxy Server Setting. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 145 Client setting It is necessary for clients to add default gateway IP address into proxy exception information so the user login successful page can show up normally. Use command “ipconfig” to get Default Gateway IP Address. Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 146 Open browser to add default gateway IP address (e.g. 192.168.1.254) and logout page IP address “1.1.1.1” into proxy exception information. For I.E For firefox Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 147 Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 148: Appendix F -Disclaimer For On-Demand Users

    = i + name.length; // end of section to compare name string if (pham.substring(i, offset) == name) { // if string matches var endstr = pham.indexOf(";", offset); //end of name=value pair if (endstr == -1) endstr = pham.length; Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 149 (i) strRtn+="a"; return strRtn; function DecodeCookie(str) var strArr; var strRtn=""; strArr=str.split("a"); for(var i=strArr.length-1;i>=0;i--) strRtn+=String.fromCharCode(eval(strArr[i])); return strRtn; function MM_swapImgRestore() { //v3.0 var i,x,a=document.MM_sr; for(i=0;a&&i<a.length&&(x=a[i])&&x.oSrc;i++) x.src=x.oSrc; function MM_preloadImages() { //v3.0 var d=document; if(d.images){ if(!d.MM_p) d.MM_p=new Array(); Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 150 Array; for(i=0;i<(a.length-2);i+=3) if ((x=MM_findObj(a[i]))!=null){document.MM_sr[j++]=x; if(!x.oSrc) x.oSrc=x.src; x.src=a[i+2];} function init(form) id = getCookie("username"); if(id!="" && id!=null) form.myusername.value = id; disclaimer.style.display=''; login.style.display='none'; function Before_Submit(form) if(form.myusername.value == "") alert("Please enter username."); form.myusername.focus(); form.myusername.select(); disableButton=false; return false; Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 151 Reminder.myusername.value = form.myusername.value; Reminder.mypassword.value = form.mypassword.value; Reminder.submit(); function cancel_onclick(form) form.reset(); function check_agree(form) if(form.selection[1].checked == true) alert("You disagree with the disclaimer, therefore you will NOT be able to log return false; in."); Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 152 Our primary purpose in collecting personal information is to provide you with a safe, smooth, efficient, and customized experience. You agree that we may use your personal information to: provide the services and customer support you request; resolve disputes, collect fees, and troubleshoot problems; prevent potentially prohibited or Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 153 Edimax AC-M3000/AC-M1000 User’s Manual illegal activities; customize, measure, and improve our services and the site's content and layout; compare information for accuracy, and verify it with third parties. We may disclose personal information to respond to legal requirements, enforce our policies, respond to claims that an activity violates the rights of others, or protect anyone's rights, property, or safety.
  • Page 154 </table> <div align="center"> <table name="login" id="login" background="../images/userlogin.gif"> <tr> <td height="146" colspan="2">&nbsp;</td> </tr> <tr> <td width="43%" height="53">&nbsp;</td> <td><input type="text" name="myusername" size="20"></td> </tr> <tr> <td height="42">&nbsp;</td> <td><input type="password" name="mypassword" size="20"></td> checked width="497" height="328" border="0" align="center" cellpadding="2" cellspacing="0" Edimax AC-M3000/AC-M1000 type="radio"></td> User’s Manual...
  • Page 155 <font color="#808080" size="2"><script language="JavaScript">if( creditcardenable == "Enabled" ) document.write("<a href=\"../loginpages/credit_agree.shtml\">Click here to purchase by Credit Card Online.<a>");</script></font> </td> </tr> </table> </div> </form> <form action="reminder.shtml" method="post" name="Reminder"> <input type=hidden name=myusername value=""> <input type=hidden name=mypassword value=""> </form> <br> <div align="center"> <table> Edimax AC-M3000/AC-M1000 User’s Manual...
  • Page 156 Edimax AC-M3000/AC-M1000 User’s Manual <tr> <td width="100%"> <font color="#808080" size="2"><script language="JavaScript">document.write(copyright);</script></font></td> </tr> </table> </div> </body> </html>...
  • Page 157: Appendix G-Dhcp Relay

    Edimax AC-M3000/AC-M1000 User’s Manual 11. Appendix G—DHCP Relay AC-M3000 supports DHCP Relay defined according to RFC 3046 . For scaling reasons, it is advantageous to set up an external DHCP server other than having the internal DHCP server implemented in AC-M3000 to assign an IP.
  • Page 158 Edimax AC-M3000/AC-M1000 User’s Manual Here is an example of configuration file of the DHCP server: From the file, client that connects to AC-M3000 sends out a DHCP request. DHCP relay function in AC-M3000 is enabled and sending a Circuit ID 00:90:0B:07:60:91_192.168.1.254 to the external DHCP server. When DHCP server gets the Circuit ID, it recognizes that the request is sent from g1_public_lan and thus assigns the client a DNS server of 169.95.1.1, an IP that can be in the range of 192.168.1.30 and 192.168.1.50, a default gateway of...

This manual is also suitable for:

Ac-m3000

Table of Contents