Page 4
Appendix D. Examples of Making Payments for End Users ........... 142 Appendix E. Issue Refund for PayPal ..................145 Appendix F. Example of AP Device Connection With VLAN ..........149 Appendix G. Use Template to setup Managed APs..............152 Appendix H. Use Auto Recovery To Setup Managed AP............
Chapter 1. Before You Start Preface The WMS-308N is a full-featured Network Access Control Gateway / Controller that aggregates up to 60 access points (APs), built-in 5000 local accounts/ on-demand accounts and delivers centralized control and security for wireless deployments.
IP Router / Firewall, Multi-WAN / QoS enforcement and Access Controller for use in wireless environments. One single WMS-308N can serve up to 500 simultaneous users, takes control over authentication, authorization, accounting and routing to the Internet as well as to the operating central.
WMS-308N Network Access Control Gateway User's Manual Specification Access Point Management and Support WMS-308N Network Access Gateway / Controller Support Max: 60 Access Points per Controller Max: 500 wireless client per Controller Provide Local Account : 5000 AP Management – Control - Monitoring Centralized AP Management AP Group management –maintain a set of setting templates that simplify the task to assign the...
WMS-308N Network Access Control Gateway User's Manual AP User Statistic – Maintain all wireless clients connection history and depict statics in diagrams Support Monitor IP on third-party APs System alarms and status reports on managed APs Topology Monitor-list monitored device; periodically updates devices’ status...
WMS-308N Network Access Control Gateway User's Manual IEEE802.1X user authentication of controller management on controller Telnet and console sessions Multiple access privilege levels Hierarchical management and password protection for management interface EAP offload for AAA server scalability and survivability Stateful 802.1X authentication for standalone APs...
Page 10
WMS-308N Network Access Control Gateway User's Manual Seamless Mobility: User-centric networking manages wired and wireless users as they roam between ports or wireless APs Service Domain Integrating with WAP-854NP/ WAP-954GP / WAP-1954NP / WAP-1954NP-C and other future products to have Service Domain feature and each Service Domain can have its own settings:...
WMS-308N Network Access Control Gateway User's Manual Configurable user black list Export/Import local users list to/from a text file Web-based Captive Portal for SSL browser-based authentication Authentication Type IEEE802.1X (EAP, LEAP, EAP-TLS, EAP-TTLS, EAP-GTC, EAP-MD5) RFC2865 RADIUS Authentication RFC3579 RADIUS Support for EAP...
Page 12
WMS-308N Network Access Control Gateway User's Manual QoS Enforcement Packet classification via DSCP (Differentiated Services code Point ) Diff/ToS IEEE802.11p/CoS IEEE 802.1Q Tag VLAN priority control IEEE 802.11e WMM Automatic mapping of WMM priorities to 802.1p and IP DSCP IGMP Snooping for efficient multicast delivery...
WMS-308N Network Access Control Gateway User's Manual Support IP Filter Support Walled garden (free surfing zone) Support MAC-address and IP –address pass through Support IP Plug and Play (IP PnP) System Administration Three administrator accounts Provide customizable login and logout portal page...
Page 14
WMS-308N Network Access Control Gateway User's Manual WMS-308N Hardware Specifications Base Platform 32-bit , MIPS24K Processor CPU Clock Speed 680 MHz Serial Port 1 (DB-9) USB Port 1 ( Optional 3G interface radio with major brands – ODM only) Reset Switch Built-in...
4. WAN1/WAN2 : Two WAN ports are available on the system. LED Green ON indicates 10/100-Mbps link is established on the port. LED Amber ON indicates 1000-Mbps link is established on the port. 5. LAN : Clients devices connect to WMS-308N via LAN ports...
Page 16
WMS-308N Network Access Control Gateway User's Manual Rear Panel 1. Power SOCKET (12V DC) : Attach the power socket here.
3. Connect WMS-308N to your network device. Connect one end of the Ethernet cable to LAN port of WMS-308N on the front panel. Connect the other end of cable to a PC for configuring the system. The LAN LED indicator should be ON to indicate a proper connection.
1. Once the hardware installation is done, set DHCP in TCP/IP of the administrator's PC to get an IP address automatically. Connect the PC to the LAN port of WMS-308N. An IP address will be assigned to the PC automatically via the WMS-308N.
Page 19
You can login as root, admin or operator. The default username and password as follows. Root : The administrator can access all area of the WMS-308N Username : root Password : default admin : The admin can access the area under Service Domain, Wireless and Advanced setting (Please see Appendix B.)
WMS-308N provides wireless and wired network service with authentication required for clients in Service Domain. Clients in the each Service Domain are isolated with each other. WMS-308N supports 8 Service Domains, Domain-0 to Domain-7. Administrator can select authentication type on each Service Domain. If Authentication Required is enabled, the clients are required to get authenticated successfully before access the Internet.
Page 21
WMS-308N Network Access Control Gateway User's Manual Step 3 : Choose System's Time Zone Click System -> Time Server, the Time Server Setup page will appear. Select the appropriate NTP Server, Time Zone from drop-down list. Click Save button. Before Hotspot service active, make sure the Local Time is correctly.
Page 22
WMS-308N Network Access Control Gateway User's Manual Click Tool Icon on Domain 0 window, the Service Domain0 Setup page will appear. For each Service Domain(by default, authentication type is none), authentication type can be selected in Pregenerated Ticket, On-Demand, Local Radius, Remote Radius Server and LDAP Server and POP3, and select one authentication type for Default Auth Type.
Page 23
WMS-308N Network Access Control Gateway User's Manual Step 5 : Add Local Radius Accounts Click Service Domain -> Authentication -> Local Radius Accounts, the Local Radius Accounts Management page will appear. A new account can be added into the Local Radius Database. To add a account here, enter the Username (e.g.
(e.g. AP00) and get associated with this ESSID. 2. The client device will obtain an IP address automatically via DHCP from WMS-308N. Open a web browser on a client device, access any URL, and then the Domain0's User Login Page will appear.
User's Manual Chapter 4. Web Interface Configuration WMS-308N provides functions as stated below where they can be configured via a user-friendly web based interface. After finishing the configuration of the settings, please click Save button and pay attention to see if a Reboot message appears on the screen.
Internet. This can be a DSL modem, Cable modem, or a WISP gateway router. WMS-308N will direct all the packets to the gateway if the destination host is not within the local network.
Page 27
IP Address do not assigned from DHCP server, the system need manual connect to DHCP server. Hostname : The Hostname of the WAN port PPPoE : This configuration type is applicable when the WMS-308N is connected to a network with the presence of a PPPoE server.
Page 28
WMS-308N Network Access Control Gateway User's Manual My WAN IP Netmask : The Subnet mask of the WAN port MTU : By default, it’s 1460 bytes. MTU stands for Maximum Transmission Unit. Consult with WISP for a correct MTU setting.
WAN1 automatically. Connection Detect : The connect detect sets the WMS-308N Device to continuously ping a user defined IP address (it can be the Internet gateway for example). If it is unable to ping under the user defined constraints, the WMS-308N device will change Primary WAN interface to secondary WAN interface automatically .
Page 30
WMS-308N Network Access Control Gateway User's Manual Service : By default, it's “Disable”. To “Enable” to activate this function. IP Address To Ping : specify an IP address of the target host which will be monitored Ping Interval : specify time interval (in seconds) between the ICMP “echo requests” are sent. Default is 60 seconds.
Service Provider: Select the correct Service Provider from the drop-down list, here included are dyndns, dhs, ods and tzo embedded in the WMS-308N. Hostname: This field represents the Host Name you register to Dynamic-DNS service and expect to export to the world.
WMS-308N Network Access Control Gateway User's Manual 4.1.5 Configure Local(LAN/VLAN) Network Here is the instruction for how to setup the local LAN/VLAN IP Address and Netmask. Please click on System -> LAN , the LAN List should be appear. This page shows information of LAN's/VLAN's settings.
Page 33
WMS-308N Network Access Control Gateway User's Manual VLAN Tag(ID) : Virtual LAN, the system supports 7 tagged VLAN port (VLAN1 ~ VLAN7). The valid values are from 1 to 4094. The default VLAN1's tag ~ VLAN7's tag are from 101 to 107.
Page 34
WMS-308N Network Access Control Gateway User's Manual example for Even Distribution of Bandwidth, set Total Max. Upload or Download to 9 Mbps, if one user access Internet, the maximum upload or download is 9 Mbps; if three users access Internet at the same time, the maximum upload or download is 3 Mbps by each user.
Page 35
WMS-308N Network Access Control Gateway User's Manual Individual Download : The Individual Download is in the range of 0~102400 Kbit/s, 0 indicates unlimited, default is 512 Kbit/s Group Total Limit : By default, it's “Disable”. To “Enable” to activate Group Total Limit.
Page 36
WMS-308N Network Access Control Gateway User's Manual Port : Indicate the system's RJ-45 interface port. By default; it's enabled. To disable to unactivated LAN's or VLAN's port. PVID : Port VID, Select desired default VLAN ID on the respective port, all untagged packets arriving at the device are tagged with the port PVID.
Page 37
WMS-308N Network Access Control Gateway User's Manual WINS IP : Enter IP address of the Windows Internet Name Service (WINS) server; this is optional. Domain : Enter the domain name for this network. Lease Time: The IP addresses given out by the DHCP server will only be valid for the duration specified by the lease time.
Port QoS Setup : When port-based priority is enabled, packets received from the high-priority port are sent to the high priority queue of the destination port. The WMS-308N provides maximum 8 queue per port for packet scheduling with queue weight and priority assignment.
WMS-308N Network Access Control Gateway User's Manual Manage the System 4.2.1 Configure System Time System time can be configured via this page where manual setting and NTP server configuration are both supported. Please click on System -> Time Server and follow the below setting.
WMS-308N Network Access Control Gateway User's Manual 4.2.2 Configure Management The administrator can later obtain the geographical location of the system via the information configured here. The administrator also can change system password and configure system login methods. Please click System ->...
Page 41
IP Address/ Domain field. Ping Watchdog : The ping watchdog sets the WMS-308N Device to continuously ping a user defined IP address (it can be the Internet gateway for example). If it is unable to ping under the user defined constraints, the WMS-308N device will automatically reboot.
Page 42
Without a valid certificate, users may encounter the following problem in IE8 when they try to access WMS- 308N's GUI (https://192.168.2.254). There will be a “Certificate Error”, because the browser treats WMS-308N as an illegal website. Click “Continue to this website” to access the WMS-308N's GUI. The WMS-308N's Home page will be appear.
WMS-308N Network Access Control Gateway User's Manual 4.2.3 Configure SNMP SNMP is an application-layer protocol that provides a message of format for communication between SNMP managers and agents. By enabling SNMP function, the administrator can obtain the system information remotely. Please click on System -> SNMP Setup and follow the below setting.
WMS-308N Network Access Control Gateway User's Manual 4.2.4 Backup / Restore and Reset to Factory Current settings on the system can be backed up, or previous backed up settings can be restored as well as resetting the system back to factory default can be performed via this page. Please click on Utilities ->...
WMS-308N Network Access Control Gateway User's Manual 4.2.5 Firmware Upgrade The administrator can download the latest firmware from website and upgrade the system here. It might take a few minutes before the upgrade process completes and the system needs to be restarted to activate the new firmware.
Times : By default, it’s 5 and the range is from 1 to 60. It indicates number of connectivity test. Traceroute : Allows tracing the hops from the WMS-308N device to a selected outgoing IP address. It should be used for the finding the route taken by ICMP packets across the network to the destination host. The test is...
WMS-308N Network Access Control Gateway User's Manual 4.2.7 Format Database This function allows administrator to format system's database. Click Format button to proceed and take around three minutes to complete. 1. Do not interrupt during format database including power on/off as this may damage system.
WMS-308N Network Access Control Gateway User's Manual 4.2.8 Reboot This function allows administrator to restart system with existing or most current settings when changes are made. Click Reboot button to proceed and take around three minutes to complete. A reminder will be available for remaining time to complete. If power cycle is necessary, please wait till completion of the reboot process.
User's Manual Access To External Network With Service Domain WMS-308N supports 8 Service Domain, administrator can quickly setup via this page. LAN Port : The bonding interface for the respective Service Domain Auth Type : The authentication type for the respective Service Domain. There are five types : Pregenereated Ticket.
WMS-308N Network Access Control Gateway User's Manual 4.3.1 Configure Service Domain Administrator can configure Service Domain with different authentication service type, specified outgoing traffic, IP PnP service, guest free service, idle time , redirect URL, scheduling authentication service and customization login page.
Page 51
Scheduling setting is on Time Policy page. IP PnP : IP Plug and Play, the WMS-308N supports IP PnP for the respective Server Domain. At the user end, a static IP address can be used to connect the system. Regardless of what the IP address at the user end is, authentication can still be performed through WMS-308N.
Page 52
WMS-308N Network Access Control Gateway User's Manual Guest Count Limit : Enter maximum number of guest to a desired number in the range of 1~100. The default value is 5. For example, while the number of the guest is set to 5, only 5 guest are allowed to connect to Internet via controller at the same time.
Page 53
WMS-308N Network Access Control Gateway User's Manual Example for Upload Page : Here the codes are supplied. Please note that the part is for the login feature(can't not modified), the green part can be modified freely by administrators. <html> <head>...
4.3.2.1 Authentication Management The WMS-308N supports multiple login for one accounts and administrator can configure alias name of the respective authentication type on login page. Please click on Service Domain -> Authentication -> Authentication Management, and follow the below setting.
WMS-308N Network Access Control Gateway User's Manual 4.3.2.2 Configure Pregenerated Tickets This section is for administrators to pregenerated authentication tickets for entire external Network. There are four types of policy ticket can be generated (One Time, Multiple Times, Volume and Unlimited Until End Time).
Page 57
WMS-308N Network Access Control Gateway User's Manual Click Save button for generate ticket databases in the Pergenerated Tickets Database List.
Page 58
WMS-308N Network Access Control Gateway User's Manual Delete : Click Delete button to delete selected tickets databases. After clicking delete button, the alert message appears as below . Click OK button, the system will check and delete selected pregenerated tickets database. The Success message will appear after deleting database.
Page 59
WMS-308N Network Access Control Gateway User's Manual List : Click “Info” button to view information of each tickets databases. Below depicts an example for information of Pregenetated tickets databases. Ticket Information : Show information for selected tickets database File ID: Identifying tickets databases...
Page 60
Export Tickets : There are three methods to backup your information of ticket databases Export BIN : The administrator can backup ticket database or copy to other WMS-308N. Click Export button, the ticket databases (FileID_passcode.bin) will be download from system. Below depicts an example for exporting tickets database.
Page 61
WMS-308N Network Access Control Gateway User's Manual Below depicts an example for printable tickets Tickets List : Show tickets information Code : User can used ticket's Passcode for access Internet. Type/Quota : Denote ticket's time/volume policy and service quota. Status : Show ticket's status. There three types of status : Unused, Used and Expired.
WMS-308N Network Access Control Gateway User's Manual 4.3.2.3 Configure On-Demand Administrators can enable and configure this authentication method to provide clients access in a Hotspot environment. Major functions include billing plans creation, accounts creation, accounts monitoring list, thermal printer support, billing report statistics, and external payment gateway support. There are three method to generate on-demand accounts : Generate by Manual, Print from Thermal Printer, Generate after Online Payments.
WMS-308N Network Access Control Gateway User's Manual 4.3.2.3.1 Create Billing Plans Click Edit button on Billing Plans List page to enter the Billing Plan Setup page. In the Billing Plan Setup page, Administrator may configure plans. Status : By default, it's “Disable”. To “Enable” to activate this billing plan.
WMS-308N Network Access Control Gateway User's Manual 4.3.2.3.2 Create On-Demand Users After configuring billing plans, administrator can create and delete on-demand users on this section. Click Info button on Billing Plans List page to enter the On-Demand Information page. In the On-Demand Information page.
Page 65
WMS-308N Network Access Control Gateway User's Manual Click Preview button to preview ticket in the billing plan. Below depicts an example for previewing ticket. Click Close button to close window. Click Add Accounts button, the create page will appear as below. Click Cancel button to close window.
Page 66
WMS-308N Network Access Control Gateway User's Manual Statistic : Show on-demand users statistic information for this billing plan Ticket Qty : Denote ticket's quantity in this billing plan Used Ticket Qty : Denote used ticket's quantity in this billing plan...
Page 67
WMS-308N Network Access Control Gateway User's Manual Delete : This will delete the ticket individually. When administrator click Delete button, the alert message will appear as below. On this List, it only shows all of generated tickets through clicking Add Accounts button.
WMS-308N Network Access Control Gateway User's Manual 4.3.2.3.3 Configure External Payment Gateway This section is for merchants to set up an external payment gateway to accept payments in order to provide access service to end customers who wish to pay for the service on-line.
Page 69
WMS-308N Network Access Control Gateway User's Manual Payment Gateway Information : Show current ticket's invoice number. Statistic : Show on-demand users statistic information for this billing plan Ticket Qty : Denote ticket's quantity in this billing plan Used Ticket Qty : Denote used ticket's quantity in this billing plan...
Page 70
WMS-308N Network Access Control Gateway User's Manual Delete : This will delete the ticket individually. When administrator click Delete button, the alert message will appear as below. On this List, it only shows all of generated tickets through External Payment Gateway.
4.3.2.3.4 Configure Thermal Printer WMS-308N can generate ticket of on-demand users manually or automatically from Thermal Printer. Please click on Service Domain -> Authentication -> On-Demand -> Thermal Printer Setup to enter the Thermal Printer List page. In the Thermal Printer List page. Administrator may configure Thermal Printer setting and generate tickets manually and delete tickets.
Page 72
WMS-308N Network Access Control Gateway User's Manual Service : By default, it's “Disable”. To “Enable” to activate this function. IP Address : Enter IP address of PSS-120 Command Port : Enter command port of the Thermal Printer COM Port : Select COM port for PSS-120 Balance Date : Enter balance date for statement printing from Thermal Printer.
Page 73
WMS-308N Network Access Control Gateway User's Manual Click Info button to enter Thermal Printer Information page. In the Thermal Printer Information page, administrator may generated and delete ticket manually. Thermal Printer Information : Show setting information in this Thermal Printer.
Page 74
WMS-308N Network Access Control Gateway User's Manual Statistic : Show on-demand users statistic information for this billing plan Ticket Qty : Denote ticket's quantity in this Thermal Printer. Used Ticket Qty : Denote used ticket's quantity in this Thermal Printer.
Page 75
WMS-308N Network Access Control Gateway User's Manual Delete : This will delete the ticket individually. When administrator click Delete button, the alert message will appear as below. On this List, it only shows all of generated tickets from Thermal Printer.
WMS-308N Network Access Control Gateway User's Manual 4.3.2.3.5 Billing Plan Report Click on Service Domain -> Authentication -> On-Demand to enter the Billing Plans Report page. Administrator can get a complete report or a report of a particular period. On-Demand Type : There are four type can be selected : ALL, On-Demand, Payment Gateway and Thermal Printer.
WMS-308N Network Access Control Gateway User's Manual 4.3.2.3.6 Ticket Customization Click on Service Domain -> Authentication -> On-Demand to enter the Ticket Customization page. Administrator can edit text on printed ticket on this page. 4-32 characters supported on these text setting field.
4.3.2.4 Configure Local Radius Accounts WMS-308N provide Local Radius server authentication. Please click on Service Domain -> Authentication - > Remote Radius Server, the page of Remote Radius Server Setup will appear. Administrator can add accounts by manual or import accounts file.
Page 79
WMS-308N Network Access Control Gateway User's Manual Local Radius Accounts List : ➔ Delete : Select specify group and click Delete button to remove accounts of specified group. ➔ Import Accounts File : Select specify group on Group option and click Select File button to select the t text file for uploading the accounts of specified group.
Page 80
WMS-308N Network Access Control Gateway User's Manual Search : Enter a keyword to be searched in the text field and all matching the keyword will be listed. These settings will become effective immediately after clicking the Save button.
4.3.2.5 Configure Remote Radius Server WMS-308N provide remote Radius server authentication. Please click on Service Domain -> Authentication -> Remote Radius Server, the page of Remote Radius Server Setup will appear Service : By default, it's “Disable”. To “Enable” to activate this function.
User's Manual 4.3.2.6 Configure LDAP Server WMS-308N provide remote LDAP server authentication. Please click on Service Domain -> Authentication -> LDAP,, the page of LDAP Server Setup will appear Service : By default, it's “Disable”. To “Enable” to activate this function.
WMS-308N Network Access Control Gateway User's Manual 4.3.2.7 Configure POP3 Server The system supports authentication by an external POP3 authentication server. Up to 8 POP3 server can be configured. Please click on Service Domain → Authentication → POP3, the page of POP3 Server Setup will appear.
This function provides local device can access Internet without authentication. If there are some workstations belonging WMS-308N that need to access to network without authentication, enter the IP or MAC address of these workstations in this list. Up to 50 address can be defined in this list. Please click on Service Domain →...
WMS-308N Network Access Control Gateway User's Manual 4.3.4 Configure Walled Garden This function provides certain free services or advertisement web pages for users to access the websites listed before login and authentication. Up to 20 address or domain names of the websites can be defined in this list.
4.3.5 Configure Notification WMS-308N can automatically send the notification of Traffic Log, On-Demand Log, Session Log, Monitor AP Report and AP Status to 3 particular E-mail addresses. The notification of AP Status is triggered by the event when a managed APs becomes unreachable during “Auto Download Profile Interval” period. A trial email is provided by the system for validation.
Page 87
WMS-308N Network Access Control Gateway User's Manual system provides authentication for sender's SMTP server Username : The sender's authentication username for STMP server Password: The sender's authentication password for STMP server Notification E-mail Setup : Receiver E-mail Address (es) : Up to 3 E-mail address can be set up to receive the notification. These are the receiver's E-mail address.
Page 88
WMS-308N Network Access Control Gateway User's Manual Traffic Log : As shown in the following figure, each line is traffic history record consisting of 10 fields : Date, Auth Type, Status, Passcode/Username, IP, MAC, Packets In, Bytes In, Packets Out and Bytes Out.
Page 89
WMS-308N Network Access Control Gateway User's Manual On-Demand Log : As shown in the following figure, each line is traffic history record consisting of 12 fields : Date, Status, Passcode/Username, IP, MAC, Packets In, Bytes In, Packets Out, Bytes Out, Start Time, End Time and...
Page 90
WMS-308N Network Access Control Gateway User's Manual End Time : Indicate that the end time of current service users Plan : Indicate that the current user's billing plan. Session Log : The system can recored connection details of each user accessing the Internet and sent out to a specified Syslog Server or E-Mail based on defined interval time.
WMS-308N Network Access Control Gateway User's Manual 4.3.6 Monitor Online Users The administrator can view status of all online users on each Service Domain. Please click on Service Domain -> Online Users, the page of Online Users will appear. Below depicts an example for Online User Information.
4.3.7 Log Information The WMS-308N can record authentication traffic history or On-Demand event and the system will automatically send out the history information via notification service(See Notification page). The history of each day will be saved separately in the DRAM for 3 days and sorted by time, the traffic provides all login and logout activity of specific date.
Page 93
WMS-308N Network Access Control Gateway User's Manual Auth Type : There will shows 6 types of authentication : Pregenerated, On-Demand, Local Users(Local Radius Users), Remote Radius, LDAP and Guest.
Page 94
WMS-308N Network Access Control Gateway User's Manual Status : There will show 10 types of status as below : LOGIN : Indicate that the user login system. LOGOUT : Indicate that the user logout system. IDLE TIMEOUT : Indicate that the user idle time is over timeout setting of Service Domain, the system will logout user automatically USE UP : Indicate that the user's service time is done.
Page 95
WMS-308N Network Access Control Gateway User's Manual ADD OD ACCOUNT : Indicate that the system add On-Demand user account. DELETE OD ACCOUNT : Indicate that the system delete On-Demand user account. Passcode/Username : Indicate that the user's passcode or username.
User's Manual Control your Managed AP WMS-308N supports to manage up to 60 managed access points (AP), WLAN users are connected to the network via the managed APs, and they can be configured in this section. This section include the following functions : Device Discovery, AP Profile Management, AP Batch Setup Management, AP Group Setup Management, AP Group Status, Notification and Website Monitor.
Page 97
WMS-308N Network Access Control Gateway User's Manual HostName : Indicate the current hostname of the respective managed AP. F/W Version : Indicate the current firmware version of the respective managed AP. F/W Date : Indicate the current firmware date of the respective managed AP.
WMS-308N Network Access Control Gateway User's Manual 4.4.2 Managed AP's Profiles Management After administrator import profile of the respective managed AP, the each managed AP's profile will saved in the database of switch and listed status on AP Profile Management page. Up to 60 managed APs can be imported to system.
Page 99
WMS-308N Network Access Control Gateway User's Manual Last Update Time : Indicate the last update time of the respective managed AP.
Page 100
WMS-308N Network Access Control Gateway User's Manual Copy To Template : Click “Copy” button to save profile of the desired managed AP to template database. The alert window should be appear, then enter desired template's name and click OK button to save. Below depicts an example for copy profile to template.
Page 101
WMS-308N Network Access Control Gateway User's Manual Load From Upload File : Select desired profile from local PC. Auto Recovery : Click “Recovery” button to upload profile to new or unlist managed AP, the AP Profile Auto Recovery page will appear.
4.4.3 Managed AP Batch Setup WMS-308N supports batch configuration of the managed APs, for automatically assigning IP addresses from a range of IP addresses to the selected managed APs; for configuring wireless general and security settings to the selected managed APs; for upgrading firmware to the selected managed APs.
Page 103
Time Server Setup : Specify correct Time zone setting for selected managed APs. The default NTP Server is switch's LAN IP address. The local time of managed APs will follow WMS-308N's local time. Wireless Basic Setup : Specify Band, Channel and Tx power for selected managed APs.
Page 104
WMS-308N Network Access Control Gateway User's Manual Upgrade Firmware Via TFTP : Enter TFTP Server IP address and firmware file, and then click “Apply AP” button to upgrade. Upgrade Firmware Via URL : Enter URL address(example : http://192.168.2.10/xxx.bin), and then click...
WMS-308N Network Access Control Gateway User's Manual 4.4.4 Managed AP Group Management Administrator specify managed APs in the same group, and locate managed APs on the specified map. The switch supports automatically channel assignment and power setting for managed APs, real time wireless clients limitation in the same group managed APs.
Page 106
WMS-308N Network Access Control Gateway User's Manual RSSI Threshold %0 indicates -95 dbm on WAP-954GP and WAP-854NP; RSSI Threshold %100 respectively indicates -35 dbm and -1 dbm on WAP-954GP and WAP-854NP Figure 4-3 Dynamic Channel and Tx Power Allocation Flow Chart Maximum Clients Control : By default, it's “Disable”.
Page 107
WMS-308N Network Access Control Gateway User's Manual Tx Threshold : Tx Threshold is in the range of 0~120400 and set in unit of KBps. The default value is 10240 KBps. Specify desired transmit bandwidth for wireless clients limitation in the same group of each managed AP.
Page 108
WMS-308N Network Access Control Gateway User's Manual Map : Click Map to configure location setting, the respective Group Location Setup page will appear, and the administrator specify flag mark as location on the Map from the Device List. The MAP function ONLY supports monitor with width resolution for...
Page 109
WMS-308N Network Access Control Gateway User's Manual Edit : Click Edit to configure settings of the respective group in the list. Delete : Click Delete to remove the respective group in the list. Upload Map Setup : Select desired Map to upload. Click Preview to view the respective Map, click Delete to remove the respective Map.
WMS-308N Network Access Control Gateway User's Manual 4.4.5 AP Group Status This section provide detailed information of group on Overview, Location, Device Information, Online Users and Device Syslog can be reviewed via this page. Overview : Show graphs which continuously represent the current data traffic and on-line clients on the respective group.
Page 111
WMS-308N Network Access Control Gateway User's Manual Device Information : Display the device information of the respective group. Online Users : Display all associated clients status of the respective group. Devices Syslog : Display all system events of the respective group.
User's Manual 4.4.6 Website Monitor WMS-308N will send out a packet periodically to monitor the connection status of the IP addresses on the list. If the monitored IP address does not respond, the system will send an e-mail to notify the administrator that such destination is not reachable.
User's Manual Manage 3rd-Party AP WMS-308N supports to manage up to 32 3rd-Party access points (AP), WLAN users are connected to the network via the 3rd-Party APs, and they can be configured in this section. This section include the following functions : CGI Path Setup, 3rd-Party AP Management, 3rd-Party Batch Setup Management and 3rd- Party AP Status.
Page 114
WMS-308N Network Access Control Gateway User's Manual Upgrade via Web Server CGI Path : Enter CGI path of the 3rd-Party AP for Firmware upgrade via Web server Reboot CGI Path : Enter CGI path of the 3rd-Party AP for system reboot.
WMS-308N Network Access Control Gateway User's Manual 4.5.2 3rd-Party AP Management After administrator add CGI Path of the respective 3rd-Party AP, the each AP can be added in the list. Up to 32 APs can be managed. Please click on 3rd-Party AP → 3rd-Party AP Management, the 3rd-Party AP Management Setup page will appear.
4.5.3 3rd-Party AP Batch Setup Management WMS-308N supports batch configuration of the 3rd-Party AP, for automatically assigning IP addresses from a range of IP addresses to the selected 3rd-Party AP; for configuring wireless general and security settings to the selected 3rd-Party AP; for upgrading firmware to the selected 3rd-Party AP.
Page 117
Time Server Setup : Specify correct Time zone setting for selected 3rd-Party AP. The default NTP Server is switch's LAN IP address. The local time of 3rd-Party AP will follow WMS-308N's local time. Click “Apply AP” to send configure data to selected 3rd-Party AP and click “Reboot AP” to send restart request to select 3rd- Party AP.
Page 118
WMS-308N Network Access Control Gateway User's Manual • Firmware Upgrade Via TFTP : Enter TFTP Server IP address and firmware file, and then click “Apply AP” button to upgrade. • Firmware Upgrade Via URL : Enter URL address(example : http://192.168.2.10/xxx.bin), and then click...
WMS-308N Network Access Control Gateway User's Manual 4.5.4 3rd-Party AP Status This section provide informations of 3rd-Party AP on System Information and Interface Information via this page. Click “Refresh” button to renew status.
WMS-308N Network Access Control Gateway User's Manual Restrain the Users and Sharing Your Internal Service 4.6.1 Configure Time Policy Administrator can define time policy for Service Domain, IP Filtering, MAC Filtering and Virtual Server. There are 10 policy can be defined. Please click on Advance -> Time Policy to enter Time Policy Setup page.
WMS-308N Network Access Control Gateway User's Manual 4.6.2 IP Filter The administrator can setting IP Filter via this page, Please click on Advance -> IP Filter and follow the below setting. Source Address/Mask : Enter the desired source IP address and netmask; the mask must be a plain number, i.e.
WMS-308N Network Access Control Gateway User's Manual 4.6.3 MAC Filter The administrator can setting MAC Filter via this page, Please click on Advance -> MAC Filter and follow the below setting. Action : Select the desired access control rule; the options are “Only Deny List MAC”, or “Disable”.
WMS-308N Network Access Control Gateway User's Manual 4.6.4 Virtual Server (Port/ IP Forwarding) A certain area in the network can be exposed to the Internet in a limited and controlled way for on-line game or video conferencing via this page. Please ensure the internal port to be used is not occupied by other applications.
WMS-308N Network Access Control Gateway User's Manual 4.6.5 The Demilitarized zone (DMZ) can be enabled and used as a place where services can be placed such as Web Servers, Proxy Servers, and E-mail Servers such that these services can still serve the local network and are at the same time isolated from it for additional security.
WMS-308N Network Access Control Gateway User's Manual 4.6.6 IP Routing The IP Routing Settings allows you to configure routing feature in the gateway. The system supports RIP(Routing Information Protocol ) and OSPF(Open Shortest Path First) dynamic routing and allows you to manually configure static network routes.
Page 126
WMS-308N Network Access Control Gateway User's Manual Change these settings as described here and click Save button to save your changes. Click Reboot button to activate your changes. Routing Rules : Mode : Click Enable to activated static routing. Destination Net/Mask : Specify desired destination IP network address with format of A.B.C.D/M Via : Select a next hop of Gateway or Interface to the destination IP network.
WMS-308N Network Access Control Gateway User's Manual Observer the Status 4.7.1 Overview Detailed information on System, Network, DHCP Clients and Service Domain can be reviewed via this page. System Information : Display the information of the system. Networking Information : Display the information of the network.
Route Information : Select “Route Information” on the drop-down list to display route table. WMS-308N could be used as a L2 or L3 device. It doesn’t support dynamic routing protocols such as RIP or OSPF. Static routes to specific hosts, networks or default gateway are set up automatically according to the IP configuration of system's interfaces.
Page 129
WMS-308N Network Access Control Gateway User's Manual ARP Table Information : Select “ARP Table Information” on the drop-down list to display ARP table. ARP associates each IP address to a unique hardware address (MAC) of a device. It is important to have a unique...
WMS-308N Network Access Control Gateway User's Manual 4.7.3 Event Log The Event log displays system events when system is up and running. Also, it becomes very useful as a troubleshooting tool when issues are experienced in system. Time : The date and time when the event occurred.
WMS-308N Network Access Control Gateway User's Manual Appendix A. Web GUI valid Characters Table A Web GUI Valid Characters Block Field Valid Characters VLAN Tag 1-4094 LAN/VLAN IP Address A.B.C.D IP Format Setup IP Netmask 128.0.0.0 ~ 255.255.255.252 IP Gateway A.B.C.D IP Format...
Page 132
WMS-308N Network Access Control Gateway User's Manual User name Length : Up to 32 0-9, A-Z, a-z ~ ! @ # $ % ^ * ( ) _ + - { } | : < > ? [ ] / ; ` , . =...
Page 133
WMS-308N Network Access Control Gateway User's Manual Table A Web GUI Valid Characters (continued) Block Field Valid Characters DDNS Hostname Length : Up to 32 0-9, A-Z, a-z @ - _ . User Name Length : Up to 32 0-9, A-Z, a-z ~ ! @ # $ % ^ * ( ) _ + - { } | : <...
Page 134
WMS-308N Network Access Control Gateway User's Manual Table A Web GUI Valid Characters (continued) Block Field Valid Characters IP Filter Source/Destination A.B.C.D IP Format Source/Destination 0 ~ 32 Source/Destination Port 1 ~ 65535 MAC Filter MAC address MAC Format; 12 HEX characters...
Page 135
WMS-308N Network Access Control Gateway User's Manual Table A Web GUI Valid Characters (continued) Block Field Valid Characters Thermal IP Address A.B.C.D IP Format Printer Command Port 1 ~ 65535, default is 5000 New Lock Password 4-8 digit number Confirm Lock Password...
Page 136
WMS-308N Network Access Control Gateway User's Manual Table A Web GUI Valid Characters (continued) Block Field Valid Characters Privilege List Device Name 4-32 characters IP Address A.B.C.D IP Format MAC Address MAC Format; 12 HEX characters Description Up to 64 characters...
WMS-308N Network Access Control Gateway User's Manual Appendix B. System Manager Privileges There are three system management accounts for maintaining the system; namely, the root, admin and operator accounts are with different levels of privileges. The root manager account is empowered with full...
Page 138
WMS-308N Network Access Control Gateway User's Manual This section is to show independent Hotspot owners how to configure related settings in order to accept payments via PayPal, making the Hotspot an e-commerce environment for end users to pay for and obtain Internet access using their PayPal accounts or credit cards.
Page 139
WMS-308N Network Access Control Gateway User's Manual Step 2 : Edit NECESSARY settings in “API Access” Please click on Profile -> API Access in the Account Information.
Page 140
WMS-308N Network Access Control Gateway User's Manual After click API Access on Account Information, the API Access setting will appear. Click “Request API credentials” in Option 2 – Request API credentials to create your own API username and password. Select Request API signature and click “Agree and Submit” button to generate API username, API...
Page 141
WMS-308N Network Access Control Gateway User's Manual The API Username, API Password and Signature will generated. Click “Done” button to finish process.
WMS-308N Network Access Control Gateway User's Manual Appendix D. Examples of Making Payments for End Users Step 1 : Click the link below the login window to pay for the service by credit card via PayPal. Step 2 : Select service package and Click Buy Now button to send out this transaction. There will be a...
Page 143
WMS-308N Network Access Control Gateway User's Manual Step 3 : You will be redirected to PayPal website to complete the payment process. You can pay service fee via Paypal account or use your credit card (Click “continue checkout” hyperlinks) Step 4 : After login Paypal The payment information will appear. Click Pay Now button to get passcode.
Page 144
WMS-308N Network Access Control Gateway User's Manual Step 5 : After clicking Pay Now button, the process of paying confirm will appear. Please don't close this window. Step 6 : After paying confirm, the system will create Passcode for end users login. Click Login button to enter Login page.
WMS-308N Network Access Control Gateway User's Manual Appendix E. Issue Refund for PayPal Step 1 : Click on Service Domain -> Authentication -> On-Demand -> Payment Gateway Setup, and then click Information button on the Billing Plan Setup List to enter Payment Gateway Information page. Click...
Page 146
WMS-308N Network Access Control Gateway User's Manual Step 3 : View the transaction detail and click “Issue a refund”.
Page 147
WMS-308N Network Access Control Gateway User's Manual Step 4 : Click Continue button to next page. Step 5 : Click Issue Refund button to refund this payment.
Page 148
WMS-308N Network Access Control Gateway User's Manual Step 6 : Go My Account, and verify Transaction Details.
The Figure shows an example for AP device with VLAN tagged and untagged connect to different Service Domain. The WMS-308N create three Service Domains : Domain 1 use On-Demand authentication with VLAN tag 101, Domain 2 use Pregeneraged Tickets authentication with VLAN tag 102, Domain 3 use Local RADIUS accounts authentication with VLAN tag 103.
Page 150
WMS-308N Network Access Control Gateway User's Manual Step 1 : Verify WAN and System's Time. Step 2 : Configure Service Domain, set Domain 1 to On-Demand authentication, Domain 2 to Pregenerate Tickets authentication, Domain 3 to Local Users authentication. Step 3 : Configure VLAN on VLAN 1 ~ VLAN3 Setup page, set VLAN1's tag to 101, VLAN2's tag to 102 and VLAN3's tag to 103.
Page 151
WMS-308N Network Access Control Gateway User's Manual Step 5 : Configure Port Setup on LAN Setup page, enable Port 4 and set Port 4's PVID to VLAN2(102). Step 6 : Reboot System Step 7 : Verify Wireless clients can connect WAP-954GP and WAP-854NP with correct authentication type...
WMS-308N Network Access Control Gateway User's Manual Appendix G. Use Template to setup Managed APs The system supports LAN setting, Time setting, Wireless Basic setting, Wireless Security setting and Firmware Upgrade, if administrator want to configure more managed APs with same settings, such as Time Server, HTTP Port, Wireless Advanced Setup …...
Page 153
WMS-308N Network Access Control Gateway User's Manual Step 3 : Import profile of the respective managed AP Step 4 : Check the respective managed AP's profile in the Profile List, and change “Auto Download Profile Interval” to 1 minute, then chick Save button.
Page 154
WMS-308N Network Access Control Gateway User's Manual Step 7 : Configure WAP-954GP-B and WAP-954GP-C with WAP-954GP-A's Template • Click Restore button on the WAP-954GP-B and WAP-954GP-C, the AP Profile Restore page will appear. • Select “Load From Template Profile” in Restore Type.
WMS-308N supports centralized management of each AP. When the system has failed AP, the administrator needs to replace the AP, and set the same as before. Using WMS-308N to quickly configure new AP, the new AP's setting will be the same as before. Below depicts an example for “Auto Recovery” function.
Page 156
WMS-308N Network Access Control Gateway User's Manual Step 5 : The WAP-954GP-D(00:1A:50:05:08:19) will display on the Available Recovery AP List and the status show “Available Use”. Step 6 : Select WAP-954GP-D and click “Recovery” button, then the WAP-954GP-D will reboot.
WMS-308N Network Access Control Gateway User's Manual Appendix I. AP Management API Description The section explains Wireless Switch or Controller how to configure 3rd-Party AP or get informations via sending POST data. Below illustration describes procedure between AP Management and 3rd-Party AP.
WMS-308N Network Access Control Gateway User's Manual 2. System Setup http://<Device IP>:<Device Port>/<Device CGI Path> Type : POST or GET Host_Name=<Host Name>&Host_Description=<Description>&Host_Location=<Location>&... Return : JSON Format Success {"status": "success"} Failure {"status": "error", "msg": <error message>} Example : URL : http://192.168.2.254:80/cgi-bin/Save.cgi?cgi=SYSTEM Data : Host_Name=AP-981X&Host_Description=In-WallAP&Host_Location=&...
Page 160
WMS-308N Network Access Control Gateway User's Manual 3. Time Zone Setup http://<Device IP>:<Device Port>/<Device CGI Path> Type : POST or GET Time_NTP=<ON/OFF>&Time_NTP_Server=<NTP Server>&Time_Zone=<Zone>&... Return : JSON Format Success {"status": "success"} Failure {"status": "error", "msg": <error message>} Example : URL : http://192.168.2.254:80/cgi-bin/Save.cgi?cgi=TIME Data : Time_NTP=1&Time_NTP_Server=192.168.2.253&Time_Zone=+0800&...
Page 161
WMS-308N Network Access Control Gateway User's Manual Table I-4. Time Zone Description Value Description +1200 (GMT+12:00) Fiji, Kamchatka, Marshall Islands, Willington +1100 (GMT+11:00) Magadan, Solomon Islands +1000 (GMT+10:00) Canberra, Guam, Port Moresby, Vladivostok +0900 (GMT+09:00) Seoul, Tokoyo, Yakutsk +0800 (GMT+08:00) Beijing, Hong Kong, Singapore, Taipei...
Page 162
WMS-308N Network Access Control Gateway User's Manual 4. Wireless Basic Setup http://<Device IP>:<Device Port>/<Device CGI Path> Type : POST or GET WLAN_Band=<Band>&WLAN_Country=<Country Code>&WLAN_Channel=<Channel>&... Return : JSON Format Success {"status": "success"} Failure {"status": "error", "msg": <error message>} Example : URL : http://192.168.2.254:80/cgi-bin/Save.cgi?cgi=WLAN Data : WLAN_Band=3&WLAN_Country=US&WLAN_Channel=6&WLAN_TxPower=5&...
Page 163
WMS-308N Network Access Control Gateway User's Manual 5. Wireless VAP Setup http://<Device IP>:<Device Port>/<Device CGI Path> Type : POST or GET WLAN_VAP_ID=<VAPID>&WLAN_ESSID=<ESSID>&WLAN_Security=<Security Type>&... Return : JSON Format Success {"status": "success"} Failure {"status": "error", "msg": <error message>} Example : URL : http://192.168.2.254:80/cgi-bin/Save.cgi?cgi=VAP Data : WLAN_VAP_ID=0&WLAN_VAP=1&WLAN_ESSID=AP00_Test&WLAN_Security=0&...
Page 164
WMS-308N Network Access Control Gateway User's Manual Table 6. Wireless VAP Command Description (Continued.) Command Name Value Note WLAN_WEP1_PW The password of WEP key 10, 26, 32 Hex format characters WLAN_WEP2_PW 5, 13, 16 ASCII format character WLAN_WEP3_PW WLAN_WEP4_PW WLAN_Cipher...
Page 165
WMS-308N Network Access Control Gateway User's Manual 6. Firmware Upgrade via TFTP http://<Device IP>:<Device Port>/<Device CGI Path> Type : POST or GET Upgrade_TFTP_IP=<TFTP Server IP>&Upgrade_TFTP_File=<Firmware Filename> Return : JSON Format Success {"status": "success"} Failure {"status": "error", "msg": <error message>} Example : URL : http://192.168.2.254:80/cgi-bin/Save.cgi?cgi=UPGRADE_TFTP...
Page 166
WMS-308N Network Access Control Gateway User's Manual 7. Firmware Upgrade via Web Server http://<Device IP>:<Device Port>/<Device CGI Path> Type : POST or GET Upgrade_URL=<Web URL> Return : JSON Format Success {"status": "success"} Failure {"status": "error", "msg": <error message>} Example : URL : http://192.168.2.254:80/cgi-bin/Save.cgi?cgi=UPGRADE_URL...
Page 167
WMS-308N Network Access Control Gateway User's Manual 8. Reboot Device Before system sent Reboot request, the system will confirm device's IP Address and HTTP Port first. When device receive request, device should send current configuration setting of device's IP address and HTTP port.
Page 168
WMS-308N Network Access Control Gateway User's Manual Example : URL : http://192.168.2.254:80/cgi-bin/index.cgi?cgi=GET Data : 1=LAN_IP&2=Login_HTTP_Port Return : ”1”: {"name" : "LAN_IP", “value”: “192.168.2.60”}, ”2”: {“name” : “Login_HTTP_Port”: “80”} URL : http://192.168.2.254:80/cgi-bin/Save.cgi?cgi=REBOOT Data : submit=Reboot...
Page 169
WMS-308N Network Access Control Gateway User's Manual 9. Show System Info http://<Device IP>:<Device Port>/<Device CGI Path> Type : POST or GET Return : HTML Tables Format <table> Content ... </table> Example : URL : http://192.168.2.254:80/cgi-bin/index.cgi?cgi=SYSTEM_INFO Return Content : <table> <tr><th>Host Name</th><td>AP-981X</td></tr>...
Page 170
WMS-308N Network Access Control Gateway User's Manual 10. Show Interface Info http://<Device IP>:<Device Port>/<Device CGI Path> Type : POST or GET Return : HTML Tables Format <table> Content ... </table> Example : URL : http://192.168.2.254:80/cgi-bin/index.cgi?cgi=INTERFACE_INFO Return Content : <table> <tr><th>PHY</th><td>eth0</td></tr>...
Need help?
Do you have a question about the WMS-308N and is the answer not in the manual?
Questions and answers