Thank you for purchasing the ESR350H 300Mbps Wireless-N Gigabit Router from EnGenius Technologies. By applying the latest in 802.11n technology, the ESR350H provides users with high speed (up to 300Mbps) to stream HD multimedia, play games online, or download large files. With 5dBi antenna, it has up to twice the range compared to other wireless routers and has better coverage to reach what would be normally weak or dead spots.
1.2. Product Layout Front Panel Description Components WPS Button Click to activate the router’s Wi-Fi Protected Setup (WPS) feature. WPS LED This LED goes BLINK when the WPS feature is being triggered. Power LED This LED goes ON when the power is being supplied to the router. WLAN LED This LED goes ON when the RF (wireless LAN) feature is enabled.
1.3. Wall Mounting Mounting the ESR350H to a wall will allow the wireless range to be optimized. To mount the device in the wall, measure the distance of the mounting holes of the ESR350H and drill the appropriate holes on the wall location. Once the nails are secure, firmly lock the mounts onto the ESR350H.
2.2. Setup Notes When considering the placement of the ESR350H remember the following: The ESR350H must be close to the DSL or Cable Modem and a Power Source. Initially, it needs to be closed to the computer that is used to ...
If you are not using Windows (Internet Explorer), please browse the CD and open the file names index.html (it can be found from the “html” folder) to start. 2. Click Quick Start. The wizard will guide you through setting up your ESR350H. [ pg. 11]...
3.2. Setup your network cables Power on ESR350H. Plug either end of an Ethernet cable into the WAN port on the back panel of the router (see CABLE 1). Plug the other end of the cable into your cable/DSL modem.
Page 13
3. Plug either end of an Ethernet cable into the LAN port on the back 4. Make sure the network cable and power adapter are firmly panel of the router (see CABLE 2). Plug the other end of the cable connected.
3.3. Login your Router Once logged in, the landing page will display information about the ESR350H. NOTE: The default user name is admin and the default password is admin. Icon introduction On the top right, you will see five icons: Home ...
Page 15
On the bottom left, you will see: View the router information and connection status Open the setup wizard by clicking Wizard button Customize the parent control setting by clicking Parent Control button [ pg. 15]...
ESR350H. Please wait a few seconds to finish detecting the Internet connection. If the ESR350H does not detect the appropriate Internet connection, you can select the correct one on the drop down menu of Login Method (also known as WAN protocol / Internet Connection method).
Page 17
To set up a PPPoE connection, enter the Username, Password, and Service (name) of the Internet connection provided by your ISP. Click Next and the ESR350H should connect to the Internet successfully. A PPPoE connection is usually from a DSL Internet service.
Page 18
Layer 2 Tunneling Protocol (L2TP) To set up an L2TP connection, enter the type of WAN connection (Static IP or DHCP). After, depending on the type of WAN, follow the instructions of DHCP or Static IP to fill out the corresponding information. Then, proceed to enter the Username, Password, and Service. Click next when completed.
Page 19
6. It is highly recommended to select High as the security level to better secure your router and prevent outside intrusion. 7. Enter your desired router name in the column of SSID, and enter your desired password in the column of Key. [ pg.
Page 20
8. Click Apply to save the information. You have now completed the ESR350H setup. Now ESR350H is ready for use. [ pg. 20]...
4. Parental Control Parental control enables centralized control on the Internet access restriction for each connected computer. You can make the access policies for a keyword or URL filtered based on weekdays or weekend. [ pg. 21]...
Page 22
You can add policies by clicking Add Policy. You will then be prompted to: Name the Policy. Click Next. 1. Select the device (by its MAC Address) to apply the policy to. Click Next. 2. Schedule when the policy will be active. Click Next. [ pg.
Page 23
3. Enter Keywords and URLs to be filtered/ blocked. Check Enable Application Filter if you would like the application filtering. Click Next. 4. Enable or disable Web Access Logging. Click Save for your settings. [ pg. 23]...
Page 24
5. If you would like to proceed to the advanced Networking Setting, please click: [ pg. 24]...
5. Networking Setting If you would like to manually configure the advanced Networking Settings please open your browser (Internet Explorer or Firefox), and type in the default IP 192.168.0.1 to get access to the web-based management utility. Once open, click to start the configuration.
Application Version: The software version of your ESR350H. You can always update to the latest firmware of your ESR350H. The latest firmware can be found on the EnGenius website. (Please visit http://www.engeniusnetworks.com/ for the latest firmware and the related documents) WAN Settings Attain IP Protocol: Displays the IP Protocol in use for the ESR350H.
Page 27
MAC Address: Your router’s LAN MAC address WLAN Settings Channel: The wireless channel number used is shown SSID_#: Up to 4 SSIDs (network groups) for the ESR350H ESSID: Your router’s name Security: Security level utilized by your ESR350H ...
6.2. Operation Mode The ESR350H supports two different operation modes: Router Mode and Repeater Mode. Router Mode In router mode the internal DHCP server allows a number of LANs/WLAN to automatically generate IP addresses to share the same Internet connection. In this mode, using Ethernet cable connect to the WAN port and cable/DSL modem.
6.3. LAN LAN IP IP Address: Your router’s LAN IP address IP Subnet Mask: Your router’s LAN Subnet Mask 802.1d Spanning Tree: 802.1d Spanning Tree is disabled by default. When enabled, the spanning tree protocol is applied to prevent network loops (transmissions won’t pass the same node twice to reach the destination).
Page 30
Second DNS Server: If you get a second DNS Server IP or you wish to assign a second DNS Server IP, please type in the desired IP address in the field. Click Apply to save your settings. [ pg. 30]...
6.4. DHCP DHCP Client Table: Displays all the connected DHCP clients whose IP addresses are assigned by the DHCP Server in your network. Click Refresh to update the table. Enable Static DHCP IP: Check Enable Static DHCP IP if you wish to add more Static DHCP IP addresses. Click Reset if you would like to erase IP address or MAC address.
6.5. Log Records the system log of the router. The log displays any event that occurred after your router starts up. Click Save if you wish to save the log in a local file for further analysis. Click Clear if you wish to erase the current log. Click Refresh to get the most updated information. If the router is powered off, the system log will disappear if it is not saved in a local file.
WAN Settings Attain IP Protocol: Displays the IP Protocol currently used by the ESR350H. It can be Dynamic IP Address, Static IP, PPPoE, PPTP, L2TP. IP Address: Your router’s WAN IP address Subnet Mask: Your router’s WAN Subnet mask ...
7.2. Dynamic IP A DHCP type of connection where your Internet connection is usually always on and your Internet service provider automatically provides you with a dynamic IP address. A DHCP connection is usually from a Cable Internet service. Hostname: Assign a name for your Internet connection type. You can leave ...
7.3. Static IP To set up a Static IP connection, enter the following: IP Address of the Internet connection, Subnet Mask, Default Gateway, and both DNS Servers provided by your Internet Service provider (ISP) or Network Administrator. MTU: Maximum Transmission Unit. It specifies the largest packet size permitted for Internet transmission.
7.4. PPPoE (Point-to-Point Protocol over Ethernet) Point-to-Point Protocol over Ethernet (PPPoE): To set up a PPPoE connection, enter the Username, Password, and Service (name) of the Internet connection provided by your ISP. A PPPoE connection is usually from a DSL Internet service. Username: The username or e-mail address that the Internet connection ...
7.5. PPTP To set up a PPTP connection, enter the type of WAN connection (Static IP or DHCP). After, depending on the type of WAN, follow the instructions of DHCP or Static IP to fill out the corresponding information. Then, proceed to enter the Username, Password, and Service IP address provided by your ISP.
7.6. L2TP To set up an L2TP connection, enter the type of WAN connection (Static IP or DHCP). After, depending on the type of WAN, follow the instructions of DHCP or Static IP to fill out the corresponding information. Then, proceed to enter the Username, Password, and Service IP Address provided by your ISP.
7.7. DS-Lite Dual-Stack Lite, or DS-Lite, allows ISPs to stop IPv4 addresses from reaching a customer’s network devices and only use IPv6. DS-Lite Configuration: Select DS-Lite DHCPv6 Option or Manual Configuration. AFTR IPv6 Address: Enter the AFTR (Address Family Transition Router) ...
Mode: Select Access Point mode or Wireless Distribution Service (WDS) mode for your router. AP: Use the ESR350H as a Wireless Access Point for wireless devices to connect. WDS: In a WDS, access points are used to expand the wireless area by connecting to ...
Page 43
Wireless Distribution System Mode Configure the router's wireless settings in WDS mode. Channel: Select a channel to assign to the wireless network. MAC Address [#]: Enter the MAC address(es) for the wireless access point(s) that are part of the WDS.
8.2. Advanced To change more advanced wireless features of the ESR350H, select the Advanced option of the Wireless section. In the Advanced option, you can change the following: Fragment Threshold: This specifies the maximum size of a packet during ...
8.3. Security To change the wireless security of the ESR350H, select the Security option of the Wireless section. It is recommended to enable security options on the wireless network to prevent intrusions to systems on your wireless network. SSID Selection: Choose the wireless network group to change the wireless security settings ...
Page 46
You can use a RADIUS server to authenticate wireless stations and provide a session key to encrypt data during communication. You will just need to provide the Server IP Address, Server Port, and Server Password of the RADIUS server to the ESR350H.
8.4. Filter When Enable Wireless Access Control selected, only wireless clients with MAC addresses listed in the table are allowed to connect to the wireless network. Enable Wireless Access Control Description: Enter a description of the device allowed to connect to the ...
To configure the WiFi Protected Setup information, select the WPS option from the Wireless section. WPS is an easy way to allow wireless clients to connect to the ESR350H. This can automate connection between the device and the ESR350H by use of a button or a PIN.
9. Parental Control Parental control enables centralized control on the Internet access restriction for each connected computer. You can make the access policies for keywords or URLs filtered based on weekdays or weekend. 9.1. Wizard To access the Parental Control Wizard, select the Wizard option in the Parental Control section. The Parental Control Wizard will bring up simple network monitoring controls.
Page 51
You can add policies by clicking Add Policy. You will then be prompted to: Name the Policy. Click Next. 1. Select the device (by its MAC Address) to apply the policy to. Click Next. 2. Schedule when the policy will be active. Click Next. [ pg.
Page 52
3. Enter Keywords and URLs to be filtered/ blocked. Check Enable Application Filter if you would like the application filtering. Click Next. 4. Enable or disable Web Access Logging. Click Save for your settings. [ pg. 52]...
9.2. Web Monitor To quickly view the Parental Control policies you already made in Parent Control Wizard, select the Web Monitor option from the Parental Control section. [ pg. 53]...
10. Guest Network The Guest Network function enables you to offer Internet connectivity to visitors or guests while keeping other networked devices (computers and hard drives) and sensitive personal or company information private and secure. The Guest Network is controlled by the Wireless SSID function. When the Guest Network function is enabled, the Guest SSID can only get the internet connection from WAN, but can not reach the client from the LAN port.
10.2. DHCP Server Setting DHCP server automatically assigns IP address to computers on your Guest network. Router IP Address: Define the router IP address for the Guest network. Default Subnet Mask: Define the Subnet Mask IP address for the Guest ...
10.3. DHCP Client Table Displays all the connected DHCP clients whose IP addresses are assigned by the DHCP Server in your Guest network. DHCP Client Table: View the guest network client list. Click Refresh to refresh the view of the list. [ pg.
11. IPv6 There are several connection types to choose from: Auto Detection, Static IPv6, Auto configuration (SLAAC/DHCPv6), PPPoE, IPv6 in IPv4 Tunnel, 6to4, and Link-local. If you are unsure of your connection method, please contact your IPv6 Internet Service Provider. Note: If using the PPPoE option, you will need to ensure that any PPPoE client software on your computers has been removed or disabled.
11.3. Static IPv6 Use Link-Local Address: Enable or disable LAN link-local address. IPv6 Address: Enter the LAN (local) IPv6 address for the router. Subnet Prefix Length: Enter the subnet prefix length. Default Gateway: Enter the default gateway. ...
11.4. Auto Configuration Obtain A DNS Server Address Automatically: Enable or disable obtaining a DNS server automatically. Primary IPv6 DNS Address: Enter the primary IPv6 DNS address. Secondary IPv6 DNS Address: Enter the secondary IPv6 DNS address. Enable DHCP-PD: Enable or disable DHCP-prefix delegation (PD).
11.5. PPPoE Address Mode: Select Static if your ISP assigned you the IP address, subnet mask, gateway, and DNS server addresses. In most cases, select Dynamic. IP Address: Enter the IP address (Static PPPoE only). User Name: Enter your PPPoE user name. ...
11.6. 6to4 6to4 Address: Enter the 6to4 IP address. Primary IPv6 DNS Address: Enter the primary IPv6 DNS address. Secondary IPv6 DNS Address: Enter the secondary IPv6 DNS address. LAN IPv6 Address: Enter the LAN IPv6 address. ...
11.7. Link Local LAN IPv6 Link-Local Address: Enter the LAN IPv6 link-local address. Click Apply to save the settings or Cancel to discard changes. [ pg. 62]...
To access the Firewall Section of the Expert Menu, select Firewall on the left hand side. 12.1. Basic To enable or disable firewall, select the Basic option in the Firewall section. In the Basic option, select whether or not you wan to Enable or Disable the firewall settings of the ESR350H. [ pg. 63]...
12.2. Advanced VPN Passthrough: Allows VPN (Virtual Private Network) packets to pass through the Firewall. If you are not using VPN, these options can be disabled. VPN L2TP Passthrough, VPN PPTP Passthrough, VPN IPSec Passthrough and PPPoE Passthrough are enabled by factory default. [ pg.
12.3. DMZ (Demilitarized Zone) If you have a client PC that cannot run an Internet application (e.g. Games) properly from behind the NAT firewall, then you can open up the firewall restrictions to allow unrestricted two-way Internet access by defining a DMZ Host. The DMZ function allows you to re-direct all packets going to your WAN port IP address to a particular IP address in your LAN.
12.4. DoS (Denial of Service) To enable blocking of DoS attacks, select the DoS option in the Firewall section. DoS attacks can flood your Internet connection with continuous transmission of data. Blocking these attack can ensure that the Internet connection will always be available.
12.5. ACL To manage Parental Control settings (either through the Parental Control Wizard or the ACL option), select the ACL option in the Firewall section. Please refer to Parental Control Section for details. [ pg. 67]...
(SOHO) users. To view the status of your VPN tunnels that were configured on the ESR350H, select the Status option in the VPN section. The status table will show the name of the VPN, the VPN type, the Gateway/Peer IP address, how many packets have been transmitted and received, and how the VPN has been up.
13.2. VPN Wizard Click Next to start VPN Wizard Create a name for the VPN tunnel in the Name field. Click Next. [ pg. 69]...
Page 70
You can select IPSec, L2TP over IPSec, L2TP or PPTP as the VPN Connection Type. Then click Next. [ pg. 70]...
Page 71
IPSec Setting You can select Client to Site or Site to Site in this page then click Next to next page. Note. If you select Client to Site, you will pass next step. Enter the Security Gateway and Remote Network. Then click Next to next page.
Page 72
Enter the Shared Key for the VPN connection. Then click Next to next page. Setup successfully, enable this policy immediately. If you don’t want enable this policy, you can un-tick the box. Then click Apply button to apply the settings. [ pg.
Page 73
L2TP over IPSec Setting Enter the Username, Password and VPN Server IP setting. Then click Next to next page. Enter the Shared Key for the VPN connection. Then click Next to next page. [ pg. 73]...
Page 74
Setup successfully, enable this policy immediately. If you don’t want enable this policy, you can un-tick the box. Then click Apply to apply the settings. [ pg. 74]...
Page 75
Server IP: Enter an IP address which is different from your router’s LAN IP address. (example: the default LAN IP of ESR350H is 192.168.0.1. You could create a Server IP address as 10.0.174.45) Remote IP Range: Enter an IP range under the same subnet as the above ...
Page 76
Server IP: Enter an IP address which is different from your router’s LAN IP address. (example: the default LAN IP of ESR350H is 192.168.0.1. You could create a Server IP address as 10.0.174.45) Remote IP Range: Enter an IP range under the same subnet of the above ...
13.3. User Setting Name: Enter the name to connect to L2TP or PPTP VPN tunnels. Password: Enter the password to connect to L2TP or PPTP VPN tunnels. Confirm: Enter the password again to confirm the password entered above.
13.4. Profile Setting If you wish to manually setup a VPN tunnel, you can go to Profile Setting in the VPN section. Before getting started, please select User Setting to create the user profile ahead of time. After completing the User Setting, please go to Profile Setting to start a manual VPN tunnel configuration. Click Add to get started. In the General tab, enter a name for the VPN tunnel in the Name field.
Page 79
IPSec profile setting General Name: Enter a name for your VPN policy. Connection Type: Supports PPTP, L2TP, IPSec and L2TP over IPSec methods to establish VPN connection. Authentication Type: Supports pre-shared key method for authentication. Shared Key: Enter the Shared Key in box. ...
Page 80
SA (Security Association) IKE (Phase 1) Proposal Exchange: Select Main Mode or Aggressive Mode for IKE Phase 1 negotiation. o Main Mode: Select this option to configure the standard negotiation parameters for IKE Phase 1 of the VPN Tunnel. (Recommended Setting) o Aggressive Mode: Select this option to configure IKE Phase 1 of the VPN Tunnel to carry out negotiation in a shorter amount of...
Page 81
Perfect Forward Secrecy: Select Enable or Disable to enable or disable PFS (Perfect Forward Secrecy). PFS is an additional security protocol. DH Group: Select a PFS DH Group from the drop-down menu (Group 1, Group 2, Group 5, Group 14). As the DH Group number increases, the ...
Page 82
L2TP over IPSec profile setting General Name: Enter a name for your VPN policy. Connection Type: Supports PPTP, L2TP, IPSec and L2TP over IPSec methods to establish VPN connection. Shared Key: Enter the Shared Key in box. Confirm: Enter your Shared Key again for verification.
Page 83
PPTP profile setting If you select PPTP as VPN Connection Type, go to PPTP tab. PPTP Authentication: There are three authentication algorithms. Please select CHAP, PAP, or MSCHAP_V2. Encryption: Supports No, 40-bit or 128-bit encryption lengths for traffic through the VPN.
Page 84
L2TP profile setting If you select L2TP as VPN Connection Type, go to L2TP tab. L2TP Authentication: There are three authentication algorithms. Please select CHAP, PAP, or MSCHAP_V2. Available Users: The users who you created in the User Setting to ...
14. Advanced To access the Advanced section of the Expert Menu, select Advanced on the left hand side. 14.1. NAT (Network Address Translation) Network Address Translation (NAT) allows multiple users at your local site to access the Internet through a single Public IP Address or multiple Public IP Addresses.
14.2. Port Mapping Port Mapping allows you to re-direct a particular range of service port numbers (from the Internet / WAN Port) to a particular LAN IP address. Enable Port Mapping: Mark the checkbox to Enable Port Mapping. Description: Enter the description on why the ports will be mapped. ...
14.3. Port Forwarding Use the Port Forwarding (Virtual Server) function when you want different servers/clients in your LAN to handle different Internet application type (e.g. Email, FTP, Web server etc.) from the Internet. Computers use port numbers to recognize a particular Internet application type. The Virtual Server allows you to re-direct a particular port number (from the Internet/WAN Port) to a particular LAN private IP address and its service port number.
14.4. Port Triggering (Special Application) Some applications require multiple connections, such as online games, videoconferencing, VoIP telephony and etc. You can configure port triggering function to support multiple connections if more than one local computer needs port forwarding for the same application or your application needs to open incoming ports that are different from the outgoing port.
14.5. ALG (Application Layer Gateway) The ALG (Application Layer Gateway) serves as a window between correspondent application processes so that they may exchange information on an open environment. Select the listed applications that need ALG support and then the router will authorize them to pass through the NAT gateway. Then click Apply. [ pg.
14.6. UPnP (Universal Plug and Play) UPnP helps Internet devices, such as gaming and videoconferencing to access the network and connect to other registered UPnP devices. [ pg. 90]...
14.7. IGMP (Internet Group Multicast Protocol) IGMP (Internet Group Multicast Protocol) is a network-layer protocol used to establish membership in a Multicast group. [ pg. 91]...
14.8. QoS (Quality of Service) QoS can prioritize the bandwidth use such as video streaming, online gaming, VoIP telephony, videoconferencing, and etc. to ensure the stable and efficient performance of the network. Total Bandwidth Settings You can specify the maximum value of the outgoing bandwidth of Uplink and Downlink for the application by selecting the speed from drop-down menus.
Page 93
Priority Queue Local IP Address: Enter the Local IP address which will have the highest priority to stream data and will not be bounded by the QoS limitation. High/Low Priority Queue: Specify the priority for different protocol. You can add and priority the desired protocol on the table.
Page 94
Bandwidth Allocation You can set the bandwidth allocation type (download and/or upload). You must provide the IP and Port ranges and select the type of protocol, policy, and rate (bps). Type: select Download or Upload which you want to reserve or ...
14.9. Routing Typically you do not need to setup static routing since the ESR350H usually has adequate routing information after it has been configured for Internet access. You will only need to set up static routing if the router is connected with a network under a different subnet and you need the static routing to allow network connection in two different subnets.
14.10. WOL (Wake on LAN) WOL allows you to turn on a computer through the router. You will just need to provide the Server Port as well as the MAC address of the computer to utilize this feature. [ pg. 96]...
In the Admin option of the Tools section, you can change the password used to log in to the router at the login screen by entering the old password, followed by the new password twice. You can also allow only one computer to edit the settings on the ESR350H by supplying its static IP address.
15.2. Time In the Time option of the Tools section, you can change the current time on the ESR350H. Enter the web address of the Network Time Protocol you want to have the ESR350H to match time with or have it synchronize with the PC accessing the ESR350H. You can also enable Daylight Saving.
15.3. DDNS (Dynamic DNS) DDNS allows users to map a static domain name to a dynamic IP address. You must get an account, password, and static domain name from the DDNS service provider such as DynDNS, ZoneEdit, CyberGate, and etc. to use this feature. DDNS benefits end users when they have their own websites or FTP sites.
15.4. Diagnosis The diagnosis feature allows the administrator to verify that another device is available on the network and is accepting request packets. If the ping result returns alive, it means a device is on line. This feature does not work if the target device is behind a firewall or has security software installed. [ pg.
15.5. Firmware In the Firmware option of the Tools section, you can update the firmware of the ESR350H. To update the firmware, follow these steps: 1. Download the appropriate firmware approved by Enenius® Technologies Inc. from an approved site. 2. Make sure the firmware file is in a known local location.
Page 102
Emergency Upgrade If your firmware upgrade failed, you may enter the Emergency Upgrade WEB page. 1. Enter IP address: 192.168.99.9 and enter Emergency Upgrade WEB page. Note: You have to configure PC/Notebook IP address to 192.168.99.8 manually. 2. Click the Browse button and navigate to the location of the upgrade file and then click Upload. 3.
Page 103
4. You can access the device again. [ pg. 103]...
1. Restore the ESR350H to factory defaults. 2. Save the current configuartion on the ESR350H to a .dlf file. 3. Restore saved settings by: a. Select Browse. b. Browse location for the file with the saved settings of the ESR350H. c. Select Upload. [ pg. 104]...
Appendix A – FCC Interference Statement Federal Communication Commission Interference Statement This equipment has been tested and found to comply with the limits for a Class B digital device, pursuant to Part 15 of the FCC Rules. These limits are designed to provide reasonable protection against harmful interference in a residential installation.
Appendix B – Industry Canada statement This device complies with RSS-210 of the Industry Canada Rules. Operation is subject to the following two conditions: (1) This device may not cause harmful interference, and (2) this device must accept any interference received, including interference that may cause undesired operation.