Page 3
WaveKROM Backhaul Installations............10 Mounting the WaveKROM Backhaul in the pole or tower ......14 1. Product Overview ................15 Compatibility and Requirements............. 15 NETKROM NMS Features ............... 15 NETKROM Features ..............15 NETKROM NMS Installation Guide........... 16 NETKROM NMS................17 Overview of NNMS Interface............
Page 5
11.2.1 WAN ....................128 11.2.2 LAN.....................130 11.2.3 DHCP ....................131 11.2.4 NAT & Protection................... 132 11.2.5 Wireless ....................136 11.2.6 Radius ....................137 11.2.7 Authentication Type................137 11.2.8 Walled Garden ..................139 11.2.9 Advertisement ..................139 Page 5 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 6
11.5.5 HotSpot running, but no activeDHCP Server ..........156 11.5.6 A user not authenticated, but can access the Internet ........ 156 11.5.7 NETKROM NMS lost connectivity with Hotspot..........156 System Services ..............157 12.1 Configuring SNMP Settings ............157 12.2 Configuring HTTP Settings............159 12.3...
The WaveKROM Backhaul and PoE injector can be damaged by incorrect power application. Read and carefully follow the installation instructions before connecting the system to its power source. Page 7 of 184 NETKROM OS and NETKROM NMS User Manual...
2. Two Mounting brackets (include: 2 Wall/ Pole mounting system and 4 screw nuts) 3. Two PoE Injectors 4. Two Power Cables 5. Two RJ45 Waterproof Connector System 6. CD ROM Page 8 of 184 NETKROM OS and NETKROM NMS User Manual...
Select an appropriate antenna to improve range and/or coverage. Additionally, the WaveKROM Backhaul also lets you fine-tune parameters such as the transmit power to achieve the best results. Page 9 of 184 NETKROM OS and NETKROM NMS User Manual...
WaveKROM Backhaul Installations The diagram below shows the overall setup of the WaveKROM Backhaul. Page 10 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 11
45 connector on the WaveKROM Backhaul. Then connect the other end of the cable to the PoE injector. For the Netkrom PoE, the recommended length of the RJ45 Category 5 cable is up to 260 feet or 80 meters. 1.- Remove the thin enclosure nut Enclosure Nut from the feedthru assembly.
Page 12
Connect the external antenna to the N Female connector of the WaveKROM Backhaul. Step 3: From the PoE injector connect one cat.5 Ethernet cable to the WaveKROM Backhaul and another cat.5 cable to a switch or PC. Page 12 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 13
Step 4: Connect the power cable supplied in the Netkrom PoE kit to the main electrical supply and the power plug into the socket of the injector. Now, turn on your power supply. Notice that the POWER LED has lighted up.
(for example, you are on the side of a mountain in view of the base station antenna below), reverse the bracket so the Netkrom wireless radio Unit can be “tilted” downward when you aim the WaveKROM Backhaul in a later step.
NETKROM NMS has been designed to provide network administrators with a comprehensive and simple way to control and configure their network nodes. Compatibility and Requirements The NETKROM NMS software operates on any PC or Mac supported by Java. That version...
Mac Address Spoofing Advanced Firewall functionality NTP (Network Time Protocol) service NETKROM NMS Installation Guide For a Windows installation, double-click the NETKROM_vX_setup.exe installer and follow the prompts. The installer comes bundled with jre 1.4, so you do not have to pre-install it.
(right click) and tabbed/sub-tabbed panes inside the main window. NNMS Main Window The NETKROM NMS window is a graphical user interface that facilitates viewing, configuring and monitoring your wireless network. The interface includes a typical main menu, tabbed panes containing graphical and textual information and shortcut menus that allow you to navigate to other windows, tabs and dialog boxes.
Main Menu The NETKROM NMS window features a menu system with four main menu headings: File, Tools, Utilities and Help. Figure 2. NNMS Main Menu System Tabbed Panes The main body of the NNMS window displays information in tabbed panes. When NNMS starts the Network Topology tab is available. This tab contains three information panes: the Topology Map, the Registered Node List and the Node Status pane.
Discovery Manager – Open the Auto Discovery dialog box Utilities MRTG – Open the MRTG window Help Home Page – Access the NETKROM website About – Display the NETKROM introductory window Page 19 of 184 NETKROM OS and NETKROM...
2.1.2 Network Topology Tab Information Panes Figure 5. The NETKROM NMS Window Topology Map Located in the center pane, the Topology Map displays icons representing network nodes and connection information describing the layout of the network. It also can display a map graphic in the background.
Note: After the base station is configured, the configuration parameters are stored in RAM (volatile memory). If the base station is powered down the configuration will be lost unless you Save Configuration to the base station’s permanent memory. Page 21 of 184 NETKROM OS and NETKROM NMS User Manual...
2.2.1 Auto-Discovering Nodes Discovery Manager allows you to discover nodes and insert them into the Topology Map. A custom polling protocol is used to detect NETKROM nodes in the specified subnet. Discovered nodes are displayed in a tabular format. To use Discovery Manager: In the Tools menu, select Discovery Manager.
Page 23
Include to Topology To display a node in the Topology Map, leave the Include to Topology checkbox selected. Submit Click the Submit button to insert the nodes into the Topology Map. Page 23 of 184 NETKROM OS and NETKROM NMS User Manual...
2. Type the IP address, Alias (optional) and SSH Settings Password. (Typically a new node is given the default password admin) 3. Select a Displayed Icon (optional) to represent the node. Page 24 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 25
4. Click the Add button. The icon will appear in the topology pane. All topology panes are updated with the new insertion information. Figure 9. Node Insertion Page 25 of 184 NETKROM OS and NETKROM NMS User Manual...
Browse to the image file you wish to load, select it and click the Load Background Image button. Note: .gif or .jpg formats may be used for background images Page 26 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 27
Create arrows indicating a connection between nodes by clicking in the center of the source node (a hand cursor will appear), and dragging to the center of the destination node. A line with arrowhead will appear between the nodes. Page 27 of 184 NETKROM OS and NETKROM NMS User Manual...
Double click any node name shown in the Node List Right click any node in the Topology Map Figure 11. Node Shortcut Menu Page 28 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 29
GUI-Node Connectivity Settings Dialog Box IP Address When NETKROM NMS scans the network it looks for the IP Address listed in this dialog. If it makes a connection, the border around the icon turns green. If not, the border is red.
Page 30
Connectivity Settings via the Node Shortcut Menu and enter the password, then click OK or Submit. The Advanced Configuration of Node tab contains three sub-tabs: Configuration, Statistics and System Properties. Page 30 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 31
VLAN Wireless Firewall DHCP Bandwidth Manager HotSpot Services Statistics Figure 15. Tab/Chapter List The table above indicates the chapters where descriptions and configuration procedures for each tab are located. Page 31 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 32
Advanced Configuration Tab Hierarchy Figure 16. Mind Map of Advanced Configuration Tabs and Sub-tabs Page 32 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 33
Click this option to reboot the node. An Alert dialog box appears with the question: Should system save its configuration before reboot. Click Yes if you want to save the configuration. Page 33 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 34
Click this option to start a wizard that provides an easy and convenient way to install new nodes. (See Chapter 16 for details) Remove Click this option to remove the currently selected node from the Topology Map and Registered Node List. Page 34 of 184 NETKROM OS and NETKROM NMS User Manual...
This section describes IP Networking settings and configuration procedures for your NETKROM node. To configure IP Networking, select the Interface Configuration tab, located under the Advanced Configuration of Node, Configuration, Network tabs. See Page 32 for a diagram showing Advanced Configuration tabs and sub-tabs.
If there is a PPP connection (from a PPPoE client or a PPTP client), the remote peer IP address is displayed in the PTP IP Address field. Otherwise this field is blank. This is a read-only field. Page 36 of 184 NETKROM OS and NETKROM NMS User Manual...
IP Forwarding all traffic to flow between interfaces even if they are set on different subnets. Select the IP Forwarding check box to allow the system to forward packets from one subnet to another. Page 37 of 184 NETKROM OS and NETKROM NMS User Manual...
Note: The bridge name must begin with the string “br”. There is no limitation to the rest of the name. Delete Bridge To delete a bridge Select the bridge in the Network Interfaces Tree Page 38 of 184 NETKROM OS and NETKROM NMS User Manual...
For example, if http://www.examplesite.com were assigned the address 222.33.44.55, virtual interfaces 222.33.44.56 and 222.33.44.57 might be assigned to www.examplesite.net and www.examplesite.org. All three sites could exist on the same system without conflict. Page 39 of 184 NETKROM OS and NETKROM NMS User Manual...
To access this option, click the Table View button located below Network Interface Tree pane. The Interface Configuration dialog appears. Page 40 of 184 NETKROM OS and NETKROM NMS User Manual...
To make a router an 802.1Q compliant device, one or more VLAN interfaces must be created with the proper tags. This can be accomplished Page 41 of 184 NETKROM OS and NETKROM NMS User Manual...
VLAN tab of the NETKROM NMS window. VLAN interfaces can be added, removed and managed from this tab. Figure 25. VLAN Tab 3.6.1 Adding VLAN Interfaces 1. In the VLAN tab, click the button. The Create a new VLAN dialog appears.
Change these settings as required, then click the Submit button. The new settings appear in the VLAN Interface list. 3.6.4 Uploading VLAN Interfaces To send the configuration settings to the node, click the button. Page 43 of 184 NETKROM OS and NETKROM NMS User Manual...
This method has the advantage of being predictable and simple to set up. It is useful in managing small networks but becomes somewhat unwieldy on larger networks. NETKROM NMS provides management tools for manipulating any of the routing tables and configuring rules.
Configuring Routing Tables and Entries NETKROM provides a multiple routing table system with a flexible infrastructure and the ability to implement policy routing. In addition to the local and main routing tables, NETKROM supports up to 252 additional routing tables. 4.1.1...
Figure 31. Insert New Route In the above example all the traffic with destination addresses that belong to subnet 192.168.2.0/24 will be forwarded via interface ath0. Page 46 of 184 NETKROM OS and NETKROM NMS User Manual...
A rule is a method for implementing Access Control Lists (ACL) for routes. Rules allow you to specify the filters that match packets to select a route structure when the filter does match. Page 47 of 184 NETKROM OS and NETKROM NMS User Manual...
7. In the Interface drop down list, select the interface that packets are received from. The interface can be one of the available physical interfaces or can be set to All. Page 48 of 184 NETKROM OS and NETKROM NMS User Manual...
Entries Commands button to move the entry upward or the button to move it downward in the list. Page 49 of 184 NETKROM OS and NETKROM NMS User Manual...
NETKROM NMS allows you to configure all wireless settings for nodes on your wireless network, including: Link Distance Transmit Power Operational Modes Radio Settings Security Settings Outdoor Settings Country Code Settings Site Survey Operation To configure Wireless settings, select the Wireless tab, located under the Advanced Configuration of Node, Configuration tabs.
If the selected interface is not active a red warning message is shown next to the interface. Setting Operational Modes A NETKROM node has the ability to operate in the following modes: Access Point WDS (Wireless Distribution System) ...
SSID box. Inactivity Limit If a station associated with the NETKROM access point is idle for a period of time defined by the Inactivity Limit field, the NETKROM access point sends a disassociation frame to the station to inform it that it had been disassociated due to inactivity timeout.
Page 53
To access a list of information for all nodes associated with the AP, click the Association List button. The Associated stations for wireless interface dialog box appear. Figure 35. Association List Page 53 of 184 NETKROM OS and NETKROM NMS User Manual...
WDS_Type Client NOTE: Every client that has ever been associated to the AP is included to this list, which is automatically saved when you click Save Configuration. Page 54 of 184 NETKROM OS and NETKROM NMS User Manual...
NETKROM AP, select the Stop Wireless to Wireless Traffic check box. NOTE: NETKROM has the ability to support Address 4 traffic. However it is necessary to put the wireless interface (the one that operates as an access point) under a Network Bridge (check IP Network configuration) if you intend to enable Address 4 support.
AP that matches the desired BSSID (Basic Service Set Identifier) and adopts the settings of the BSS (Basic Service Set). After the association is complete, NETKROM repeats the BSS creating a brand new BSS range. Repeaters implement a combination of both Client mode and Access Point mode functionality and features such as Stealth Mode and Wireless to Wireless Traffic control.
Page 57
As the diagram above illustrates, the NETKROM Repeater is associated with the NETKROM Base Node. After being associated, the NETKROM Repeater extends the NETKROM Base Node’s BSS. The result is that the Initial BSS range is expanded to the footprint shown by the Final Merged BSS range with the Repeater acting as an access point with the Base Node settings.
3 traffic for all possible entities which maybe adjacent to its Ethernet interface. You can select either mode based on your network needs. Figure 39. AP Client Mode Settings Page 58 of 184 NETKROM OS and NETKROM NMS User Manual...
5.1.6 Using Site Survey Operation The Site Survey button is available on all OpMode tabs. If a NETKROM node operates as AP Client, Repeater or Station, Site Survey will scan all available channels to find an appropriate BSSID to join (based on user credentials SSID, BSSID, Security etc).
Page 60
Rows in the dialog box display all the available information for every node scanned. After the scan is complete and the dialog box list is populated, the status bar at the bottom of NETKROM NMS window displays the message Site survey list retrieved successfully. Figure 41.
set and enable the Frag value set and enable the RTS parameter enable Spoofing configure the MAC Address enable Diversity operation select the Antenna connector Page 61 of 184 NETKROM OS and NETKROM NMS User Manual...
The TxRate drop down list allows you to select a standard transmission rate based on the available rates associated with the selected physical layer standard. You also can select Auto mode. In Auto mode NETKROM will be auto-configured to support the optimal TxRate for each related node.
Setting RTS The RTS field allows you to implement RTS/CTS handshaking between a NETKROM node and another station on the wireless network. RTS/CTS handshaking helps minimize collisions among hidden stations on a wireless network. An RTS/CTS handshake involves the originating node sending a Ready To Send frame to its destination, then waiting for the destination to return a Clear To Send frame.
ACL (Access Control List) 5.3.1 Setting Wired Equivalent Privacy (WEP) Through the WEP tab you can configure a NETKROM node to encrypt/decrypt data with keys based on the WEP protocol. To implement WEP, select WEP in the Selected Encryption Mode drop down list.
EAP-TLS is by default the supported protocol for EAP. The NETKROM node uses 802-1X authentication to authenticate its clients. If the NETKROM node is configured as a client, in the case of EAP-TLS usage, you should upload the appropriate certificates on NETKROM station.
Page 66
NETKROM node. TKIP (Temporal Key Integrity Protocol) AES(CCMP) (Advanced Encryption Standard-Counter Mode CBC- MAC Protocol) BOTH (selected if a NETKROM node is configured as an access point) Page 66 of 184 NETKROM OS and NETKROM...
Group Cipher (Group Cipher is not functional in NETKROM NMS version 1.1.3) 5.3.3 Configuring Access Control Lists (ACL) When the Selected Operational Mode has been set to Access Point or WDS, the ACL sub-tab in the Security tab is available for selection. You have the option of setting an Access Control List to manage clients trying to connect to the access point.
It increases throughput by transmitting more data per frame and removing inter-frame pauses. To implement fast frames, select the Fast Frames check box. Page 68 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 69
Settings checkbox to access the Advanced WMM Parameters dialog Box. Figure 50. Advanced WMM Parameters WMM QUEUES (TRAFFIC PRIORITIES) There are the four queues that h/w uses to organize and prioritized the packets AC_BK= Background Access Category Page 69 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 70
Input to the algorithm that specifies the initial random backoff wait time (window as known) for retry transmission.This valuw is the upper limit in msecs of a range from which initial random backoff wait time is determined. Page 70 of 184 NETKROM OS and NETKROM NMS User Manual...
Wireless Topology Scenarios In this section two possible specific wireless topologies are described, based on NETKROM's operational modes. In the first section two ways of setting a point-to-point link are described. In the second section a specific topology concerning NETKROM Repeater functionality is described.
Page 72
WDS-Node-2’s MAC address should be set in Node-1’s WDS list. Both nodes should transmit on the same frequency. NETKROM Stealth Mode should be used (if you want to avoid beacon transmitting) or Hide ESSID (if you want beacons to be transmitted but not to publish the NETKROM node’s ESSID.)
Figure 53. Extended Repetition Topology Example In this scenario the NETKROM Base Node’s BSS is repeated through a Repeater chain. Each NETKROM Repeater node repeats the BSS of the previous node. Each station is connected to a different Repeater Node, but they all belong to the same BSS as if they were on the same access point.
RFC 2082. Also, in an effort to avoid waking up hosts that do not participate in the routing protocol, RIPv2 multicasts routing updates to 224.0.0.9, as opposed to RIPv1 which uses broadcast. Page 74 of 184 NETKROM OS and NETKROM NMS User Manual...
RIPv1. Password: Password input text field. Split Horizon: Enables the Split Horizon option. This is simply data suppression. It works by not sending updates about networks Page 75 of 184 NETKROM OS and NETKROM NMS User Manual...
In a situation where a neighbor cannot process multicast packets, it is necessary to establish a direct link between routers. The neighbor command allows the network administrator to specify a router as a RIP neighbor. Page 76 of 184 NETKROM OS and NETKROM NMS User Manual...
Static: Redistributes routing information from static route entries into the RIP tables. Default: Redistributes routing information from kernel route entries into the RIP tables. Page 77 of 184 NETKROM OS and NETKROM NMS User Manual...
However, a firewall mis-configuration may result in denial of service even for the administrator, outlining a high risk configuration. NETKROM OS Firewall and NAT subsystems consist of four firewall and two NAT queue chains. 7.1.1 Firewall Chains ...
Set up Policy Add, delete and manage Firewall Rules and Flowmarks Write rules to the active list Refresh the displayed information Figure 55. Firewall Chains Page 79 of 184 NETKROM OS and NETKROM NMS User Manual...
IP address. When the adjacent check box is selected the rule will match all packets except the ones that have the specified Source IP address. Basic Rule Settings Figure 56. Firewall Rule Configuration Dialog Box, Basic Tab Page 80 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 81
Flowmark chain. New Flowmark The New Flowmark field is available if Mark is selected in the Action field. Type the name of the new flowmark in the New Flowmark box. Page 81 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 82
The following selections may be configured in this field: ALL – A match always occurs. TCP – A match occurs if 1. the packet’s protocol type is TCP Page 82 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 83
3. RESPONSE: A match occurs if the packet is an ICMP response. GRE – A match occurs if the packet’s protocol type is GRE (Generic Routing Encapsulation) Page 83 of 184 NETKROM OS and NETKROM NMS User Manual...
AH – A match occurs if the packet’s protocol type is AH Connection State NETKROM can perform firewall functions based on the connection state. The following selections may be configured in this field: New - A match occurs if the packet starts a new connection (router has seen packets in one direction).
For example, Source MAC: is configured with the specific MAC address. When the adjacent check box is selected the rule will match all packets except the ones that have the specified Source MAC address. Page 85 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 86
(in case the configured interface is a bridge, this also matches with interfaces under the bridge). In the Output Interface drop down list, select a specific input interface, or select ANY. Page 86 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 87
Masquerade: The IP address to be assigned to outgoing packets is dynamically retrieved by the current outgoing interface’s IP address (does not need to explicitly configure the outgoing source IP address). Page 87 of 184 NETKROM OS and NETKROM NMS User Manual...
SSH connections from the internet, you can insert a rule in the Input chain of the Firewall system that will drop this kind of connection (because they are TCP connections, SYN flag will be set). Page 88 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 89
Destination Port: 22(SSH) Figure 62. Basic Rule Example Configuration Figure 63. Advanced Rule Example Configuration Click Submit to add the rule to the list and apply it to the router. Page 89 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 90
Translate Source IP to: 0.0.0.0-0 MASQUERADE (eth0’s address) Comment: NAT_on_WAN Figure 65. NAT Configuration - Masquerade Example Click Submit to add the rule to the list and apply it to the router. Page 90 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 91
HINT: make sure IP Forwarding is enabled on the router (Interface settings Panel). Important: To enable a NAT rule (write it to the active list) you must click the button. Page 91 of 184 NETKROM OS and NETKROM NMS User Manual...
See Page 32 for a diagram showing Advanced Configuration tabs and sub-tabs. Configuring a DHCP SERVER The NETKROM DHCP server provides an extended set of configuration parameters while at the same time being effective and low resource consuming.
Start IP and End IP Type the appropriate IP addresses into the Start IP and End IP fields. These are the upper and lower limits for the DHCP server address pool. Page 93 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 94
(leased). This field specifies the number of seconds the DHCP server should cache the offers it has extended to discovering DHCP clients. The default value is 60 seconds. On fast network media this value can be decreased. Page 94 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 95
DHCP leases file. After an IP allocation you are able to see the new record in the DHCP Leases dialog after approximately a 60 second delay. Page 95 of 184 NETKROM OS and NETKROM NMS User Manual...
DHCP client will search for DHCP servers. Similar to DHCP server configuration, multiple instances of DHCP client on different interfaces are allowed. Page 96 of 184 NETKROM OS and NETKROM NMS User Manual...
DHCP messages and forwarding them on (and onto other network segments). This eliminates the necessity of having a DHCP server on each physical network. Page 97 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 98
Interface where application relays on should has a valid ip and subnet mask and like the other DHCP apis, DHCP relay can have multiple instances on different interfaces. To complete the configuration, click Submit. Page 98 of 184 NETKROM OS and NETKROM NMS User Manual...
IP address and subnet mask on this interface. To view the full PPPoE tab, select the PPPoE option button and select the Active check box. The PPPoE tab appears. After completing the required fields, click Submit. Page 99 of 184 NETKROM OS and NETKROM NMS User Manual...
To set a static DNS address and/or a default gateway, or leave another application to configure them, (e.g. DHCP client), select the Keep DNS and Gateway check box. Page 100 of 184 NETKROM OS and NETKROM NMS User Manual...
Configuring a PPTP Client The PPTP client application is used to create PPTP connections with PPTP servers mainly used by Internet Service Providers. Page 101 of 184 NETKROM OS and NETKROM NMS User Manual...
Dial IP or ISP Name To identify the PPTP server, type the IP address in the Dial IP field, OR type the DNS name of the PPTP service in the ISP Name field. Page 102 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 103
When you click the Refresh button the Current Status field displays information on the current connection (whether there is a connection or the reason for an unsuccessful attempt to connect). Page 103 of 184 NETKROM OS and NETKROM NMS User Manual...
Mitigate DoS attacks by restricting the network usage available for specific kinds of traffic (eg. ICMP traffic). 10.1 The QoS window tab Let's have a look first, at the overall GUI interface (Picture 77). Page 104 of 184 NETKROM OS and NETKROM NMS User Manual...
Classes” label in the respective Panel. You can define as many Traffic Classes as you wish. A Traffic Class can also form a tree-like hierarchy of Subclasses. The tree may have at most two layers of subclasses (Picture 78). Page 105 of 184 NETKROM OS and NETKROM NMS User Manual...
Bear in mind, that you can't assign more than one policy per interface flow; as well as, the same policy to both flows of the same interface. The way that Classes, Policies and Interfaces are interrelated is depicted in picture 79. Page 106 of 184 NETKROM OS and NETKROM NMS User Manual...
Negations of most of the eg. ! 192.168.1.1/32 aforementioned These parameters constitute the MATCH part of a class. The GUI panel responsible for these options is depicted at picture 80. Page 107 of 184 NETKROM OS and NETKROM NMS User Manual...
Committed Burst Size Excess Burst Size Priority These parameters constitute the TARGET part of a class. The GUI interface responsible for these options are depicted in Picture 81. Page 108 of 184 NETKROM OS and NETKROM NMS User Manual...
For instance, when we browse the Internet, our web browser requests a web page and then remains idle for a long period of time, until another page is requested. Page 109 of 184 NETKROM OS and NETKROM NMS User Manual...
These automatically generated classes, get the rest of the bandwidth (as its CIR), which is not reserved for any of the user-defined ones. System generated classes are always of priority 7. Page 110 of 184 NETKROM OS and NETKROM NMS User Manual...
Servers Let's have a look now at one example, in order to better comprehend the QoS mechanism. Let's say that we have a NETKROM OS powered Hotspot, equipped with an standard 11mbps wireless interface. The real available bandwidth on such an interface is approximately 5.5mbps or 5500kbps.
2. We add a new class, named let's say “ftp_traffic_out”, to handle outgoing traffic from interface ath0. 3. We click on “ftp_traffic_out” class and configure the MATCHES and TARGET as depicted on picture 83. Page 112 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 113
Figure 84. 'ftp_traffic_in' configuration 5. Now we will create two policies, one for each flow direction, named 'ftp_in' and 'ftp_out'. We accomplish this by right-clicking on 'Traffic Policies' label. Page 113 of 184 NETKROM OS and NETKROM NMS User Manual...
3. In a similar manner, we create two new classes, named 'ftp_traffic_out_ftp2' and 'ftp_traffic_in_ftp2' to handle traffic originated from/destined to 192.168.1.190/32 (Picture 86). We also set the TARGET application type to FTP. Page 114 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 115
For instance, the two classes depicted at picture 87 are overlapping, cause is ambiguous which one will handle traffic originating within subnet 172.8.1.0/24 and destined to host 192.168.1.1/32 with destination port number 200. Page 115 of 184 NETKROM OS and NETKROM NMS User Manual...
192.168.1.0/24. This is to allow for other ftp sessions to take place. Next, on the MATCHES part, we set the port range to 20 – 21 (ftp- data, ftp-control), and the protocol type to FTP. Page 116 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 117
Page 117 of 184 NETKROM OS and NETKROM NMS User Manual...
10.5 Example: Elimination of P2P Traffic Currently, NETKROM OS does not support filtering of ip traffic based on its Layer 7 properties. For example, you can't set up a firewall rule to block incoming/outgoing P2P traffic. Nonetheless, you can virtual eliminate it, by restricting the bandwidth available to it.
Page 119
P2P applications altogether. The following pictures demonstrate the QoS configuration needed. Figure 90. Class hierarchy for restricting P2P traffic on both interfaces p2p_in, p2p_out MATCHES p2p_in, p2p_out TARGET Figure 91. Overlapping parallel classes Page 119 of 184 NETKROM OS and NETKROM NMS User Manual...
Example: Access Point Bandwidth Sharing 10.6.1 New QoS Entry NETKROM OS NNMS has a convenient way to set bandwidth policies for individual clients of an Access Point. This feature works only for clients that have a statically assigned IP and not via DHCP. If you want to...
Page 121
Note: If it's about a single IP, use a subnet mask of /32. However, if you want the policy to cover multiple IPs, then use the appropriate subnet mask. After submitting both windows the resulting class hierarchy will be: Figure 94. Resultant QoS layout for Maria and John Page 121 of 184 NETKROM OS and NETKROM NMS User Manual...
The pie chart corresponds to the number of packets services by the class up to now. By choosing the table view you get some more detailed statistics, including dropped packets due to rate/burst limitations. Page 122 of 184 NETKROM OS and NETKROM NMS User Manual...
Similarly, all packets forwarded by the gateway, have as source mac the gateway's mac address. Hence, it's pointless to use these fields on a NETKROM OS powered AP, which acts as a gateway. Page 123 of 184 NETKROM OS and NETKROM...
PIR on a subclass and not set it on one of its sibling classes. All of them should either have or not have a PIR defined. Page 124 of 184 NETKROM OS and NETKROM NMS User Manual...
TARGET properties of a class. On the other hand 'Submit' is used to save the overall QoS configuration. Finally, don't forget to save configuration on the device via the 'Save Configuration' option on the 'View Topology' window. Page 125 of 184 NETKROM OS and NETKROM NMS User Manual...
The NETKROM OS HotSpot Access Gateway enables telcos, operators, wireless ISPs, enterprises, government institutions, or school campuses to deploy WLANs with secured user authentication support. Based on both RADIUS (Remote Authentication User Dial-In Service) and Web Redirection technology, when an unauthenticated wireless user is trying to...
Page 127
Users Info button. The HotSpot Users dialog box appears. The Users Info button is available when the HotSpot configuration is complete and the HotSpot is running. Page 127 of 184 NETKROM OS and NETKROM NMS User Manual...
The following sections describe the configuration settings for each tab. 11.2.1 WAN WAN is the interface that the HotSpot should use to connect to the Internet. Page 128 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 129
The WAN interface will retrieve dynamically the corresponding IP Settings via DHCP protocol. PPTP Client The WAN interface will try to connect via the PPTP protocol based on its configuration parameters. Page 129 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 130
HotSpot Interfaces box. You have the flexibility to select multiple interfaces, either Ethernet or wireless. When the HotSpot is initialized, these interfaces will be bridged under a network bridge called br_HotSpot. Page 130 of 184 NETKROM OS and NETKROM NMS User Manual...
IP address 192.168.1.255 is the Broadcast IP, which cannot be assigned. DNS 1 and DNS 2 If DNS values are set to 0.0.0.0, the Hotspot will assign the router's DNS IP addresses. Page 131 of 184 NETKROM OS and NETKROM NMS User Manual...
IP addresses, but private ones. If NAT Enable is not selected, HotSpot users' IP addresses will be forwarded to the Internet unmodified. Figure 106. HotSpot Wizard NAT & Protection Tab Page 132 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 133
SNMP request NNMS connection accepted New NNMS connection ICMP traffic Limited to 5/sec All ICMP types UDP port 500 and Protocols Accepted IPsec traffic AH, ESP (IPsec) Everything else Dropped Page 133 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 134
HotSpot users NNMS connection accepted New NNMS connection ICMP traffic Limited to 5/sec All ICMP types UDP port 500 and Protocols Accepted IPsec traffic AH, ESP (IPsec) Everything else Dropped Page 134 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 135
Type Action Comments Connections To Internet Accepted Traffic from HotSpot users ICMP traffic Limited to 5/sec All ICMP types Protocols AH, ESP (IPsec) Accepted IPsec traffic Everything else Dropped Page 135 of 184 NETKROM OS and NETKROM NMS User Manual...
Key 1, Key 2, Key 3 and Key 4 Type up to four different Key codes in these fields and select the one to be used by clicking the option button beside it. Page 136 of 184 NETKROM OS and NETKROM NMS User Manual...
The Accounting Port is the port used to send Accounting Requests to the Radius Server (1813 by default). 11.2.7 Authentication Type Authentication Type is the method used to authenticate HotSpot users. At least one must be enabled. Page 137 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 138
Address of the Radius Access Response (if present), or the next available IP address in the range of Dynamic IP addresses. If authentication fails and UAM Authentication is enabled, user obtains an IP address in the Page 138 of 184 NETKROM OS and NETKROM NMS User Manual...
HotSpot Wizard Walled Garden Tab 11.2.9 Advertisement Advertisement is a set of at most five URLs that a HotSpot user will be redirected to, after having authenticated successfully using UAM authentication. Page 139 of 184 NETKROM OS and NETKROM NMS User Manual...
Type additional text for promotional purposes. E.g. Featured by Tony’s HotSpot Operators. Select Color Click Select Color to access the Select Background Color dialog box. Select the background color of the redirection Web page. Page 140 of 184 NETKROM OS and NETKROM NMS User Manual...
To apply the configuration to the router, click the Submit button at the bottom of the Summary tab. Exit Click Exit to return to the main HotSpot configuration tab Page 141 of 184 NETKROM OS and NETKROM NMS User Manual...
To poll the HotSpot’s status, click the Refresh button. If the Status box displays Initializing, retry a few minutes later. The Status box will display Running when initialization is complete. Page 142 of 184 NETKROM OS and NETKROM NMS User Manual...
Paned-IP-Address = 192.168.1.3, WISPr-Bandwidth-Max-Up = 256000, WISPr-Bandwidth-Max-Down = 512000 *NOTE: FORMAT HAS BEEN CHANGED FROM VERSION 1.1.0 (XX-XX-XX-XX-XX-XX INSTEAD OF XXXXXXXXXXXX). CAPITAL LETTERS MUST BE USED (0A-0B-0C-0D- 0E-0F). Page 143 of 184 NETKROM OS and NETKROM NMS User Manual...
HotSpot will send Accounting requests to radius every 60 seconds. 11.4 HotSpot Configuration Example Assume that the user’s system is equipped with two Ethernet interfaces and one wireless interface. Page 144 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 145
The authentication is assumed to be handled by the user’s local Radius Server (IP 192.168.1.00). NETKROM HotSpot’s WAN Interface in that case is eth0, the one connected to the router (and Internet). Hotspot users will be assigned with IPs in the subnet 192.168.0.0/24 To sum up, NETKROM HotSpot should be configured with: ...
Page 146
HotSpot Configuration Procedure Select Advanced Node Configuration from the Node Shortcut Menu in NETKROM NMS. Click the HotSpot tab to begin the HotSpot configuration. The HotSpot tab appears. Page 146 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 147
5. In the Gateway field type: 192.168.1.1 Click the Next button. The LAN tab will appear. Figure 120. WAN Configuration – Example The LAN tab contains two lists: Physical Interfaces and HotSpot Interfaces Page 147 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 148
Mask portion representing 255.255.255.0) 2. In the DNS 1 field, type: 0.0.0.0 (This will tell it to get NETKROM WAN DNS IP) 3. In the Domain field type: domain_of_your_choice 4. In the Lease field, type 600, the lease time for DHCP (in seconds) Click the Next button.
Page 149
2. In the IP Address 2 field, type: 0.0.0.0 (no backup radius server) 3. In the Authentication Method drop down list, select: CHAP 4. In the Secret Key field, type: radius_secret Page 149 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 150
A user connected to a HotSpot LAN Interface can then access that address without authentication. ) Click the Next button. The Advertisement tab will appear. Page 150 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 151
2. In the Brand Name and Extra Text boxes, type a text message. 3. Click the Select Image button to browse for image files to insert into the Web page. Click the Next button. The Summary tab will appear. Page 151 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 152
Summarize Configuration – Example Click the Exit button. The main HotSpot pane appears. Although the configuration has been loaded, Hotspot is not running. (Status field displays: Stopped). To complete the procedure: Page 152 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 153
Figure 132. HotSpot is Running – Example Return to the Network tab and note the Interface List contains a bridge br_HotSpot with eth1 and ath0 under it. Page 153 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 154
Interface Panel after HotSpot’s Initiation – Example Select the Firewall and NAT tabs and note that they also are initialized. Figure 134. New Firewall Settings – Example Figure 135. NAT Settings – Example Page 154 of 184 NETKROM OS and NETKROM NMS User Manual...
11.5.1 Cannot set wireless interface configuration Check if you have selected channel and ESSID. If you are running NETKROM OS with a CPE license, wireless interfaces cannot be used as access points, and Hotspot cannot have wireless HotSpot interfaces.
Check if the domain the user has accessed is in the Walled Garden domains. 11.5.7 NETKROM NMS lost connectivity with Hotspot If you access Hotspot through the WAN interface, make sure WAN interface has established its connectivity, or you have not selected HIGH Protection Level in Hotspot configuration (in this situation the NNMS connection from WAN is dropped).
NETKROM can be configured to run the following services: SNMP (Simple Network Management Protocol) Service HTTP (Hyper-Text Transfer Protocol) Service SSH (Secure Shell Protocol) Service NTP (Network Time Protocol) Service To configure System Services settings, select the Services tab, located under the Advanced Configuration of Node, Configuration tabs.
Page 158
The collection of variables is described by a Management Information Base (MIB). When SNMP is enabled, NETKROM will respond to SNMP requests (SNMP get, getnext, getbulk, walk). A community name can be configured, as a read-only community. SNMP set requests are not supported.
(Hyper-Text Transfer Protocol) connections from web browsers delivering Web pages and other files to them, as well as processing form submissions. When HTTP is enabled, NETKROM will respond to HTTP/HTTPS requests. To configure HTTP, select the HTTP tab under the Services tab.
Based on UTC time, independent of time zones and day-light saving time. Synchronization accuracy can reach 1 millisecond. When NTP is enabled, NETKROM will periodically send a request to a configured NTP server (based Interval time) and adjust NETKROM’s local system time.
Type the new password in the New Password text box. The new password must be at least 8 characters and no more than 63 characters Re-type Re-type the new password in the Retype text box Page 162 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 163
Submit Figure 142. Change Administrator’s Password Click Submit to apply the configuration. Page 163 of 184 NETKROM OS and NETKROM NMS User Manual...
The advanced statistics engine of NETKROM OS, in combination with the graphing facilities of NETKROM NMS, lets the administrator delve into the results real-time, identifying high bandwidth nodes and possible bottlenecks. Some Monitoring and Statistics features are available from the Node Shortcut Menu.
NETKROM NMS provides the option of real time traffic monitoring. To view the Current Throughput Graph, click Current Throughput in the Node Shortcut Menu. Figure 144. Current Throughput Window 13.3 Viewing Packet Statistics The Packet Stats tab contains information concerning the total packet statistics per interface.
13.4 Viewing the ARP Table The ARP Entries tab contains the ARP (Address Resolution Protocol) table of the currently selected NETKROM node. On a single physical network, individual hosts are known on the network by their physical hardware address. Higher-level protocols address destination hosts in the form of a symbolic address (IP address in this case).
When the utility is terminated it summarizes the results in a graphic display, giving the average round trip time and the percent packet loss. This utility can be Page 167 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 168
Packet Statistics (Transmitted Packets, Received Packets and Loss %) and Time Statistics (Min, Max and Average) in bar graph format. Page 168 of 184 NETKROM OS and NETKROM NMS User Manual...
Traceroute is a utility that records the route (the specific gateway computers at each hop) through the Internet between your NETKROM node and a specified destination. It also calculates and displays the amount of time each hop took. Traceroute is a handy tool for understanding where problems are in the Internet network.
CPU and Memory. To access the System Properties, select the System Properties tab under the Advanced Configuration tab, Figure 150. System Properties Dialog To refresh the data in the System Properties fields, click the Refresh button. Page 170 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 171
TCP Timeout for Established Connections The TCP Timeout for established connections field contains the maximum value permitted by a TCP implementation for the established timeout, measured in milliseconds. Page 171 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 172
Max concurrent TCP SYN requests Max concurrent TCP SYN requests field contains the number of concurrent connection request attempts at one time. Page 172 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 173
Max elements in arp table Max elements in arp table field contains the maximun number of entries in arp table, the maximum number of entries and cannot be passed. Page 173 of 184 NETKROM OS and NETKROM NMS User Manual...
MRTG generates HTML pages containing GIF images which provide a live visual representation of this traffic. MRTG client support of NETKROM NMS uses the package provided by JRobin (http://oldwww.jrobin.org/utilities/mrtgdemo.html). To use the MRTG, select MRTG under the Utilities menu.
The WISP Easy Wizard is an extension to NETKROM NMS providing a convenient and easy way to install NETKROM nodes. To start the WISP Easy Wizard, in the Node Shortcut Menu, select WISP Easy Wizard (WEW). The WISP Easy Wizard (WEW) dialog box appears which displays some typical WISP installations.
A) Do the following if you remember the administration password Required tools: Null Modem Cable with Full Handshaking: A Terminal Emulator (e.g. Hyperterminal) Parameters: Bits per second: 115200 Data Bits: Parity: None Stop Bits: Flow Control: None Page 176 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 177
( Previously you have to open the outdoor enclosure) Open the Terminal Emulator and use the parameters mentioned above. Power Up the Radio (Use the same PoE system provided by Netkrom Technologies) Press Enter continuously.
Page 178
Note: Remove only the conf.tgz file. If you remove any other file and cannot access the radio anymore, please contact the Tech Support Department. Page 178 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 179
Association List ..........................53 Authentication MAC ..................................143 UAM..................................144 Backend Radius Configuration................................143 Backup ..............................33 Bandwidth Manager ..........................104 Beacon Period ............................ 52 BSSID Preferred................................59 Current Throughput ........................ 34, 164 Page 179 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 180
DNS Address DHCP Servers ..............................95 Global Settings................................38 Fade Margin ............................54 Firewall ..............................74, 78 Chains ..................................78 Examples.................................88 Matching Fields ..............................80 Global Settings ............................37 Hide ESSID ............................55 HotSpot Page 180 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 181
MAC ................................. 138 Address ................................37, 54 Spoofing..................................37 MRTG .............................. 171, 174 Chains ..................................78 Matching Fields ..............................85 Rules ..................................84 Network Bridge ............................38 Network Interfaces Tree Using..................................36 Node Add ..................................24 Page 181 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 182
Channels and Frequencies............................62 Configuration................................61 MAC Address .................................62 Phycial Layer ................................62 Transmission Rates ..............................62 Reboot..............................33 Repeater Mode Configuration................................56 Routers ..............................95 Routing Modifying ................................49 Removing................................49 Repositioning................................49 Static ..................................47 Tables..................................45 Security Page 182 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 183
PPTP Fields ................................102 Walled Garden Fields ............................139 System Properties............................ 170 System Services Configuration................................157 Table View ..............................40 Throughput.............................. 164 TKIP................................66 Trace Route ............................. 169 Transmission Rate ........................... 54 Page 183 of 184 NETKROM OS and NETKROM NMS User Manual...
Page 184
PPPoE Client ................................99 WDS ................................55 WEP ................................ 136 WINS Servers .................................95 Wireless..............................50 Extended Repetition..............................73 Point to Point Links ..............................71 Scenarios.................................71 Setting Modes .................................51 WISP Easy Wizard ........................... 34 Page 184 of 184 NETKROM OS and NETKROM NMS User Manual...
Need help?
Do you have a question about the WaveKrom Backhaul BH-1000 and is the answer not in the manual?
Questions and answers