& your body. This transmitter must not be co-located or operating in conjunction with any other antenna or transmitter. Gemtek Systems declares that P-560 ( FCC ID: MXF-AP930621G ) is limited in CH1~CH11 by specified firmware controlled in U.S.A.
This user’s guide and the software described in it are copyrighted with all rights reserved. No part of this publication may be reproduced, transmitted, transcribed, stored in a retrieval system, or translated into any language in any form by any means without the written permission of Gemtek Systems Holding BV.
Purpose ............................... 7 Prerequisite Skills and Knowledge...................... 7 Conventions Used in this Document ....................7 Help Us to Improve this Document! ....................7 Gemtek Systems Technical Support....................7 CHAPTER 1 – INTRODUCTION ......................8 Product Overview ..........................8 Management Options .......................... 9 Access Controller Features .........................
Page 5
User Interface | Start Page ......................87 User Interface | Walled Garden .....................87 User Interface | Web Proxy......................89 System............................... 90 System | Configuration | Syslog.....................90 System | Configuration | Trace System ..................91 System | Configuration | Clock ......................91 Gemtek Systems Page 5...
Page 6
System Commands ........................129 Status Commands ........................131 Connection Commands .......................131 E) Standard RADIUS Attributes ......................133 Vendor Specific Attributes ......................134 F) Location ID and ISO Country Codes ..................136 G) User Pages Templates Syntax....................140 GLOSSARY ............................145 INDEX ..............................150 Gemtek Systems Page 6...
This document provides information and procedures on hardware installation, setup, configuration, and management of the Gemtek Systems high performance 56Mb Hotspot-in-a-Box model P-560. The P-560 is a highly integrated Access Controller for public access areas. We will call it AC later in the manual.
It combines a high-speed wireless LAN Access Point, an IP Router, a 4-port LAN Switch and a complete Access Controller for Wi-Fi Hotspots in one box. One single P-560 can serve up to 100 simultaneous users (depending on SW license), takes control over authentication, accounting and routing to the Internet as well as to the operator’s central.
User’s Guide Installation Installation This chapter provides installation instructions for the hardware and software components of the Access Controller P-560. It also includes the procedures for the following tasks: Hardware Introduction (LEDs, Connectors) Connecting the Access Controller First Configuration Step-by-Step Setup...
User’s Guide Installation Hardware Introduction General Overview Figure 1 – P-560 Access Controller General View The front panel of the Access Controller contains: A series of indicator lights (LEDs) that help describe the state of various networking and connection operations.
User’s Guide Installation Back Panel Figure 2 – Back Panel of the P-560 The back panel of the Access Controller contains: Model and device name (see item 1 in figure above). The official device name is 54Mb Hotspot- in-a-Box, model P-560.
P-560 is booting Orange Writing to FLASH memory PPPoE/PPTP/GRE tunnel for DSL is Online Green active on P-560 No active PPPoE/PPTP/GRE tunnel for DSL on P-560 Orange WAN active/working WLAN Orange WLAN active/working LAN (1, 2, 3, 4) Green 100 Mbps network connection exists...
Access Controller. Step 6 Wait 30 seconds until the boot process is finished and check to ensure that at least the following LEDs are ON: Status LED (steady On) WAN LED LAN LED WLAN link LED Gemtek Systems Page 15...
Software Introduction: KickStart The Gemtek Systems KickStart is a software utility that is included on the Installation CD. The utility automatically detects access points and access controllers installed on your network, regardless of its host IP address and lets you configure each unit’s IP settings. The feature list for the...
Page 17
Step 1 Install the KickStart utility from the Installation CD. Click Start > Programs > GSI > KickStart to launch the application. If the P-560 device is connected to your network, the utility will automatically find your AC: Gemtek Systems...
Page 18
Press the reset button for more than 5 seconds. Now you are enabled to perform the initial controller configuration. Follow the next section for step-by- step setup instruction to configure the device according to your needs. Gemtek Systems Page 18...
In the network interface | RADIUS settings menu you can first define the local settings of the integrated RADIUS client of the Access Controller. For example you can modify timeouts and the NAS server ID (name of the RADIUS client): Gemtek Systems Page 19...
Page 20
(default = on) - the page with online help information for log-on. start page (default = on) - the default-page that will be presented to the user after successful log-on. unauthorized page (default = on) - the page which appears if web login method is disabled. Gemtek Systems Page 20...
Page 21
Users connected to the LAN port of the Access Controller can type in any URL in their browser and they will be redirected to your defined welcome (if enabled) and login pages. Administrators can monitor connected users via the connection | users menu. Gemtek Systems Page 21...
IP: 10.1.1.1/16 IP Conflict Conflict: Subscriber’s IP address must not be IP: 192.168.2.66/24 identical to the LAN IP address of the Access Controller. Work-around: Use a seldom-used IP address range for the LAN port. IP: 10.1.1.1 Gemtek Systems Page 22...
Page 23
DHCP and UAT are used in parallel. Work-around: Enable the DHCP service. IP: 10.11.11.11 IP Conflict IP: 10.11.11.11 Subnet: 255.255.0.0 The subscriber’s IP address and gateway Gateway: 10.11.1.254 address must be in the same subnet (a real network configuration). Gemtek Systems Page 23...
One Click page – the additional pop-up pages, displayed when one click roaming for the third party WLAN operators are preconfigured. All further presented user pages are factory default. The Hotspot operator can upload new templates for all user pages. Gemtek Systems Page 24...
Figure 11 – Simple Login Page The login name and password can be obtained from your Hotspot Operator. Login format available for P-560: username@WISPdomain WISPdomain/username The login page also displays subscriber’s logical and physical network addresses (IP and MAC).
Refresh button – click the button to refresh the subscriber session information. The Hotspot operator can change the logout page interface according to its needs. See more details in section: Changing User Pages. All session details are further accessible via the operator XML interface. Gemtek Systems Page 26...
Figure 14 – Unauthorized Page The Hotspot operator can change the unauthorized page according to its needs. See more details in section: Changing User Pages. Gemtek Systems Page 27...
Prepare your new user pages template for each user page: welcome/login/logout/help/unauthorized/oneclick. Step 2 Under the user interface | configuration | pages menu select the user page you want to change (e.g. login) Step 3 Choose the external option under the use column: Gemtek Systems Page 28...
Page 29
Save entered changes with the apply changes button: Step 6 Check for new uploaded user page (e.g. login): If at anytime you wish to restore factory default user pages, click the reset button under the system | reset menu. Gemtek Systems Page 29...
Specify the location for the additional files of new user page templates: images and a cascading style sheet file (css) by clicking the browse button or enter the location manually: Gemtek Systems Page 30...
Page 31
Check for the newly uploaded user pages and images to ensure that everything is uploaded and displayed correctly. Go to the link: https://<device-IP-address>/ to get to the new user welcome page: Click the here link or enter the link directly: https://<device-IP-address>/login.user to get to the new user login page: Gemtek Systems Page 31...
Page 32
User’s Guide Chapter 4 – User Pages If at anytime you wish to restore the factory default user pages, click the reset button under the system | reset menu. Gemtek Systems Page 32...
POST data not back to the AC, but to the Web Application Server (5). Thereafter the client communicates directly with the Web Application Server. Find more details on how to prepare the .XSL templates to renter the HTML in Appendix: G) User Pages Templates Syntax. Gemtek Systems Page 33...
Page 34
To define such redirection URL use the user interface | configuration | pages menu. Enable welcome page, set the redirect setting and specify the redirect location for such authentication process (also see: User Interface | Configuration | Pages). Gemtek Systems Page 34...
NAS server ID value. Can be changed or specified under the network nasid interface | RADIUS | RADIUS settings menu nasip P-560 WAN IP address. Can be changed or specified under the network interface | configuration | interface configuration menu. cientip Client IP address. Cannot be defined manually.
Page 36
User with supplied MAC address not found. No user by IP User with supplied IP address and username not found. No user by IP and MAC User with supplied IP, MAC addresses and username not found. Gemtek Systems Page 36...
Page 37
No user by IP and username User with supplied IP address and username not found. XML output when no errors and user statistics got successfully: <ppstatus> <status>Ok</status> <error>0</error> <description>Got user status.</description> <entry id="1">g17</entry> <entry id="2">192.168.2.117</entry> <entry id="3">200347C92B63</entry> <entry id="4">00:00:05</entry> Gemtek Systems Page 37...
Page 38
User IP address User MAC address Session time Session ID User idle time Output bytes Input bytes User WISP name Remaining bytes Remaining output bytes Remaining input bytes Bandwidth upstream Bandwidth downstream Remaining session time Authentication method Gemtek Systems Page 38...
192.168.2.66 where 192.168.2.66 is the default WAN interface IP. Login to CLI mode and the prompt will be displayed automatically. Enter the administrator login settings (refer to the Login section for details). Gemtek Systems Page 39...
A full list of all available connection commands/subcommands and its parameters is available in the Appendix section: D) CLI Commands and Parameters. In general, connection usage is as follows: connection <command> <value> To get a list of all available commands in the connection category type: Gemtek Systems Page 40...
<command> ?, (e.g. network radius ?) All available subcommands for radius are displayed: Figure 22 – Configure Network (1) Specific command contains several subcommands: network <command> <subcommand1> ?, (e.g. network radius servers ?) All available subcommands are displayed: Gemtek Systems Page 41...
Page 42
In some cases, entered commands without parameters display current controller configuration or settings: network <command> <subcommad1> <subcommad2>, (e.g. radius servers accounting), displays available RADIUS servers and its settings list (in this case, the RADIUS accounting server which is already updated): Figure 26 – Configure Network (5) Gemtek Systems Page 42...
<command> ?, (e.g. wireless basic ?) All available subcommands for radius are displayed: Figure 28 – Configure Wireless Basic To configure the desired controller interface setting, type all required parameters with values and subcommands. Use the samples from previous section. Gemtek Systems Page 43...
-u – define URL address -s – define URL description, visible for user: Figure 31 – Configure User Interface (2) If successful, a message regarding the successful completion is displayed; otherwise, an error message is displayed. Gemtek Systems Page 44...
Appendix section: D) CLI Commands and Parameters. In general, the system command usage is as follows: system <command> <subcommand1> <subcommand2> [-parameter] <value> To get the full list of the system commands, type: system ? Gemtek Systems Page 45...
Please note, that even the administrator password will be set back to the factory default. Refer to Appendix section: B) Factory Defaults for the Access Controller. Exit To leave the CLI mode, type the Exit command in the command line. Gemtek Systems Page 46...
Chapter 6 – SNMP Management Chapter 6 – SNMP Management Introduction Another way to configure and monitor the Access Controller (P-560) via a TCP/IP network is SNMP (Simple Network Management Protocol). SNMP is an application layer protocol that facilitates the exchange of management information between network devices.
Read-only—Gives read access to authorized management stations to all objects in the MIB except the community strings, but does not allow write access. Read-write—Gives read and write access to authorized management stations to all objects in the MIB, but does not allow access to the community strings. Gemtek Systems Page 48...
(up or down), MAC address tracking, and so forth. The SNMP agent also responds to MIB-related queries sent by the SNMP manager in get- request, get-next-request, and set-request format. P-560 get-request, get-next-reguest, get-bulk, set-request get-response, traps...
Advanced – channel selection, layer 2 client isolation and other settings Security – WEP and WPA ACL –access control default policy, static ACL, access control by MAC address WDS – access point and WDS modes User Interface Configuration –Welcome/Login/Logout/Help page customization Gemtek Systems Page 50...
Page 51
Users – connected users’ statistics list and log-out user function E-Mail Redirection – outgoing mail (SMTP) redirection settings Station Supervision – monitor station availability with ARP-pings settings In the following sections, short references for all menu items are presented. Gemtek Systems Page 51...
Interface name cannot be changed because the hardware drivers define it. Status – select the status of interface: [enabled/disabled]. Do not disable the interface through which you are connected to the P-560. Disabling such interface will lose your connection to the device.
Page 53
For such general changes as interface settings change, the Hotspot-in-a-Box server needs to be restarted. Request for restart server appears: Figure 43 – Restart Server Restart – Click the button to restart the server and apply the changes. Gemtek Systems Page 53...
IP Address – enter the network address of your VLAN [format: digits and dots]. Netmask – enter the netmask for your VLAN network [format: digits and dots]. Gateway – select gateway for VLAN network [default: ixp1]. Gemtek Systems Page 54...
Netmask – enter the target network netmask [dots and digits]. Save – save the new route. Cancel – restore all previous values. Figure 51 – Save New Route Up to 255 static routes can be set between each interface. Gemtek Systems Page 55...
Type = TCP, local IP address/port = 192.168.2.248:8080 remote IP address/port = 1.2.3.4:8080. With such a rule all traffic coming to port 8080 on the P560 interface local address 192.168.2.248 will be forwarded to port 8080 on the server (host) 1.2.3.4. Port forwarding is limited to 255 rules. Gemtek Systems Page 56...
When user is redirected to device welcome/login page, redirection will be done to: WAN-IP, if no hostname defined; hostname, if hostname defined, but domain empty; hostname.domain, if hostname and domain defined. You can enter the primary and secondary DNS servers settings under the network interface | DNS menu: Gemtek Systems Page 58...
IP address range and WINS address for client workstations. Other settings, such as the default gateway and DNS server address are configured automatically according to the interface settings. To see the complete DHCP service configuration, click the details button in the action column: Figure 61 – DHCP Settings Details Gemtek Systems Page 59...
Page 60
DNS secondary address – specify the secondary DNS server’s IP address [in digits and dots notation]. Case 2 Configure the DHCP relay Select the interface on which you want to configure the DHCP service [eth0/ixp0/vlan[n]]. Select the DHCP relay and click the update button specify the DHCP relay parameters: Gemtek Systems Page 60...
Page 61
If DHCP relay service is selected, the default WAN gateway is used automatically. Update – to update entered values, the following screen appears: Figure 65 – Apply or Discard DHCP Server Settings Apply Changes – to save entered new DHCP settings. Discard Changes – to restore previous values. Gemtek Systems Page 61...
Accounting Backup – backup the RADIUS subscribers accounting information. In the Appendix tables: E) Standard RADIUS Attributes and Vendor Specific Attributes Hotspot operators will find the required standard RADIUS attributes for setting up the RADIUS system. Gemtek Systems Page 62...
Bandwidth Up – maximum bandwidth up at which corresponding user is allowed to transmit [bps]. Bandwidth Down – maximum bandwidth down at which corresponding user is allowed to receive [bps]. User can check its available bandwidth in the logout page statistics. Gemtek Systems Page 63...
Page 64
Figure 68 – Apply or Discard RADIUS Settings Apply Changes – click if RADIUS settings configuration is finished. Discard Changes – restore all previous values. Gemtek Systems Page 64...
Edit – edit selected RADIUS server settings. Delete – remove selected RADIUS server. To view complete RADIUS server settings, click the details button in the action column: Figure 70 – RADIUS Server's Details To edit RADIUS server click the edit button: Gemtek Systems Page 65...
Page 66
UAM authentication method – select authentication method from drop-down menu: PAP – Password Authentication Protocol CHAP – Challenge Handshake Authentication Protocol MSCHAP1 – Microsoft Challenge Handshake Authentication Protocol version 1 MSCHAP2 – Microsoft Challenge Handshake Authentication Protocol version 2 Gemtek Systems Page 66...
(P560). The AP should be in the bridge mode. Step 2 Using the network interface | RADIUS | proxy menu configure the RADIUS proxy parameters: RADIUS authentication port (UDP), RADIUS accounting port (UDP) - different from authentication port and Accounting detection timeout: Gemtek Systems Page 67...
Page 68
RADIUS server for which the following packet will be forwarded. Such preconfigured AC will act as RADIUS proxy and will forward the RADIUS authentication and accounting packets from AP according WISP and RADIUS server settings in the AC configuration without any modification. Gemtek Systems Page 68...
Backup to local file – enable this option, and the download button appears: Download – click the button to download the accounting information file to your selected location. Both types of accounting backup can be enabled. Gemtek Systems Page 69...
AAA traffic between the hotspot network and the network operation center of the operator. The Gemtek Systems Access Controllers support PPTP and GRE tunnels. Furthermore PPP (Point- to-Point Protocol) can be use to authenticate the AC to a authentication server and to assign IP settings to the WAN port of the AC.
Password – enter password by which user should be authenticated [text string, can not be empty]. Encryption – enables use of MPPE encryption. Network/Netmask – enter remote network settings [format: dots and digits]. Up to 16 VPN entries can be set. Gemtek Systems Page 71...
Router: 192.168.82.16 GRE Server GRE Tunnel Internet Net B GRE Device IP: 211.139.210.168 WLAN: 192.168.3.0/24 P-560 Figure 83 – GRE Tunnel For example, there are 2 internal networks: network A and B, and intermediate network - Internet. Gemtek Systems Page 72...
Page 73
LAN IP: 192.168.82.16 WAN IP: 211.139.210.123 Settings in GRE tunnel page: GRE Remote Host: 211.139.210.123 GRE Route: 192.168.82.0/24 Network B has subscribers on wireless P-560 interface (eth0) we shall call this network (192.168.3.0/24) “Net B”: Network: 192.168.3.0 Netmask: 255.255.255.0 Router: 192.168.3.1 Where GRE interface (WAN IP of AC) is 211.139.210.168.
Page 74
32-N bits left that are part of our network. The first N bits of x.x.x.x correspond to x.0.0.0 when N=8, our network address, and the netmask is 255.0.0.0 (when N=8). bits netmask 255.255.255.255 255.255.255.252 255.255.255.248 … … 255.255.255.192 255.255.255.128 255.255.255.0 … … 255.255.0.0 … … 255.0.0.0 … … 0.0.0.0 Gemtek Systems Page 74...
Supported Rates – are the list of rates that the radio is capable of running. Preamble Settings – indicates Dynamic mode that allows mixing Long Preamble only clients with Short Preamble capable clients. If both 802.11g clients and Long Preamble only clients are Gemtek Systems Page 75...
Page 76
For example, for three Access Points in close proximity choose channels 1, 6 and 11. Gemtek Systems Page 76...
A mobile client that supports WPA and your operating system To configure the WPA with pre-shared key security on the P-560 use the network interface | wireless | security menu, select the WPA with pre-shared key security method and enter the pre-...
WPA with RADIUS server makes use of external AAA (RADIUS) server to generate and exchange dynamic WPA keys between P-560 and user station. To configure the WPA with RADIUS server security on the P-560 use the network interface | wireless | security menu and select the WPA with RADIUS server security method: Figure 89 –...
Page 79
[allow/deny]. The special ACL rule policy should differ from the default ACL policy otherwise the ACL rule does not work. Update – click the button to add new ACL rule. Gemtek Systems Page 79...
Wired LAN Figure 93 – WDS Link The WDS mode is configured by entering the WDS link peer access points (AP e.g. P-560) MAC address in each other’s AP configuration e.g. Web interface. As a result APs that relay data received from a wireless station to another access points (and vice versa) have to receive and send each packet over the same channel.
Page 81
MAC for Per AP [1-8] – enter wireless interface (eth0) MAC address of the peer AP for the WDS link [6-HEX pairs separated by colon [1-9] [A-F] [a-f]]. You can discover the wireless interface (eth0) MAC address of your P-560 in the system | status page.
Extended UAM). Status – choose enable/disable welcome page status. Note that redirect option with status ‘disabled’ would work. Location – enter location for external templates or redirect (e.g. WAS IP address). Figure 97 – Redirect User Pages Gemtek Systems Page 82...
User Interface | Configuration | Headers System administrator can set HTML headers encoding and language settings for AC web management interface and new uploaded user pages. Select user interface | configuration | headers menu: Figure 100 – HTTP Headers Settings Gemtek Systems Page 83...
Click the edit button next to appropriate settings to specify remote authentication parameters: Figure 103 – Enable Remote Authentication Remote Authentication – select status: [enabled/disabled]. Shared Secret – enter password for WAS to communicate with AC [sting (4-32), no spaces allowed]. Gemtek Systems Page 84...
Welcome Pages are stored on Portal. Every user, even T-mobile and Netcheckin will see Welcome pages loaded from Portal server. The Welcome page with portal URL should be entered on network interface | configuration | page. See the following diagram to understand One-Click roaming: Gemtek Systems Page 85...
The system administrator also can be the RADIUS user with corresponding attributes. The administrator menu is for changing the administrator’s settings: user name and password: Figure 107 – Administrators Settings Default administrator logon settings are: User Name: admin Password: admin01 Gemtek Systems Page 86...
This feature gives the ability to define a free, restricted service set for a user not yet logged into the system. Use the user interface | walled garden menu to view or change the free URLs or hosts: Gemtek Systems Page 87...
Page 88
Host – Web server address [IP address or host name]. Netmask – enter the network mask to specify the host servers network. Port – network port, which is used to reach the host [1-65535]. For standard protocols use the default ports: Protocol Port HTTP HTTPS Gemtek Systems Page 88...
To add more port number for web proxy, click the new button: Figure 116 – Add Web Proxy Port Port – add port number for web proxy to listen to [1-65535]. Save – click the button to save new proxy port number. Gemtek Systems Page 89...
Informational – informational messages including [warning/error/fatal] Warning – warning condition messages including [error/fatal] Error – error and critical condition messages including [fatal] Fatal – critical and fatal condition for device messages. Actions should be taken immediately. Gemtek Systems Page 90...
Refresh – click to refresh trace system messages. System | Configuration | Clock To set the Hotspot-in-a-Box internal clock, use the clock utility, accessed by selecting the system | configuration | clock menu link: Figure 121 – Clock Utility Gemtek Systems Page 91...
| configuration | clock menu. You may want to add more than one NTP host, for example, in the case where the first host fails to connect. Click the new button to add additional host settings: Gemtek Systems Page 92...
Depending on the public key infrastructure implementation, the certificate includes the owner's public key, the expiration date of the certificate, the owner's name, and other information about the public key owner. The default certificate implemented in the AC includes the following: Gemtek Systems Page 93...
You can use this file any time you want to restore this configuration to the device by using the upload button (see: Figure 130 – Save and Restore). Select the configuration file and upload it on the device: Gemtek Systems Page 94...
Heartbeat messages are sending between the nodes that indicate a node is up and running. Remote host – specify remote host [IP address or host name]. Remote port – specify remote host port number: 1-5 numbers, no spaces allowed, [1-65535]. Gemtek Systems Page 95...
New – click to create new access control rule for specific network to specific service(s) [all/ /ssh/telnet/snmp]. To configure the access control, click the edit button and specify the network address and select services to allow/deny: Figure 136 –Modify Access Control Gemtek Systems Page 96...
By default telnet is disabled: Figure 137 – Default Telnet Status To switch the telnet function on, click the edit button and change the status: Gemtek Systems Page 97...
Save – click the button to save the configuration. Cancel – restore the previous value. System | Access | AAA It is recommended to use the Gemtek Systems product Smart Client Manager (S-200) for EAP authentication methods. Such multimode Authentication, Authorization and Accounting (AAA) methods are supported on the AC: UAM –...
Then the IP address and Netmask can be changed: Figure 143 – Change Universal Address Translation Settings IP address – specify network IP of UAT address pool. Netmask – specify UAT address pool network mask. Update – update old values with entered ones. Gemtek Systems Page 99...
LAN. By default, clients connected on the WLAN and LAN cannot communicate among them-selves. This is prevented by default firewall rules. See the picture below to view the difference between employee and visitor traffic: Gemtek Systems Page 100...
Need help?
Do you have a question about the P-560 and is the answer not in the manual?
Questions and answers