Nexcom IWF2220 User Manual

Light industrial access point

Advertisement

Quick Links

User Manual
Light Industrial Access Point
IWF2220
V1.2

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the IWF2220 and is the answer not in the manual?

Questions and answers

Summary of Contents for Nexcom IWF2220

  • Page 1 User Manual Light Industrial Access Point IWF2220 V1.2...
  • Page 2: Fcc Statement

    NEXCOM, INC. Disclaimer NEXCOM, INC. does not assume any liability arising out the application or use of any products, or software described herein. Neither does it convey any license under its parent rights not the parent rights of others.
  • Page 3 This device and it's antennas(s) must not be co-located or operating in conjunction with any other antenna or transmitter except in accordance with FCC multi-transmitter product procedures. This device is going to be operated in 5.15~5.25GHz frequency range, it is restricted in indoor environment only. IMPORTANT NOTE: FCC Radiation Exposure Statement: Copyright © NEXCOM, INC.
  • Page 4 1. Handling the unit: carry the unit with both hands and handle it with care. 2. Maintenance: to keep the unit clean, use only approved cleaning products or cleans with a dry cloth. Copyright © NEXCOM, INC.
  • Page 5: Table Of Contents

    1.2 Document Conventions ........................6 1.3 Package Content ..........................7 System Overview and Getting Started ..................... 8 2.1 Introduction of NEXCOM Access Points ..................8 2.2 Hardware Description........................9 2.3 Hardware Installation ........................11 2.4 Access Web Management Interface ..................... 12 Connect your AP to your Network ....................
  • Page 6 7.4.4 Reboot ..........................74 7.4.5 Upload Certificate ......................75 7.4.6 Channel Analysis ......................75 7.5 Status ..............................77 7.5.1 Overview ......................... 77 7.5.2 Associated Clients ......................78 7.5.3 WDS Link Status ......................79 7.5.4 Event Log ........................80 Copyright © NEXCOM, INC.
  • Page 7: Before You Start

    Indicates that clicking this button will save the changes you made, but you must reboot the system for the changes to take effect. Indicates that clicking this button will clear what you have set before the settings are applied. Copyright © NEXCOM, INC.
  • Page 8: Package Content

    User’s Manual Light Industrial AP ENGLISH 1.3 Package Content The standard package of IWF2220 includes:  NEXCOM IWF2220  CD-ROM (with User’s Manual and QIG)  Ethernet Cable  Power cord  Power Adaptor (12V)  Detachable Antenna It is recommended to keep the original packing materials for possible future shipment when repair or maintenance is required.
  • Page 9: System Overview And Getting Started

    IWF2220 features dual radio RF cards to offer flexible implementations needed for the growing wireless networking applications. The IWF Series make wireless communication fast, secure and easy.
  • Page 10: Hardware Description

    User’s Manual Light Industrial AP ENGLISH 2.2 Hardware Description This section depicts the hardware information including all panel description. IWF2220 Front Panel IWF2220 Front Panel Copyright © NEXCOM, INC.
  • Page 11 User’s Manual Light Industrial AP ENGLISH Rear Panel IWF2220 Rear Panel Restart / Reset Press once to restart the system; to reset the system to factory default settings, hold for more than 5 seconds. WES Button (RF B) WDS Easy Setup. Press the button to build up a WDS link with another peer.
  • Page 12: Hardware Installation

    Step 2. Connect the IWF2220 to your network device. Connect one end of the Ethernet cable to the Uplink port of IWF2220 and the other end of the cable to a switch, a router, or a hub. IWF2220 is then connected to your existing wired LAN network.
  • Page 13: Access Web Management Interface

    Light Industrial AP ENGLISH 2.4 Access Web Management Interface NEXCOM Access Points support web-based configuration. When hardware installation is complete, the AP can be configured through a PC by using a web browser. The default values of the AP’s LAN IP Address and Subnet Mask are: IP Address: 192.168.1.1...
  • Page 14 The Web Management Interface - System Overview Page  To logout, simply click on the Logout button at the upper right hand corner of the interface to return to the Administrator Login Page. Click OK to logout. Copyright © NEXCOM, INC.
  • Page 15  Enter the old password and then a new password with a length of up to 32 characters, and retype it in the Re-enter New Password field. Congratulation! Now, the NEXCOM Access Point is installed and configured successfully.  It is strongly recommended to make a backup copy of your configuration settings.
  • Page 16: Connect Your Ap To Your Network

    Step 1: Configuring the AP’s System Information  Enter the AP’s default IP Address (192.168.1.1) into the URL of a web browser.  Log in using Username: admin and Password: admin. The Web Management Interface will appear as shown below. Copyright © NEXCOM, INC.
  • Page 17 The alternative method is NTP. Upon selecting NTP under the Time field, the configuration changes to allow up to two NTP servers. Simply enter a local NTP server’s IP Address (if available) or search online for an NTP server nearest to you. Set the time zone and click SAVE. Copyright © NEXCOM, INC.
  • Page 18 Click SAVE when you are finished to save changes that have been made. Step 3: Configure the AP’s Wireless General Settings Click on the Wireless icon followed by the General tab. On this page we need to choose the Band and Channel that we wish to use. Copyright © NEXCOM, INC.
  • Page 19 The rest of the fields are optional and can be configured at another time. Click SAVE if any changes have been made. •For IWF2220, the RF Card A supports only 2.4GHz bands (b/g/n) and RF Card B supports ...
  • Page 20 VAP-1). Click on the Overview tab to proceed. Virtual AP Overview Page On this page click the hyperlink in the row and column that corresponds with VAP-1’s State. This will bring up the following page. Copyright © NEXCOM, INC.
  • Page 21 VAP will be used for; otherwise, leave it as default. VLAN ID can be chosen at another time. Click SAVE to save all changes up to this point and Reboot the system to apply these revised settings. Congratulations! After reboot, the AP can start to operate with these revised settings. Copyright © NEXCOM, INC.
  • Page 22: Adding Virtual Access Points

    Please click on the Wireless icon to review the VAP Overview page. VAP Overview Page To proceed with specific VAP configuration, click on the corresponding cell in the State column and row of the VAP; the particular VAP’s Configuration page will then appear for further configuration. Copyright © NEXCOM, INC.
  • Page 23 A VLAN ID can be provided to indicate the traffic through this particular VAP. It may allow further management/control (e.g. access rights and Internet usage, etc) of each VAP with a management gateway. Click SAVE and then Reboot for the changes to take effect. Copyright © NEXCOM, INC.
  • Page 24: Securing The Ap

    VAP Overview Page On the VAP Overview page, check the table to confirm the VAP State. If it is Enabled, skip to Step 2. If not, click on to proceed with VAP Configuration for that particular VAP. Copyright © NEXCOM, INC.
  • Page 25 MAC addresses is desired, skip to Step3. MAC restriction can be coupled with wireless security to provide extra protection. First, click on the corresponding cell in the column labeled Security Type. This hyperlink will direct the user to the following Security Settings page. Copyright © NEXCOM, INC.
  • Page 26 Select the desired Security Type from the drop-down menu, which includes None, WEP, 802.1X, WPA-PSK, and WPA-RADIUS.  802.11g+802.11n band does not support WEP nor WPA-PSK running TKIP. When the Security Type is set as such, the RF is only able to run ‘g’ band. Copyright © NEXCOM, INC.
  • Page 27 Security Settings: None  WEP: WEP (Wired Equivalent Privacy) is a data encryption mechanism with key length selected from 64-bit, 128-bit, or 152-bit. Security Settings: WEP  802.11 Authentication: Select from Open System, Shared Key, or Auto. Copyright © NEXCOM, INC.
  • Page 28 Security Settings: 802.1X Authentication  Dynamic WEP Settings: Dynamic WEP: For 802.1X security type, Dynamic WEP is always enabled to automatically generate WEP keys for encryption. WEP Key Length: Select a key length from 64-bits or 128-bits. Copyright © NEXCOM, INC.
  • Page 29 Accounting Port: The port number used by the RADIUS server for accounting purposes. Specify a port number or use the default, 1813. Accounting Interim Update Interval: The system will update accounting information to the RADIUS server every interval period. Copyright © NEXCOM, INC.
  • Page 30  Pre-shared Key: Enter the key value for the pre-shared key; the format of the key value depends on the key type selected.  Group Key Update Period: The time interval for the Group Key to be renewed; the time unit is in seconds. Copyright © NEXCOM, INC.
  • Page 31 RADIUS server. Accounting Port: The port number used by the RADIUS server for accounting purposes. Specify a port number or use the default, 1813. Accounting Interim Update Interval: The system will update accounting information to the Copyright © NEXCOM, INC.
  • Page 32 MAC ACL Allow List: This means that only the client devices (identified by their MAC addresses) listed in the Allow List (“allowed MAC addresses”) are granted with access to the system. The administrator can temporarily block any allowed MAC address by checking Disable, until the administrator renews the listed MAC. Copyright © NEXCOM, INC.
  • Page 33 MAC ACL Deny List: This means that all client devices are granted with access to the system except those listed in the Deny List (“denied MAC addresses”). The administrator can allow any denied MAC address to connect to the system temporarily by checking Enable. Copyright © NEXCOM, INC.
  • Page 34 ACL is selected, all incoming MAC addresses will be authenticated by an external RADIUS server. Please note that each VAP MAC ACL and its security type (shown on the Security Settings page) share the same RADIUS configuration. Copyright © NEXCOM, INC.
  • Page 35 User’s Manual Light Industrial AP ENGLISH RADIUS ACL Click SAVE and Reboot upon completing the related configurations to take effect. Copyright © NEXCOM, INC.
  • Page 36: Creating A Wds Bridge Between Two Aps

    Click the Wireless icon and then General tab to go to the following page. Wireless General Settings Page Please make sure both APs are using the same Band and Channel in order to establish a successful WDS link. Click SAVE if any changes have been made. Copyright © NEXCOM, INC.
  • Page 37 Step 3: Building the WDS Link To extend the wireless coverage, each RF card supports up to 4 WDS links for connecting wirelessly to other WDS-capable APs (peer APs). By default, all WDS profiles are disabled. Copyright © NEXCOM, INC.
  • Page 38 4. Choose the desired WDS profile: Enable WDS. Enter the MAC Address (peer AP) and then Click SAVE. If you are using another NEXCOM APs as the peer AP, simply repeat the above-mentioned steps to configure another peer AP(s). Copyright © NEXCOM, INC.
  • Page 39: Web Management Interface Configuration

    This chapter will guide the user through the AP’s detailed settings. The following table shows all the User Interface (UI) functions of NEXCOM’s Enterprise Access Points. The Web Management Interface (WMI) is the page where the status is displayed, control is issued and parameters are configured. In the Web Management Interface;...
  • Page 40 After clicking SAVE,  Note: the following message will appear: “Some modification has been saved and will take effect after Reboot.” All online users will be disconnected during reboot or restart. Copyright © NEXCOM, INC.
  • Page 41: System

     Device Time: Display the current time of the system.  Time Zone: Select an appropriate time zone from the drop-down list box.  Time: Synchronize the system time by reachable NTP servers or manual setup. Copyright © NEXCOM, INC.
  • Page 42 Set Time: Select the appropriate Hour, Min, and Sec from the drop-down menu. Unless Internet connection or NTP becomes unavailable, it is recommended to use NTP server for time synchronization because system time needs to be reconfigured upon reboot. Copyright © NEXCOM, INC.
  • Page 43: Network Interface

    Moreover, a broadcast storm may consume most of the available system resources in addition to available bandwidth. Thus, enabling the Layer 2 STP can lower such undesired occurrence and derive the best available data path for network communication. Copyright © NEXCOM, INC.
  • Page 44: Port

    The ‘TIP’ in red at the bottom of the page explains that each service zone, from default to  Service Zone 8, has its fixed, pre-determined VLAN ID number. Admin needs to enter one of the numbers in order to direct traffic back to a certain service zone. Copyright © NEXCOM, INC.
  • Page 45 VLAN ID such as connecting to a specific VAP with the same VLAN ID. Enter a value between 1 and 4094 for the VLAN ID if the option is enabled.  Note: Management is done without the utilization of VLAN IDs on selected AP models. Copyright © NEXCOM, INC.
  • Page 46 SYSLOG Server IP: The IP address of the Syslog server that will receive the reported events.  Server Port: The port number of the Syslog server.  SYSLOG Level: Select the desired level of received events from the drop-down menu. Copyright © NEXCOM, INC.
  • Page 47: Capwap

     Static Discovery: Using Static approach to discover access controller.  AC Address: The IP address of the access controller. If it can not discover the first AC, it will try to discover the second AC. Copyright © NEXCOM, INC.
  • Page 48: Ipv6

    Light Industrial AP ENGLISH 7.1.6 IPv6 The NEXCOM Access Point supports IPv6 and IPv4 dual stack addressing capability. IPv6 by default is disabled but it can be enabled on this tab page. Mode: There are two options for acquiring an IPv6 address for this device.
  • Page 49: Wireless

    This section includes the following functions: VAP Overview, General, VAP Configuration, Security, Repeater, Advanced, and Access Control. The NEXCOM Access Point supports up to eight Virtual Access Points (VAPs) per RF card. Each VAP can have its own settings (e.g. ESSID, VLAN ID, security settings, etc.).
  • Page 50  Security Type: The hyperlink showing the security type links to the Security Settings Page. VAP – Security Type Page  MAC ACL: The hyperlink showing Allow or Disable links to the Access Control Settings Page. Copyright © NEXCOM, INC.
  • Page 51: General

    Light Industrial AP ENGLISH VAP – MAC ACL Page  Advanced Settings: The advanced settings hyperlink links to the Advanced Wireless Settings Page. VAP – Advanced Settings Page 7.2.2 General AP’s general wireless settings can be configured here: Copyright © NEXCOM, INC.
  • Page 52 Channel 1-11 is available in North American and Channel 1-13 in Europe, or choose the default 6.  Max Transmit Rate: The maximum wireless transmit rate can be selected from the drop-down menu. Copyright © NEXCOM, INC.
  • Page 53 116, 120, 124, 128, 132, 36M, 48M, 54M, MCS0~15 136, 140 1M, 2M, 5.5M, 11M, 12M, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 802.11n+802.11g 18M, 24M, 36M, 48M, 54M, 11, 12, 13 MCS0~15 Copyright © NEXCOM, INC.
  • Page 54 User’s Manual Light Industrial AP ENGLISH *Please note that available values above will vary depending on the regulation of different countries. Copyright © NEXCOM, INC.
  • Page 55: Vap Configuration

    VAP. It can be coupled with different service levels like a variety of wireless security types.  VLAN ID: The NEXCOM Access Point supports tagged VLANs (virtual LANs). To enable VLAN function, each VAP shall be given a unique VLAN ID with valid values ranging from 1 to 4094.
  • Page 56: Security

    This is the default setting as shown in the following figure. Security Settings: None  WEP: WEP (Wired Equivalent Privacy) is a data encryption mechanism based on a 64-bit, 128-bit, or 152-bit shared key algorithm. Security Settings: WEP Copyright © NEXCOM, INC.
  • Page 57 Re-keying Period: The time interval for the dynamic WEP key to be updated; the time unit is in seconds.  RADIUS Server Settings (Primary/Secondary): Host: Enter the IP address or domain name of the RADIUS server. Copyright © NEXCOM, INC.
  • Page 58  Group Key Update Period: The time interval for the Group Key to be renewed; the time unit is in seconds.  WPA-RADIUS: If this option is selected, the RADIUS authentication and data encryption will both be enabled. Copyright © NEXCOM, INC.
  • Page 59 Accounting Port: The port number used by the RADIUS server for accounting purposes. Specify a port number or use the default, 1813. Accounting Interim Update Interval: The system will update accounting information to the RADIUS server every interval period. Copyright © NEXCOM, INC.
  • Page 60: Repeater

    Light Industrial AP ENGLISH 7.2.5 Repeater NEXCOM Access Points are capable of utilizing WDS to extend wireless network coverage. If WDS is enabled, the AP can support up to 4 WDS links to its peer APs. Security Type (None, WEP, or WPA/PSK) can be configured to decide which encryption is to be used for WDS connections respectively.
  • Page 61: Advanced

    SSID is disabled, only devices that have the correct SSID can connect to the system.  Wireless Station Isolation: By enabling this function, all stations associated with the system are isolated and can only communicate with the system. Copyright © NEXCOM, INC.
  • Page 62 Access Point’s multicast/ broadcast bandwidth here.  Management Frame Rate: This feature controls the bandwidth for Management Frames. The higher the rate it, the shorter range the transmission covers Copyright © NEXCOM, INC.
  • Page 63: Access Control

     Maximum Number of Clients The NEXCOM Access Point supports various methods of authenticating clients for wireless LAN access. The default policy is unlimited access without any authentication requirement. To restrict the station number of wireless connections, simply change the Maximum Number of Stations to a desired number.
  • Page 64 MAC. MAC Allow List An empty Allow List means that there is no allowed MAC address. Make sure at least the  Note: MAC of the management system is included (e.g. network administrator’s computer) Copyright © NEXCOM, INC.
  • Page 65 MAC ACL Deny List: When selecting MAC ACL Deny List, all client devices are granted access to the system except those listed in the Deny List (“denied MAC addresses”). The administrator can allow any denied MAC address to connect to the system temporarily by checking Disable. Deny List Copyright © NEXCOM, INC.
  • Page 66 ACL is selected, all incoming MAC addresses will be authenticated by an external RADIUS. Please note that each VAP’s MAC ACL and its security type (shown on the Security Settings page) share the same RADIUS configuration. RADIUS ACL Copyright © NEXCOM, INC.
  • Page 67: Firewall

    Remark: Shows the note of this rule.  Setting: 4 actions are available; Del denotes to delete the rule, Ed denotes to edit the rule, In denotes to insert a rule, and Mv denotes to move the rule. Copyright © NEXCOM, INC.
  • Page 68 (when EtherType is IPv4); ARP IP/MAC & MASK indicate the ARP payload fields. Destination: MAC Address/Mask indicates the destination MAC; IP Address/Mask indicates the  destination IP address (when EtherType is IPv4); ARP IP/MAC & MASK indicate the ARP payload fields. Copyright © NEXCOM, INC.
  • Page 69 After the SAVE button is clicked and system is rebooted, the order of rules will be updated. Please make sure all desired rules (state of rule) are checked and saved in the overview page; the rules will be enforced upon system reboot. Copyright © NEXCOM, INC.
  • Page 70 User’s Manual Light Industrial AP ENGLISH Copyright © NEXCOM, INC.
  • Page 71: Service

    There are 28 firewall services available in default settings; these default services cannot be deleted but can be disabled. If changes are made, please click SAVE to save the settings before leaving this page. Firewall Service Page Copyright © NEXCOM, INC.
  • Page 72: Advanced

    ARP request. Other network nodes can still send their ARP requests; however, if their IP appears on the static list (with different MAC), their ARP requests will be dropped to prevent eavesdropping. If any settings are changed, please click SAVE to save the configuration before leaving this page. Copyright © NEXCOM, INC.
  • Page 73: Utilities

    This function is used to backup and restore the Access Point’s settings. The AP can also be restored to factory default using this function. It can be used to duplicate settings to other access points (backup settings of this system and then restore on another AP). Copyright © NEXCOM, INC.
  • Page 74 After network parameters have been reset / restored, the network settings of the administrator PC may need to be changed to ensure that the IP address of the administrator PC is on the same subnet mask as the AP. Copyright © NEXCOM, INC.
  • Page 75: System Upgrade

    Click Reboot to restart the system. Please wait for the blinking timer to complete its countdown before accessing the system’s Web Management Interface again. The System Overview page will appear after a successful reboot. Occasionally, it is necessary to reboot the AP to ensure that parameter changes are submitted. Copyright © NEXCOM, INC.
  • Page 76: Upload Certificate

    The Channel Analysis is an excellent tool for IT staff to quickly grasp an idea of what the channel dynamics are. Included for channel analysis is a spectrogram, density graph and other charts to detect interference from Copyright © NEXCOM, INC.
  • Page 77 Environment installed beforehand, or it would not display any information. • The system only allows 1 operator to use this function at one time. • Channel Analysis only runs on the 2.4GHz RF Card A of IWF2220. Copyright © NEXCOM, INC.
  • Page 78: Status

    This page is used to view the current condition and state of the system and it includes the following functions: Overview, Associated Clients, WDS Link Status and Event Log. 7.5.1 Overview The System Overview page provides an overview of the system status for the administrator. System Overview Page Copyright © NEXCOM, INC.
  • Page 79: Associated Clients

    The administrator can remotely oversee the status of all associated clients on this page. When a low SNR is found here, the administrator can tune the corresponding parameters or investigate the settings of associated clients to improve network communication performance. Copyright © NEXCOM, INC.
  • Page 80: Wds Link Status

    Disconnect: Upon clicking Kick, the client will be disconnected from the system. 7.5.3 WDS Link Status The administrator can review detailed information of the repeater function at Status > WDS Link Status. Information of WDS status, traffic statistics, encryption and other details are provided. Copyright © NEXCOM, INC.
  • Page 81: Event Log

    Hostname: Indicates which host recorded this event. Note that all events on this page are local events, so the hostname in this field is always the same. In remote SYSLOG service however, this field will help the administrator identify which event is from this Access Point. Copyright © NEXCOM, INC.
  • Page 82 Light Industrial AP ENGLISH  Process name: Indicate the event generated by the running instance.  Description: Description of the event. To save the file locally, click SAVE LOG; to clear all of the records, click CLEAR. P/N: V10020130328 Copyright © NEXCOM, INC.

Table of Contents