Dahua Technology DH-PFM888S-AC User Manual
Dahua Technology DH-PFM888S-AC User Manual

Dahua Technology DH-PFM888S-AC User Manual

Wireless access controller

Advertisement

Quick Links

Wireless Access Controller
User's Manual
V 1.0.0
ZHEJIANG DAHUA VISION TECHNOLOGY CO., LTD.

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the DH-PFM888S-AC and is the answer not in the manual?

Questions and answers

Subscribe to Our Youtube Channel

Summary of Contents for Dahua Technology DH-PFM888S-AC

  • Page 1 Wireless Access Controller User’s Manual V 1.0.0 ZHEJIANG DAHUA VISION TECHNOLOGY CO., LTD.
  • Page 2: Legal Statement

    Legal Statement Copyrights © 2018 ZHEJIANG DAHUA VISION TECHNOLOGY CO., LTD.. All rights reserved. Any or full contents of the user’s manual cannot be copied, transmitted, distributed, partially or wholly, by any means, without the prior written notice of ZHEJIANG DAHUA VISION TECHNOLOGY CO., LTD.
  • Page 3: Cybersecurity Recommendations

    Cybersecurity Recommendations Mandatory actions to be taken towards cybersecurity 1. Change Passwords and Use Strong Passwords: The number one reason systems get “hacked” is due to having weak or default passwords. It is recommended to change default passwords immediately and choose a strong password whenever possible.
  • Page 4 ● You do not need to forward any ports for individual cameras if they are all connected to a recorder on site; just the NVR is needed. 7. Disable Auto-Login on SmartPSS: Those using SmartPSS to view their system and on a computer that is used by multiple people should disable auto-login.
  • Page 5 15. Connect IP Cameras to the PoE Ports on the Back of an NVR: Cameras connected to the PoE ports on the back of an NVR are isolated from the outside world and cannot be accessed directly. 16. Isolate NVR and IP Camera Network The network your NVR and IP camera resides on should not be the same network as your public computer network.
  • Page 6: Preface

    Preface Overview This document mainly introduces mounting and basic function of small wireless AC management platform. Applicable Model DH-PFM888S-AC Symbol Definition The following symbols may appear in the document. Please refer to the table below for the respective definition. Symbol...
  • Page 7: Important Safeguards And Warnings

    Important Safeguards and Warnings The following description is the correct application method of the device. Please read the manual carefully before use, in order to prevent danger and property loss. Strictly conform to the manual during application and keep it properly after reading. Operating Requirement Suitable working environment is the foundation of normal operation.
  • Page 8 Please don’t provide two or more power supply modes simultaneously, which may damage  the device or lead to safety risks.  It is suggested that overcurrent protection device (fuse or air switch) should be used in serial in device power circuit. Its overcurrent protection rated value shall not exceed 2 times as many as rated current of the device.
  • Page 9: Table Of Contents

    Table of Contents Legal Statement ..............................I Cybersecurity Recommendations ........................II Preface ..................................V Important Safeguards and Warnings ......................VI 1 Product Overview .............................. 1 1.1 Product Profile ............................1 1.2 Features ..............................1 1.3 Hardware Parameters ..........................4 1.4 Performance Specification ........................5 2 Device Mounting ..............................
  • Page 10 4.7.1 Online Map ........................... 51 4.7.2 Offline Map ........................... 54 4.7.3 Map Management ........................55 4.8 Marketing Management ......................... 56 4.8.1 Advertising Management ......................57 4.8.2 Theme Management ........................58 4.8.3 Advertising Statistics ........................59 4.8.4 Message Management ....................... 60 4.8.5 Application Example ........................
  • Page 11: Product Overview

    Product Overview Product Profile DH-PFM888S-AC is a wireless access control product independently researched, with a built-in Dahua wireless management platform. With this controller, realize centralized management and configuration of AP, and solve some management problems of traditional AP. Without needs to change the structure, this controller integrates with existing network perfectly, simplifies network allocation and management greatly, and thus saves users’...
  • Page 12 Figure 1-1 L2/L3 Network Configuration DH-PFM888S-AC boasts functions such as user management, smart radio frequency (RF) management and restoration. In any existing L2/L3 network, this product can realize seamless and safe wireless network configuration, without needs to interrupt present network operation.
  • Page 13 Figure 1-2 Real-time Surveillance System With real-time surveillance function, DH-PFM888S-AC is able to monitor the operating state of network, and timely report connection, disconnection and abnormal alarm info. Meanwhile, all records can be uploaded to log server. Support many types of system info.
  • Page 14: Hardware Parameters

    Map Display Device With map display function, observe the distribution and operation conditions of the device. Support to display device location on Baidu/Google Map.   Visually display the device info on the map. Figure 1-4 Hardware Parameters For relevant hardware parameters, please refer to Table 1-1. Feature Specification IPQ4028...
  • Page 15: Performance Specification

    Performance Specification For performance specification of DH-PFM888S-AC, please refer to Table 1-2. Features Specification Quantity of managed devices Quantity of support modules 8192 Table 1-2...
  • Page 16: Device Mounting

    Device Mounting Interface Schematic diagram of interfaces is shown in Figure 2-1. Please refer to Table 2-1 for descriptions. Figure 2-1 Interface Name Connection and Function DC12V DC-JACK DC power supply (12V 2A). LED indicator LED indicator Power indicator, 2G/5G indicator. Import license info to open authority of AP managed number.
  • Page 17: Device Mounting

    Table 2-1 Device Mounting DH-PFM888S-AC can be mounted on the wall or on desktop directly. Step 1 Drill 8mm hole in the wall. Step 2 Put in rivet bolt, and tighten screw. Step 3 Install the device onto the screw.
  • Page 18: Go Online

    Go Online L2 Goes Online Access points can directly connect LAN interface of DH-PFM888S-AC to go online. To join DH-PFM888S-AC, clients shall associate with access point device that has already joined DH-PFM888S-AC. 3.1.1 Access Point Device Goes Online Step 1 Open IP address page of the access point device to modify its IP address.
  • Page 19: Client Device Goes Online

    Item Description WTP Name Name of access point device on DH-PFM888S-AC, to be filled in according to needs. Info about device location on DH-PFM888S-AC, to be filled in according to needs. Location It consists of manual designation and automatic mode. Access point device IP and IP of DH-PFM888S-AC LAN interface shall be in the same network segment.
  • Page 20: L3 Goes Online

    Up to now, setting of access point and client has been completed, ready to join DH-PFM888S-AC. Please check at DH-PFM888S-AC page. L3 Goes Online When DH-PFM888S-AC and the device to be managed are located in different network segments in relatively complicated network environment, online environment of access point and client is shown as follows.
  • Page 21: Access Point Device Goes Online

    Figure 3-6 Step 2 Set the following parameters in wireless setting page of access point device. SSID is DaHua, automatic channel; default encryption is WPA2-PSK (key is 1234567890abc). After the device joins DH-PFM888S-AC, these parameters can be modified on DH-PFM888S-AC pages.
  • Page 22 WTP Location according to needs. It consists of manual designation and automatic mode. Access point device IP and IP of DH-PFM888S-AC LAN interface shall be in the same network segment.  In case of manual designation, fill in IP address of DH-PFM888S-AC Add IP LAN interface manually;...
  • Page 23: Client Device Goes Online

    Connect access point device with one LAN interface of L3 router, whose IP address is 192.168.2.254. Access point device will go online at DH-PFM888S-AC. 3.2.2 Client Device Goes Online To join DH-PFM888S-AC, client devices shall wirelessly associate with access point device that has already joined DH-PFM888S-AC. Step 1 Open IP address page of the client device to modify its IP address.
  • Page 24 Figure 3-10 Up to now, setting of access point and client has been completed, ready to join DH-PFM888S-AC. Please check at DH-PFM888S-AC page.
  • Page 25: Functional Introduction

    255.255.255.0 255.255.255.0 Table 4-1 Operating Steps Step 1 Input DH-PFM888S-AC platform address in the browser, and press [Enter] key. The system displays login interface, as shown in Figure 4-1. Figure 4-1 Input username and password; click “Login”. Step 2 Default username is “root” and password is “admin”. It is suggested that a password...
  • Page 26: State Statistics

    State Statistics State statistics page is mainly used to display basic info about DH-PFM888S-AC, device and terminal state, as shown in Figure 4-2. Figure 4-2 For meanings of every column, please refer to Table 4-2.
  • Page 27: Device Management

    Table 4-2 Device Management 4.3.1 Device List Device list page displays info about all online/offline access point devices of DH-PFM888S-AC, as well as client devices under access point devices, as is shown in Figure 4-3 and Figure 4-4. Figure 4-3...
  • Page 28: Delete Device

    Parameter Description MAC Address Wired MAC address of access point or client device. Soft. Version Software version of access point or client device. Run Time Run time after access point or client device goes online. Group Group name of access point device. On the right of the list, select “More >...
  • Page 29: Edit Group

    Figure 4-5 4.3.3 Edit Group This part mainly introduces how to edit groups in batches and multiple levels. Click “ ”. Step 1 The system displays “Edit Group” interface, as shown in Figure 4-6. Figure 4-6 Click “New”, fill in name of root directory, such as “All”. Then, click “Finish”. Step 2 On completion, the interface is shown as Figure 4-7.
  • Page 30 Figure 4-7 Click “New” button again, fill in group name, choose higher level group, and click Step 3 “Finish”. Create multi-level group by reference to this step. The interface is shown in Figure 4-8. Figure 4-8 Choose one group, click “Add Device”, and thus add devices to this group in batches. Step 4...
  • Page 31: Issue Template

    Figure 4-9 4.3.4 Issue Template In the interface of device list, the added template can be issued to designated access point and client devices. Please refer to “4.5.1 Template Management” for details. Device with state means that the device is not configured. Select “More >...
  • Page 32: Device Upgrade

     If access point device owns client(s), client(s) will be issued at the same time. On DH-PFM888S-AC, templates cannot be directly issued to client(s). When the connected access point changes its configuration, the client will adapt to parameters of access point, so as to maintain normal communication with access point.
  • Page 33: Retrieve The Client

    Figure 4-13 In “Soft. Version”, select the desired version. Step 2 After editing, select “More > Save” to start upgrade. Step 3 The state changes into upgrading . The device disconnects during  upgrade. Its state becomes online after upgrade, which means that upgrade has been successful If the selected version in device list is the current version of device, it won’t be ...
  • Page 34: Terminal Management

    Step 2 Wait for 5 minutes. All clients once associated with access point will be associated again. Meanwhile, wireless template of access point will be changed to null. The interface is shown in Figure 4-15. Figure 4-15 Step 3 Select template name again and save. Terminal Management 4.4.1 Terminal List When mobile phones, notebooks and other terminals are connected with access point device,...
  • Page 35: Info Statistics

    Parameter Description Wireless Mode Wireless mode of access point associated with terminal Rate Connection rate of access point associated with terminal SSID SSID of access point associated with terminal User User name used by terminal for Web authentication Flow Upstream and downstream flow rate used by terminal after associated with access point Run Time Run time after terminal is associated with access point...
  • Page 36 Figure 4-17 Display “Online Terminal Type” and “Online User Group” according to “Terminal Type” in  terminal list and the edited “Group Name”. Figure 4-18  In the icon box of time sharing info, display the number of online users, number of registered users, upstream flow and downstream flow.
  • Page 37 Figure 4-19 “Download” to download the figure of present time sharing info. Click  “Line Chart” or “Bar Chart” to modify display mode. Click “Restore” to  Click restore display mode to default state. In Figure 4-20, the data is displayed with bar chart. Figure 4-20 In “Query Date”...
  • Page 38: Advanced Management

    Figure 4-22 Click MAC drop-down box to view time sharing info of every terminal according to MAC  address, as shown in Figure 4-23. Figure 4-23 Advanced Management 4.5.1 Template Management Template management page manages main template, basic template and VAP template. For the first time, create basic template and VAP template first, and then the main template is able to associate with the created basic template and VAP template.
  • Page 39 In the navigation bar, select “Advanced > Template”. Step 1 Click “VAP Template” tab and click “New”. Step 2 Fill in relevant info according to the user’s actual needs. Step 3 The interface is shown in Figure 4-24. Please refer to Table 4-6 for parameter descriptions.
  • Page 40 Parameter Description Choose to enable or disable this VAP. VAP Enable When it is enabled, the terminal can scan and connect with this VAP. SSID Name of wireless network. By setting it, limit the quantity of terminals that are connected with Max Terminals access point.
  • Page 41 Parameter Description Internet time length allowed after authentication. Universal Internet The terminal is not subject to length limit after enabling “Focus on Length Public No. to Unlimited Internet Access”. Flow Control Allowed traffic flow after authentication. The unit is day and month. Time Control Allowed time to surf the Internet after authentication.
  • Page 42 4.5.1.2 Basic Template 128 basic templates can be created at most. In the navigation bar, select “Advanced > Template”. Step 1 Click “Basic Template” and then click “New”. Step 2 Step 3 Fill in relevant info according to needs. The interface is shown in Figure 4-26. Please refer to Table 4-7 for parameter descriptions.
  • Page 43 Parameter Description Channel of info transmission. Before using non-standard frequency band, please check whether it Channel conforms to local laws and regulations, as well as wireless management rules. To use non-standard frequency band, please change the country to test mode. Channel Width It refers to maximum data transmission rate of the channel.
  • Page 44 Figure 4-28 Other Operations Select the template; click “Edit” to edit the basic template.  Select the template; click “Del” to delete it. Multiple templates can be selected and deleted  together, but the template under use cannot be deleted. ...
  • Page 45: Image Management

    AP and associated client device immediately. In case that wireless service configuration template, which is planned to be deleted, has  been applied to online device with DH-PFM888S-AC management, the template cannot be deleted. 4.5.2 Image Management Image management is used to manage the software version, which can be upgraded manually or automatically through software in image management list.
  • Page 46 Figure 4-32 Update: Click “Manual Update” to select and update the selected devices that meet version  requirements. Click “Upgrade All” to update all devices that meet version requirements.  4.5.2.1 Automatic Upgrade In the navigation bar, select “Advanced > Image Management”. Step 1 The system displays “Image Management”...
  • Page 47 4.5.2.2 Manual Update Devices managed by DH-PFM888S-AC can be updated manually in two ways: Single device update: please refer to “4.3.5 Device Upgrade” for details.   Multiple devices update: please refer to this section. In the navigation bar, select “Advanced > Image Management”.
  • Page 48: System Log

    Figure 4-36 4.5.3 System Log Log management keeps all log info and warning info of the system. It is able to look up relevant log info according to keyword, log module, log level and time frame, and help research and development personnel to troubleshoot.
  • Page 49: System Settings

     Search Alarm Click “Alarm”, set the keyword, alarm module, alarm level or time frame, and click “Search” to search alarm info, as shown in Figure 4-38. Figure 4-38 System Settings Page of system settings includes basic settings, upgrade configuration management and access control.
  • Page 50 Table 4-8 Click “Save”. Step 2 4.6.1.2 Time Synchronization Set time synchronization between DH-PFM888S-AC and NTP server. In the navigation bar, select “System Settings > Basic Settings”. Step 1 Click “Time Sync” tab. Step 2 The system displays “Time Sync” interface, as shown in Figure 4-40.
  • Page 51 After this function is enabled, please fill in address of NTP Client proper time server according to needs, such as 118.103.146.184. At this time, LAN port of DH-PFM888S-AC shall be connected to public network, and configured with correct IP address and gateway. NTP Server IP IP address of designated NTP server.
  • Page 52: Upgrade Configuration Management

    Parameter Description Default IP address of WAN interface is 192.168.3.100. PC connects WAN Interface management interface and visits the network management interface of the device through the browser. PC connects LAN interface, and visits the network management  interface of the device through the browser. LAN Interface ...
  • Page 53: Access Control

    Upload Configuration: upload config.db file to configure DH-PFM888S-AC. Click “Select File”, select “config.db”, and then click “Upload”. If image file on DH-PFM888S-AC server is inconsistent with image file info in the uploaded configuration file, at the end of waiting page, there will be hints to delete info.
  • Page 54 4.6.3.1 Enable Web Authentication After Web authentication is enabled, Web authentication system will redirect the client to authentication login interface. The user inputs valid username and password, and then submits. Web authentication system will show successful login interface, and redirect authenticated client to the designated URL.
  • Page 55 In case of external Portal, set external Portal server address, and ensure connection of LAN interface of DH-PFM888S-AC and Portal server.  In case of internal Portal, Portal server is DH-PFM888S-AC itself. During billing, billing server makes statistics of billing info about Accounting Interval wireless client at set intervals.
  • Page 56 Step 5 Click “New”. Add IP address and port of Portal server. In case of internal Portal, add IP and 80 port of DH-PFM888S-AC.  In case of external Portal, add IP and corresponding http port (such as 80 or ...
  • Page 57 Enable pre-authentication access control white list, and add the previous rules to white list, as shown in Figure 4-47. Please refer to Table 4-13 for parameter description. Figure 4-47 Type Parameter Description Set the access right before wireless terminal Authentication passes Web authentication.
  • Page 58 Type Parameter Description Fill in SSID to be controlled; select rules that have been set at “ACL Control Rules” interface. SSID Terminals associated with this SSID wirelessly will take effect according to rules. Table 4-13 Click “Authentication Account” tab to configure parameters. Step 7 ...
  • Page 59 Figure 4-51 Figure 4-52 Step 10 Access point device issues template to enable Web authentication. Step 11 Web authentication of wireless terminal. Wireless terminal associates with SSID that has enabled Web authentication, and obtains IP address of public network. Open the browser of terminal device, input any address and it will be forced to visit the address of Web authentication server.
  • Page 60 Operating Step Step 1 VAP template issued by access point device shall enable WeChat authentication. Enable WeChat authentication at “Advanced > Template > VAP Template”. Please refer to “4.5.1.1 VAP Template” for details. In the navigation bar, select “System Settings > Access Control”. Step 2 Configure Portal parameters.
  • Page 61: Map Mode

    Map Mode In map mode, all devices are displayed on the map. Import planar graphs of apartments, communities, malls and schools, and display the devices on planar graphs. 4.7.1 Online Map When access point and client devices in the device list are online, devices are displayed on the map normally, and they can be dragged and modified.
  • Page 62 Figure 4-54 Configuration Result View configured device info on the map. AP and STA icons appear.  Colored icon represents online device, whereas gray icon represents offline device.  MAC address of the device is displayed on every icon.  Green line between devices represents wireless connection at present;...
  • Page 63 Figure 4-55 Other Operations Drag: if you are uncertain about specific address, drag online device icon to determine the  location. For example, drag AP icon to Linjiang Park. Online device (whose configuration status is normal operation) supports drag operation, but offline device doesn’t support. Delete offline device: click the right mouse button and select “Delete”.
  • Page 64: Offline Map

    4.7.2 Offline Map Step 1 Import offline map. In the navigation bar, select “Map Mode > Map Management”. Click “Offline Map” tab. Click “Import” to import image info. Resolution ratio of uploaded image shall be larger than 600×600.  Support “.png” and “.jpg” images. ...
  • Page 65: Map Management

    Figure 4-58 Click “Confirm”, and the interface displays the added device. Step 4 Figure 4-59 4.7.3 Map Management Online Map Management Online map is “Baidu Map” by default, as shown in Figure 4-60. Map selection: online map selects “Baidu Map” by default. ...
  • Page 66: Marketing Management

    Figure 4-60 Offline Map Management The system supports to import offline map, such as planar graphs of apartments, communities, malls and schools, and display the devices on planar graphs. In the navigation bar, select “Map Mode > Map Management”. Step 1 Click “Offline Map Management”...
  • Page 67: Advertising Management

    advertising theme at theme management interface. After selecting the theme, advertising image will be pushed when the terminal connects access point. 4.8.1 Advertising Management Upload advertising image, which is imported by theme management interface. In the navigation bar, select “Marketing Management > Advertising Management”. Step 1 The system displays “Advertising Management”...
  • Page 68: Theme Management

    Parameter Description Ad image name. Ad Name Ad name can be 1 ~ 63 non-null characters, including number, letter or Chinese character (one Chinese character occupies 3 digits). The position of ad image on the terminal device. Ad Position In theme 1, available position includes top image carousel and tail image. In theme 2, ad position is full screen image.
  • Page 69: Advertising Statistics

    Figure 4-65 In theme 1, click at top image carousel, in order to upload multiple images. 4.8.3 Advertising Statistics Advertising statistics interface makes a statistics of the number of clicks of the advertising. View the data of today, yesterday, last seven days and this month; search according to date. The data can be exported with Excel.
  • Page 70: Message Management

    Figure 4-66 4.8.4 Message Management Message management interface is used to view the user’s message feedback info. In the navigation bar, select “Marketing Management > Message Management”. The system displays “Message Management” interface, as shown in Figure 4-67. Figure 4-67 4.8.5 Application Example Before marketing management interface enables advertising authentication, please enable internal Web authentication (please refer to “4.6.3.1 Enable Web Authentication”...
  • Page 71 Click “Radius” tab to configure “Internal Radius”, as shown in Figure 4-69. Step 3 Figure 4-69 Click “ACL Control Rules” tab to fill in AC IP address and 80 port number, and add to Step 4 white list, as shown in Figure 4-70. Figure 4-70 Click “Rule Configuration”...
  • Page 72 Figure 4-72 In the navigation bar, select “Marketing Management > Theme Management”, create a Step 7 theme and select advertising image, as shown in Figure 4-73. Figure 4-73 Select the box on the left of theme name, and click “Confirm”. Step 8 Advertising images of this theme will be pushed in the terminal, as shown in Figure 4-74.
  • Page 73 Web authentication, and then go online. Advertising viewing interface of the terminal is shown in Figure 4-75. LAN port of DH-PFM888S-AC shall be connected with public network.  Wireless terminal, such as mobile phone and notebook computer, obtains IP ...
  • Page 74: Logout

    Figure 4-75 Logout Click button at the top right corner of the interface, and return to login interface.
  • Page 75 ZHEJIANG DAHUA VISION TECHNOLOGY CO., LTD. Address: No. 1199, Bin’an Road, Binjiang District, Hangzhou, P.R. China Postcode: 310053 Tel: +86-571-87688883 Fax: +86-571-87688815 Email:overseas@dahuatech.com Website: www.dahuasecurity.com...

Table of Contents